/srv/irclogs.ubuntu.com/2008/05/16/#ubuntu-server.txt

_ZeuZ_Hello guys, hope you received my email from the mailing list... what do you think about my little script?00:39
* _ZeuZ_ Feels ignorated...00:52
owh_ZeuZ_: You have to remember that not every body is doing Ubuntu full-time. For example I'm self-employed and I'm volunteering my time to the project because in the long term both I and my clients benefit. Others have different motivations.01:07
_ZeuZ_I know, I'm also at university, while working for TodoSoft and trying to start my own security team at savajesoft.net my style is pretty secure until now... savajesoft.net/site/index.php01:08
goukigiovani: thank you01:52
pteagueyay, i finally got rid of my grub error 17, but now i'm just getting a grub prompt02:19
_ZeuZ_pteague, why not just doing update-grub after installing it?02:31
_ZeuZ_pteague, first remove it (apt-get purge grub) then reinstall it (apt-get install grub) and then make it update and configure itself with update-grub02:31
pteaguefirst time i've been able to even get to anything from grub other than the Error 17... i can't even get to a linux terminal to run apt02:41
pteagueif you can tell me what i need to do in order to get grub to actually load the kernel i'll be happy to do whatever's needed with apt :)02:43
flotishtuhow to auto configure    dpkg-reconfigure ipmasq       .(no need to press enter or yes/no again and again) just one command. ?02:44
_ZeuZ_pteague, well, you have any working OS there that you can access?02:44
_ZeuZ_flotishtu, I really don;t trust that server, I rather do masquerading myself through iptables02:45
_ZeuZ_Though, you'll have to pass the parameters, or you can do something like assume yes, letme review what;s the glitch to make it do that02:45
flotishtu_ZeuZ_ how02:47
flotishtuok02:47
_ZeuZ_flotishu: check the mailing list, you'll see a script I made for that...02:48
pteaguenope, new install of ubuntu-server02:49
flotishtu_ZeuZ_ what list?02:49
_ZeuZ_pteague: boot from a live-cd02:49
_ZeuZ_flotishtu, read the topic and you'll find what you need to know02:50
flotishtu_ZeuZ_ ^_-02:50
_ZeuZ_You might also find this: http://bulma.net/body.phtml?nIdNoticia=1794&nIdPage=6 intresting02:51
pteaguei installed fedora 9 which actually booted & seemed to fix the detection error i was having before... reinstalled ubuntu-server again & now i'm stuck at grub... think i'll have to burn a cd for *buntu desktop02:51
_ZeuZ_pteague, come again? you are now on fedora, right?02:51
Centaur5Does apt-cacher need inetutils-inetd or can you use xinetd now?02:52
_ZeuZ_ONe does not have any relationship (exept perhas some dependencie) with the other, Centaur502:53
Centaur5_ZeuZ_: well I didn't have any inetd package installed before but apt-cacher was the only thing that broke upgrading from Gutsy to Hardy and /var/log/apt-cacher/error.log says no running inetd server so I was wondering if it mattered which one I chose.02:55
_ZeuZ_I don;t see any realtion and theoretically it shouldn;t be there any02:56
pteagueno, i was initially having problems getting anything... "GRUB loading... \ Error 17" & that was it...  guy from local lug is a fedora chump & suggested i install fedora... so i installed fedora & it started right up with no problems... but i'm trying to set up a debian based server so that doesn't get me anywhere in the long term so i deleted the partitions & reinstalled ubuntu-server & got the grub prompt02:56
Centaur5_ZeuZ_: Okay, I'll keep trying to fix it then.  Do you think it would be wise to use apt-cacher-ng now that it's in repositories?02:58
pteaguethis box used to dual-boot win/linux as it's my old desktop... only difference is it now has an extra drive in it attached to a new sata pci card02:59
