/srv/irclogs.ubuntu.com/2007/04/21/#ubuntu-server.txt

=== Malder [n=Yourmom@netblock-68-183-40-214.dslextreme.com] has joined #ubuntu-server
Maldershould I worry about how I partition my server as far as security is concerned? Most articles I've been reading about security are very brief about this topic...12:19
theacolytea couple considerations12:19
theacolytelike if you'll be having people keep user directories, you may consider keeping them on a seperate drive/partition/filesystem12:19
theacolyteoften times people do /boot and /root as well12:19
Malderlike having a xxGB partion /home ? or are we talking about /usr12:20
theacolyteit depends12:20
theacolytewhat is the box for12:20
Malderhehe12:20
theacolytei was referring to /home though12:20
Malderok12:20
Malderit serves a couple small website and also a file server for a small office12:21
Malderso it is not dedicated in either way and really can't be...12:21
theacolyteah... it really wouldn't matter12:21
theacolytealthough best practices would dictate you cared12:21
theacolyteI wouldn't though :)12:21
theacolyteis the web server public facing?12:21
Malderyes12:22
theacolyteehhh12:22
theacolyteit's not necessary12:22
theacolyteyou can though12:22
MalderIt got cracked a couple days ago and I'm starting from scratch with 7.0412:22
theacolytepermissions takes care of the majority of issues12:22
theacolytecracked? how?12:22
theacolytewhat?12:22
theacolytehgehe12:22
Maldermy best guess is brute force (weak password... I was lazy)12:23
theacolytethat'll do it every time12:23
Malderthere were multiple accepted logins from a Bulgarian IP address through ssh12:23
Malder;(12:23
Maldergot a few thousand error messages from postfix saying that xyz domain is bad or some such... not from anytthing I did...12:24
theacolytehow do you know you were hacked?12:25
Malderadmin password didn't work. Looked at auth.log and it was growing by about 10x each day....12:25
Malderso you would advise to just go with basically one big partition and then just lock everything down with file permissions? Don't worry about trying to mess with boot options for security...?12:27
Malderand obviously strong passwords...12:27
Burgworkdon't activate your root account12:29
Burgworkthere is a nifty iptables script I saw to prevent brute forcing of ssh via looking at multiple connections12:29
MalderI think I am going to go with fail2ban for that... pretty neat little package...12:30
MalderI didn't have any root account active, but still did no good. Everything was done through sudo12:30
MalderI didn't turn off root login for ssh, but didn't think that would matter since there was essentially no root user... right?12:31
Nafallodo you need to permit password login?12:31
NafalloI just use public key12:31
MalderI'm not sure. I would like to look into just using keys.. is that what you're thinking?12:31
Nafalloyea12:31
NafalloI've turned off all other ways of logging in.12:32
Nafallothat and serial cable :-)12:32
Malderdo you have a reference article on that? When are passwords necessary? I've never used keys...12:32
Malderhehe12:32
NafalloI never uses passwords anymore. I think there is something on help.ubuntu.com/community about that.12:32
MalderI do have physical access so I can do that too... always nice12:32
Nafalloor rather. I use passwords for sudo :-)12:33
Malderright, but that's after login to SSH with your key, right?12:33
Nafalloyes12:33
MalderSounds good to me12:34
Malderok. Off to partition. Thanks for the help.12:34
Nafallono problem :-)12:34
theacolytesorry about that Malder, had to go AFK12:55
theacolyteyou may try also installing rkhunter, apf, and bfd12:56
theacolytei've used them before, and they work great for brute force attacks12:56
theacolytehttp://www.rfxnetworks.com/proj.php12:56
