How the internet works · Final challenge

Final challenge: the Monday morning meltdown

Monday, 8:02 a.m. The club's messages are piling up: the website won't load, the server can't get updates, the wiki says "not secure", the lab is unreachable, and someone swears the site "still shows the old version". It's all the same server. Every layer of this path is broken somewhere on it.

How this works

No step-by-step instructions. The objectives say what must be true, and they're checked live as you work. Use the ladder from lesson 9: test one layer at a time, read every error word for word, change one thing at a time, and make every fix survive a reboot. Hints are below if you get stuck.

The brief

  1. The website loads from the laptop (http://192.168.1.50), not just from the server itself.
  2. The server reaches the internet by name (ping rockylinux.org works), and the fix is saved for the next reboot.
  3. Programs on the server get club.example.org's new address, 203.0.113.10.
  4. The lab server 10.20.0.15 is reachable, through the lab router at 192.168.1.60, and that survives a reboot.
  5. curl https://wiki.club.lan works without -k, using the club's CA in ~/club-root-ca.pem.

Stuck? Hints

Open only as many as you need.

1. The website

Does it work from inside (curl localhost)? Then something sits between the server and the laptop. Look at the firewall, and at where Apache listens (sudo ss -tlnp, the Listen line). Lessons: lesson 5, lesson 9.

2. The internet

Two rungs are broken: ip route (is there a default?) and DNS (cat /etc/resolv.conf / resolvectl status). Save the fix in NetworkManager (Rocky) or netplan (Ubuntu). Lessons: lesson 3, lesson 4.

3. The old address

dig and getent hosts can disagree. Apps check /etc/hosts first, and caches remember old answers until their TTL runs out. Lesson: lesson 4.

4. The lab

ip route get 10.20.0.15 shows which way packets go. Add a route via 192.168.1.60, and save it (nmcli +ipv4.routes on Rocky, a netplan routes: entry on Ubuntu). Lesson: lesson 3.

5. The wiki

"unable to get local issuer certificate": this machine doesn't trust the club's CA yet. Each family has its own trust-store folder and update command (and Ubuntu wants a .crt name). Lesson: lesson 7.

Complete every objective in the terminal and the challenge is marked done automatically. It's optional, but it goes on your certificate.