/srv/irclogs.ubuntu.com/2008/07/03/#ubuntu-server.txt

uvirtbotNew bug: #245031 in munin (universe) "apt_all doesn't grok Ubuntu" [Undecided,New] https://launchpad.net/bugs/24503100:11
=== macd_ is now known as macd
=== yell0w_ is now known as yell0w
axisys!raid04:20
ubottuTips and tricks for RAID and LVM can be found on https://help.ubuntu.com/community/RaidConfigurationHowto and http://www.tldp.org/HOWTO/LVM-HOWTO - For software RAID, see https://help.ubuntu.com/community/FakeRaidHowto04:20
axisys^ is there anything simpler that these?04:20
uvirtbotaxisys: Error: "is" is not a valid command.04:20
axisyss/that/than/04:21
axisysfirst link has nothing04:21
axisyssecond one is not ubuntu specific04:21
axisysthird one is really lot of work04:21
axisysin solaris SVM is super simple04:21
axisysSVM aka disk suite aka soft raid app04:22
axisyswish ZFS is already in linux .. life would be sooo easy04:23
=== lamont` is now known as lamont
nxvlsommer: i have never love you like today05:24
nxvlubuntu server guide is awesome05:24
axisyshow do I get notified when there is a pkg update available?05:28
nxvlas in new debian version or as in new upstream version?05:28
nxvlor as in new ubuntu version for updating your server?05:28
axisysnxvl: ubuntu05:29
axisysnxvl: ubuntu server05:29
axisysnxvl: or pkgs05:29
nxvli use scripts for that05:29
nxvla cron running apt-get update05:29
nxvland stuff05:29
nxvlsommer_: i have never love you like today05:30
nxvlubuntu server guide is awesome05:30
axisysnxvl: how would u know when reboot is necessary? in workstation it shows the icon05:30
nxvlmm05:30
hadsIt's not nessecary :)05:30
nxvli think there is an update-manager interface for CL05:31
hadsIf you do a kernel update then you will need to reboot to get the new kernel, that's about it.05:31
axisysin other words there is no way to get notified.. even with log or email?05:32
nxvlaxisys: you can write a shell script and add it to cron05:32
nxvlBUT05:32
nxvli remember there was an easy one05:32
hadsWell it's your responsibility to notice what packages you install/upgrade.05:32
nxvljust don't remember what it was05:32
nxvlaxisys: please add it to brainstorm05:33
nxvlaxisys: brainstorm.ubuntu.com05:33
hadsThere's apticron/cron-apt etc. which will notify you when there are updates available.05:33
axisyshads: how about when I need to reboot ? there is no notification for that?05:34
hadsAs I said, if you do a kernel update then you will need to reboot to get the new kernel.05:34
nxvlaxisys: i don't have a solutions for it in mind, but, you can send an e-mail to the list http://lists.ubuntu.com/mailman/listinfo/ubuntu-server and add it to brainstorm http://brainstorm.ubuntu.com/05:35
nxvlneed to run05:36
nxvlaxisys: please follow my suggestion, i find your idea relly usefull and viable05:36
nxvls/viable/feasible/g05:36
nxvlread you later05:36
axisysnxvl: http://brainstorm.ubuntu.com/idea/10640/05:44
axisysjust added it05:44
psychohi guys07:55
psychoneed some help with ubuntu 8.04 server edition working as a router !07:55
psychoi used to have a 2.4.34 kernel router system and everything was working fine07:56
psychowhen i upgraded to ubuntu 8.04 2.6.24 kernel everything works fine except for creating new hotmail passport live account07:57
psychodoes anyone have an idea where to start looking ?07:57
xtdo you have a pppoe connection?07:57
psychono its not pppoe and the mtu size is 1500 as i always had it07:58
xtalright, I thought it might be mss size07:58
xtyou can always packet sniff07:58
psychomss or mtu !?08:00
xton ppp you "need" -A FORWARD -m comment  -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS  --clamp-mss-to-pmtu --comment "MSS CLAMP"08:00
sorenHow would mtu size affect ability to create a hotmail account?08:00
xtsoren: I've seen all sorts of weird stuff going on without that on a pppoe connection, for example certain web pages not working08:01
psychothis is weird as on 2.4 kernel i have the same firewall rules and same scheme as of 2.6.24 kernel router08:01
psycho2.4 works like magic 2.6 doesn't08:02
sorenxt: Sounds "special".08:03
xtsoren, I despise ppp on broadband connections, hehe. Luckily I dont have one myself as I have fibre at home08:03
psychoalthough everything working great on 2.6 except for this feature08:03
psychoi have E1 connection08:04
=== malt is now known as wrecky
wreckyyo whats probably the best free web system control panel, besides webmin08:57
wreckyor a control panel that works game servers to like CS 1.6 or CS:S08:57
Kamping_Kaiserebox recomended by ubuntu over webmin08:57
jiphexCan someone please lend a hand with configuring exim4, it seems it's not reading /etc/mailname for some reason, and hence I can't send any mail locally or remotely from the box because exim (correctly) fails to resolve "etc_mailname" or "ETC_MAILNAME" as mail hosts http://pastie.org/22696310:04
Kevin_openworldHello all10:35
Kevin_openworldCan some one help me with Php myadmin.10:36
Kevin_openworldon ubutnu10:36
xthttp://www.catb.org/~esr/faqs/smart-questions.html10:39
Kevin_openworldWell this is what going on. I install phpmyadmin and it not found when i go to http://192.168.2.6/phpmyadmin. I installed it for Apache 2 the site is Apache/2.2.810:57
henoHello good people of #ubuntu-server!11:00
henoIs there anyone here who has VMware-ESX set up and can help us wrap up the last JeOS test case for Hardy.1?11:01
henosee http://iso.qa.ubuntu.com/qatracker/test/171111:01
henonijaba, soren, dendrobates- ^11:01
Kevin_openworldHeno11:02
Kevin_openworldI think all the people are asleep11:02
Kevin_openworldBecuse i asked for help and got no reply11:02
henook thanks Kevin_openworld11:03
heno2 or those 3 should be in European timezones though :)11:03
Kevin_openworldI am in EST 6:05 AM11:06
Koonheno: nijaba is on a trip. soren should be back soon, though11:06
henook, great11:07
