<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:friends="wordpress-plugin-friends:feed-additions:1" >

<channel>
	<title>Debian &#8211; WindfluechterNet Blog</title>
	<atom:link href="https://blog.windfluechter.net/tag/debian/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.windfluechter.net</link>
	<description>&#34;Allen Gewalten zum Trotz sich erhalten&#34;</description>
	<lastBuildDate>Sat, 29 Aug 2026 08:05:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
	<item>
		<title>Debian GR on Responsible Use of Generative AI</title>
		<link>https://blog.windfluechter.net/2026/08/29/debian-gr-on-responsible-use-of-generative-ai/</link>
					<comments>https://blog.windfluechter.net/2026/08/29/debian-gr-on-responsible-use-of-generative-ai/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Sat, 29 Aug 2026 07:40:00 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Software]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=97337</guid>

					<description><![CDATA[So, the members of Debian (developers and such) have voted in a GR about &#8220;LLM usage in Debian&#8221; for Option 5)/Proposal E) &#8220;Responsible Use of Generative AI&#8221;. And in the #Fediverse the hell breaks lose! Currently there is a huge... <a href="https://blog.windfluechter.net/2026/08/29/debian-gr-on-responsible-use-of-generative-ai/" class="readmore">Read more<span class="screen-reader-text">Debian GR on Responsible Use of Generative AI</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">So, the members of Debian (developers and such) have voted in a <a href="https://www.debian.org/vote/2026/vote_002">GR about &#8220;LLM usage in Debian</a>&#8221; for Option 5)/Proposal E) &#8220;Responsible Use of Generative AI&#8221;. </p>



<p class="wp-block-paragraph">And in the <a rel="tag" class="hashtag u-tag u-category" href="https://blog.windfluechter.net/tag/fediverse/">#Fediverse</a> the hell breaks lose!</p>



<p class="wp-block-paragraph">Currently there is a huge vibe against (Generative) AI, i.e. generating code, images, etc. I can understand some furor about this and in general I dislike much of the AI as well. For example I dislike the energy and water consumption, what the hype did to memory &amp; storage prices, the awful look of all these AI generated images, the ignorance of AI companies about copyrights and all this. </p>



<p class="wp-block-paragraph">But I also see the benefits of AI: people are entitled to do things they couldn&#8217;t do before. You can proceed faster with your pet project when AI assist you and all of the bells and whistles. </p>



<p class="wp-block-paragraph">Anyway, let&#8217;s face it: AI is a disruptive technolgy like the invention of electricity, the steam engine, combustion engine, the computer or the smartphone were. It will not go away anymore. Pandoras box is open. </p>



<p class="wp-block-paragraph">But what you can do is: </p>



<ul class="wp-block-list">
<li>learn what AI is and what not</li>



<li>use AI in a responsible way</li>



<li>experience the Do&#8217;s &amp; Don&#8217;ts of AI</li>



<li>increase your knowledge about AI and its dangers and beneftis</li>



<li>help others with getting used resonsibly to AI</li>



<li>build a good sense that AI is telling you nonsense</li>



<li>don&#8217;t blindly trust AI</li>



<li>learn about new technology with and without the help of AI</li>



<li>use it as a tool</li>



<li>etc&#8230;</li>
</ul>



<p class="wp-block-paragraph">I don&#8217;t say you should embrace AI completely, but demonizing it won&#8217;t help you either. Be sceptic, be curious about it, act responsible. AI is not your saviour, but it&#8217;s also not armageddon. It is a discruptive technology. Deal with it. You&#8217;ll have no other option anyway. 🤷‍♂️</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2026/08/29/debian-gr-on-responsible-use-of-generative-ai/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>Outages on Nerdculture.de due to Ceph &#8211; Part 2</title>
		<link>https://blog.windfluechter.net/2026/01/06/outages-on-nerdculture-de-due-to-ceph-part-2/</link>
					<comments>https://blog.windfluechter.net/2026/01/06/outages-on-nerdculture-de-due-to-ceph-part-2/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Tue, 06 Jan 2026 15:57:33 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Ceph]]></category>
		<category><![CDATA[Server]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=34917</guid>

					<description><![CDATA[Last weekend I had &#8220;fun&#8221; with Ceph again on a Saturday evening. But let&#8217;s start at the beginning&#8230;. Before the weekend I announced a downtime/maintenance windows to upgrade PostgreSQL from v15 to v17 &#8211; because of the Debian upgrade from... <a href="https://blog.windfluechter.net/2026/01/06/outages-on-nerdculture-de-due-to-ceph-part-2/" class="readmore">Read more<span class="screen-reader-text">Outages on Nerdculture.de due to Ceph &#8211; Part 2</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Last weekend I had &#8220;fun&#8221; with Ceph again on a Saturday evening. But let&#8217;s start at the beginning&#8230;. </p>



<p class="wp-block-paragraph">Before the weekend I announced a downtime/maintenance windows to upgrade PostgreSQL from v15 to v17 &#8211; because of the Debian upgrade from <em>Bookworm</em> to <em>Trixie</em>. After some tests with a cloned VM I decided use the quick path of <em>pg_ugradecluster 15 main -v 17 -m upgrade &#8211;clone</em>. As this would be my first time to upgrade PostgreSQL that way, I made several backups. In the end everything went smooth and the database is now on v17. </p>



<p class="wp-block-paragraph">However, there was also a new Proxmox kernel and packages, so I also upgrade one Proxmox node and rebootet it. And then the issues began: </p>



<p class="wp-block-paragraph">But before that I also encountered an issue with Redis for Mastodon. It complained about this: </p>



<pre class="wp-block-code"><code>Unable to obtain the AOF file appendonly.aof.4398.base.rdb</code></pre>



