Re: ... GDPR takedown request

2022-06-14 Thread Jeremy T. Bouse
e secret keys > because he has to read 16 encrypted mails soon... > > Gabor > > -- Jeremy T. Bouse Sr. DevOps Engineer 678.348.0867 UnderGrid.net <http://undergrid.net/> <https://www.credly.com/badges/ebfdee3b-04ff-4ead-9f5c-d9345f759a0f> <https://www.credly.com/ba

Re: keyserver.insect.com GDRP takedown request

2022-05-26 Thread Jeremy T. Bouse
itizens) so I think GDPR applies in this case. > > > --- > Prof. Ari Trachtenberg ECE, Boston University > trach...@bu.eduhttp://people.bu.edu/trachten > > -- Jeremy T. Bouse Sr. DevOps Engineer 678.348.0867 UnderGrid.net <http://undergrid.net/&

Re: shutdown of pgpkeys.co.uk and pgpkeys.uk

2021-06-22 Thread Jeremy T. Bouse
Actually, my research into Hagrid appears to indicate that it performs the functions of HKP and WKS/WKD. The lack of ability to synchronize keys being the biggest issue. The lack of third-party signatures is regrettable as it does essentially neuter the keys retrieved as far as a web of trust

Re: shutdown of pgpkeys.co.uk and pgpkeys.uk

2021-06-22 Thread Jeremy T. Bouse
Actually my research into Hagrid appears to indicate that it performs the functions of HKP and WKS/WKD. The lack of ability to syncrohnize On Tue, Jun 22, 2021 at 3:52 PM Andrew Gallagher wrote: > On 22/06/2021 19:28, Kiss Gabor (Bitman) wrote: > > On Tue, 22 Jun 2021, Todd Fleisher wrote: > >

Re: shutdown of pgpkeys.co.uk and pgpkeys.uk

2021-06-22 Thread Jeremy T. Bouse
Yes, I've come to the same conclusion that Hagrid does not at this point in time have any means of federation or "peering". I don't know enough about Hockeypuck myself and had only briefly looked at it before in the past. One of the major issues with the way peering worked with SKS that was

Re: shutdown of pgpkeys.co.uk and pgpkeys.uk

2021-06-22 Thread Jeremy T. Bouse
In all honesty, as much as I would like to restore my own key server and make it available as a public resource I think realistically looking at the SKS software with objective eyes there are flaws that would have to be addressed or the same situation would persist. The manner in which the

SKS Recon/Gossip operational functionality

2020-10-28 Thread Jeremy T. Bouse
Okay, so as my move has settled down and I've been working on trying to get my keyserver back online I think I've come up against a functionality issue that I'm trying to see if I can't figure out how to work around it. So I'm trying to deploy within my AWS environment using ECS Fargate with an

Re: Building SKS on Alpine Linux 3.12 with ocaml 4.08

2020-10-18 Thread Jeremy T. Bouse
So I've spent the weekend working on my SKS Docker image build... The repo is available at https://github.com/UGNS/sks-docker and the image itself is available at https://hub.docker.com/r/jtbouse/sks I'd welcome some further sets of eyes on it. I've ran several tests against it all weekend with

Building SKS on Alpine Linux 3.12 with ocaml 4.08

2020-10-14 Thread Jeremy T. Bouse
Okay, so I have completed my move and finally had some time to take a look back at trying to get sks.undergrid.net back online and started with trying to rebuild my Docker images which I found the build to be failing in part to the repo change. So I remembered the email here and updated my

Fate of sks.undergrid.net

2020-02-26 Thread Jeremy T. Bouse
Regrettably, at this time sks.undergrid.net will be going offline indefinitely. My wife and I are in the process of selling our house in Georgia and moving to Florida. In preparation, I've been moving most of my services I need to keep available into the cloud. Unfortunately due to the usage/abuse

[Sks-devel] sks.undergrid.net back online

2019-04-01 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I've been dealing with instability here but I think I've got a handle on it. Should see how the next 24-48 hours go after taking everything offline for the past 12 hours. I had the DB on my primary node get corrupted once again. I've changed

Re: [Sks-devel] Unusual traffic for key 0x69D2EAD9 and 0xB33B4659

2019-03-20 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 3/20/2019 2:42 PM, Andrew Nagy wrote: > All, > > Looking to figure out a solution here. A Maintainer on the Ubuntu > Key server informed me about discussion of the following keys > 0x69D2EAD9 and 0xB33B4659 here: >

