Index: branches/fc15-dev/host/debian/scripts-vm-host/debian/changelog
===================================================================
--- branches/fc15-dev/host/debian/scripts-vm-host/debian/changelog	(revision 1985)
+++ branches/fc15-dev/host/debian/scripts-vm-host/debian/changelog	(revision 1989)
@@ -1,2 +1,8 @@
+scripts-vm-host (0.5) stable; urgency=low
+
+  * Add useful dependencies
+
+ -- Quentin Smith <quentin@mit.edu>  Sun, 11 Sep 2011 23:44:32 -0400
+
 scripts-vm-host (0.4) stable; urgency=low
 
Index: branches/fc15-dev/host/debian/scripts-vm-host/debian/control
===================================================================
--- branches/fc15-dev/host/debian/scripts-vm-host/debian/control	(revision 1985)
+++ branches/fc15-dev/host/debian/scripts-vm-host/debian/control	(revision 1989)
@@ -11,4 +11,5 @@
 Depends: ${misc:Depends},
  apticron,
+ build-essential,
  bwm-ng,
  bzip2,
@@ -44,5 +45,7 @@
  munin-node,
  subversion,
+ screen,
  scripts-syslog-ng-config,
+ sysstat,
 Description: Configures a machine to be a scripts VM host
  Configures a machine to be a scripts VM host, installing all
Index: branches/fc15-dev/host/doc/install-xen
===================================================================
--- branches/fc15-dev/host/doc/install-xen	(revision 1985)
+++ branches/fc15-dev/host/doc/install-xen	(revision 1989)
@@ -29,4 +29,9 @@
 EOF
 
+# (on HPs) add HP repos to etc/apt/sources.list.d
+  cat <<EOF > /etc/apt/sources.list.d/hp.list
+deb http://downloads.linux.hp.com/SDR/downloads/ProLiantSupportPack/ maverick/current non-free
+EOF
+
 # install host keytab
   cp $keytab /etc/krb5.keytab
@@ -38,3 +43,7 @@
 
 # Install scripts-vm-host
+  aptitude update
   aptitude install scripts-vm-host
+
+# (on HPs) install HP software
+  aptitude install hpacucli hp-health
Index: branches/fc15-dev/server/doc/install-ldap
===================================================================
--- branches/fc15-dev/server/doc/install-ldap	(revision 1985)
+++ branches/fc15-dev/server/doc/install-ldap	(revision 1989)
@@ -162,5 +162,5 @@
             M1 <---> M2 <---> S
 
-    3. Set up the rest of the replication agreements at your leisure.
+    3. Set up the rest of the replication agreements.
 
                 M1 <---> M2
@@ -169,5 +169,19 @@
                 +--> S <--+
 
+    4. Push a change from every existing server (to the new server), and
+       then a change from the new server to (all) the existing servers.
+       In addition to merely testing that replication works, this will
+       set up the servers' changelogs properly.
+
+       If this step is not completed before any server's LDAP server
+       shuts down, then the replication agreements will fall apart the
+       next time a change is made. You may wish to intentionally reboot
+       any servers that look like they want to crash _before_ beginning
+       this process.
+
   Here's how you do it.
+
+    0. Tell -c scripts not to go off and reboot servers until you're
+       done (or to get any rebooting done with first).
 
     1. Pull open the replication part of the database. It's fairly empty
@@ -286,4 +300,20 @@
     then try again.
 
+    7. Repeat step 6 to complete the graph of replications (i.e., from
+    every other server to the new server, and from the new server to
+    every other server).
+
+    Note the only difference between steps 5 and 6 is the lack of
+    nsDS5ReplicaRefresh: start. That only needs to be done once, to the
+    new server.
+
+    8. If at this point you look at the new server's changelog with
+    cl-dump (preferably /mit/scripts/admin/cl-dump.pl, to not prompt you
+    for a password), you won't see the servers you added in step 7. So,
+    from each of those servers, make a change to some record so it gets
+    propagated to the new server, and then one from the new server so it
+    gets propagated to all the existing servers' changelogs. This is
+    also good for making sure the replication agreements actually work.
