<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Kian Mohageri</title>
	<atom:link href="http://kianm.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://kianm.wordpress.com</link>
	<description>Well if you really want to hear about it...</description>
	<lastBuildDate>Fri, 17 Jul 2009 07:33:05 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='kianm.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/28280085dc6fa344c57fafd5388515ee?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Kian Mohageri</title>
		<link>http://kianm.wordpress.com</link>
	</image>
			<item>
		<title></title>
		<link>http://kianm.wordpress.com/2009/07/17/42/</link>
		<comments>http://kianm.wordpress.com/2009/07/17/42/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 07:33:05 +0000</pubDate>
		<dc:creator>kian</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kianm.wordpress.com/?p=42</guid>
		<description><![CDATA[I&#8217;ve recently started learning and using tmux as an alternative to screen since its import into the OpenBSD. Upon seeing the simplicity of the man page and commands over screen (nice default status line too), I became a fan and subsequently installed it on all of our servers.  It motivated me to re-subscribe to OpenBSD&#8217;s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=42&subd=kianm&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve recently started learning and using <a href="http://sourceforge.net/projects/tmux/">tmux </a>as an alternative to screen since its <a href="http://undeadly.org/cgi?action=article&amp;sid=20090707041154">import into the OpenBSD.</a> Upon seeing the simplicity of the man page and commands over screen (nice default status line too), I became a fan and subsequently installed it on all of our servers.  It motivated me to re-subscribe to<a href="http://kerneltrap.org/mailarchive/openbsd-source-changes/"> OpenBSD&#8217;s source-changes mailing list</a> and learn that <a href="http://undeadly.org/cgi?action=article&amp;sid=20090712190402">Nicholas Marriott</a> (tmux author according to Undeadly) is a maniac when it comes to commits and also writes good commit logs.  Think we&#8217;ll be seeing more of him in the near future.</p>
<p>There are about 7 screens open on Juicebox, and 1 tmux.   Hence this post.</p>
<p>In other news, I&#8217;ve been reading a lot about DHCP and Option 82 lately upon finding some new types of information in our dhcpd.leases file.  I&#8217;m graduating soon, but if we could make it work and log as <a href="http://www.thtech.net/article/10">this article </a>indicates (the logging part), it&#8217;d be pretty cool.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kianm.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kianm.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kianm.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kianm.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kianm.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kianm.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kianm.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kianm.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kianm.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kianm.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=42&subd=kianm&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kianm.wordpress.com/2009/07/17/42/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/23f2c9fd20cc891d8d257388c7155e1f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kian</media:title>
		</media:content>
	</item>
		<item>
		<title>inna di red</title>
		<link>http://kianm.wordpress.com/2009/03/29/inna-di-red/</link>
		<comments>http://kianm.wordpress.com/2009/03/29/inna-di-red/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 19:04:32 +0000</pubDate>
		<dc:creator>kian</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kianm.wordpress.com/?p=36</guid>
		<description><![CDATA[Spring break was quiet at ResTek.  I haven&#8217;t been into the office much.  I guess because I like to work from home more, where I have my own computer and access to as much coffee as I would like.
