[debian-edu-commits] [Git][debian-edu/debian-edu-config][trixie] 64 commits: sbin/debian-edu-fsautoresize: Avoid division by zero error on unused mountpoints.
Mike Gabriel (@sunweaver)
gitlab at salsa.debian.org
Fri Sep 25 08:01:17 BST 2026
Mike Gabriel pushed to branch trixie at Debian Edu / debian-edu-config
Commits:
1afb50ce by Mike Gabriel at 2025-09-16T10:32:22+02:00
sbin/debian-edu-fsautoresize: Avoid division by zero error on unused mountpoints.
- - - - -
5d768f5f by Mike Gabriel at 2025-09-16T17:43:41+02:00
sbin/debian-edu-pxeinstall: Support overriding tasksel/desktop selection via mydesktop parameter in /etc/debian-edu/pxeinstall.conf.
- - - - -
c7974f2a by Mike Gabriel at 2025-09-16T17:48:09+02:00
sbin/debian-edu-pxeinstall: Fix comment about mapping debconf template keywords to kernel cmdline keywords and drop unused variable assignment.
- - - - -
730df785 by Mike Gabriel at 2025-09-16T21:28:46+02:00
sbin/debian-edu-pxeinstall: Regression fix, only adjust desktop to mydesktop from pxeinstall.conf if we are processing the tasksel/desktop setting.
- - - - -
e7f8fe8b by Daniel Teichmann at 2026-03-13T16:54:07+01:00
Add new file 'debian-edu-router.ldif'. Empty proxy groups should be installed on all new Tjeners.
These are preconfigured empty proxy groups for the use in Debian Edu Router.
See Debian Edu Router Plugin: Content filter at https://salsa.debian.org/debian-edu/debian-edu-router/-/tree/master/docs.
- - - - -
1342f54b by Daniel Teichmann at 2026-03-13T16:54:10+01:00
ldap-bootstrap/debian-edu-router.ldif: Add 'server-hosts' nisNetgroup to 'proxy-trusted' nisNetgroup, via 'memberNisNetgroup' attribute.
- - - - -
ae91d71a by Daniel Teichmann at 2026-03-13T16:54:10+01:00
share/debian-edu-config/gosa.conf.template: Activate nisNetgroup tab for user accounts.
This makes it possible to add a user into a nisNetgroup while editing a user.
This is a fine addition to the already present 'NIS Netgroup' tab on the left.
- - - - -
c53528cf by Mike Gabriel at 2026-05-07T22:28:30+02:00
share/debian-edu-config/tools/copy-host-keytab: Support SSH publickey login to tjener, if this is possible (e.g. if admin is using SSH agent forwarding).
- - - - -
b892e2fa by Daniel Teichmann at 2026-05-22T22:28:45+00:00
apache2 debian-edu-default.conf: Do not force HTTPS on *.crt (including Debian-Edu_rootCA.crt).
Closes: #1068388
- - - - -
a624dc1c by Daniel Teichmann at 2026-05-22T22:29:28+00:00
etc/dovecot/local.conf: Fix passdb block syntax for Dovecot 2.4.x compatibility.
Dovecot 2.4.x introduced a breaking change to the passdb/userdb
configuration block syntax. A prior commit 63523d4c partially adapted
etc/dovecot/local.conf to Dovecot 2.4.x by splitting mail_location
into mail_driver, mail_path, and mail_inbox_path, but did not update
the passdb block, leaving the configuration broken.
This causes Dovecot to fail immediately at startup with:
- doveconf: Fatal: Error in configuration file /etc/dovecot/local.conf line 10: passdb { }
- dovecot.service: Main process exited, code=exited, status=89/n/a
- - - - -
17c18602 by Daniel Teichmann at 2026-05-22T22:30:02+00:00
debian/control: Add 'Conflicts: firefox-esr-mobile-config'.
This ensures that /usr/share/firefox-esr/distribution/policies.json
will not be overwritten by the other package.
Closes: #1126881
- - - - -
16922109 by Daniel Teichmann at 2026-05-22T22:34:37+00:00
v3CA.cnf: Fix Root CA X.509v3 extensions for OpenSSL 3 compatibility
OpenSSL 3 strictly enforces certificate purposes.
