/srv/irclogs.ubuntu.com/2008/05/31/#ubuntu-server.txt

zulkees: for you....anything00:03
* kees hugs zul00:06
=== mindframe_ is now known as mindframe
m_newtonIS there any RECOMENDED/Needed security measure when runing a web server??03:48
m_newtonHelp?  IS there any RECOMENDED/Needed security measure when runing a web server??03:50
m_newtonare the ppl in this fourm dead?03:57
=== thomas__ is now known as The-Kernel
Jeeves_Why is it, that Microsoft is stepping away from the GUI tools and into the shell-tools, and Ubuntu is going to focus on writing GUI tools for the server07:46
Jeeves_?07:47
Jeeves_As described here: https://wiki.ubuntu.com/ServerTeam/Bug007:47
Kamping_Kaisermy main query (use of gui tools aside) is, why arnt existing ones being adapted instead of new ones written07:53
Jeeves_Kamping_Kaiser: Because everyone can dot it better :P07:53
Kamping_KaiserJeeves_, hehe :P07:54
* Kamping_Kaiser imagines booting ubu-serv - "hi, i'm the ubuntu logo, do you need help configuring a server?"07:55
Jeeves_My gui tool is better than yours! (Even though, they all suck)07:55
Jeeves_ARe you sure you want to add this user?07:55
Jeeves_Really?07:55
Jeeves_Really really?07:55
Kamping_Kaiserlols07:55
Kamping_Kaiser"Offer a scalable, robust, standards-compliant mail server. The answer will frequently be “does it talk natively to unmodified Outlook clients, and unmodified Exchange servers?”" <-arnt these two items directly at odds?07:55
Jeeves_Kamping_Kaiser: Indeed, they are07:56
Kamping_KaiserJeeves_, oh good, i was doubting my sanity for a tick there07:57
Jeeves_I don't want to sound negative or something, but I somewhat hope this bug doesn't get fixed.07:57
Kamping_KaiserJeeves_, i'm still not sure what the bug /is/07:58
Jeeves_The first part of the bug is great, ditch M$ in the server environment. But the way to get there IMHO is defenitly not what is described in there.07:58
Kamping_Kaisernod07:58
Jeeves_Kamping_Kaiser: That M$ sells too many ISA servers07:58
Jeeves_And Exchange servers07:58
Jeeves_And that Ubuntu needs to be changed so people start to use that07:59
Kamping_Kaiserhm. then i'm with you - agree with the bug, not sure i like the chosen path07:59
Jeeves_Instead, you should start by fixing evolution so that it doesn't grow to 2gb memory footprint when using calendars07:59
Jeeves_Fix something that enables you to do normal calendaring (as exchange does)08:00
Jeeves_Than, you are able to get far with the current tools08:00
Jeeves_The problem isn't the configuration of the features08:01
Jeeves_The problem is the inexcistence and/or brokenness of the features08:01
Kamping_Kaisernow apples calnedar server is in debian (and probably ubuntu) that job will probably have just got much easier08:01
* Kamping_Kaiser is in the process of setting itt up at work atm08:01
Jeeves_ah let me know how that goed08:02
Jeeves_s/d/s08:02
Kamping_Kaisercan do.08:02
Kamping_Kaiseronly got as far as installing the packages ("backported") before getting another thing to work on, but will do08:03
shtoomhi can I use uck to build customized ubuntu servers ?08:17
scuffiohi10:34
scuffiothere is anybody here  ?10:34
scuffiosorry10:34
scuffiois there...10:34
scuffio:)10:35
n6rejyeah10:35
scuffioHi10:36
scuffioI'd like to be a memeber of this team10:36
scuffiowhat i have to do  ?10:37
n6rejscuffio: https://wiki.ubuntu.com/ServerTeam/GettingInvolved10:37
n6rejscuffio: i'm not a dev so I can't tell you but that will10:37
scuffio ok mate10:38
scuffiothk10:38
n6rejnp10:38
scuffioI've a problem with launchpad.11:45
scuffiobasically, I don't recive the email11:46
scuffioin order to complete the registration11:46
scuffiosomeone can help me   ?11:46
scuffiohttps://launchpad.net/~ubuntu-server/+join/+login11:46
=== jords__ is now known as jords
ErosionIs OpenSSL installed by default on ubuntu-server?13:07
jpdsemgent: yeah13:25
jpdserr, he left, sorry emgent13:26
Terrasqueheh. Found an old bug.. http://ubuntuforums.org/archive/index.php/t-583958.html - that one is apparantly not fixed yet.13:49
Terrasqueafter upgrading from feisty to gutsy I encountered it, on my root partition, no less. Leaving me with the very basic init system to fix things.. Is there a text editor in that system, btw? I couldnt find any, and had to resort to cat, sed, cp and mv13:51
will01if i have a vpn server thats connected to the switch, and the switch is connected to a router, which is plugged into the modem, will i be able to use that vpn anywhere?16:33