sorenwazzup?11:09
sorenKevin_openworld: Did you restart (or reload) apache?11:10
sorenheno: No ESX access for me.11:10
sorenheno: nijaba's your man.11:10
henosoren: ok, he's on travels though?11:11
sorensoren: Yes, on his way to South France. He left really early, though, so he might be there now, but now that you mention it, it's probably not going to be easy for him to do any testing from there. He's attending a meeting or something.11:12
* heno just found #vmare on freenode with 160 people in it ...11:14
henowill ask nicely there :)11:14
sorenHeh.. Good plan :)11:16
Kevin_openworldI restarted Apache Soren11:32
Kevin_openworldI just got back and seen your text.11:32
krautmoin11:32
sorenKevin_openworld: And no luck?11:36
sorenOh, hang on.11:36
sorenTry this:11:36
Kevin_openworldNope11:36
sorenhttp://192.168.2.6/phpmyadmin/11:37
soren(note the trailing slash)11:37
Kevin_openworldsame page i been going to11:37
Kevin_openworldnot working11:37
sorenThat's not what you said, though.11:37
Kevin_openworldI know11:37
Kevin_openworldboth of them wont work11:37
sorenWhat happens?11:37
sorenWhat do you see instead?11:37
Kevin_openworldThe requested URL /phpmyadmin/ was not found on this server.11:37
sorenHave you changed apache's config at all? Using virtualhosts, perhasp?11:38
sorenperhaps, even.11:38
Kevin_openworldI think so11:39
Kevin_openworldI am using Webmin11:39
Kevin_openworldalso11:39
sorengah..11:39
sorenThen you're on your own, dude :)11:39
Kevin_openworldAny one else?11:40
Kevin_openworldwait11:40
Kevin_openworldDo they make a Windows PRogram?11:40
Kevin_openworldto edit mysql and things?11:40
sorenprobably.11:42
Kevin_openworldI will google it.11:42
Kevin_openworldI think i seen one before11:42
Kevin_openworldWait11:43
Kevin_openworldCan i download phpmyadmin as a php files?11:43
Kevin_openworldBecuse i looked in the var/www11:43
Kevin_openworldand their no phpmyadmin file?11:44
sorenThe phpmyadmin package configures apache to look for the files in /usr/share/phpmyadmin.11:50
sorenIIRC.11:50
sorenKevin_openworld: ^11:50
Kevin_openworldok11:51
soren...so that's where they are.11:52
Kevin_openworldfond them11:52
Kevin_openworldDo i drag and drop them all?11:52
Kevin_openworldin11:52
Kevin_openworldvar/www/phpadmin?11:53
Kevin_openworldOr copy?11:53
sorenI don't do drag and drop.11:53
sorenI recommend a symlink.11:53
sorenOr configuring apache to look in the right place.11:53
Kevin_openworld?11:53
Kevin_openworldoo11:53
Kevin_openworldHow?11:53
Kevin_openworldCan i just copy?11:53
sorenwebmin => You're on your own. I have no idea.11:53
Kevin_openworldk11:54
Kevin_openworldWell i found them so i think i know what to do11:54
Kevin_openworldThanks a lot.11:54
sorenYou probably need to sacrifice a lamb somewhere in the process.11:54
hadsheh11:54
* soren -> food11:54
Kevin_openworldit worked11:56
Kevin_openworldTHanks11:56
=== emgent_ is now known as emgent
griffonanybody here who has experience with the ldap overlay module: smbk5pwd?12:26
griffoni compiled it for the current openldap server 2.4 from ubuntu 8.04 but it won't work. If i change pam_password to exop and i'll change my password using passwd it stalls after making the EXOP call (according the logfile output of openldap)12:28
zulmorning13:05
emgenthey people rapache 0.4 is out with apache modules support13:07
emgentIt`s in rapache-devel PPA13:07
=== jjesse_ is now known as jjesse
sommer_hey all14:08
aiwatchHi every one14:17
=== sommer_ is now known as sommer
zulsoren: apt_all.in patched for ubuntu14:25
sorenzul: *blink*14:25
sorenReally14:26
soren?14:26
zulsoren: yep14:26
sorenAwesome, dude!14:26
zulfor intrepid14:26
* soren hugs zul14:26
zulperl is fun14:26
sorenI think it's SRU worthy.14:26
* soren realises he just increased the pain by 1000%14:27
zulhttp://pastebin.com/d2dc26fdf14:27
zulnot very painful14:28
sorenI mean doing SRU's, but I guess you're used to that, too :)14:29
sorenDid you test the patch?14:29
zuli wrote a test program that basically does that14:29
sorenBecause ISTR that munin isn't too fond of dashes.14:29
zulmind testing that out for intrepid once it gets build14:30
ScottKsoren: Do you post stuff to the Ubuntu Server blog or is that just mathiaz?14:32
sorenScottK: I do.14:33
sorenEr..14:33
sorenSorry. No. I don't.14:33
ScottKYou could, but you don't?14:33
bill_is there a way to set up resource rate limits on things like I/O?14:33
sorenDon't think I could, no. Not at this point.14:33
sorenI think it's intended to be open to the entire server team at some point, but I'm not sure.14:34
ScottKOK.  I think the mail I just sent to the server list would be a good post.  I'll wait for him.14:34
ScottKThanks.14:34
sorennp :)14:34
=== freaky[t] is now known as c1|freaky
ScottKsommer: When you have some time, I'd like to discuss documenting whitelisting based on DKIM/SPF results in the server guide (this is generally the docs piece of the amavisd/dkim spec.14:36
Tophatis there anything for linux that can act like a windows domain controller?  such as Active Directory or have it setup as a Central Authorization Point?14:41
blue-frogldap or samba-ldap14:43
blue-frogfor windows domain samba-ldap14:44
sommerScottK: now's an okay time... is there a wiki page on the procedure?14:48
ScottKsommer: No.  It's in the package docs.14:48
ScottKCan you grab the current Intrepid source package?14:49
sommerah, that should be good enough... sure14:49
arvind_khadri in the server edition the postfix can be configured when we want to correct??14:49
arvind_khadrior has it to be done while installation only14:49
ScottKarvind_khadri: Yes.  Unless you select the mail server task it's not installed by default.14:50
ScottKYou can configure it at install time or later.14:50
henoanyone fancy setting up a vmware-esx demo install? we still have an outstanding JeOS test case14:50