NafalloI hope you meant against :-)12:57
theacolytehehe12:57
theacolytemaybe!12:58
=== defendguin [n=supertux@cpe-72-181-7-135.houston.res.rr.com] has joined #ubuntu-server
defendguini'm trying to install feisty server and it's telling me it can't mount my cdrom drive12:59
defendguinobviously its able to read the cdrom or it wouldn't have booted12:59
theacolytewhat kind of controller is the cdrom attached to?01:00
defendguinide 01:00
theacolytemobo?01:00
defendguinyeah right to the motherboard01:01
defendguinnothing very special about the box no odd hardware 01:01
theacolytewell, if feisty isn't finding the cdrom when you load up the installer, 100% of the time it's because your controller isn't supported through normal channels01:02
theacolytewhat motherboard?01:02
defendguini couldn't tell you off hand01:02
theacolyteah01:02
defendguinit was supported when i installed edgy desktop01:03
theacolytea good example of it would be my jmicron controller is hated by 99% of the distros out there01:03
defendguindoes server edition support less hardware than desktop?01:04
Burgworkno01:04
defendguinbesides wireless card01:05
defendguinhmmm i wonder why it had no problem with edgy 01:06
theacolytedistros change01:06
theacolytebut without knowing the specific hardware, there's no way of knowing for sure01:06
defendguinwell i can just boot up without the CD and let you know what hal says01:07
Burgworkthat is why big orgs keep testing hardware around01:09
defendguinwhat item am i looking at in the device manager01:10
defendguin?01:10
defendguinsays intel brookdale chipset 01:11
Burgworkif it is wireless, do you need the firemaer01:11
defendguinno wireless on this computer01:12
theacolytedefendguin: what's under either RAID controller or IDE/ATA/ATAPI controllers?01:12
defendguinintel 82801BA ide U10001:12
theacolytethat it?01:13
defendguinoem vendor HP01:13
defendguinpci_8086_244b01:14
=== foo [n=foo@unaffiliated/foo] has joined #ubuntu-server
defendguini'm just poking through what the hal device manager says is there a specific field you would like to know about?01:17
theacolyteno just the device names under ide controller, i'm just a little slammed right now01:18
defendguinmaybe i could just do a dist upgrade 01:19
theacolyteyou could01:19
defendguinnah i like fresh installs01:19
defendguinhow could the installer even get started if the cdrom isn't supported01:21
=== mipe [n=05049bb3@gate-so-1.actebis.com] has left #ubuntu-server []
defendguini guess i could rip the CD to an iso on this machine and mount the iso and do a net install?01:22
theacolytewell01:26
theacolyteit will boot because your BIOS takes care of that01:26
theacolyteto actually copy files from the cd to your hard drive, it needs a driver to mount it01:27
theacolytenot quite the best explanation of it, but like I said, i'm slammed01:27
defendguini understand01:28
=== Atlas95 [n=Atlas@84.5.54.145] has joined #ubuntu-server
Atlas95hello02:38
Atlas95anybody here pleasE?02:38
Atlas95i have a big problem02:38
Atlas95i follow perfect setup guide02:38
Atlas95and i have this error when i try to install some packages:02:39
Atlas95E: Le sous-processus /usr/sbin/dpkg-preconfigure --apt || true a renvoy un code d'erreur (100)02:39
=== ToonArmy [n=chris@88-105-163-143.dynamic.dsl.as9105.com] has joined #ubuntu-server
=== dj-fu [i=aj@unaffiliated/dj-fu] has joined #ubuntu-server
=== sahafeez [n=sahafeez@ip68-6-223-156.sd.sd.cox.net] has joined #ubuntu-server
sahafeezis the only diff between desktop and server what is installed by default?06:15
Burgundaviasahafeez: the default kernel is slightly different07:08
sahafeezcan you install desktop and then apt-get the server kernel07:08
Burgundaviayes07:12
