lwood: (wizpod)
lwood ([personal profile] lwood) wrote2006-01-11 06:07 pm
Entry tags:

lorien update -- updated and bumped throughout the day

IMPORTANT! AFFECTS ALL MY USERS!
11 Jan 06 1807 PST:

Had to wrassle OpenSSL to the ground in order to generate keys that said mail.snugharbor.com instead of lorien.snugharbor.com. All e-mail users should enable encryption, but not encrypted authentication, with their POP and/or IMAP services, and should be using mail.snugharbor.com as their incoming and outgoing mail servers, regardless of what domain they use to get their mail. If you need help reconfiguring your mail client, reply here or e-mail me.


11 Jan 06, 1618 PST:

New SMTP authorization via SASL and/or TLS is in place. This means you can configure your mail reader to use authentication and/or encryption to send mail, and it will send things out -- this augments the pop-before-smtp that we were using before that sent passwords in the clear. Did I mention that was bad? 'cos it is.

11 Jan 06, 1330 PST:

Name service is back -- when it wasn't up, mail receipt would have been a bit peculiar, and not worked at all for the mailing lists.

Consequently -- mailing lists are back! Yay!

Next target: web services, including web pages, photo galleries, and webmail.

For those of you who ssh and ftp (if you don't know what they are, you don't care), they're up. The ssh keys have changed, of course, so calm your worried little clients down if they spaz.

11 Jan 06, 1140 PST:

Part of the gyrations that we've gone through means that we now accept... drumroll... Secure IMAP and POP! This means your password need no longer be sent in the clear across the net, that your e-mail will have a harder time being intercepted in transport by nogoodniks, and general privacy prevails. Indeed, non-encrypted IMAP is throwing odd errors and doesn't work; please consider reconfiguring your mail client appropriately if you would like to take advantage of encryption in your e-mail while I work on the plain stuff some more (which you shouldn't use).

As for outgoing e-mail, pop-before-smtp authentication "should" be working as of this update. Please advise if you use me for your outgoing mail server and it used to work, but now is not.

11 Jan 06, 1132 PST:

We are now receiving mail! You may or may not be able to pick it up yet, but it's hitting mailboxes, which means no more mail will be lost--some, from reports, was. Next is to debug POP and IMAP handling.

11 Jan 06, 0251 PST:

Okay, after a lot of fussing about partition sizes, I got lorien to boot with a new OS. After some well-deserved sleep, I get to install apache and postfix... MY WAY. That's tomorrow's Fun and Excitement.

User data came through fine, but it's still unavailable.

As for e-mail, it's supposed to be being queued up on my backup MX host, but this may not have been done successfully. I'm just as screwed as any of the rest of you, and just as pissed about it not working perfectly...

My deepest apologies for all the inconvenience my error has caused. A drink on me, when next we meet!

-- Lorrie, currently playing Sibelius to her Linux server in hopes to awaken its folksoul or summat.

[identity profile] cadhla.livejournal.com 2006-01-11 03:19 pm (UTC)(link)
Query for you: is the lack of user data the reason I can't log in, or did something else go flooey?

[identity profile] lwood.livejournal.com 2006-01-11 05:20 pm (UTC)(link)
The whole machine had to be rebuilt because I blew it up real good. You won't be able to log in until I reconstruct more of how the system interacts with the (intact, safe) user data.

-- Lorrie

[identity profile] cadhla.livejournal.com 2006-01-11 11:28 pm (UTC)(link)
No snitties here, just curiousity.

I can log in now, but still in TF. Do I need to reinstall that, or will it be recovered?

[identity profile] lwood.livejournal.com 2006-01-12 12:28 am (UTC)(link)
Just installed tinyfugue system-wide for you. Enjoy!

-- Lorrie

[identity profile] dasubergeek.livejournal.com 2006-01-11 05:43 pm (UTC)(link)
Hm. I think I'm going to have a loud snit-fit over the unavailability of a service I don't pay any money for, that's given to me out of friendship and the goodness of your heart. Not so much, no.

Which reminds me, call me and tell me where you want lunch from today and I'll conference you in and pay for it. :)

[identity profile] lwood.livejournal.com 2006-01-11 06:31 pm (UTC)(link)
Well, one of the few people who actually does pay mentioned in her journal that she'd probably move over this, but I don't blame her for that in the slightest.

Lunch? Wha?

-- Lorrie
ardaniel: photo of Ard in her green hat (Default)

[personal profile] ardaniel 2006-01-11 10:05 pm (UTC)(link)
I think he means "call him and tell him where you want lunch from, he'll call the place and have it paid for."

[identity profile] lwood.livejournal.com 2006-01-12 02:08 am (UTC)(link)
Bother, I'd already had soup.

-- Lorrie

[identity profile] dasubergeek.livejournal.com 2006-01-12 04:09 am (UTC)(link)
[livejournal.com profile] ardaniel has it right. Call me tomorrow at the appropriate time...