Re: [Sks-devel] DNS broken for hkps.pool.sks-keyservers.net

2019-03-18 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 3/18/2019 1:08 PM, Kristian Fiskerstrand wrote: > On 3/18/19 3:58 PM, Todd Fleisher wrote: >> The GNUPG-users post mentions something that may be the root >> cause: The status page for sks-keyservers.net shows no hosts are >> currently available

Re: [Sks-devel] No dumps

2019-03-15 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I've checked out the script that Matt uses and once I get my server stabilized more I'll get it enabled and available. My server is in the US but it is on a gigabit fiber connection. On 3/15/2019 6:49 PM, Matt Rude wrote: > The keyserver

Re: [Sks-devel] exception Bdb.DBError

2019-03-13 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 3/13/2019 12:35 PM, fuat wrote: > hello, I get the following error. > > Fatal error: exception Keydb.Unsafe.No_db > > This error occurred when the gossip was set with the servers. > before the apache proxy started giving error. This error

Re: [Sks-devel] SKS Performance oddity

2019-03-09 Thread Jeremy T. Bouse
On 3/9/2019 5:29 AM, Michiel van Baak wrote: > > Hey, > > I hav exactly the same problem. > Several times in the last month I have done the following steps: > > - Stop all nodes > - Destroy the datasets (both db and ptree) > - Load in a new dump from max 2 days old > - Create the ptree

[Sks-devel] SKS Performance oddity

2019-03-08 Thread Jeremy T. Bouse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I don't know what is going on here with my cluster but I have 3 of 4 nodes that absolutely perform as I would expect... They have 2 vCPU with 4GB RAM each along with an extra 50GB drive exclusively for SKS use under /var/lib/sks. The three

[Sks-devel] sks.undergrid.net back online

2019-03-06 Thread Jeremy T. Bouse
    I know it's been down for awhile, I think I recall it went down with corrupted data sometime around October last year, but I'm pleased to announce that sks.undergrid.net is back online and fully populated. I've cleaned up my membership file and do currently have one commented out as I've

Re: [Sks-devel] Debugging a corrupted key

2019-03-06 Thread Jeremy T. Bouse
On 3/6/2019 12:01 PM, Jim Popovitch wrote: > On Wed, 2019-03-06 at 11:44 -0400, Jason Harris wrote: > > On Wed, Mar 06, 2019 at 09:57:58AM -0500, Jim Popovitch wrote: > >> Hello! > >> > >> What are some investigative techniques to determine how my GPG key was > >> corrupted. > >> > >> gpg

Re: [Sks-devel] SKS Memory pattern anomaly

2019-03-05 Thread Jeremy T. Bouse
thoughts for next steps? On 3/5/2019 1:09 AM, Jeremy T. Bouse wrote: >     Has anyone else been monitoring the memory pattern for SKS and > noticed an exceedingly high memory usage pattern? My secondary nodes are > generally showing < 11% of the instance memory used but for some reason >

[Sks-devel] SKS Memory pattern anomaly

2019-03-04 Thread Jeremy T. Bouse
    Has anyone else been monitoring the memory pattern for SKS and noticed an exceedingly high memory usage pattern? My secondary nodes are generally showing < 11% of the instance memory used but for some reason I'm seeing my primary node using nearly 100% of memory, and CPU for that matter. My

Re: [Sks-devel] SKS scaling configuration

2019-03-04 Thread Jeremy T. Bouse
ual SKS back-end can handle? > > Jonathon > > Jonathon Weiss > MIT/IS/Cloud Platforms > > > > > On Fri, 1 Mar 2019, Jeremy T. Bouse wrote: > >> >> I ended up with the following NGINX configuration... >> >> in /etc/nginx/conf.d/

Re: [Sks-devel] SKS scaling configuration

2019-02-28 Thread Jeremy T. Bouse
following log entry popping up only on my primary node:     add_keys_merge failed: Eventloop.SigAlarm On 2/25/2019 12:37 PM, Todd Fleisher wrote: >> On Feb 23, 2019, at 8:35 PM, Jeremy T. Bouse >> mailto:jeremy.bo...@undergrid.net>> wrote: >> >> I didn't have as many

Re: [Sks-devel] SKS scaling configuration

2019-02-23 Thread Jeremy T. Bouse
Hi Todd,     The timing of this thread and your reply are ideal as I'm in the process of working to fix my cluster that has been down for some time due to system failure and lack of available time on my part to repair it. Since I'm in the process I've been working to revisit the setup itself.    