henohttp://www.ntpro.nl/blog/archives/325-The-ultimate-ESX-3.5-white-box.html14:50
henothat's the most help I could get in #vmware14:50
ScottKheno: It would be very handy if Canonical had a virtualization engineer or some such to help out with things like that.14:50
sommerScottK: source acquired... that was the amavid-new source right?14:50
ScottKYes.14:51
sommercool, what am I looking for?14:51
ScottKLook in the file RELEASE_NOTES14:51
henoScottK: sure, but we are a community project too ;)14:52
zulScottK: soren is the virtualization engineer14:52
sommergotcha... doesn't seem to complicated after a quick glance14:52
arvind_khadriScottK, postfix is the POP right??14:52
ScottKzul: ;-)14:52
ScottKarvind_khadri: No.  Postfix is MTA.  You want Dovecot for POP.14:52
arvind_khadriScottK, oh ok14:53
ScottKsommer: For someone who is knowlegable, it's not so hard, but I think we need to cover how to add domains to the whitelist and what it does.14:54
sommerScottK: sure, I'll add it to the mail filtering section14:54
ScottKsommer: I'd also like to document using SPF results to whitelist in Spamasssasin, but I need to do some reasearch on that.14:54
ScottKsommer: Great.14:54
ScottKsommer: Updating the server guide is part of the spec, please let me know if you need help and/or when it's done.14:55
ScottKsommer: It is really amazingly wonderful to get an answer like, "sure, I'll add it to the mail filtering section".  Thanks.14:56
sommerScottK: sure will do, it may be later this month... still working on Samba, but that's maybe this close to being ready for review |--------|14:56
sommerScottK: np14:56
arvind_khadriScottK, how to add route the entry should look like default 192.168.1.115:01
ScottKarvind_khadri: I don't understand what problem you are trying to solve.15:02
arvind_khadriScottK, i want to add a route as of now15:02
ScottKarvind_khadri: I don't have enough context to answer that question.15:03
arvind_khadriScottK, hmm thanks ..15:03
sorenzul: I'm afraid your patch doesn't work.15:16
sorenzul: a) there's a missing comma in your @releases.15:16
sorenzul: b) Since we in Ubuntu are dealing with pockets rather than suites, "-t $release" won't cut it.15:17
sorenMy suggestion about using "-s" and looking for the suite doesn't quite cut it either, though.15:17
soren...since that doesn't do much to detect held packages.15:18
sorenI've got a patch here that does nothing but return the package count, but doesn't set extinfo.15:18
soren...which is a bit of a shame.15:18
sorenMy perl-fu isn't very strong :(15:19
zulsoren: damn it15:25
sorenzul: When my ssh keys get updated (submitted a few minutes ago), I'll put my new patch on people.u.c.15:26
zulsoren: okie dokie15:27
* delcoyote hi15:37
spiekeyHi15:40
spiekeysoren: you there? :)15:40
sorenOui.15:42
spiekeyjust a sec :)15:45
spiekeyyey! it works!!!!15:54
spiekeythanks soren :)15:54
sorenHahha!15:55
sorenspiekey: Any time, dude. :)15:55
* soren is about to let out a sigh of relief15:57
sorenI think I've finally found a structure for the new VMBuilder that I'm happy with.15:57
spiekeyyes!16:03
spiekeyyey!16:03
spiekey:))16:03
spiekey:-/-<16:04
spiekey:-\-<16:04
spiekey:-|-<16:04
jdstrandMatBoy: you know, we talked about nscd wrt libnss-ldap and libpam-ldap the other day. I didn't realize nscd was in universe until today, so I moved it to Suggests in libnss-ldap16:06
jdstrandmathiaz: ^16:06
jdstrandsoren: so you refactored ubuntu-vm-builder correct? this was in part to create libraries that ubuntu devs can use I assume. I recently refactored ufw, and wonder it there is anything we can share16:09
jdstrandsoren: the one from ufw that may be worthwhile is util.py (http://bazaar.launchpad.net/~jdstrand/ufw/trunk/annotate/160?file_id=util.py-20080701191142-03fec67gtdcg30cn-6)16:11
jdstrandsoren: that there are still some ufw specific bits in there (I think just references to UFWError)16:12
jdstrandsoren: we'd need to clean up the 'debugging' variable, but between those two, I think itmight be useful16:13
jdstrands/between/if we address/16:14
=== pteague is now known as pteague_work
sorenjdstrand: There are a few things we might be able to share.16:17
* soren . o O { import uncomplicated }16:18
sorenI like the rollback mechanism, I came up with, but it probably won't be of much use to you.16:18
jdstrandsoren: oh, did you rename it (uvb)? I didn't know it was official16:21
sorenIt's not.16:21
soren:)16:21
jdstrandsoren: well, I doubt the network sutff would be that interesting to you either, but maybe another uncomplicated app might like all this stuff :)16:21
sorenI imagine uncomplicated live migration will.16:22
sorenOr uncomplicated directory server.16:22
* ScottK notes the absence of Server Team from https://wiki.ubuntu.com/TeamReports/June2008 and is glad he's not required to fill it out.16:22
* jdstrand nods16:22
* soren glances at mathiaz 16:23
ScottKmathiaz: Did you see my latest message to the Server ML on DKIM testing?  I think it would be good as a blog post.16:23
mathiazScottK: not yet - I'm getting there though.16:24
ScottKOK.16:25
ScottKPlease keep that in mind when you get to it.16:25
jdstrandsoren: so I guess we need to create a python-ulib package, then put it in LP and collaborate. this is not likely something I can do super quickly, but I could add my ufw stuff to it easily enough. This will need to get a MIR though, since ufw will depend on it16:29
melteris there a recommended mail server for ubuntu?16:32
sorenpostfix16:32
sorenjdstrand: Yeah. It's not super important right now, though, but it's something we could look into when it's slightly more than 3-4 functions.16:33
melterhow is it decided which options dpkg-reconfigure will set for postfix?16:34
lamontmelter: postfix's dpkg-reconfigure behavior is generally to take what is in main.cf as the defaults, and then (depending on the debhelper severity setting) either ask or not ask to change them.  If the option is not one of the ones that is in debhelper, then dpkg-reconfigure won't change it16:36