I had to buy a new french press (accidentally broke the last one that I got for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=36&subd=kianm&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Spring break was quiet at ResTek.  I haven&#8217;t been into the office much.  I guess because I like to work from home more, where I have my own computer and access to as much coffee as I would like.</p>
<p><img class="alignleft size-full wp-image-37" title="Bodum Kenya French Press" src="http://kianm.files.wordpress.com/2009/03/kenya4.jpg?w=160&#038;h=191" alt="Bodum Kenya French Press" width="160" height="191" />I had to buy a new french press (accidentally broke the last one that I got for Christmas, ouch) so I bought the <a title="Bodum Kenya 16oz" href="http://www.amazon.com/Bodum-Kenya-16-Ounce-Coffee-Press/dp/B0000U6PWC" target="_blank">Bodum Kenya</a> model because it wasn&#8217;t as expensive as the Chambord (original &#8212; $40!).</p>
<p>On Wednesday I took a train down to Seattle to help my dad with some things at his business and ran into Symons across the street from the store.</p>
<p>Work has been uneventful, but I managed to finish the Perl script that I use to add new accounts.  It&#8217;s a lot more user-friendly now (view groups before selecting one, allow you to enter name or number, deal with non-ResTek accounts, etc.)  In addition to that, I extended our password-reset application.  It now supports changing more of your LDAP information such as phone numbers, email addresses, name, and login shell which means people don&#8217;t have to use <a title="phpldapadmin" href="http://phpldapadmin.sourceforge.net">phpldapadmin</a> (they still can).  I broke away from using our current Staff class which encompasses employee information in doing so, but since <a title="extended Zend_Ldap proposal" href="http://framework.zend.com/wiki/display/ZFPROP/Extended+Zend_Ldap+Proposal+-+Stefan+Gehrig" target="_blank">Zend_Ldap is going to be extended soon</a> (I hope!) I have plans to convert all of our PHP LDAP code to a consistent interface in the near future anyway.</p>
<div id="attachment_38" class="wp-caption alignleft" style="width: 138px"><a href="http://kianm.files.wordpress.com/2009/03/debian-vbox-vista-3-29-2009.png"><img class="size-thumbnail wp-image-38" title="debian-vbox-vista-3-29-2009" src="http://kianm.files.wordpress.com/2009/03/debian-vbox-vista-3-29-2009.png?w=128&#038;h=80" alt="Debian with VirtualBox (+Vista)" width="128" height="80" /></a><p class="wp-caption-text">Debian with VirtualBox (+Vista)</p></div>
<p>A while back I was talking to a friend and our discussion convinced me to install Linux (or something else) on my desktop.  I decided to give Debian another go, and I&#8217;ve been really happy with it.  I&#8217;ve had it on my laptop for quite a while, and now it&#8217;s on my desktop too.  The same discussion led to me installing VirtualBox, and I added 2GB more ram (making 4GB total) to my desktop to give my virtual machine(s) more memory.</p>
<p>When the time comes to buy a new laptop, I&#8217;ll probably use the same setup.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kianm.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kianm.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kianm.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kianm.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kianm.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kianm.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kianm.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kianm.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kianm.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kianm.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=36&subd=kianm&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kianm.wordpress.com/2009/03/29/inna-di-red/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/23f2c9fd20cc891d8d257388c7155e1f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kian</media:title>
		</media:content>

		<media:content url="http://kianm.files.wordpress.com/2009/03/kenya4.jpg" medium="image">
			<media:title type="html">Bodum Kenya French Press</media:title>
		</media:content>

		<media:content url="http://kianm.files.wordpress.com/2009/03/debian-vbox-vista-3-29-2009.png?w=128" medium="image">
			<media:title type="html">debian-vbox-vista-3-29-2009</media:title>
		</media:content>
	</item>
		<item>
		<title>Finals Week</title>
		<link>http://kianm.wordpress.com/2009/03/15/finals-week/</link>
		<comments>http://kianm.wordpress.com/2009/03/15/finals-week/#comments</comments>
		<pubDate>Sun, 15 Mar 2009 19:54:12 +0000</pubDate>
		<dc:creator>kian</dc:creator>
				<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://kianm.wordpress.com/?p=32</guid>