Re: [Sks-devel] "SKS is effectively running as end-of-life software at this point"?

2019-02-06 Thread Jeremy T. Bouse
On 2/6/2019 11:26 AM, Andrew Gallagher wrote: > On 06/02/2019 13:11, Steffen Kaiser wrote: >> Is it meant litterally? The current SKS project is end of life and, >> effectively, we have to look into another direction? Other software, new >> fork with rewrite? > I said "effectively", not

Re: [Sks-devel] heads-up: another attack tool, using SKS as FS

2018-07-14 Thread Jeremy T. Bouse
On 7/14/2018 9:42 AM, Hendrik Visage wrote: > > >> On 14 Jul 2018, at 13:04 , Gabor Kiss > > wrote: >> Then let's drop keys that don't contain a valid email address in the key id. >>> >>> How do you propose to validate the email address? >>> >>> (Hint: this is

[Sks-devel] Operational question for all

2018-03-13 Thread Jeremy T. Bouse
    I've been running my SKS cluster under Docker for awhile now and my current Docker cluster is currently Tango Uniform it would appear (hence sks.undergrid.net being offline still). I've got an ECS (Docker-based) cluster already running and operational in AWS that I could move the service over

[Sks-devel] Unplanned outage of sks.undergrid.net

2018-02-15 Thread Jeremy T. Bouse
Apologizes to those peered with me but I've encountered an unexpected issue with my Docker cluster that has my containerized SKS cluster offline. I'm working to remedy the issue but so far having some trouble identifying the exact cause. ___ Sks-devel

Re: [Sks-devel] unplanified downtime for sks.neel.ch

2018-02-09 Thread Jeremy T. Bouse
On 2/9/2018 10:15 AM, David Néel wrote: > > Hi everybody, > > > I moved my database to a new disk 2 days ago. Since that, my database > is corrupted and I have to rebuild my database from a fresh dump. > > I'll do it in the beginning of the next week as my wedding is tomorrow :) > > Please stay

Re: [Sks-devel] [FIXED] sks.undergrid.net is out of order

2017-11-02 Thread Jeremy T. Bouse
, Jeremy T. Bouse wrote: >     It appears my cluster has outgrown it's available space and has been > causing the server to appear to bounce in and out of service. I've > stopped all containers at this point while I work out a more long term > solution and repair the database as it app

[Sks-devel] sks.undergrid.net is out of order

2017-10-14 Thread Jeremy T. Bouse
    It appears my cluster has outgrown it's available space and has been causing the server to appear to bounce in and out of service. I've stopped all containers at this point while I work out a more long term solution and repair the database as it appears to have been corrupted in the process

Re: [Sks-devel] Raising the floor for the pool to SKS version 1.1.6 [was: Re: Importing ed25519 subkeys from SKS < 1.1.6]

2017-09-06 Thread Jeremy T. Bouse
On 9/6/2017 6:33 PM, Kristian Fiskerstrand wrote: > On 09/07/2017 12:16 AM, Daniel Kahn Gillmor wrote: > 4 >> We will (temporarily) go from 116 members of the main pool to 85 -- a >> loss of about 25%. But we also provide an incentive for those members >> to upgrade to 1.1.6, so i expect we'll

Re: [Sks-devel] Blank initial DB

2017-01-22 Thread Jeremy T. Bouse
On 1/22/2017 1:09 AM, Phil Pennock wrote: > On 2017-01-22 at 00:30 -0500, Jeremy T. Bouse wrote: >> As I've been working to rebuild my cluster I've been looking to try >> and implement a CI/CD setup to test before rolling out changes... Rather >> than having to

[Sks-devel] sks.undergrid.net back online (Was: sks.undergrid.net offline)

2017-01-19 Thread Jeremy T. Bouse
On 1/18/2017 3:04 PM, Jeremy T. Bouse wrote: > On 1/17/2017 8:41 AM, Jeremy T. Bouse wrote: >> Just to inform that sks.undergrid.net cluster is offline and I'm >> working to resolve the technical issues surrounding it. It looks as >> though I will likely have to move

