Bug #16121

Migrate our Schleuder lists outside of boum.org

Added by intrigeri 2018-11-12 15:28:42 . Updated 2019-02-21 21:16:39 .

Status:
Resolved
Priority:
Normal
Assignee:
groente
Category:
Infrastructure
Target version:
Start date:
2018-12-11
Due date:
% Done:

100%

Feature Branch:
Type of work:
Sysadmin
Blueprint:

Starter:
Affected tool:
Deliverable for:

Description


Subtasks

Feature #16217: Migrate some of our Schleuder lists to puscii Resolved

100

Feature #16218: Migrate some of our Schleuder lists to lizard Resolved

100

Bug #16251: Fix tails@ configuration Rejected groente

0

Bug #16252: Schleuder keys update cronjob fails for our lists at puscii Resolved

100

Bug #16254: Update sysadmin team doc wrt. new services: Schleuder and DNS Resolved

100

Bug #16256: SPF issue while sending mail to lists hosted by puscii Resolved groente

0


Related issues

Related to Tails - Bug #16255: puscii fails to deliver email to boum.org Resolved 2018-12-28
Related to Tails - Bug #16767: Schleuder mailing lists non functional: MXs of Autistici/Inventati are misconfigured Resolved
Blocks Tails - Feature #13284: Core work: Sysadmin (Adapt our infrastructure) Confirmed 2017-06-30

History

#1 Updated by intrigeri 2018-11-12 15:28:48

  • blocks Feature #13284: Core work: Sysadmin (Adapt our infrastructure) added

#2 Updated by intrigeri 2018-11-12 15:30:30

Some of these lists should be self-hosted while some others will be hosted at puscii.nl. Which ones exactly is under discussion.

Regarding email routing and DNS setup, initial rough draft:

  • the MX for tails.b.o points to lizard
  • the canonical address for lists hosted at lizard becomes tails.b.o * the canonical address for lists hosted at puscii becomes puscii.nl
  • for backwards compatibility, the current @b.o addresses are redirected to the new ones; that would be set up wherever the b.o MX will point to, likely A/I; I’m not sure how best this would be implemented

#3 Updated by groente 2018-11-12 16:07:16

> * the MX for tails.b.o points to lizar
> * the canonical address for lists hosted at lizard becomes tails.b.o > * the canonical address for lists hosted at puscii becomes puscii.nl

migrating schleuder lists becomes a lot easier when you don’t change their name. that way, you won’t have to add identities to the PGP keys, which is probably going to be manual labour.

> * for backwards compatibility, the current @b.o addresses are redirected to the new ones; that would be set up wherever the b.o MX will point to, likely A/I; I’m not sure how best this would be implemented

instead of redirects, we can use transport maps to send the @b.o mail to the right server handling that particular list.

#4 Updated by intrigeri 2018-11-15 12:21:18

> migrating schleuder lists becomes a lot easier when you don’t change their name. that way, you won’t have to add identities to the PGP keys, which is probably going to be manual labour.

I’m not concerned about adding a few UIDs to a dozen keys or so.

>> * for backwards compatibility, the current @b.o addresses are redirected to the new ones; that would be set up wherever the b.o MX will point to, likely A/I; I’m not sure how best this would be implemented

> instead of redirects, we can use transport maps to send the @b.o mail to the right server handling that particular list.

Yeah, that was one of the options I had in mind when I wrote “redirected” :)

#5 Updated by intrigeri 2018-12-09 16:48:06

For now, we won’t change canonical addresses but will ensure the boum.org MX has aliases redirecting to the new hosting providers. Later on, if we get our own domain name or decide to postpone the topic for the foreseeable future, we might want to remove this layer of indirection in order to have one less point of failure (the boum.org MX): add UIDs to the GnuPG keys, make the new hosting location’s domain the canonical addres of the lists, and after a while drop the backwards compat aliases.

#6 Updated by groente 2018-12-09 17:04:07

intrigeri wrote:
> For now, we won’t change canonical addresses but will ensure the boum.org MX has aliases redirecting to the new hosting providers.

Just to be clear, we need transport maps, not aliases for hits.

The MTA where boum.org’s MX points to should have transport maps set for the schleuder lists which deliver (deliver, not forward) mail to the hosting provider. The hosting provider should accept mail for boum.org. Specifically, it should accept mail for the lists it hosts and have a transport map that delivers everything else to wherever boum.org’s MX points.

#7 Updated by intrigeri 2018-12-11 09:11:44

Thanks for the clarification. I’ve filed 2 subtasks to track the next steps :)

#8 Updated by intrigeri 2018-12-28 10:37:49

  • related to Bug #16255: puscii fails to deliver email to boum.org added

#9 Updated by intrigeri 2018-12-28 17:12:19

  • related to #16257 added

#10 Updated by intrigeri 2018-12-29 11:06:33

  • Status changed from Confirmed to In Progress

Applied in changeset commit:tails|1304ea6bc33d27c5ca6d2643f45b24dc9c9f64d9.

#11 Updated by anonym 2019-01-30 11:59:36

  • Target version changed from Tails_3.12 to Tails_3.13

#12 Updated by groente 2019-02-21 21:16:39

  • Status changed from In Progress to Resolved

#13 Updated by Anonymous 2019-05-31 10:57:39

  • related to Bug #16767: Schleuder mailing lists non functional: MXs of Autistici/Inventati are misconfigured added