|
|
@853
|
16 years |
andersk |
Put the children out of their misery.
|
|
|
@847
|
16 years |
andersk |
Run munin as an unprivileged user with sudo for root access when necessary
|
|
|
@845
|
16 years |
andersk |
Use the local LDAP server (as is already the case on both servers).
|
|
|
@842
|
16 years |
andersk |
Run php directly from suexec, so php scripts don’t need to be executable.
|
|
|
@841
|
16 years |
geofft |
[help.mit.edu #694790]
|
|
|
@831
|
16 years |
andersk |
MaxRequestsPerChild < Ridiculous
|
|
|
@829
|
16 years |
geofft |
Debathena's reasoning seems sound enough. Add fuse_allow_other, which ...
|
|
|
@822
|
16 years |
geofft |
OM NOM NOM NOM CERTIFICATES
|
|
|
@821
|
16 years |
geofft |
I'm stupid.
|
|
|
@820
|
16 years |
geofft |
Add server certS for random-hall.mit.edu and mitsoc.mit.edu
|
|
|
@817
|
16 years |
geofft |
Added code to zephyr on OOM kills.
Also commented out a change by ...
|
|
|
@814
|
16 years |
geofft |
As Anders would say...
|
|
|
@813
|
16 years |
geofft |
This looks useful too
|
|
|
@811
|
16 years |
quentin |
Add localhost to the list of scripts names
|
|
|
@808
|
16 years |
geofft |
Probably a useful file to have.
|
|
|
@807
|
16 years |
quentin |
Add routes for sql via eth1
|
|
|
@804
|
16 years |
andersk |
We don't actually have a deb.gif.
|
|
|
@802
|
16 years |
andersk |
Allow a directory index of /__scripts/icons.
|
|
|
@801
|
16 years |
geofft |
/etc: Add pki/tls/certs/*.pem to the repository.
|
|
|
@799
|
16 years |
geofft |
Uncommitted changes from o-f: reboot on kernel panic (do we actually ...
|
|
|
@794
|
16 years |
quentin |
Update sudoers based on F9 template
|
|
|
@792
|
16 years |
quentin |
We don't share /tmp (eeew)
|
|
|
@791
|
16 years |
quentin |
Add bees-knees and cats-whiskers to /etc/hosts
|
|
|
@790
|
16 years |
geofft |
Oops, missed scripts-test's IP.
|
|
|
@789
|
16 years |
geofft |
Update names for scripts[1-4]
|
|
|
@787
|
16 years |
geofft |
Fix some stuff about our iptables rules, including:
- Remove ACCEPT ...
|
|
|
@784
|
16 years |
quentin |
Use explicit recipients for non-root log messages
|
|
|
@783
|
16 years |
geofft |
Make d_zroot.pl zephyr people in the .k5login in personals
|
|
|
@781
|
16 years |
quentin |
munin needs to start as root so it can setuid to run the script; it ...
|
|
|
@780
|
16 years |
geofft |
Munin should not run as root.
Remove munin's htpasswd file, since it's ...
|
|
|
@779
|
16 years |
geofft |
mod_status is a serious privacy violation.
|
|
|
@778
|
16 years |
geofft |
This list is a little better
|
|
|
@777
|
16 years |
geofft |
Add more sysnames to differentiate between OS releases, and add the ...
|
|
|
@775
|
16 years |
geofft |
Version nscd.conf, and reduce the negative TTL to 5 seconds to solve ...
|
|
|
@770
|
17 years |
quentin |
Stop more spew; parse ssh keys and identify the used key when ...
|
|
|
@768
|
17 years |
geofft |
Commented out scripts-spew. It is inappropriate to send syslogs about ...
|
|
|
@759
|
17 years |
quentin |
Tweak httpd settings
|
|
|
@758
|
17 years |
quentin |
Avoid spew in cases of serious error
|
|
|
@757
|
17 years |
quentin |
Add AFS monitoring to Nagios
|
|
|
@755
|
17 years |
andersk |
Oops, missed a spot.
|
|
|
@754
|
17 years |
andersk |
Use the scripts private key for *.scripts as well (the previous ...
|
|
|
@751
|
17 years |
andersk |
Configure nsswitch.conf to use nss_nonlocal.
|
|
|
@749
|
17 years |
andersk |
Nope. Don't care.
|
|
|
@740
|
17 years |
andersk |
Update SSL configuration directives from Fedora's ssl.conf. Notably, ...
|
|
|
@739
|
17 years |
andersk |
spew--
|
|
|
@738
|
17 years |
andersk |
SHUT. THE. FUCK. UP.
|
|
|
@734
|
17 years |
andersk |
Turn on KeepAlive for SSL and increase timeouts, to avoid pathological ...
|
|
|
@715
|
17 years |
quentin |
Allow syn to access nrpe through iptables
|
|
|
@712
|
17 years |
quentin |
Allow syn to monitor scripts
|
|
|
@708
|
17 years |
geofft |
Add rebecca to sudoers.