The old Root CA configuration lacked the required critical
basic constraints (CA:TRUE) and the proper key usage flags
(cRLSign, keyCertSign) necessary to act as an issuing authority.
Without these, OpenSSL 3 rejects the CA with an
"invalid CA certificate" error.
The flag "critical" is also required by OpenSSLv3.
- - - - -
1ef598be by Daniel Teichmann at 2026-05-22T22:34:37+00:00
v3.cnf: Fix server cert X.509v3 extensions for OpenSSL 3 compatibility
OpenSSL 3 requires server certificates to explicitly declare
their extended key usage.
The v3.cnf file previously only defined Subject Alternative Names,
lacking the serverAuth Extended Key Usage flag.
This caused OpenSSL 3 clients (like libldap) to reject the server
certificate during the TLS handshake with an
"unsuitable certificate purpose" error.
This commit adds the necessary Key Usage and Extended Key Usage definitions.
- - - - -
e5573407 by Daniel Teichmann at 2026-05-22T22:34:37+00:00
tools/create-debian-edu-certs: Fix script to apply correct configurations
1. It failed to apply the $V3_CA_CONF extensions when generating the Root CA,
resulting in a CA missing its basic constraints.
2. It erroneously used the CA configuration ($SSL_CA_CONF) instead of the
server configuration ($SSL_CONF) when generating the server CSR.
This caused the Root CA and the Server Certificate to share identical
Subject DNs, confusing the OpenSSL 3 validation chain.
This commit corrects the openssl req invocations to use the appropriate
configuration and extension files.
- - - - -
f2bacf68 by Daniel Teichmann at 2026-05-22T22:34:37+00:00
tools/create-server-cert: Add OpenSSL 3 extensions and fix base config
* Injects missing `keyUsage` and `extendedKeyUsage` into the generated
v3.conf to satisfy OpenSSL 3 strict validation requirements.
* Switches the template from `sslCA.cnf` to `ssl.cnf` so server
certificates do not inherit the Root CA's Organizational Unit.
NOTE: These are fixes, which come from previous commits.
See history of create-debian-edu-certs for more info.
- - - - -
0092caec by Mike Gabriel at 2026-05-23T00:49:22+02:00
release 2.13.0
- - - - -
57b7fda3 by Daniel Teichmann at 2026-08-17T20:34:11+02:00
Add new daily running script 'debian-edu-apache2-update-allowlist', which updates Apache2 'Host:' allowlist.
- - - - -
3aaed7b6 by Daniel Teichmann at 2026-08-17T20:34:11+02:00
Apache2 debian-edu-default.conf: Make Tjener be reachable with custom aliases without 302 redirects.
+ 10.x.x.x/8 is always allowed.
+ Allows .crt .dat files to be downloaded without HTTPS.
+ Supports custom aliases using allowlist map at: '/usr/share/debian-edu-config/apache2_host-allowlist.map'.
+ Allowlist map will be updated by systemd/cron once a day.
+ Uses predefined fallback (www.intern).
- - - - -
1ca2ebec by Daniel Teichmann at 2026-08-17T20:34:11+02:00
Apache2 debian-edu-default.conf: Convert indentation spaces to tabs (whitespace-only).
- - - - -
7edfcae0 by Daniel Teichmann at 2026-08-18T10:02:28+02:00
Rename Apache2 host allowlist to TJENER alias map.
Avoid confusion with Debian Edu hosts (devices). The map lists
HTTP Host header values that refer to TJENER, not client machines.
Also document the timer as 15 minutes after boot, then daily, and
add the author email to debian-edu-apache2-update-tjener-aliases.
- - - - -
71f9695a by Daniel Teichmann at 2026-08-18T18:45:43+02:00
testsuite/ldap-server: Check /var/lib/ldap ownership.
Regression check for Debian#1144741 (slapd / systemd-sysusers).
debian-edu-config does not create the directory.
- - - - -
9710a70a by Mike Gabriel at 2026-08-19T23:25:59+02:00
debian/control: Add to D: (debian-edu-config): procps. (Closes: #1136493).
