Index: branches/fc11-dev/server/fedora/Makefile
===================================================================
--- branches/fc11-dev/server/fedora/Makefile	(revision 1175)
+++ branches/fc11-dev/server/fedora/Makefile	(revision 1179)
@@ -21,5 +21,5 @@
 upstream_yum	= krb5 httpd openssh php
 upstream	= openafs $(upstream_yum)
-oursrc		= execsys tokensys accountadm httpdmods logview sql-signup nss_nonlocal nss_nonlocal.i386 whoisd mit-zephyr nss-ldapd scripts-base
+oursrc		= execsys tokensys accountadm httpdmods logview sql-signup nss_nonlocal nss_nonlocal.i586 whoisd mit-zephyr nss-ldapd nss-ldapd.i586 scripts-base
 allsrc		= $(upstream) $(oursrc)
 oursrcdir	= ${PWD}/../common/oursrc
@@ -127,9 +127,9 @@
 $(oursrc): rpmbuild_args += --define 'scriptsversion $(shell svnversion ${oursrcdir}/$** | tr ':' '_')'
 
-$(filter %.i386,$(oursrc)): %.i386: setup
+$(filter %.i586,$(oursrc)): %.i586: setup
 	PATH="/usr/kerberos/sbin:/usr/kerberos/bin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin" \
-	setarch i386 rpmbuild $(rpmbuild_args) --target=i386 --define="_lib lib" -bb ${tmp_specs}/$**.spec
+	setarch i586 rpmbuild $(rpmbuild_args) --target=i586 --define="_lib lib" -bb ${tmp_specs}/$**.spec
 
-$(filter-out %.i386,$(oursrc)): %: setup
+$(filter-out %.i586,$(oursrc)): %: setup
 	PATH="/usr/kerberos/sbin:/usr/kerberos/bin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin" \
 	rpmbuild $(rpmbuild_args) -bb ${tmp_specs}/$**.spec
@@ -180,5 +180,5 @@
 # The following packages are needed for our packages
 basic-deps	= kernel-devel rpm-build rpmdevtools gcc autoconf patch krb5-workstation glibc-devel.i586 glibc-devel libtool libgcc.i586
-oursrc-deps	= hesinfo openldap-clients
+oursrc-deps	= hesinfo openldap-clients openldap-devel.i586
 httpdmods-deps	= httpd-devel
 httpd-deps	= xmlto db4-devel expat-devel zlib-devel libselinux-devel apr-devel apr-util-devel pcre-devel openssl-devel distcache-devel
Index: branches/fc11-dev/server/fedora/config/etc/environment
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/environment	(revision 1179)
+++ branches/fc11-dev/server/fedora/config/etc/environment	(revision 1179)
@@ -0,0 +1,1 @@
+JAVA_TOOL_OPTIONS=-Xmx128M
Index: branches/fc11-dev/server/fedora/config/etc/httpd/vhosts.d/cycling-club.conf
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/httpd/vhosts.d/cycling-club.conf	(revision 1175)
+++ 	(revision )
@@ -1,32 +1,0 @@
-# do not trailing-slash DocumentRoot
-
-<VirtualHost *:80>
-	ServerName cycling-club.scripts.mit.edu
-	ServerAlias cycling-club.scripts
-	DocumentRoot /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-	Alias /~cycling-club /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-	SuExecUserGroup cycling-club cycling-club
-	Include conf.d/vhosts-common.conf
-</VirtualHost>
-
-<IfModule ssl_module>
-	<VirtualHost *:443>
-		ServerName cycling-club.scripts.mit.edu
-		ServerAlias cycling-club.scripts
-		DocumentRoot /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-		Alias /~cycling-club /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-		SuExecUserGroup cycling-club cycling-club
-		Include conf.d/vhosts-common-ssl.conf
-		SSLCertificateFile /etc/pki/tls/certs/cycling-club.pem
-	</VirtualHost>