		<description><![CDATA[The end of another quarter is approaching which means finals are coming up.  I&#8217;ve got 2 on Monday (Business and Its Environment, and Business Database Development) and another on Thursday (Telecommunications).  The week before finals, known as &#8220;dead week&#8221;, turned out to be just an extension of finals week.  I had a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=32&subd=kianm&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The end of another quarter is approaching which means finals are coming up.  I&#8217;ve got 2 on Monday (Business and Its Environment, and Business Database Development) and another on Thursday (Telecommunications).  The week before finals, known as &#8220;dead week&#8221;, turned out to be just an extension of finals week.  I had a final for the lab portion of my database class, and another in MIS 495 &#8212; my capstone course &#8212; on Thursday, and a project due Friday.  It&#8217;s been a busy quarter.  It does look like I&#8217;m set to graduate this summer though.</p>
<p>I&#8217;m registered for next quarter: </p>
<ul>
<li>Computer-mediated communications</li>
<li>Network Administration</li>
<li>Humanities of Islamic Civilization</li>
<li>Gender and Society</li>
</ul>
<p>Pretty diverse schedule now that I have most of my major out of the way.</p>
<p>The world of ResTek has been quiet.  One of the two new developers is leaving WWU at the end of this quarter, leaving only one (Symons and Ben are gone after this quarter).  The servers are pretty easy to maintain and with zero budget to work with, I don&#8217;t have much to work with in the hardware upgrade realm.</p>
<p>I&#8217;d like to repartition the servers over break, since the current space allocation isn&#8217;t ideal.  The database server, for example, needs more space for /var.</p>
<p>I haven&#8217;t broken anything too terribly in a while, but I did render our logserver useless for a while:</p>
<p><code><br />
OpenBSD 4.5 (GENERIC) #1749: Sat Feb 28 14:51:18 MST 2009<br />
</code></p>
<p>I used the first 4.5 snapshots to do so.  When I upgraded the kernel and rebooted, I lost access.  When I finally made it down to Bond Hall on Monday, the problem became clear.  None of the network interfaces had been created because ifconfig(8) was out of sync with the new kernel due to some of the changes in 4.5.  I extracted the new ifconfig(8) from base45.tgz of my snapshot and that fixed the problem.  I later learned that a page for <a href="http://www.openbsd.org/faq/upgrade45.html">upgrade45.html</a> exists even though 4.5 is not yet released &#8212; I&#8217;ll be following a process more similar to the one mentioned therein from now on when using snapshots.</p>
<p>Snapshots can be more interesting than supported upgrades between releases and that&#8217;s why I like them.  They&#8217;re also relatively painless for the most part when you read about the changes made between releases (<a href="http://www.openbsd.org/faq/current.html">current.html</a>, <a href="http://www.openbsd.org/plus45.html">plus45.html</a>).</p>
<p>I&#8217;m excited to see what kind of impact the pfsync improvements will have on our firewalls.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kianm.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kianm.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kianm.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kianm.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kianm.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kianm.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kianm.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kianm.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kianm.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kianm.wordpress.com/32/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=32&subd=kianm&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kianm.wordpress.com/2009/03/15/finals-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/23f2c9fd20cc891d8d257388c7155e1f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kian</media:title>
		</media:content>
	</item>
		<item>
		<title>Secure LDAP Redundancy With OpenLDAP (Postfix, Dovecot, Apache, etc.)</title>
		<link>http://kianm.wordpress.com/2008/12/27/ldap-redundancy-with-openldap-postfix-dovecot-apache-etc/</link>
		<comments>http://kianm.wordpress.com/2008/12/27/ldap-redundancy-with-openldap-postfix-dovecot-apache-etc/#comments</comments>
		<pubDate>Sat, 27 Dec 2008 00:31:41 +0000</pubDate>
		<dc:creator>kian</dc:creator>
				<category><![CDATA[Technical]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kianm.wordpress.com/?p=13</guid>
		<description><![CDATA[Our LDAP clients previously connected to a single IP address (ldap.restek.wwu.edu) which was a virtual address (using CARP) shared by two LDAP servers in a master/slave setup with replication.  The slave of this pair was rarely used because the master rarely went down.  CARP, therefore, created host-level redundancy for our LDAP directory but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=13&subd=kianm&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Our LDAP clients previously connected to a single IP address (ldap.restek.wwu.edu) which was a virtual address (using <a href="http://en.wikipedia.org/wiki/Common_Address_Redundancy_Protocol">CARP</a>) shared by two LDAP servers in a master/slave setup with replication.  The slave of this pair was rarely used because the master rarely went down.  CARP, therefore, created host-level redundancy for our LDAP directory but not service-level.  The other host would have to lose network connectivity entirely for the slave to be used. </p>