- - - - -
760801e3 by Wolfgang Schweer at 2026-08-19T23:42:53+02:00
share/debian-edu-config/d-i/pre-pkgsel: Cleanup pre-pkgsel from cruft. (Closes: #1055648).
- - - - -
63575146 by Mike Gabriel at 2026-08-20T18:10:19+02:00
ldap-tools/ldap-debian-edu-install: Make sure interactions with debconf are UTF-8 based.
This resolves GECOS field transliteration after having retrieved
debian-edu-config/first-user-fullname from the debconf db.
(Closes: #939717).
- - - - -
6e60cafb by Daniel Teichmann at 2026-08-21T11:22:45+02:00
debian/debian-edu-config.lintian-overrides: Fix stale reference. (Fixes commit: 63575146)
https://jenkins.debian.net/job/edu-packages_sid_debian-edu-config/1078/console
- - - - -
0033de22 by Daniel Teichmann at 2026-08-21T14:49:39+00:00
Drop unused wicd preconnect hook
wicd is no longer in Debian. The hook was the only remaining wicd
integration and is not referenced anywhere else in the package.
- - - - -
63442a25 by Mike Gabriel at 2026-08-21T20:09:31+02:00
share/debian-edu-config/d-i/pre-pkgsel: white-space cleanup
- - - - -
62717ef0 by Mike Gabriel at 2026-08-21T20:09:31+02:00
share/debian-edu-config/d-i/pre-pkgsel: Use 'tjener' in /etc/hostname and derive FQDN from /etc/hosts. (Closes: #893394).
- - - - -
c618de32 by Mike Gabriel at 2026-08-21T20:09:31+02:00
testsuite/hostname: Test that /etc/hostname on installation profile Main-Server is set correctly
- - - - -
88aae95c by Daniel Teichmann at 2026-08-21T20:22:00+02:00
testsuite/hostname: escape regex dot and exit non-zero on failure
The unescaped dot in the 'tjener.intern' grep matched any character.
Escape it so the FQDN check is exact. Both error paths now exit 1 so a
broken hostname fails the test instead of silently passing.
- - - - -
06e2bd3d by Daniel Teichmann at 2026-08-21T20:22:41+02:00
share/debian-edu-config/d-i/pre-pkgsel: resolve leftover merge conflict
Commit 63442a25 committed a merge-conflict block around the
create_initial_localadmin_user() function. That function was removed
from master by 760801e3 (cruft cleanup, #1055648). Drop the conflict
markers and the cruft to match master.
- - - - -
d319a79f by Mike Gabriel at 2026-08-21T20:48:57+02:00
cf3/cf.cfengine3: Stop cfengine3 service on all Debian Edu machines
Esp. cf-execd (calling cf-agent command) clobbers the log on all Debian
Edu clients (Debian Edu 12 and onwards) and thus on syslog.intern (aka
tjener).
In Debian Edu, we use cfengine3 for managing configuration adjustments
via manual invocation of the cf-agent command, but we don't support
(yet?) to use cfengine3 for constant system management.
Partially addresses #1051834.
- - - - -
a402079a by Serhii Horichenko at 2026-08-21T23:29:58+02:00
ltsp: Add 'quiet splash' to hide boot details on clients
- - - - -
9bdaa01c by Serhii Horichenko at 2026-08-21T23:59:31+02:00
Revert "ltsp: Add 'quiet splash' to hide boot details on clients"
This reverts commit a402079a5101ceb334adc8a0a3824023be527b0d.
- - - - -
edbfefbb by Serhii Horichenko at 2026-08-23T10:19:19+02:00
ltsp: Add 'quiet splash' to hide boot details on clients
- - - - -
6966abd0 by Mike Gabriel at 2026-08-25T21:04:20+02:00
sbin/debian-edu-ltsp-install: Use KERNEL_PARAMETERS variable, if we define it
- - - - -
6169ac8e by Mike Gabriel at 2026-08-25T21:05:47+02:00
sbin/debian-edu-ltsp-install: Fix variable interpretation in sed commands
... by using double quotes, not single quotes.
- - - - -
13b1674d by Serhii Horichenko at 2026-08-25T19:06:31+00:00
etc/nagios3/debian-edu/commands.cfg: Add key -l for check_apt to list packages available for upgrade.