pteagueok, i installed kubuntu 8.04, rebooted & ended up at a grub prompt again ;)03:43
ScottKFor Kubuntu help, try #kubuntu03:58
cyris|hows it going everyone?04:09
nealmcbhmm - it seems I'd want a version of ssh-vulnkey that runs on dapper so I can see if folks have uploaded bad keys to it - but the USN only provides post-dapper updates - anyone have a dapper version?06:28
hotmonkeyluvwhen installing ubuntu server, where is the option to install the bootloader to a different partition (or does it automatically install it to /boot no matter where that partition is?)?06:39
nealmcbLooks like dowkd.pl is the easy option most anywhere:  http://wiki.debian.org/SSLkeys#head-45e521140d6b8f2a0f96a115a5fc616c4f1baf0b06:43
randomwalkeri upgraded openssh after the recent vulnerability report, and now my authorized_keys stopped working06:45
randomwalkeri freshly copied the id_rsa.pub from the client, but still no go06:46
randomwalkerany ideas?06:46
krautmoin08:09
krautmoin08:28
RockHoundhi everyone ... is there a way that I can force an openldap 2.3.x to be installed on hardy instead of 2.4.x?09:30
nxvlRockHound: we are just on an openldap talk at FOSS Camp09:35
nxvlbut yes09:35
nxvli think you can09:35
nxvljust you need to install it by hand09:36
nxvldownloading the .deb09:36
RockHoundokay ... thank .. ran into real troubles with syncprov and syncrepl ...09:41
RockHoundso the deb of feisty should work?09:42
nxvli think09:42
RockHoundwill try my best09:42
nxvlsearch the gusty ones if there are some09:42
nxvlor just package it by yourself09:42
nxvl:D09:42
RockHoundgutsy is what i meant09:43
uvirtbotNew bug: #231006 in nagios2 (universe) "Recommend mailx or other package providing /usr/bin/mail" [Undecided,New] https://launchpad.net/bugs/23100609:45
uvirtbotNew bug: #231007 in nagios-plugins (main) "check_radius command uses wrong syntax" [Undecided,New] https://launchpad.net/bugs/23100709:51
AnRkeydoes anyone here know why M$ outlook 2k3 hangs when it opens and tries to connect to a postfix server?11:31
AnRkeyi am using dovecot11:31
ivoksso, postfix or dovecot? :)11:34
ivoksone is for sending mail, and the other for recieving11:34
AnRkeyivoks, soz for not answering, i was cruising through the forums11:46
AnRkeythis is my problem >> http://ubuntuforums.org/showthread.php?p=4971185#post497118511:47
AnRkeyOutlook 2k3 hangs when it tries to connect to dovecot-imapd11:47
ivoksso, your users are in mysql?11:48
ivoks(today is not my day; not sure why...)11:50
AnRkeymysql?11:50
ivoksyes11:50
AnRkeyno11:51
AnRkeyi am using unix accounts11:51
ivoksok11:51
AnRkeydefault install11:51
ivoksyou've setup mail_location in dovecot.conf?11:51
\shplain or login mech?11:53
sorenAnRkey: Which version of Ubuntu?11:53
AnRkey7.1011:54
AnRkeyi see now that the thread is about mysql too11:54
AnRkeyi don't think that is the prob as my install has the same issue11:54
ivokswell, i can't tell you that this combination works on at least 10 my mail servers :)11:55
AnRkeycan't or can11:55
ivoksi'm sure it's configuration problem11:55
ivokscan11:55
ivokssorry11:55
AnRkey:P11:55
AnRkeyi am soooo close to being finished too :D11:56
ivoksare you using maildir or mbox format?11:56
AnRkeymaildir11:56
ivoksok, so did you set up mail_location in dovecot?11:56
AnRkeydo you know how to increase the verbosity of the logging?11:56
AnRkeychecking11:56
ivoks#mail_debug = no11:56
ivoksand even11:56
ivoks#auth_debug = no11:56
ivoks#auth_verbose = no11:57
AnRkeyahh ok11:57
AnRkeythanks11:57
AnRkeymail_location is not set no11:57
ivoksheh11:57
AnRkeybut TB and OE both work fine11:57
ivoksmaildir:~/Maildir11:58
ivoksi guess you've setup postfix to use maildir?11:58
AnRkeyyes11:59
AnRkeyi followed this guide without all the SSL stuff https://help.ubuntu.com/community/Postfix11:59
ivoksthen fix dovecot to user maildir12:00