-	<VirtualHost *:444>
-		ServerName cycling-club.scripts.mit.edu
-		ServerAlias cycling-club.scripts
-		DocumentRoot /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-		Alias /~cycling-club /afs/athena.mit.edu/activity/c/cycling-club/web_scripts
-		SuExecUserGroup cycling-club cycling-club
-		Include conf.d/vhosts-common-ssl.conf
-		Include conf.d/vhosts-common-ssl-cert.conf
-		SSLCertificateFile /etc/pki/tls/certs/cycling-club.pem
-	</VirtualHost>
-</IfModule>
Index: branches/fc11-dev/server/fedora/config/etc/httpd/vhosts.d/geofft.conf
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/httpd/vhosts.d/geofft.conf	(revision 1179)
+++ branches/fc11-dev/server/fedora/config/etc/httpd/vhosts.d/geofft.conf	(revision 1179)
@@ -0,0 +1,32 @@
+# do not trailing-slash DocumentRoot
+
+<VirtualHost *:80>
+	ServerName geofft.mit.edu
+	ServerAlias geofft
+	DocumentRoot /afs/athena.mit.edu/user/g/e/geofft/web_scripts/geofft
+	Alias /~geofft /afs/athena.mit.edu/user/g/e/geofft/web_scripts
+	SuExecUserGroup geofft geofft
+	Include conf.d/vhosts-common.conf
+</VirtualHost>
+
+<IfModule ssl_module>
+	<VirtualHost *:443>
+		ServerName geofft.mit.edu
+		ServerAlias geofft
+		DocumentRoot /afs/athena.mit.edu/user/g/e/geofft/web_scripts/geofft
+		Alias /~geofft /afs/athena.mit.edu/user/g/e/geofft/web_scripts
+		SuExecUserGroup geofft geofft
+		Include conf.d/vhosts-common-ssl.conf
+		SSLCertificateFile /etc/pki/tls/certs/geofft.pem
+	</VirtualHost>
+	<VirtualHost *:444>
+		ServerName geofft.mit.edu
+		ServerAlias geofft
+		DocumentRoot /afs/athena.mit.edu/user/g/e/geofft/web_scripts/geofft
+		Alias /~geofft /afs/athena.mit.edu/user/g/e/geofft/web_scripts
+		SuExecUserGroup geofft geofft
+		Include conf.d/vhosts-common-ssl.conf
+		Include conf.d/vhosts-common-ssl-cert.conf
+		SSLCertificateFile /etc/pki/tls/certs/geofft.pem
+	</VirtualHost>
+</IfModule>
Index: branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/check.pl
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/check.pl	(revision 1179)
+++ branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/check.pl	(revision 1179)
@@ -0,0 +1,28 @@
+#!/usr/bin/perl
+
+use File::Basename;
+use Date::Parse;
+
+my $dir = basename($0);
+chdir $dir;
+
+my $now = time();
+
+our $verbose = 0;
+$verbose = 1 if ($ARGV[0] eq "-v");
+
+use constant WARNING => 60*60*24*14; # Warn if a cert is expiring within 14 days
+
+foreach my $cert (glob "*.pem") {
+  open(X509, "-|", qw(openssl x509 -in), $cert, qw(-enddate -noout)) or die "Couldn't invoke openssl x509: $!";
+  chomp(my $exp = <X509>);
+  close(X509);
+  $exp =~ s/^notAfter=// or warn "Cert appears broken: $cert";
+
+  my $time = str2time($exp);
+
+  if ($verbose || ($time - $now) <= WARNING) {
+    printf "Certificate expiring in %.2f days: %s for ", (($time - $now) / (60.0*60*24)), $cert;
+    system(qw(openssl x509 -in), $cert, qw(-subject -noout));
+  }
+}
Index: branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/cycling-club.pem
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/cycling-club.pem	(revision 1175)
+++ 	(revision )
@@ -1,35 +1,0 @@
------BEGIN CERTIFICATE-----
-MIIGETCCBPmgAwIBAgIQOTKSLw4+ShFTT6pc11D3azANBgkqhkiG9w0BAQUFADCB
-lzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
-Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
-dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xHzAdBgNVBAMTFlVUTi1VU0VSRmlyc3Qt
-SGFyZHdhcmUwHhcNMDkwNDE3MDAwMDAwWhcNMDkwNTE3MjM1OTU5WjCCAVgxCzAJ
-BgNVBAYTAlVTMQ4wDAYDVQQREwUwMjEzOTEWMBQGA1UECBMNTWFzc2FjaHVzZXR0
-czESMBAGA1UEBxMJQ2FtYnJpZGdlMR0wGwYDVQQJExQ4NCBNYXNzYWNodXNldHRz
-IEF2ZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUgb2YgVGVjaG5v
-bG9neTEYMBYGA1UECxMPc2NyaXB0cy5taXQuZWR1MS0wKwYDVQQLEyRURVNUIFVT
-RSBPTkxZIC0gTk8gV0FSUkFOVFkgQVRUQUNIRUQxMzAxBgNVBAsTKkhvc3RlZCBi
-eSBTZWN1cmUgU29ja2V0cyBMYWJvcmF0b3JpZXMsIExMQzEZMBcGA1UECxMQQ29t
-b2RvIFRyaWFsIFNTTDElMCMGA1UEAxMcY3ljbGluZy1jbHViLnNjcmlwdHMubWl0
-LmVkdTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAtT4hTcGJawGMR4D+szcn
-dvhSQeaiPUt2eOXyZjwPsa37l48uorZT07YO4mb5uQu3zrTV9RwfbyJ9SPVt8BbN
-jkh50RRKFC8v+MS9HYfPfYtcd61YJLAOoW3WCsfYvC9nZchd2NgxwmdLSvShpVSC
-r8s0CCoEf458TLfb3GqKXYECAwEAAaOCAhcwggITMB8GA1UdIwQYMBaAFKFyXyYb
-KJhDlV0HN9WFlp1L0sNFMB0GA1UdDgQWBBRUEXwJVUQclEWponZGKywkJmpE6DAO
-BgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADAdBgNVHSUEFjAUBggrBgEFBQcD
-AQYIKwYBBQUHAwIwEQYJYIZIAYb4QgEBBAQDAgbAMEYGA1UdIAQ/MD0wOwYMKwYB
-BAGyMQECAQMEMCswKQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5u
-ZXQvQ1BTMHsGA1UdHwR0MHIwOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29t
-L1VUTi1VU0VSRmlyc3QtSGFyZHdhcmUuY3JsMDagNKAyhjBodHRwOi8vY3JsLmNv
-bW9kby5uZXQvVVROLVVTRVJGaXJzdC1IYXJkd2FyZS5jcmwwcQYIKwYBBQUHAQEE
-ZTBjMDsGCCsGAQUFBzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNvbS9VVE5BZGRU
-cnVzdFNlcnZlckNBLmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2Rv
-Y2EuY29tMEkGA1UdEQRCMECCHGN5Y2xpbmctY2x1Yi5zY3JpcHRzLm1pdC5lZHWC
-IHd3dy5jeWNsaW5nLWNsdWIuc2NyaXB0cy5taXQuZWR1MA0GCSqGSIb3DQEBBQUA
-A4IBAQAOWgCNSXK8Ff3XoQrmdxc1iI1eXVi5HNQFBn3fhFIUyhHXAyqg5GkrcM7x
-w1APfNur0rum17lWCFtArVRPss4IJzrkipnIzgRPqRhXwGtiz5/bYkXPwHCYMQup
-XHKm34nnNjvWQtXuMiCKAZ1sX9trCChvqxm6limhiPpSjyrwnKullRa+y4ADIGcn
-wDoSO8lu0NqXlNcm6y3HWfaCQXR2l3XyGNFwO69WU+RRh2LAmpQ1tmZbdiAAU1x+
-4dvmkSKgq+x6w+R5RakUvpMiZ5F5SS6jCyqgvqP/Hy5VXJvgRbYjnXD6Du2+MA7n
-bFIuEbqwW1yMuBXFKBdwwbd1KWYM
------END CERTIFICATE-----
Index: branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/geofft.pem
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/geofft.pem	(revision 1179)
+++ branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/geofft.pem	(revision 1179)
@@ -0,0 +1,20 @@
+-----BEGIN CERTIFICATE-----
+MIIDSTCCArKgAwIBAgIDC5fgMA0GCSqGSIb3DQEBBQUAMFoxCzAJBgNVBAYTAlVT
+MRwwGgYDVQQKExNFcXVpZmF4IFNlY3VyZSBJbmMuMS0wKwYDVQQDEyRFcXVpZmF4
+IFNlY3VyZSBHbG9iYWwgZUJ1c2luZXNzIENBLTEwHhcNMDkwNTEzMDEzNTA3WhcN
+MDkwNjEzMDkwMjA4WjCBuDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDmdlb2ZmdC5t
+aXQuZWR1MRMwEQYDVQQLEwpHVDAzOTQ4OTc5MTEwLwYDVQQLEyhTZWUgd3d3LnJh
+cGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTA5MS8wLQYDVQQLEyZEb21haW4g
+Q29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEXMBUGA1UEAxMOZ2VvZmZ0
+Lm1pdC5lZHUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALU+IU3BiWsBjEeA
+/rM3J3b4UkHmoj1Ldnjl8mY8D7Gt+5ePLqK2U9O2DuJm+bkLt8601fUcH28ifUj1
+bfAWzY5IedEUShQvL/jEvR2Hz32LXHetWCSwDqFt1grH2LwvZ2XIXdjYMcJnS0r0
+oaVUgq/LNAgqBH+OfEy329xqil2BAgMBAAGjgb0wgbowDgYDVR0PAQH/BAQDAgTw
