Live data from Hacker News

Manjaro website off-line again due to lapsed certificate

distrowatch.com

31–40 of 43 posts

Re: Manjaro website off-line again due to lapsed certificate

#31
post #9

I love Manjaro too much, use it as daily distro but their certificate issues and its recursive behaviour threaten me a little bit.

Try CachyOS

Same issue as Monds comments. When arch pushes an update the package database becomes inconsistent until cachyos syncs it, which can take 30 minutes. Cachy packages just increment a nonce on the package version numbers so when arch pushes updates they get considered to be more recent than the Cachy versions, cause .so dependency errors. It's all just one fragile stateful system

Re: Manjaro website off-line again due to lapsed certificate

#33
post #31

Earlier quoted context omitted.

Try CachyOS

Same issue as Monds comments. When arch pushes an update the package database becomes inconsistent until cachyos syncs it, which can take 30 minutes. Cachy packages just increment a nonce on the package version numbers so when arch pushes updates they get considered to be more recent than the Cachy versions, cause .so dependency errors. It's all just one fragile stateful system

yeah its fast doe

Re: Manjaro website off-line again due to lapsed certificate

#34

If you never want this to happen again to your systems, we’re building a tool that bakes monitoring and validation into automatic cert renewals. https://www.certkit.io/ >

You're developing "certbot, but it's paid and sends private keys around the network instead of generating the csr locally"? Why? Who's the target audience? Platforms that can't run certbot, or any of the infinite amount of other acme clients, most likely won't be able to run your agent as well, so what's the value add vs just running a regular, well-defined (and free!) acme client and just moving the cert over manually?

Re: Manjaro website off-line again due to lapsed certificate

#35

Earlier quoted context omitted.

This is like the third or fourth time this has happened to them. The Manjaro team has also caught flak for a bunch of other stuff. There's a page or two our there that detail the issues, which I'm too lazy to link here. But let's just say this isn't their first rodeo.

Going to play devil's advocate and say that they make minimal to no revenue off of their website so it being down is not a huge deal. It's exactly the opposite to what happens if the the main ad server for a company in the ad serving business looks at things. Or another example: From an inventory management perspective, it's ok to be out of stock for low margin items b/c the opportunity cost is low.

[deleted]

Re: Manjaro website off-line again due to lapsed certificate

#36
post #4

I used Manjaro for a few years. That's how I learned a pretty important lesson about software engineering that still informs how I work to this day. "A layer of abstraction on top of a stateful legacy system often doesn't result in a simpler system, it just introduces exciting new failure possibilities. This especially applies when the owners of the legacy system have no responsibility over the abstraction layer."

The word "legacy" doesn't seem needed there.

Re: Manjaro website off-line again due to lapsed certificate

#37

Earlier quoted context omitted.

This is like the third or fourth time this has happened to them. The Manjaro team has also caught flak for a bunch of other stuff. There's a page or two our there that detail the issues, which I'm too lazy to link here. But let's just say this isn't their first rodeo.

Going to play devil's advocate and say that they make minimal to no revenue off of their website so it being down is not a huge deal. It's exactly the opposite to what happens if the the main ad server for a company in the ad serving business looks at things. Or another example: From an inventory management perspective, it's ok to be out of stock for low margin items b/c the opportunity cost is low.

> Going to play devil's advocate and say that they make minimal to no revenue off of their website so it being down is not a huge deal.

How much revenue they make doesn't matter if it impacts users. Prospective users need to be able to see what they are getting and download and verify ISOs from the team.

I despise ZorinOS for what they are doing in many ways that violate software licenses, but one thing they got right is charging users and being somewhat accountable to their userbase.

Re: Manjaro website off-line again due to lapsed certificate

#38
post #9

I love Manjaro too much, use it as daily distro but their certificate issues and its recursive behaviour threaten me a little bit.

I went from Manjaro to EndeavourOS. Great experience and I don't see it changing anytime soon. The community is healthy and the project well managed.

Re: Manjaro website off-line again due to lapsed certificate

#39
post #6

A lot of repositories and similar go offline randomly. It hasn't happened in a few months but usually the Microsoft package mirrors go past their Azure limits and I get reminders.

This is like the third or fourth time this has happened to them. The Manjaro team has also caught flak for a bunch of other stuff. There's a page or two our there that detail the issues, which I'm too lazy to link here. But let's just say this isn't their first rodeo.

> There's a page or two our there that detail the issues, which I'm too lazy to link here.

https://manjarno.pages.dev/ (hasn't been updated yet)

Re: Manjaro website off-line again due to lapsed certificate

#40
post #17

Earlier quoted context omitted.

"I use arbitrarily complex software that has a rapid SDLC to obfuscate the issue with the fact that we have to have military grade encryption for displaying the equivalent of a poster over the internet". The state of our industry is such that there will be a lot of people arguing for this absurdity in the replies to me. (or I'll be flagged to death). Package integrity makes sense, and someone will make the complicate…

Nah, you've simply never lived in a country which is afraid of its own population and does (or tried to) MITM internet traffic. Mine does both, there was a scandal several years ago: https://news.ycombinator.com/item?id=20472179 I'll take enforced HTTPS for absolutely everything, thank you very much. Preferably with certificate pinning and similar aggressive measures to thwart any attempts to repeat this.

> MITM internet traffic.

Are there countries that don't do this ?

Post reply on HN