- - - - -
028e3f93 by Daniel Teichmann at 2026-08-25T19:07:16+00:00
debian/control: Depend on iproute2
- - - - -
beb42a3b by Mike Gabriel at 2026-08-25T19:07:16+00:00
sbin/update-hostname-from-ip: white-space cleanup
- - - - -
36910c1e by Mike Gabriel at 2026-08-25T19:07:16+00:00
sbin/update-hostname-from-ip: Stop using net-tools, use ip command from iproute2 instead
- - - - -
021b4b13 by Daniel Teichmann at 2026-08-25T19:07:16+00:00
testsuite/network: Stop using net-tools, use ip from iproute2 instead
- - - - -
703ccd7f by Daniel Teichmann at 2026-08-25T19:07:16+00:00
ldap-tools/ldap-debian-edu-install: Get MAC addresses via ip link instead of ifconfig
- - - - -
cde0e7df by Daniel Teichmann at 2026-08-25T19:07:16+00:00
share/debian-edu-config/testsuite-lib.sh: Use ss instead of netstat
- - - - -
b509dcee by Daniel Teichmann at 2026-08-25T19:07:16+00:00
testsuite/ldap-server: Use ss instead of netstat
- - - - -
c24d32a2 by Daniel Teichmann at 2026-08-25T19:07:16+00:00
debian/control: Drop Depends: net-tools
- - - - -
8b60974e by Mike Gabriel at 2026-08-25T19:07:48+00:00
share/debian-edu-config/d-i/pre-pkgsel: Support hostname override via /proc/cmdline. (Closes: #1008597).
- - - - -
22bbc38a by Daniel Teichmann at 2026-08-25T19:07:48+00:00
share/debian-edu-config/d-i/pre-pkgsel: Tighten hostname= parsing and sanitization from /proc/cmdline.
Handle hostname= as first cmdline token, ignore empty values and
strip characters invalid in hostnames.
- - - - -
107e8bf0 by Daniel Teichmann at 2026-08-25T19:07:48+00:00
share/debian-edu-config/d-i/pre-pkgsel: strip hyphens only when present
Use 's/^-+//' / 's/-+$//' instead of '-*' so the substitution only
fires when there actually is a leading/trailing hyphen to remove.
- - - - -
d5cef833 by Daniel Teichmann at 2026-08-25T19:09:26+00:00
tools/create-debian-edu-certs: Switch root CA and server key generation to ECDSA prime256v1
RSA with 2048 bits is the bare minimum with OpenSSL 3. Replace
'openssl genrsa' with 'openssl genpkey -algorithm EC' using the
prime256v1 (secp256r1 / NIST P-256) curve.
- - - - -
a15aa1fc by Daniel Teichmann at 2026-08-25T19:09:26+00:00
tools/create-server-cert: Switch key generation to ECDSA prime256v1 and drop keyEncipherment key usage
keyEncipherment is only meaningful for RSA keys. For ECDSA server
certificates only the digitalSignature key usage is applicable
(RFC 5480).
- - - - -
4bfee5ad by Daniel Teichmann at 2026-08-25T19:09:26+00:00
v3.cnf: Drop keyEncipherment from server cert key usage
keyEncipherment is not applicable to ECDSA keys (RFC 5480), only
digitalSignature is required for TLS server certificates.
- - - - -
3ae89a7c by Mike Gabriel at 2026-08-25T21:18:28+02:00
release as 2.13.1
Signed-off-by: Mike Gabriel <mike.gabriel at das-netzwerkteam.de>
- - - - -
c2ba0299 by Serhii Horichenko at 2026-09-04T19:26:12+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an environment check to avoid starting the image creation on an LTSP-client (Closes: #1092123).
- - - - -
8b5765b6 by Serhii Horichenko at 2026-09-04T19:40:06+02:00
share/debian-edu-config/tools/run-at-firstboot: Add an ability to create a Diskless Workstation chroot and separate the creation of an image on an LTSP-server without the Main-Server role (Closes: #1092123).
- - - - -
1b3d05e6 by Mike Gabriel at 2026-09-04T21:24:53+00:00
sbin/debian-edu-ltsp-install: When creating a DLW, set PROFILE to 'Workstation' (Closes: #1092123).
