/srv/irclogs.ubuntu.com/2007/11/29/#ubuntu-server.txt

phaidroskgoetz: you are right ..00:00
lamontkgoetz: any luck with ldap?00:03
kgoetzlamont: fraid not, i've been busy with other work. i managed to get ldapsearch going ok ( http://pastebin.ca/801040 ) and from my reding of that i can connect to ldap00:04
lamontkgoetz: are you doing ldaps or ldap in the end?00:05
kgoetzlamont: /etc/ldap.conf -> uri ldap://127.0.0.1/ . ldapi "wasnt working " as i recall00:06
lamontyou want some spamage here, or pastebin, or where?00:07
kgoetzpastebin woul be fine.00:07
kgoetzavoid turning the channel against us ;)00:08
lamontstep 1 is to get ldap://127.0.0.1/ working.  Then we can worry about making a cert and getting ldaps happy00:08
kgoetzi have ldaps enabled, dont remember if i mad a cert for it or not00:08
kgoetzi just didnt see a reason to ldaps: onto localhost00:08
kgoetzin /etc/default/slapd i put SLAPD_SERVICES="ldap://127.0.0.1:389/ ldaps:/// ldapi:///"00:09
lamonthttp://pastebin.ca/80111000:11
lamontin there, s/foobaz/whatever/00:12
lamontand comment out the TLS_CACERT00:12
kgoetzlooking atm :)00:12
lamontTLS_REQCERT should be uh... something00:12
lamont'never'00:12
lamontand rootbinddn should be god-of-ldap (whatever you said when you configured slapd)00:13
lamont_THEN_ ldapsearch -x -h localhost -D cn=admin,dc=foobaz,dc=com -W "(uid=kgoetz)" uid00:14
lamontthat'll prompt you for the passphrase, which should be what's stored in /etc/ldap.secret00:14
lamontand if _that_ query works, then all we have to do is argue with nsswitch.conf00:15
kgoetz*starts looking for all those files/lines in files00:15
lamontkgoetz: I just finished smacking my config into usability again for gutsy00:16
lamontin the process, I fear I actually understand pam now.00:16
lamontdon't tell anyone00:16
lamont:-)00:16
kgoetzhehehe. i got famiar with pam_radius and a few related bits... i wish i still rememberd :)00:16
phaidrosany ideas what might be the problem with hotplug if "cat /proc/kernel/sys/hotplug" -> cat: /proc/kernel/sys/hotplug: No such file or directory (2.6.22-14-xen)00:20
phaidros?00:20
kgoetzyour file or directory isnt there?00:20
phaidrosbut it shoul, shouldn't it?00:21
kgoetzlamont: teh TLS_REQCERT -i dont see that in my config. can i just add it?00:21
kgoetzs/teh/the00:21
lamont find /proc | grep plug00:21
lamont/proc/sys/kernel/hotplug00:21
phaidrosuh oh o.O00:22
lamontkgoetz: I expect so.  That's almost exactly what the file looks like on my machine... worst case it just mutters about lines it doesn't understand00:22
kgoetz# here because "lamont said"00:23
kgoetzTLS_REQCERT demand00:23
lamontyou want TLS_REQCERT never00:24
lamontfor now00:24
kgoetzok.00:24
lamontbecause we're not doing ldaps yet.  just ldap.00:24
kgoetzok00:25
kgoetzshouldi comment out the extra lines that you dont have?00:27
kgoetzoooh. it worked :o00:29
kgoetzls: /etc/libnss-ldap*: No such file or directory00:30
kgoetzbut the query workd :)00:30
lamontlibnss-ldap*  will need to be there when we say 'getent shadow |grep kgoetz'00:34
lamontwhich we want to see two lines from, hence the fetcheverythingandgrep solution00:34
lamontapt-get install libnss-ldap00:34
lamontand may as well install libpam-ldap too00:35
kgoetzboth are already installed00:35
lamontand finger-ldap :-)00:35
lamontah, on gutsy?00:35
kgoetzyes.00:35
lamontthe symlinks may or may not be needed... I'm to lazy to figure it out - they're certainly needed on dapper. :-)00:36
lamontand I have dapper machines, too.00:36
lamontsudo /etc/init.d/nscd restart00:36
kgoetzthey dont seem to be needed anmore ;)00:36
kgoetz*any more :)00:36
lamontactually, do a stop and then a start - restart doesn't always give me the love I want00:36
lamontand the uri in /etc/ldap.conf is ldap://127.0.0.1/, not the ldaps://ldap.foobaz.com/, right?00:37
lamont /query lamont and paste /etc/ldap.conf :-)00:37
kgoetzi dont have an nscd00:38
* kgoetz cuts out comments from config file00:39
lamontno nscd just means that you'll query the ldap server alot.  OTOH, it also means that nscd won't be stepping in the middle and LYING to you00:40
kgoetzpm flooded00:43
lousygaruadid anyone ever tried `rsync` over WebDAV? does it works??01:18
