Rotate unused jens dyndns password for hygiene
Account has no hostname or key left to act on since the auth-binding fix, but its password predated the whole migration - rotated it via htpasswd -b. Verified new password works, old one is rejected, and the account is still fully inert for DNS updates either way. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -173,6 +173,15 @@ Nothing here is urgent; all are low-risk, no-downtime changes.
|
|||||||
`vpn` have now each been confirmed live across a real IP change with
|
`vpn` have now each been confirmed live across a real IP change with
|
||||||
their own dedicated login; this item is fully done, nothing further
|
their own dedicated login; this item is fully done, nothing further
|
||||||
to track.
|
to track.
|
||||||
|
**`jens` password rotated 2026-07-26**: since the account is now
|
||||||
|
unused (no hostname or key left to act on) and its old password
|
||||||
|
predates this whole migration, rotated it for hygiene via
|
||||||
|
`htpasswd -b`. Old `.htpasswd` backed up to
|
||||||
|
`/root/removed-configs-backup/dyndns-jens-rotate-20260726124040/`.
|
||||||
|
Verified: new password authenticates fine (`200`), old password now
|
||||||
|
gets `401`, and — as expected since the fix — even a successful
|
||||||
|
`jens` login still can't perform any DNS update (`badauth`). Account
|
||||||
|
kept around (not asked to remove it), but fully inert either way.
|
||||||
|
|
||||||
- [x] **dyndns/default-vhost access logging is a no-op** — done 2026-07-25
|
- [x] **dyndns/default-vhost access logging is a no-op** — done 2026-07-25
|
||||||
found 2026-07-20 while investigating the command injection below.
|
found 2026-07-20 while investigating the command injection below.
|
||||||
|
|||||||
Reference in New Issue
Block a user