sahafeezi take it that the desktop installs tons of stuff and it is better to just do server and then install a gui if you need it. 07:23
Kamping_Kaiserdesktop installs a desktop. if its not going to be a desktop, its probably a bad choice of intall07:23
Kamping_Kaiser*install07:23
sahafeezi am replacing a w2k3 server at work and have tried sles, rhel. i think i am settling on ubuntu07:24
sahafeezi need to have ldap+samba+postfix+cryusimap+postgress+opengroupware07:24
sahafeezand everything needs to auth on ldap07:24
=== dj-fu [i=aj@aj.noc.maxnet.co.nz] has joined #ubuntu-server
Kamping_Kaiseri havent tried setting up those services, so i cant comment. ldap+samba+postfix+postgres are in the repos, not sure about the other two you meantion07:26
Burgundaviainstall the server, then install what you need07:26
sahafeezok, thanks.07:29
Burgundaviathen you can absolutely control what is on the server07:29
Burgundaviadesktop will leave you with all kinds of stuff you don't need07:30
BurgundaviaI would also spread out those services across multiple servers07:30
Burgundavialdap+samba on one, mail on the other07:31
sahafeezit is for 10 people.07:32
Burgundaviastill worth it07:33
Burgundaviahardware is cheap07:33
sahafeezone box with 2gb of ram, 3ware raid5 and core 2 is easier07:33
Burgundaviathen kvm it up07:33
sahafeeztrying to cut down on the support.07:33
sahafeezhave another box running slack + asterisk pbx07:34
Burgundaviaahh07:34
sahafeezhave openbsd box for vpn/firewall07:34
BurgundaviaI would have a common platform07:34
sahafeezand the w2k3 sbs file+exchange. guess which box gives me issues?07:35
Burgundaviaexcept asterisk is not in main07:35
sahafeezgoing to move the asterisk box to whatever disto i put on the file server. so ubuntu if it works out.07:35
sahafeezi will do asterisk from source07:35
Burgundaviahmm, I distrust source07:36
Burgundaviasecurity updates are a headache07:36
sahafeeznaw, asterisk is simple.07:36
Burgundaviasetting it up is a royal pain07:37
Burgundaviaand debugging is a bigger one07:37
sahafeeztook me forever the 1st time. 07:37
sahafeezafter that it got simple. just had to learn it07:38
Burgundaviawe have a lot of moving pieces, with two offices07:38
sahafeezserver installs compile tools by default or no?07:38
Burgundaviano07:38
Burgundaviaserver installs enough to run the hardware and login07:38
Burgundaviathat is it. No open ports, no running services, nothing07:38
sahafeez2 offices, one east one west, openbsd vpn. 3 houses with vpn and remote phones. all ip phones. just works07:39
sahafeezvery openbsd like07:39
sahafeezi am a bsd person. i am forced onto linux by hardware/or software that i need.07:39
Burgundaviaahh07:39
Burgundaviapersonally, I like having a common server platform07:42
Burgundaviahaving 3 distros like that means 3 times as much security07:42
sahafeezsettled on opengroupware for the exchange replacement so i need to run it on linux for the most part. it runs on bsd, etc but its a pain to setup and i need the blackberry push stuff 07:42
sahafeezi would run every thing on solaris if i could or openbsd. those would be my main choices07:43
sahafeezi would do gentoo for linux however i need something a bit simpler because others may have to touch it. i started looking at SLES and RHEL because of that.07:44
sahafeezRHEL sucks07:44
=== volvoguy [n=volvoguy@c-68-60-52-220.hsd1.mi.comcast.net] has joined #ubuntu-server
volvoguycan i ask you guys a support question or is this just a dev channel?07:44
sahafeezand SLES is very very good cept the updated make the system unbootable as the hardware is too new and i do not feel like figuring it out 07:45
Burgundaviavolvoguy: both07:45
volvoguywoohoo!07:45
BurgundaviaI have heard good things about SLES07:45
