Re: Installation instructions

Hunter Matthews <[email protected]> 02 Feb 2003 16:49:25 -0500
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
On Sat, 2003-02-01 at 10:42, Jonathan S. Shapiro wrote:
> In reading the Current installation instructions, I have a suggestion
> and a question.
> 
> 1. The instructions focus on an SSL install. When testing, it is
> probably a good idea to do a non-SSL configuration first. If nothing
> else, it lets me know that Current is working before I start wrestling
> with the joys of SSL. Provided the RPMs themselves are signed, it is not
> clear that running up2date over SSL is actually important, and SSL adds
> *impressive* load to a server (we use it in OpenCM, and it's a pain).

This is not under current's control - thats governed by how the client
is designed, and I'm utterly unwilling to debug client problems caused
by not following the assumptions built into it.

Yes, sometimes getting SSL right is a pain. There's nothing for it but
clearer docs. I _SERIOUSLY_ doubt Red Hat is going to even test the
client for completely un-ssl'd operation.

> 
> If only for testing purposes, I suggest that maybe this should be a
> separate phase of the install, accompanied by a cogent discussion of
> when/why SSL-based updates are indicated.

When/why SSL'd package and header transfers might indeed be a good idea.
John?

When/why to create an SSL setup for current at all? Do that at the
beginning, in the order we spec'd - otherwise the client may not like
it, and I'm not debugging that.

> 
> I do understand why SSL setup is a good idea -- I'm not arguing about
> that.
> 
> 2. The instructions fail to make clear that I am actually configuring
> SSL for my entire apache server -- not just for current. It is
> *terrific* that the current install makes this an easy thing to do, but
> this needs to be broken out more clearly. I'ld hate to have some
> administrator clobber their current SSL config by following the
> directions without thinking.
>

Bug, discussed by John and I and we agree. This will be fixed in the
next rev of docs.

 
> A corollary to this is that I may have already DONE an SSL install for
> my apache config, in which case I really don't want to disrupt the keys
> I have in place. In that situation, I need instructions on how to
> produce RHNS-CS-CERT. Is it merely the CA cert that was used to produce
> the server.key/server.crt pair? I'm guessing yes. Can somebody confirm?

Its simple. Let us test that however, and we'll add that to the docs as
well. ( we agree here that this is a bug with the docs)

 
-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.