+MB0GA1UdDgQWBBRUEXwJVUQclEWponZGKywkJmpE6DA7BgNVHR8ENDAyMDCgLqAs
+hipodHRwOi8vY3JsLmdlb3RydXN0LmNvbS9jcmxzL2dsb2JhbGNhMS5jcmwwHwYD
+VR0jBBgwFoAUvqigdHJQa0S3ySPY+6j/s1draGwwHQYDVR0lBBYwFAYIKwYBBQUH
+AwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQEFBQADgYEAO7B0
+T9u1ut4xt7FHPzd2WpUbOm2PfCRwwAlHk9tml5awQRwdpZvl/JrZCi5EU+vZ78hf
+mKzuf7r0JOCS8SxogEcOmBp/brBjkAfWzW/UFdRnqse8ytUMdAgjylS0bVau7OAf
+cB13QcrOBu0HK+FiuyAAqQLHqBPRNLOjV2DFqug=
+-----END CERTIFICATE-----
Index: branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/scripts.pem
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/scripts.pem	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/scripts.pem	(revision 1179)
@@ -2,11 +2,11 @@
     Data:
         Version: 3 (0x2)
-        Serial Number: 2871 (0xb37)
+        Serial Number: 745256 (0xb5f28)
         Signature Algorithm: sha1WithRSAEncryption
-        Issuer: C=US, ST=Massachusetts, O=Massachusetts Institute of Technology, OU=MIT Certification Authority
+        Issuer: C=US, O=Equifax, OU=Equifax Secure Certificate Authority
         Validity
-            Not Before: Jul 23 16:00:00 2008 GMT
-            Not After : Jul 23 16:00:00 2009 GMT
-        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=Student Information Processing Board, CN=scripts.mit.edu/Email=scripts@mit.edu
+            Not Before: Jun  4 20:22:36 2009 GMT
+            Not After : Jun  7 02:53:00 2011 GMT
+        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=Student Information Processing Board, CN=scripts.mit.edu
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
@@ -24,41 +24,42 @@
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
-            X509v3 Basic Constraints: 
-                CA:FALSE
-            Netscape Cert Type: 
-                SSL Client, SSL Server, S/MIME
-            X509v3 Extended Key Usage: 
-                TLS Web Server Authentication, E-mail Protection, TLS Web Client Authentication
-            X509v3 Key Usage: 
-                Digital Signature, Non Repudiation, Key Encipherment
+            X509v3 Key Usage: critical
+                Digital Signature, Non Repudiation, Key Encipherment, Data Encipherment
             X509v3 Subject Key Identifier: 
                 54:11:7C:09:55:44:1C:94:45:A9:A2:76:46:2B:2C:24:26:6A:44:E8
+            X509v3 CRL Distribution Points: 
+                URI:http://crl.geotrust.com/crls/secureca.crl
+
+            X509v3 Authority Key Identifier: 
+                keyid:48:E6:68:F9:2B:D2:B2:95:D7:47:D8:23:20:10:4F:33:98:90:9F:D4
+
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
     Signature Algorithm: sha1WithRSAEncryption
-        3f:34:05:8a:a7:a1:c1:51:9b:f0:6d:c6:e4:2a:aa:fc:cd:2a:
-        50:8e:36:12:74:7e:d8:9f:a7:db:63:cf:d2:19:48:01:00:aa:
-        50:f8:83:5c:5b:4b:68:b8:de:a6:0a:2b:0d:f0:af:fa:d6:92:
-        a5:46:73:20:e4:1c:62:d4:a3:b7:48:8d:f4:6a:88:d2:a8:e0:
-        2a:38:ab:c8:df:9a:55:ec:e5:83:c7:1f:e5:63:d5:b6:d5:3d:
-        30:6e:a3:6e:30:84:d1:f2:35:09:b9:31:e1:c8:f1:3d:11:4d:
-        99:ad:f7:33:95:8d:d7:5c:88:6a:49:23:02:1e:7d:94:ff:a7:
-        7f:bf
+        0e:42:72:ba:24:61:07:eb:69:d6:3e:4a:e9:ec:a3:f8:16:c0:
+        a2:31:2d:f0:93:ec:37:2c:dc:c0:7c:a6:9e:60:52:d4:c6:af:
+        f4:c7:cb:f0:ad:bf:3c:b8:34:a7:1e:35:c3:15:84:f6:79:96:
+        f3:ec:d7:78:62:83:81:b5:bb:5e:77:0a:19:b6:d1:9f:ae:a9:
+        0b:f6:8a:7c:71:1e:a9:8e:e7:3d:e7:a6:38:47:3a:9f:0c:69:
+        37:a1:3f:0e:44:77:47:b9:75:4a:49:08:f3:42:43:58:2c:24:
+        d2:b9:5b:9c:8b:9a:5f:b6:83:cc:bb:ec:26:65:b7:75:50:83:
+        a6:5b
 -----BEGIN CERTIFICATE-----
-MIIDOjCCAqOgAwIBAgICCzcwDQYJKoZIhvcNAQEFBQAwezELMAkGA1UEBhMCVVMx
-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNVBAoTJU1hc3NhY2h1c2V0dHMg
-SW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxJDAiBgNVBAsTG01JVCBDZXJ0aWZpY2F0
-aW9uIEF1dGhvcml0eTAeFw0wODA3MjMxNjAwMDBaFw0wOTA3MjMxNjAwMDBaMIHS
-MQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJ
-Q2FtYnJpZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBU
-ZWNobm9sb2d5MS0wKwYDVQQLEyRTdHVkZW50IEluZm9ybWF0aW9uIFByb2Nlc3Np
-bmcgQm9hcmQxGDAWBgNVBAMTD3NjcmlwdHMubWl0LmVkdTEeMBwGCSqGSIb3DQEJ
-ARYPc2NyaXB0c0BtaXQuZWR1MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC1
-PiFNwYlrAYxHgP6zNyd2+FJB5qI9S3Z45fJmPA+xrfuXjy6itlPTtg7iZvm5C7fO
-tNX1HB9vIn1I9W3wFs2OSHnRFEoULy/4xL0dh899i1x3rVgksA6hbdYKx9i8L2dl
-yF3Y2DHCZ0tK9KGlVIKvyzQIKgR/jnxMt9vcaopdgQIDAQABo3UwczAJBgNVHRME
-AjAAMBEGCWCGSAGG+EIBAQQEAwIF4DAnBgNVHSUEIDAeBggrBgEFBQcDAQYIKwYB
-BQUHAwQGCCsGAQUFBwMCMAsGA1UdDwQEAwIF4DAdBgNVHQ4EFgQUVBF8CVVEHJRF
-qaJ2RissJCZqROgwDQYJKoZIhvcNAQEFBQADgYEAPzQFiqehwVGb8G3G5Cqq/M0q
-UI42EnR+2J+n22PP0hlIAQCqUPiDXFtLaLjepgorDfCv+taSpUZzIOQcYtSjt0iN
-9GqI0qjgKjiryN+aVezlg8cf5WPVttU9MG6jbjCE0fI1Cbkx4cjxPRFNma33M5WN
-11yIakkjAh59lP+nf78=
+MIIDKDCCApGgAwIBAgIDC18oMA0GCSqGSIb3DQEBBQUAME4xCzAJBgNVBAYTAlVT
+MRAwDgYDVQQKEwdFcXVpZmF4MS0wKwYDVQQLEyRFcXVpZmF4IFNlY3VyZSBDZXJ0
+aWZpY2F0ZSBBdXRob3JpdHkwHhcNMDkwNjA0MjAyMjM2WhcNMTEwNjA3MDI1MzAw
+WjCBsjELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNV
+BAcTCUNhbWJyaWRnZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUg
+b2YgVGVjaG5vbG9neTEtMCsGA1UECxMkU3R1ZGVudCBJbmZvcm1hdGlvbiBQcm9j
+ZXNzaW5nIEJvYXJkMRgwFgYDVQQDEw9zY3JpcHRzLm1pdC5lZHUwgZ8wDQYJKoZI
+hvcNAQEBBQADgY0AMIGJAoGBALU+IU3BiWsBjEeA/rM3J3b4UkHmoj1Ldnjl8mY8
+D7Gt+5ePLqK2U9O2DuJm+bkLt8601fUcH28ifUj1bfAWzY5IedEUShQvL/jEvR2H
+z32LXHetWCSwDqFt1grH2LwvZ2XIXdjYMcJnS0r0oaVUgq/LNAgqBH+OfEy329xq
+il2BAgMBAAGjga4wgaswDgYDVR0PAQH/BAQDAgTwMB0GA1UdDgQWBBRUEXwJVUQc
+lEWponZGKywkJmpE6DA6BgNVHR8EMzAxMC+gLaArhilodHRwOi8vY3JsLmdlb3Ry
+dXN0LmNvbS9jcmxzL3NlY3VyZWNhLmNybDAfBgNVHSMEGDAWgBRI5mj5K9KylddH
+2CMgEE8zmJCf1DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJKoZI
+hvcNAQEFBQADgYEADkJyuiRhB+tp1j5K6eyj+BbAojEt8JPsNyzcwHymnmBS1Mav
+9MfL8K2/PLg0px41wxWE9nmW8+zXeGKDgbW7XncKGbbRn66pC/aKfHEeqY7nPeem
+OEc6nwxpN6E/DkR3R7l1SkkI80JDWCwk0rlbnIuaX7aDzLvsJmW3dVCDpls=
 -----END CERTIFICATE-----
Index: branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/star.scripts.pem
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/star.scripts.pem	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/pki/tls/certs/star.scripts.pem	(revision 1179)
@@ -2,11 +2,11 @@
     Data:
         Version: 3 (0x2)
-        Serial Number: 2870 (0xb36)
+        Serial Number: 744584 (0xb5c88)
         Signature Algorithm: sha1WithRSAEncryption
-        Issuer: C=US, ST=Massachusetts, O=Massachusetts Institute of Technology, OU=MIT Certification Authority