AnRkeyso set the mail_location to mail_location = maildir:~/Maildir12:00
ivoksoe ant thunderbird probably work, but don't show you your mails :)12:00
AnRkeythey both show and send emails12:00
ivoksoe ant? omg... time for food :D12:00
AnRkeyoe ant? << ?12:01
MyrttiI've got a question. I've got a virtual server, dapper 6.06.2 which I plan to update to hardy. the person hosting the virtual server says I've got to update to libc6-xen and remove libc6. I'd love to do the update with sudo do-release update, though. Will I run into trouble if I do the upgrade with do-release update and not the way he says it should be done, namely fiddling with the sources.list, installing the libc6-xen and removing the libc6?12:03
Myrttiand then doing aptitude safe-upgrade?12:04
AnRkeyivoks,12:04
AnRkeyTask 'Checking for new mail in subscribed folders on 192.9.201.6.' reported error (0x800CCC0F) : 'Outlook is unable to download folder (null) from the IMAP e-mail server for account 192.9.201.6. Error: The TCP/IP connection was unexpectedly terminated by the server. If you continue to receive this message, contact your server administrator or Internet service provider (ISP).'12:04
AnRkeythats what i get now12:04
ivoksMyrtti: i think that would work fine... libc6-xen provides libc612:06
MyrttiI know, but I still cringe at the idea of upgrading that way12:06
ivoksAnRkey: try subscribing to some folders trough oe12:07
Myrttimakes my skin crawl12:07
ivoksMyrtti: do do-release-upgrade, and when it is over, install libc6-xen12:07
AnRkeyivoks, ok12:07
MyrttiI managed to break several installations of Debian back in the days of pre-ubuntu-existance that way12:07
Myrttiivoks: you think that could do it too?12:08
ivoksMyrtti: just do it12:09
=== Myrtti_ is now known as Myrtti
Myrttihere it goes then.12:42
Myrtti*sigh*12:42
reya276morning13:12
reya276If users that are on a windows client connecting to ubuntu using "winscp" software for sftp/ssh will that connection be compromised due to this ssh vulnerability issue? Keep in mind I have already applied the updates to openssh and ssl13:14
normanmreya276, if the pubkeys they use are affected yes.. if not no13:15
reya276normanm: ok is there a way for me to reset those keys mainly for the windows users connecting to the server13:16
reya276because other ubuntu PC automatically let's the users know they can't connect13:17
Terrasquereya276: do they use key based auth? or password based?13:18
normanmreya276, find /home -name authorized_keys -exec ssh-vulnkey {} \;13:18
normanmif they use not key based out it is not affected anyway13:19
Terrasquenormanm: "ssh-vulnkey -a" will check all users13:20
normanmTerrasque, oh ok ;-)13:20
normanmso no need for find ;-)13:20
Terrasquecorrect :)13:20
normanmTerrasque, but find is such a nifty tool =P13:21
Terrasquetrue, true. But no need to overuse :p13:21
TerrasqueI'm sure you could have chained in grep and xargs too if you really wanted, but .. simple is good :D13:22
reya276Terrasque: well they have to put in their passwords to be able to logon to their home directories, but their is some sort of key authentication13:22
Terrasquereya276: well, "sudo ssh-vulnkey -a" will tell you all weak keys on the system13:22
Terrasqueif they're used or not, it will show them13:23
reya276thank you guys, let me try this13:24
reya276oh I got this message13:25
reya276sudo: ssh-vulnkey: command not found13:25
reya276Terrasque: that command is not working for me13:26
Terrasquethen upgrade :)13:30
Terrasqueits included in the latest upgrade13:30
reya276I though I did, I'm running fiesty 7.0413:31
Terrasquedid you do upgrade, or dist-upgrade?13:31
Terrasquethe new openssh packages pulls a new package too, so you need to use dist-upgrade13:31
reya276I did sudo apt-get update then sudo apt-get upgrade13:32
