[SAC] FWD: [SECURITY] [DSA 2360-1] Two month advance notification for upcoming end-of-life for Debian oldstable (lenny)

Hi SAC,

http://seclists.org/bugtraq/2011/Dec/30
is an advance notice that security support for Debian GNU/Linux 5.0
(code name "lenny") will be terminated in two months.
The security support for the old release of 5.0 is going
to end on the 6th of February 2012 as previously announced.

We need to upgrade all (almost) OSGeo machines to the
current stable release.
Is there anything special to consider for the VMs?

Markus

On Fri, Dec 09, 2011 at 07:42:53PM +0100, Markus Neteler wrote:

Is there anything special to consider for the VMs?

I'm already in preparation of such upgrade for the Wiki VM and given
the fact that these VM's are running a regular distro kernel I don't
expect any major trouble.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

Hi,

I plan on upgrading the adhoc VM to Squeeze tomorrow, starting at
00:00 UTC Sat 18 Dec. That's about 23 hours from now.
Expected downtime ~ 1 hour.

Hamish

Hamish wrote:

I plan on upgrading the adhoc VM to Squeeze tomorrow,
starting at 00:00 UTC Sat 18 Dec. That's about 23 hours from
now.

Hi,

well, I got as far as upgrading the stuff which didn't need dist-upgrade,
then the kernel and udev, but upon rebooting directly after installing
udev it doesn't seem to want to come back up. :frowning:
maybe stuck on fsck wanting to press "c" to continue or something..?

manual edits (sync with earlier custom mods) of note were to bootmisc.sh
and hosts.deny.

some host level intervention on the non-virtual machine is requested to
see what the trouble is..

thanks,
Hamish

On Sat, Dec 17, 2011 at 06:02:33PM -0800, Hamish wrote:

well, I got as far as upgrading the stuff which didn't need dist-upgrade,
then the kernel and udev, but upon rebooting directly after installing
udev [...]

For the next distro upgrade of any OSGeo VM I'd recommend to draw a
well-defined line. Rebooting is safe after upgrading ("aptitude
install") apt, aptitude, dpkg plus their required dependencies. But
everything past this point, including kernel environment and boot
loader, should be done in one single "dist-upgrade" without further
reboot.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

Hamish wrote:
> well, I got as far as upgrading the stuff which didn't need
> dist-upgrade, then the kernel and udev, but upon rebooting
> directly after installing udev [...]

Martin wrote:

For the next distro upgrade of any OSGeo VM I'd recommend
to draw a well-defined line. Rebooting is safe after upgrading
("aptitude install") apt, aptitude, dpkg plus their required
dependencies. But everything past this point, including kernel
environment and boot loader, should be done in one single
"dist-upgrade" without further reboot.

... simply following the order of ceremonies from
  http://www.debian.org/releases/stable/amd64/release-notes/ch-upgrading.en.html#upgrading-udev

which recommends that you take care of the kernel & udev + reboot before
the doing the dist-upgrade.

we'll see what happened soon enough, Alex was kind enough to pass a request
to osuosl & I was logging the session up to that point.

Hamish

ps- mod file was /etc/init.d/denyhosts not hosts.deny btw

Since the 6th of February 2012 is approaching quickly, we should
get a plan for the other machines to be updated.

I would like to get the projectsVM updated soon and I am willing to
do that (maybe with some remote assistance backup from others).

No idea though about the other systems awaiting update.

Markus

On Sun, Jan 22, 2012 at 05:08:45PM +0100, Markus Neteler wrote:

No idea though about the other systems awaiting update.

As far as I can tell, the only systems having seen a dist-upgrade are
"wiki" and "adhoc". To be honest, my main motivation for upgrading the
Wiki was to get a newer PHP version as a preparatory step for a
MediaWiki update ....

I'll take care of the "secure" and the "backup" VM. I'm planning to do
the dist-upgrade on "secure" this monday starting at approx. 15:00 UTC
In contrast, the "backup" is pretty non-critical because it's idling
most of the day.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Sun, Jan 22, 2012 at 05:34:35PM +0100, Martin Spott wrote:

I'll take care of the "secure" and the "backup" VM. I'm planning to do
the dist-upgrade on "secure" this monday starting at approx. 15:00 UTC

Sorry, I had been away on the road at this time, next try this
wednesday, same time,

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Mon, Jan 23, 2012 at 07:48:19PM +0100, Martin Spott wrote:

On Sun, Jan 22, 2012 at 05:34:35PM +0100, Martin Spott wrote:

> I'll take care of the "secure" and the "backup" VM. I'm planning to do
> the dist-upgrade on "secure" this monday starting at approx. 15:00 UTC

Sorry, I had been away on the road at this time, next try this
wednesday, same time,

