cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: Wytze van der Raay <wytze AT cacert.org>
- To: Philipp Guehring <philipp AT cacert.org>
- Cc: CAcert System Administrators <cacert-sysadm AT lists.cacert.org>
- Subject: Re: [Visit BIT][10.08.2009]: recover non-functional signing server
- Date: Wed, 19 Aug 2009 09:51:49 +0200
- Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none
- Organization: CAcert
[directing follow-ups of this discussion tot cacert-sysadm rather than
cacert-systemlog (which should be used for logging mainly)]
On 08/19/2009 12:26 AM, Philipp Guehring wrote:
>> ...
>> 2. The startup of the CommModule process should not be hacked into the
>> Apache server startup script, but requires a proper startup script of
>> its own, including precautions against multiple starts.
>>
> Can anyone develop a proper startup script?
Yes, it's on my list of things to do. It's not hard, just needs som
close attention.
>> 3. The size of the CAcert CRLs should be monitored, and a drop in size
>> should generate an immediate alert.
>
> Hmm, just an alert, or a prevention of the update?
My thinking was an alert, but prevention of the update would possibly
be safer, except for:
> Well, seldomly, CRLs are being cleaned up. In those cases,
> update-prevention would be bad.
Is this actually possible? Does the current system ever shrink the CRL?
Or do you mean that it could be shrunk by a manual update? If so, when
would that happen?
> I am currently thinking, whether we should check the signature on the
> CRL, before we accept an updated CRL and continue distributing it.
> (instead of just checking the size)
Checking the signature sounds good to me. Something like:
openssl crl -in revoke.crl -inform der -CAfile CAcert.crt -noout
?
Regards,
-- wytze
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Re: [Visit BIT][10.08.2009]: recover non-functional signing server, Wytze van der Raay, 08/19/2009
Archive powered by MHonArc 2.6.16.