Sunday, December 03, 2023
support@conference.yunohost.org
December
Mon Tue Wed Thu Fri Sat Sun
        1
2 3
4
5 6
7 8
9
10
11 12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28 29
30
31
             

[09:57:20] <zewatch> Good morning, Yuno-Folks
[09:58:03] <zewatch> Is it ok to ask a question here about installing / using YunoHost?
[10:02:53] <zewatch> I see that the installation process allows for the allocation of a domain (xxx.nohost.me or similar)
[10:03:05] <zewatch> Which was amazingly cool :)
[10:03:40] <zewatch> Is this domain usable for the whole process, including setting-up dynamic DNS or do I still need to purchase a domain?
[10:04:45] <zewatch> And, if I can use the xxx.nohost.me domain, does it auto-configure the dynamic DNS or will I still need to do that manually through one of the dynamic DNS free services?
[10:04:52] <zewatch> Thank You :)
[10:58:54] <Charles P.> .nohost.me (and .ynh.fr) domains, are fully automatically managed, they are usable for the whole process (whatever you meant by that), you can use them without buying a domain, dyndns is also automatically managed
[11:00:09] <zewatch> Oh, that’s great - thank you
[11:00:20] <zewatch> I meant the process of setting-up the server
[17:28:04] <Azu> Do manual testing branch installs auto update too,or do I have to somehow manually do a update check?
[17:28:28] <Azu> This is for Akkoma specifically,which runs fine on my server
[17:30:39] <Aleks (he/him/il/lui)> upgrading to an app's testing branch does nothing in particular except upgrading to a version that is not yet released ... if a new "stable" version that is higher than your currently installed version is released, then you'll get an upgrade advertised in your webadmin
[17:30:56] <Aleks (he/him/il/lui)> but yunohost won't magically "follow" any new development in the testing branch
[17:38:15] <Azu> Got it,I noticed akkoma was removed from the app store,though the only issue I ever had with the stable branch was the md5 check constantly breaking,I'm guessing that's why,though
[17:43:15] <Charles P.> https://github.com/YunoHost/apps/pull/1884
[17:44:05] <Charles P.> https://aria.im/_matrix/media/v1/download/stratus.family/gKMqhMsNNJQwTXDMXkiflMeQ
[18:38:01] <Azu> Testing branch installed without incident and has been running fine though?
[18:49:03] <Aleks (he/him/il/lui)> Then idk, share your feedback un whichever relevant ticket on the app repo
[18:55:47] <Azu> Might just do that then
[19:49:03] <Guillaume Bouzige> hello, I have just installed a fresh yunohost last version on an rpi at home (behind an internet freebox), after creating a .local domain and installing an application (adguardhome) I cannot access the application. what can i do ? I used a similar setup in the past with no particular issue
[19:50:13] <Guillaume Bouzige> I did access my yunohost via the ip address so far
[19:52:53] <Guillaume Bouzige> I dont have any particular error message or logs since I just cannot access, the .local domain of any the yunohost main domain or the app domain. Is there anything particular to configure to get those .local domains to work ?
[20:06:58] <Guillaume Bouzige> I do have noticed a difference tho, when I add a domain, now there is the third option for local/test domain. this is new, is there could be an error there ?
[20:08:07] <Guillaume Bouzige> now I am trying to add a domain with the usual domain option like before and I receive those errors when adding
[20:08:08] <Guillaume Bouzige> postmap: fatal: open /etc/postfix/sni: No such file or directory
Could not run script: /usr/share/yunohost/hooks/conf_regen/19-postfix
[20:10:39] <Guillaume Bouzige> but when I create this new .local domain without using the new option for it, I get to access it and being redirected to the main domain sso now I am confronted to this error ```Secure Connection Failed

An error occurred during a connection to server.local. You are attempting to import a cert with the same issuer/serial as an existing cert, but that is not the same cert.