sahafeezvery clean and polished. comes out of the box with samba+ldap setup correct. YAST is a great tool.07:45
volvoguyi'd like to upgrade my breezy server to at least edgy, if not feisty. the support pages recommend not using apt-get for this, but i don't exactly have "update-manager" which they DO recommed. is there a safe way to use non-gui tool?07:46
Burgundaviasome of the integration stuff is better in SLES/RHEL07:46
Burgundaviavolvoguy: release cycle was breezy --> dapper --> edgy07:46
BurgundaviaI would keep servers on dapper, as it is supported longer07:47
Burgundaviasadly, there is no tool yet07:47
volvoguyoh, i'm sorry. i meant I'm on dapper, not breezy.07:47
Burgundaviaahh07:47
Burgundaviaif you update past dapper, you will have to update a lot07:47
Burgundaviajust to be aware07:47
volvoguythat's what i want to avoid though - having to upgrade through many releases. 07:47
Burgundaviathen you should stay on dapper until the next LTS07:48
Burgundaviain april 200807:48
BurgundaviaI am a very conservative person when it comes to my servers, however07:48
volvoguyand not bother with performance/feature updates until then?07:48
Burgundavialess headaches > a bit of performance07:49
volvoguyBurgundavia, yeah - i can understand that. this is a simple file server and part-time web-dev server. it doesn't do much.07:49
Burgundaviabackup your data and do the edgy update manually07:49
Burgundaviathen use the edgy --> feisty update07:50
volvoguyBurgundavia, so you'll do a clean install for every LTS release?07:50
sahafeezi would love to see zfs ported to linux. that would be the best of all worlds, well zfs and pf07:50
Burgundaviano, LTS --> LTS supported07:50
volvoguyright.07:50
Burgundaviathus 6.06 will update to 8.0407:50
volvoguyand will do so with less complication?07:50
Burgundaviaor you can do 6.06 --> 6.10 --> 7.04 --> 7.1007:51
ajmitch(assuming that 8.04 is LTS, and that significant work is put in to support upgrades)07:51
Burgundaviaajmitch: the latter is assumed. Canonical has large paying customers that will demand it07:51
Burgundaviaand what better way to test an update tool than on the community, no?07:51
ajmitchwhat I mean is that many packages will need to be checked & modified for upgrades07:52
volvoguyajmitch, that was my concern. it seemed to me that smaller updates made more sense, but if canonical is going to try to make a smooth upgrade path to 8.04 - i'll wait for that.07:52
ajmitchlittle things like directories moving around, symlinks, handling corner cases in maintainer scripts07:52
ajmitchit'll take a bit of work, but I'd say that it's expected07:52
volvoguyok. cool. :)07:52
Burgundaviathe cool stuff is on the desktop anyway07:53
ajmitchthe next LTS release would probably end up with less cool new stuff, and more time spent polishing07:53
volvoguyyeah. feisty looks great. 07:53
ajmitchBurgundavia: pfft, server is getting cool stuff :)07:53
sahafeezthe fact that i can buy support is the reason i am looking at ubuntu07:53
Burgundaviaso I keep my laptop running the absolutely latest and my servers and work desktops running the LTS07:53
volvoguymy "production" server is a virtual ubuntu server at unixshell. hopefully their xen system will be upgradable to 8.04 easily too. :)07:55
volvoguythey're probably one of those paying customers though - so they'll be one demanding it. hehe.07:56
volvoguywell, thanks for the quick updates guys. i'm not involved and online anymore as much as i'd like to be, but i know i can always turn to you for help! talk to you later.07:57
Burgundaviacya07:57
sahafeezwhat is with the delay in the partitioning when doing anything - switching between stuff, lvm, etc. 08:13
Burgundaviaon the installer?08:13
sahafeezyes08:13
Burgundaviano idea08:13