- - - - -
18d340a3 by Mike Gabriel at 2026-09-04T21:26:05+00:00
share/debian-edu-config/tools/kerberos-kdc-init: Don't hard-code master_key_type, use MIT/Kerberos' default. (Closes: #1052962).
- - - - -
a3082be9 by Mike Gabriel at 2026-09-04T21:26:19+00:00
Stop using killer script in Debian Edu. (Closes: #703710).
- - - - -
b03fe98b by Mike Gabriel at 2026-09-04T21:26:55+00:00
cf3/cf.ldapclient: Ensure empty file /etc/netgroup exists. (Closes: #1146398).
- - - - -
476a3853 by Mike Gabriel at 2026-09-04T21:27:14+00:00
exim4/exim-ldap-{server,client}-v4.conf: Write logs to syslog. (Closes: #1051836).
- - - - -
a6cd1123 by Mike Gabriel at 2026-09-04T21:27:45+00:00
run-at-firstboot: Initialize first user's mailbox only when logging into Main-Server
- - - - -
bd9d8250 by Mike Gabriel at 2026-09-04T23:38:51+02:00
release as 2.13.2
Signed-off-by: Mike Gabriel <mike.gabriel at das-netzwerkteam.de>
- - - - -
232294bc by Mike Gabriel at 2026-09-07T10:58:26+02:00
Merge tag '2.13.2' into trixie
released as 2.13.2
- - - - -
970a5bdc by Mike Gabriel at 2026-09-07T11:00:38+02:00
release to trixie as 2.13.2~deb13u1
Signed-off-by: Mike Gabriel <mike.gabriel at das-netzwerkteam.de>
- - - - -
41 changed files:
- Makefile
- cf3/cf.cfengine3
- cf3/cf.ldapclient
- cf3/cf.workarounds
- debian/changelog
- debian/control
- debian/debian-edu-config.cron.daily
- + debian/debian-edu-config.debian-edu-apache2-update-tjener-aliases.service
- + debian/debian-edu-config.debian-edu-apache2-update-tjener-aliases.timer
- debian/debian-edu-config.lintian-overrides
- debian/debian-edu-config.maintscript
- debian/rules
- etc/apache2/sites-available/debian-edu-default.conf
- etc/dovecot/local.conf
- etc/exim4/exim-ldap-client-v4.conf
- etc/exim4/exim-ldap-server-v4.conf
- etc/nagios3/debian-edu/commands.cfg
- − etc/wicd/scripts/preconnect/set_wireless_mac_from_eth0
- + ldap-bootstrap/debian-edu-router.ldif
- ldap-tools/ldap-debian-edu-install
- + libexec/debian-edu-apache2-update-tjener-aliases
- sbin/debian-edu-ltsp-install
- sbin/debian-edu-ltsp-ipxe
- sbin/debian-edu-pxeinstall
- sbin/update-hostname-from-ip
- + share/debian-edu-config/apache2_tjener-aliases.map
- share/debian-edu-config/d-i/pre-pkgsel
- share/debian-edu-config/gosa.conf.template
- − share/debian-edu-config/killer.cron
- share/debian-edu-config/testsuite-lib.sh
- share/debian-edu-config/tools/copy-host-keytab
- share/debian-edu-config/tools/create-debian-edu-certs
- share/debian-edu-config/tools/create-server-cert
- share/debian-edu-config/tools/kerberos-kdc-init
- share/debian-edu-config/tools/run-at-firstboot
- share/debian-edu-config/tools/setup-roaming
- share/debian-edu-config/v3.cnf
- share/debian-edu-config/v3CA.cnf
- + testsuite/hostname
- testsuite/ldap-server
- testsuite/network
The diff was not included because it is too large.
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/8b11587ea744239a50c64f7d56684ff75214c006...970a5bdcc5265ee77f5f874e4e19a59490912897
--
View it on GitLab: https://salsa.debian.org/debian-edu/debian-edu-config/-/compare/8b11587ea744239a50c64f7d56684ff75214c006...970a5bdcc5265ee77f5f874e4e19a59490912897
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-edu-commits/attachments/20260925/fc4ed25b/attachment-0001.htm>
More information about the debian-edu-commits
mailing list