<p>The load on the server wasn&#8217;t enough to justify load-balancing, but the setup had obvious problems.  For simplicity, the two shared the same SSL certificate/keys with just one CN (ldap.restek.wwu.edu) and no subjectAltNames to make connecting to other hostnames (i.e., directly to the slave) over SSL impossible.  Another problem was that when you needed to restart the OpenLDAP daemon for an upgrade on the master, it would be unable to look things up.  This required workarounds like adjusting CARP settings temporarily during upgrades.  Anyway, the setup was problematic and clearly not effective long-term.</p>
<p>Our certificates expired a day or two ago, and I decided to use the opportunity to fix the setup.</p>
<h3>1. New DNS names</h3>
<p>Rather than having only one name, I decided to create two more aliases for the LDAP servers: <em>ldap1</em>, and <em>ldap2</em>.  These were simply CNAMEs for our master and slave LDAP server, respectively.  This follows the convention that I used for nameserver naming: ns1, ns2, ns3, etc.</p>
<h3>2.  New certificates</h3>
<p>I also created new and unique self-signed certificates for each LDAP server.  I created certificates with information like the following:</p>
<p><code><br />
Subject:<br />
C=US, ST=Washington, L=Bellingham, O=Western Washington University, OU=ResTek,<br />
CN=vali.restek.wwu.edu/emailAddress=admin@restek.wwu.edu<br />
</code><br />
<code><br />
X509v3 Subject Alternative Name:<br />
DNS:vali.restek.wwu.edu, DNS:ldap1.restek.wwu.edu, DNS:ldap.restek.wwu.edu<br />
</code></p>
<p>The Subject Alternative Name (subjectAltName) piece, described in <a href="http://tools.ietf.org/html/rfc3280">RFC 3280</a>, is to ensure that people can securely connect to any of those three names without warnings or errors about the names not matching.  I believe it is possible to also use wildcard certificates, but I prefer this.  Wildcards are ambiguous <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   I added the primary hostname to subjectAltName because some reading indicated that a client might prefer alternative names over subject CN.  It may also be possible to leave CN blank in the case where you use subjectAltName, but I&#8217;m not sure how older clients handle this.</p>
<p>I installed these certificates on the clients (all FreeBSD servers) into <em>/etc/ssl/certs</em> with descriptive filenames.</p>
<p><code><br />
vali-restek-wwu-edu-ldap-20081223163515.crt<br />
vidar-restek-wwu-edu-ldap-20081223173447.crt<br />
</code></p>
<p>These &#8220;2008&#8243; numbers are simply the issue dates of the certificates.  I wasn&#8217;t sure whether I wanted to use issue date, expiration date, neither, or what.  But I ended up sticking with issue date for now.  The main reason behind this was to allow a new administrator to install new certificates without renaming the old ones.</p>
<p>If you&#8217;re at all familiar with SSL configuration, you may know that most applications allow you to specify a path to a <em>directory</em> of certificates rather than a filename.  This is most often used for CA certificates which you trust.  How are these located when you need them?  It seems that OpenSSL expects them to be located according to their hash.  Rather than rename them, I created links to the actual certificates using commands like the following:</p>
<p><code><br />
$ openssl x509 -hash -noout -in vali-restek-wwu-edu-ldap-20081223163515.crt<br />
51afeb96<br />
$ ln -s vali-restek-wwu-edu-ldap-20081223163515.crt 51afeb96.0<br />
</code></p>
<p>The extra digit (i.e. 0) appended to the end of the symbolic link name is used in case of multiple certificates with the same hash value.</p>
<h3>3.  pam_ldap, nss_ldap configuration</h3>
<p>I won&#8217;t go over the entire configurations I have &#8211; just what I changed.  First, I changed the URI to include both hosts:</p>
<p><code><br />
uri ldap://ldap1.restek.wwu.edu/ ldap://ldap2.restek.wwu.edu/<br />
</code></p>
<p>The second will be tried if the first fails, according to the documentation and my tests.  Obviously this is much better than a single CARP&#8217;ed IP address.</p>
<p>I also changed the certificate location from a single file to a directory:</p>
<p><code><br />
tls_cacertdir /etc/ssl/certs<br />
</code></p>
<p>This is where the symlinks come into play.  Notice I did not have to specify the actual filenames &#8212; just the directory where certificates are located.</p>
<h3>4.  Postfix</h3>
<p>The manual page <a href="http://www.postfix.org/ldap_table.5.html">ldap_table(5)</a> was <em>extremely</em> helpful (it described the necessity of the hash symlinks shown above in addition to exactly what Postfix needed).  Relevant parts of my Postfix LDAP configuration file (ldap.cf):</p>
<p><code><br />
server_host = ldap://ldap1.restek.wwu.edu ldap://ldap2.restek.wwu.edu<br />
start_tls = yes<br />
tls_ca_cert_dir = /etc/ssl/certs/<br />
tls_require_cert = yes<br />
</code></p>
<h3>5. Dovecot</h3>
<p>Dovecot <a href="http://wiki.dovecot.org/AuthDatabase/LDAP">documentation</a> wasn&#8217;t as clear.  I ended up looking at the source and discovered that it does support options similar to Postfix, but they aren&#8217;t in the wiki to my knowledge.  They are, however, documented in the example LDAP configuration included with the distribution.</p>