+
 Troubleshooting
 ===============
Index: branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/bluechips.emergent-studios.com.conf
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/bluechips.emergent-studios.com.conf	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/bluechips.emergent-studios.com.conf	(revision 1989)
@@ -0,0 +1,34 @@
+# do not trailing-slash DocumentRoot
+
+<VirtualHost *:80>
+	ServerName bluechips.emergent-studios.com
+	
+	DocumentRoot /afs/sipb.mit.edu/contrib/blue-sun/web_scripts/bluechips.emergent-studios.com
+	Alias /~blue-sun /afs/sipb.mit.edu/contrib/blue-sun/web_scripts
+	SuExecUserGroup blue-sun blue-sun
+	Include conf.d/vhosts-common.conf
+</VirtualHost>
+
+<IfModule ssl_module>
+	<VirtualHost *:443>
+		ServerName bluechips.emergent-studios.com
+		
+		DocumentRoot /afs/sipb.mit.edu/contrib/blue-sun/web_scripts/bluechips.emergent-studios.com
+		Alias /~blue-sun /afs/sipb.mit.edu/contrib/blue-sun/web_scripts
+		SuExecUserGroup blue-sun blue-sun
+		Include conf.d/vhosts-common-ssl.conf
+		SSLCertificateFile /etc/pki/tls/certs/bluechips.emergent-studios.com.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+	<VirtualHost *:444>
+		ServerName bluechips.emergent-studios.com
+		
+		DocumentRoot /afs/sipb.mit.edu/contrib/blue-sun/web_scripts/bluechips.emergent-studios.com
+		Alias /~blue-sun /afs/sipb.mit.edu/contrib/blue-sun/web_scripts
+		SuExecUserGroup blue-sun blue-sun
+		Include conf.d/vhosts-common-ssl.conf
+		Include conf.d/vhosts-common-ssl-cert.conf
+		SSLCertificateFile /etc/pki/tls/certs/bluechips.emergent-studios.com.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+</IfModule>
Index: branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/crosslinks.conf
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/crosslinks.conf	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/crosslinks.conf	(revision 1989)
@@ -0,0 +1,34 @@
+# do not trailing-slash DocumentRoot
+
+<VirtualHost *:80>
+	ServerName crosslinks.mit.edu
+	ServerAlias crosslinks
+	DocumentRoot /afs/athena.mit.edu/org/c/crosslinks/web_scripts/Crosslinks
+	Alias /~crosslinks /afs/athena.mit.edu/org/c/crosslinks/web_scripts
+	SuExecUserGroup crosslinks crosslinks
+	Include conf.d/vhosts-common.conf
+</VirtualHost>
+
+<IfModule ssl_module>
+	<VirtualHost *:443>
+		ServerName crosslinks.mit.edu
+		ServerAlias crosslinks
+		DocumentRoot /afs/athena.mit.edu/org/c/crosslinks/web_scripts/Crosslinks
+		Alias /~crosslinks /afs/athena.mit.edu/org/c/crosslinks/web_scripts
+		SuExecUserGroup crosslinks crosslinks
+		Include conf.d/vhosts-common-ssl.conf
+		SSLCertificateFile /etc/pki/tls/certs/crosslinks.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+	<VirtualHost *:444>
+		ServerName crosslinks.mit.edu
+		ServerAlias crosslinks
+		DocumentRoot /afs/athena.mit.edu/org/c/crosslinks/web_scripts/Crosslinks
+		Alias /~crosslinks /afs/athena.mit.edu/org/c/crosslinks/web_scripts
+		SuExecUserGroup crosslinks crosslinks
+		Include conf.d/vhosts-common-ssl.conf
+		Include conf.d/vhosts-common-ssl-cert.conf
+		SSLCertificateFile /etc/pki/tls/certs/crosslinks.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+</IfModule>
Index: branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/rpl.conf
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/rpl.conf	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/httpd/vhosts.d/rpl.conf	(revision 1989)
@@ -0,0 +1,34 @@
+# do not trailing-slash DocumentRoot
+
+<VirtualHost *:80>
+	ServerName rpl.mit.edu
+	ServerAlias rpl
+	DocumentRoot /afs/athena.mit.edu/org/r/rpl/web_scripts
+	Alias /~rpl /afs/athena.mit.edu/org/r/rpl/web_scripts
+	SuExecUserGroup rpl rpl
+	Include conf.d/vhosts-common.conf
+</VirtualHost>
+
+<IfModule ssl_module>
+	<VirtualHost *:443>
+		ServerName rpl.mit.edu
+		ServerAlias rpl
+		DocumentRoot /afs/athena.mit.edu/org/r/rpl/web_scripts
+		Alias /~rpl /afs/athena.mit.edu/org/r/rpl/web_scripts
+		SuExecUserGroup rpl rpl
+		Include conf.d/vhosts-common-ssl.conf
+		SSLCertificateFile /etc/pki/tls/certs/rpl.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+	<VirtualHost *:444>
+		ServerName rpl.mit.edu
+		ServerAlias rpl
+		DocumentRoot /afs/athena.mit.edu/org/r/rpl/web_scripts
+		Alias /~rpl /afs/athena.mit.edu/org/r/rpl/web_scripts
+		SuExecUserGroup rpl rpl
+		Include conf.d/vhosts-common-ssl.conf
+		Include conf.d/vhosts-common-ssl-cert.conf
+		SSLCertificateFile /etc/pki/tls/certs/rpl.pem
+		SSLCertificateKeyFile /etc/pki/tls/private/scripts.key