Re: [Sks-devel] sks.undergrid.net offline

2017-01-18 Thread Jeremy T. Bouse
On 1/17/2017 8:41 AM, Jeremy T. Bouse wrote: > Just to inform that sks.undergrid.net cluster is offline and I'm > working to resolve the technical issues surrounding it. It looks as > though I will likely have to move and rebuild the nodes before that occurs. So, ser

[Sks-devel] sks.undergrid.net offline

2017-01-17 Thread Jeremy T. Bouse
Just to inform that sks.undergrid.net cluster is offline and I'm working to resolve the technical issues surrounding it. It looks as though I will likely have to move and rebuild the nodes before that occurs. smime.p7s Description: S/MIME Cryptographic Signature

Re: [Sks-devel] SKS and containers

2016-11-18 Thread Jeremy T. Bouse
On 11/18/2016 8:09 PM, Gunnar Wolf wrote: > Jeremy T. Bouse dijo [Fri, Nov 18, 2016 at 02:29:12PM -0500]: >> I'm just curious if anyone has looked at running SKS within >> containers using Docker? I've seen a couple images on the Docker hub >> that appear to be

[Sks-devel] SKS and containers

2016-11-18 Thread Jeremy T. Bouse
I'm just curious if anyone has looked at running SKS within containers using Docker? I've seen a couple images on the Docker hub that appear to be based on Alpine Linux but was curious if anyone on here had attempted. smime.p7s Description: S/MIME Cryptographic Signature

Re: [Sks-devel] Get SKS to listen on port 80

2016-08-25 Thread Jeremy T. Bouse
On 8/25/2016 6:13 PM, Danny Horne wrote: > On 25/08/2016 11:10 pm, Jeremy T. Bouse wrote: >> Do you have Apache or Nginx running on the server? If so they're likely >> what is bound to port 80 already. >> >> > I have Nginx running on 11371 (reverse proxy), nothing

[Sks-devel] SaltStack formula for SKS deployment

2016-08-19 Thread Jeremy T. Bouse
Not entirely sure who else beside DKG on here might be running Debian for their keyserver or if anyone is making use of SaltStack to manage their servers or not, but I figured I'd put it out there for review if anyone is interested. I'm still working on the documentation but the logic is

Re: [Sks-devel] seeking peers for keyserver.flippylosaurus.eu

2016-05-26 Thread Jeremy T. Bouse
Doesn't seem strange at all if it is behind Apache or Nginx that listens on 11371... Though Apache/Nginx could be made to listen on 11371 on the public IP and SKS listen on 11371 on a private IP or loopback... that's actually what I do. On 5/26/2016 9:41 AM, Gabor Kiss wrote: >> I'm running a

[Sks-devel] Your thoughts and any objective performance data

2015-10-05 Thread Jeremy T. Bouse
Okay, so I need to rebuild the sks.undergrid.net cluster to upgrade the base OS image. I currently have the nginx and sks configuration handled via Salt so that isn't a big issue with me rebuilding from scratch. The issue is the systems have 20GB drives and the sks database is 13GB. This

Re: [Sks-devel] HKPS + ssl + nginx

2015-07-30 Thread Jeremy T. Bouse
Here is my nginx configuration that I use for my server. Obviously some of it would need to be customized and it is setup to support my 3 SKS nodes. upstream sks_servers { least_conn; server 127.0.0.1:11371; server xx.xx.xx.228:11371; server xx.xx.xx.229:11371; }

Re: [Sks-devel] HKPS certificate

2015-06-11 Thread Jeremy T. Bouse
On 5/19/2015 3:31 AM, Kiss Gabor (Bitman) wrote: [alt_names] DNS.1 = hkps.pool.sks-keyservers.net DNS.2 = *.pool.sks-keyservers.net DNS.3 = pool.sks-keyservers.net DNS.4 = keys.niif.hu This part is unnecessary, the SANs are added by me the input is discarded when generating the certificate.