lamontwill01: I'm having trouble parsing your question...16:38
InsomniaCitywill01: that depends on how your router is set up16:38
lamontby "anywhere" do you mean "in even one location" or "everywhere"16:38
lamontand in any case, the answer is "you'll be able to use that from anywhere that has IP connectivity (can reach) the vpn server, which, in turn, depends on the config of all of those devices, as well as possibly your ISP (some ISPs hand out RFC1918 addrs to their customers, which is really just sad...))16:40
lamontwill01: your question basically boils down to "if I plug something into my switch, can I talk to it from anywhere?"...  and the answer winds up being "it depends"16:41
will01ok16:42
lamontI have run vpn endpoints with a topology of: internet -> modem -> router -> switch -> vpn many times.. my current config is slightly different in immaterial ways.16:45
lamontbrb16:47
will01i got it figured out, forgot to configure the dmz doh16:58
=== astro76_ is now known as astro76
=== RoAk is now known as RoAkSoAx
methodsanyone home ?20:54
methodsrubygems keeps saying it can't find sqlite3.h even though i have the dev package installed21:01
methodsi had to get it from universe21:02
RainCTHi21:07
RainCTIs it possible to let SSH listen on port 80 or will this kill penguins? :P21:07
stickystyleRainCT: You can have ssh listen on any port you want.21:08
stickystyleproviding that it doesn't have something already running on it.21:09
RainCTAh. So if there's already Apache on port 80 SSH can't run there, or?21:09
stickystyleYes, if apache is already running on port 80 you cannot run sshd there also.21:09
stickystyleI'm thinking your trying to get past a proxy...am I right?21:10
RainCTnot sure what it is, but yes :P21:11
RainCTI'm building a server as baccalaureate research project and the PC is at school21:11
RainCTand I'm waiting since weeks for the technicians from the education department who give the internet to open the ports (until now they've only opened 80)21:12
stickystyleAh.21:12
stickystyleSo if you already have apache running on port 80, and port 80 is the only port that you have open on the server, i guess your kind of stuck for ssh access.21:17
stickystylethere are little php apps out there that will give you a kind of shell through your web browser, but they are ridiculously insecure and i could never recomend running on.21:18
RainCTright. well, thanks :)21:18
JanCthere is a python one too21:20
JanCand AFAIK it is secure enough if you use decent authentication/encryption   ;)21:20
lamontRainCT: you could do abusive things with openvpn and iptables DNAT - but that's a very long discussion that I don't have time for21:25
RainCTJanC: well, I guess I'll wait for a while more before falling back to such stuff21:25
lamont(if the source port is XXXX then DNAT to the openvpn instance, otherwise, let it through to port 8021:25
lamontor I suppose you could do that with SSH as well21:26
mfournier 21:27
lamontssh -D XXXX -p 80 server  - and then the server has iptables -t nat -A PREROUTING -p tcp --sport XXXX --dport 80 -j DNAT --to-destination :2221:28
lamontthe downside to that is that every now and then, some poor web user will get an ssh connection instead of an http connection...21:29
RainCTlamont: what would the XXXX there be?21:30
lamontsome number, probably >= 1024, definitely <= 6553521:30
RainCTah, I see. the local port to use, right?21:31
lamontnote also that circumventing an organization's firewall usually has some administrative penalties attached to it....21:31
lamontyes21:31
RainCTgreat, thanks21:32
lamontof course, if the client goes through any sort of NAT firewalling or a proxy, then that won't do anything for you, since the port is likely to be different then21:33
UbuntuJulhi everyone - Linux newbie here, having some troubles getting PHP to "work" - anybody feel like spreading some love?22:30
emgentheya22:49
RainCTbye22:50
firehead_eomhey guys.23:04
firehead_eomi have a question about setting up a mail server using a SQL database to hold virtual domains and users.23:06
firehead_eomso far, i've followed the default 'tasksel' to install a standard mail server, but alas, the howtos i've found end with me needing to use phpmyadmin to create users and no easy way to connect via imap.23:09
firehead_eomany help would be greatly appreciated.23:09
nealmcbfirehead_eom: what do you mean, no easy way to connect via imap?  is the dovecot server installed?23:11
