Categories

  • 13k Topics
    115k Posts
    Tom ElliottT

    @Coolguy3289 Thanks for the log line. It points at a bug, not at your approach.

    The installer creates a “FOG Agent CA” under the server root CA. It only creates it when the file is missing. If the root CA changes later (for example, you copy the old server’s /opt/fog/snapins/ssl onto the new box so existing clients keep trusting it), the agent CA stays signed by the first root. Every enrollment then fails with the error you see, and the agent gets a 503.

    The fix is in PR #1810: the installer now re-creates the agent CA when the current root did not sign it.

    To fix your server now, without waiting for the PR:

    sudo grep PKI_AGENT_CA_CERT /opt/fog/.fog-pki

    Move the .fogAgentCA.pem and .fogAgentCA.key files in that directory to a backup location. Then re-run the installer. It creates a new agent CA under your current root, and enrollment works.

    You do not need your internal PKI for this. The FOG-generated root is fine for production.

  • Get the latest news on what's happening.
    188 Topics
    829 Posts
    Tom ElliottT

    FOG 1.6.0-RC-4 is available

    The fourth release candidate for FOG 1.6.0 is on the rc-1.6.0 branch. It reports version 1.6.0-RC-4.

    Release page: https://github.com/FOGProject/fogproject/releases/tag/1.6.0-RC-4

    Upgrade from RC-3 now if you delete images or snapins from the web UI. In RC-3, the delete dialog can remove the files on the storage node even when the “remove file data” box is cleared.

    Fixed since RC-3

    A cleared “remove file data” box on the image or snapin delete dialog still deleted the files. It now keeps them. (#1819) When the storage node was unreachable, every snapin failed with “Hash does not match”. The server now returns an error status instead of a bad file. (#1817) The installer did not repair a missing service account home directory (by default /home/fogproject), which broke FTP and snapin downloads. It now repairs it on every run. (#1820) A failed schema update now shows the reason in the installer error log. (#1812) “On Server Size” now shows the image size right after a capture, not up to an hour later. This field is informational only. (#1814)

    Update (as root)

    A 1.6 beta or RC server: bin/updatefog.sh --channel rc from your FOG checkout. A 1.5 server installed from git: update to the current 1.5 stable, then run bin/updatefog.sh --channel rc. A new server, or a 1.5 server installed from a tarball:
    curl -fsSL https://raw.githubusercontent.com/FOGProject/fogproject/working-1.6/bin/bootstrap.sh | bash -s -- --channel rc

    Test on a lab or non-production server first. The upgrade from 1.5 to 1.6 changes the database schema, and there is no way back. Back up your database and /opt/fog/.fogsettings before you upgrade.

    Report problems at https://github.com/FOGProject/fogproject/issues with your FOG version, your OS, and the installer log from bin/error_logs/.

  • View tutorials or talk about FOG in general.
    2k Topics
    19k Posts
    8

    @Cpasjuste I just wanted to let you know that I’ve added in your method of using userland NFS support to my container. I have given you credit for the method in the README. I’d love for you to test it out if/when you get a chance. Thank you again for your work!

  • Report bugs, request features, or get the latest progress.
    2k Topics
    21k Posts
    S

    Hi @Tom-Elliott
    After moving from RC-2 to RC-4 the plugin, the WinPE image and the step that closes the task at the end of the WinPE flow all kept working. Only the Apache part needed a change.

    With RC-4 the whole vhost sits inside FOG’s managed block, so my earlier Alias plus rewrite exception was gone and /fog/winpe_3400/wimboot started answering 308 (FOG’s rewrite rule sends it to the API). Instead of putting the exception back, I now serve the files from /winpe_3400/ (no /fog/ prefix), with an Alias and a <Directory> in a separate conf-available file enabled with a2enconf. FOG’s rewrite rule only matches /fog/, so it never sees these requests, and nothing in 001-fog.conf should need restoring after an update. The only change in the plugin is its WIMBOOT_HTTP_PATH constant.

    Checked after the change: the Latitude fetches wimboot, BCD, boot.sdi and boot.wim from the new path (all 200), WinPE starts, and a full deploy on the Latitude 3400 and one on an HP with the normal FOS/Partclone flow both completed and closed their tasks.

77

Online

12.8k

Users

17.7k

Topics

157.2k

Posts