<p class="wp-block-paragraph">Solution to this was to change redis configuration to <em>autoappend no</em>.</p>



<p class="wp-block-paragraph">And then CephFS was unavailable again, complaining about laggy MDS or no MDS at all, which &#8211; of course &#8211; was totally wrong. I search for solutions and read many forum posts in the Proxmox forum, but nothing helped. I also read the <a href="https://docs.ceph.com/en/quincy/cephfs/#troubleshooting-and-disaster-recovery">official Ceph documentation</a>. After a whole day offline for all of the services to my thousands of users, I somehow managed to get <em>systemctl reset-failed mnt-pve-cephfs &amp;&amp; systemctl start mnt-pve-cephfs</em> again. Shortly before that I followed the advice in the <a href="https://docs.ceph.com/en/quincy/cephfs/troubleshooting/#rados-health">Ceph docs for RADOS Health</a> and there especially section about <a href="https://docs.ceph.com/en/quincy/rados/troubleshooting/troubleshooting-mon/">Troubleshooting Monitors</a>. </p>



<p class="wp-block-paragraph">In the end, I can&#8217;t say which step exactly did the trick that CephFS was working again. But as it seems, I will have one or two more chances to find out, because only one server out of three is currently updated. </p>



<p class="wp-block-paragraph">Another issue during the downtime also was that one server crashed/rebooted and didn&#8217;t came back. It hang in the midst of an upgrade at the point of <em>upgrade-grub</em>. Usually it wouldn&#8217;t be a big deal: just go the IPMI website and reboot the server. </p>



<p class="wp-block-paragraph">Nah! That&#8217;s too simple!</p>



<p class="wp-block-paragraph">For some unknow reason the IPMI interfaces lost their DHCP leases: the DHCP server at the colocation was not serving IPs. So I opened a ticket, got some acknowledgement from the support but also a statement &#8220;maybe tomorrow or on Monday&#8230;&#8221;. Hmpf!</p>



<p class="wp-block-paragraph">On Sunday evening I managed to bring back CephFS. As said: no idea what specific step did the trick. But the story continues: On Monday before lunch time the IPMI DHCP was working again and I could access the web interfaces again, logged in&#8230;. and was forcefully locked out again: </p>



<pre class="wp-block-code"><code>Your session has timed out. You will need to open a new session</code></pre>



<p class="wp-block-paragraph">I hit the problem <a href="https://www.reddit.com/r/techsupport/comments/5l60td/supermicro_ipmi_web_session_expires_immediately/">described here</a>. But cold resetting the BMC didn&#8217;t work. So still no working web interface to deal with the issue. But on my phone I got &#8220;IPMIView&#8221; as app and that still worked and showed the KVM console. But what I saw there didn&#8217;t make me happy as well:</p>



<figure class="wp-block-image"><img fetchpriority="high" decoding="async" width="554" height="416" src="https://blog.windfluechter.net/wp-content/uploads/2026/01/63d0aed21ea4d3fd.jpeg" alt="" class="wp-image-34931"/></figure>



<p class="wp-block-paragraph">The reason for this is apparently the crash while running update-grub. Anyway, using the Grub bootloader and selecting an older kernel works fine. The server boots, Proxmox is showing the node as up and&#8230;. the working CephFS is stalled again! Fsck!</p>



<p class="wp-block-paragraph">Rebooting the node or stopping Ceph on that node results immediatedly in a working CephFS again. </p>



<p class="wp-block-paragraph">Currently I&#8217;m moving everything off of Ceph to the local disks of the two nodes. If everything is on local disks I can work on debugging CephFS without interrupting the service for the users (hopefully). But this also means that there will be no redundancy for Mastodon and mail. </p>



<p class="wp-block-paragraph">When I have more detailled information about possible reasons and such, I may post to the Proxmox forum. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2026/01/06/outages-on-nerdculture-de-due-to-ceph-part-2/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>Outages on Nerdculture.de due to Ceph</title>
		<link>https://blog.windfluechter.net/2025/10/12/outages-on-nerdculture-de-due-to-ceph/</link>
					<comments>https://blog.windfluechter.net/2025/10/12/outages-on-nerdculture-de-due-to-ceph/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Sun, 12 Oct 2025 10:50:19 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Server]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=9299</guid>

					<description><![CDATA[Well, maybe it&#8217;s not entirely correct to blame Ceph for outages that happened in the last weeks to Nerdculture.de and other services running on my servers, but, well, I need to start somehow&#8230; Overview Shortly after the update from Debian... <a href="https://blog.windfluechter.net/2025/10/12/outages-on-nerdculture-de-due-to-ceph/" class="readmore">Read more<span class="screen-reader-text">Outages on Nerdculture.de due to Ceph</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Well, maybe it&#8217;s not entirely correct to blame Ceph for outages that happened in the last weeks to Nerdculture.de and other services running on my servers, but, well, I need to start somehow&#8230; </p>



<h2 class="wp-block-heading">Overview</h2>



<p class="wp-block-paragraph">Shortly after the update from Debian 12 &#8220;Bookworm&#8221; to Debian 13 &#8220;Trixie&#8221; I also updated the Debian-based Proxmox installations. And then the issues began and I had sleepless nights, many downtimes and frustrated users, because the usually rock-stable Ceph storage became unstable. The OSDs went off the net, the Ceph Filesystem got degraded and everything became slow. The Ceph Filesystems (CephFS) also holds the mail storage as well as the shared storage (code &amp; data) for my Nerdculture.de Mastodon instance. </p>



<p class="wp-block-paragraph">Just to outline what I&#8217;m about to discuss, here&#8217;s the cabling plan for my 3-node hyperconverged Proxmox server setup: </p>