+	</VirtualHost>
+</IfModule>
Index: branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/bluechips.emergent-studios.com.pem
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/bluechips.emergent-studios.com.pem	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/bluechips.emergent-studios.com.pem	(revision 1989)
@@ -0,0 +1,150 @@
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number: 275891 (0x435b3)
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Class 1 Primary Intermediate Server CA
+        Validity
+            Not Before: Sep 12 00:58:16 2011 GMT
+            Not After : Sep 12 14:56:41 2012 GMT
+        Subject: description=508223-DC90aIhDy1Y0fd12, CN=bluechips.emergent-studios.com/emailAddress=evan@ebroder.net
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+                Public-Key: (4096 bit)
+                Modulus:
+                    00:bf:a3:f2:7b:98:cc:16:a7:57:e6:92:85:34:56:
+                    f1:e3:62:83:9e:6a:4f:35:9d:f0:cf:89:87:73:e3:
+                    93:f7:b7:01:57:38:6e:e9:fc:59:4d:24:eb:a7:17:
+                    47:ca:2c:51:0e:45:c8:b7:68:c9:0e:32:26:e0:91:
+                    d3:06:5c:8c:7c:0e:6c:99:0c:b2:46:05:0f:4d:f1:
+                    b0:c7:5e:35:06:62:fe:2a:d6:0f:1b:2c:b5:02:24:
+                    4c:c3:06:71:ec:94:ca:1d:aa:af:7e:b9:2d:c0:55:
+                    4b:cc:bc:51:3d:76:68:5b:d3:ed:35:d0:03:ba:1b:
+                    6c:f3:a0:d8:d3:dc:6b:44:b0:5e:01:51:d3:02:cc:
+                    4a:da:52:12:de:35:31:69:16:5a:48:8b:0f:ce:ad:
+                    4d:e4:d5:8b:11:36:7f:87:1c:fd:84:da:43:2e:87:
+                    2f:41:70:ac:ad:df:54:c0:ed:f6:21:51:fa:c5:06:
+                    f0:1b:eb:a1:b0:bf:4d:1c:42:34:8a:d5:6f:f7:25:
+                    66:73:8f:60:c4:d7:8d:33:91:f4:46:3a:97:09:59:
+                    01:ff:c3:64:94:40:48:30:68:f0:6e:03:26:74:c2:
+                    a1:b3:d7:cb:94:fc:6e:53:8a:2a:9e:fd:b1:4f:c4:
+                    74:56:25:63:1f:aa:bd:95:25:78:9c:45:46:1b:0c:
+                    21:71:eb:84:94:d0:b2:f1:da:52:f6:d1:7f:63:1d:
+                    08:23:52:5f:c2:f9:4d:ac:a4:44:e5:9a:54:70:fc:
+                    c9:fc:d4:d4:b7:1d:75:95:00:e3:bf:3e:4c:f3:43:
+                    c3:96:c7:09:2a:29:45:12:d2:31:d6:79:4c:8a:e7:
+                    54:27:22:c6:80:ae:87:23:56:f1:8d:49:9b:c8:fa:
+                    ed:33:5b:5f:56:76:c8:0f:7e:85:14:69:c4:48:31:
+                    07:39:a5:34:81:f2:6b:15:50:22:fb:bb:2c:ad:4b:
+                    84:ea:55:64:f7:de:56:9d:d0:b6:d0:7d:1e:1b:51:
+                    50:37:44:94:e6:c4:15:eb:45:31:f1:b3:ec:0f:b3:
+                    a9:0c:f8:1c:47:c7:51:00:05:ef:ee:b0:3d:9f:7e:
+                    07:a7:38:e8:83:4c:3d:db:34:b6:24:0c:90:57:c0:
+                    f9:d0:64:14:8a:93:47:9b:41:f5:a3:14:1d:9e:18:
+                    5d:d5:d8:66:af:f5:f3:c8:2f:bc:a7:02:a7:ef:dc:
+                    f0:0e:c7:47:8d:2e:d6:a8:62:42:93:5b:7c:f5:35:
+                    f8:31:10:7b:38:d4:40:24:68:81:13:27:cb:fb:76:
+                    0e:d1:99:14:d8:d5:eb:f7:69:64:8f:af:8f:82:bb:
+                    24:29:f9:d4:29:1d:ce:e6:14:ba:4c:8b:09:ff:46:
+                    ce:8b:6d
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: 
+                CA:FALSE
+            X509v3 Key Usage: 
+                Digital Signature, Key Encipherment, Key Agreement
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication
+            X509v3 Subject Key Identifier: 
+                CB:11:B7:01:5F:86:55:4F:45:5E:AB:27:69:BE:E1:3C:89:7A:55:62
+            X509v3 Authority Key Identifier: 
+                keyid:EB:42:34:D0:98:B0:AB:9F:F4:1B:6B:08:F7:CC:64:2E:EF:0E:2C:45
+
+            X509v3 Subject Alternative Name: 
+                DNS:bluechips.emergent-studios.com, DNS:emergent-studios.com
+            X509v3 Certificate Policies: 
+                Policy: 1.3.6.1.4.1.23223.1.2.2
+                  CPS: http://www.startssl.com/policy.pdf
+                  CPS: http://www.startssl.com/intermediate.pdf
+                  User Notice:
+                    Organization: StartCom Certification Authority
+                    Number: 1
+                    Explicit Text: This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.
+                  User Notice:
+                    Organization: StartCom Certification Authority
+                    Number: 2
+                    Explicit Text: Liability and warranties are limited! See section "Legal and Limitations" of the StartCom CA policy.
