[debian-edu-commits] [Git][debian-edu/debian-edu-config][personal/sunweaver/exim4-log-to-syslog] 7 commits: share/debian-edu-config/tools/run-at-firstboot: Add an environment check to...

Mike Gabriel (@sunweaver) gitlab at salsa.debian.org
Fri Sep 4 22:27:19 BST 2026



Mike Gabriel pushed to branch personal/sunweaver/exim4-log-to-syslog at Debian Edu / debian-edu-config


Commits:
c2ba0299 by Serhii Horichenko at 2026-09-04T19:26:12+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an environment check to avoid starting the image creation on an LTSP-client (Closes: #1092123).

- - - - -
8b5765b6 by Serhii Horichenko at 2026-09-04T19:40:06+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an ability to create a Diskless Workstation chroot and separate the creation of an image on an LTSP-server without the Main-Server role (Closes: #1092123).

- - - - -
1b3d05e6 by Mike Gabriel at 2026-09-04T21:24:53+00:00
sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).

- - - - -
18d340a3 by Mike Gabriel at 2026-09-04T21:26:05+00:00
share/debian-edu-config/tools/kerberos-kdc-init: Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes: #1052962).

- - - - -
a3082be9 by Mike Gabriel at 2026-09-04T21:26:19+00:00
Stop using killer script in Debian Edu. (Closes: #703710).

- - - - -
b03fe98b by Mike Gabriel at 2026-09-04T21:26:55+00:00
cf3/cf.ldapclient: Ensure empty file /etc/netgroup exists. (Closes: #1146398).

- - - - -
476a3853 by Mike Gabriel at 2026-09-04T21:27:14+00:00
exim4/exim-ldap-{server,client}-v4.conf: Write logs to syslog. (Closes: #1051836).

- - - - -


10 changed files:

- Makefile
- cf3/cf.ldapclient
- cf3/cf.workarounds
- etc/exim4/exim-ldap-client-v4.conf
- etc/exim4/exim-ldap-server-v4.conf
- sbin/debian-edu-ltsp-install
- − share/debian-edu-config/killer.cron
- share/debian-edu-config/tools/kerberos-kdc-init
- share/debian-edu-config/tools/run-at-firstboot
- share/debian-edu-config/tools/setup-roaming


Changes:

=====================================
Makefile
=====================================
@@ -289,7 +289,6 @@ install: install-testsuite
 	set -e ; for f in \
 		share/debian-edu-config/d-i/finish-install \
 		share/debian-edu-config/d-i/pre-pkgsel \
-		share/debian-edu-config/killer.cron \
 		share/debian-edu-config/tools/passwd \
 		share/debian-edu-config/tools/clean-up-host-keytabs \
 		share/debian-edu-config/tools/create-debian-edu-certs \


=====================================
cf3/cf.ldapclient
=====================================
@@ -41,6 +41,10 @@ files:
 
     "/etc/nsswitch.conf"
       edit_line => nsswitch_conf;
+
+  debian.installation::
+      "/etc/netgroup" create => "true";
+
 }
 
 bundle edit_line nsswitch_conf


=====================================
cf3/cf.workarounds
=====================================
@@ -15,13 +15,4 @@ files:
 
     "$(gosa_file)"
       create => "true";
-
-  debian.ltspserver.installation::
-
-    "/etc/cron.hourly/killer"
-      delete => tidy;
-
-    "/etc/cron.hourly/killer"
-      copy_from => local_cp("/usr/share/debian-edu-config/killer.cron"),
-      perms => mog("755","root","root");
 }


=====================================
etc/exim4/exim-ldap-client-v4.conf
=====================================
@@ -17,6 +17,9 @@ LOCALHOST = 127.0.0.1/8
 # constant warning messages in the log file
 keep_environment =
 
+# Send log messages to syslog
+log_file_path = syslog
+
 # These options specify the Access Control Lists (ACLs) that
 # are used for incoming SMTP messages - after the RCPT and DATA
 # commands, respectively.


=====================================
etc/exim4/exim-ldap-server-v4.conf
=====================================
@@ -17,6 +17,9 @@
 # from 'check_local_user' directive instead.
 # -- Wolfgang Schweer <wschweer at arcor.de>, 2020-06-27.
 