lamontNov 28 16:05:21 mmjgroup postfix/local[15044]: warning: pipe_command_read: read time limit exceeded02:16
* lamont grumbles02:16
danphi. where would i find a list (or an RSS feed) of packages that are updated in universe/multiverse?02:39
danpi have a server running edgy and perdition was updated for security fixes but i couldn't find that announced anywhere02:39
Burgundaviadanp: ubuntu.nl has feeds02:47
Burgundaviadanp: https://lists.ubuntu.com/archives/ubuntu-devel/2005-August/009392.html02:48
danpthanks, seems to be gone now though02:49
Burgundaviathey are there still02:50
Burgundaviajust moved02:50
Burgundaviajust trying to find them02:50
Burgundaviadanp: http://blogs.ubuntu-nl.org/dennis/2007/10/21/hardy-heron-changes-feed/02:52
danpthanks!03:07
danpBurgundavia: hmm, this still only seems to be changes to main. perdition is in universe03:56
Burgundaviadanp: there have been no changes to edgy since release, as only main is security supported04:00
kgoetzany (easy) way to increase teh logging prouced by pam? i'm unable to get multiple logins over ssh using ldap backend (i also have issues with sudo)04:00
Burgundaviadanp: https://lists.ubuntu.com/archives/edgy-changes/2007-November/thread.html04:01
Burgundaviadanp: and why are you still running an edgy server?04:01
Burgundaviait is not supported for all that much longer (6months)04:01
danpthat's still only main changes...perdition is in universe and was recently updated04:02
Burgundaviahttp://changelogs.ubuntu.com/changelogs/pool/universe/p/perdition/perdition_1.17-7ubuntu0.6.10.1/changelog04:02
Burgundaviahmm, wonder why they are not showing up04:03
danpand i'm still running edgy because it's supported for another 6 months :P04:03
Burgundaviaat which point you need to upgrade to Feisty, for another 6 months04:04
Burgundaviaand then to Gutsy and then to Hardy04:04
ScottKBurgundavia: There have been edgy-security uploads for Universe packages.  I've done a couple myself.04:08
BurgundaviaScottK: yes, but not many04:09
Burgundavianot that I would trust a production server to04:09
danpi'm on ubuntu-security and i never got a notice for perdition04:09
ScottKWell you take that risk pretty much whenever you run Universe stuff.04:09
Burgundaviabecause -security doesn't carry universe stuff04:09
Burgundaviathis is a fairly serious issue, the lack of notification04:09
ScottKdanp: Even when Universe packages get updated, they won't do a USN.04:09
Burgundaviait should at a minimum, go to -changes04:10
ScottKAgreed.04:10
danpis there at least a published list of the changes?04:10
Burgundavialet me put it on the tech board agenda04:10
Burgundaviadanp: there is the mailing list. I have no idea why this upload did no make it there04:10
ScottKLP developers dropped security from -changes because the fact that it was there before was a 'bug' and not by design.04:10
Burgundaviaugh, that is dump04:10
Burgundaviadumb, rather04:10
ScottKThey've been thrashed and promise to put it back Real Soon Now.04:10
ScottKWell it's LP.  That's redundant04:11
BurgundaviaI am very strongly of the opinion that LP is mostly just a giant non-free rathole04:11
danpthis is just an example, but in a more general sense i'm looking for a way to get notified/informed of *any* changes to whatever release i'm using04:11
Burgundaviathis is one of those holes04:12
ScottKBurgundavia: Agreed.04:12
danpis my best bet right now to track the package list files?04:12
ScottKWhen I asked, "If it's a bug, where's the spec that describes how it's supposed to work?"04:12
ScottKAnswer I got was, "will you help us write one"04:12
Burgundaviadanp: -changes should have everything. This is a bug04:13
Burgundaviahttps://wiki.ubuntu.com/TechnicalBoardAgenda04:13
Burgundaviaadded both items to the next TB meeting04:13
ScottKhttps://wiki.ubuntu.com/UbuntuDevelopment/PackageArchive/SoyuzUserDocumentationDraft is what now exists for documentation. it's a bit, um, thin.04:14
danpthanks!04:14
ScottKMy larger answer on the help write the spec issue is that I have a consulting rate for proprietary system development work.04:15
ScottKWhich is where the non-free bit kicks in.04:15
danpso at the moment what is going to -changes?04:15
ScottKFor Edgy, you would get edgy-updates.04:15