<figure class="wp-block-image size-full"><img decoding="async" width="1108" height="784" src="https://blog.windfluechter.net/wp-content/uploads/2025/10/Bildschirmfoto-2025-10-12-um-10.08.22.png" alt="" class="wp-image-9303" srcset="https://blog.windfluechter.net/wp-content/uploads/2025/10/Bildschirmfoto-2025-10-12-um-10.08.22.png 1108w, https://blog.windfluechter.net/wp-content/uploads/2025/10/Bildschirmfoto-2025-10-12-um-10.08.22-640x453.png 640w, https://blog.windfluechter.net/wp-content/uploads/2025/10/Bildschirmfoto-2025-10-12-um-10.08.22-768x543.png 768w" sizes="(max-width: 1108px) 100vw, 1108px" /></figure>



<p class="wp-block-paragraph">Basically you see 3 types of connections: <br>1) Internet connection to the colocation switch<br>2) Internal Proxmox connections between the 3 nodes<br>3) Internal Ceph connections between the 3 nodes</p>



<p class="wp-block-paragraph">The internal, directly wired connections are necessary because the colocation provider have had no additional Copper 10 Gbit/s ports (10GbaseT) available. So I had to wire up all those by directly attached patch cables.  </p>



<p class="wp-block-paragraph">Ceph has a backend and frontend network. You can run Ceph with just one network, but well, then Proxmox and Ceph would need to share the same network and access to Ceph would slow down when Virtual Machines (VMs) were migrated between the nodes. </p>



<h2 class="wp-block-heading">What happened the last weeks?</h2>



<p class="wp-block-paragraph">The problem started, as said, after updating the Proxmox nodes. On Sept. 24th the first outage happened. You can read my <a href="https://nerdculture.de/@order/115266340703690551" data-type="link" data-id="https://nerdculture.de/@order/115266340703690551">summary here</a>. Somehow the network Ceph connection between didn&#8217;t work anymore. The setup that was running for years now didn&#8217;t work anymore. The Ceph backend network couldn&#8217;t see the disks (OSD) any longer, so added manual routes between the nodes instead of relying on FRR with OSPF (a dynamic routing protocol). This solved the problem back then. </p>



<p class="wp-block-paragraph">The next issue happened a week later on <a href="https://nerdculture.de/@order/115304479907005014">Oct. 2nd</a>: since the last issue a week before I discovered that CephFS was awkfully slow. Loading the mails took like 10 seconds instead of being instantly there. So I tried to find the reason. My best assumption was: the WD Red SA500 2 TB that are holding the WAL/DB for the Ceph cluster are reaching the wear level end. These SSDs are not made for that kind of workload.</p>



<p class="wp-block-paragraph">Another reason might be that the Ceph frontend network, which uses the Proxmox network, because the VMs need to access the Ceph frontend, is a OpenVSwitch bridge and traffic from Baldur is using the link via Pepper to Gate, for example, instead of using the direct connection, which adds some latency and reducing bandwidth. </p>



<p class="wp-block-paragraph">And with that being said, this was the reason why there was an outage yesterday as well: </p>



<p class="wp-block-paragraph">For the Ceph backend network, I use an internal Linux bridge in Proxmox to hold the IP for the Ceph backend on each node. Then there are two network cards, as described in the drawing. On the link between the nodes I configured Point to Point connections and added a route for the direct neighbor with a lower metric and a route for the other node with a higher metric. The other link vice versa. This works pretty well for the Ceph backend. </p>



<p class="wp-block-paragraph">Yesterday I wanted to deploy those changes as well to the Proxmox network and get rid off of that Layer 2 network via OpenVSwitch. Settings this up in the operating system was no big deal, but unfortunately Proxmox complained later about the nodes having more than one IP. And there the issue started again. </p>



<p class="wp-block-paragraph">But there was another problem, because even when reverting that network change, the Ceph cluster had issues again and couldn&#8217;t find its peers. I restarted services, rebooted nodes, etc&#8230; whatever to make it work again. But still OSDs were failing, coming online again, and failing again. The service <code>mnt-pve-cephfs.mount</code> was not able to mount the CephFS and thus CephFS was not available for the VMs and therefore the services like mail and Mastodon failed to load as well as nearly all services that need SSL certificates which &#8211; you guess it! &#8211; lies on CephFS as well. No CephFS available, no SSL certs and no service. </p>



<p class="wp-block-paragraph">But why was it not possible to mount the CephFS on the Proxmox host nodes? I had a look onto the syslog and other logs while restarting services, but the output was that much and fast, that I couldn&#8217;t find the root cause for it. </p>



<p class="wp-block-paragraph">At one time I was lucky and spotted this line: <br><code>2025-10-12T01:05:28.209050+02:00 baldur ceph-mgr[40880]: ERROR:root:Module 'xmltodict' is not installed.</code><br>And the solution was as simple as searching the web for that error message and stumble across <a href="https://forum.proxmox.com/threads/ceph-managers-seg-faulting-post-upgrade-8-9-upgrade.169363/">this post in the Proxmox forum</a>:</p>



<p class="wp-block-paragraph"><code>I was able to correct this with python3-xmltodict, that resolved one issue</code><br>So, after installing that package the Ceph cluster was happy again and Proxmox could finally mount CephFS with restarting <code>mnt-pve-cephfs.mount</code>. </p>



<p class="wp-block-paragraph">Then it was <em>just</em> a matter of restarting VMs and services and finally Mastodon on https://nerdculture.de/ was available again as well as mail started to come in. </p>