sahafeezit could tell you something you know.08:13
fabbionesahafeez: known issue08:13
fabbioneit was in the release notes.. there is a bug linked from there08:14
fabbioneit's only annoying but it doesn't affect final installation or functionality08:14
sahafeezno, but it makes the install take, oh, 2 hours longer ;)08:14
fabbionei know.. it adds 3 minutes wait on each lv you create08:15
fabbionethere is really nothing we could do to fix it when i first found out of the problem08:15
fabbioneit was too late in the release process :(08:15
sahafeezoh well. just happy it is not just me08:15
fabbioneit's a good excuse for a cup of coffee08:15
=== sahafeez thinks i should read this release note things
fabbionethe bug is generic.. 08:16
=== sahafeez has a beer
fabbionethat'd work too :)08:16
sahafeezthis is my 1st install of ubuntu. i was having debian flash backs. 08:16
=== sahafeez hates debian
sahafeezstill waiting ....08:18
fabbionesahafeez: as i said... 3 minutes for each lv you created08:19
=== fabbione goes back to bed
sahafeezwell i am on 6 mins now and all i am trying to do is active an existing lvm setup08:20
fabbionesahafeez: read the bug or you will keep waiting and asking herre08:20
fabbionehere even08:20
sahafeezyes, i am reading now..08:20
=== fabbione &
sahafeezsince i have the time and all.08:21
sahafeezbetween this and the broken ide on my sparc copying files....08:22
sahafeez:)08:22
=== foxiness [n=nayif@unaffiliated/foxiness] has joined #ubuntu-server
sahafeezi am kinda wondering why your servers got so hammered, being large network scaling guy08:24
Burgundavialots and lots of people08:27
Burgundaviawe did better than suse and fedora last releas08:27
Burgundaviathey went off the air08:27
sahafeezyah, but it is so simple to fix08:27
maswansahafeez: well, it depends, if you can answer me why suddenly there were thousands of CLOSE_WAITs on my mirrors, filling up all the apache slots?08:27
maswanwith 0 bytes in send-q too08:28
sahafeeznice.08:28
sahafeezhow many servers08:28
maswanfor my mirror? 608:28
=== sahafeez is still trying to find a server that will let me look at the release notes
maswan(i'm se.releases.ubuntu.com)08:28
sahafeezhow does your SLB work?08:29
Burgundaviamaswan: you guys are the big ones, no?08:29
maswanwhat's slb? :)08:29
sahafeezah, server load balancers 08:29
maswanBurgundavia: we peaked at 3.8Gbit/s, so yeah.08:29
maswanah, large requests (.isos etc) get http-redirected to one of the frontends depending on hash (so that one iso always ends up on the same backend, to keep cache locality)08:30
sahafeezwas it a load issue or an apache bug issue. 3.8 is not alot08:30
maswansahafeez: don't know, afaik they blame eachother08:30
maswanor go "huh?" when reported08:31
sahafeezwhat box is doing that? a linux box or switch hardware08:31
maswanthe frontend[s]  that's in dns, they have to handle the small files (deb:s etc that can't be http-redirected), and also ftp&rsync08:31
maswanindividual isos that have more demand than one frontend can satisfy, we manually identify and spread out on more frontends08:32
maswanit actually works really well, except when we get that CLOSE_WAIT issue08:32
sahafeezwas the traffic balanced over the servers - after action - looking that the mrtg or whatever you use08:33
maswanhttp://www.acc.umu.se/technical/statistics/ftp/monitordata/index.html.en08:33
sahafeezrrdtool08:33
maswanso, not very well balanced, but then the servers are not equal either08:34
maswanwell enough balanced after 21:00 local time yesterday though08:34
sahafeezquestion, and this is because i am not a linux guy, using ext3 on a lvm for a postgress db. any mount options i should look at08:34
sahafeezok. it would be interesting to see the network drawing.08:34
sahafeezi love this kind of stuff.08:35
