Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #12068 > unrolled thread

Q: When dnsZoneEntry is freed after DD retired

Started byKentaro Hayashi <kenhys@xdump.org>
First post2020-09-28 10:50 +0200
Last post2020-11-03 10:20 +0100
Articles 7 — 3 participants

Back to article view | Back to linux.debian.project


Contents

  Q: When dnsZoneEntry is freed after DD retired Kentaro Hayashi <kenhys@xdump.org> - 2020-09-28 10:50 +0200
    Re: Q: When dnsZoneEntry is freed after DD retired Mattia Rizzolo <mattia@debian.org> - 2020-09-28 13:20 +0200
      Re: Q: When dnsZoneEntry is freed after DD retired Kentaro Hayashi <kenhys@xdump.org> - 2020-09-29 10:30 +0200
        Re: Q: When dnsZoneEntry is freed after DD retired Mattia Rizzolo <mattia@debian.org> - 2020-09-30 13:10 +0200
          Re: Q: When dnsZoneEntry is freed after DD retired "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2020-09-30 18:10 +0200
            Re: Q: When dnsZoneEntry is freed after DD retired Kentaro Hayashi <kenhys@xdump.org> - 2020-10-02 14:20 +0200
              Re: Q: When dnsZoneEntry is freed after DD retired Kentaro Hayashi <kenhys@xdump.org> - 2020-11-03 10:20 +0100

#12068 — Q: When dnsZoneEntry is freed after DD retired

FromKentaro Hayashi <kenhys@xdump.org>
Date2020-09-28 10:50 +0200
SubjectQ: When dnsZoneEntry is freed after DD retired
Message-ID<ATX17-4wG-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi,

I couldn't find article about the rule of 
"When dnsZoneEntry is freed after DD retired".
So, I want to know it.

It seems that when DD has retired, dnsZoneEntry: is disabled.
(It is bound to *.debian.net)

  ref. https://wiki.debian.org/DebianDotNet

It is okay but dnsZoneEntry: is still hold on by retired DD.


I've observed that the number of 88 person (retiring or inactive) 
owns dnsZoneEntry: field.

I could check it by ldapsearch and filter entries:

  ldapsearch -u -x -H ldap://db.debian.org -b dc=debian,dc=org dnsZoneEntry=*

There is a possibility to come back to Debian Project, but it is "may be".
I think it is better to remove dnsZoneEntry: field from retired DD account
because it means that such a subdomain is not reusable by active DD, how
do you thik?

Regards,

P.S. I've attached list of kept dnsZoneEntry by retiring or inactive DD.



[toc] | [next] | [standalone]


#12069

FromMattia Rizzolo <mattia@debian.org>
Date2020-09-28 13:20 +0200
Message-ID<ATZmi-61p-1@gated-at.bofh.it>
In reply to#12068

[Multipart message — attachments visible in raw view] — view raw

On Mon, Sep 28, 2020 at 05:40:23PM +0900, Kentaro Hayashi wrote:
> I couldn't find article about the rule of 
> "When dnsZoneEntry is freed after DD retired".
> So, I want to know it.
> 
> It seems that when DD has retired, dnsZoneEntry: is disabled.
> (It is bound to *.debian.net)
> 
>   ref. https://wiki.debian.org/DebianDotNet
> 
> It is okay but dnsZoneEntry: is still hold on by retired DD.
> 
> 
> I've observed that the number of 88 person (retiring or inactive) 
> owns dnsZoneEntry: field.


This totally looks like I bug.  I know of a previous instance when the
DSA team explicitly told me that were expecting a DD to have their
account formally retired/removed before freeing a .d.n entry.

FTR, I believe this is the script DSA uses when locking down an account
after their retirement/removal:
https://salsa.debian.org/dsa-team/mirror/userdir-ldap/-/blob/master/ud-lock

-- 
regards,
                        Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540      .''`.
More about me:  https://mapreri.org                             : :'  :
Launchpad user: https://launchpad.net/~mapreri                  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-

[toc] | [prev] | [next] | [standalone]


#12070

FromKentaro Hayashi <kenhys@xdump.org>
Date2020-09-29 10:30 +0200
Message-ID<AUjbj-V9-1@gated-at.bofh.it>
In reply to#12069
Hi,


On Mon, 28 Sep 2020 13:11:48 +0200
Mattia Rizzolo <mattia@debian.org> wrote:

> On Mon, Sep 28, 2020 at 05:40:23PM +0900, Kentaro Hayashi wrote:
snip
> > I've observed that the number of 88 person (retiring or inactive) 
> > owns dnsZoneEntry: field.
> 
> 
> This totally looks like I bug.  I know of a previous instance when the
> DSA team explicitly told me that were expecting a DD to have their
> account formally retired/removed before freeing a .d.n entry.
> 
> FTR, I believe this is the script DSA uses when locking down an account
> after their retirement/removal:
> https://salsa.debian.org/dsa-team/mirror/userdir-ldap/-/blob/master/ud-lock

How should I ask to remove them in this case?
Is it better to submit a ticket via admin@rt.debian.org?

  https://wiki.debian.org/Teams/DSA/RTUsage

Regards,

[toc] | [prev] | [next] | [standalone]


#12071

FromMattia Rizzolo <mattia@debian.org>
Date2020-09-30 13:10 +0200
Message-ID<AUI9H-7zJ-3@gated-at.bofh.it>
In reply to#12070

[Multipart message — attachments visible in raw view] — view raw

On Tue, Sep 29, 2020 at 05:10:23PM +0900, Kentaro Hayashi wrote:
> How should I ask to remove them in this case?