+        Issuer: C=US, O=Equifax, OU=Equifax Secure Certificate Authority
         Validity
-            Not Before: Jul 23 16:00:00 2008 GMT
-            Not After : Jul 23 16:00:00 2009 GMT
-        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=Student Information Processing Board, CN=*.scripts.mit.edu/Email=scripts@mit.edu
+            Not Before: Jun  4 09:13:16 2009 GMT
+            Not After : Jun  5 13:13:22 2014 GMT
+        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=Student Information Processing Board, CN=*.scripts.mit.edu
         Subject Public Key Info:
             Public Key Algorithm: rsaEncryption
@@ -24,41 +24,42 @@
                 Exponent: 65537 (0x10001)
         X509v3 extensions:
-            X509v3 Basic Constraints: 
-                CA:FALSE
-            Netscape Cert Type: 
-                SSL Client, SSL Server, S/MIME
-            X509v3 Extended Key Usage: 
-                TLS Web Server Authentication, E-mail Protection, TLS Web Client Authentication
-            X509v3 Key Usage: 
-                Digital Signature, Non Repudiation, Key Encipherment
+            X509v3 Key Usage: critical
+                Digital Signature, Non Repudiation, Key Encipherment, Data Encipherment
             X509v3 Subject Key Identifier: 
                 54:11:7C:09:55:44:1C:94:45:A9:A2:76:46:2B:2C:24:26:6A:44:E8
+            X509v3 CRL Distribution Points: 
+                URI:http://crl.geotrust.com/crls/secureca.crl
+
+            X509v3 Authority Key Identifier: 
+                keyid:48:E6:68:F9:2B:D2:B2:95:D7:47:D8:23:20:10:4F:33:98:90:9F:D4
+
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, TLS Web Client Authentication
     Signature Algorithm: sha1WithRSAEncryption
-        2a:6e:b7:99:2a:13:93:a1:35:42:e2:fd:a9:30:3c:63:a2:e0:
-        c0:87:b0:8c:1a:60:9e:12:db:be:e7:6d:01:9a:1b:d2:80:fd:
-        fa:49:12:2b:7e:48:cf:00:0d:d6:f8:aa:d2:2a:0d:cf:86:01:
-        4c:bd:33:bf:ca:ee:b5:4e:aa:fe:4b:c3:6d:e5:2a:ad:d8:2e:
-        8a:87:e3:f0:3e:11:c8:fa:0e:bf:0f:6e:c3:7a:25:17:e5:96:
-        33:7a:e6:fb:5b:03:b0:b3:7d:75:31:e7:ab:59:3a:0e:f9:11:
-        44:0a:23:1a:3e:1c:a8:06:5c:f7:e7:7d:0b:0c:f4:53:02:e9:
-        51:8d
+        2c:25:90:82:a2:82:e8:03:58:b4:38:11:bc:c0:b5:f0:44:ee:
+        b3:d9:5f:90:ab:b3:f6:24:fa:92:6b:9c:3a:7d:5d:89:f4:a2:
+        3c:2f:cb:85:b2:fe:b6:92:0f:1b:94:65:2d:d6:70:f8:9f:77:
+        9c:b3:20:fa:16:91:9d:e1:b7:64:07:27:42:8b:be:e2:f3:d9:
+        78:71:42:12:3d:6f:33:37:4b:01:2e:1d:87:25:48:bf:50:23:
+        7a:b0:02:41:5d:35:08:bf:e7:15:08:5c:11:7d:91:10:06:52:
+        19:d3:05:01:94:86:07:f7:76:41:e1:fb:d9:1c:d0:ee:74:9f:
+        51:66
 -----BEGIN CERTIFICATE-----
-MIIDPDCCAqWgAwIBAgICCzYwDQYJKoZIhvcNAQEFBQAwezELMAkGA1UEBhMCVVMx
-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNVBAoTJU1hc3NhY2h1c2V0dHMg
-SW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxJDAiBgNVBAsTG01JVCBDZXJ0aWZpY2F0
-aW9uIEF1dGhvcml0eTAeFw0wODA3MjMxNjAwMDBaFw0wOTA3MjMxNjAwMDBaMIHU
-MQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJ
-Q2FtYnJpZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBU
-ZWNobm9sb2d5MS0wKwYDVQQLEyRTdHVkZW50IEluZm9ybWF0aW9uIFByb2Nlc3Np