|
|
|
@707
|
17 years |
andersk |
This sucker has had it coming for a long time.
|
|
|
@690
|
17 years |
quentin |
Ignore more syslog messages
|
|
|
@687
|
17 years |
andersk |
We might as well present the *.scripts.mit.edu certificate for ...
|
|
|
@682
|
17 years |
andersk |
Revert r681; this doesn't actually work.
|
|
|
@681
|
17 years |
andersk |
Drop to nobody in case of a terrible mod_vhost_ldap disaster.
|
|
|
@677
|
17 years |
andersk |
Remove hacks-old.
|
|
|
@671
|
17 years |
quentin |
Remove broken configuration for deprecated mime_magic module, as we ...
|
|
|
@669
|
17 years |
geofft |
disable X11 forwarding; allow forwarding $EDITOR and $VISUAL because ...
|
|
|
@668
|
17 years |
quentin |
Ignore more meaningless sshd logs
|
|
|
@667
|
17 years |
quentin |
Don't log logins from non-root users
|
|
|
@666
|
17 years |
quentin |
Change syslog zephyring to coalesce messages
|
|
|
@665
|
17 years |
quentin |
Make Zephyrs more useful and move to -c scripts-auto
|
|
|
@664
|
17 years |
andersk |
-c scripts -> -c scripts-auto.
|
|
|
@662
|
17 years |
quentin |
Save log and pid in the right places
|
|
|
@661
|
17 years |
quentin |
Run whoisd on startup
|
|
|
@657
|
17 years |
quentin |
Run if_ plugin as root so it can determine the interface speed
|
|
|
@656
|
17 years |
andersk |
And finally the vhosts directory is unused.
|
|
|
@653
|
17 years |
andersk |
Convert framewrapper vhosts to real vhosts in LDAP.
|
|
|
@649
|
17 years |
presbrey |
httpd.conf: configure SNI support for *:444
|
|
|
@648
|
17 years |
presbrey |
httpd.conf: configure SNI support
|
|
|
@646
|
17 years |
quentin |
Send to host-specific instance, and send for both root and logview
|
|
|
@645
|
17 years |
quentin |
syslog-ng configuration for zephyring when root logs in
|
|
|
@644
|
17 years |
quentin |
Remove overrides of session.save_path and include_path (old ...
|
|
|
@643
|
17 years |
quentin |
Commit outstanding change allowing ldap backups
|
|
|
@642
|
17 years |
andersk |
Only check .htaccess files inside web_scripts, thus eliminating a past ...
|
|
|
@635
|
17 years |
andersk |
Enable mod_expires.
|
|
|
@624
|
17 years |
quentin |
Allow monitoring by syn.mit.edu
|
|
|
@623
|
17 years |
quentin |
Move the heartbeat script to /__scripts/heartbeat so we can serve it ...
|
|
|
@607
|
17 years |
quentin |
Add a second NTP server, for good measure.
|
|
|
@605
|
17 years |
andersk |
blah blah APACHE HAS NO GODDAMN ABSTRACTION BARRIERS blah blah blah.
|
|
|
@604
|
17 years |
andersk |
Prevent vhost access controls from applying to /__scripts.
|
|
|
@603
|
17 years |
andersk |
Modularize the redirect-to-certs kludge so that users just need to say ...
|
|
|
@602
|
17 years |
andersk |
/icons -> /__scripts/icons to avoid shadowing vhost namespace.
|
|
|
@584
|
17 years |
quentin |
Support hacks.mit.edu
|
|
|
@583
|
17 years |
geofft |
oops, webmaster@szs is a special case
|
|
|
@566
|
17 years |
geofft |
webzephyr IP address
|
|
|
@556
|
17 years |
geofft |
Postfix changes for webzephyr
|
|
|
@548
|
17 years |
geofft |
i can has root@scripts?
|
|
|
@520
|
17 years |
andersk |
Enable mod_negotiation.
|
|
|
@512
|
17 years |
andersk |
Use ldapi:// url.
|
|
|
@511
|
17 years |
andersk |
Re-enable sendfile now that it works.
|
|
|
@509
|
17 years |
andersk |
Apparently sendfile() breaks with kernel 2.6.23 and openafs 1.4.5.
|
|
|
@503
|
17 years |
quentin |
Add smart monitoring to munin
|
|
|
@500
|
17 years |
andersk |
Add b-m and o-f aliases.
|
|
|
@493
|
17 years |
andersk |
Make 127.0.0.1 work, for Munin monitoring.
|
|
|
@487
|
17 years |
andersk |
Not used anymore.
|
|
|
@486
|
17 years |
andersk |
Oops, clean up a few things from r484.
|
|
|
@484
|
17 years |
andersk |
/etc/ldap.conf.
|
|
|
@482
|
17 years |
andersk |
ou=vhosts -> ou=VirtualHosts.
|
|
|
@478
|
17 years |
geofft |
more ldap chocolatey goodness
|
|
|