[Sks-devel] Question regarding generated membership list on meta page

2015-03-14 Thread Jeremy T. Bouse
I'm curious how the generated membership file on the status meta page is created as I've been looking over it for my server and find several that are not in my membership file on my server. I know the list on the meta page is usually difficult to be accurate as it depends on which of the

Re: [Sks-devel] memory leak

2015-03-14 Thread Jeremy T. Bouse
On 14.03.2015 01:47, Kiss Gabor (Bitman) wrote: for my server, i have # max cache DB cache: 80 I have no such settings. sksconf is unchanged since Dec 17 2013. Now I add this entry. Then I listen and wait. :-) At first sight memory footprint of sks recon is drastically reduced.

Re: [Sks-devel] Cleaning up KDB directory?

2015-02-22 Thread Jeremy T. Bouse
On 19.02.2015 14:12, Jeffrey Johnson wrote: On Feb 19, 2015, at 1:48 PM, Matt Wagner wrote: Signed PGP part Hi all, I just noticed on one of my servers that the KDB directory has grown to 26GB in size, including almost 1,200 10MB log.00 files. My other server has only 600 of the log

Re: [Sks-devel] Cleaning up KDB directory?

2015-02-22 Thread Jeremy T. Bouse
On 22.02.2015 10:23, Jeffrey Johnson wrote: On Feb 22, 2015, at 10:19 AM, Jeremy T. Bouse jeremy.bo...@undergrid.net wrote: There are two approaches: 1) (automated) Add this line to DB_CONFIG (which you are using, correct?) set_flags DB_LOG_AUTOREMOVE 2) (manual) Run these commands on idle

Re: [Sks-devel] Depeering Notice

2015-02-08 Thread Jeremy T. Bouse
On 09.02.2015 01:00, Jeremy T. Bouse wrote: On 07.02.2015 02:08, Christian Felsing wrote: Hello, following peerings were removed from key.ip6.li: sks.undergrid.net pek1.sks.reimu.io reason: No crosspeering best regards Christian Felsing As you never contacted me to establish peering

Re: [Sks-devel] Upcoming maintenance for sks.undergrid.net

2014-10-17 Thread Jeremy T. Bouse
after restarting SKS. Possible memory leak? On 10/16/2014 11:48 PM, Jeremy T. Bouse wrote: While sks.undergrid.net is out of the pool currently as it appears to keep falling behind the key count for days at a time and I haven't isolated the root cause I am going through moving the hosts

Re: [Sks-devel] Upcoming maintenance for sks.undergrid.net

2014-10-16 Thread Jeremy T. Bouse
peering with me and have firewall rules set up with tight ingress control my IPv4 address will be changing as well as the addition of an IPv6 address. On 09/28/2014 01:51 PM, Jeremy T. Bouse wrote: I am currently preparing to move my sks.undergrid.net cluster to another facility within my

[Sks-devel] Debian and 1.1.5

2014-05-19 Thread Jeremy T. Bouse
Just making note that it looks like sks 1.1.5-1 was uploaded to Debian unstable/Sid today. It doesn't appear to have made it through to the wheezy BPO yet but hopefully now that unstable has 1.1.5 the BPO package should be forthcoming. signature.asc Description: OpenPGP digital

Re: [Sks-devel] Changes to sks-keyservers.net pools

2014-05-11 Thread Jeremy T. Bouse
On 05/11/2014 05:18 PM, Kristian Fiskerstrand wrote: On 05/11/2014 10:43 PM, Kristian Fiskerstrand wrote: On 05/06/2014 02:55 PM, Jeremy T. Bouse wrote: On 05/06/2014 05:08 AM, Kristian Fiskerstrand wrote: Dear lists, Following the release of SKS 1.1.5[0] the following changes will be made

Re: [Sks-devel] old certificates

2014-05-07 Thread Jeremy T. Bouse
On 04/29/2014 06:52 AM, Kiss Gabor (Bitman) wrote: sks.undergrid.net Nov 14 17:52:09 2013 GMT I ask everybody to declare if they did not use compromised version of openssl since the start of validity period of certificate. I do not believe my hosts were running

Re: [Sks-devel] Changes to sks-keyservers.net pools

2014-05-06 Thread Jeremy T. Bouse
On 05/06/2014 05:08 AM, Kristian Fiskerstrand wrote: Dear lists, Following the release of SKS 1.1.5[0] the following changes will be made to the pools of sks-keyservers.net subset.pool.sks-keyservers.net has been set to a minimum requirement of SKS 1.1.5 with immediate effect. Due to

