[–] 11 points 5 hours ago*

Lustig wie die Bundes-CDU in Berlin unverhohlen mit den "Konsequenzen" droht, sollte jemand mit den Linken regieren (inklusive absolut unwürdiger Idee, wie die im Grundgesetz vorgesehene Vergesellschaftung zu verbieten, oder dem Bundesland den Geldhahn abdrehen zu wollen), aber auf der anderen Seite in Sachsen-Anhalt brav still ist, während ihr eigener Landesverband freiwillig, unnötig und ohne jeden Zwang für AfD Politiker stimmt, die deren Stimmen nicht mal benötigen. Deutlicher kann man nicht auch dem Letzten verkünden, welche Faschisten ihre Wunschkoalitionspartner sind.

  • source
  • [–] 1 point 6 hours ago*

    Is the rise of AfD in Germany a concern, what has the other parties done to slow it down?

    Nothing. All they do is help accelerating the AfD's rise by parroting any lie the AfD tells. Because the AfD isn't a problem for them but the chance to finally get rid of that pesky democracy that sets limits on their corruption.

    That's the common denominator for all "conservatives". If they have to chose between democracy and power they will chose the latter every single time.

    Their only other option would be actual sensible policies. But that's not actually a real option if you are deeply corrupt and just looking for a way to implement policies for your ultra-rich donors. So diversion via culture war and right-wing propaganda it is instead. Not a long-term solution when you will be eaten up by far-right parties this way. But who cares for long-term when it's about money and nice board positions now...

    (And so they are happily abolishing transparency laws already while helping to implement more surveilance and more police powers. Because they are totally not planning to cooperate with fascists soon *wink wink*.)

  • source
  • [–] 1 point 6 hours ago

    If you use the shortlived profile and your key is compromised, you benefit from the short lifetime.

    Maybe I'm just too stupid to understand how those certificates work.

    But in what scenario is my key compromised but not my server? Because someone getting control of my server can just get an new long-term certificate. That was my actual point in the comment above. I understand the argument of added security if they only issue short-term certificates. But where is the benefit of my short-term certificate when someone compromising my server can just get a new long-term one in seconds?

    Also we are talking about self hosting. I understand the issue of revoking certificates when you have a massive userbase where some might miss the revocation for quite some time. Not so much with the dozen max family and friends.

  • source
  • parent
  • context
  • [–] 2 points 6 hours ago* (last edited 6 hours ago)

    Keine Ahnung... ich überprüfe selten die Halbarkeitsdaten, um zu sehen wie lange Müllermilch Flaschen im Regal stehen bleiben. Aber es gibt wohl genug Leute, die damals bei der Aktion Vorräte angelegt haben, denn ich seh auch heute noch häufiger lustige Aufkleber wie diese hier:

    Und bei Milchprodukten kann man ja dank Kennzeichnung immer gut nachschauen, aus welchem Werk Produkte mit anderer Markenbezeichnung stammen.

    PS: Ich muss allerdings auch ehrlich zugeben, dass ich nicht weiß wer Müllermilch im speziellen überhaupt je gekauft hat. In meinen Augen war das seit jeher überteuerter Mist, den ich in der selben Qualität auch für einen Bruchteil des Preises bekomme.

    Und gerade da seh ich halt auch eher die (nicht politisch motivierten) Parallelen. Die ganzen überteuerten Schokoladensorten haben ja beispielsweise gerade das selbe Problem, nicht mit dem Umsatz an Schokolade, sondern speziell mit ihren Produkten. Aber auch darüber verliert Müller selbstverständlich kein Wort. Nein, das Problem ist der Unwille der Kunden ihre Saucen im Glas zu kaufen.

  • source
  • parent
  • context
  • [–] 1 point 6 hours ago*

    That's the result of decades of neo-liberal propaganda frying brains: If the current (right-wing) policies are bad for you, voting for the even more right-wing, more stupid, more corrupt alternative is your only option. After all –as your damaged brain tells you– everything further to the left wants to destroy the country (or kill you and replace you with some refugee from Africa or destroy all industry because of their insane ideology or... two dozen of other narratives).