<h2 class="wp-block-heading">Lessons learned</h2>



<p class="wp-block-paragraph">For one I&#8217;m going to buy new SSDs for WAL/DB in Ceph, most likely Micron 5400 MAX. This should bringt he latency down with Ceph and increase the overall speed, because data is only written for the client, when all 3 nodes have written their data to disk. The slowest node or disk is the resulting speed of Ceph. WD Red SSDs might be good enough for NAS systems, but for constant disk writes like in the case of WAL/DB in Ceph, they seem to hit their limit rather soon. </p>



<p class="wp-block-paragraph">Another thing I could improve is the network. It is a complex setup and prone to errors. I need to talk to the colocation if I can get 6x 10 Gbps ports on their switch or if I can bring in my own switch and what that would cost?</p>



<p class="wp-block-paragraph">Speaking of: what switch would you recommend?<br></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2025/10/12/outages-on-nerdculture-de-due-to-ceph/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>XMPP and the effect of providers.xmpp.net</title>
		<link>https://blog.windfluechter.net/2022/08/13/xmpp-and-the-effect-of-providers-xmpp-net/</link>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Sat, 13 Aug 2022 16:07:11 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[XMPP]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3344</guid>

					<description><![CDATA[Some of you may already know that I&#8217;m operating an XMPP server. So far there are several domains running on that XMPP server and two domains are open for public registration. Namely these domains are hookipa.net and xmpp.social. You can... <a href="https://blog.windfluechter.net/2022/08/13/xmpp-and-the-effect-of-providers-xmpp-net/" class="readmore">Read more<span class="screen-reader-text">XMPP and the effect of providers.xmpp.net</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Some of you may already know that I&#8217;m operating an XMPP server. So far there are several domains running on that XMPP server and two domains are open for public registration. Namely these domains are hookipa.net and xmpp.social. You can find the service under the main domain on <a href="https://hookipa.net">https://hookipa.net</a>. </p>



<p class="wp-block-paragraph">Interesting in this is, that for some time xmpp.social seemed to be the domain of choice for many users, maybe because of &#8220;xmpp&#8221; and &#8220;social&#8221; in the domain name &#8211; or because it is easier to name it than &#8220;hookipa&#8221; with &#8220;double-oh&#8221; and &#8220;kay&#8221;&#8230; who knows&#8230; </p>



<p class="wp-block-paragraph">So, the user counts on xmpp.social were rising in a steeper curve than for hookipa.net, so much that I even considered to move over to xmpp.social for the main domain of that website. </p>



<p class="wp-block-paragraph">But then something happened: the <a href="https://invent.kde.org/melvo/xmpp-providers" data-type="URL" data-id="https://invent.kde.org/melvo/xmpp-providers">curated list of XMPP providers</a>, which is now available under <a href="https://providers.xmpp.net">https://providers.xmpp.net</a>. Since then some client software apps included the list, e.g. <a href="https://github.com/UWPX/UWPX-Client/issues/158#ref-commit-0dd8c0e" data-type="URL" data-id="https://github.com/UWPX/UWPX-Client/issues/158#ref-commit-0dd8c0e">uwpx</a>, and the user count was rising on hookipa.net &#8211; while it slowed down on xmpp.social. </p>



<figure class="wp-block-image size-full"><img decoding="async" width="897" height="584" src="https://blog.windfluechter.net/wp-content/uploads/2022/08/ejabberd_registrations-pinpoint16266225531660664153.png" alt="" class="wp-image-3345" srcset="https://blog.windfluechter.net/wp-content/uploads/2022/08/ejabberd_registrations-pinpoint16266225531660664153.png 897w, https://blog.windfluechter.net/wp-content/uploads/2022/08/ejabberd_registrations-pinpoint16266225531660664153-640x417.png 640w, https://blog.windfluechter.net/wp-content/uploads/2022/08/ejabberd_registrations-pinpoint16266225531660664153-768x500.png 768w" sizes="(max-width: 897px) 100vw, 897px" /><figcaption>Red curve: xmpp.social, blue curve: hookipa.net</figcaption></figure>



<p class="wp-block-paragraph">Here you can see that the red curve of xmpp.social was for a long time above the blue curve of hookipa.net. Approx. in August 2021 something changed and hookipa.net was steadily increasing its user count. After a year, roughly in August 2022 hookipa.net surpassed the user count of xmpp.social. </p>



<p class="wp-block-paragraph">Reason for this might be that hookipa.net is listed under Class A provider on providers.xmpp.net. Class A just means that some certain criteria is met like open registration and such. It doesn&#8217;t say anything whether or not it is a well-operated service. Well, at least not directly. </p>



<p class="wp-block-paragraph">You can also look at the graphs on https://the-federation.info about the <a href="https://the-federation.info/node/hookipa.net" data-type="URL" data-id="https://the-federation.info/node/hookipa.net">increase on hookipa.net</a> and the <a href="https://the-federation.info/node/xmpp.social" data-type="URL" data-id="https://the-federation.info/node/xmpp.social">stagnation on xmpp.social</a>. There you can see the difference between a service that is listed on such a providers list and one that isn&#8217;t listed. Both domains are equally operated on my server and when you visit the Hookipa website you can register for both domains. But currently a downside (for me) of providers.xmpp.net is, that you need to provide the data for your classification on a website. Hookipa has a website, xmpp.social not, because it redirects to hookipa.net. Therefor xmpp.social is not included on providers.xmpp.net and thus is not gaining that many new users than hookipa.net. </p>



<p class="wp-block-paragraph">I find that quite interesting, how registration counts are shifted from one domain to the other over time and what leads to that shift. </p>



<p class="wp-block-paragraph">If you want to know which XMPP apps make use of the providers list, you can have a look at <a href="https://providers.xmpp.net/apps/">https://providers.xmpp.net/apps/</a>.</p>
]]></content:encoded>
					
