Files
HomeAudit/comprehensive_discovery_results/ssl_files_fedora.txt
admin 705a2757c1 Major infrastructure migration and Vaultwarden PostgreSQL troubleshooting
COMPREHENSIVE CHANGES:

INFRASTRUCTURE MIGRATION:
- Migrated services to Docker Swarm on OMV800 (192.168.50.229)
- Deployed PostgreSQL database for Vaultwarden migration
- Updated all stack configurations for Docker Swarm compatibility
- Added comprehensive monitoring stack (Prometheus, Grafana, Blackbox)
- Implemented proper secret management for all services

VAULTWARDEN POSTGRESQL MIGRATION:
- Attempted migration from SQLite to PostgreSQL for NFS compatibility
- Created PostgreSQL stack with proper user/password configuration
- Built custom Vaultwarden image with PostgreSQL support
- Troubleshot persistent SQLite fallback issue despite PostgreSQL config
- Identified known issue where Vaultwarden silently falls back to SQLite
- Added ENABLE_DB_WAL=false to prevent filesystem compatibility issues
- Current status: Old Vaultwarden on lenovo410 still working, new one has config issues

PAPERLESS SERVICES:
- Successfully deployed Paperless-NGX and Paperless-AI on OMV800
- Both services running on ports 8000 and 3000 respectively
- Caddy configuration updated for external access
- Services accessible via paperless.pressmess.duckdns.org and paperless-ai.pressmess.duckdns.org

CADDY CONFIGURATION:
- Updated Caddyfile on Surface (192.168.50.254) for new service locations
- Fixed Vaultwarden reverse proxy to point to new Docker Swarm service
- Removed old notification hub reference that was causing conflicts
- All services properly configured for external access via DuckDNS

BACKUP AND DISCOVERY:
- Created comprehensive backup system for all hosts
- Generated detailed discovery reports for infrastructure analysis
- Implemented automated backup validation scripts
- Created migration progress tracking and verification reports

MONITORING STACK:
- Deployed Prometheus, Grafana, and Blackbox monitoring
- Created infrastructure and system overview dashboards
- Added proper service discovery and alerting configuration
- Implemented performance monitoring for all critical services

DOCUMENTATION:
- Reorganized documentation into logical structure
- Created comprehensive migration playbook and troubleshooting guides
- Added hardware specifications and optimization recommendations
- Documented all configuration changes and service dependencies

CURRENT STATUS:
- Paperless services:  Working and accessible externally
- Vaultwarden:  PostgreSQL configuration issues, old instance still working
- Monitoring:  Deployed and operational
- Caddy:  Updated and working for external access
- PostgreSQL:  Database running, connection issues with Vaultwarden

NEXT STEPS:
- Continue troubleshooting Vaultwarden PostgreSQL configuration
- Consider alternative approaches for Vaultwarden migration
- Validate all external service access
- Complete final migration validation

TECHNICAL NOTES:
- Used Docker Swarm for orchestration on OMV800
- Implemented proper secret management for sensitive data
- Added comprehensive logging and monitoring
- Created automated backup and validation scripts
2025-08-30 20:18:44 -04:00