reya276yes but if I do dist-upgrade means that my OS will be update right?13:32
Terrasqueno13:33
Terrasqueits called "dist-upgrade" for historical reasons :) but basically, upgrade only updates existing packages, and will not for example download a new package. dist-upgrade will do that. Historically (and most of the times now) it was used to upgrade to a newer version with new packages (and removed old packages).13:34
Terrasqueit will show what it will do and ask for confirmation first, so you can doublecheck that nothing weird happens13:34
reya276yes I was able to13:38
rysiekhi all13:48
rysiekI am trying to set-up syslog to log remote messages (i.e. set-up a syslogd *server*)13:49
rysiekthe thing I cannot find anything on is: is there a way of telling syslog "log messages from SOME_IP to /var/log/SOME_IP.log"13:49
rysiekman syslog.conf tells me only about how to send my log messages to a remote syslogd server13:50
rysiekso does google13:50
rysiekany ideas?13:50
Myrttiivoks: busted, segfaulted13:50
ivoksdo-release-upgrade is python script13:52
ivoksit doesn't segfault :)13:52
TrioTorusinstalling ebox on 8.04: http://pastebin.com/m73a88b0a what password is being asked for here? root? ebox user?13:53
mok0TrioTorus: spooky13:56
MyrttiLALALALALALALA13:57
TrioTorusmok0: when I tried first time around, the ebox users was being added to the system and to the adm group13:57
Terrasqueivoks: I've seen python runtime segfault :D13:58
Myrttiivoks: dpkg segfaults13:58
Myrttidpkg --configure -a does a cowardly exit and runs to a nearby forest13:58
stickystyleTrioTorus: Never touched ebox, but if i had to guess by looking at the install log you posted, its asking for a pass for the SSL key file probably.13:58
stickystyleTrioTorus: since it looks like one already exists.13:59
mok0TrioTorus: try looking in the postinst script13:59
ivoksMyrtti: you should at least paste output to pastebin or something14:02
MyrttiI'm trying the magic tricks first14:02
Jeeves_http://www.prevented.net/~mark/bit/openssl-remote-vulncert14:03
MatBoyhuh ? my systems doesn't recognize updatedb anymore14:13
uvirtbotNew bug: #231003 in openssh (main) "Host key regeneration leaves ltsp out in the cold (dup-of: 230565)" [Undecided,New] https://launchpad.net/bugs/23100315:23
glycoknobhi15:27
glycoknobis it possible to disable openvpn-vulnkeys? i'm aware of the problems and new keys are on the way but i'd like to have running deamon15:27
ScottKjdstrand_: ^^^15:28
jdstrand_glycoknob: there is not currently an option to disable it no. if you were really determined, you could move openvpn-vulnkey out of the way and put a script in it's place15:29
jdstrand_s/it's/its/15:29
glycoknobworks thanks15:34
jdstrand_glycoknob: I am not recommending doing that though :)15:34
=== jjesse_ is now known as jjesse
cyris||If I take a password, hash it with ssha, and then take the same password and hash it again with ssha, will i get the same hash?16:45
denndaWhat's the easiest way to set up a fully functional mailing server on ubuntu hardy? (Which programs, for example?) On Debian Etch I use postfix and dovecot16:46
denndacyris||: yes, that's the theory. but you won't be able to reproduce the passwort from the hash16:46
cyris||dennda, right, i understand that, then hrm why are we getting a different hash value for the same password entered :S16:47
ivoksdennda: exactly the same; postfix + dovecot + postfix/dovecot for sasl16:49
ivoksthere are even docs for doing that16:49
m1rhello16:51
ivoksdennda: https://help.ubuntu.com/community/PostfixDovecotSASL16:51
cyris||dennda, lots of guides on howtoforge as well16:54
c1|freakyis there any possibility to have a directory ona linux server mounted or whatever on a windows vista machine? so i can make changes directly there (save/read) etc.?17:57
