[debian-edu-commits] [Git][debian-edu/debian-edu-config][personal/sunweaver/mailbox-init-first-user] 6 commits: sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).

Mike Gabriel (@sunweaver) gitlab at salsa.debian.org
Fri Sep 4 22:27:49 BST 2026



Mike Gabriel pushed to branch personal/sunweaver/mailbox-init-first-user at Debian Edu / debian-edu-config


Commits:
1b3d05e6 by Mike Gabriel at 2026-09-04T21:24:53+00:00
sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).

- - - - -
18d340a3 by Mike Gabriel at 2026-09-04T21:26:05+00:00
share/debian-edu-config/tools/kerberos-kdc-init: Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes: #1052962).

- - - - -
a3082be9 by Mike Gabriel at 2026-09-04T21:26:19+00:00
Stop using killer script in Debian Edu. (Closes: #703710).

- - - - -
b03fe98b by Mike Gabriel at 2026-09-04T21:26:55+00:00
cf3/cf.ldapclient: Ensure empty file /etc/netgroup exists. (Closes: #1146398).

- - - - -
476a3853 by Mike Gabriel at 2026-09-04T21:27:14+00:00
exim4/exim-ldap-{server,client}-v4.conf: Write logs to syslog. (Closes: #1051836).

- - - - -
a6cd1123 by Mike Gabriel at 2026-09-04T21:27:45+00:00
run-at-firstboot: Initialize first user's mailbox only when logging into Main-Server

- - - - -


10 changed files:

- Makefile
- cf3/cf.ldapclient
- cf3/cf.workarounds
- etc/exim4/exim-ldap-client-v4.conf
- etc/exim4/exim-ldap-server-v4.conf
- sbin/debian-edu-ltsp-install
- − share/debian-edu-config/killer.cron
- share/debian-edu-config/tools/kerberos-kdc-init
- share/debian-edu-config/tools/run-at-firstboot
- share/debian-edu-config/tools/setup-roaming


Changes:

=====================================
Makefile
=====================================
@@ -289,7 +289,6 @@ install: install-testsuite
 	set -e ; for f in \
 		share/debian-edu-config/d-i/finish-install \
 		share/debian-edu-config/d-i/pre-pkgsel \
-		share/debian-edu-config/killer.cron \
 		share/debian-edu-config/tools/passwd \
 		share/debian-edu-config/tools/clean-up-host-keytabs \
 		share/debian-edu-config/tools/create-debian-edu-certs \


=====================================
cf3/cf.ldapclient
=====================================
@@ -41,6 +41,10 @@ files:
 
     "/etc/nsswitch.conf"
       edit_line => nsswitch_conf;
+
+  debian.installation::
+      "/etc/netgroup" create => "true";
+
 }
 
 bundle edit_line nsswitch_conf


=====================================
cf3/cf.workarounds
=====================================
@@ -15,13 +15,4 @@ files:
 
     "$(gosa_file)"
       create => "true";
-
-  debian.ltspserver.installation::
-
-    "/etc/cron.hourly/killer"
-      delete => tidy;
-
-    "/etc/cron.hourly/killer"
-      copy_from => local_cp("/usr/share/debian-edu-config/killer.cron"),
-      perms => mog("755","root","root");
 }


=====================================
etc/exim4/exim-ldap-client-v4.conf
=====================================
@@ -17,6 +17,9 @@ LOCALHOST = 127.0.0.1/8
 # constant warning messages in the log file
 keep_environment =
 
+# Send log messages to syslog
+log_file_path = syslog
+
 # These options specify the Access Control Lists (ACLs) that
 # are used for incoming SMTP messages - after the RCPT and DATA
 # commands, respectively.


=====================================
etc/exim4/exim-ldap-server-v4.conf
=====================================
@@ -17,6 +17,9 @@
 # from 'check_local_user' directive instead.
 # -- Wolfgang Schweer <wschweer at arcor.de>, 2020-06-27.
 
