#12835 some improvements on smtp-auth-cc-rdu01.fedoraproject.org
Closed: Migrated to Fedora Forge by ryanlerch. Opened by kevin.

A few improvements we need to do on this machine.

This vm is used to relay (authenticated) emails out to people from various places (copr cron outputs, flock / conference stuff, packager reports).

  1. It would be nice to adjust postfix config to not leak the headers/ips from the orig systems, ie something like https://serverfault.com/a/998993 or the like

  2. The ssl cert on this machine is a self signed one, but it's also expired. Would be nice to generate a new one and make sure to keep it up to date.


Metadata Update from @james:
- Issue priority set to: Waiting on Assignee (was: Needs Review)
- Issue tagged with: low-gain, medium-trouble

The cert has been fixed.

The config change hasn't been done yet.

I imported the new self-signed cert into my local trust store and tried to run the orphans email script without disabling tls verification. It now fails with Error: tls: failed to verify certificate: x509: certificate relies on legacy Common Name field, use SANs instead. Would it be possible to fix this or to use a letsencrypt cert? If the server can have port 80 opened, one could be gotten with the HTTP-01 challenge and auto-renewed with certbot or similar.

I don't think I like the idea of running a web server on this instance just for this... it exposes it a lot more. :(

@james might you be able to look at a new cert without this problem above?

This issue has been migrated to Fedora Forge:
https://forge.fedoraproject.org/infra/tickets/issues/12835

Please continue any further discussion there.

Metadata Update from @ryanlerch:
- Issue close_status updated to: Migrated to Fedora Forge
- Issue status updated to: Closed (was: Open)

Metadata