• the_strange@feddit.org
        link
        fedilink
        English
        arrow-up
        46
        ·
        13 days ago

        The certificate for manjaro.org was renewed only a few hours ago. Given Manjaros track record, they probably let the cert expire (again) and fixed it since the original screenshot was taken.

        • Ghoelian@piefed.social
          link
          fedilink
          English
          arrow-up
          12
          ·
          13 days ago

          The screenshot seems to be taken at 1:50 utc, and the new certificate was valid from 00:18 utc. It is possible though that they just.enrolled the cert too late.

  • rozodru@piefed.world
    link
    fedilink
    English
    arrow-up
    114
    ·
    13 days ago

    some iconic duos in the Linux community: Arch and AUR malware, Ubuntu and bad updates, NixOS and community/team members leaving, Manjaro and failing to renew its cert.

    • not_IO@lemmy.blahaj.zoneOP
      link
      fedilink
      English
      arrow-up
      38
      arrow-down
      1
      ·
      13 days ago

      Welcome to Linux, do you want the BenevolentDictatorOS, WeaponsManifaturerOS, MalwareOS or Debian?

      • AVincentInSpace@pawb.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 days ago

        WeaponsManufacturerOS is Nix, obviously (they’ve since dropped Anduril as a sponsor but we’re never going to let them live it down), MalwareOS I’m guessing is Arch, but what’s BenevolentDictatorOS?

    • Dran@lemmy.world
      link
      fedilink
      arrow-up
      21
      ·
      13 days ago

      Ubuntu and bad updates

      This is the only drama in your list I’m not familiar with already. What/when did they last break?

      • SwingingTheLamp@piefed.zip
        link
        fedilink
        English
        arrow-up
        7
        ·
        13 days ago

        Recently, the nvidia-dkms driver updates wouldn’t build for 5.x series kernels, so if you hadn’t cleaned up old kernels, the update bombed out before updating the initrd filesystem, the system couldn’t boot without intervention. Thankfully, I noticed before trying to reboot my work desktop, and the solution was “apt autoremove && apt upgrade”.

        But the install media for my desktop at home was 18.04, and it’s running 26.04 now. It has an AMD GPU, so it hasn’t had update problems.

        • kungen@feddit.nu
          link
          fedilink
          arrow-up
          1
          ·
          12 days ago

          If your playbooks don’t include an autoremove, you’re doing it wrong!

          Or rather, lessons learned from when the default /boot partition was only like 100 MB.

        • Auth@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          12 days ago

          Its intended behavior from Debian team. because they ships a version of the software at the time and only backport security patches. So if the version they ship has bugs then those bugs stay for years. This generates quite a bit of noise for upstream projects but it is what it is.

  • Natanox@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    82
    ·
    13 days ago

    The funniest thing about this is that it needs a single Bash script and a cronjob to solve (unless they got a REALLY bad hoster).

    That bash script probably exists a bazillion times already… so even an LLM could spit it out for them.

    Their organisational structure must be abhorrent for nobody to feel even remotely responsible for this.

    • loutr@sh.itjust.works
      link
      fedilink
      arrow-up
      57
      ·
      13 days ago

      Most web server have ACME support built-in nowadays, setup is a matter of minutes, no scripting required. This has been a solved problem for years, any sysadmin who can’t handle this basic task has no business running public-facing servers.

    • Ann Archy@lemmy.world
      link
      fedilink
      arrow-up
      13
      ·
      edit-2
      13 days ago

      BINGO!

      In fact I got a full 5x5 card of bingo because I wrote “Manjaro doesn’t renew its cert” in all of the boxes.

    • muhyb@programming.dev
      link
      fedilink
      arrow-up
      17
      ·
      13 days ago

      Well, Manjaro popped up when a lot of people cannot install Arch on their own. Same thing with Ubuntu and Debian. Once a userbase formed, people follow suit I guess.

    • brucethemoose@lemmy.world
      link
      fedilink
      arrow-up
      13
      ·
      13 days ago

      It was part of my linux journey long ago, and TBH I bet many still run into in from historical recommendations and popularity.

      But I think CachyOS is taking over their “preconfigured arch with the most SEO” spot.

    • Frank Exchange of Views@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      13 days ago

      Honestly, I installed it on my 2nd laptop and workstation because I really wanted the AUR, but got tired of Arch unstable update process 15 years ago and left Linux for personal use for MacOS. It still has everything I want on my main laptop, home brew and a terminal with tmux.

      It just works and I just couldn’t be arsed reinstalling, but yeah, if I would, I would just use Arch again now.

      • toddestan@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        13 days ago

        I’m also in the club of having a couple of Manjaro installs that now date back a few years to when it was still cool.

        Honestly as a distro it works pretty well and my complaints are few. If I had to reinstall I’d take a closer look at CachyOS, EndeavourOS, or even just Arch, but I can’t really be bothered to replace something that’s working just fine so I’ll stick with it for now.