lamontif it is, and you change the answer, then postfix will change it in main.cf for you16:37
melteri'm guess i'm wondering why, for example, "myhostname" is set explicitly to the hostname that exists at the time of configuration, when the default it for postfix to automatically use the system's current hostname when it starts16:37
lamontbecause the return from gethostname(3) was totally and completely broken at one point16:37
melteris it fixed now?16:37
ilowehi guys, I'm having a problem with a preseeded install... my installer just hangs at some point16:37
lamontdunno.16:37
jdstrandsoren: that's cool. I just wanted to broach the subject as dendrobates mentioned doing something like that at some point16:38
melterthe problem is that when my hostname changes, i have to reconfigure postfix16:38
sorenjdstrand: Certainly.16:38
jdstrandsoren: actually, I count 11 in util.py ;)16:38
lamontmelter: the purpose of the postinst in postfix is to get most people a working mailer config out of the box.  from there, it is assumed that clueful admins will probably tweak main.cf and such, and never run dpkg-reconfigure16:38
sorenjdstrand: Sure, but at this point there's like 3 or so that we'd be sharing :)16:38
* jdstrand nods16:38
lamontmelter: you're welcome to comment out the entry in main.cf....16:38
lamontassuming that works for you16:39
jdstrandsoren: I expect you to use all 11, *now*!16:39
iloweanybody done preseeded installs before?16:39
lamontnote also that postfix kind of believes that the host tends to have a long-lived name that exists in the DNS16:39
mathiazilowe: you may wanna try in #ubuntu-installer and specify where it hangs in the process16:40
ilowemathiaz: thanks much16:40
=== [miles] is now known as [diablo]
ScottKlamont: Now it's just sort of broken.16:45
lamontScottK: sounds about how I remembered it...16:46
* lamont finds himself continually amazed that people run MTAs on their laptops16:46
ScottKI use Postfix on my laptop to relay to one of my real MTAs so reportbug and bts work.16:49
axisysi just upgraded the linux-restricted-modules .. do I need to reboot?16:49
axisyswish there is some mail alert or syslog alert to let me know that.. already requested that in brainstorm16:51
lamontScottK: ditto although as much for testing as for any real MTA usage - and configured to relay through the home machine, via an openvpn route --> trusted16:52
lamontI guess I should really teach my home machine about allowing sasl-authed users to send mail.. :0-(16:52
ScottKaxisys: Generally if it's a kernel update you do and if it's not you don't.  Reading the security advisories is always recommended and they will tell you if a reboot is required.16:52
ScottKlamont: I do it via SASL.16:52
axisysScottK: so it is not like workstation where it just notifies u16:52
ScottKNo.  Where would it notify you?  Most servers aren't constantly logged into.16:53
axisysScottK: not expecting a gui (since it is a server and not workstation) alert .. but a syslog ot email alert seems needed16:53
axisysScottK: r u kidding? syslog or email are not always on16:54
axisys?16:54
ScottKThere was some discussion at the last UDS about increased automation of security updates, but I don't recall the details.16:54
axisysScottK: ok.. thnx16:55
nealmcbScottK: Cool message about your DKIM work - thanks!  Sounds like a great blog post16:56
BlinnyWhat would cause /etc/cron.daily/apt to take 4 hours to run every night?16:56
ScottKnealmcb: Thanks.16:57
nealmcbScottK: I was following DKIM early on during some of the discussions about mail list issues  - is there a preferred way to keep good dkim signatures when going thru mailman?  e.g. not mangling the subject line, what to do about appending ml signatures etc?17:18
* nealmcb should just google again and read the spec :)17:19
sorenBlinny: DNS failure?17:22
sorenBlinny: 3 minutes multiplied by number of nameservers multiplied by number of requests apt-get update would have made.17:22
ScottKnealmcb: I think the current mailman has some kind of no-mangle setting, but I'm not a mailman admin.17:31
ScottKnealmcb: Any change to the body or a signed header field is going to cause a failure.17:31
nealmcbScottK: wasn't there a way to say "only validate the first x bytes of the body" so that signatures could be ignored?  or was that dropped?17:32
ScottKnealmcb: It's in the spec, but no one uses it.17:32
nealmcbhopefully enough mail agents will guide the user to mail-list-related headers and folks won't need to rely on sigs to explain about unsubscribing, but that will take time...17:34
ScottKMailman also has an option to strip pre-existing signatures.17:35
ScottKIn theory this shouldn't be needed since broken sig is supposed to be treated just like no signature, but in the real world it's not.17:35
nealmcboh - dkim sigs - yeah - that is complicated also.  who is doing what with broken sigs?17:36
ScottKWith DK (and so I presume the same will happen with DKIM) I had experience with people bouncing mail to the From address due to a broken sig.17:40
ScottKThere's no standardized reason to do it, but people grasp at straws.17:41
michalskihello, i've had a bug report open for a couple of months now and it seems to have been pushed aside (https://bugs.edge.launchpad.net/ubuntu/+source/ebox-ntp/+bug/222620)18:13
uvirtbotLaunchpad bug 222620 in ebox-ntp "package ebox-ntp None failed to install/upgrade: subprocess post-removal script returned error exit status 1" [Undecided,New]18:13
michalskiI was wondering if it would be appropriate to assign it to the ubuntu-server team18:13
michalskior if it even is a bug18:14
mathiazmichalski: assign no - subscribe yes18:15
michalskiwilco18:15
mathiazmichalski: if you can provide steps to reproduce it it will help18:15