This being debian-project@ I'm sure there are several DSA members who
follow the list, so I'd say to try and wait some time to see if any of
them follow up.

-- 
regards,
                        Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540      .''`.
More about me:  https://mapreri.org                             : :'  :
Launchpad user: https://launchpad.net/~mapreri                  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-

[toc] | [prev] | [next] | [standalone]


#12072

From"Adam D. Barratt" <adam@adam-barratt.org.uk>
Date2020-09-30 18:10 +0200
Message-ID<AUMQ2-20A-5@gated-at.bofh.it>
In reply to#12071
On Wed, 2020-09-30 at 12:57 +0200, Mattia Rizzolo wrote:
> On Tue, Sep 29, 2020 at 05:10:23PM +0900, Kentaro Hayashi wrote:
> > How should I ask to remove them in this case?
> 
> This being debian-project@ I'm sure there are several DSA members who
> follow the list, so I'd say to try and wait some time to see if any
> of them follow up.

As noted in the original mail, as soon as an account is locked any
corresponding debian.net DNS entries stop being published. The only
question under consideration is thus whether those entries should
become available for re-use and, if so, when.

My (anecdotal) experience is that debian.net entries tend to fall into
two categories - those that only have any relevance or usefulness to an
individual, and those that are of wider use, where there may be
surprise at their disappearance. It's not entirely clear in either case
how soon after retirement the record should become available, and we
don't have tooling to support any answer other than "immediately".

If there's a need / desire for a particular DNS name previously owned
by an ex-DD to be made available, then we'd be happy to discuss that on
a per-case basis.

As a side-note, please bear in mind that -project is publicly archived
when considering whether to post data from LDAP to it (even publicly-
visible data).

Regards,

Adam
[as a member of, but not on behalf of, DSA]

[toc] | [prev] | [next] | [standalone]


#12073

FromKentaro Hayashi <kenhys@xdump.org>
Date2020-10-02 14:20 +0200
Message-ID<AVscx-2GY-1@gated-at.bofh.it>
In reply to#12072
Hi,

2020年10月1日(木) 1:04 Adam D. Barratt <adam@adam-barratt.org.uk>:
>
> On Wed, 2020-09-30 at 12:57 +0200, Mattia Rizzolo wrote:
> > On Tue, Sep 29, 2020 at 05:10:23PM +0900, Kentaro Hayashi wrote:
> > > How should I ask to remove them in this case?
> >
> > This being debian-project@ I'm sure there are several DSA members who
> > follow the list, so I'd say to try and wait some time to see if any
> > of them follow up.
>
> As noted in the original mail, as soon as an account is locked any
> corresponding debian.net DNS entries stop being published. The only
> question under consideration is thus whether those entries should
> become available for re-use and, if so, when.
>
> My (anecdotal) experience is that debian.net entries tend to fall into
> two categories - those that only have any relevance or usefulness to an
> individual, and those that are of wider use, where there may be
> surprise at their disappearance. It's not entirely clear in either case
> how soon after retirement the record should become available, and we
> don't have tooling to support any answer other than "immediately".
>
> If there's a need / desire for a particular DNS name previously owned
> by an ex-DD to be made available, then we'd be happy to discuss that on
> a per-case basis.

So, I want to discuss a particular DNS entry: fabre.debian.net.
This DNS record was owned by ex-DD ukai.
He was retired 2009-08-25, and it holds dnsZoneEntry: fabre IN A 218.223.29.46.

You can ensure this by the following command:

  ldapsearch -u -x -H ldap://db.debian.org -b dc=debian,dc=org uid=ukai

I want to reuse this subdomain to plan running an experimental service.
Here is a brief explanation about it.

  https://slide.rabbit-shocker.org/authors/kenhys/debconf2020-online/

> As a side-note, please bear in mind that -project is publicly archived
> when considering whether to post data from LDAP to it (even publicly-
> visible data).

I thought that we need to discuss based on the fact, so I've attached that list.
But, I should be more careful to handle it...

Regards,

[toc] | [prev] | [next] | [standalone]


#12098

FromKentaro Hayashi <kenhys@xdump.org>
Date2020-11-03 10:20 +0100
Message-ID<B70DT-7Ll-1@gated-at.bofh.it>
In reply to#12073
Hi,

On Fri, 2 Oct 2020 20:20:58 +0900
Kentaro Hayashi <kenhys@xdump.org> wrote:
> So, I want to discuss a particular DNS entry: fabre.debian.net.
> This DNS record was owned by ex-DD ukai.
> He was retired 2009-08-25, and it holds dnsZoneEntry: fabre IN A 218.223.29.46.
> 
> You can ensure this by the following command:
> 
...
> 
> I want to reuse this subdomain to plan running an experimental service.

FYI: This subdomain issue was resolved.
ref. [rt.debian.org #8439] 

Thank you!

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.project


csiph-web