#linode IRC Logs for 2021-02-21

---Logopened Sun Feb 21 00:00:48 2021
05:52<shang>so if host -t ns points to linode's name servers, and the domain is set up on linode itself, ping should point to the linode's ip address right?
05:53<shang>what is happening is that when I ping the domain, it's showing that the IP address is different, even though host -t ns shows that it's been updated to linode's. Or perhaps I still have to wait longer?
06:02<shang>never mind, turns out I just had to flush my local dns :(
06:03-!-shang [~shang@] has quit [Quit: Leaving]
11:50<linbot>Another satisfied customer! NEXT!
11:56<rsdehart>decisions, decisions
12:19-!-LouWestin [~Lou@2600:3c00::f03c:92ff:fedd:c7fa] has joined #linode
12:19-!-LouWestin is "Lou the Dungeon Capturer" on #linode #debian-next #debian
13:59<esselfe>my arch linode doesn't like my main site's acme https/ssl cert
13:59<esselfe>all my 4 other servers with different providers accept it
14:00<esselfe>it's probably not a linode problem though
14:00<esselfe>ERROR: The certificate of ‘’ is not trusted.
14:00<esselfe>ERROR: The certificate of ‘’ doesn't have a known issuer.
14:00<esselfe>that's when using wget
14:03<Peng_>Looks like the web server is misconfigured. Instead of sending your certificate and the intermediate, it sends your certificate, your certificate, and the intermediate.
14:03<esselfe>curl works
14:03<Peng_>Some clients will be more accepting than others.
14:16<esselfe>well I removed TLS 1.0 and 1.1, I don't know what to do about it...
14:18<Peng_>You need to configure the certificates correctly.
14:33<LouWestin>I'm trying to find where you can update LE's ciphers
14:34<grawity>do you mean with that thing where you let certbot automatically put things in apache.conf and it configures "secure" ciphers for you?
14:35<esselfe>no I use, I move the certs in /etc/apache2/certs and have set mods-available/ssl.conf manually
14:35<grawity>in that case you just set SSLCipherSuite or whatever, LE has nothing to do with it
14:36<LouWestin>Yeah. I know I modified it on my other server to make it get a better rating
14:36<Peng_>If you had Certbot configure Apache, you can edit the file /etc/letsencrypt/options-apache-something-or-other.conf.
14:36<Peng_>Though the defaults should be good in recent versions.
14:40<LouWestin>I don't just remember what I did on the old server LOL. Gah... I need to write this stuff down
14:41<grawity>esselfe: what do you have in apache's SSLCertificateFile, and how do you generate that file?
14:41<esselfe>the file and it's options was already there, just changed the filenames correctly
14:42<esselfe>well I had to 'ln -sv ../mods-available/ssl.conf mods-enabled'
14:43<esselfe>anyways I'm out of time, thanks everyone
14:43<Peng_>SSLCertificateFile and/or SSLCertificateChainFile
14:45<grawity>(the latter only if you're still stuck with apache 2.2)
15:11<LouWestin>Ok I remember what I did now... I added those changes into the Apache2 sites-available config file
15:14<LouWestin>Add Strict Transport Security
15:14<LouWestin>and Include Cipher Suites
15:19<LouWestin>restart apache and that did it
15:20<LouWestin>A+ rating on
15:44-!-soundless [] has joined #linode
15:44-!-soundless is "OFTC WebIRC Client" on #linode
15:45<soundless>Hi there, anyone have a test IP to newark ? Would like to test routing and backbone using mtr from a few pops
15:48<kharlan>Pretty sure you can use:
15:48<kharlan>Alternatively you can spin up a nanode for a few hours. It's only a few cents.
15:50<soundless>speedtest.newark worked. Thanks!
15:51-!-soundless [] has quit [Quit: Page closed]
16:14<esselfe>LouWestin: thanks, my site is now A+
16:15<esselfe>(I'm back)
16:29<LouWestin>esselfe: excellent!
16:30<LouWestin>I think it was Dr. J who taught me that. I haven't see him in a long time though
18:32<linbot>New news from community: How to add an SSH key to an existing Linode? <>
18:52<linbot>New news from community: IP Transfer Swap and reboot still shows old IP address <>
21:27-!-Bryan [~oftc-webi@2a02:c7f:362a:cc00:e4f8:8f38:466d:b6f5] has joined #linode
21:27-!-Bryan is "OFTC WebIRC Client" on #linode
21:27-!-Bryan is now known as Guest13779
21:27<Guest13779>HI need some help in migrating a domain and site to linode
21:32<Guest13779>Hello anyone here???
21:32<LouWestin>Hi Guest13779
21:33<virtual>hi Guest13779. Kind of here and not here. Best to ask a specific question to wake people up :)
21:33<Guest13779>I would like to migrate from my current web hosting company to linode
21:34<Guest13779>and would like to get an idea of how quickly this can be done ( domain name registration/swap etc )
21:34<Guest13779>Very unhappy with my current provider and looking to make a clean break asap
21:34<LouWestin>There's a free migration that you might qualify for
21:36<LouWestin>Otherwise Linode is mostly unmanaged so if you have the know how you could migrate over in about a day depending
21:38<Guest13779>I have never done so before but I am technical.
21:38<@mcivi>Guest13779: If you're not eligible for the free migration, this guide may help in getting started -
21:38<Guest13779>But is I am left alone to do everything with no help then that would not work. I would need assistance
21:38<virtual>domain name registration is not something I'm aware of Linode doing, so you'd have to do that part elsewhere, I think?
21:38<virtual>but they can do the DNS hosting part no problem.
21:41<LouWestin>Yeah he'd have to point the domain to Linode's name servers. Technically he doesn't have to I know, but for simplicity stake.
21:41<LouWestin>You might want to look for a managed host then
