Disable apache2 on microbel #420

Open
opened 2026-07-24 14:41:57 +02:00 by oysteikt · 2 comments
Owner

Might have to do something about mailman2, either put it on a different machine or just expose it to the world directly.

I don't think we need apache2 on microbel. Let's reduce the attack surface as much as possible, and let this machine only care about its disks and mail.

Might have to do something about mailman2, either put it on a different machine or just expose it to the world directly. I don't think we need apache2 on microbel. Let's reduce the attack surface as much as possible, and let this machine only care about its disks and mail.
oysteikt added the security label 2026-07-24 14:41:57 +02:00
oysteikt added this to the Kanban project 2026-07-24 14:41:57 +02:00
Owner

Yes, it is very important to either do something like #18, or get everyone off of our mailing lists first. I am not sure how many external users/groups/orgs use them anymore, we should check.

Yes, it is very important to either do something like https://git.pvv.ntnu.no/Drift/issues/issues/18, or get everyone off of our mailing lists _first_. I am not sure how many external users/groups/orgs use them anymore, we should check.
Author
Owner

I originally thought that it might be possible to move it over to another machine, but maybe it needs direct access to the mail directory. Remote mounting the directory sounds wack, let's not do that. I also see in the repo itself that mailman expects to be rendered by an external program: https://github.com/Koumbit/mailman2/blob/master/debian/contrib/apache.conf

I suppose this renders this issue inactionable

I originally thought that it might be possible to move it over to another machine, but maybe it needs direct access to the mail directory. Remote mounting the directory sounds wack, let's not do that. I also see in the repo itself that mailman expects to be rendered by an external program: https://github.com/Koumbit/mailman2/blob/master/debian/contrib/apache.conf I suppose this renders this issue inactionable
oysteikt added the blocked label 2026-07-24 15:40:50 +02:00
oysteikt moved this to Low priority in Kanban on 2026-07-24 15:48:02 +02:00
Sign in to join this conversation.
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Drift/issues#420