Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

(tick)

All linux servers use IPv6 resolvers

Only statically configured IPv6 addresses in /etc/resolv.conf

(tick)

All linux servers run SSH on IPv6 only

Configure ListenAddress :: in sshd_config.

(tick)

All linux servers run Postfix on IPv6 only (except public mail server)

Remove IPv4 address from $mynetworks, and set inet_protocols = ipv6

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="b8539226cb8d1cc3-32371099-478840ab-ae2081b4-2ed2d40ac49d8aee39df9e92"><ac:plain-text-body><![CDATA[

(tick)

Nagios runs only on IPv6

Configure Listen [2001:610:158:98d::42]:80 in /etc/apache/ports.conf.

]]></ac:plain-text-body></ac:structured-macro>

(question)

Radius

In progress. Radiusd cannot connect to LDAP. To be fixed.

(tick)

Entire host IPv6 only

System svn.terena.org is IPv6. Removed IPv4 address.

(question)

All PostgreSQL server use IPv6

Should be configured on all hosts (web, mail, dev, etc). To do.

...

Some tests indicate the Ecdysis works well.
Also, they presented at our own conference last year (wink)
Take into consideration!

Linux issues

(tick)

apt-get

security.ubuntu.com does not work, so no security updates. Workaround: use local mirror nl.archive.ubuntu.com for security updates.

(tick)

Pear Net_Socket

Does not like IPv6 addresses, wrote patch.

(tick)

ntp

ntp.ubuntu.com does not work. Use our own NTP server graham.terena.org

(tick)

ntp

dumps core without IPv4 loopback address. Keep legacy 127.0.0.1 address

(tick)

Confluence LDAP auth via IPv6 = b0rked

Workaround: use IPv6 hostname: ldap.ipv6.terena.org

...