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      12 days ago

      The website cert is the one that expires. It doesn’t impact anything else about the distro. The package mirrors are on different hosts (and certs). It’s a good distro, wish they’d sort out the kerfuffle with the founder (who’s the one holding them back).

  • esc@piefed.social
    link
    fedilink
    English
    arrow-up
    36
    ·
    13 days ago

    A little stability and consistency in the world, manjaro always delivers when it comes to this.

  • Victor@lemmy.world
    link
    fedilink
    arrow-up
    35
    ·
    13 days ago

    Like, when you… “get” the certificate… Doesn’t it say… “on it” exactly which date it expires? So maybe set a thing in your calendar or an alarm on your phone or some shit? How hard can this be?

    • pressanykeynow@lemmy.world
      link
      fedilink
      arrow-up
      46
      ·
      13 days ago

      LetsEncrypt also gives you a month to update certificate, you don’t even have to do it yourself, just run a script once a week in cron. That’s such a level of incompetence I wonder why anyone will trust them with a distro when they can’t even do such a simple task.

      • TerHu@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        14
        ·
        13 days ago

        yes, but the people who want to implement that are held back and sabotaged by the guy who owns the shit. this is not about incompetence.

    • The_v@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      13 days ago

      You could proactively take care of it with a reminder on the calendar. Or alternatively, just let the community inform you when you need to renew it. Both are effective methods.

      • chronicledmonocle@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        13 days ago

        They use LetsEncrypt. There is literally a bot you can install to automate the renewal process daily on a cron schedule and notify you if it fails.

        They’re just fucking morons managing the infra for their domain.

        • The_v@lemmy.world
          link
          fedilink
          arrow-up
          5
          ·
          13 days ago

          Yes there is an easy fix that will make the problem go away. At this point you know it’s deliberate.

          I personally think it’s hilarious.

        • The_v@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          13 days ago

          Since I have never used the distro but have seen threads like these popping up every time the cert expires, I don’t think it takes much trust.

          Also it’s pretty fucking hilarious.

    • Ann Archy@lemmy.world
      link
      fedilink
      arrow-up
      14
      ·
      13 days ago

      Why isn’t it for everyone? How often I see this with, I mean, major actors is head shakingly baffling.

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      12
      ·
      12 days ago

      Why isn’t this an automated processs for them?

      Because manjaro.org is controlled personally by Phil, the CEO of the company, who’s paranoid about letting anybody else handle it. And also can’t figure out how to renew automatically, apparently. People have to remind him on Discord. 🤦

      Everything else *.manjaro.org (forums, mirrors etc.) is handled by different people and have never expired afaik.

      It’s literally just the main webpage that has this problem, everything else about the distro is never impacted.

      • StarDreamer@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        14
        ·
        13 days ago

        This came up last time the cert expired iirc.

        Tl;dr one of the founders is holding up the infra not allowing any change. According to someone who worked on Manjaro, it was trivially easy to get this fixed, but that single person simply wouldn’t approve it. Last I checked they sent the founder an ultimatum: either hand over the project or see the staff walk. I suppose the staff walked.

  • renegadespork@lemmy.jelliefrontier.net
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    1
    ·
    13 days ago

    This is literally why I stopped using Manjaro.

    I’ve botched 2 Manjaro installs just doing a pacman -Syu while their certs were expired and I ended up with an incomplete upgrade.

    Never once had this issue with EndeavorOS.

    • StarDreamer@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      13 days ago

      Doesn’t happen with Antergos either.

      I mean, I’ve gotten a NXDomain error ever since they shut down, but at least it’s not a certificate expiry!

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      12 days ago

      Look, I don’t want to call you a liar… so let’s say maybe you meant to say pamac or got things wrong.

      Because:

      1. That’s not how pacman works. If it hits a mirror with expired certs it just outputs a warning and uses another mirror.
      2. On a fresh install Manjaro will compile an optical subset of mirrors for you based on location and response time. Those mirrors are spread around the world on different domains. It’s very unlikely that your list would include ONLY mirrors.manjaro.org and mirrors2.manjaro.org.
      3. But even if it did, and let’s say for the sake of argument there is a bug in pacman AND you got those mirrors… those two hosts are on a different certificate from manjaro.org (the website), are CNAME’d to .rsc.cdn77.org hosts, get renewed automatically separately from the website cert, and have never been allowed to lapse afaik.
      • renegadespork@lemmy.jelliefrontier.net
        link
        fedilink
        English
        arrow-up
        5
        ·
        12 days ago

        Maybe it wasn’t due to certs, but it still happened. That was enough for me to switch distros. I was much less experienced with Linux back then, so I wasn’t able to figure out how to get it working again.

        So far I’ve daily-driven EndeavorOS, Mint, PopOS, and Kubuntu. None of them have broken themselves with an apt or pacman upgrade.

  • VonReposti@feddit.dk
    link
    fedilink
    arrow-up
    24
    ·
    13 days ago

    Seems fine for me now. In fact it looks like they switched to Let’s Encrypt for certification so maybe they learned something from last time.