-bmcgQm9hcmQxGjAYBgNVBAMTESouc2NyaXB0cy5taXQuZWR1MR4wHAYJKoZIhvcN
-AQkBFg9zY3JpcHRzQG1pdC5lZHUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGB
-ALU+IU3BiWsBjEeA/rM3J3b4UkHmoj1Ldnjl8mY8D7Gt+5ePLqK2U9O2DuJm+bkL
-t8601fUcH28ifUj1bfAWzY5IedEUShQvL/jEvR2Hz32LXHetWCSwDqFt1grH2Lwv
-Z2XIXdjYMcJnS0r0oaVUgq/LNAgqBH+OfEy329xqil2BAgMBAAGjdTBzMAkGA1Ud
-EwQCMAAwEQYJYIZIAYb4QgEBBAQDAgXgMCcGA1UdJQQgMB4GCCsGAQUFBwMBBggr
-BgEFBQcDBAYIKwYBBQUHAwIwCwYDVR0PBAQDAgXgMB0GA1UdDgQWBBRUEXwJVUQc
-lEWponZGKywkJmpE6DANBgkqhkiG9w0BAQUFAAOBgQAqbreZKhOToTVC4v2pMDxj
-ouDAh7CMGmCeEtu+520BmhvSgP36SRIrfkjPAA3W+KrSKg3PhgFMvTO/yu61Tqr+
-S8Nt5Sqt2C6Kh+PwPhHI+g6/D27DeiUX5ZYzeub7WwOws311MeerWToO+RFECiMa
-PhyoBlz3530LDPRTAulRjQ==
+MIIDKjCCApOgAwIBAgIDC1yIMA0GCSqGSIb3DQEBBQUAME4xCzAJBgNVBAYTAlVT
+MRAwDgYDVQQKEwdFcXVpZmF4MS0wKwYDVQQLEyRFcXVpZmF4IFNlY3VyZSBDZXJ0
+aWZpY2F0ZSBBdXRob3JpdHkwHhcNMDkwNjA0MDkxMzE2WhcNMTQwNjA1MTMxMzIy
+WjCBtDELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNV
+BAcTCUNhbWJyaWRnZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUg
+b2YgVGVjaG5vbG9neTEtMCsGA1UECxMkU3R1ZGVudCBJbmZvcm1hdGlvbiBQcm9j
+ZXNzaW5nIEJvYXJkMRowGAYDVQQDFBEqLnNjcmlwdHMubWl0LmVkdTCBnzANBgkq
+hkiG9w0BAQEFAAOBjQAwgYkCgYEAtT4hTcGJawGMR4D+szcndvhSQeaiPUt2eOXy
+ZjwPsa37l48uorZT07YO4mb5uQu3zrTV9RwfbyJ9SPVt8BbNjkh50RRKFC8v+MS9
+HYfPfYtcd61YJLAOoW3WCsfYvC9nZchd2NgxwmdLSvShpVSCr8s0CCoEf458TLfb
+3GqKXYECAwEAAaOBrjCBqzAOBgNVHQ8BAf8EBAMCBPAwHQYDVR0OBBYEFFQRfAlV
+RByURamidkYrLCQmakToMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwuZ2Vv
+dHJ1c3QuY29tL2NybHMvc2VjdXJlY2EuY3JsMB8GA1UdIwQYMBaAFEjmaPkr0rKV
+10fYIyAQTzOYkJ/UMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjANBgkq
+hkiG9w0BAQUFAAOBgQAsJZCCooLoA1i0OBG8wLXwRO6z2V+Qq7P2JPqSa5w6fV2J
+9KI8L8uFsv62kg8blGUt1nD4n3ecsyD6FpGd4bdkBydCi77i89l4cUISPW8zN0sB
+Lh2HJUi/UCN6sAJBXTUIv+cVCFwRfZEQBlIZ0wUBlIYH93ZB4fvZHNDudJ9RZg==
 -----END CERTIFICATE-----
Index: branches/fc11-dev/server/fedora/config/etc/postfix/main.cf
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/postfix/main.cf	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/postfix/main.cf	(revision 1179)
@@ -10,5 +10,5 @@
 alias_database = hash:/etc/aliases
 myorigin = scripts.mit.edu
-mydestination = scripts.mit.edu, scripts, $myhostname, scripts-test.mit.edu, scripts-test, localhost
+mydestination = scripts.mit.edu, scripts, $myhostname, scripts-test.mit.edu, scripts-test, scripts-vhosts.mit.edu, scripts-vhosts, localhost
 relayhost =
 mynetworks = 127.0.0.0/8
Index: branches/fc11-dev/server/fedora/config/etc/security/limits.conf
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/security/limits.conf	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/security/limits.conf	(revision 1179)
@@ -45,5 +45,4 @@
 # For everyone else,
 *                soft    core            0
-*                -       memlock         64
 *                -       rss             524268
 *                -       data            1048576
Index: branches/fc11-dev/server/fedora/config/etc/ssh/shosts.equiv
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/ssh/shosts.equiv	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/ssh/shosts.equiv	(revision 1179)
@@ -2,5 +2,7 @@
 old-faithful.mit.edu
 bees-knees.mit.edu