sahafeezsetup a network that took a 10gb/s DoS once and kept working08:35
maswanwell, remember, this is just my mirror at the academic computer club at umea university08:35
maswanwe're depending on what hardware gets donated to us, and whatever bandwidth the university feel like giving us08:36
sahafeezok.08:36
maswanthe canoncial setup (main servers) is not public, AFAIK08:36
sahafeezno big. i am a nut about network design.08:36
maswanso in short, out of those machines orion,vega,napoleon are on a separate 2Gbit/s network [borrowed machines from the hpc center at the uni] , the rest share a 2Gbit/s uplink too.08:37
maswanthen it ends up roughly like this: http://www.umdac.umu.se/netmaster/net/Campusnetpresentationumu.jpg08:38
maswanand then: http://stats.sunet.se/stat-q/load-map/optosunet-kunder,,traffic,peak08:38
maswanand sorry, can't think of anything for your mount options question08:39
sahafeezno prob08:39
sahafeezinteresting. it looks abit over complex for my taste...the network08:40
maswanthe campus one or the optosunet?08:40
sahafeezthe 2nd one.08:42
sahafeezthe campus - those are routed or layer2 links08:42
sahafeezbetween the cisco switches08:42
maswansahafeez: remmeber that on the second one, all those names are different universities accross sweden that requires redundant paths08:43
maswanthe campus one shows the routers on campus, not all the dumb switches08:44
sahafeezbased on as the cable runs and build out time no doubt vs what would be logical08:44
sahafeezok, so you are using the 65xx as swtich/routers to distribute08:45
sahafeez6509 is a switch cisco just added a router card as an after thought08:45
maswanyeah, that's my understanding of it. the next-gen campus network is in next year or so08:45
=== loVolt [n=rick@s216-232-87-188.bc.hsia.telus.net] has joined #ubuntu-server
maswanwell, there aren't very big routing decisions that needs to be made within campus08:46
sahafeezwhatever you do do not fill them with gige ports and run them flat out. it will crash ;)08:46
maswan:)08:46
loVoltmind if I pose a fiesty/samba question ?08:46
sahafeezas i am trying to setup samba myself sure08:46
maswanloVolt: go ahead, don't be surprised if noone is around to answer08:46
loVoltthx , I give it a try08:46
loVoltwalking though any number of howto's 08:47
maswansahafeez: actually, the optosunet one is based on the returns of a single tender for dark fiber across sweden08:47
loVoltI can get everything cept' getent passwd/group to work08:47
loVoltlike nssswitch is ignored08:47
loVoltlike bank in 2000/2001 08:48
loVolter bank/back08:48
loVoltwbinfo and others work fine08:48
maswansahafeez: and the weirdness comes from requiring a "red" and a "green" network connection to all sites, and there not being enough fiber in the ground to make the most logical extension to all sites08:48
loVoltis there a ubuntu-samba chan?08:48
ajmitchloVolt: 'winbind enum users = true' in smb.conf08:49
ajmitchthat allows enumeration of users with getent08:49
ajmitchit should be able to resolve normally anyway08:49
maswansahafeez: http://basun.sunet.se/karta/opto2.gif a bit more geographical08:49
loVoltyes08:49
sahafeezah, makes sense.08:49
sahafeezmaswan thanks for sharing the info. i love looking at this stuff08:50
loVoltgetent only show local pass/groups08:50
loVoltshot in the dark08:51
maswansahafeez: btw, sthml is clickable on the optosunet map and you can get to nordunet that way too08:51
ajmitchand you restarted winbind after changing that option?08:51
loVoltI ran cvs and samba4 last night on fiesty ...semms to go well08:51
sahafeezlooking..08:51
loVoltajmitch, rebooted even08:51
ajmitchloVolt: sorry, it's 'winbind enum users = yes'08:52
ajmitchand the corresponding one for groups08:52