Looking forward to more updates, like "SquirrelMail is working again"... I actually had to do WORK today during the Teleconference of Extreme Boredom.

[identity profile] lwood.livejournal.com 2006-01-12 07:28 am (UTC)(link)
Much apologizings! Need to make modssl, apache, php, and squirrelmail itself go to pull that off -- got as far as partway through modssl before I had to leave. More Thursday!

-- Lorrie

Just FYI

[identity profile] mendou.livejournal.com 2006-01-12 03:44 am (UTC)(link)
I seem to be getting a bunch of spam that I wasn't before. I've been junk-mailing it through Outlook but that doesn't seem to be working.

Take care.
M

Re: Just FYI

[identity profile] lwood.livejournal.com 2006-01-12 07:29 am (UTC)(link)
Yes -- SpamAssassin isn't working right now, and I haven't had time to debug. Needed to make sure that everyone's mail was getting here, and getting to them, then work on making sure info is available to the world at large, and then I bring the ninjas back out...

Sorry about that. The problem is that it all has to be done yesterday, so I have to work out an order.

-- Lorrie

[identity profile] bellacrow.livejournal.com 2006-01-12 08:07 am (UTC)(link)
is there an eta on when this - https://webmail.nerdalfheim.org/src/login.php is back?

Check checking, not meaning to be pushy!

[identity profile] emberleo.livejournal.com 2006-01-13 02:49 am (UTC)(link)
Yeah, that's the bit that I'm interested in as well.

Again jumping on the bandwagon of "not about to look a gift-horse in the mouth, just wanting to know what's up".

If I'd realized webmail would be down for long, I would have temporarily moved a couple of lists to my gmail account, for a couple things that are time sensitive.

The rest can wait as long as I can pick it up this month, as long as the messages aren't still being lost.

--Ember--

[identity profile] lwood.livejournal.com 2006-01-15 12:33 am (UTC)(link)
Sorry about that, but it's all back and error-free now; the lingering error on send was due to an underlying PHP upgrade that the squirrelmail version running atop it didn't know how to handle. This has now been Fixed.

-- Lorrie

[identity profile] lwood.livejournal.com 2006-01-15 12:32 am (UTC)(link)
Not only back, but with a kicky new logo. 8-)

-- Lorrie

[identity profile] sidewinder.livejournal.com 2006-01-12 01:22 pm (UTC)(link)
For those of you who ssh and ftp (if you don't know what they are, you don't care), they're up. The ssh keys have changed, of course, so calm your worried little clients down if they spaz.

I'm getting password-incorrect errors on my FTP and email for my 3 domains (sockiipress, spacial-anomaly, johnglover.info) still...should I just assume they're down still, or is it something I need to change on my end? (I have no idea how to enable encryption on Mac's Mail program...) I use Transmit for ftp.

[identity profile] lwood.livejournal.com 2006-01-15 12:39 am (UTC)(link)
ftp should work, encrypting your POP with Mail.app works something like this:

Under the Mail menu, select Preferences. In the window that appears, select "Accounts" (the white @ on a blue background).

Click the e-mail account you want to twiddle from the choices at the left.

Just right of center, there are three buttons: Account Information, Special Mailboxes, and Advanced.

Click on "Account Information" and change your Incoming Mail Server to mail.snugharbor.com.

Now click on "Advanced". Just below center on this window, you'll see Port: (which should be 110 at the moment) a checkbox saying "Use SSL", and a dropdown of various authentication methods.

Check the "Use SSL" box. The 110 should automagically change to a 995. If you are using IMAP instead of POP, the port values will be different but will still change when you check that box. Authentication: should be Password, if it isn't already.

That should fix it -- if not, let me know!

-- Lorrie

[identity profile] sidewinder.livejournal.com 2006-01-15 01:18 pm (UTC)(link)
Thanks! That seems to be working now (so is FTP).

[identity profile] lwood.livejournal.com 2006-01-16 06:21 pm (UTC)(link)
Groovalicious!

-- Lorrie

eudora help

[identity profile] bellacrow.livejournal.com 2006-01-16 06:37 am (UTC)(link)
Hola!

I get this error message - Cert Chain not trusted, Try adding this cert to your cert database for SSL to succeed. Cert Error: Unknown and unprovuded root cert Cert bad:

What do I need to change or tick off?

thank you!

Re: eudora help

[identity profile] lwood.livejournal.com 2006-01-16 06:24 pm (UTC)(link)
Your problem here is that Eudora is doing all right at the protocol, but as I don't have stupid amounts of money to spend on an Officially Signed SSL Certificate, I had to sign mine myself. Nobody trusts that, so you have to explain things to Eudora. This page (http://support.tigertech.net/eudora-cert) should have the info you need, except for the part where upgrading Eudora won't do you any good.

-- Lorrie

Re: eudora help

[identity profile] bellacrow.livejournal.com 2006-01-16 08:08 pm (UTC)(link)
danke! I have a paid 5.2 something version, and it wasnt quite in where they said it was but I found it!!! Yay!

now to debate upgrading.