Re: Installation instructions
John Berninger <[email protected]> Sat, 1 Feb 2003 10:47:58 -0500
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
Yet again, responses to individual points inlined.
On Sat, 01 Feb 2003, Jonathan S. Shapiro wrote:
> In reading the Current installation instructions, I have a suggestion
> and a question.
>
> 1. The instructions focus on an SSL install. When testing, it is
> probably a good idea to do a non-SSL configuration first. If nothing
> else, it lets me know that Current is working before I start wrestling
> with the joys of SSL. Provided the RPMs themselves are signed, it is not
> clear that running up2date over SSL is actually important, and SSL adds
> *impressive* load to a server (we use it in OpenCM, and it's a pain).
>
> If only for testing purposes, I suggest that maybe this should be a
> separate phase of the install, accompanied by a cogent discussion of
> when/why SSL-based updates are indicated.
>
> I do understand why SSL setup is a good idea -- I'm not arguing about
> that.
SSL is an absolute requirement, even for testing. The client
has the ability to transfer package headers and packages via HTTP, but
the login information is always transferred using HTTPS. This is
because the login information can potentially contain confidential user
data, which should never be transmitted in the clear.
> 2. The instructions fail to make clear that I am actually configuring
> SSL for my entire apache server -- not just for current. It is
> *terrific* that the current install makes this an easy thing to do, but
> this needs to be broken out more clearly. I'ld hate to have some
> administrator clobber their current SSL config by following the
> directions without thinking.
Erp. Good point - I'll drop that into the issues database.
> A corollary to this is that I may have already DONE an SSL install for
> my apache config, in which case I really don't want to disrupt the keys
> I have in place. In that situation, I need instructions on how to
> produce RHNS-CS-CERT. Is it merely the CA cert that was used to produce
> the server.key/server.crt pair? I'm guessing yes. Can somebody confirm?
I'll add this to the issues database as well.
Keep the comments coming - we need comments like these last two
because we can't think of everything between just the two of us, and we
really don't want to have to dodge sharp metal pointy things thrown at
us by irate sysadmins when they follow our directions and it does
something bad. :)
--
Thank you,
John Berninger
Systems Administrator [email protected]
Department of Mathematics Box 8205, Harrelson Hall
NC State University Raleigh, NC 27695
Phone: (919)515-6315 Fax: (919)515-3798
GPG Key ID: A8C1D45C
Fingerprint: B1BB 90CB 5314 3113 CF22 66AE 822D 42A8 A8C1 D45C
--