Error code: SEC_ERROR_REUSED_ISSUER_AND_SERIAL

The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem.```
[20:18:15] <Guillaume Bouzige> ok adding the .local domain to my /etc/hosts doesnt help neither
[20:19:30] <Guillaume Bouzige> when trying to delete and recreate one guard.local domain, I received those errors :
[20:19:38] <Guillaume Bouzige> ```The configuration file '/var/www/.well-known/server.local/autoconfig/mail/config-v1.1.xml' has been manually modified and will not be updated
postmap: fatal: open /etc/postfix/sni: No such file or directory
Could not run script: /usr/share/yunohost/hooks/conf_regen/19-postfix
Self-signed certificate now installed for the domain 'guard.local'
The configuration file '/var/www/.well-known/server.local/autoconfig/mail/config-v1.1.xml' has been manually modified and will not be updated
Configuration updated for 'postfix'
Configuration updated for 'mdns'
Configuration updated for 'dnsmasq'
Domain created```
[20:20:20] <Guillaume Bouzige> what is this thing about postfix here...?
[20:26:14] <Guillaume Bouzige> after verifying the file `/etc/postfix/sni` DOES exist
[20:26:44] <Guillaume Bouzige> maybe with the wrong rights ? `-rw-r--r-- 1 root root 92 Dec 3 20:18 sni`
[20:30:16] <Guillaume Bouzige> oh gosh, even more weird now...after going into ssh, digging into yunomdns service playing with status and then stop and start...I found out that an yunohost.local domain got created...and guess what this .local domain works super fine
[20:30:30] <Guillaume Bouzige> but none of the others....
[20:31:43] <Guillaume Bouzige> and this domain does not appear in the domain list on the webadmin interface....but it is the only one that actually works
[20:32:34] <Guillaume Bouzige> I do remember now that during the install when ask for my domain, I used that new third option to declare my domain as server.local....is this why this all go weird ?
[20:39:49] <Guillaume Bouzige> I cannot reinstall it all now, is there anything I can do ?
[20:41:34] <Guillaume Bouzige> can I apply via cli that yunohost.local domain that works to my application ?
[20:50:36] <Guillaume Bouzige> since that domain does not appear
[21:19:19] <Guillaume Bouzige> so yeah last version of yunohost doesnt work with local domains...
[21:19:38] <Aleks (he/him/il/lui)> dude it feels like you are panicking and looking at totally unrelated stuff right now
[21:19:41] <Aleks (he/him/il/lui)> the "third option" is fine
[21:20:03] <Guillaume Bouzige> i am trying to figure out a solution...
[21:20:17] <Guillaume Bouzige> sure then how to get this to work then
[21:20:17] <Aleks (he/him/il/lui)> the key is to explain what you mean by "i cannot access", which you did later, i.e. the `Error code: SEC_ERROR_REUSED_ISSUER_AND_SERIAL`
[21:20:39] <Aleks (he/him/il/lui)> which is probably related to the fact that, i'm guessing, you used that domain in the past and did some reinstall of some sort
[21:20:48] <Guillaume Bouzige> I have no clue, i am pretty clueless
[21:21:03] <Guillaume Bouzige> the yunohost is a fresh install
[21:21:12] <Aleks (he/him/il/lui)> and there's indeed a boring issue with serial being reused for selfsigned certs and whatever and browsers not happy with that
[21:21:33] <Guillaume Bouzige> that server has been installed from iso to sd card with no previous configuration
[21:21:34] <Aleks (he/him/il/lui)> yes, the yunohost may be a fresh install, but your browser is not fresh ...
[21:22:02] <Guillaume Bouzige> what do you mean by that ? I have try different browsers
[21:22:34] <Guillaume Bouzige> what shall I do in my browser to get it work then ?
[21:23:45] <Guillaume Bouzige> how about this hidden yunohost.local domain that appear only in yunomdns service ?
[21:23:56] <Guillaume Bouzige> but not in the webadmin
[21:24:14] <Aleks (he/him/il/lui)> it's super boring but you have to make your browser forget about the old certificate, which (assuming firefox) happens somewhere in the security settings, in the "certificate" section, gotta find where it registered the cert and delete it
[21:24:49] <Aleks (he/him/il/lui)> > how about this hidden yunohost.local domain that appear only in yunomdns service ?

this is just something standard that is configured on any fresh install for easy access to the postinstall during the initial setup ...
[21:24:50] <Guillaume Bouzige> > <@Alekswag:matrix.org> it's super boring but you have to make your browser forget about the old certificate, which (assuming firefox) happens somewhere in the security settings, in the "certificate" section, gotta find where it registered the cert and delete it

I can try that now
[21:25:11] <Guillaume Bouzige> > <@Alekswag:matrix.org> this is just something standard that is configured on any fresh install for easy access to the postinstall during the initial setup ...

yep I thought that, but how come it is the only .local domain that works
[21:25:36] <Aleks (he/him/il/lui)> > <@Alekswag:matrix.org> it's super boring but you have to make your browser forget about the old certificate, which (assuming firefox) happens somewhere in the security settings, in the "certificate" section, gotta find where it registered the cert and delete it

*but* i've had experiences with firefox where even if you "delete" it, somehow it comes back immediately and you have to repeat it like 5 or 6 times until somehow it does get deleted for real. i have no idea wtf
[21:26:17] <Guillaume Bouzige> > I can try that now

went into the certificate manager part of "privacy and security" part and I have no certificates there appart from CA
[21:26:51] <Guillaume Bouzige> I am using librewolf and I have try with standard firefox too
[21:27:08] <Guillaume Bouzige> I have try with some .local domain that I never used before, fichtre.local
[21:28:07] <Guillaume Bouzige> I am gonna try more times with firefox then, but how come the yunohost.local does works since it is the one I most likely did used in the past...
[21:30:20] <Aleks (he/him/il/lui)> ¯\_(ツ)_/¯
[21:30:28] <Guillaume Bouzige> ok it is indeed funny, I can access the main .local domain now with firefox
[21:30:35] <Guillaume Bouzige> but not the application one
[21:30:40] <Guillaume Bouzige> werid
[21:30:47] <Guillaume Bouzige> > werid

weird
[21:34:29] <Guillaume Bouzige> can't find anywhere any cerficates related to .local domains in librewolf
[21:53:35] <Guillaume Bouzige> it does works in standard Firefox tho, sorry aleks if I made too much noize for you and thanks for your help...you always know everything !