+cats-whiskers.mit.edu
 172.21.0.53
 172.21.0.57
 172.21.0.167
+172.21.0.228
Index: branches/fc11-dev/server/fedora/config/etc/ssh/ssh_known_hosts
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/ssh/ssh_known_hosts	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/ssh/ssh_known_hosts	(revision 1179)
@@ -1,2 +1,3 @@
+cats-whiskers.mit.edu,cats-whiskers,c-w.mit.edu,c-w,scripts4.mit.edu,scripts4,18.181.0.228,172.21.0.228 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAuEpkEgaIgjK7F1gV81lLSYTwSqIZX/9IJs37VaJCsJFv3D86uuJSdfI3Y94fPn2OH6AxfdaqGNksVdi27mKQfzvCB4ogjQgxmM391MIDLd+izZDY0YvCb4DqJLMJUpX49cNUMkj+/rJg1O0K2w/lb8DGr7wdoLSPKCUJNJv5WMMDxpFL253lPELsmnds4T+R6LpTt6W9+FalHl84me51sEjV9PbmhcTaNwuoJStAjhrKPfgHHDIKNyCUvaVkoHPXEsdzz00yY7i57djyZlzPV/jM7LKar+Xw2LB0Z3098IQcdbD8zmz2DdakPTlShxavNPC6kZDZ3WVqziC+bszaSQ==
 bees-knees.mit.edu,bees-knees,b-k.mit.edu,b-k,scripts3.mit.edu,scripts3,18.181.0.167,172.21.0.167 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAuEpkEgaIgjK7F1gV81lLSYTwSqIZX/9IJs37VaJCsJFv3D86uuJSdfI3Y94fPn2OH6AxfdaqGNksVdi27mKQfzvCB4ogjQgxmM391MIDLd+izZDY0YvCb4DqJLMJUpX49cNUMkj+/rJg1O0K2w/lb8DGr7wdoLSPKCUJNJv5WMMDxpFL253lPELsmnds4T+R6LpTt6W9+FalHl84me51sEjV9PbmhcTaNwuoJStAjhrKPfgHHDIKNyCUvaVkoHPXEsdzz00yY7i57djyZlzPV/jM7LKar+Xw2LB0Z3098IQcdbD8zmz2DdakPTlShxavNPC6kZDZ3WVqziC+bszaSQ==
 better-mousetrap.mit.edu,better-mousetrap,b-m.mit.edu,b-m,scripts1.mit.edu,scripts1,18.181.0.57,172.21.0.57 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAuEpkEgaIgjK7F1gV81lLSYTwSqIZX/9IJs37VaJCsJFv3D86uuJSdfI3Y94fPn2OH6AxfdaqGNksVdi27mKQfzvCB4ogjQgxmM391MIDLd+izZDY0YvCb4DqJLMJUpX49cNUMkj+/rJg1O0K2w/lb8DGr7wdoLSPKCUJNJv5WMMDxpFL253lPELsmnds4T+R6LpTt6W9+FalHl84me51sEjV9PbmhcTaNwuoJStAjhrKPfgHHDIKNyCUvaVkoHPXEsdzz00yY7i57djyZlzPV/jM7LKar+Xw2LB0Z3098IQcdbD8zmz2DdakPTlShxavNPC6kZDZ3WVqziC+bszaSQ==
Index: branches/fc11-dev/server/fedora/config/etc/ssh/sshd_config
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/ssh/sshd_config	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/ssh/sshd_config	(revision 1179)
@@ -19,3 +19,3 @@
 IgnoreRhosts yes
 IgnoreUserKnownHosts yes
-DenyUsers root@old-faithful.mit.edu root@better-mousetrap.mit.edu root@bees-knees.mit.edu
+DenyUsers root@old-faithful.mit.edu root@better-mousetrap.mit.edu root@bees-knees.mit.edu root@cats-whiskers.mit.edu
Index: branches/fc11-dev/server/fedora/config/etc/sysconfig/network-scripts/route-eth1
===================================================================
--- branches/fc11-dev/server/fedora/config/etc/sysconfig/network-scripts/route-eth1	(revision 1175)
+++ branches/fc11-dev/server/fedora/config/etc/sysconfig/network-scripts/route-eth1	(revision 1179)
@@ -5,2 +5,3 @@
 18.181.0.57 via 172.21.0.57
 18.181.0.167 via 172.21.0.167
+18.181.0.228 via 172.21.0.228
Index: branches/fc11-dev/server/fedora/specs/nss_nonlocal.spec
===================================================================
--- branches/fc11-dev/server/fedora/specs/nss_nonlocal.spec	(revision 1175)
+++ branches/fc11-dev/server/fedora/specs/nss_nonlocal.spec	(revision 1179)
@@ -2,5 +2,5 @@
 Group: System Environment/Libraries
 Name: nss_nonlocal
-Version: 1.8
+Version: 1.9
 Release: 0
 URL: http://debathena.mit.edu/nss_nonlocal/
