I even built a tool for users to minimize the potential for error in this process.
But if a user can’t type their own personal name correctly I am at the bottom of my toolbox.

#Sysadminnery #InfoSec

There is no lesser joy than the process of resetting a password for someone who chronically mistypes their own name.

#Sysadminnery #InfoSec

Someday I will get through the first quarter of a year without having to direct a client to https://kb.isc.org/docs/aa-01640

2026 is not that year. 18 in a row. Had to explain it to marketoons for my prior employer as well, for both major brands.

I don’t *like* making their other vendors look like idiots but I do not really have a choice.

#Sysadminnery #DNS

CNAME at the apex of a zone

This article explains why you can't have a CNAME at the zone apex, and then discusses potential alternatives.

It seems to me based on mailing list traffic like a lot of people are seeing the free side of MS email (outlook.com, hotmail.com, etc. not paying customers on ms365) doing what it so often does today: mystery rejections and dropping mail on the floor.
I assure you: if you're getting bounces because of this, your mail admin knows that it is happening and has NO WAY to address it.

#Sysadminnery
#email #microsoft #ms365 #hotmail

I never ceases to amaze me that mail systems do this shit. I know it was a thing with Sendmail but most of us have moved on or at least fixed the stupid mailer flags.

#Sysadminnery #Email #Sendmail

#TIL: XenCenter makes no objection when one tells it to delete an apparently unused “backend" vdisk which has a (sparse) descendant busy with a running VM. Also, doing that to a Windows VM does not cause it to fail immediately.
Unclear how this mistake has not been previously made in this environment.

#Sysadminnery

CONFESSION:
My ongoing hatred of git is almost entirely grounded in my inability to switch FreeBSD branches without wiping and recloning.

#Sysadminnery

@knowprose It started in the mid '90s. The common refrain of Unix email admins was "Any moron can run Exchange, and most of them do."

#Sysadminnery

RE: https://mastodon.social/@nixCraft/116001279782592904

I have yet to see anyone even *claim* the capacity to do my job with a bot. I have never understood how I might "prompt" one for anything I do where it could do better than my own ad hoc automation.

#Sysadminnery

It’s a rhetorical Q.
It’s almost a miracle that it was found.

It’s also why I do a paranoid level of consistency checks on every #SpamAssassin release. Our definitive repo is in Apache SVN, so we don’t have precisely the same vulnerability as libxz had, but I still verify that no matter how one gets the source, it is identical to what we've checked in.

#FOSS #Sysadminnery #InfoSec @mjg59 https://nondeterministic.computer/@mjg59/115961116648470244

Matthew Garrett (@[email protected])

Just to check on something: whomst amongst you would genuinely say you would have spotted the libxz backdoor by examination rather than by beaviour

Nondeterministic Computer