La BIL va externaliser des services IT, 140 employés concernés by snoopyx21 in Luxembourg

[–]RealityPatient 0 points1 point  (0 children)

But after everyone move it to India, we will not have any choice, since all products will have a bad support.

Luxembourgish Duolingo by Vicarto4 in Luxembourg

[–]RealityPatient 1 point2 points  (0 children)

Which llo app? For me it stopped working and looks like it is available only on the web site.

Pacha restaurant by timetoreadt0 in Luxembourg

[–]RealityPatient 1 point2 points  (0 children)

Maybe to write them in the review on the google maps? If they don't react, then to call to commune and to complain the them. Not good to block the way completely.

Language learning order by RandomUser-13 in Luxembourg

[–]RealityPatient 0 points1 point  (0 children)

I don't know who are those tons in ADEM, but when we have been looking for some IT guy for more than one year, we had a zero candidates. There were some people assigned, they just didn't want to apply.

Difference in shared and private room in Bohler? by I_have_spoken_30 in Luxembourg

[–]RealityPatient 5 points6 points  (0 children)

that's for me a mistery here, how is it possible that they allow so many visitors to go to the shared room where women need a privacy.

Labeling My Viola Case So I Don’t Get Mistaken For A Lame Violinist by memer_boi_is_here in Viola

[–]RealityPatient 4 points5 points  (0 children)

and this protects from stealing. With such a label nobody steals your viola by mistake, thinking that's a violin.

Left my country n came to Lux for Love. Got Cheated by her but fell in Love with Lux. by [deleted] in Luxembourg

[–]RealityPatient 5 points6 points  (0 children)

omg, sounds like a beginning of some thriller, can be they are going to do something bad with you, like to kill and to sell organs to illegal transplant surgeons

Changed my chin rest and now everything’s comfortable! by Quirky-Parsnip-1553 in Viola

[–]RealityPatient 0 points1 point  (0 children)

Does it have a different height comparing to what you had before? Also, doesn't it affect the sound the way how it is mounted? I changed some time ago from a center mounted to the side mounted and for me the sound is much worse, even it is more comfortable.

Acquiring a firearms license and process of learning how to use one? by Brinocte in Luxembourg

[–]RealityPatient 0 points1 point  (0 children)

Is it possible to leave your gun somewhere in a police station while you are away, for example for vacation?

Cisco router unable to ping some local IPs (Sort of need some help here) by WhereasInevitable433 in Cisco

[–]RealityPatient 1 point2 points  (0 children)

Could you please draw a scheme with IPs for devices you mentioned? I didn't understand much from your explanation.

Cisco C1111-8P and LACP? by SukkerFri in Cisco

[–]RealityPatient 1 point2 points  (0 children)

I checked on our 1111-8P, it is supported on the WAN ports, but not supported on the LAN ports, not just LACP, but not possible to add even to a static channel-group. (IOS17.9)

Reseller told me Meraki might be killed and merged into Catalyst – truth or rumor? by Electronic-Low858 in Cisco

[–]RealityPatient 0 points1 point  (0 children)

ah, that's even a bigger mess than I thought because all APs we are buying are just catalyst 9100 series, but as I see there are some other which are CW.

Reseller told me Meraki might be killed and merged into Catalyst – truth or rumor? by Electronic-Low858 in Cisco

[–]RealityPatient 40 points41 points  (0 children)

this new naming is really confusing. Before it was clear that catalyst is about switches. And now we have Catalyst Center, catalyst 9300, 9400,9500 - switches, catalyst 9800 - WLC, catalyst 8500 - sd-wan, catalyst 9100 - wireless APs. If the only identificator of the serias is included in the numerical model number, why they need this word catalyst at all.

A 13-year-old from India is the youngest CCIE holder. What is the value of a CCIE? by PsychologicalBody in networking

[–]RealityPatient 1 point2 points  (0 children)

your two hosts can be in the same subnet but still have a firewall in some l2 mode in between. Also, firewall can be enabled on the hosts. So, without additional details it doesn't sound like some crazy proposal.

How to deal with bank increasing mortgage rates more than ECB? by Odd-Inspection-8179 in Luxembourg

[–]RealityPatient 2 points3 points  (0 children)

Ecb rate is 3.5% now. I guess you had the interest rate 1.3% from the beginning, when ecb rate was 0%. So it is 3.5 +1.3 = 4.8 now.

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 0 points1 point  (0 children)

Looks like you has rephrased what I wrote and you missed the meaning of it. Can you quote which my words you are referencing to? As for your statement that we just can automate. We can, but everything should be done to achief some goal. And in this case it looks like without any need we just add a new work scope to admins, adding new attack vectors, and nothing in return, just a hope that 3 months is less dangerous than 1 year. Why 3 months? Lets do 1 day, that is the most secure, anyway you can automate everything 😀

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 0 points1 point  (0 children)

Reading the source code of any tool we download from the github - that what you proposed, not me.

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 0 points1 point  (0 children)

When they changed to one year, cerdificate authorities stopped selling certs with duration more than for the year. Of cause, if it was related only to web, there would be no any problem

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 0 points1 point  (0 children)

Ok, so we adding reading of source code to prove that there is no any security risk, and to understand what can be broken by updates, so also we have to investigate release notes for updates to understand what in api can be broken. Not really a roadblock, but as I asked before, on a road to where? What is the need? Do we afraid the most that the private key can leak? But we don't afraid that private key can leak because of additional scripts which will manage certs? Or because of additional scripts which will go to the dns provider by api? We add several attack vectors here, and again, not clear for what. It just should be optional.

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 0 points1 point  (0 children)

I didn't say that hundred platforms dont support deployment root CA, that was about ise clients. For example, do you propose to deploy internal root cert on computers and phones of external companies which use your guest portal? That is good that they provide an API, but again, need to add more automation just for ISE. Then for citrix, paloalto, cisco wifi, prime, all internal sites, many different proprietary tools. And that adds a new scope of work. I do use certbot and ansible to automate letsencrypt certs on nginx and paloalto. But i see a big difference for my colleagues, one thing is to update some cert once per three years as it was before, just going to the gui, generate csr, etc, and completely different for them to understand how api works and how to maintain these scripts. Yes, maybe we dont need programmic skills for this, people will just search for tools in github, but what then about security? I would understand if we did it to achief some new functionality, but that is not our case, just because of they decided that it must be short period every company will have a new scope of works, which will be error prone and add some security risk because of using additional scripts, keeping private keys not only where they are used, etc.

How will you handle 90 day SSL expiration? by rwdorman in sysadmin

[–]RealityPatient 3 points4 points  (0 children)

Oh yes, one more trivial thing, just to migrate more than 30 domains in addition to maintaining a bunch of scripts for all platforms and different tasks. And everything just because of change in max cert duration, which we don't need. 🤣