Skip Navigation

screaming in digital

@ qprimed @lemmy.ml

Posts
1
Comments
369
Joined
3 yr. ago

fixate on what you think you know... you're missing what you don't though.

  • well... that was fucking horrific.

  • but... see! v0t3r Fr4uD! now praise your orange jeebus.

    there will be violence from a small, but thoroughly brainwashed group of fascists.

  • This is the aftermath of the supreme court’s disastrous 6-3 ruling in Louisiana v Callais, decided less than a month ago, which gravely weakened the Voting Rights Act’s protections for Black representation. Ever since, Republicans have resembled eager children on Christmas morning, tearing our electoral maps to shreds.

    Louisiana is set to eliminate one of its two Black-majority districts. The court let :::

    ::: spoiler Alabama

    The court let Alabama erase one of its two Black-majority districts before this fall’s primaries.

    In Mississippi, the Republican state senator who chairs the Medicaid committee said this week that it was time to “erase Bennie Thompson’s district”.

    you utter trash. you absolute excrement of humanity. we will remember every one of you racist fucks. retribution may be delayed, but it will come and your graves will be pissed upon for generations, you loathsome, useless waste of oxygen.

  • you're on lemmy with the rest of us - you have no friends!

  • 🎶every fuck'n day🎶

  • sounds like things have come full-circle.

    some might say... a perfect circle.

  • get this man on a goddamn ballot somewhere.

  • rare good news!

  • “I think the audience of receptive Republicans is a lot bigger than what most folks would think in the Republican party,” Duncan said. “It’s not fun to have to defend Donald Trump.”

    W.T.A.F?!

    any time I think there just might be some minor redemption for these ghouls, their inner bootlicker congeals and oozes out of their putrid, flapping face-hole.

    why did you defend this narcissistic, child raping, snake-oil pimping, murderous megalomaniac in the first place? it certainly wasn't fun for any of his victims for decades and isn't fun now. fuck all the way off, you useless sycophantic piece of shit.

  • no. I will call it what it is and shame anyone who uses weasel words to excuse the butchery of entire groups of people.

    fuck anyone to hell if they choose to do otherwise.

  • agreed. you are using DNS-01 challenges. so the workflow is...

    your local certbot machine initiates an https connection to the letsencrypt servers to start the DNS-01 challenge. during this HTTPS dialog, your local certbot is informed of the key material to insert into your DNS records. your local certbot then modifies your netcup DNS server (hosted remotely, not on your local network) with the keying material and the letsencrypt servers verify that the keys are actually there, proving that you control the domain. the letsencrypt serves then issue you the certificate (again, via HTTPS) and your local certbot stores it in your local host.

    the issue is most likely stems from the initial HTTPS connection that certbot tries to make to the let's encrypt servers. while your firewall allows this traffic out, it does not allow return traffic back in because of your explicit blocking of US (and perhaps other) based addresses.

    even through your are using DNS for your domain autentocation, your local host - the machine running certbot - is unable to initiate the certificate transfer because of the firewall blocking return traffic.

    the two external networks (and, therefore IP ranges/subnets/etc) that are important here are the let's encrypt servers and the netcup DNS servers. certbot will have to talk to both of these in order to function.

  • not sure what you mean by external DNS

    not hosting your own DNS server. specifically it sounds like your DNS server is hosted on your domain provider, not your own local network. you have set up certbot to automatically configure your remotely hosted DNS server for the DNS based renewal.

    if DNS based recert was working before then it should be working now.

    as I said in my edit, you are likely blocking the return https traffic from the US based let's encrypt acme servers - so your initial diagnostic is correct. your local firewall is likely stopping the acme servers from talking back to your local host.

    you are right back where you started, asking for info in how to allow-list the acme IP ranges. but at least we may now know why it is not working and you are seeing an https timeout even though you are using DNS based certificate renewals.

    edit: typos

  • The DNS server/root isn't in my home network

    are you using external DNS hosting? is it in a (now) blocked country? if so, then your local certbot is unable to update the DNS server records (return traffic from your DNS host is being blocked by your iptables/nftables config).

    error: HTTPSConnectionPool(host='acme-v02.api.letsencrypt.org', port=443): Read timed out. (read timeout=45)

    yeah, that would suggest an https renewal method. had you previously configured web server renewal at all before switching over to DNS? any other suspicious notifications in the logs?

    edit: in thinking about this a little more... the renewal has to be initiated by your host, and that is likely done via https (you talk https to the acme server and tell it you want a renewal by DNS). so, if you are blocking the acme servers then the same issue applies - no return traffic.

  • unless something has changed drastically, I pretty sure LMDE is based on official Debian repos, not Ubuntu. LM adds their flavor on top.

    die hard Debian user here here, but if LMDE fits the bill, I agree - go for it. its a great distribution.

  • skipped a few steps there i think.

    thanks for the considered reply. didn't mean to jump all the way down to electrons and sound so flippant.

    my claim is that JavaScript arrays are arrays because the spec defines their behavior as such. the implementation details are absolutely interesting from a performance perspective and I was genuinely curious how an internally linked list implementation would actually work, real-world. regardless... almost every interaction I have ever had with a JS programmer has ended in "its strings all the way down".. so... I mean... yes-ish?

    loved your poking of the hornets nest in this thread :-)

  • fucked anyway

  • and the backing for that is linear or page addressed MOS transistors, spinning rust or flippy-round magnets.

    do you have a source that indicates mainstream JS engines internally uses a list structure for arrays? I can't find one.

  • 🎶her name was lua🎶 🎶she was a coder🎶