michalskithats just the thing, its so random, I go to synaptics and search up ebox, I see that ebox-ntp has residual config that I just want to get rid of, so I mark it as completly remove18:17
michalskibut it just comes back with that error18:17
zulmathiaz: we should really really get the new apache from debian18:36
mathiazzul: yes - I'm working on merging openldap 2.4.10 now18:38
zulmathiaz: cool18:38
zulwant me to take care of apache then?18:38
nealmcbmichalski: what was the command line?  did you use --purge?18:40
michalskilet me verify neal18:41
nealmcbahh - synaptics - unusual for a server....18:41
michalskihehe :)18:41
michalskisudo apt-get remove ebox-ntp --purge =====says its not installed so not removed18:42
JanCmichalski: did you also test the newer upstream ebox stuff for Ubuntu?18:42
michalskithe config is still there18:42
michalskiJanC: no, im just trying to remove ebox18:42
nealmcbmichalski: that log in the bug has lots of xorg stuff also - seems like a more complicated story....18:43
JanCif it's fixed there, that would maybe help to find the issue by looking at the differences...18:44
zulmathiaz: please include these patches in the opendldap merge as well http://people.ubuntu.com/~chucks18:44
mathiazzul: the ones in http://people.ubuntu.com/~chucks/ldap/ ?18:45
zulyep18:46
zulsorry :)18:46
michalskiim having similar problems with googleearth-4.3 schooltool-2008 virtualbox-ose-modules-2.6.2218:47
michalskiuninstalled, yet config still there18:47
zulthe first one was the patch discussed yesterday and the second one fixes the asseriton error  described by that launchpad bug18:47
ScottKlamont: Both the hppa buildd's for Intrepid seem to need a kick.18:56
Blinnysoren: Good guess, but I don't think so - I run a caching nameserver that is a master for local (192.168.0.0/16) addresses18:57
lamontinfinity: ^^18:58
Blinnysoren: I can aptitude update & safe-upgrade quick-as-lightnin18:58
uvirtbotNew bug: #245265 in openssh (main) "package openssh-client None [modified: /var/lib/dpkg/info/openssh-client.list] failed to install/upgrade: unable to make backup link of `./usr/bin/ssh' before installing new version" [Undecided,New] https://launchpad.net/bugs/24526519:00
infinityScottK: Again?  Hrmph.19:03
nealmcbmichalski: it is curious that it doesn't have more info in the error message - you might try just removing that package again to get a cleaner error report and just post that rather than such a big log.  and look for more debugging output or see what the script is actually running and run that yourself - I just don't know offhand how to do that19:05
michalski--->reinstalling ebox-ntp, and others19:07
michalskiOutput while reinstalling:19:10
michalskiErrors were encountered while processing:19:10
michalski ebox19:10
michalski ebox-objects19:10
michalski ebox-network19:10
michalski ebox-services19:10
michalski ebox-firewall19:10
michalski ebox-ntp19:10
michalskiE: Sub-process /usr/bin/dpkg returned an error code (1)19:10
michalskihold on i'll pastebin it this goes way back19:11
michalskihttp://pastebin.com/d3955479319:12
nealmcbhmm - why did you reinstall?  seems like it would make it harder to debug the uninstall19:13
michalskireinstall could recreate some dependencies that it might have needed to uninstall?19:15
michalskiits giving me the same errors while removing again19:17
michalskioh and just to note the reason I have synaptic and a GUI installed is because this is my laptop, my server has no GUI. I always test out new apps before putting them on my server19:20
zulmathiaz: actually apache can just be synced again19:31
=== jjesse_ is now known as jjesse
uvirtbotNew bug: #245276 in apache2 (main) "Please sync apache apache-2.2.9-3 from debian unstable" [Undecided,New] https://launchpad.net/bugs/24527619:42
=== GreeneMile_ is now known as GreeneMile
jdstrandzul: did you/are you planning to apply http://www.openldap.org/devel/cvsweb.cgi/libraries/liblber/io.c.diff?r1=1.120&r219:53
jdstrand=1.121&hideattic=1&sortbydate=0 ?19:53
jdstrandzul: it's the openldap DoS19:53
zuljdstrand: for intrepid?19:54
jdstrandzul: yeah19:54
zuljdstrand: mathiaz was doing the merge right now19:54
jdstrandzul, mathiaz: the above commit is apparently bad and been reverted upstream19:55
zuljdstrand: good thing we didnt include it then :)19:55
jdstrandzul, mathiaz: http://www.openldap.org/devel/cvsweb.cgi/libraries/liblber/io.c (rev 1.122)19:55
zulyeah I didnt touch that patch I would have wanted feedback first19:57
jdstrandok-- it sounds like 1.122 is ok19:57
jdstrandI don't know though, I haven't actually tested anything-- just passing along what I've heard ;)19:58
zul:)19:58
michalskimust go cya19:58
mathiazjdstrand: are you doing a security update for hardy ?20:06
AnRkeyi am remotely ssh'ed in to a box that I need to conf. eth1 and eth2 both have the exact same network config, why I don't know. I need to know which interface my connection is using. Is there a way to see this? I have tried tracepath already and I can't see any interface info. Man tracepath is not much help either.20:06
mathiazjdstrand: I'm refering to the openldap cvs commit you've mentionned above20:06
nealmcbmichalski: thanks - it would help if you can add those updates to the bug, and try asking on #ebox20:07
nealmcbAnRkey: what does route -n say?20:08
BlinnyAnRkey: tcpdump? Or push a file to it and watch Rx/Tx grow20:08
AnRkeybrb20:09
AnRkeyBlinny, i like your idea and I think it will help me ID cards in the future :D20:11
AnRkeynealmcb, here is the pastebin link >> http://paste.ubuntu.com/24783/20:14
AnRkeynealmcb, i am connected via the 196 ip20:15
jdstrandmathiaz: not today-- I just cam across that on oss-security20:18
nealmcbAnRkey: yeah - Blinny has a good approach.  odd situation20:18
AnRkeynealmcb, yeah Blinny's approach worked with some reading20:19
