Rodeo Four Production Server: Difference between revisions

From CES IT Wiki
Jump to navigation Jump to search
Added cron jobs.
Updated information regarding certificates.
Line 38: Line 38:


===SSL===
===SSL===
Certificate is provided by Comodo through InCommon.  It has a term of three years.  It has been temporarily swapped out for a Let's Encrypt certificate due to a certificate lapse on September 9, 2018.  The Comodo certificate and key are located at the following paths respectively:
Certificate is provided by InCommon.  It has a term of two years.  On September 11, 2018, the certificate expired without notification.  It was replaced temporarily with a Let's Encrypt certificate, due to site inaccessibility.  The renewal application was initially rejected because three-year certificates were no longer supported.  A subsequent certificate – one listing ces-it@fas.harvard.edu as the email address – was applied for, approved, and installed on September 13.  The expired InCommon certificate and key are located at the following paths respectively:


  <nowiki>/etc/nginx-sp/certs/ces.fas.harvard.edu/ces1.unix.fas.harvard.edu.crt
  <nowiki>/etc/nginx-sp/certs/ces.fas.harvard.edu/ces1.unix.fas.harvard.edu.crt
Line 47: Line 47:
  <nowiki>/etc/letsencrypt/live/ces.fas.harvard.edu/fullchain.pem
  <nowiki>/etc/letsencrypt/live/ces.fas.harvard.edu/fullchain.pem
/etc/letsencrypt/live/ces.fas.harvard.edu/privkey.pem</nowiki>
/etc/letsencrypt/live/ces.fas.harvard.edu/privkey.pem</nowiki>
The new InCommon certificate and key are active and located at the following paths respectively:
<nowiki>/etc/ssl/certs/ces.fas.harvard.edu.cer
/etc/ssl/private/ces.fas.harvard.edu.key</nowiki>


====Cold standby====
====Cold standby====
In case of certificate lapse, uncomment the lines located in <code>/etc/nginx-sp/vhosts.d/ssl.conf</code> which point to the Let's Encrypt certificate and key.
In case of certificate lapse, uncomment the lines located in <code>/etc/nginx-sp/vhosts.d/ssl.conf</code> which point to the Let's Encrypt certificate and key.

Revision as of 14:47, 13 September 2018

Web Production Server
IP Address 45.55.45.195
Domain Name ces.fas.harvard.edu
Droplet Name ces.fas.harvard.edu-production
Platform Craft CMS 2.6.2911
Operating System Ubuntu 16.04 x64
Web engine Apache 2
PHP Version 7
Database Server MariaDB
Host DigitalOcean
Region NYC3
Public Launch Date July 13, 2016

The web production server is a public-facing web application and database server that hosts the website. It was designed and developed by Mildly Geeky, with additional features and bug fixes performed by Shotgun Flat. The server was provisioned by Peter Stevens using a DigitalOcean droplet. It features directory information for Center affiliates, a calendar of events, information about opportunities provided by the Center, news relating to the Center and its affiliates, and publications.

Website updates

In July 2017, Gila Naderi began conversations with Mike McKenna on the 2018 Website Update Pilot Project.

Cron jobs

  • Every Sunday at 8am, the server will execute /etc/cron.d/certrenewal. Note: the Let's Encrypt certificates may not be used by the web engine. They are stored as a standby in case of certificate lapses.

Security

Password authentication

Password authentication is temporarily turned on due to permission denied error messages.

SSL

Certificate is provided by InCommon. It has a term of two years. On September 11, 2018, the certificate expired without notification. It was replaced temporarily with a Let's Encrypt certificate, due to site inaccessibility. The renewal application was initially rejected because three-year certificates were no longer supported. A subsequent certificate – one listing ces-it@fas.harvard.edu as the email address – was applied for, approved, and installed on September 13. The expired InCommon certificate and key are located at the following paths respectively:

/etc/nginx-sp/certs/ces.fas.harvard.edu/ces1.unix.fas.harvard.edu.crt
/etc/nginx-sp/certs/ces.fas.harvard.edu/ces1.unix.fas.harvard.edu.key

The Let's Encrypt certificate and key are located at the following paths respectively:

/etc/letsencrypt/live/ces.fas.harvard.edu/fullchain.pem
/etc/letsencrypt/live/ces.fas.harvard.edu/privkey.pem

The new InCommon certificate and key are active and located at the following paths respectively:

/etc/ssl/certs/ces.fas.harvard.edu.cer
/etc/ssl/private/ces.fas.harvard.edu.key

Cold standby

In case of certificate lapse, uncomment the lines located in /etc/nginx-sp/vhosts.d/ssl.conf which point to the Let's Encrypt certificate and key.