ScottKBackports too, I think.04:16
danpcool04:20
lamontBurgundavia: bzgrep ^Package: ubuntu/dists/gutsy-security/universe/binary-i386/Packages.bz2 |wc -l04:27
lamont5504:27
lamontuniverse gets security updates, it's just not something that canonical funds doing, other than best-effort by keescook et al.04:28
ScottKThe larger point that Burgundavia makes is valid though.  There's no announcement mechanism.04:29
Burgundavialamont: yep, I get that. This is more about making certain what updates do get done get notifications created04:29
lamont"notification" == advisory?04:29
danpnot necessarily04:29
ScottKI've don't -security updates for packages that were in Universe in some releases and in Main in others and the USN just talked about the Main ones (leaving one to reasonably infer the other releases weren't affected when they were(04:30
ScottK(/)04:30
lamontBurgundavia: and launchpad has nothing to do with -security packages getting built.04:30
danpi personally just want a way to be notified of every possible change to a release04:30
Burgundavialamont: I didn't say it did04:30
BurgundaviaI was talking about mailing lists04:30
danphopefully not as low-level as reviewing changes to the Packages files myself04:30
lamontmost of the stuff that builds in -security is built while it's embargoed.  hence no notice to -changes.  the embargo is also the root cause of LP not being involved.04:31
Burgundaviabut that is a bug that can be fixed04:31
lamontsince launchpadlibrarian has no concept of read restrictions04:31
lamontBurgundavia: fixed how?04:31
lamontI can't send you a notification when i build it.04:31
Burgundavialamont: by sending the notification only when it is unembargoed04:31
ScottKlamont: At some point LP learns of the change.  Then.04:32
lamontI _can_ send you a notification when its unembargoed.  I've only seen that notification in the form of a security advisory.04:32
lamontfor _any_ software distro04:32
lamontLP learns of the change once it's unembargoed04:32
lamontI think.04:32
lamontit must be importing -secuity back from the dak archive04:33
Burgundaviaright, I am not arguing implementation at the moment04:33
lamontso at the point that LP imports the -security bits from dak, it could generate a -changes mail04:33
* lamont is speculating on that bit of process.04:33
Burgundaviaright, those are details I don't know, nor do I really specifically care, given I am not an LP dev04:34
ScottKThe key bit is that it used to be there and was removed.  What man has once accomplished he can aspire to achieve again.04:38
lousygaruawow, it's cold in here and i've just put a nice heat-blower straight on my feet!04:40
* lousygarua is delighted04:40
kgoetzi just found my ldap is far more broken then i thought04:40
* kgoetz is upset04:40
lousygaruahow can an ldap get broken?04:41
danpBurgundavia and ScottK, thanks for the tips. i look forward to -changes being my answer soon :)04:41
kgoetzmy lookups arnt working properly somehow. I have no name!@newmoon:/root$04:42
Burgundaviadanp: no worries. Sorry we cannot help you in the imm.04:42
danpit's cool. i can make do with looking at Packages in the mean time. but i'm sure other people would appreciate that information if it was readily available04:43
kgoetzlamont: you aroud? i cant seem to figure out some issues04:44
lamontheh04:44
kgoetz:(04:44
lamontfire away04:44
* lamont waits for "how do we find the girl? If we do find the girl, how do we get away?"04:45
kgoetzi can run 'id $USERNAME' and it lists out the users IDs, but bash/anything else cant map the IDs04:46
kgoetzi can ssh in as the user, but it seems only once at a time04:46
lamontmake life easier: apt-get install nscd04:46
lamontwhich, amusingly, shouldn't change anything04:47
kgoetzintalling now04:47
kgoetzreasonably small config file04:48
lamontit has a config file?04:48
lamont:-)04:48
kgoetzyes... dont i need it? :\04:49
lamontI expect so.04:49
lamontI never even noticed04:49
lamontas in, it won't need any edits04:49
kgoetzok04:49
lamonthow is bash trying to map the id?04:49
lamont(as in, what do you mean that it can't?  what's your testcase?)04:50
kgoetzinstalling that makes a difference o04:51
kgoetzs/ o//04:51
kgoetzlamont: i typed in 'bash'04:51