cyris||c1|freaky, check out samba18:01
c1|freakyit's a server somewhere on the internet18:01
c1|freakyno LAN18:02
cyris||c1|freaky, you may need to run a vpn then,or get some software to map a drive over ssh18:04
cyris||c1|freaky, thats assuming you have ssh access to this machine18:04
c1|freakyyes i have18:04
cyris||c1|freaky, novel also has netdrive, maps ftp sites, but thats insecure :S18:05
c1|freakyok thank you18:05
cyris||pretty dead in here today, i smell a long weekend :D18:06
Deepssamba works over the internet18:06
cyris||well, its a long weekend in canada anyways18:06
Deepsyou probably dont want to do samba over an unsecured link though, heh18:06
InsomniaCityyeah, its dead easy to do over an ssh tunnel18:07
Deepswtf are you doing in here noob?18:13
InsomniaCitywatching you ofc18:13
Deepssaucy18:13
specialKso if ssh-vulnkey says a key is unknown should I just assume that key is weak/comprimised21:21
cyris||specialK, good question, id regenerate21:31
cyris||my co-worker is about finished writing a php script that updates a users userPassword attribute in ldap, and he is interested in making this available for anyone who wants it. Is sourceforge the best place for this?21:32
ScottKThere are lots of good places to host open source software projects.  That's one.  Google Code it another.  Some people speak highly of Launchpad for the purpose.21:34
cyris||ScottK, oh right Launchpad! :D21:34
giovanispecialK: unless you have specific knowledge of where/when the key was generated, regenerate it21:34
Myrtticyris||: there are people who don't like launchpad because it's proprietary, and dislike google because it's $evil_global_corporate21:35
ScottKPersonally as an Ubuntu developer I find it highly confusing to deal with upstreams that are also on LP, but in theory it's supposed to be great.21:35
ScottKAll three of the ones I mentioned are proprietary.21:35
cyris||Myrtti, haha yeah i hear ya21:35
ScottKI don't like Launchpad also because it's hard to use.21:35
ScottKThere is also gforge.21:35
MyrttiScottK: sourceforge too?21:36
ScottKAnd other FOSS based services.21:36
ScottKYes.  What they release and what they use are very different things.21:36
Myrttihm21:36
ScottKGotta run.21:36
cyris||ScottK, thanks later21:36
Myrttinever thought of that before21:36
macdOn gutsy sshd, when a user logs out, its leaving a stale session, is anyone else experiencing this, (only started a after the second sshd update)21:57
=== klaf is now known as afk_away
vcorreiahello everyone22:16
vcorreiahas anyone tried ubuntu's ebox new integration22:16
vcorreia?22:16
cyris||vcorreia, i played with in a few weeks ago for like 30mins thats it22:17
vcorreiawhat do u make of it?22:17
cyris||vcorreia, um its alright22:17
vcorreiai've noticed that the ebox developers have already launched new  eBox 0.11.100  ubuntu specific packages22:18
vcorreiacyris, i'm testing them as we speak22:19
vcorreiacyris, thanks for your feedback22:19
cyris||vcorreia, sorry i can't provide any more feedback, i didn't use it that long22:20
cyris||vcorreia, what do you plan on using it for?22:21
vcorreiacyris, no problem :) i've used the debian implementation, but as soon as i heard they'd be porting it to ubuntu.... ahhh it was bliss :)22:22
cyris||vcorreia, so you use it on production machines?22:24
vcorreiacyris, i have used it on a semi-devel/production environment22:25
vcorreiacyris, i administer some production ubuntu servers and if i could use ebox with ubuntu, it would be perfect, harmony-wise22:27
cyris||:D22:27
vcorreiacyris, just the fact that it supports 802.1q is, on its own, excellent22:29
cyris||vcorreia, sexy22:43
vcorreiacyris, indeed22:44
=== Shkodra is now known as ShKoDrAnI

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!