Re: [Sks-devel] Changes to sks-keyservers.net pools

2014-05-06 Thread Jeremy T. Bouse
On 05/06/2014 05:08 AM, Kristian Fiskerstrand wrote: Dear lists, Following the release of SKS 1.1.5[0] the following changes will be made to the pools of sks-keyservers.net subset.pool.sks-keyservers.net has been set to a minimum requirement of SKS 1.1.5 with immediate effect. Due to

Re: [Sks-devel] old certificates

2014-04-29 Thread Jeremy T. Bouse
On 29.04.2014 14:07, Gabor Kiss wrote: I'm not on the list and if you connect to my server I did not. This was the command: for server in a.keyserver.pki.scientia.net key.adeti.org key.ip6.li \ keys.alderwick.co.uk keys.fedoraproject.org keys.niif.hu keys.sflc.info \

Re: [Sks-devel] Cleaning time

2014-04-29 Thread Jeremy T. Bouse
. sks.undergrid.net 11370 # Jeremy T. Bouse jeremy.bo...@undergrid.net 0x15D0A62ED01E190C signature.asc Description: OpenPGP digital signature ___ Sks-devel mailing list Sks-devel@nongnu.org https://lists.nongnu.org/mailman/listinfo/sks-devel

Re: [Sks-devel] Configuring the reverse proxy to support large keys - HTTP error 413

2014-04-28 Thread Jeremy T. Bouse
I don't know about the others on the list but my configuration follows the recommendations from https://bitbucket.org/skskeyserver/sks-keyserver/wiki/Peering which has never stated anything about this issue as long as I've been following it. Do we need to make changes to the documentation that's

Re: [Sks-devel] SKS Peering

2014-04-06 Thread Jeremy T. Bouse
I don't know what failed status you're referring to with my cluster running on sks.undergrid.net as you've certainly never made any attempt at contact, but I've gone ahead and removed you from my membership file as well. On 06.04.2014 05:19, Christian wrote: -BEGIN PGP SIGNED

[Sks-devel] Peering etiquette reminder

2014-04-06 Thread Jeremy T. Bouse
Having just spent about an hour sifting through my recon.log and trying to track down the number of unauthorized gossip attempts I was seeing I've stopped. I've already contacted a few that I was able to identify and instead just figured I'd blanket the list as it seems to be a wider issue.

Re: [Sks-devel] Peering etiquette reminder

2014-04-06 Thread Jeremy T. Bouse
tell you when a host is added or removed. In your case, keys.niif.hu was missing when I was going through the logs and I was seeing unauthorized gossip attempts and I was able to track down which host it was. I then added it: commit feb47ddab6c29dbd4618bac226b78df0f69116dd Author: Jeremy T. Bouse

Re: [Sks-devel] Peering etiquette reminder

2014-04-06 Thread Jeremy T. Bouse
On 04/06/2014 06:19 PM, David Benfell wrote: On Sun, Apr 06, 2014 at 11:37:50AM -0400, Jeremy T. Bouse wrote: Having just spent about an hour sifting through my recon.log and trying to track down the number of unauthorized gossip attempts I was seeing I've stopped. I've already contacted

Re: [Sks-devel] [SECOND NOTICE] Fate of keyserver.undergrid.net

2014-02-19 Thread Jeremy T. Bouse
11370 keyserver.serviz.fr 11370 On 02/11/2014 04:32 PM, Jeremy T. Bouse wrote: It has come to the point in cleaning up my infrastructure due to finances that I am looking to have to shutter the host that runs keyserver.undergrid.net on. The good news is that I'll be able to maintain

Re: [Sks-devel] Tuning

2014-02-11 Thread Jeremy T. Bouse
On 11.02.2014 08:38, Christian Reiß wrote: [...] Also I am using puppet to deploy the sks server. Anyone else using puppet? membership file (et all) is managed over hiera. So if we have any puppet3 users I am glad to share. Lastly, I wrote a (10 liner) php-script that queries the sks-keyserver

Re: [Sks-devel] Tuning

2014-02-11 Thread Jeremy T. Bouse
On 02/11/2014 02:19 PM, Daniel Kahn Gillmor wrote: On 02/11/2014 01:58 PM, Benny Baumann wrote: Am 11.02.2014 16:59, schrieb Kristian Fiskerstrand: Unless you run it in a clustered setup where the different members calculate it on different times and the frontend passes the request on before