kgoetzand got "I have no name!@newmoon:/root$" back04:51
lamontis /etc/ldap.conf readable by mortals?04:51
kgoetznow i get "kim@newmoon:/etc/pam.d$04:51
kgoetz"04:51
lamont /etc/nsswitch.conf?04:52
lamont(/etc/ldap.secret should be root:root, 60004:52
kgoetzyes they are.04:52
lamontthe others, should be 64404:52
kgoetzyep04:52
lamontso installing nscd fixed it?04:52
kgoetzyes04:53
lamontif you figure out why, I'd love to know04:53
kgoetzyou are a genius :)04:53
lamontthanks04:53
lamontI should really put the whole mess into a howto on the wiki sometime04:54
kgoetzi was goign to work on one/two as well. getting it working became a higher priority then writing about it though ;)04:56
lamontI wonder if it's because nscd runs as root04:56
* lamont automated ssh key replication to clients from ldap04:56
* lamont is lazy04:57
kgoetz.... your writing the guide :P04:58
lamontheh05:05
kgoetzhm. root@newmoon:~# ldapaddgroup kgoetz 117905:12
kgoetzgrep: /etc/pam_ldap.conf: No such file or directory05:12
kgoetzis pam_ldap.conf still in use? iirc i read its been retired05:12
lamontif it's being used, it should be a symlink to /etc/ldap.conf05:13
lamont_I_ have it. :0)(05:13
kgoetzreading /usr/share/doc/libpam-ldap/README.Debian is interesting05:15
lamontyeah.  that and the manpage for pam.conf were very eye opening on monday night05:16
kgoetzstupid pam05:17
lamontheh.  pam is love, man.05:18
kgoetzpolletheme pam :\05:19
kgoetzwin 3205:19
zero-9376is there a metapackage for the lamp server that you install from the server cd07:08
krautmoin08:11
_rubenmornin08:22
sorenzero-9376: No, but if you had bothered to stick around for more than 27 seconds, someone might have told you what to do..08:37
_ruben;)08:46
_rubenwell .. 6 minutes a bit longer than 27 secs .. but still :-)08:47
Burgundaviasoren: I see him being in channel for 5 minutes at least09:18
sorenBurgundavia: Potato, potato.09:20
sorenDoesn't really work in writing, does it?09:20
sorenBurgundavia: 5 minutes is still an annoyingly short time to stick around for when you've asked a question.09:20
joycetickive just installed ubuntu-server 7.10 on a laptop but its wireless pcmcia card is being recognised (i think, it shows up in iwconfig at eth2) but returns errors when trying to connect to the network (this card was working before in xubuntu 7.04)11:50
=== Pumpernickle is now known as Pumpernickel
krautjoycetick: why do you install ubuntu-server on a laptop?13:22
joycetickits a 800Mhz machine so i wanted to install fluxbox or similar on it13:23
firecrotchjoycetick: what about Xubuntu?13:24
joycetickand my isp mirrored the iso so it was easier to get than fluxbuntu (which i just found through google)13:24
joyceticki was using that before i installed ubuntu-server, might have to go back to it13:25
phaidrosany xen expert around ?14:11
avatar_!ask14:19
ubotuDon't ask to ask a question. Just ask your question :)14:19
avatar_i'm not an expert14:19
henrixor try #ubuntu-xen ;)14:20
Gargoylelibc6 is what is commonly known as glib isn't it?15:36
Gargoyle*glibc15:36
spiekeyhow can you force ubuntu to write directly onto usb stick, without caching?15:57
spiekeyis this a mount option?15:57
sorenspiekey: I don't remember if "flush" works?16:24
sorenspiekey: mount -o flush -t vfat /dev/whatever /media/whereever16:24
sorenspiekey: Otherwise, "-o sync" is what you're looking for.16:24
sorenspiekey: It'll kill your usb stick, though.16:25
sorenspiekey: They're only built to handle a certain amount of writes to them. If you mount it with sync, and you have a particularly stupid application write to it, just writing a single file to it can cause it to be written to several thousand times.16:25
=== dendrobates is now known as dendro-away
darrendhi all17:14
darrendI have a cron job in /etc/cron.hourly that fails when cron executes it ("Exec Bad Format" or similar message).  If I execute it manually, it runs fine.  Any ideas?17:15
darrendscript is at http://pastebin.com/d13dc62ab17:15
mralphabetdarrend: that looks right . . . the bad format is from syslog?17:25
darrendmralphabet: the message was being added to the email that cron was sending (which was ending up in ~/dead.letter but is now being accepted by the remote mail server and ending up in a black hole17:31
