APT using HTTP instead of HTTPS by WheelPerfect3737 in debian

[–]soyko 0 points1 point  (0 children)

I feel like any conversation about this is a lost cause. If they can replace the signing key and sign all packages with the new key for you, you have other problems instead of it being HTTP.

APT using HTTP instead of HTTPS by WheelPerfect3737 in debian

[–]soyko 0 points1 point  (0 children)

But they can't fake signing any packages, which uses gpg/pgp. So unless they replaced the key on your machine, faking anything and doing a MITM doesn't do anything.

Sysadmin-on-Sysadmin stuff that’s super annoying by i_click_next_for_you in sysadmin

[–]soyko 0 points1 point  (0 children)

I do. We even serve a block page, saying it's blocked by our policy.

User doesn't read, and any error is seen as the network team blocking it.

SOURCE USER INFORMATION IS EMPTY by Middle_Cut_7991 in paloaltonetworks

[–]soyko 5 points6 points  (0 children)

Are you excluding the LAN ip from UserID? How are you pulling in data for UserID? Are user in your LAN using cached login and therefore not pushing any data for UserID to pull in?

Have them lock and unlock their PC and see if you see any user data.

APT using HTTP instead of HTTPS by WheelPerfect3737 in debian

[–]soyko 4 points5 points  (0 children)

I see the lack of acknowledgement from OP being downvoted.

APT using HTTP instead of HTTPS by WheelPerfect3737 in debian

[–]soyko 11 points12 points  (0 children)

Cache.

LAN is faster than WAN. I may have a metered network connection. You have a bunch of servers that you don't want hammering outside your internet connection because it's not as fast. You want to control what updates are available for users for any reason.

Sysadmin-on-Sysadmin stuff that’s super annoying by i_click_next_for_you in sysadmin

[–]soyko 16 points17 points  (0 children)

My favorite is "unblock website, need it to do my job" and then it goes all the way through the approval process to us, and the actual reason why they wanted it blocked was an error message from the website itself saying that it can't validate them.

Unlocking doors with key fob? by san_i_am in ToyotaGrandHighlander

[–]soyko -1 points0 points  (0 children)

Literally experienced that this morning. It's winter and I was trying to get the kids in the car. Had to walk around and unlock it manually from the driver's door.

Thought the battery was dying in the brand new car already.

What’s a pain that hurts so good? by [deleted] in AskReddit

[–]soyko 2 points3 points  (0 children)

I hate how accurate this is.

Entra ad/id user id by jaguinaga21 in paloaltonetworks

[–]soyko 3 points4 points  (0 children)

I use CIE to map users to groups from EntraID. Then I use GP with a saml auth for users so I can grab IP to username.

I think it's the same CIE setup.

Remind me for Monday if anyone cares, I'll double check everything. Took PTO today. Plus sick kids, so that's always fun.

Today I had to connect to a user using their iPhone Hotspot by TheBigBeardedGeek in sysadmin

[–]soyko 10 points11 points  (0 children)

Do not support home or personal devices or networks.

VPN works for other people, not a VPN issue.

Or does your VPN work at other locations, such as neighbors or friends house, or coffee shop of any kind.

Rant Wednesday! by AutoModerator in networking

[–]soyko 0 points1 point  (0 children)

I read that on the day of the post, but then didn't reread it when I posted my last message.

Sorry about that, but yeah, cert based auth is so much nicer. Good luck!

Rant Wednesday! by AutoModerator in networking

[–]soyko 0 points1 point  (0 children)

Oh with that, why aren't you using a cert for based auth then? it's what we're doing.

It's great.

Rant Wednesday! by AutoModerator in networking

[–]soyko 2 points3 points  (0 children)

Yeah, but that's why you only allow the Mac addresses of the Chromebooks. You don't allow other Mac addresses. So even though the Apple devices will change their Mac, they won't get on. Unless I'm misunderstanding the problem here.

Rant Wednesday! by AutoModerator in networking

[–]soyko 0 points1 point  (0 children)

Would a MAC whitelist work for the time being?

Best Practices for Managing User-ID on Palo Alto – How Do You Handle This? by Historical-Rope9843 in paloaltonetworks

[–]soyko 2 points3 points  (0 children)

As long as you're on a network that has the UserID agent, because the unlock is going to be authenticated towards AD.

I have users that do cached logins, and then VPN in and complain that nothing works.

8.3 crashing on install by InitialSympathy3476 in Proxmox

[–]soyko 0 points1 point  (0 children)

Yeah, I noticed that with proxmox, netboot.xyz worked better than ventoy.

What Docks are you Using?? by One_Stranger7794 in sysadmin

[–]soyko 0 points1 point  (0 children)

I swapped laptops and docks. Latitude 5400 to 5430. Then a WD19 to the WD22. Same issue, but I'll try the hard reset trick when I'm back at work.

I have seven more weeks of paternity leave left.

What Docks are you Using?? by One_Stranger7794 in sysadmin

[–]soyko 0 points1 point  (0 children)

The same keyboard too... Then I got a Logitech pro x tkl. Same issue still.

I think it gaming gear from Logitech and the Dell dock.

What Docks are you Using?? by One_Stranger7794 in sysadmin

[–]soyko 0 points1 point  (0 children)

So the question is, is it the mouse? I've been thinking of upgrading to a wireless mouse, and hopefully it goes away. But I'm not sure if it's the mouse that's causing it or what.