  • source
  • parent
  • context
  • [–] 1 point 7 hours ago* (last edited 6 hours ago)

    As of the manpages systemd-sleep looks for:

    The main configuration file is loaded from one of the listed directories in order of priority, only the first file found is used: /etc/systemd/, /run/systemd/, /usr/local/lib/systemd/, /usr/lib/systemd/.

    Also

    The default configuration is set during compilation, so configuration is only needed when it is necessary to deviate from those defaults.

    So yes, you can use any existing file from another computer as your template (root:root 644 would be the default owner/permissions for it).

    PS: I tried on my PC and setting AllowHibernation=no in the config file produced a different "hibernate is disabled by config" error. Only if I remove the resume=<swap location> kernel parameter do I get the "not set up" error you mentioned but I'm not at home and only have my old (encrypted and able to hibernate) bios laptop with me. So I can't check this for modern UEFI where systemd-sleep should automatically pick a suitable swap space and save the location in an EFI variable without any additional configuration.

    You can however set the resume=UUID=<your swap's UUID> kernel parameter anyway. Even the automatic systemd/uefi setup accepts this as a way to manually select a location. So maybe you try that. If your problem is decryption of the swap at startup you should not get an error when initiating the hibernation as you do now but instead get problems when you try to restart from swap.

  • source
  • parent
  • context
  • [–] 14 points 7 hours ago

    Vom wem denn? Sie tut doch genau das, was die C*U für ihre überreichen Spender und fossilen Lobbyisten getan haben möchte. Und der wahnhaft dumme Deutsche denkt sich mehrheitlich, "Ja, die Partei wähl ich wieder" oder "Ich möchte das selbe in noch korrupter und noch dümmer, aber in alternativem Blauton".

    Katherina Reiche ist kein Problem, sondern genau das was die Mehrheit in Deutschland will und verdient. Wenn dem nicht so ist, könnten sie jederzeit aufhören, in ihrer Wahlenscheidung nur zwischen Stillstand und Verfall oder aktiver Zerstörung zu schwanken.

  • source
  • parent
  • context
  •  

    As this will -thanks to me being quite clueless- be a very open question I will start with the setup:

    One nginx server on an old Raspi getting ports 80 and 443 routed from the access point and serving several pages as well as some reverse proxies for other sevices.

    So a (very simplified) nginx server-block that looks like this:

    # serve stuff internally (without a hostname) via http
    server {
    	listen 80 default_server;
    	http2 on;
    	server_name _; 
    	location / {
    		proxy_pass http://localhost:5555/;
                    \# that's where all actual stuff is located
    	}
    }
    # reroute http traffic with hostname to https
    server {
    	listen 80;
    	http2 on;
    	server_name server_a.bla;
    	location / {
    		return 301 https://$host$request_uri;
    	}
    }
    server {
    	listen 443 ssl default_server;
    	http2 on;
    	server_name server_a.bla;
       	ssl_certificate     A_fullchain.pem;
        	ssl_certificate_key A_privkey.pem;
    	location / {
    		proxy_pass http://localhost:5555/;
    	}
    }
    #actual content here...
    server {
    	listen 5555;
    	http2 on;
        	root /srv/http;
    	location / {
            	index index.html;
       	} 
        	location = /page1 {
    		return 301 page1.html;
    	}
        	location = /page2 {
    		return 301 page2.html;
    	}
            #reverse proxy for an example webdav server 
    	location /dav/ {
    		proxy_pass        http://localhost:6666/;
    	}
    }
    

    Which works well.

    And intuitively it looked like putting Anubis into the chain should be simple. Just point the proxy_pass (and the required headers) in the "port 443"-section to Anubis and set it to pass along to localhost:5555 again.

    Which really worked just as expected... but only for server_a.bla, server_a.bla/page1 or server_a.bla/page2.

    server_a.bla/dav just hangs and hangs, to then time out, seemingly trying to open server_a.bla:6666/dav.

    So long story short...

    How does proxy_pass actually work that the first setup works, yet the second breaks? How does a call for localhost:6666 (already behind earlier proxy passes in both cases) somehow end up querying the hostname instead?

    And what do I need to configure -or what information/header do I need to pass on- to keep the internal communication intact?

    view more: next ›