darrendlet me try to disable the mail output so I see the messages again.17:31
lamontkeescook: are you the apparmor guy?17:31
lamontNov 29 10:01:22 mix kernel: [739593.226765] audit(1196355682.459:35):  type=1503 operation="inode_permission" requested_mask="r" denied_mask="r" name="/etc/ldap/ldap.conf" pid=16512 profile="/usr/sbin/cupsd"17:32
lamonthow do I tell it that it's OK?17:32
keescooklamont: well, mathiaz and I both work on it17:32
keescookwhy is cups trying to read ldap.conf?  but anyway, sudo vi /etc/apparmor.d/*cups17:32
keescookadd:   /etc/ldap/ldap.conf  r,17:32
keescookthen sudo /etc/init.d/apparmor reload17:33
lamontand then restart cups17:33
keescooknope17:33
lamontwell,  I did the first two steps...17:33
keescookthe aa reload will just update the running process's confinement17:33
keescookyou can do   sudo aa-status   to see what aa thinks of the world17:34
keescookif you did apparmor stop/start you're SOL, and you need to restart cups17:34
lamontaalib is part of apparmor? :-)17:34
keescookthat would rule17:34
keescook"I'm pwning you in ASCII!"17:34
lamontI might have done /etc/init.d/apparmor restart17:35
lamontmind you, I'd rather see us make selinux happier17:35
keescookrestart == reload so that's okay17:35
keescooklamont: sure, we're just waiting on some upstream patches to roll out for that17:35
keescooklamont: where does aa-status report cupsd?17:36
lamont2 profiles are in enforce mode.17:36
lamont   /usr/sbin/cupsd17:36
lamont   /usr/lib/cups/backend/cups-pdf17:36
lamont1 processes are in enforce mode :17:36
lamont   /usr/sbin/cupsd (18409)17:36
darrendmralphabet: error message is.. "run-parts: failed to exec /etc/cron.hourly/00backup: Exec format error"17:36
keescook(also, you added the ldap.conf to the cupds section not the cups-pdf section of /etc/apparmor.d/*cupsd ?17:37
lamontNov 29 10:36:12 mix kernel: [741679.573259] audit(1196357772.436:39):  type=1503 operation="inode_permission" requested_mask="r" denied_mask="r" name="/etc/ldap/ldap.conf" pid=18573 profile="/usr/sbin/cupsd"17:37
lamontno.17:37
lamontabstractions/cups-client17:37
* lamont does the right file17:37
keescookah, yeah, the cups-client is for stuff trying to talk to the cups server, etc.17:38
darrendmralphabet: I think google may know the answer.. looks like I need /bin/sh and not /bin/bash17:39
lamontyeah!  helps to fix the right file.17:39
lamontthansk17:39
mralphabetdarrend: heh17:40
darrendhmm.. no - still fails17:40
darrendbrb17:41
mralphabet;(17:43
rodpodwould it be better if i used iptables to forward GRE and port 1723 to access a RRAS VPN (PPTP) server, or just setup the VPN stuff on my ubuntu server and use LDAP for authenticating...what would be the best package with ldap support for doing this?17:45
* nealmcb congratulates jdstrand on Ubuntu Membership :-)17:51
jdstrandthanks again nealmcb! :)17:52
=== gamble6x is now known as gamble|mission
AlexJTanneri have a question18:28
AlexJTanneranyone there?18:29
somerville32!ask18:30
ubotuDon't ask to ask a question. Just ask your question :)18:30
AlexJTannerwell here's my question "everytime I use apt-get install on my ubuntu servers they want me to put in the DVD, how can I get it to instead of taking the packages from the DVD to take them fromt the reprostories18:30
AlexJTannerI have SSH acess to both of them18:34
emberhow may have it source.list to get it from dvd i think18:34
rodpodnano /etc/apt/sources.list18:35
rodpodtake out the cdrom entries18:35
AlexJTannerk thanks18:35
AlexJTannerI feel a bit of a newb asking this question18:35
AlexJTannerthis is just my first time running ubuntu without gnome18:36
AlexJTanneri am working on getting both of them ready to go into my basement, and part of that is not having to run down and put a DVD in everytime I need to install something18:38
=== gamble|mission is now known as gamble6x
=== macd_ is now known as macd
ScottKlamont: I think Bug #172925 is worth you having a look at.22:43
ubotuLaunchpad bug 172925 in postfix "postfix upgrade does not add 'retry' service" [Medium,Confirmed] https://launchpad.net/bugs/17292522:43
lamontgah.22:58
lamontwill do22:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!