<p><code><br />
uris = ldap://ldap1.restek.wwu.edu ldap://ldap2.restek.wwu.edu<br />
tls = yes<br />
tls_ca_cert_dir = /etc/ssl/certs<br />
tls_require_cert = demand<br />
</code></p>
<h3>6.  Apache (mod_authnz_ldap) </h3>
<p>Not much needed to change in the Apache configuration, but one thing did require testing.  The syntax to specify multiple hosts is as follows:</p>
<p><code><br />
AuthLDAPURL "ldap://ldap1.restek.wwu.edu ldap2.restek.wwu.edu/ou=People,dc=restek,dc=wwu,dc=edu?uid?" TLS<br />
</code></p>
<p>I&#8217;m still trying to figure out how to configure Apache to trust certain certificates.</p>
<p>In order to make this easy to maintain in the future, I may end up setting up a local CA or using a free provider.  This way, the clients won&#8217;t need to be reconfigured when the certificates change.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kianm.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kianm.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kianm.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kianm.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kianm.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kianm.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kianm.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kianm.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kianm.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kianm.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=13&subd=kianm&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kianm.wordpress.com/2008/12/27/ldap-redundancy-with-openldap-postfix-dovecot-apache-etc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/23f2c9fd20cc891d8d257388c7155e1f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kian</media:title>
		</media:content>
	</item>
		<item>
		<title>blogging again!</title>
		<link>http://kianm.wordpress.com/2008/12/13/test-post/</link>
		<comments>http://kianm.wordpress.com/2008/12/13/test-post/#comments</comments>
		<pubDate>Sat, 13 Dec 2008 19:35:20 +0000</pubDate>
		<dc:creator>kian</dc:creator>
				<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://kianm.wordpress.com/?p=9</guid>
		<description><![CDATA[I upgraded the WordPress installations over at ResTek to 2.7 this morning and the new design made me want to start up my own blog again.  A while back I deleted my account over at Dreamhost because I got tired of paying for it so I decided to use this free service instead.
With me [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=9&subd=kianm&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I upgraded the WordPress installations over at <a title="ResTek" href="http://restek.wwu.edu">ResTek</a> to 2.7 this morning and the new design made me want to start up my own blog again.  A while back I deleted my account over at <a title="Dreamhost" href="http://www.dreamhost.com">Dreamhost</a> because I got tired of paying for it so I decided to use this free service instead.</p>
<p>With me being set to graduate in a 2-3 quarters (finally&#8230;), we&#8217;re looking for a new <a title="Server Admnistrator Description" href="http://restek.wwu.edu/about-us/jobs-at-restek/server-admin/">Server Administrator</a> for ResTek.  We found one to do the Housing stuff a while back.  The pay isn&#8217;t anything to write home about and you&#8217;re limited to 19 hours per week (40 during breaks) but it&#8217;s an opportunity to learn an incredible amount, whether it be through experimentation or your peers.  Things run really smoothly lately as far as the servers are concerned, but they won&#8217;t forever, and whoever is around will have an opportunity (like I did) to make improvments.</p>
<p>A while back I ended up picking up <a title="Samsung SyncMaster 2253BW" href="http://www.amazon.com/Samsung-SyncMaster-2253BW-22-inch-Monitor/dp/B0013PSOT0">a new monitor</a> finally.  Next on my list is a set of speakers, but I&#8217;m too broke to pay for those just yet and Christmas is coming up meaning I&#8217;ll be spending my money on gifts for people.  Estimates show the new monitor has increased my productivity about 35.7%.  It&#8217;s nothing amazing but it&#8217;s nice to be able to watch movies or TV shows (The X-Files) from the comfort of your bed.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kianm.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kianm.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kianm.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kianm.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kianm.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kianm.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kianm.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kianm.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kianm.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kianm.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kianm.wordpress.com&blog=5840128&post=9&subd=kianm&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://kianm.wordpress.com/2008/12/13/test-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/23f2c9fd20cc891d8d257388c7155e1f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kian</media:title>
		</media:content>
	</item>
	</channel>
</rss>