* nealmcb notes that you may find more folks around to help during the week23:12
firehead_eomnealmcb: i installed dovecot, but i believe my settings are such that when i try to connect using an email client, the connection is actively refused, leading me to believe it's most likely a mysql problem23:12
nealmcbis the port open?23:13
nealmcbwhat exactly do you see?23:13
firehead_eomtrue.. i'm in no hurry to set this up quickly, but i wanted to see if help could be found.23:13
sergevnfirehead_eom: try using syscp23:14
firehead_eomi'm sad to say i won't be able to answer that question. I realised that i'd muddled the settings a bit too much and proceeded to apt-get --purge remove all non-core packages from the server.23:15
firehead_eomi have to admit, i'm kind of new to setting up a mail server with a sql backend.23:17
nealmcbsergevn: doesn't look like syscp is packaged for ubuntu - do you know why not?23:18
sergevnnealmcb: syscp is an complete ISP package, it contains smtp(postfix, dovecot etc) ,http(apache) and ftp(proftpd)23:20
sergevnnealmcb: all based on mysql23:20
firehead_eomoh.. interesting.23:21
sergevnyes, and it's opensource ofcourse :)23:21
nealmcbsergevn: still seems like it would be nice to have the isp-specific things in a package, and use the standard tasksel for all those things23:22
nealmcbotherwise os upgrades can be more difficult23:22
nealmcbis there an up-to-date howto on using syscp in ubuntu?23:23
sergevnnealmcb: yes, just use the debian-etch howto on their website23:23
sergevnnealmcb: i currently have it running on gutsy.23:23
* nealmcb wonders how the config is different....23:23
sergevnnealmcb: not that different, it also works on freebsd23:24
sergevnit's application dependand, not OS dependand :)23:24
sergevnmaybe the peeps on #syscp could give you a better explanation ;)23:24
sergevn;) = :)23:25
sergevnI have it running on my hosting servers and works perfect.23:25
sergevnSafe by design :)23:26
nealmcbwell, offhand I'd recommend using standard packages - easier security updates, better ubuntu support etc23:26
sergevnnealmcb: yeah, that's the catch, with syscp you are using packages of your distro. sysscp is only a set of phpscripts :)23:26
nealmcbcatch?23:27
sergevncatch/trick/advantage23:27
nealmcbif syscp uses standard packages for most stuff, then again I wonder why it isn't packaged already itself23:27
sergevnjust copy the php files in your webroot23:28
firehead_eomwouldn't that mean, however, that if the packages themselves are changed, then syscp may not be able to recognise that change and break?23:28
firehead_eomthen again, it's worth a look/try.23:29
sergevnfirehead_eom: could be with an dist-upgrade, but not likely23:29
firehead_eomthanks sergevn :)23:29
firehead_eomand thanks to you too nealmcb.23:29
sergevnsyscp has very good documentation and irc support :)23:29
sergevnfirehead_eom: no prob, you can always contact me if you have problems with installing it23:29
sergevnnealmcb: you too23:30
sergevnto make it clear, you just install the postfix-mysql package allong with your normal postfix install.23:30
sergevnin the configuration file you put the SQL query's that is documented on their website and in the syscp panel itself while installing23:31
* danshearer is away: Zzzz23:43
samuelCan anyone help me with getting the image GD installed for php?23:46
nealmcb!ask | samuel23:47
nealmcbsamuel: Guide to asking questions on IRC: http://www.sabi.co.uk/Notes/linuxHelpAsk.html  | Be patient.  Don't ask to ask, just ask.23:48
samuelOh, sorry.23:48
nealmcb:)23:48
samuelAnyways, I found the solution to my problem. =/ I was just searching for the wrong terms.23:49
nealmcbsamuel: yeah - I often find that just crafting a good question is all I need to figure out the answer :)23:50
seisen_i tried settting up raid on a server but there is a previous raid setup on there that can't be deleted because it keeps popping up that its still busy, how can I get rid of it.23:51
samuelnealmcb: It's hard as hell to google for what you're trying to do, when you've used windows all your life. The excessive use of command line probably discuouraged people from properly documenting things, or something.23:51
=== seisen_ is now known as seisen
nealmcbseisen: I don't know, but more specifics (versions, error messages, etc like in that guide above) will make it more likely that someone else can hep23:55
nealmcbhelp23:55

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!