Tuesday, March 14th, 2017, 00:22 UTC
[00:22:33] amessina (amessina!~amessina@unaffiliated/amessina) has quit (Quit: Konversation terminated!)
[00:49:37] Roklobster (Roklobster! has joined #mythtv
[01:12:22] mad_enz (mad_enz!~mad_enz@2607:f090:488d:7ab:55d5:ec07:5347:d681) has quit (Ping timeout: 246 seconds)
[01:26:55] mad_enz (mad_enz!~mad_enz@2607:f090:488d:7ab:ddbe:9b:65f0:4d19) has joined #mythtv
[03:18:36] Hydr0p0nX (Hydr0p0nX! has joined #mythtv
[03:56:35] peper03 (peper03!~peper03@mythtv/developer/peper03) has quit (Ping timeout: 240 seconds)
[04:03:33] peper03 (peper03!~peper03@mythtv/developer/peper03) has joined #mythtv
[04:58:04] Roklobster (Roklobster! has quit (Quit: Leaving)
[04:58:28] Roklobster (Roklobster! has joined #mythtv
[07:32:10] amessina (amessina!~amessina@unaffiliated/amessina) has joined #mythtv
[07:46:34] Chutt (Chutt!~ijr@2605:a000:1208:c087:b834:753:9054:aca1) has quit (Ping timeout: 264 seconds)
[08:06:44] dekarl: should we merge "IRC#Legally-Dubious Content" and "Mailing List etiquette#FAQ" and some other parts (forum?) into some "community standard"? I'd like to suggest these guys to just use any of the grabbers that serve North America
[08:10:46] amessina (amessina!~amessina@unaffiliated/amessina) has quit (Remote host closed the connection)
[08:11:45] SteveGoodey (SteveGoodey! has joined #mythtv
[08:25:07] dekarl (dekarl!~dekarl@mythtv/developer/dekarl) has quit (Ping timeout: 258 seconds)
[08:28:06] dekarl (dekarl!~dekarl@mythtv/developer/dekarl) has joined #mythtv
[08:39:52] amessina (amessina!~amessina@unaffiliated/amessina) has joined #mythtv
[08:54:23] willcooke (willcooke! has joined #mythtv
[08:54:23] willcooke (willcooke! has quit (Changing host)
[08:54:24] willcooke (willcooke!~willcooke@ubuntu/member/willcooke) has joined #mythtv
[08:56:04] Merlin83b (Merlin83b!~Daniel@2a00:1ee0:3:1337:7546:5601:f861:4137) has joined #mythtv
[09:12:18] stuarta: morning all
[09:14:32] SteveGoodey: stuarta: Can you reenable wiki registrations? I suggested to a forum user he add something forgetting he can't register!!
[09:15:27] amessina (amessina!~amessina@unaffiliated/amessina) has quit (Remote host closed the connection)
[09:22:11] stuarta: SteveGoodey: ah yes, i can do that
[09:22:34] SteveGoodey: stuarta: Ta.
[09:23:26] stuarta: done
[09:26:39] SteveGoodey: That was quick thanks. I'll let the user know and ask him to register. Do you want to revert registering after?
[09:27:10] stuarta: i expect i will, otherwise our spam fight will move from the forum back to the wiki
[09:34:40] SteveGoodey: I wonder how long it will take them to realise it's open again?
[09:42:40] stuarta: not that long
[09:44:00] ShapeShifter499 (ShapeShifter499!~ShapeShif@unaffiliated/shapeshifter499) has quit (Read error: Connection reset by peer)
[09:47:46] ShapeShifter499 (ShapeShifter499!~ShapeShif@unaffiliated/shapeshifter499) has joined #mythtv
[10:41:10] ikevin (ikevin! has quit (Ping timeout: 256 seconds)
[10:41:58] ikevin (ikevin! has joined #mythtv
[10:45:48] benklop (benklop! has quit (Ping timeout: 240 seconds)
[10:52:34] benklop (benklop! has joined #mythtv
[11:44:31] ** stuarta sighs **
[11:58:24] stuarta: well that's one set of certs fixed
[12:19:24] Roklobster (Roklobster! has quit (Remote host closed the connection)
[12:33:00] membiblio (membiblio! has quit (Remote host closed the connection)
[13:58:09] stuarta: \o/ woot all ssl cert's redone with letsencrypt
[13:58:13] stuarta: happy about that
[13:58:29] stuarta: that's the end of pita renewals
[13:59:48] jheizer_ (jheizer_!~jheizer@2601:246:8200:70ab:b8bb:d87a:a5ee:446f) has joined #mythtv
[14:03:25] jheizer (jheizer!~jheizer@2601:246:8200:70ab:e165:a95c:e2a8:3230) has quit (Ping timeout: 246 seconds)
[14:08:01] ikevin: letsencrypt <3
[14:15:12] stuarta: and A+ ratings on both endpoints....