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>setupSSO.sh : SAML SSO in Univention UCS Server</title>
		<link>https://blog.windfluechter.net/2022/08/13/setupsso-sh-saml-sso-in-univention-ucs-server/</link>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Sat, 13 Aug 2022 10:05:38 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[SAML&SSO]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[UCS]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3341</guid>

					<description><![CDATA[Disclaimer: For over a decade I worked on the topic of Cisco Unified Communications, so IP telephony, Cisco Jabber and video conferencing. Now I&#8217;m working at Univention doing some Linux and even Debian related stuff as an IT Consultant. For... <a href="https://blog.windfluechter.net/2022/08/13/setupsso-sh-saml-sso-in-univention-ucs-server/" class="readmore">Read more<span class="screen-reader-text">setupSSO.sh : SAML SSO in Univention UCS Server</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Disclaimer: For over a decade I worked on the topic of Cisco Unified Communications, so IP telephony, Cisco Jabber and video conferencing. Now I&#8217;m working at <a href="https://univention.de/" data-type="URL" data-id="https://univention.de/">Univention</a> doing some Linux and even Debian related stuff as an IT Consultant. </p>



<p class="wp-block-paragraph">For years I&#8217;m self-hosting lots of stuff and also for family, friends and others. The user management was either standalone for each service like Nextcloud, Mastodon, Friendica, XMPP, or based on the mail auth backend on PostgreSQL, for example by authenticating against Dovecot IMAP server. This became complex over time and I was looking for a centralized auth backend. Basically this means: LDAP backend. </p>



<p class="wp-block-paragraph">For that I took a look into 389ds, FusionDirectory and Univention Corporate Server (UCS). With 389ds I had installation or setup issues. FusionDirectory was way better and easier to use, but also very complex. In the end I went with UCS because of the UI experienced, the ease of use and having a working self-care portal for the users. And UCS comes with some kind of <a href="https://www.univention.com/products/univention-app-center/app-catalog/" data-type="URL" data-id="https://www.univention.com/products/univention-app-center/app-catalog/">App Center</a> with some nice apps in it that are preconfigured for the LDAP directory. So, really easy to use and to get started. </p>



<p class="wp-block-paragraph">So, last year (even before I got employed by Univention) I migrated my users from PostgreSQL backend to UCS and LDAP backend. The migration was smooth and nice and worked like a charme. Only issue: things like my <a href="https://hookipa.net/" data-type="URL" data-id="https://hookipa.net/">public XMPP server</a>, <a href="https://nerdica.net">Friendica</a> or <a href="https://nerdcultura.de">Mastodon</a> are still using open registration and therefor internal auth backend. It will be much more difficult to migrate these with an existing user base of 3000-4000 users in total. So, having LDAP as user/auth backend is nice, but you should consider this at an early stage and not when you already have a plenty of services and users on your services. 😉</p>



<p class="wp-block-paragraph">However, it&#8217;s even nicer when you can use Single Sign On (SSO) with your apps. I got a taste of SSO when I was doing Cisco UC stuff and liked it that I don&#8217;t need to enter my credentials over and over again. SSO is also possible with UCS, so I wanted to give it a try on my own server. </p>



<p class="wp-block-paragraph">The official <a href="https://help.univention.com/t/reconfigure-ucs-single-sign-on/16161" data-type="URL" data-id="https://help.univention.com/t/reconfigure-ucs-single-sign-on/16161">HowTo on setting up SAML SSO</a> basically covers the process of setting it up, but my impression was, that this process can be made better, less error-prone and more reproducible by automatting the setup. </p>



<p class="wp-block-paragraph">So I wrote in my spare time a small shell script to follow the instructions from the official HowTo and after many tests and enhancements, I released the script on <a href="https://codeberg.org/Windfluechter/setupSSO.sh" data-type="URL" data-id="https://codeberg.org/Windfluechter/setupSSO.sh">Codeberg: setupSSO.sh</a>.</p>



<p class="wp-block-paragraph">So, what are the benefits of setupSSO.sh over the official HowTo?</p>



<ul class="wp-block-list"><li>reproducible </li><li>reduces copy &amp; paste errors by automation</li><li>works from Primary Directory Node (PDN) by logging into other Directory Nodes via SSH</li><li>asks you some simple configuration settings instead of ing you to change the code snippets from the HowTo</li><li>asks you for the passwords beforehand, e.g. if you are using a single password for all servers or different passwords.</li><li>checks for hostnames in SSL certs </li><li>checks your Identity Provider (IdP) SSL certs for validity and create a new IdP SSL cert if validity is shorter than 1 year, otherwise it will reuse the existing cert. </li><li>maybe some more benefits. </li></ul>



<p class="wp-block-paragraph">So, if you are using UCS as well, you might want to have a look into setupSSO.sh when you are using SSO as well or plan to do so. </p>



<p class="wp-block-paragraph">Disclaimer 2: As said I did this script in my spare time, so there is no support for it by Univention. Feedback via Codeberg is appreciated, of course. </p>
]]></content:encoded>
					
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>New Server  &#8211; NVMe Issues</title>
		<link>https://blog.windfluechter.net/2022/03/24/new-server-nvme-issues/</link>
					<comments>https://blog.windfluechter.net/2022/03/24/new-server-nvme-issues/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Thu, 24 Mar 2022 09:49:26 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[NVMe]]></category>
		<category><![CDATA[Server]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3333</guid>