* Blinny flexes20:19
AnRkeyi did this for eth1 and eth220:19
AnRkeysudo tcpdump -c 20 -i eth120:19
jdstrandmathiaz: zul mentioned the DoS to me, so I wanted to make sure the previous/bad patch wasn't used20:19
nealmcbBlinny: lol20:19
AnRkeyBlinny, you should have been more convincing :P20:20
BlinnyBah!20:20
AnRkeyI learned three nice tips today20:20
AnRkeyi so love ubuntu20:20
AnRkeymy life is sooooo easy now20:20
AnRkeyi am working on a box 1500km away and I have never met the owner or the contractor that I am sub contracting to :P20:21
mathiazjdstrand: allright - I'm not sure I'll include it today though20:22
mathiazjdstrand: FYI, I'm about to upload 2.4.10 with make tests enabled \o/20:22
mathiazjdstrand: now it takes around 2 hours to build openldap20:23
HomesickAhey, anyone installed pvpgn on ubuntu before?20:23
zulmathiaz: ergh...all the tests pass or are some still disabled?20:24
AnRkeyI will have to give Blinney credit for this when I post to my blog about it :P20:24
AnRkeyi have so many uses for this20:24
jdstrandmathiaz: re make test> \o/, re 2 hours> icky20:24
mathiazzul: good question - I don't know - debian enabled the test in 2.4.10-120:28
mathiazjdstrand: I've added support for the nocheck debuild option20:29
mathiazjdstrand: so that you can build the package without running the tests20:29
jdstrandmathiaz: that's cool20:29
ScottKI'd appreciate it if someone could give me a tutorial on how tasksel works.  As an example, the phrase dovecot appears nowhere at all in the package, but both pop and imap are in the mail-server task.20:30
mathiazScottK: the list available tasks is computed from the seeds20:31
ScottKAh.20:31
ScottKSo I need to look there too.20:31
ScottKOK.20:31
mathiazScottK: in order to add a new task, we have to add it to the seeds and then rebuild tasksel20:31
ScottKRight.20:31
ScottKLet me tell you what I was thinking ...20:31
ScottKThe server flavor spec isn't happening for Intrepid.20:32
ScottKSo we do the best we can with tasksel.20:32
ScottKWhat if instead of one mail server task we had two:20:32
mathiazScottK: http://bazaar.launchpad.net/~ubuntu-core-dev/ubuntu-seeds/ubuntu.intrepid/annotate/1295?file_id=mailserver-20070919110458-uemtbuz83qwix5rc-1 - this is where pop and imap are being pulled in20:33
ScottK1. mail-server-delivery which would be ~ the current mail-server task.20:33
ScottK2.  mail-server-filtering which would not pull in the delivery agent, but would have postfix, amavisd-new, spamassassin, and clamav.20:34
mathiazScottK: hm - I think it would clutter the install a little bit20:35
ScottKThe admin installing would still have to configure stuff, but there's 3 good use cases.20:35
mathiazScottK: what about using meta-packages instead ?20:35
ScottKCan't do it during install then.20:35
ScottKmail-server-delivery would be good for an internal MDA, mail-server-filtering would be good for a border relay, and mail-server-filtering + mail-server-delivery would be good for a single level architecture.20:36
zulmathiaz: got a changelog somehwere?20:36
mathiazScottK: right - I think that these are 3 valid use cases. However I wonder if all 3 of them should be available at install time20:37
zulim curious20:37
mathiazzul: you can probably look up the changes in debian svn repository20:37
zulmathiaz: point taken20:38
ScottKIf the goal is to make things more useful essentially out of the box, then I think yes.  If not, you may as well do away with the mail-server task entirely and switch to metapackages.20:38
mathiazScottK: right - I'm still not convinced that tasksel and the installer is the right place to do that20:39
ScottKmathiaz: Fundamentally I agree that tasksel is not sufficiently scalable for our needs.  Unfortunately we don't have a great plan B that we are doing.20:40
mathiazScottK: providing meta-packages for the first two scenarios and a tasksel for the third seems good to me20:40
nealmcbit brings up the question of how to deal with lots more tasks in tasksel (or flavors) at some point, as we move more towards appliances and lots of options20:40
nealmcbwhich we've talked about before20:40
ScottKYep20:40
mathiaznealmcb: exactly - I think we all agree on that20:40
ScottKSo far we have one solution that is technically and policy doable, but it's not approved.20:41
ScottKmathiaz: I'm going to get extremely frustrated if the answer is dendrobates doesn't approve flavors and you don't approve more tasksel.20:42
nealmcbwhat does "approved" imply here - that the team agrees that it is the right way to go? that it would make it into main? or that development is funded?20:43
ScottKApproved means at the very least he marked approved on the spec.20:43
ScottKFunded would be awesome, but it's far too disruptive a concept to put in the archive without an approved spec.20:44
mathiazScottK: the reason I'm raise concerns about more tasks to tasksel is because of clutter20:44
ScottKmathiaz: I understand the concern.20:44
mathiazScottK: I wouldn't want to have a list of 20 things a newbie can install20:45
ScottKI think the solution to the concern is a different way, but we have to suck up the clutter in the meantime or we stop progressing.20:45
nealmcbsure, but I can imagine various interpretations of that, and it isn't clear to me - I guess the flavors spec would be part of main by definition, so you mean more or less "we'd take it if it were implemented"?20:45
mathiazScottK: to go back to your specific proposal, IMO mail-server-filtering and mail-server-delivery are very specific tasks20:45
ScottKThat's true.20:46
ScottKMy first thought had been mail-server with just Postfix and then those two for add-ons.20:46
mathiazScottK: someone that can make the difference between the two already has a good knwoledge about the system (ie senior sysadmin)20:46
ScottKSo maybe we need better names.20:47