[14:16:06] ikevin: now http2.0? :p
[14:17:34] stuarta: the one that supports it yes, although i haven't turned it on for all the sites, probably should
[14:17:36] ikevin: oh, i see use http2
[14:17:44] stuarta: as i haven't seen a single issue from it
[14:17:58] stuarta: the legacy host doesn't support it
[14:35:04] ** stuarta ponders pushing some DNS CAA records **
[15:04:44] peterbennett (peterbennett!~peter@2601:183:100:fa4d:143e:4dbc:a2c2:efe) has joined #mythtv
[15:11:07] Chutt (Chutt!~ijr@2605:a000:1208:c087:7973:ea56:1802:aaef) has joined #mythtv
[15:23:09] gary_buhrmaster: stuarta: recommendation: Add to your calendar to check that the automated renewals really work in two months (when I first set things up, everything looked great, but the automated renewal failed due to some bad setup on my part (this was in the "beta" days, so things have gotten better), and I am the "trust, by verify" kind of person).
[15:23:44] stuarta: gary_buhrmaster: i added monitoring a while back for all the mythtv sites including ssl certs
[15:25:09] stuarta: mainly because alcor has a habit of going bang randomly
[15:25:19] gary_buhrmaster: Excellent! (said in a Mr. Burns voice).
[15:25:22] stuarta: (yes, the hardware is knackered)
[15:26:04] stuarta: old sysadmin habit die hard. must monitor so you have any idea of what is going on
[15:26:12] gary_buhrmaster: I remember the history of alcor (all too well I remember the ups, and downs.... and downs).
[15:26:55] gary_buhrmaster: As long as the monitoring does not annoy you saying "the SSL cert will expire in a month", which is right on the edge with letsencrypt.
[15:26:57] stuarta: i'm dreading it dying before i finish migrations
[15:27:26] stuarta: hah, i changed the defaults to 60d / 30d for warning / critical
[15:27:37] stuarta: i may lower that now that letencrypt is being used
[15:27:41] gary_buhrmaster: If you did not monitor, or measure it, it did not happen.
[15:28:05] stuarta: exactly, detected alcor rebooted itself a while back, no reason, it just did
[15:28:17] gary_buhrmaster: Yep, 27d/14d might be a better choice with LE.
[15:28:56] gary_buhrmaster: I claim there was a reason. Perhaps not a reason mere mortals understand, but there was a reason.
[15:29:39] stuarta: given the ability to easily increase and decrease the servernames protected by the cert, you don't want the old ones to live on too long
[15:29:53] stuarta: as a way of avoiding wildcard certs
[15:30:00] stuarta: it makes complete sense to me
[15:40:47] gary_buhrmaster: Yes, I agree with most of the arguments for the time limits of the LE certificates. Yes, it does mean that some needs will not be a good fit for LE, but such is life.
[15:42:21] stuarta: for us, assuming the autorenewal works then it's actually a perfect fit
[15:46:12] gary_buhrmaster: And the price is right. There are fewer reasons not to have your site use encryption these days.
[15:56:55] stuarta: we had free before, but i was a royal pain in the arse
[15:57:06] stuarta: this is free, and simples!
[15:57:16] stuarta: and automatic!
[16:18:51] stuarta: SteveGoodey: already have a dodgy looking account created on the wiki
[16:44:30] SteveGoodey: stuarta: Yeah saw that.
[16:49:10] peterbennett (peterbennett!~peter@2601:183:100:fa4d:143e:4dbc:a2c2:efe) has quit (Quit: Leaving.)
[18:08:52] Merlin83b (Merlin83b!~Daniel@2a00:1ee0:3:1337:7546:5601:f861:4137) has quit (Quit: Leaving)
[18:31:27] willcooke (willcooke!~willcooke@ubuntu/member/willcooke) has quit (Quit: Do your hobbies)
[21:01:05] Roklobster (Roklobster! has joined #mythtv
[21:58:50] amessina (amessina!~amessina@unaffiliated/amessina) has joined #mythtv
[22:08:45] SteveGoodey (SteveGoodey! has quit (Quit: Konversation terminated!)
[22:30:45] Roklobster (Roklobster! has quit (Remote host closed the connection)
[22:55:45] arescorpio (arescorpio! has joined #mythtv