+# Send log messages to syslog
+log_file_path = syslog
+
 ##
 keep_environment = KRB5_KTNAME : PWD : ^LDAP
 tls_advertise_hosts = *


=====================================
sbin/debian-edu-ltsp-install
=====================================
@@ -607,11 +607,15 @@ EOF
 	rm -f /etc/resolv.conf
 	echo "nameserver $dns_server" > /etc/resolv.conf
 	echo "search intern" >> /etc/resolv.conf
+	# Temporary workaround needed to turn DLW images into machines of profile type 'Workstation'
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"Workstation\"/g"
 	# Create SqashFS image.
 	ltsp image /,,/boot,subdir=boot,,/usr,subdir=usr,,/var,subdir=var
 	# Revert resolver workaround from above.
 	rm -f /etc/resolv.conf
 	ln -s /run/resolvconf/resolv.conf /etc/resolv.conf
+	# Revert temporary change to PROFILE in /etc/debian-edu/config
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"${PROFILE}\"/g"
 	# next modification avoids ltsp command error if lot of images are available.
 	ALL_IMAGES=1 ltsp kernel
 	ltsp initrd
@@ -675,7 +679,7 @@ EOF
 	chroot /srv/ltsp/dlw apt-get install -y -qq apt-utils ltsp
 
 	# Turn system into a Debian Edu workstation.
-	chroot /srv/ltsp/dlw sh -c "DESKTOP=$desktop /sbin/debian-edu-bless"
+	chroot /srv/ltsp/dlw sh -c "PROFILE=Workstation DESKTOP=$desktop /sbin/debian-edu-bless"
 	mkdir -p /srv/ltsp/dlw/skole
 	chmod 755 /srv/ltsp/dlw/skole
 	rm -f /srv/ltsp/dlw/etc/resolv.conf


=====================================
share/debian-edu-config/killer.cron deleted
=====================================
@@ -1,3 +0,0 @@
-#!/bin/sh
-
-if [ "$(ps aux | grep sshd: | grep @notty)" = "" ] && [ -x /usr/sbin/killer ] ; then /usr/sbin/killer; fi


=====================================
share/debian-edu-config/tools/kerberos-kdc-init
=====================================
@@ -173,7 +173,6 @@ mit_kerberos_kdc() {
         kdc_ports = 750,88
         max_life = 10h 0m 0s
         max_renewable_life = 7d 0h 0m 0s
-        master_key_type = des3-hmac-sha1
         default_principal_flags = +preauth
     }
 EOF


=====================================
share/debian-edu-config/tools/run-at-firstboot
=====================================
@@ -26,6 +26,14 @@ at_exit() {
 	error "script $0 terminated unexpectedly."
 }
 disable_exception() { trap - INT TERM EXIT; }
+is_ltsp_client() {
+        if grep -q "initrd=ltsp.img" < /proc/cmdline; then
+                return 0
+        else
+                return 1
+        fi
+}
+
 trap at_exit INT TERM EXIT
 
 info "Executing run-at-firstboot script."
@@ -62,9 +70,23 @@ fi
 # information from some daemons isn't available during installation. It's done
 # for a combined server but not for a separate LTSP server because the image
 # needs to include the krb5.keytab file which isn't available at this time.
-if echo "$PROFILE" | grep -Eq 'Main-Server.*LTSP-Server' && \
-	[ ! -f /srv/ltsp/images/$ltspimg ] ; then
-	/usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+if ! is_ltsp_client; then
+	# If this runs on a combi server (Main-Server + LTSP-Server), create
+	# Diskless Workstation chroot from scratch as clean environment.
+	if echo "$PROFILE" | grep -Eq 'Main-Server' && \
+		echo "$PROFILE" | grep -Eq 'LTSP-Server'; then
+			if [ ! -d /srv/ltsp/dlw ]; then
+				/usr/sbin/debian-edu-ltsp-install --dlw yes
+			fi
+	# else if this runs on a pure LTSP-Server (no Main-Server role), then
+	# let's use the file system of the LTSP-Server and generate the LTSP
+	# image directly from it (faster!).
+	elif echo "$PROFILE" | grep -Eqv 'Main-Server' && \
+		echo "$PROFILE" | grep -Eq  'LTSP-Server'; then
+			if [ ! -f /srv/ltsp/images/$ltspimg ] ; then
+					/usr/sbin/debian-edu-ltsp-install --diskless_workstation yes
+			fi
+	fi
 fi
 
 # Update PXE setup on LTSP servers with proxy values set in environment


=====================================
share/debian-edu-config/tools/setup-roaming
=====================================
@@ -27,10 +27,6 @@ apt-get purge -y libpam-krb5
 # Avoid double caching, as sssd is already caching
 apt-get purge -y nscd
 
-# Roaming workstations are typically single user machines, so do not
-# throw out the user if he is idle.
-apt-get purge -y killer
-
 # try to configure sssd dynamically, fall back to default setup if
 # generation fail
 # sssd refuses to read the sssd.conf file unless it is 0600 root:root



View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/658e7ed4be70a3c44c2c4c1a9a813ef6a55cb911...476a3853e3e2f8053d962c653cde44987e14064a

-- 
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/658e7ed4be70a3c44c2c4c1a9a813ef6a55cb911...476a3853e3e2f8053d962c653cde44987e14064a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260904/be08454c/attachment-0001.htm>


More information about the debian-edu-commits mailing list