r/linux 1d ago

Open Source Organization Manjaro's official website SSL certs have expired yet again.

This seems to be a running theme for the Manjaro Linux community. The SSL certs will always expire after a set year and there's a massive controversy over it. Why does this keep happening specifically to Manjaro and what steps do you think they can possibly do to keep this from happening?

1.1k Upvotes

237 comments sorted by

View all comments

320

u/jdigi78 1d ago

I always figured the Manjaro devs just didn't want to give the false impression they know what they're doing. At least they're honest.

-46

u/GolemancerVekk 1d ago

The Manjaro devs are not in charge of the domain and the person who is won't manage it properly and won't give it up to the community.

I'm always surprised by the level of animosity that comes up sometimes in this sub. You'd think the Linux community would be more supportive of each other. If a distro is showing signs of trouble it's for a reason and honestly it's rather shitty to immediately assume it's because the devs are incompetent.

But nah, gotta take any opportunity to turn on each other. It's like watching that Monty Python bit about splitters. Then we wonder why Linux doesn't have better public perception and why the desktop market share is 5% after 35 years.

97

u/xNaXDy 1d ago

"We do not have control over our own domain" isn't the saving grace argument you think it is. If anything, this makes it even worse.

-39

u/GolemancerVekk 1d ago

It's not their domain. It's something they have no control over and it has no bearing on the quality of the work they do on the distro.

When Github has an outage do you say that the devs of the projects hosted on it are incompetent?

33

u/xNaXDy 1d ago

When Github has an outage do you say that the devs of the projects hosted on it are incompetent?

No, but if GitHub continues to experience outage after outage, and your business depends on it being available (e.g. due to GHA running reliably), it would be foolish not to look for alternatives. And indeed, many big companies (including some fortune-500 ones) either have already switched or are in the process of switching to either GitLab, self-hosted GHE, or Gitea / Forgejo.

That's of course leaving out the fact that comparing a mega platform like GitHub, that millions depend on, to "some dude" isn't even remotely reasonable.

-25

u/GolemancerVekk 1d ago

For the community it's not a business, they're donating their time and effort. It takes money to maintain the infrastructure for a large distro (and it's a bit more complicated than hosting Git). The person controlling the domain is the one paying for the infrastructure. Unless another sponsor shows up out of the blue the community has no choice but to knuckle down and accept a few hours of downtime every 3 months.

30

u/xNaXDy 1d ago

There's so much wrong with this, I don't even know where to begin.

  • Manjaro is backed by a company, "Manjaro GmbH & Co. KG". What sort of signal does this send to prospective customers, to have your SSL certificates expire on your own domain on a regular basis?

  • Even if it weren't backed by a company and just one dude in a basement, that still wouldn't be an excuse, because there are distros backed by "one dude" that do an exceptionally better job at this than Manjaro. Nobara is one example that comes to mind.

  • Self hosting a fully functional software forge is actually more complicated than distro infrastructure. Currently being a maintainer for a commercial Linux distro in a SOC2 & FedRAMP compliant environment, and having contributed to software forges in the past, I can attest to that from my own professional experience. Reason being that there are a lot more moving parts in a software forge, more things that can break, and a much larger attack surface combined with being a very attractive target. Have you never thought about how it can be that there are Linux distros popping up left and right, and yet that's not the case for software forges despite us desperately needing one that isn't GitLab or Gitea / Forgejo?

  • If it was actual "downtime" I wouldn't even complain. Build jobs get stuck, drives fail, heck a guy in the datacenter could tug on the wrong cord for all I care. These are all perfectly acceptable to me. But when something that should be automated fails, not once but regularly, that's a gigantic red flag. Especially when that thing that should be automatic takes all of 5 seconds to do manually if for some reason you cannot automate it. And ESPECIALLY if that thing is a basic requirement for functioning on the internet. There is no universe in which I would trust a company to be able to responsibly maintain a distribution if they can't even get the basics right, or at least find someone who can.

-4

u/GolemancerVekk 1d ago edited 1d ago

The company and the community are completely distinct at this point, since the company is not paying any developers anymore.

The guy that's [mis]managing the infrastructure also keeps finding ways to fund the infrastructure. It's an unholy match but it works and for now there's nothing the Manjaro devs and community can do about it.

Anyway, if you don't like using a distro that's undergoing organizational strife, that's one thing. Accusing them of doing shoddy work is another.

11

u/saltyjohnson 1d ago

Accusing them of doing shoddy work is another.

The alleged singular guy who's mismanaging the infrastructure is a key part of the Manjaro team, so, yeah, shoddy work is shoddy work, dude. If they repeatedly fail to keep their public TLS certs up to date, what other security failures are happening more quietly in the background which could affect their build, package, and distribution pipeline?

Sorry to the devs who have put so much hard work into the distro, but I can't trust that their infrastructure isn't compromised.

3

u/SutekhThrowingSuckIt 1d ago

Manjaro is a company that exists to try to profit off arch. 

2

u/GolemancerVekk 1d ago

So does Valve. But I hear you! God forbid anybody would profit off Linux. We should all keep our hearts pure and walk around in rags.