loVoltajmitch, yeah users and groups08:52
ajmitchgetting users/groups off an AD server?08:52
loVoltyeah08:52
ajmitchsecurity=ads, and realm is set?08:52
loVoltyeup08:53
maswansahafeez: everything goes into the a[123] sth routers, using virtual routers in those junipers, AIUI08:53
ajmitchwbinfo -u returns the right info?08:53
loVoltyes08:53
loVoltwbinfo -g as well08:53
sahafeezjunipers are the best routers right now so that is good.08:53
ajmitchloVolt: you could increase the debug output on winbindd08:54
loVoltchecking08:54
ajmitchin /etc/default/winbind08:54
=== ajmitch recently had issues with this, and it just took the smb.conf options for getent to work properly
loVoltlog level = 3 in defaults/winbind do ?08:56
sahafeezwhat is the deal with using a custom kernel on ubuntu. no issues?08:56
loVoltsahafeez, haven't found any issues08:57
loVoltlots of apt-getting :)08:57
sahafeezok, cool. 08:57
sahafeezi want to mount an mac hfs drive ;)08:57
loVoltdon't forget autoconf if you want other pcakacges08:58
ajmitchloVolt: no, I'd put "-d 3 -n" in WINBINDD_OPTS08:58
loVoltk 08:58
loVoltheh screaming about invalid option :)08:58
loVoltfixing08:58
=== sahafeez is new to ubuntu and is trying to get my head around it. used to gentoo for linux
loVoltI've got two boxes , one fiesty dns only no devl tools and 2nd is fiesty dns with devl / samba409:00
loVoltdarned is samba4 didn't "just work"09:00
=== loVolt shivvered
loVoltk' started again , lets tail the chaos09:01
loVoltcool idmap went boom09:03
loVoltfatal error uid range full09:03
ajmitchwonderful09:03
loVoltmax 20000009:04
loVoltlets up that a bit09:04
ajmitchenum users/groups may not be a good thing if you have that many :)09:05
loVoltI don't 09:05
loVoltabout 150 not inc a/d spare parts 09:05
loVoltdoubled it and rebooting09:05
loVolt load average: 5.64, 5.71, 5.6409:06
loVoltdifferent box09:06
loVolt:)09:06
loVoltwierdness09:08
loVoltstill says full , could not lookup domain user luser09:09
loVoltwonder if I lower the level09:10
loVolttrying 2000-1000009:12
loVoltsame09:15
loVoltI need coffee to live09:15
=== sahafeez [n=sahafeez@ip68-6-223-156.sd.sd.cox.net] has joined #ubuntu-server
sahafeezsilly question. how do i see what to install when i do not know the package name. i want to install sshd09:39
lionelsahafeez: for ssh the package name is openssh-server09:41
lionelin general, you use apt-cache search for package search09:41
sahafeezok. i need to read about apt as it is new to me.09:41
sahafeezthanks09:41
loVoltgnite09:52
=== DisabledDuck [n=duck@c-24-129-213-76.hsd1.fl.comcast.net] has joined #Ubuntu-Server
=== ivoks [n=ivoks@4-39.dsl.iskon.hr] has joined #ubuntu-server
=== dj-fu [i=aj@home.junglist.gen.nz] has joined #ubuntu-server
=== jsgotangco [n=jsg123@ubuntu/member/jsgotangco] has joined #ubuntu-server
=== ivoks [n=ivoks@37-230.dsl.iskon.hr] has joined #ubuntu-server
foxinesshi, am on step of create " Virtual Server Scenario " url: https://help.ubuntu.com/community/RubyOnRails? , on this line sudo nano /etc/apache2/sites-available/<servername> , <servername> = ??? its not clear to me if i need to <domain.net> or domin.net or domaindotnet12:11
ivoksit is irrelevant12:17
ivoksyou can put there 000-mambo-jambo12:17
ivokscontent of that file is important12:18
foxinessk,now it clear thanks i need now to figure out ,next step port 80 12:26
ivoksheh12:27
ivoksfirst time configuring apache?12:27
foxiness:) yes12:28
ivoksgrab a book or something :D12:28
foxinesshost@home12:28
foxinessbook? or something? , like what ?12:29
ivokshowtos, tutorials, etc..12:29
ivoksi have two apache books, both are over 300 pages :)12:29
ivoksand these are small apache books12:30
ivoksbbl; bye12:30
=== ||arifaX [n=||arifaX@pd9e78468.dip0.t-ipconnect.de] has joined #ubuntu-server