167 lines
12 KiB
Plaintext

/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt
/etc/pki/ca-trust/extracted/pem/directory-hash/ACCVRAIZ1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AC_RAIZ_FNMT-RCM.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/ANF_Secure_Server_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Actalis_Authentication_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AffirmTrust_Commercial.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AffirmTrust_Networking.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AffirmTrust_Premium.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/AffirmTrust_Premium_ECC.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Amazon_Root_CA_1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Amazon_Root_CA_2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Amazon_Root_CA_3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Amazon_Root_CA_4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Atos_TrustedRoot_2011.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/BJCA_Global_Root_CA1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/BJCA_Global_Root_CA2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Baltimore_CyberTrust_Root.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Buypass_Class_2_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Buypass_Class_3_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CA_Disig_Root_R2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CFCA_EV_ROOT.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/COMODO_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/COMODO_ECC_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/COMODO_RSA_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certainly_Root_E1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certainly_Root_R1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certigna.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certigna_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certum_EC-384_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certum_Trusted_Network_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certum_Trusted_Network_CA_2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Certum_Trusted_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CommScope_Public_Trust_ECC_Root-01.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CommScope_Public_Trust_ECC_Root-02.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CommScope_Public_Trust_RSA_Root-01.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/CommScope_Public_Trust_RSA_Root-02.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Comodo_AAA_Services_root.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/D-TRUST_BR_Root_CA_1_2020.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/D-TRUST_EV_Root_CA_1_2020.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/D-TRUST_Root_Class_3_CA_2_2009.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/D-TRUST_Root_Class_3_CA_2_EV_2009.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Assured_ID_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Assured_ID_Root_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Assured_ID_Root_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Global_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Global_Root_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Global_Root_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_High_Assurance_EV_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_TLS_ECC_P384_Root_G5.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_TLS_RSA4096_Root_G5.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/DigiCert_Trusted_Root_G4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Entrust.net_Premium_2048_Secure_Server_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Entrust_Root_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Entrust_Root_Certification_Authority_-_EC1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Entrust_Root_Certification_Authority_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Entrust_Root_Certification_Authority_-_G4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/FIRMAPROFESIONAL_CA_ROOT-A_WEB.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GDCA_TrustAUTH_R5_ROOT.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GLOBALTRUST_2020.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GTS_Root_R1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GTS_Root_R2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GTS_Root_R3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GTS_Root_R4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_ECC_Root_CA_-_R4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_ECC_Root_CA_-_R5.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_Root_CA_-_R3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_Root_CA_-_R6.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_Root_E46.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/GlobalSign_Root_R46.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Go_Daddy_Class_2_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Go_Daddy_Root_Certificate_Authority_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/HARICA_TLS_ECC_Root_CA_2021.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/HARICA_TLS_RSA_Root_CA_2021.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Hellenic_Academic_and_Research_Institutions_RootCA_2015.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/HiPKI_Root_CA_-_G1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Hongkong_Post_Root_CA_3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/ISRG_Root_X1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/ISRG_Root_X2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/IdenTrust_Commercial_Root_CA_1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/IdenTrust_Public_Sector_Root_CA_1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Izenpe.com.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Microsec_e-Szigno_Root_CA_2009.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Microsoft_ECC_Root_Certificate_Authority_2017.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Microsoft_RSA_Root_Certificate_Authority_2017.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/NAVER_Global_Root_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/NetLock_Arany__Class_Gold__F__tan__s__tv__ny.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/OISTE_WISeKey_Global_Root_GB_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/OISTE_WISeKey_Global_Root_GC_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/QuoVadis_Root_CA_1_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/QuoVadis_Root_CA_2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/QuoVadis_Root_CA_2_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/QuoVadis_Root_CA_3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/QuoVadis_Root_CA_3_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_EV_Root_Certification_Authority_ECC.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_EV_Root_Certification_Authority_RSA_R2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_Root_Certification_Authority_ECC.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_Root_Certification_Authority_RSA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_TLS_ECC_Root_CA_2022.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SSL.com_TLS_RSA_Root_CA_2022.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SZAFIR_ROOT_CA2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Sectigo_Public_Server_Authentication_Root_E46.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Sectigo_Public_Server_Authentication_Root_R46.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SecureSign_RootCA11.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SecureTrust_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Secure_Global_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Security_Communication_ECC_RootCA1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Security_Communication_RootCA2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Security_Communication_RootCA3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Starfield_Class_2_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Starfield_Root_Certificate_Authority_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Starfield_Services_Root_Certificate_Authority_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SwissSign_Gold_CA_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/SwissSign_Silver_CA_-_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/T-TeleSec_GlobalRoot_Class_2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/T-TeleSec_GlobalRoot_Class_3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TWCA_Global_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TWCA_Root_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Telekom_Security_TLS_ECC_Root_2020.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Telekom_Security_TLS_RSA_Root_2023.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TeliaSonera_Root_CA_v1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Telia_Root_CA_v2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TrustAsia_Global_Root_CA_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TrustAsia_Global_Root_CA_G4.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Trustwave_Global_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Trustwave_Global_ECC_P256_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/Trustwave_Global_ECC_P384_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/TunTrust_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/UCA_Extended_Validation_Root.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/UCA_Global_G2_Root.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/USERTrust_ECC_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/USERTrust_RSA_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/XRamp_Global_CA_Root.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/certSIGN_ROOT_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/certSIGN_Root_CA_G2.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/e-Szigno_Root_CA_2017.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/ePKI_Root_Certification_Authority.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/emSign_ECC_Root_CA_-_C3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/emSign_ECC_Root_CA_-_G3.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/emSign_Root_CA_-_C1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/emSign_Root_CA_-_G1.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/vTrus_ECC_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/directory-hash/vTrus_Root_CA.pem
/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
/etc/pki/ca-trust/extracted/pem/email-ca-bundle.pem
/etc/pki/ca-trust/extracted/pem/objsign-ca-bundle.pem
/etc/pki/ca-trust/source/ca-bundle.legacy.crt
/etc/pki/fwupd-metadata/LVFS-CA.pem
/etc/pki/fwupd/LVFS-CA.pem
/etc/pki/tls/certs/ca-bundle.crt
/etc/pki/tls/certs/ca-bundle.trust.crt
/etc/pki/tls/certs/ca-certificates.crt
/etc/pki/tls/cert.pem
/etc/ssl/cert.pem
/etc/unbound/dnssec-root.key
/etc/unbound/icannbundle.pem
/etc/unbound/root.key
/etc/brlapi.key
/etc/trusted-key.key
/opt/android-studio/plugins/android-ndk/resources/lldb/lib/python3.11/site-packages/pip/_vendor/certifi/cacert.pem