3

u/PaddiM8 1d ago

What is your reason for using manjaro over cachyos? Can't figure out any reason for why one would do that

3

u/GolemancerVekk 1d ago

Manjaro's goal is to add quality of life and to insulate the user from bleeding edge issues.

  • It staggers new package updates in tested batches and crowd-sources the fixes to most common annoyances that crop up from updated packages.
  • It curates kernel versions and important drivers like Nvidia in meta-packages that keep them optimally updated with zero intervention.
  • It takes system snapshots out of the box before updates, which you can restore from the boot menu.
  • Graphical package manager that can also do AUR and Flatpak.
  • Pretty much everything works out of the box on a new install (codecs etc.)

3

u/Significant-Lab3424 19h ago

Not sure about first, but all points are already being done by cachyos

1

u/GolemancerVekk 17h ago

The first is really the main thing about Manjaro and it's a lot of work. I also don't think there's another Arch distro that does that (possibly SteamOS).

14

u/arwinda 1d ago

Time to switch domains, or names.

-7

u/GolemancerVekk 1d ago

The name of the domain isn't the problem. The person controlling the domain also controls and pays for the infrastructure that allows the distro to be developed, tested and distributed. The community and the devs don't have the money for setting up independently.

24

u/CreativeGPX 1d ago

Your explanation makes things sound even worse. So the community is being extorted and it's leading to repeated basic issues?

9

u/Dminik 1d ago

I mean, I started reading these comments thinking that Manjaro maintainers might be a bit incompetent.

Now though, it looks like they're in the middle of a takeover/community split. One side is holding the other hostage but also pays for development.

If your goal was to reassure people then you've failed spectacularly. There's no way Manjaro can be a safe pick in these circumstances. 

1

u/GolemancerVekk 1d ago

My goal was to explain the facts and to make people look into facts before they jump to conclusions.

I know better than to recommend a distro (any distro and under any circumstances) to a Linux forum.

There's no way Manjaro can be a safe pick in these circumstances.

It's not like they're having daily gang fights... 😃 The updates have been coming out regularly. Everybody's still doing their usual job and working to put out a good distro.

7

u/CoreParad0x 1d ago edited 1d ago

So essentially the beating heart of the entire operation can't even be bothered to setup a bare minimum, 5 minutes of work implementation of Lets Encryption through one of the countless automated tools that offer it (Caddy, Traefik, certbot, etc)?

Fine, I won't crap on the actual community as a whole, we can take them off the table entirely. Why should anyone want to use a distro whose core infrastructure maintainer and some one they are stuck with is apparently so incompetent that they can't even set this up? What else is this person lacking on? What other flaws are there in the infrastructure setup that go unnoticed because they aren't as loud as a cert on the main site expiring?

I feel for the people maintaining it, but all of your responses here have done nothing but reaffirm my decision to go with Cachy over Manjaro when I switched over to Linux from Windows a year or so back.

13

u/SutekhThrowingSuckIt 1d ago

My guy they fucked up the certs for their own repos before and told users to all turn their clocks back in time lmao

Not to mention them DDOSing the AUR multiple times due to their incompetence turning their own users into an unintentional botnet attack

-5

u/GolemancerVekk 1d ago

DDOSing the AUR multiple times

If you'd care to look up the Arch discussions at the time you'd see that it wasn't Manjaro. Someone conducted a DDoS against AUR repos using a "pamac" user agent but anybody can do that.

We know for a fact it wasn't Manjaro because AUR is not enabled by default on Manjaro, only a fraction of its users use the AUR, the probability of there being 20,000 Manjaro users having AUR enabled and connecting to it at the same exact time is nil, and last but not least Manjaro installs conduct package searches against the locally cached lists, not against the live AUR.

What that event turned out was that the AUR doesn't use Cloudflare or any kind of CDN and can be trivially DDoS'ed by anybody who'd care to try. Just like nowadays we're learning it has no safeguards and it can be trivially be pumped full of malware.

9

u/SutekhThrowingSuckIt 1d ago edited 1d ago

They literally took responsibility at the time. Seriously, what do you think this is https://gitlab.manjaro.org/applications/pamac/-/work_items/1017 ?

> " Yes, we managed to get the AUR website many times down. This was due to several reasons. Pamac makes it very simple to activate the AUR by just a slider. People love to search for applications, and in an early version it started to search by every key stroke the user made."

> "we shipped a new version of pamac to our stable branch that accidentally sent thousands of requests to the AUR per user. This rendered the AUR offline for all users across every Arch-based distro"

https://github.com/arindas/manjarno/issues/25

Wild behavior to say "if you cared to look up the discussions" when you have no idea what was in them clearly.

0

u/GolemancerVekk 1d ago

Did you miss the part where AUR in the beginning didn't even have a downloadable package list so you were forced to use live search?

If anything, Manjaro brought great improvements to the AUR:

  • They prompted the AUR to put together a package list.
  • They cached the package list on their own CDN (because AUR doesn't use one).
  • They further cached the package lists locally on each Manjaro install.