Starting to dist-upgrade the "secure" VM now, expect occasional LDAP
outages,

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Jan 25, 2012 at 04:03:28PM +0100, Martin Spott wrote:

On Mon, Jan 23, 2012 at 07:48:19PM +0100, Martin Spott wrote:
> On Sun, Jan 22, 2012 at 05:34:35PM +0100, Martin Spott wrote:
>
> > I'll take care of the "secure" and the "backup" VM. I'm planning to do
> > the dist-upgrade on "secure" this monday starting at approx. 15:00 UTC
>
> Sorry, I had been away on the road at this time, next try this
> wednesday, same time,

Starting to dist-upgrade the "secure" VM now, expect occasional LDAP
outages,

Network trouble @ OSUOSL ? Anyone having access to the Wiki pages ? Or
is this just me ?

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Jan 25, 2012 at 04:37:45PM +0100, Martin Spott wrote:

Network trouble @ OSUOSL ? Anyone having access to the Wiki pages ? Or
is this just me ?

Can anyone read http://www.osuosl.org/ or http://ganeti.osuosl.org/ ?

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Jan 25, 2012 at 04:03:28PM +0100, Martin Spott wrote:

Starting to dist-upgrade the "secure" VM now, expect occasional LDAP
outages,

Dist-upgrade of the "secure" VM is mostly over and LDAPS should be
working. Anyhow, I still have to deal with the boot loader and will
finally issue two reboots,

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Jan 25, 2012 at 06:26:07PM +0100, Martin Spott wrote:

Dist-upgrade of the "secure" VM is mostly over and LDAPS should be
working. Anyhow, I still have to deal with the boot loader and will
finally issue two reboots,

Ok, I think I've finished the journey. Please test, test, test,

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Jan 25, 2012 at 06:34:24PM +0100, Martin Spott wrote:

On Wed, Jan 25, 2012 at 06:26:07PM +0100, Martin Spott wrote:

> Dist-upgrade of the "secure" VM is mostly over and LDAPS should be
> working. Anyhow, I still have to deal with the boot loader and will
> finally issue two reboots,

Ok, I think I've finished the journey. Please test, test, test,

Mmmmh, looks like the OSUOSL sites are unavailable again ....

  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Sun, Jan 22, 2012 at 5:08 PM, Markus Neteler <neteler@osgeo.org> wrote:

Since the 6th of February 2012 is approaching quickly, we should
get a plan for the other machines to be updated.

I would like to get the projectsVM updated soon and I am willing to
do that (maybe with some remote assistance backup from others).

I would do that more or less now. Hanging out in IRC, too.

Markus

On Wed, Feb 1, 2012 at 11:16 PM, Markus Neteler <neteler@osgeo.org> wrote:

On Sun, Jan 22, 2012 at 5:08 PM, Markus Neteler <neteler@osgeo.org> wrote:

I would like to get the projectsVM updated soon and I am willing to
do that (maybe with some remote assistance backup from others).

I would do that more or less now. Hanging out in IRC, too.

Done so, all updated.
But: reboot seems to fail, so console access is needed (how?).

Just in case:
I made a copy of /etc in /backup_projectsVM_etc/

Markus

On Wed, Feb 1, 2012 at 5:15 PM, Markus Neteler <neteler@osgeo.org> wrote:

On Wed, Feb 1, 2012 at 11:16 PM, Markus Neteler <neteler@osgeo.org> wrote:

On Sun, Jan 22, 2012 at 5:08 PM, Markus Neteler <neteler@osgeo.org> wrote:

I would like to get the projectsVM updated soon and I am willing to
do that (maybe with some remote assistance backup from others).

I would do that more or less now. Hanging out in IRC, too.

Done so, all updated.
But: reboot seems to fail, so console access is needed (how?).

Just in case:
I made a copy of /etc in /backup_projectsVM_etc/

Folks,

I will try to followup with OSU OSL. In the meantime the Projects
VM (gdal.org, mapserver.org grass.org and other stuff) is down.

  http://wiki.osgeo.org/wiki/ProjectsVM

I'll try to be available in #telascience or #osgeo to consult on this
matter. I will
also notify OSGeo discuss and the gdal-dev and mapserver-users list of the
extended downtime.

Best regards,
--
---------------------------------------+--------------------------------------
I set the clouds in motion - turn up | Frank Warmerdam, warmerdam@pobox.com
light and sound - activate the windows | http://pobox.com/~warmerdam
and watch the world go round - Rush | Geospatial Software Developer

I would note that I didn't complete the old packages
purging on the projectsVM.

Markus

Since it's not in regular production use all over the day, I'll be
upgrading the backup machine later today as my schedule permits.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------