+
+            X509v3 CRL Distribution Points: 
+
+                Full Name:
+                  URI:http://crl.startssl.com/crt1-crl.crl
+
+            Authority Information Access: 
+                OCSP - URI:http://ocsp.startssl.com/sub/class1/server/ca
+                CA Issuers - URI:http://aia.startssl.com/certs/sub.class1.server.ca.crt
+
+            X509v3 Issuer Alternative Name: 
+                URI:http://www.startssl.com/
+    Signature Algorithm: sha1WithRSAEncryption
+        14:17:ec:4c:8b:bd:41:b3:23:4b:d6:9f:b5:e9:61:e5:33:70:
+        c6:3b:f7:be:af:c1:d3:26:fa:c4:a4:14:ca:87:b6:a0:fc:cd:
+        63:7c:33:7d:4d:11:8f:cb:9a:b0:6e:6d:0f:89:9f:aa:f5:af:
+        1f:98:03:9a:e8:69:10:d6:5d:1b:7a:7e:bf:26:74:fb:1a:23:
+        3d:12:4b:d7:b4:c1:64:87:56:b6:c9:53:1a:9e:b9:f2:72:a3:
+        1d:6a:f1:b9:b4:e3:6c:6a:6f:fe:5f:13:6f:cc:f6:0c:79:9f:
+        28:35:87:a2:14:fe:37:45:a5:fb:cb:b6:55:c0:37:d8:64:72:
+        29:5e:4e:0c:cf:f4:1a:a5:96:f1:e9:f6:6b:6b:5f:5f:94:05:
+        7a:30:bd:f2:61:5a:d1:bd:0a:a4:13:d9:60:0e:f1:af:15:db:
+        a7:e9:c4:bf:5d:a9:56:39:1a:d3:d7:cc:c6:5d:25:90:3c:3f:
+        c8:6a:1e:34:d0:1e:97:9d:6d:af:16:5a:64:5f:7a:bf:d2:d4:
+        10:8d:e1:ad:75:75:86:7b:ab:5d:f3:27:39:a3:a9:67:18:1a:
+        6a:a3:98:98:f4:1d:15:d4:db:40:c0:fb:cf:6a:95:ae:c2:a1:
+        64:32:dd:3f:9f:ff:bc:fa:ea:f0:46:4f:23:a0:39:27:1c:91:
+        c8:f2:1c:80
+-----BEGIN CERTIFICATE-----
+MIIIPDCCBySgAwIBAgIDBDWzMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJ
+TDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0
+YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3Mg
+MSBQcmltYXJ5IEludGVybWVkaWF0ZSBTZXJ2ZXIgQ0EwHhcNMTEwOTEyMDA1ODE2
+WhcNMTIwOTEyMTQ1NjQxWjBsMSAwHgYDVQQNExc1MDgyMjMtREM5MGFJaER5MVkw
+ZmQxMjEnMCUGA1UEAxMeYmx1ZWNoaXBzLmVtZXJnZW50LXN0dWRpb3MuY29tMR8w
+HQYJKoZIhvcNAQkBFhBldmFuQGVicm9kZXIubmV0MIICIjANBgkqhkiG9w0BAQEF
+AAOCAg8AMIICCgKCAgEAv6Pye5jMFqdX5pKFNFbx42KDnmpPNZ3wz4mHc+OT97cB
+Vzhu6fxZTSTrpxdHyixRDkXIt2jJDjIm4JHTBlyMfA5smQyyRgUPTfGwx141BmL+
+KtYPGyy1AiRMwwZx7JTKHaqvfrktwFVLzLxRPXZoW9PtNdADuhts86DY09xrRLBe
+AVHTAsxK2lIS3jUxaRZaSIsPzq1N5NWLETZ/hxz9hNpDLocvQXCsrd9UwO32IVH6
+xQbwG+uhsL9NHEI0itVv9yVmc49gxNeNM5H0RjqXCVkB/8NklEBIMGjwbgMmdMKh
+s9fLlPxuU4oqnv2xT8R0ViVjH6q9lSV4nEVGGwwhceuElNCy8dpS9tF/Yx0II1Jf
+wvlNrKRE5ZpUcPzJ/NTUtx11lQDjvz5M80PDlscJKilFEtIx1nlMiudUJyLGgK6H
+I1bxjUmbyPrtM1tfVnbID36FFGnESDEHOaU0gfJrFVAi+7ssrUuE6lVk995WndC2
+0H0eG1FQN0SU5sQV60Ux8bPsD7OpDPgcR8dRAAXv7rA9n34Hpzjog0w92zS2JAyQ
+V8D50GQUipNHm0H1oxQdnhhd1dhmr/XzyC+8pwKn79zwDsdHjS7WqGJCk1t89TX4
+MRB7ONRAJGiBEyfL+3YO0ZkU2NXr92lkj6+PgrskKfnUKR3O5hS6TIsJ/0bOi20C
+AwEAAaOCA8QwggPAMAkGA1UdEwQCMAAwCwYDVR0PBAQDAgOoMBMGA1UdJQQMMAoG
+CCsGAQUFBwMBMB0GA1UdDgQWBBTLEbcBX4ZVT0VeqydpvuE8iXpVYjAfBgNVHSME
+GDAWgBTrQjTQmLCrn/Qbawj3zGQu7w4sRTA/BgNVHREEODA2gh5ibHVlY2hpcHMu
+ZW1lcmdlbnQtc3R1ZGlvcy5jb22CFGVtZXJnZW50LXN0dWRpb3MuY29tMIICIQYD
+VR0gBIICGDCCAhQwggIQBgsrBgEEAYG1NwECAjCCAf8wLgYIKwYBBQUHAgEWImh0
+dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEWKGh0
+dHA6Ly93d3cuc3RhcnRzc2wuY29tL2ludGVybWVkaWF0ZS5wZGYwgfcGCCsGAQUF
+BwICMIHqMCcWIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MAMCAQEa
+gb5UaGlzIGNlcnRpZmljYXRlIHdhcyBpc3N1ZWQgYWNjb3JkaW5nIHRvIHRoZSBD
+bGFzcyAxIFZhbGlkYXRpb24gcmVxdWlyZW1lbnRzIG9mIHRoZSBTdGFydENvbSBD
+QSBwb2xpY3ksIHJlbGlhbmNlIG9ubHkgZm9yIHRoZSBpbnRlbmRlZCBwdXJwb3Nl
+IGluIGNvbXBsaWFuY2Ugb2YgdGhlIHJlbHlpbmcgcGFydHkgb2JsaWdhdGlvbnMu
+MIGcBggrBgEFBQcCAjCBjzAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhv
+cml0eTADAgECGmRMaWFiaWxpdHkgYW5kIHdhcnJhbnRpZXMgYXJlIGxpbWl0ZWQh
+IFNlZSBzZWN0aW9uICJMZWdhbCBhbmQgTGltaXRhdGlvbnMiIG9mIHRoZSBTdGFy
+dENvbSBDQSBwb2xpY3kuMDUGA1UdHwQuMCwwKqAooCaGJGh0dHA6Ly9jcmwuc3Rh
+cnRzc2wuY29tL2NydDEtY3JsLmNybDCBjgYIKwYBBQUHAQEEgYEwfzA5BggrBgEF
+BQcwAYYtaHR0cDovL29jc3Auc3RhcnRzc2wuY29tL3N1Yi9jbGFzczEvc2VydmVy
+L2NhMEIGCCsGAQUFBzAChjZodHRwOi8vYWlhLnN0YXJ0c3NsLmNvbS9jZXJ0cy9z
+dWIuY2xhc3MxLnNlcnZlci5jYS5jcnQwIwYDVR0SBBwwGoYYaHR0cDovL3d3dy5z
+dGFydHNzbC5jb20vMA0GCSqGSIb3DQEBBQUAA4IBAQAUF+xMi71BsyNL1p+16WHl
+M3DGO/e+r8HTJvrEpBTKh7ag/M1jfDN9TRGPy5qwbm0PiZ+q9a8fmAOa6GkQ1l0b
+en6/JnT7GiM9EkvXtMFkh1a2yVManrnycqMdavG5tONsam/+XxNvzPYMeZ8oNYei
+FP43RaX7y7ZVwDfYZHIpXk4Mz/QapZbx6fZra19flAV6ML3yYVrRvQqkE9lgDvGv
+Fdun6cS/XalWORrT18zGXSWQPD/Iah400B6XnW2vFlpkX3q/0tQQjeGtdXWGe6td
+8yc5o6lnGBpqo5iY9B0V1NtAwPvPapWuwqFkMt0/n/+8+urwRk8joDknHJHI8hyA
+-----END CERTIFICATE-----
Index: branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/crosslinks.pem
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/crosslinks.pem	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/crosslinks.pem	(revision 1989)
@@ -0,0 +1,110 @@
+From mitcert@MIT.EDU Fri Sep 23 11:43:45 2011
+Date: Fri, 23 Sep 2011 11:43:44 -0400
+From: "mitcert@MIT.EDU" <mitcert@MIT.EDU>
+To: Alexander Chernyakhovsky <achernya@mit.edu>
+Subject: [help.mit.edu #1746138] certificate signing request for scripts-vhost crosslinks.mit.edu 
+
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            ef:de:cb:5e:53:c5:10:65:d2:46:38:56:c4:9f:cf:5e
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=US, ST=Massachusetts, O=Massachusetts Institute of Technology, OU=MIT Certification Authority
+        Validity
+            Not Before: Sep 21 16:00:00 2011 GMT
+            Not After : Sep 20 16:00:00 2012 GMT
+        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=scripts.mit.edu web hosting service, CN=crosslinks.mit.edu/emailAddress=scripts@mit.edu
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+            RSA Public Key: (4096 bit)
+                Modulus (4096 bit):
+                    00:bf:a3:f2:7b:98:cc:16:a7:57:e6:92:85:34:56:
+                    f1:e3:62:83:9e:6a:4f:35:9d:f0:cf:89:87:73:e3:
+                    93:f7:b7:01:57:38:6e:e9:fc:59:4d:24:eb:a7:17:
+                    47:ca:2c:51:0e:45:c8:b7:68:c9:0e:32:26:e0:91:
+                    d3:06:5c:8c:7c:0e:6c:99:0c:b2:46:05:0f:4d:f1:
+                    b0:c7:5e:35:06:62:fe:2a:d6:0f:1b:2c:b5:02:24:
+                    4c:c3:06:71:ec:94:ca:1d:aa:af:7e:b9:2d:c0:55:
+                    4b:cc:bc:51:3d:76:68:5b:d3:ed:35:d0:03:ba:1b:
+                    6c:f3:a0:d8:d3:dc:6b:44:b0:5e:01:51:d3:02:cc:
+                    4a:da:52:12:de:35:31:69:16:5a:48:8b:0f:ce:ad:
+                    4d:e4:d5:8b:11:36:7f:87:1c:fd:84:da:43:2e:87:
+                    2f:41:70:ac:ad:df:54:c0:ed:f6:21:51:fa:c5:06:
+                    f0:1b:eb:a1:b0:bf:4d:1c:42:34:8a:d5:6f:f7:25:
+                    66:73:8f:60:c4:d7:8d:33:91:f4:46:3a:97:09:59:
+                    01:ff:c3:64:94:40:48:30:68:f0:6e:03:26:74:c2:
+                    a1:b3:d7:cb:94:fc:6e:53:8a:2a:9e:fd:b1:4f:c4:
+                    74:56:25:63:1f:aa:bd:95:25:78:9c:45:46:1b:0c:
+                    21:71:eb:84:94:d0:b2:f1:da:52:f6:d1:7f:63:1d:
+                    08:23:52:5f:c2:f9:4d:ac:a4:44:e5:9a:54:70:fc:
+                    c9:fc:d4:d4:b7:1d:75:95:00:e3:bf:3e:4c:f3:43:
+                    c3:96:c7:09:2a:29:45:12:d2:31:d6:79:4c:8a:e7:
+                    54:27:22:c6:80:ae:87:23:56:f1:8d:49:9b:c8:fa:
+                    ed:33:5b:5f:56:76:c8:0f:7e:85:14:69:c4:48:31:
+                    07:39:a5:34:81:f2:6b:15:50:22:fb:bb:2c:ad:4b:
+                    84:ea:55:64:f7:de:56:9d:d0:b6:d0:7d:1e:1b:51:
+                    50:37:44:94:e6:c4:15:eb:45:31:f1:b3:ec:0f:b3:
+                    a9:0c:f8:1c:47:c7:51:00:05:ef:ee:b0:3d:9f:7e:
+                    07:a7:38:e8:83:4c:3d:db:34:b6:24:0c:90:57:c0:
+                    f9:d0:64:14:8a:93:47:9b:41:f5:a3:14:1d:9e:18:
+                    5d:d5:d8:66:af:f5:f3:c8:2f:bc:a7:02:a7:ef:dc:
+                    f0:0e:c7:47:8d:2e:d6:a8:62:42:93:5b:7c:f5:35:
+                    f8:31:10:7b:38:d4:40:24:68:81:13:27:cb:fb:76:
+                    0e:d1:99:14:d8:d5:eb:f7:69:64:8f:af:8f:82:bb:
+                    24:29:f9:d4:29:1d:ce:e6:14:ba:4c:8b:09:ff:46:
+                    ce:8b:6d
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: 
+                CA:FALSE
+            Netscape Cert Type: 
+                SSL Client, SSL Server, S/MIME
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, E-mail Protection, TLS Web Client Authentication
+            X509v3 Key Usage: 
+                Digital Signature, Non Repudiation, Key Encipherment
+            X509v3 Subject Key Identifier: 
+                CB:11:B7:01:5F:86:55:4F:45:5E:AB:27:69:BE:E1:3C:89:7A:55:62
+            X509v3 CRL Distribution Points: 
+                URI:http://ca.mit.edu/ca/mitserver.crl
+
+    Signature Algorithm: sha1WithRSAEncryption
+        81:d6:5e:78:c5:f5:49:f4:b4:eb:05:07:6f:c9:db:c2:0d:a3:
+        5f:c1:50:d8:1d:22:2b:c2:e6:cd:0a:e2:b4:fa:90:22:b5:6f:
+        2b:20:e0:04:50:2b:27:ff:d1:91:62:5f:6a:ba:00:f3:52:53:
+        ac:00:4c:e4:0f:f9:ae:e6:30:75:10:32:c5:63:a5:0a:62:13:
+        2b:49:6d:c4:8c:06:98:73:b8:b5:a4:91:90:db:1c:ea:55:02:
+        c7:07:38:e9:d3:38:42:ca:80:6f:7d:71:68:bf:13:5d:67:3f:
+        4a:e8:8d:56:94:8c:1e:c7:7f:7b:32:ce:e5:cd:78:67:4d:3d:
+        de:13
+-----BEGIN CERTIFICATE-----
+MIIFBjCCBG+gAwIBAgIRAO/ey15TxRBl0kY4VsSfz14wDQYJKoZIhvcNAQEFBQAw
+ezELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNVBAoT
+JU1hc3NhY2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxJDAiBgNVBAsT
+G01JVCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0xMTA5MjExNjAwMDBaFw0x
+MjA5MjAxNjAwMDBaMIHUMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVz
+ZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRz
+IEluc3RpdHV0ZSBvZiBUZWNobm9sb2d5MSwwKgYDVQQLEyNzY3JpcHRzLm1pdC5l
+ZHUgd2ViIGhvc3Rpbmcgc2VydmljZTEbMBkGA1UEAxMSY3Jvc3NsaW5rcy5taXQu
+ZWR1MR4wHAYJKoZIhvcNAQkBFg9zY3JpcHRzQG1pdC5lZHUwggIiMA0GCSqGSIb3
+DQEBAQUAA4ICDwAwggIKAoICAQC/o/J7mMwWp1fmkoU0VvHjYoOeak81nfDPiYdz
+45P3twFXOG7p/FlNJOunF0fKLFEORci3aMkOMibgkdMGXIx8DmyZDLJGBQ9N8bDH
+XjUGYv4q1g8bLLUCJEzDBnHslModqq9+uS3AVUvMvFE9dmhb0+010AO6G2zzoNjT
+3GtEsF4BUdMCzEraUhLeNTFpFlpIiw/OrU3k1YsRNn+HHP2E2kMuhy9BcKyt31TA
+7fYhUfrFBvAb66Gwv00cQjSK1W/3JWZzj2DE140zkfRGOpcJWQH/w2SUQEgwaPBu
+AyZ0wqGz18uU/G5Tiiqe/bFPxHRWJWMfqr2VJXicRUYbDCFx64SU0LLx2lL20X9j
+HQgjUl/C+U2spETlmlRw/Mn81NS3HXWVAOO/PkzzQ8OWxwkqKUUS0jHWeUyK51Qn
+IsaArocjVvGNSZvI+u0zW19WdsgPfoUUacRIMQc5pTSB8msVUCL7uyytS4TqVWT3
+3lad0LbQfR4bUVA3RJTmxBXrRTHxs+wPs6kM+BxHx1EABe/usD2ffgenOOiDTD3b
+NLYkDJBXwPnQZBSKk0ebQfWjFB2eGF3V2Gav9fPIL7ynAqfv3PAOx0eNLtaoYkKT
+W3z1NfgxEHs41EAkaIETJ8v7dg7RmRTY1ev3aWSPr4+CuyQp+dQpHc7mFLpMiwn/
+Rs6LbQIDAQABo4GrMIGoMAkGA1UdEwQCMAAwEQYJYIZIAYb4QgEBBAQDAgXgMCcG
+A1UdJQQgMB4GCCsGAQUFBwMBBggrBgEFBQcDBAYIKwYBBQUHAwIwCwYDVR0PBAQD
+AgXgMB0GA1UdDgQWBBTLEbcBX4ZVT0VeqydpvuE8iXpVYjAzBgNVHR8ELDAqMCig