					<description><![CDATA[My current server is somewhat aged. I bought it new in July 2014 with a 6-core Xeon E5-2630L, 32 GB RAM and 4x 3.5&#8243; hot-swappable drives. Gladly I had the opportunity to extend the memory to 128 GB RAM at... <a href="https://blog.windfluechter.net/2022/03/24/new-server-nvme-issues/" class="readmore">Read more<span class="screen-reader-text">New Server  &#8211; NVMe Issues</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">My current server is somewhat aged. I bought it new in July 2014 with a 6-core Xeon E5-2630L, 32 GB RAM and 4x 3.5&#8243; hot-swappable drives. Gladly I had the opportunity to extend the memory to 128 GB RAM at no additional cost by using memory from my ex-employer. It also has 4x 2 TB WD Red HDDs with 5400 rpm hooked up to the SATA backplane, but unfortunately only two of them are SATA-3 with 6 Gbit/s. </p>



<p class="wp-block-paragraph">The new server is a used/refurbished Supermicro server with 2x 14-core Xeon E5-2683 and 256 GB RAM and 4x 3.5&#8243; hot-swappable drives. It also came with a Hardware-RAID SAS/SATA 8-port controller with BBU. I also ordered two slim drive kits (<a href="https://www.supermicro.com/en/products/accessories/drivekit/MCP-220-81504-0N.php">MCP-220-81504-0N</a> &amp; <a href="https://www.supermicro.com/en/products/accessories/drivekit/MCP-220-81506-0N.php">MCP-220-81506-0N</a>) to be able to use 2x 3.5&#8243; slots for rotational HDDs as a cheap storage. Right now I added 2x 128 GB Supermicro SATA DOMs, 4x WD Red 4 TB SSDs and a Sonnet Fusion 4&#215;4 Silent and 4x 1 TB Seagate Firecuda 520 NVMe disks. </p>



<p class="wp-block-paragraph">And here the issue starts: </p>



<p class="wp-block-paragraph">The NVMe should be capable of 4-5 GB/s, but they are connected to a PCIe 3.0 x16 port via the Sonnet Fusion 4&#215;4, which itself features a PCIe bridge, so bifurbacation is not necessary. </p>



<p class="wp-block-paragraph">When doing some tests with bonnie++ I get around 1 GB/s transfer rates out of a RAID10 setup with all 4 NVMes. In fact, regardless of the RAID level there are only transfer rates of about 1 &#8211; 1.2 GB/s with bonnie++. (All software RAIDs with mdadm.)</p>



<p class="wp-block-paragraph">But also when constructing a RAID each NVMe gives around 300-600 MB/s in sync speed &#8211; except for one exception: RAID1. </p>



<p class="wp-block-paragraph">Regardless of how many NVMe disks in a RAID1 setup the sync speed is up to 2.5 GB/s for each of the NVMe disks. So the lower transfer rates with bonnie++ or other RAID levels shouldn&#8217;t be limited by bus speed nor by CPU speed. Alas, atop shows upto 100% CPU usage for all tests. I even tested </p>



<p class="wp-block-paragraph">In my understanding RAID10 should perform similar to RAID1 in terms of syncing and better and while bonnie++ tests (up to 2x write and 4x read speed compared to a single disk). </p>



<p class="wp-block-paragraph">For the bonnie++ tests I even made some tests that are <a href="https://windfluechter.org/s/ePRW2FGGYWWpnfK">available here</a>. You can find the test parameters listed in the hostname column: Baldur is the hostname, then followed by the layout (near-2, far-2, offset-2), chunk size and concurrency of bonnie++. In the end there was no big impact of the chunk size of the RAID. </p>



<p class="wp-block-paragraph">So, now I&#8217;m wondering what the reason for the &#8220;slow&#8221; performance of those 4x NVMe disks is? Bus speed of the PCIe 3.0 x16 shouldn&#8217;t be the cause, because I assume that the software RAID will need to transfer the blocks in RAID1 as well as in RAID10 over the bus. Same goes for the CPU: the amount of CPU work should be roughly the same for RAID1 and for RAID10. RAID10 should even have an advantage because the blocks only need to be synced to 2 disks in a stripe set. </p>



<p class="wp-block-paragraph">Bonnie++ tests are a different topic for sure. But when testing reading with dd from the md-devices I &#8220;only&#8221; get around 1-1.5 GB/s as well. Even when using LVM RAID instead of LVM on top of md RAID. </p>



<p class="wp-block-paragraph">All NVMe disks are already set to 4k and IO scheduler is set to mq-deadline. </p>



<p class="wp-block-paragraph">Is there anything I could do to improve the performance of the NVMe disks? On the other head, pure transfer rates are not that important to a server that runs a dozen of VMs. Here the improved IOPS performance over rotation disks is a clear performance gain. But I&#8217;m still curious if I could get maybe 2 GB/s out of a RAID10 setup with the NVMe disks. Then again having two independent RAID1 setups for MariaDB and for PostgreSQL databases might be a better choice over a single RAID10 setup? </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2022/03/24/new-server-nvme-issues/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>Old Buildd.Net Database</title>
		<link>https://blog.windfluechter.net/2022/02/11/old-buildd-net-database/</link>
					<comments>https://blog.windfluechter.net/2022/02/11/old-buildd-net-database/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Fri, 11 Feb 2022 18:05:18 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[BuilddNet]]></category>
		<category><![CDATA[PostgreSQL]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3329</guid>

					<description><![CDATA[Since March/April 2000 I was deeply involved in Debian m68k and operated multiple m68k autobuilder for over a decade. In fact my Amiga 3000 named &#8220;arrakis&#8221; was the second buildd for m68k in addition to the Debian owned Amiga 3000UX... <a href="https://blog.windfluechter.net/2022/02/11/old-buildd-net-database/" class="readmore">Read more<span class="screen-reader-text">Old Buildd.Net Database</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Since March/April 2000 I was deeply involved in Debian m68k and operated multiple m68k autobuilder for over a decade. In fact my Amiga 3000 named &#8220;arrakis&#8221; was the second buildd for m68k in addition to the Debian owned Amiga 3000UX named &#8220;kullervo&#8221;. </p>



