[Users] SSL in cloned VEs

2009-07-09 Thread Greg
Hi, I'm currently creating a debian based VE for my site web services and i'm planning to duplicate on 2 other servers. Usually with real servers we need to install seperately on each server and get the SSL info for each. How does it work with VEs. If I install it on the VE before cloning, will i

[Users] Firewall on HN or VE?

2009-07-09 Thread Greg
Hi, On one server setup with proxmox i intent to have 4 VE (web, dns, mysql, mail). I guess i'll have 1 IP for each VE. Concerning the firewall i'm thinking of configuring iptables but my concern is to do it on HN or on each VE. I'm looking for best way to do it so your ideas are more than welc

Re: [Users] SSL in cloned VEs

2009-07-09 Thread Gregor at HostGIS
How does it work with VEs. If I install it on the VE before cloning, will it work on the clone directly or will i need to reissue certificate for each clone. An invalid SSL certificate, even a self-signed or expired one, will still "work" as far as encrypting data. If you're talking internal u

Re: [Users] SSL in cloned VEs

2009-07-09 Thread John Drescher
On Thu, Jul 9, 2009 at 4:23 PM, Greg wrote: > Hi, > I'm currently creating a debian based VE for my site web services and i'm > planning to duplicate on 2 other servers. Usually with real servers we need > to install seperately on each server and get the SSL info for each. How does > it work with V

Re: [Users] Firewall on HN or VE?

2009-07-09 Thread Gregor at HostGIS
We do the firewall confguration on the HN, not in the VE. This keeps it safely out of the customers' hands and in our centralized control. By "safely out of their hands" I mean not only the customers' inexpertise, but also accidental deletion/chmoding of the firewall script in their VE, or a h

[Users] Re: Firewall on HN or VE?

2009-07-09 Thread Suno Ano
Greg> Hi, On one server setup with proxmox i intent to have 4 VE (web, Greg> dns, mysql, mail). I guess i'll have 1 IP for each VE. Concerning Greg> the firewall i'm thinking of configuring iptables but my concern Greg> is to do it on HN or on each VE. I'm looking for best way to do Greg> it

Re: [Users] Firewall on HN or VE?

2009-07-09 Thread Roberto Mello
On Thu, Jul 9, 2009 at 4:29 PM, Greg wrote: > Hi, > On one server setup with proxmox i intent to have 4 VE (web, > dns, mysql, mail). I guess i'll have 1 IP for each VE. Concerning the > firewall i'm thinking of configuring iptables but my concern is to do it on > HN or on each VE. I'm looking

[Users] Re: SSL in cloned VEs

2009-07-09 Thread Suno Ano
you say webservices and SSL (Secure Sockets Layer) so I guess you want to do websites i.e. https for example yes? If so, then the cloning will give you a working clone instantly. However, you need to have wildcard certs (e.g. *.example.com which would match www.example.com, mail.example.com, wiki.