[Sks-devel] Fate of keyserver.undergrid.net

2014-02-11 Thread Jeremy T. Bouse
and can respond quickly as well. I'd like to have this migration done by Monday the 24th so that I have time to backup everything on the host and shut it down before I get billed for another cycle. sks.undergrid.net # Jeremy T. Bouse jeremy.bo...@undergrid.net 0xD01E190C signature.asc Description

Re: [Sks-devel] Debian vs SKS

2013-12-16 Thread Jeremy T. Bouse
On 16.12.2013 15:09, Daniel Kahn Gillmor wrote: On 12/16/2013 02:53 PM, Teun Nijssen wrote: https://lists.debian.org/debian-release/2013/12/msg00432.html Please don't characterize this ongoing discussion as Debian vs SKS. The Debian project and the SKS project are not in conflict. Regards,

[Sks-devel] Was there a problem overnight

2013-12-06 Thread Jeremy T. Bouse
I just checked the pool status page and noticed that it was down to only a bakers dozen of hosts in the pool. Was a little disconcerting considering it was up over 60 the last time I had checked it. I also noticed that one of my hosts isn't reporting as being available on HKPS but there had

Re: [Sks-devel] Question about apache2 configuration

2013-11-20 Thread Jeremy T. Bouse
On 20.11.2013 10:56, Gabor Kiss wrote: But I had a problem. When sks was set to listen on port 11371, apache complained about listening on the same port. So I have changed the sks port to 11372 and configured Proxy to this port: VirtualHost *:80 *:11371 ServerName klucze.achjoj.info

[Sks-devel] Seeking peering for sks.undergrid.net

2013-11-14 Thread Jeremy T. Bouse
keyserver.undergrid.net, my other SKS keyserver, on November 13, 2013 and is currently peered with keyserver.undergrid.net. I see 3456086 keys loaded currently. For operational issues, please contact me directly. sks.undergrid.net 11370 # Jeremy T. Bouse jeremy.bo...@undergrid.net 0xD01E190C Regards, Jeremy T. Bouse

[Sks-devel] Replacement or Addition

2013-11-13 Thread Jeremy T. Bouse
I'm currently working on setting up a new HA cluster for my keyserver. I've got it setup using a new hostname currently (sks.undergrid.net) but I'm debating whether to simply retire my existing server (keyserver.undergrid.net) and point it at the new HA cluster or run them both. The new cluster

Re: [Sks-devel] Status flags are red

2013-10-28 Thread Jeremy T. Bouse
On 28.10.2013 12:32, Kristian Fiskerstrand wrote: On 10/28/2013 05:26 PM, Kiss Gabor (Bitman) wrote: BTW. A suggestion: yellow color could mean: SSL works but CA is other than expected. Red simply means that it is not considered for the pool, it is not in itself a status of success on the

Re: [Sks-devel] why does SKS have /dev/random open for writing?

2013-09-19 Thread Jeremy T. Bouse
Looks fine on my system and I'm running the stock 1.1.4 code. root@borkbork:~# lsof /dev/random COMMAND PIDUSER FD TYPE DEVICE SIZE/OFF NODE NAME named2617bind9r CHR1,8 0t0 7175 /dev/random java15783 chef_server6r CHR1,8 0t0 7175

[Sks-devel] seeking peers for keyserver.undergrid.net

2013-09-17 Thread Jeremy T. Bouse
16, 2013. I see 3400912 keys loaded currently. For operational issues, please contact me directly. keyserver.undergrid.net 11370 # Jeremy T. Bouse jeremy.bo...@undergrid.net 0x62DBDF62 Regards, Jeremy T. Bouse signature.asc Description: OpenPGP digital signature

[Sks-devel] seeking peers for keyserver.undergrid.net

2013-09-17 Thread Jeremy T. Bouse
http://keys.niif.hu/keydump/, dumped dated September 16, 2013. I see 3400912 keys loaded currently. For operational issues, please contact me directly. keyserver.undergrid.net 11370 # Jeremy T. Bouse jeremy.bo...@undergrid.net 0x62DBDF62 Regards, Jeremy T. Bouse -BEGIN PGP SIGNATURE