=== ra1nb0w [n=davide@213-156-55-129.fastres.net] has joined #ubuntu-server
=== ||arifaX_ [n=||arifaX@pD9E78468.dip0.t-ipconnect.de] has joined #ubuntu-server
=== ra1nb0w [n=davide@213-156-55-129.fastres.net] has joined #ubuntu-server
=== vciaglia [n=vciaglia@host53-17-dynamic.11-87-r.retail.telecomitalia.it] has joined #ubuntu-server
=== ivoks [n=ivoks@4-147.dsl.iskon.hr] has joined #ubuntu-server
=== ToonArmy [n=chris@88-105-163-143.dynamic.dsl.as9105.com] has joined #ubuntu-server
=== jsgotangco [n=jsg123@ubuntu/member/jsgotangco] has joined #ubuntu-server
=== soothsay [n=soothsay@bas5-montreal02-1096554204.dsl.bell.ca] has joined #ubuntu-server
=== sahafeez [n=sahafeez@ip68-6-223-156.sd.sd.cox.net] has joined #ubuntu-server
fooHm, what's your mta of preference? exim? postfix? hopefully not sendmail.09:03
Nafallopostficx09:04
Nafallopostfix09:04
sahafeeztelnet mail 2509:04
sahafeez;)09:04
fooNafallo: What's your reasoning? Have you used exim? Someone recently told me to check out ensim, I'm a postfix fan too09:05
Nafallofoo: it's built with security in mind and is extendible into infinity. also it's what are recommended from the distroteam.09:07
fooNafallo: Hm, ok, then I think I'll just stick with that.09:08
Nafallogood choice :-)09:09
fooHm, now, this system has 5 domains. I've never set up "virtual domains" or something before with postfix, I'll need to figure that one out09:09
fooNafallo: eh, actually, I just remember, this server has debian etch. The data center couldn't put ubuntu on them, eh. I'll still use postfix, though, hehe09:10
Nafallofoo: help.ubuntu.com/community/Servers is a good one09:10
fooah, thanks09:11
=== soothsay [n=soothsay@bas5-montreal02-1096554204.dsl.bell.ca] has joined #ubuntu-server
fooNafallo: Hm, I'm checking out that wiki. I guess, my main concern is say, this server hosts about 5 domains... it only sends mail via the web scripts, it does not receive. How does postfix distinguish which @domain to send mail from if 5 different domains are on the system?09:27
Nafallonot sure. I use MUA to send mail myself.09:28
fooMail User Agent ?09:30
Nafalloyes09:31
=== aalex [n=aalex@modemcable097.146-57-74.mc.videotron.ca] has joined #ubuntu-server
=== r00tintheb0x [n=r00tinth@cpe-72-177-144-169.houston.res.rr.com] has joined #ubuntu-server
=== Impaque [n=imp@cable-89-216-129-141.dynamic.sbb.co.yu] has joined #ubuntu-server
fooNafallo: yeah, seems like the best way to change From: field is just in the code09:54
fooNafallo: thanks09:54
Nafallothat's probably right. no problem.09:54
Impaquehello, is anyone using AMD64 on Intel-based 64-bit machines?09:54
Impaque(amd64 version of ubuntu-server)09:55
=== stratus [n=stratus@201.53.55.52] has joined #ubuntu-server
=== Burgundavia [n=corey@ubuntu/member/burgundavia] has joined #ubuntu-server
=== vciaglia [n=vciaglia@host103-37-dynamic.10-87-r.retail.telecomitalia.it] has joined #ubuntu-server
=== soothsay_ [n=soothsay@bas5-montreal02-1167964376.dsl.bell.ca] has joined #ubuntu-server
sahafeezif i want software raid, that is not part of LVM right. i have to make the raid 1st then put the LVM over it'11:09
=== foxiness [n=nayif@84.235.36.29] has joined #ubuntu-server
=== Burgundavia [n=corey@ubuntu/member/burgundavia] has joined #ubuntu-server
=== jsgotangco [n=jsg123@ubuntu/member/jsgotangco] has joined #ubuntu-server
=== ra1nb0w [n=davide@213-156-55-129.fastres.net] has joined #ubuntu-server
=== jhutchins [n=jonathan@64-151-34-11.dyn.everestkc.net] has joined #ubuntu-server
soothsay_Anyone know how to use DHCPD to set (some) fixed ip addresses?11:43
sahafeezman dhcpd.conf12:02
sahafeezyou have to create a static entry via the mac address in the config file12:03

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!