/srv/irclogs.ubuntu.com/2020/07/14/#ubuntu-server.txt

=== Napsterbater_ is now known as Napsterbater
=== paride4 is now known as paride
=== ktosiek6 is now known as ktosiek
JonTheNiceGuyHi, if I was hoping to set up a simple centralised AAA system on Ubuntu for 5 Linux servers, am I best off with FreeRadius+PAM_Radius, should I look at some kind of LDAP service, or is there some other option I've missed?09:36
JonTheNiceGuyAlso, rate of change between servers is pretty low and connectivity between servers is very stable.09:36
=== frickler is now known as frickler_pto
=== frickler_pto is now known as frickler
rbasakJonTheNiceGuy: o/12:42
rbasakJonTheNiceGuy: openldap + sssd seems to be one commonly done thing if it'll work for you. No need for radius then AFAIK.12:43
JonTheNiceGuyHey rbasak12:55
JonTheNiceGuyI need to have a poke around and find more about setting up OpenLDAP then :)12:56
JonTheNiceGuyAny whitepapers or Ubuntu Wiki entries I can have a paw through?12:56
rbasakI'm not familiar with this area, sorry. I'd ask ahasenack but he's not here right now.13:03
rbasakLooks like he's out until later today13:03
JonTheNiceGuyNo worries :)13:16
=== frickler is now known as frickler_pto
=== JanC_ is now known as JanC
ahasenackJonTheNiceGuy: hi, just saw your AAA question, it really depends on who are the clients you want to authenticate. You need a common denominator, or else you will be duplicating authentication again14:45
ahasenackFreeIPA is a common solution to this on the server side, as it also gives you all the management tools you need, but I don't think it's running well on ubuntu yet, it's a fedora thing14:47
iceyjamespage: should I mark that MIR bug in-progress, new, or something else?15:14
jamespageinprogress and assign it to yourself while you're prepping for the MIR15:53
jamespagethen set back to new and assign to ubuntu-mir when what's in ubuntu is ready for review15:53
=== coconut_ is now known as coconut
JonTheNiceGuyThanks "ahasenack" (https://matrix.to/#/@freenode_ahasenack:matrix.org)  that's the worry I have. I've basically got 5 admins and about 25 users. It's the sort of thing I could (Ansible|puppet|chef|bash) but I'd rather do it "better"...16:30
ahasenackJonTheNiceGuy: well, start with all the things you want to authenticate (user login, ssh, windows login, some webapp you have, etc), and find a common denominator amongst them, and throw in security requirements17:06
RoyKldap+kerberos17:06
RoyKAD should work17:07
RoyK:)17:07
JonTheNiceGuy"RoyK" (https://matrix.to/#/@freenode_RoyK:matrix.org) joke.popey.com :)18:21
JonTheNiceGuyOh, it doesn't do the sounds any more :(18:21
kevindankHello, im having firewall issues i believe.  Ive issued an SSL certificcate for my wordpress install running on ubuntu, but when i try to curl it it shows 443 connection refused18:59
kevindankI allowed port 44318:59
kevindankwhen i do ufw verbose it shows 443 as allow19:00
=== tds2 is now known as tds
sarnoldkevindank: do you need to modify security groups or other cloud-provided firewalling?19:04
kevindanksarnold: I don't believe so19:17
kevindanksite is ledwell.com19:18
ahasenackdo you have something listening on port 443?19:24
kevindankYes, i setup a listener through the openlitespeed control panel to set 443 to any ip address19:31
kevindankset it to secure19:31
kevindanki used certbot for the certificate, so i set the paths and then set chained certificate to yes19:34
sarnolddoes ss -ntlp show your server listening on the correct port and address?19:35
kevindankI dont see 443 in that list19:36
sarnoldaha :) figure out which program should be listening to that port and make it see things your way :)19:36
kevindanki think i may have figured it ut19:40
kevindankunder protocal i needed to check off ssl 3.0  and tls 1.319:41
kevindankrebooted after that and it seems to work but i cant get to my wp-admin panel now19:41
kevindankactually, now its giving me a 404 for the domain also19:41
sarnold"check off ssl 3.0 and tls 1.3" -- I'm confused and worried what this means19:42
kevindanktheres an area when you setup the ssl certificate paths, that says protocal and inside there you have to enable ssl3 and tls19:45
kevindankbut now that ive done that by site is displaying a 404 and not my wordpress install which i still see on the http only version19:45
kevindanklike its almost like it doesnt recognize that it needs to display the wordpress install19:55
kevindankbut its using the same vhost as the non ssl version19:55
sarnoldunless you've got something crazy going on, you don't want ssl3, tls1, tls1.119:58
sarnolda lot of people like mozilla's recommendations for tls configuration https://wiki.mozilla.org/Security/Server_Side_TLS19:59
=== halvors1 is now known as halvors

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!