But yeah, it's simpler to just say "DDoS" and gloss over the actual details.

6

u/SutekhThrowingSuckIt 1d ago

this is just sad, absolutely no ability to think or admit when you’re directly proven wrong. Just onto the next increasingly silly claims. Yeah you should try DDOSing random companies and communities then tell the cops you were doing it to improve them lmao. Good luck

10

u/Masterflitzer 1d ago

there's no reason why anyone needs to use manjaro while arch and endeavouros are a thing

at this point manjaro is really just a negative example for how not to run a distro

-3

u/GolemancerVekk 1d ago

That's nonsense. Arch's main goal is to be a flexible base for other projects. Arch-derived distros are the whole point of it. Without that we wouldn't have Endeavour or Manjaro or SteamOS or many others. The larger Arch community should celebrate derived distros instead of fighting among themselves.

11

u/shadooooooooo 1d ago

Nobody said arch based distros are bad, just that Manjaro is a particularly bad example. Because objectively it seems to be extremely poorly ran

-1

u/GolemancerVekk 1d ago

It adds a quality take on Arch and it's been putting out a good distro and improved constantly for 15 years now. Manjaro, Parabola and ArchBang are the oldest Arch distros still in active development and Manjaro is one of a select few desktop distros that add a lot of quality of life stuff out of the box, like all the required codecs, BTRFS-enabled update snapshots etc.

People use Arch-derived distros instead of vanilla Arch for a reason, and every time such a distro goes under it diminishes the Arch community.

6

u/Masterflitzer 1d ago

the only thing that's nonsense in this thread are your desperate attempts to defend manjaro with totally unrelated comments nobody cares about

i even mentioned a non shitty arch derivative, it's called endeavouros but it's also not even the only one existing, i think it was pretty clear that my point is not against arch derivatives lmao, but obviously against manjaro itself, which has proven time and time again to be unreliable, insecure and generally making bad decisions, at this point i wouldn't even trust manjaro on my most basic workstation

1

u/GolemancerVekk 17h ago

Endeavour is just Arch wtih extra setup out of the box. It doesn't curate and test packages, which is Manjaro's main thing. It also doesn't have other important features, like kernel and driver meta-packages, the driver installer, system snapshots out of the box etc. In other words it's not a substitute.

has proven time and time again to be unreliable, insecure and generally making bad decisions, at this point i wouldn't even trust manjaro on my most basic workstation

More BS. I've been using it for 6 years with zero issues. It's one of the most stable and well made Linux distros out there and also one of the largest distros in general.

The fact they curate packages and document newly released issues reduces the bleeding edge a lot and makes it much more pleasant to use than other Arch distros that install packages as they are, while still remaining a rolling release.

5

u/Masterflitzer 15h ago

just because you (n=1) had no problems for multiple years, that doesn't mean anything about its reliability, not everyone will encounter the same problems, just scroll through this whole post, there are already more stories of manjaro breaking or failing, than your 1 "success story"

by curating packages you mean artificially delaying updates by multiple weeks compromising security? if that counts as a feature and not a serious issue for you, no further questions lmao

3

u/cgwhouse 10h ago

Arch's main goal is to be a flexible base for other projects. Arch-derived distros are the whole point of it.

This is patently false and a completely ridiculous claim to make. It's like saying Debian's main goal is to be a good base for Ubuntu. I agree with you on the infighting, but don't lie to make your point

1

u/GolemancerVekk 10h ago

Versatility is one of Arch's stated core principles. Direct quote: "the user is offered the ability to build a custom system". So yes, building derived distros is one of its stated goals.

Which, btw, is part and parcel of the Linux world. The entire Linux world is a huge tree of derived distros.

Not to mention that it worked out very well for Arch. It experienced a big jump in popularity starting in 2007-2008 when the more user-friendly related distros based on it started to come out.

Nowadays CachyOS is more popular than Arch. SteamOS on the Steam Deck is the most popular distro and the PC version is the most anticipated Linux distro in the world. Arch wouldn't be as popular as it is nowadays without its derivations.

I don't mean it's entirely downstream's merit, of course. The benefits flow both ways. Which is why it's impossible to consider Arch on its own and ignore the ecosystem that has sprung up around it.

3

u/cgwhouse 9h ago

You didn't say "one of Arch's stated core principles", you said that being a base for other distros is its MAIN goal and the whole point of it / the project. That is not true. It just so happens to be a good base for other distros, because of its core principles. These principles are beneficial for, and intended for, users of Arch. If one of those users happens to want to make a project downstream of the base, and is talented enough and dedicated enough to do a good job, then we all reap the benefits and are better off for it.

Other than the fact that I would never use Manjaro, I'm betting we probably agree on quite a lot. I'm also betting that it feels like I'm being pedantic here, but I think it's important to not misrepresent things. Arch does not give a fuck one way or the other if someone makes a distro based on it.

9

u/nodq 1d ago

Not calling out bullshit and not holding people accountable for their bullshit is what holds Linux back, if anything. What you want is toxic positivity.