<p class="wp-block-paragraph">Back in that time there was some small website running on Kullervo to display some information about the Debian autobuilder. After some time we (as m68k porters) moved that webpage away from Kullervo to my root server. Step by step this site evolved to Buildd.Net and extended to other archs and &#8220;suites&#8221; beside unstable like backports or non-volatile. The project got more and more complex and beyond my ability to do a complete necessary rewrite. </p>



<p class="wp-block-paragraph">So, in <a href="https://blog.windfluechter.net/2016/06/05/1724-request-adoption-builddnet-project/">2016 I asked for adoption</a> of the project and in 2018 I shut it down, because (apparently) there was nobody taking over. From November 2005 until January 2018 I do have entries in my PostgreSQL database for Buildd.Net. </p>



<p class="wp-block-paragraph">I think the data in the database might be interesting for those that want to examine that data. You can use the data to see how build times have increased over time, which e.g. led to the expulsion of m68k as release arch, because the arch couldn&#8217;t keep up anymore. I could imagine that you could do other interesting analysis with that data. For example how new versions of the toolchain increased the build times, maybe even if a specific version of e.g. binutils or gcc had a positive effect on certain archs, but a negative effect on other archs. </p>



<p class="wp-block-paragraph">If there is interest in this data I could open the database to the public or even upload the dump of the database so that you can download and install it on your own. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2022/02/11/old-buildd-net-database/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>XMPP and Mail Clients</title>
		<link>https://blog.windfluechter.net/2022/01/31/xmpp-and-mail-clients/</link>
					<comments>https://blog.windfluechter.net/2022/01/31/xmpp-and-mail-clients/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Mon, 31 Jan 2022 20:06:25 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[XMPP]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3321</guid>

					<description><![CDATA[I really like XMPP, but I&#8217;m a little unhappy about the current general situation of XMPP. I think XMPP could do better if there were some benefits of having an XMPP address. For me one of those benefits is to... <a href="https://blog.windfluechter.net/2022/01/31/xmpp-and-mail-clients/" class="readmore">Read more<span class="screen-reader-text">XMPP and Mail Clients</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I really like XMPP, but I&#8217;m a little unhappy about the current general situation of XMPP. I think XMPP could do better if there were some benefits of having an XMPP address. For me one of those benefits is to have the option to have just one address I need to communicate to others. If everything is in place and well-configured, a user can be reached by mail, XMPP and SIP (voice/video calls) by just one address. </p>



<p class="wp-block-paragraph">To address this I would like to see XMPP support in mail clients (MUAs). So when you reply to a mail or write a new one, the client will do a lookup in your addressbook if the address has an XMPP field associated with it and (if not) do a DNS lookup for _xmpp-server._tcp.example.com (or the matching domain part of recipients address). If there is an XMPP address listed in mail header, that JID will be used. When the lookup is successful and an xmpp: protocol handler is configured in the system, the MUA offers an option to begin a chat with the recipient and/or displays the presence status of the recipients (depending on available web-presence or presence subscription). </p>



<p class="wp-block-paragraph">Basically a good candidate could be Thunderbird, because it already has XMPP support built in, albeit not a good implementation and lacking many modern features like OMEMO. But for basic functions (like presence status and such) it should be sufficient for a start. </p>



<p class="wp-block-paragraph">Other candidates could be Evolution, Kmail (as KDE MUA and Kaidan as a native KDE XMPP client) or even Apple Mail.app, because Apples addressbook supports XMPP fields for each contact. </p>



<p class="wp-block-paragraph">Basically the same could be done for SIP contacts: if a SIP SRV record for that domain does exist, the MUA could offer an option to call the recipient. </p>



<p class="wp-block-paragraph">I would be willing to give some money via Bountysource or similar platforms. Is anyone aware of such a project or willing to write some addons? Maybe within the GSoC?</p>



<p class="wp-block-paragraph">PS: there is <a href="https://www.rfc-editor.org/rfc/rfc7259.html">RFC7259</a> about Jabber/XMPP JID in mail headers and there is also a page in the <a href="https://wiki.xmpp.org/web/Jabber_Email_Header">XMPP.org wiki</a>. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2022/01/31/xmpp-and-mail-clients/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>Moving my repositories from Github to Codeberg.org</title>
		<link>https://blog.windfluechter.net/2022/01/07/moving-my-repositories-from-github-to-codeberg-org/</link>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Fri, 07 Jan 2022 22:50:16 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Software]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3316</guid>

					<description><![CDATA[Some weeks ago I moved my repositories from Github (evil, Microsoft, blabla) to Codeberg. Codeberg is a non-profit organisation located in Germany. When you really dislike Microsoft products it is somewhat a natural reaction (at least for me) to move... <a href="https://blog.windfluechter.net/2022/01/07/moving-my-repositories-from-github-to-codeberg-org/" class="readmore">Read more<span class="screen-reader-text">Moving my repositories from Github to Codeberg.org</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Some weeks ago I moved my repositories from Github (evil, Microsoft, blabla) to <a href="https://codeberg.org/">Codeberg</a>. Codeberg is a non-profit organisation located in Germany. When you really dislike Microsoft products it is somewhat a natural reaction (at least for me) to move away from Github, which was bought by Microsoft, to some more independent service provider for hosting source code. Nice thing with Codeberg is as well that it offers a migration tool from Github to Codeberg. Additionally <a href="https://mastodon.technology/@codeberg">Codeberg is also on Mastodon</a>. If you are looking for a good service hosting your git repositories and want to move away from Github as well, please give Codeberg a try. </p>



