My views on clients for Lets Encrypt

To use Let's Encrypt , you need a client,as LE certificates are available only through their automatedprotocol. I can't say I've checked out all the available clients( there are a lot of them ),but here are the three that I've actively looked at and explored.I stopped exploring clients after three because these meet my needsand pretty much work the way I want.

The official Let's Encrypt client is, well,the official client. It's big


Some notes on OpenSSH's optional hostname canonicalization

As I mentioned in my entry on how your SSH keys are a potentialinformation leak , I want to stopoffering my ssh public keys to all hosts and instead only offerthem to our hosts. The fundamental reason that I wasn't doing thisalready is that I make heavy use of short hostnames, either entirelywithout a domain or with only our local subdomain (ie, hostnameslike apps0 or comps0.cs ). When you use short hostnames, OpenSSH'srelatively limited ' Host ...


Sometimes, doing a bunch of programming can be the right answer

I like doing programming, and on top of that I can be a bit obsessiveabout it; for instance, if there are obvious features for a programto have, I want to add them even if they may not be strictlynecessary. If left to myself, I would write plenty of programs forplenty of things and enjoy it a fair bit. The problem with this isthat locally written programs are often an overhead and a long termburden, as xkcd has famously pointed out . Sure, it's


Turning over a rock on some weird HTTP requests to our web server

I recently made the mistake of looking at our Apache access.log , and infact watching it live with ' tail -f '. Me being me, I can't justlet what I saw sit quietly, so now I'm here to tell you about thebig weirdness I saw. Put simply, it was a whole rapid burst ofrequests that looked like:

IP - - [28/Feb/2016:17:18:38 -050

The status of null-sender spam from outlook.com

Recently, David left a comment on my last entry on null sender spamfrom outlook.com noting that his site hadseen a stop of null sender spam from Outlook at the end of December.This made me curious about what we're seeing (and David asked, too),so I've now gone looking.

The short version is that clear null sender spam from outlook.comappears to have stopped at the end of last year (and I mean literallythe end of last year, as we


Link: A Short History Of Removable Media Behind The Iron Curtain

Pete Zaitcev 's A Short HistoryOf Removable Media Behind The Iron Curtain is a fascinating lookinto the history of (re)movable hard drives in the USSR. Apparentlythese were far more common there than they were in the west, to thepoint where it was routine to do this with what the west thoughtof as fixed hard drives. As a bonus it also includes some informationon the early history of byte order independence in Linux filesystems,which Pete Zaitcev was there for.

(I know just enough about


Sometimes brute force is the answer, Samba edition

Like many places, we have a Samba server so that users with varioussorts of laptop and desktop machines can get at their files. Forgood reason the actual storage does not try to liveon the Samba server but instead lives on our NFS fileservers . For similarly good reasons, peopledon't have separate Samba credentials; they use their regular Unixlogin and password.However, behind the scenes Samba has a separate login and passwordsystem, so we are actually creating and maintaining two accountsfor people; a Unix


Our problem with iSCSI connections at boot on OmniOS

You might perhaps wonder why I recently needed to run a scriptwhen our OmniOS machines booted . As ithappens, we sometimes have a little problem with our iSCSI networkingwhen we reboot a system, and we would like to know about it rightaway. First, the high speed summary of iSCSI on our ZFS fileservers is that fileservers connect to their iSCSIbackends over two separate and thus redundant networks. At amechanical level this is done by statically configuring each iSCSItarget disk twice, one over each network, joining them


I'm often an iterative and experimental programmer

I've been doing a significant amount of programming lately ( fora good cause ),and in the process I've been reminded that I'm often fundamentallyan iterative and explorative programmer. By this I mean that I flailaround a lot as I'm developing something.

In theory, the platonic ideal programmer plans ahead. They may notwrite more than they need now, but what they do write is consideredand carefully structured. They think about the right data structuresand code flow before they start


Mozilla, Symantec, SHA-1 certificates, and the balance of power

In theory, all CA s are supposed to havestopped issuing SHA-1 certificates on January 1st. In Payment Processors Still Using Weak Crypto ( via ),Mozilla has now announced that they will allow Symantec to issue a limitednumber of SHA-1 certificates. The reactions I've seen are reasonablyharsh . While Idon't entirely disagree, I have an additional cynical perspective that'sbased on the balance of power between CAs and browsers.

Let us be blunt here: Symantec wants to issue