mathiazScottK: these people are not looking at tasksel - you could point them to a meta-package20:47
ScottKSo why do we have any tasksel?20:47
mathiazScottK: IMO it's junior sysadmin that are using the choices in tasksel to install general purpose systems20:47
ScottKWe have tasksel for SSH that installs one package.20:47
ScottKThat's using a cannon to ring a doorbell..20:48
mathiazScottK: correct - that's because a lot of people are doing this at install time.20:48
ScottKIf the mail server task has no spam filtering (as now) it's only useful for internal delivery without a lot of adding.20:49
ScottKSo what you have now is a config that only serves a very narrow market.20:50
mathiazScottK: correct - now that we plan to have spamassassin in main, we can add it to the mail server task20:50
ScottKOTOH, all in one, with the spam filtering only caters to the SOHO market.20:50
ScottKYou don't have to be very big before wanting a two tier architecture.20:50
mathiazScottK: correct - and that's the market/end user tasksel targets20:51
ScottKBy supporting two tier, you get into the more mid-size range where people are more likely to buy support contracts.20:51
mathiazScottK: that's true - once you moved to a two tier archicture, we could assume that the end user is more knwoledgeable20:51
ScottKBut Canonical gets the money for that, so whatever.20:51
mathiazScottK: I'm all in favor to provide also a way to support a two tier architecture20:52
mathiazScottK: which would be your mail-server-delivery and mail-server-filtering proposal20:52
ScottKYes.20:52
mathiazScottK: that's why I'd suggest to have meta-packages for the mail-server-delivery and mail-server-filtering (because we can assume that the end users knows about meta-packages)20:53
ScottKAnd then selecting both gives you single tier architecture.20:53
mathiazScottK: and use the mail-server task to cater for the single tier architecture20:53
ScottKThen I REALLY think we need to remove the mail-server task.20:54
ScottKIt will really confuse people to do it at install if you want one type of install and do it later if you want another.20:54
ScottKNot Ubuntu at all.20:54
AnRkeyhow can i make ubuntu redetect and assign all network interfaces again?20:54
ScottKAnRkey: Presumabley sudo sh /etc/init.d/networking restart would do.20:55
AnRkeyScottK, eth0 is not being picked up20:55
mathiazScottK: correct - but we run into some usability issues with tasksel then20:55
AnRkeyScottK, it works with another ubuntu install on another drive20:56
ScottKmathiaz: Yes.  There is no single perfect answer.20:56
ScottKmathiaz: I can see either tasksel or meta packages, but not both.20:56
mathiazScottK: that's why I suggest to provide meta-packages for -filtering and -delivery and then provide a mail-server task that pulls in both meta-packages20:57
ScottKmathiaz: What we really need in tasksel is server-basic and server-full.20:57
ScottKmathiaz: Which leaves the confusion about doing it at install or post install depending on what you want.20:57
ScottKI think that's very bad.20:57
mathiazScottK: hm - I would view that from the target end user perspective20:58
mathiazScottK: junior sysadmin/non-techis -> tasksel - advanced sysadmin -> apt-get install meta-package20:58
ScottKI don't think it'll go like that.20:59
ScottKI think even on the advanced system the junior guy will do the work, just that a senior admin will have told him what to do.20:59
ScottKI think it's much better to be able to say in the server guide one way to do it.21:00
mathiazScottK: true21:00
ScottKmathiaz: Handle it however you want, but this resistance is honestly really affecting my motivation level.21:00
AnRkeyScottK, is there a way to get ubuntu to redetect the cards and start from scratch? Reloading the network cards is not picking up the card21:01
ph8AnRkey:  It's not being detected as eth1 or eth2 by accident or anything is it?21:05
ph8what's lspci say?21:05
mathiazScottK: I see your point - I'd ask cjwatson what he thinks about it - he's one of the tasksel author and part of the installer team.21:05
mathiazScottK: He may have another idea on how to tackle this problem.21:06
ScottKmathiaz: In the tasksel man page I did see some hints about hiding some tasks by default.  It might be extensible to revealing subtasks if a primary is selected.21:07
ScottKmathiaz: Thanks for looking into it.21:07
=== w0ihw0gy is now known as mindframe
mathiazScottK: yes - that's another thought I had in this discussion - there are more tasks defined than the one you see in the server install21:10
AnRkeyph8, no21:10
mathiazScottK: so may be we can add new tasks, but hide the ones we don't want to be available at install time21:10
AnRkeyph8, hmm21:10
AnRkeybrb21:10
mathiazScottK: the other interesting part is that tasksel can be called on the command line21:11
ScottKIt'd be even cooler to be able to show subtasks at install time once a primary task was selected.21:11
ScottKUnfortunately my Perl is non-existant, so I've got no code even potentially offer.21:11
mathiazScottK: right - I think we discussed that with cjwatson during the last UDS and there are some issue with the UI IIRC21:11
mathiazScottK: and the way d-i works21:12
AnRkeyph8, ScottK, sorry for being a tard. I have just realised that the config for that interface has been commented out by a "special" person21:12
ScottK;-)21:12
ScottKThere's always a reason.21:12
AnRkeyph8, i have had cards that have been detected as eth1, 2 and 3 before too so I checked that like 3 times21:12
AnRkeythanks though21:12
AnRkeyScottK, ph8, is there a way to get the card redetected as eth0 if it's somehow moved to say eth1, 2 or 3? (just for interest sake)21:14
ph8yes21:15
ph8/etc/udev/rules.d21:15
ph8something*persistent_rules21:15
ph8it's got persistent_rules in the filename somewhere21:16
ph8might be Z70*21:16