+# Send log messages to syslog
+log_file_path = syslog
+
 ##
 keep_environment = KRB5_KTNAME : PWD : ^LDAP
 tls_advertise_hosts = *


=====================================
sbin/debian-edu-ltsp-install
=====================================
@@ -607,11 +607,15 @@ EOF
 	rm -f /etc/resolv.conf
 	echo "nameserver $dns_server" > /etc/resolv.conf
 	echo "search intern" >> /etc/resolv.conf
+	# Temporary workaround needed to turn DLW images into machines of profile type 'Workstation'
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"Workstation\"/g"
 	# Create SqashFS image.
 	ltsp image /,,/boot,subdir=boot,,/usr,subdir=usr,,/var,subdir=var
 	# Revert resolver workaround from above.
 	rm -f /etc/resolv.conf
 	ln -s /run/resolvconf/resolv.conf /etc/resolv.conf
+	# Revert temporary change to PROFILE in /etc/debian-edu/config
+	sed -i /etc/debian-edu/config -e "s/^PROFILE=.*/PROFILE=\"${PROFILE}\"/g"
 	# next modification avoids ltsp command error if lot of images are available.
 	ALL_IMAGES=1 ltsp kernel
 	ltsp initrd
@@ -675,7 +679,7 @@ EOF
 	chroot /srv/ltsp/dlw apt-get install -y -qq apt-utils ltsp
 
 	# Turn system into a Debian Edu workstation.
-	chroot /srv/ltsp/dlw sh -c "DESKTOP=$desktop /sbin/debian-edu-bless"
+	chroot /srv/ltsp/dlw sh -c "PROFILE=Workstation DESKTOP=$desktop /sbin/debian-edu-bless"
 	mkdir -p /srv/ltsp/dlw/skole
 	chmod 755 /srv/ltsp/dlw/skole
 	rm -f /srv/ltsp/dlw/etc/resolv.conf


=====================================
share/debian-edu-config/killer.cron deleted
=====================================
@@ -1,3 +0,0 @@
-#!/bin/sh
-
-if [ "$(ps aux | grep sshd: | grep @notty)" = "" ] && [ -x /usr/sbin/killer ] ; then /usr/sbin/killer; fi


=====================================
share/debian-edu-config/tools/kerberos-kdc-init
=====================================
@@ -173,7 +173,6 @@ mit_kerberos_kdc() {
         kdc_ports = 750,88
         max_life = 10h 0m 0s
         max_renewable_life = 7d 0h 0m 0s
-        master_key_type = des3-hmac-sha1
         default_principal_flags = +preauth
     }
 EOF


=====================================
share/debian-edu-config/tools/run-at-firstboot
=====================================
@@ -122,10 +122,11 @@ fi
 # Send mail to the first user to avoid the Dovecot permission pitfall
 # also in this special case. It doesn't seem to work during installation,
 # because Exim4 needs to grab information from LDAP which fails at that time.
-FIRSTUSER=$(grep -1 first-user-name /var/cache/debconf/config.dat | grep Value | cut -d' ' -f2)
+if echo "$PROFILE" | grep -q Main-Server ; then
+	FIRSTUSER=$(grep -1 first-user-name /var/cache/debconf/config.dat | grep Value | cut -d' ' -f2)
 
-if [ ! -d /var/mail/"$FIRSTUSER" ] ; then
-    cat << EOF | /usr/lib/sendmail $FIRSTUSER
+	if [ ! -d /var/mail/"$FIRSTUSER" ] ; then
+	    cat << EOF | /usr/lib/sendmail $FIRSTUSER
 Subject: Welcome to the mail-system
 
 Hello $FIRSTUSER,
@@ -135,7 +136,8 @@ welcome to the mail-system.
 (Sent from the Debian Edu first boot script.)
 
 EOF
-	logger -t exim-create-environment -p notice Sent mail to first-user.
+		logger -t exim-create-environment -p notice Sent mail to first-user.
+	fi
 fi
 
 # Create first user's Samba account. The smbpasswd command fails inside d-i


=====================================
share/debian-edu-config/tools/setup-roaming
=====================================
@@ -27,10 +27,6 @@ apt-get purge -y libpam-krb5
 # Avoid double caching, as sssd is already caching
 apt-get purge -y nscd
 
-# Roaming workstations are typically single user machines, so do not
-# throw out the user if he is idle.
-apt-get purge -y killer
-
 # try to configure sssd dynamically, fall back to default setup if
 # generation fail
 # sssd refuses to read the sssd.conf file unless it is 0600 root:root



View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/e1bef19fc3cb597b14a47ae495d9b9fe0c72a8ef...a6cd1123b89d7a20b7afce927e02951c8f5dd08e

-- 
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/e1bef19fc3cb597b14a47ae495d9b9fe0c72a8ef...a6cd1123b89d7a20b7afce927e02951c8f5dd08e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260904/d62963c6/attachment-0001.htm>


More information about the debian-edu-commits mailing list