+JqAkhiJodHRwOi8vY2EubWl0LmVkdS9jYS9taXRzZXJ2ZXIuY3JsMA0GCSqGSIb3
+DQEBBQUAA4GBAIHWXnjF9Un0tOsFB2/J28INo1/BUNgdIivC5s0K4rT6kCK1bysg
+4ARQKyf/0ZFiX2q6APNSU6wATOQP+a7mMHUQMsVjpQpiEytJbcSMBphzuLWkkZDb
+HOpVAscHOOnTOELKgG99cWi/E11nP0rojVaUjB7Hf3syzuXNeGdNPd4T
+-----END CERTIFICATE-----
+
Index: branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/rpl.pem
===================================================================
--- branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/rpl.pem	(revision 1989)
+++ branches/fc15-dev/server/fedora/config/etc/pki/tls/certs/rpl.pem	(revision 1989)
@@ -0,0 +1,110 @@
+From mitcert@MIT.EDU Sun Sep 18 20:14:32 2011
+Date: Sun, 18 Sep 2011 20:14:31 -0400
+From: "mitcert@MIT.EDU" <mitcert@MIT.EDU>
+To: Alexander Chernyakhovsky <achernya@mit.edu>
+Subject: [help.mit.edu #1739925] certificate signing request for scripts-vhost rpl.mit.edu 
+
+Certificate:
+    Data:
+        Version: 3 (0x2)
+        Serial Number:
+            31:20:29:07:c1:47:e4:4d:d4:f4:d6:16:59:c9:ea:cb
+        Signature Algorithm: sha1WithRSAEncryption
+        Issuer: C=US, ST=Massachusetts, O=Massachusetts Institute of Technology, OU=MIT Certification Authority
+        Validity
+            Not Before: Sep 17 16:00:00 2011 GMT
+            Not After : Sep 17 16:00:00 2012 GMT
+        Subject: C=US, ST=Massachusetts, L=Cambridge, O=Massachusetts Institute of Technology, OU=scripts.mit.edu web hosting service, CN=rpl.mit.edu/emailAddress=scripts@mit.edu
+        Subject Public Key Info:
+            Public Key Algorithm: rsaEncryption
+            RSA Public Key: (4096 bit)
+                Modulus (4096 bit):
+                    00:bf:a3:f2:7b:98:cc:16:a7:57:e6:92:85:34:56:
+                    f1:e3:62:83:9e:6a:4f:35:9d:f0:cf:89:87:73:e3:
+                    93:f7:b7:01:57:38:6e:e9:fc:59:4d:24:eb:a7:17:
+                    47:ca:2c:51:0e:45:c8:b7:68:c9:0e:32:26:e0:91:
+                    d3:06:5c:8c:7c:0e:6c:99:0c:b2:46:05:0f:4d:f1:
+                    b0:c7:5e:35:06:62:fe:2a:d6:0f:1b:2c:b5:02:24:
+                    4c:c3:06:71:ec:94:ca:1d:aa:af:7e:b9:2d:c0:55:
+                    4b:cc:bc:51:3d:76:68:5b:d3:ed:35:d0:03:ba:1b:
+                    6c:f3:a0:d8:d3:dc:6b:44:b0:5e:01:51:d3:02:cc:
+                    4a:da:52:12:de:35:31:69:16:5a:48:8b:0f:ce:ad:
+                    4d:e4:d5:8b:11:36:7f:87:1c:fd:84:da:43:2e:87:
+                    2f:41:70:ac:ad:df:54:c0:ed:f6:21:51:fa:c5:06:
+                    f0:1b:eb:a1:b0:bf:4d:1c:42:34:8a:d5:6f:f7:25:
+                    66:73:8f:60:c4:d7:8d:33:91:f4:46:3a:97:09:59:
+                    01:ff:c3:64:94:40:48:30:68:f0:6e:03:26:74:c2:
+                    a1:b3:d7:cb:94:fc:6e:53:8a:2a:9e:fd:b1:4f:c4:
+                    74:56:25:63:1f:aa:bd:95:25:78:9c:45:46:1b:0c:
+                    21:71:eb:84:94:d0:b2:f1:da:52:f6:d1:7f:63:1d:
+                    08:23:52:5f:c2:f9:4d:ac:a4:44:e5:9a:54:70:fc:
+                    c9:fc:d4:d4:b7:1d:75:95:00:e3:bf:3e:4c:f3:43:
+                    c3:96:c7:09:2a:29:45:12:d2:31:d6:79:4c:8a:e7:
+                    54:27:22:c6:80:ae:87:23:56:f1:8d:49:9b:c8:fa:
+                    ed:33:5b:5f:56:76:c8:0f:7e:85:14:69:c4:48:31:
+                    07:39:a5:34:81:f2:6b:15:50:22:fb:bb:2c:ad:4b:
+                    84:ea:55:64:f7:de:56:9d:d0:b6:d0:7d:1e:1b:51:
+                    50:37:44:94:e6:c4:15:eb:45:31:f1:b3:ec:0f:b3:
+                    a9:0c:f8:1c:47:c7:51:00:05:ef:ee:b0:3d:9f:7e:
+                    07:a7:38:e8:83:4c:3d:db:34:b6:24:0c:90:57:c0:
+                    f9:d0:64:14:8a:93:47:9b:41:f5:a3:14:1d:9e:18:
+                    5d:d5:d8:66:af:f5:f3:c8:2f:bc:a7:02:a7:ef:dc:
+                    f0:0e:c7:47:8d:2e:d6:a8:62:42:93:5b:7c:f5:35:
+                    f8:31:10:7b:38:d4:40:24:68:81:13:27:cb:fb:76:
+                    0e:d1:99:14:d8:d5:eb:f7:69:64:8f:af:8f:82:bb:
+                    24:29:f9:d4:29:1d:ce:e6:14:ba:4c:8b:09:ff:46:
+                    ce:8b:6d
+                Exponent: 65537 (0x10001)
+        X509v3 extensions:
+            X509v3 Basic Constraints: 
+                CA:FALSE
+            Netscape Cert Type: 
+                SSL Client, SSL Server, S/MIME
+            X509v3 Extended Key Usage: 
+                TLS Web Server Authentication, E-mail Protection, TLS Web Client Authentication
+            X509v3 Key Usage: 
+                Digital Signature, Non Repudiation, Key Encipherment
+            X509v3 Subject Key Identifier: 
+                CB:11:B7:01:5F:86:55:4F:45:5E:AB:27:69:BE:E1:3C:89:7A:55:62
+            X509v3 CRL Distribution Points: 
+                URI:http://ca.mit.edu/ca/mitserver.crl
+
+    Signature Algorithm: sha1WithRSAEncryption
+        79:33:7a:46:f0:be:8e:45:4d:da:4e:af:f0:15:8c:9e:e3:63:
+        07:ea:34:22:ee:ec:e2:a3:af:b7:57:27:cf:b3:26:63:1f:7d:
+        42:81:2e:b9:30:34:24:ac:23:df:d6:1a:12:59:21:55:2f:2d:
+        9e:99:83:b1:15:5d:a2:76:cd:51:25:81:da:46:c0:d7:e0:97:
+        b6:74:28:ef:b7:20:ee:72:76:48:ed:fe:65:50:25:2d:6d:fa:
+        df:67:f1:dc:cb:b4:83:12:96:56:29:1b:15:82:b1:d6:8a:be:
+        d7:6e:2d:29:11:38:07:e6:72:e6:e8:c5:53:0f:6e:98:34:f1:
+        be:ab
+-----BEGIN CERTIFICATE-----
+MIIE/jCCBGegAwIBAgIQMSApB8FH5E3U9NYWWcnqyzANBgkqhkiG9w0BAQUFADB7
+MQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czEuMCwGA1UEChMl
+TWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUgb2YgVGVjaG5vbG9neTEkMCIGA1UECxMb
+TUlUIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTExMDkxNzE2MDAwMFoXDTEy
+MDkxNzE2MDAwMFowgc0xCzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNl
+dHRzMRIwEAYDVQQHEwlDYW1icmlkZ2UxLjAsBgNVBAoTJU1hc3NhY2h1c2V0dHMg
+SW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxLDAqBgNVBAsTI3NjcmlwdHMubWl0LmVk
+dSB3ZWIgaG9zdGluZyBzZXJ2aWNlMRQwEgYDVQQDEwtycGwubWl0LmVkdTEeMBwG
+CSqGSIb3DQEJARYPc2NyaXB0c0BtaXQuZWR1MIICIjANBgkqhkiG9w0BAQEFAAOC
+Ag8AMIICCgKCAgEAv6Pye5jMFqdX5pKFNFbx42KDnmpPNZ3wz4mHc+OT97cBVzhu
+6fxZTSTrpxdHyixRDkXIt2jJDjIm4JHTBlyMfA5smQyyRgUPTfGwx141BmL+KtYP
+Gyy1AiRMwwZx7JTKHaqvfrktwFVLzLxRPXZoW9PtNdADuhts86DY09xrRLBeAVHT
+AsxK2lIS3jUxaRZaSIsPzq1N5NWLETZ/hxz9hNpDLocvQXCsrd9UwO32IVH6xQbw
+G+uhsL9NHEI0itVv9yVmc49gxNeNM5H0RjqXCVkB/8NklEBIMGjwbgMmdMKhs9fL
+lPxuU4oqnv2xT8R0ViVjH6q9lSV4nEVGGwwhceuElNCy8dpS9tF/Yx0II1JfwvlN
+rKRE5ZpUcPzJ/NTUtx11lQDjvz5M80PDlscJKilFEtIx1nlMiudUJyLGgK6HI1bx
+jUmbyPrtM1tfVnbID36FFGnESDEHOaU0gfJrFVAi+7ssrUuE6lVk995WndC20H0e
+G1FQN0SU5sQV60Ux8bPsD7OpDPgcR8dRAAXv7rA9n34Hpzjog0w92zS2JAyQV8D5
+0GQUipNHm0H1oxQdnhhd1dhmr/XzyC+8pwKn79zwDsdHjS7WqGJCk1t89TX4MRB7
+ONRAJGiBEyfL+3YO0ZkU2NXr92lkj6+PgrskKfnUKR3O5hS6TIsJ/0bOi20CAwEA
+AaOBqzCBqDAJBgNVHRMEAjAAMBEGCWCGSAGG+EIBAQQEAwIF4DAnBgNVHSUEIDAe
+BggrBgEFBQcDAQYIKwYBBQUHAwQGCCsGAQUFBwMCMAsGA1UdDwQEAwIF4DAdBgNV
+HQ4EFgQUyxG3AV+GVU9FXqsnab7hPIl6VWIwMwYDVR0fBCwwKjAooCagJIYiaHR0
+cDovL2NhLm1pdC5lZHUvY2EvbWl0c2VydmVyLmNybDANBgkqhkiG9w0BAQUFAAOB
+gQB5M3pG8L6ORU3aTq/wFYye42MH6jQi7uzio6+3VyfPsyZjH31CgS65MDQkrCPf
+1hoSWSFVLy2emYOxFV2ids1RJYHaRsDX4Je2dCjvtyDucnZI7f5lUCUtbfrfZ/Hc
+y7SDEpZWKRsVgrHWir7Xbi0pETgH5nLm6MVTD26YNPG+qw==
+-----END CERTIFICATE-----
+