ScottKIIRC restarting networking (as I suggested earlier) should do it if there is an appropriate config in /etc/network/interfaces21:16
ph8it designates eth0/1/2/3 based on the card's mac address AnRkey21:16
AnRkeywhere is that config stored?21:16
AnRkeycommon, it must be somewhere... I WILL FIND IT :P21:17
ScottKAnRkey: /etc/network/interfaces21:17
AnRkeyScottK, then how does eth0 become eth1, 2 or 3 on my boxes?21:17
ScottKLooks like you find it in udev/rules.d/70-persistent-net.rules21:19
android6011im looking to add a wap proxy to my server, is there something i can install to do this or do you have any ideas?21:34
ScottKmathiaz: To support your discussions with cjwatson, here is what I would suggest http://paste.ubuntu.com/24804/21:54
SquarkHello there!22:38
SquarkGot some questions about Webmin.22:38
SquarkIs there anyone willing to help me, please?22:38
FreeSoftspanish?22:38
SquarkNo.22:38
ropetinSquark: Everyone is willing to help, if you ask the question!22:39
SquarkOkey, true. Almost forgot about the question part. :)22:39
FreeSoftspanish?22:39
FreeSoftnever22:39
SquarkSo, I've set up Webmin backup module..22:39
Squarkto send me an email everytime a backup is made to a remote host.22:40
SquarkThe server with Webmin installed does not have any MTA server installed.22:40
SquarkSo I've set up mta-relaying with SSMTP.22:41
SquarkBut still, Webmin doesnt send me email reports.22:42
SquarkReally don't know what to do.22:42
jpds!webmin | Squark, have you seen this:22:42
ubottuSquark, have you seen this:: webmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration files, and is likely to cause unexpected issues with your system. See !ebox instead.22:42
SquarkHuh.22:42
SquarkNo, havent seen it.22:43
SquarkBut the .deb package can be downloaded on the offical Webmin page.22:43
jpds!ebox | Squark22:44
ubottuSquark: ebox is a web-based GUI interface for administering a server. It is designed to work with Ubuntu/Debian style configuration management. See https://help.ubuntu.com/community/eBox22:44
Squarkokej, gonna check it out.22:45
lukehasnonameI haven't used ebox22:45
lukehasnonameI just remember liking Webmin a lot22:45
SquarkMe also.22:45
SquarkNice administration tool.22:46
Squarki can't believe it is not supported on debian and debian like distributions.22:46
lukehasnonameDon't quote me on this (I hear I give bad advice) but it has to do with how the two programs handle config files22:47
lukehasnonameI BELIEVE ebox has its own config files that won't mess with the system's22:48
ScottKSquark: It used to be, but it was removed.  ebox is supposed to be more reliable, but I've used neither.22:48
SquarkWebmin has been around for quite some time. Never heard about ebox, but will check what it offers.22:51
ScottKmathiaz: Since I've gotten no uptake on my mail about please test amavisd-new stuff, I'd really appreciate that in a blog post.22:51
lukehasnonameSquark: People seem to like ebox, so give it a shot, I say.22:53
Squarkthe eBox version released with Ubuntu 7.10 (Gutsy Gibbon) has several bugs that severely limit it's usefulness23:00
SquarkIm somehow sceptical about this thingy. :)23:00
SquarkAre there anymore alternatives to Webmin?23:01
lukehasnonameNetdirector?23:04
lukehasnonameBut I tried installing it unsuccessfully23:04
lukehasnonamebtw 7.10 was 8 months ago23:04
lukehasnonameif you're running 8.04 I doubt those same problems are present. If you have 7.10, you could check the backports, or install the package from ebox's site.23:05
Squarkyeah, but this project is still very young and doesn't have all the features Webmin does.23:05
lukehasnonamethen use webmin23:08
lukehasnonamefrom the site23:08
lukehasnonameI don't know what to tell you. Netdirector might be too much or not the right fit, ebox is the preferred tool, and webmin is still available23:09
lukehasnonameI'm out, ttyl23:09
Squarklukehasnoname: thanks for your answers.23:12
CaptObviousI have a weird situation23:27
CaptObviousI've basically figured out I'm pretty much screwed23:27
CaptObviousbut I was just wondering if any of you guys could come up with a creative solution23:27
CaptObviousI have a box running ubuntu server that I have recently edited the fstab on23:27
CaptObviousI added an invalid argument by accident and rebooted23:28
CaptObviousas such, it's mounting / as ro on boot23:28
CaptObviouswell, more like the remount to rw is failing23:28
CaptObviousthe only access I have to the box is via ssh but for some reason it won't authenticate via sudo or su with a ro root filesystem23:29
CaptObviousif I could get a root shell I could fix it, I just don't know how to get it to authenticate su or sudo while the root partition is ro23:29
CaptObviousany ideas?23:29
SquarkWithout physical access to the computer you cant do much, i think.23:33
CaptObviouswell, it's sat under my desk23:34
CaptObviousbut the only keyboard I have prevents the machine from booting when connected23:34
CaptObviousI don't think the BIOS likes the USB hub in the keyboard23:34
CaptObviousand I don't have any optical drives for it23:34
CaptObviousI pretty much need a new keyboard don't I?23:34
SquarkHum, I think so.23:35
CaptObviouswish I had another machine I could hook the drive up to and edit the fstab in there23:35
CaptObviousbut my only other machine is a laptop23:36
CaptObviousthat's a bit of a bad design isn't it?  not letting sudo authenticate if the root filesystem is read-only?23:36
SquarkIf I'm correct Ubuntu with read only set on root partition can't fully boot. So you are left in a bash like console in the middle of boot process.23:41
SquarkWithout keyboard you are pretty much screwed, as you already realized.23:43
CaptObviousit boots finer23:52
CaptObviousfine*23:52
CaptObviousjust has a ro root filesystem23:52
CaptObviousI can't log in locally, but I can log in via ssh23:52

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!