<p class="wp-block-paragraph">So, please update your git settings to <code>https://github.com/ingoj</code> to <code>https://codeberg.org/Windfluechter</code>  (or the specific repo). </p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
		<item>
		<title>LetsEncrypt CA Chain Issues with Ejabberd</title>
		<link>https://blog.windfluechter.net/2021/09/29/letsencrypt-ca-chain-issues-with-ejabberd/</link>
					<comments>https://blog.windfluechter.net/2021/09/29/letsencrypt-ca-chain-issues-with-ejabberd/#comments</comments>
		
		<dc:creator><![CDATA[ij]]></dc:creator>
		<pubDate>Wed, 29 Sep 2021 21:49:27 +0000</pubDate>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Ejabberd]]></category>
		<category><![CDATA[LetsEncrypt]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[XMPP]]></category>
		<guid isPermaLink="false">https://blog.windfluechter.net/?p=3301</guid>

					<description><![CDATA[UPDATE: It&#8217;s not as simple as described below, I&#8217;m afraid&#8230; It appears that it&#8217;s not that easy to obtain new/correct certs from LetsEncrypt that are not cross-signed by DST Root X3 CA. Additionally older OpenSSL version (1.0.x) seems to have... <a href="https://blog.windfluechter.net/2021/09/29/letsencrypt-ca-chain-issues-with-ejabberd/" class="readmore">Read more<span class="screen-reader-text">LetsEncrypt CA Chain Issues with Ejabberd</span><span class="fa fa-angle-double-right" aria-hidden="true"></span></a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">UPDATE: <br>It&#8217;s not as simple as described below, I&#8217;m afraid&#8230; It appears that it&#8217;s not that easy to obtain new/correct certs from LetsEncrypt that are not cross-signed by DST Root X3 CA. Additionally older OpenSSL version (1.0.x) seems to have problems. So even when you think that your system is now ok, the remote server might refuse to accept your SSL cert. The same is valid for the SSL check on xmpp.net, which seems to be very outdated and beyond repair. </p>



<p class="wp-block-paragraph">Honestly, I think the solution needs to be provided by LetsEncrypt&#8230;  </p>



<hr class="wp-block-separator"/>



<p class="wp-block-paragraph">I was having some strange issues on my ejabberd XMPP server the other day: some users complained that they couldn&#8217;t connect anymore to the MUC rooms on my server and in the logfiles I discovered some weird warnings about LetsEncrypt certificates being expired &#8211; although they were just new and valid until end of December. </p>



<p class="wp-block-paragraph">It looks like this:</p>



<pre class="wp-block-preformatted"><code>[warning] &lt;0.368.0&gt;@ejabberd_pkix:log_warnings/1:393 Invalid certificate in /etc/letsencrypt.sh/certs/buildd.net/fullchain.pem: at line 37: certificate is no longer valid as its expiration date has passed</code></pre>



<p class="wp-block-paragraph">and&#8230;</p>



<pre class="wp-block-preformatted">[warning] &lt;0.18328.2&gt;@ejabberd_s2s_out:process_closed/2:157 Failed to establish outbound s2s connection nerdica.net -&gt; forum.friendi.ca: Stream closed by peer: Your server's certificate is invalid, expired, or not trusted by forum.friendi.ca (not-authorized); bouncing for 237 seconds</pre>



<p class="wp-block-paragraph">When checking out with some online tools like SSLlabs or XMPP.net the result was strange, because SSLlabs reported everything was ok while XMPP.net was showing the chain with X3 and D3 certs as having a short term validity of a few days: </p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="741" height="315" src="https://blog.windfluechter.net/wp-content/uploads/2021/09/Bildschirmfoto-2021-09-29-um-23.35.26.png" alt="" class="wp-image-3302" srcset="https://blog.windfluechter.net/wp-content/uploads/2021/09/Bildschirmfoto-2021-09-29-um-23.35.26.png 741w, https://blog.windfluechter.net/wp-content/uploads/2021/09/Bildschirmfoto-2021-09-29-um-23.35.26-640x272.png 640w" sizes="auto, (max-width: 741px) 100vw, 741px" /></figure>



<p class="wp-block-paragraph">After some days of fiddling around with the issue, trying to find a solution, it appears that there is a problem in Ejabberd when there are some old SSL certifcates being found by Ejabberd that are using the old CA chain. Ejabberd has a really nice feature where you can just configure a SSL cert directory (or a path containing wildcars. Ejabberd then reads all of the SSL certs and compare them to the list of configured domains to see which it will need and which not. </p>



<p class="wp-block-paragraph">What helped (for me at least) was to delete all expired SSL certs from my directory, downloading the current CA file pems from LetsEncrypt (see their <a href="https://letsencrypt.org/2020/09/17/new-root-and-intermediates.html">blog post from September 2020</a>), run <code>update-ca-certificates</code> and <code>ejabberdctl restart</code> (instead of just <code>ejabberdctl reload-config</code>). UPDATE: be sure to use dpkg-reconfigure ca-certificates to uncheck the DST Root X3 cert (and others if necessary) before renewing the certs or running update-ca-certificates. Otherwise the update will bring in the expired cert again. </p>



<p class="wp-block-paragraph">Currently I see at least two other XMPP domains in my server logs having certicate issues and in some MUCs there are reports of other domains as well.</p>



<p class="wp-block-paragraph">Disclaimer: Again: this helped me in my case. I don&#8217;t know if this is a bug in Ejabberd or if this procedure will help you in your case nor if this is the proper solution. But maybe my story will help you solving your issue if you experience SSL certs issues in the last few days, especially now that the R3 cert has already expired and the X3 cert following in a few hours. </p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.windfluechter.net/2021/09/29/letsencrypt-ca-chain-issues-with-ejabberd/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<friends:post-format>standard</friends:post-format>
	</item>
	</channel>
</rss>
