/srv/irclogs.ubuntu.com/2008/07/20/#ubuntu-server.txt

godsynPlease help. Ubuntu 2.6.24-19-server. System clock is running fast, and ntpd is setting it back many times a day.  Example : "Jul 19 15:58:00 synserv ntpd[5564]: time reset -141.725880 s". This is causing other time sensitive daemons to commit suicide. How would I find out why the system clock is fast, and ultimately resolve the issue?00:51
godsynPlease help. Ubuntu 2.6.24-19-server. System clock is running fast, and ntpd is setting it back many times a day.  Example : "Jul 19 15:58:00 synserv ntpd[5564]: time reset -141.725880 s". This is causing other time sensitive daemons to commit suicide. How would I find out why the system clock is fast, and ultimately resolve the issue?01:33
=== nealmcb1 is now known as nealmcb
nealmcbgodsyn: ntpd would never do that.  ntpdate would - a separate but related package01:40
godsynremoving ntpdate wants me to remove ubuntu minimal :/01:41
nealmcbgodsyn: one guess is that you have a bad clock in your list of servers, so look at how it is configured.  ntpq -p should tell you more01:41
nealmcbdon't remove it - fix it01:41
nealmcbbut fyi ubuntu-minimal is not itself a big deal if you ever do really want to remove something that depends on i01:42
nealmcbit01:42
nealmcbit is a metapackage01:42
godsynwhat is an ideal offset for an ntp server?01:43
godsynwell, I assume ideal would be 0, what is tolerable?01:44
nealmcbit should get below 30, 0.5 is nice01:44
nealmcbmilliseconds01:44
godsyn-5.009   0.774 for #1. still, doesn't account for the 141 second change.01:45
nealmcbis there one that is way off?01:45
nealmcbwhich server is it?01:46
godsynthat is the most. -ntp2.your.org   216.218.254.202  2 u   42   64  377   45.960   -5.009   2.65701:46
godsynbut it just changed 15 mins ago... Jul 19 20:32:44 synserv ntpd[6800]: time reset -38.871876 s01:47
godsynso it'll get worse over the next few hours.01:47
nealmcbperhaps something else is setting the time01:48
godsynif so, it fails to mention in messages or daemon.log, and does it whenever it pelases.01:49
nealmcbgodsyn: very odd....01:53
nealmcbpaste the other lines of the ntpq -p output (should only be one or two)01:54
nealmcbbrb01:54
godsynit is a bit, but seeing as there aren't many active the spam shouldn't be too much. sec.01:57
godsyn     remote           refid      st t when poll reach   delay   offset  jitter01:57
godsyn==============================================================================01:57
godsyn-ntp2.your.org   216.218.254.202  2 u    6   64  377   44.885   -4.632   1.51701:57
godsyn+wsip-98-172-32- 68.0.14.76       2 u   25   64  377   80.182    1.876   2.83801:57
godsyn-mirror          128.118.25.3     3 u   16   64  377   39.499    2.942   0.93501:57
godsyn+puttynuts.com   18.145.0.30      2 u   15   64  377   47.327   -1.202   0.91801:57
godsyn*europium.canoni 193.79.237.14    2 u   33   64  377  120.256   -0.650   0.84701:57
godsynserver 0.us.pool.ntp.org; server 1.us.pool.ntp.org; server 2.us.pool.ntp.org; server 3.us.pool.ntp.org; server ntp.ubuntu.com (from ntpd, enter replaced with ";" to reduce line feed spam))01:59
godsyn*ntp.conf01:59
nealmcbgodsyn: so that looks great - they all agree within a couple ms - but what is ntpdate using as a reference?02:05
* nealmcb forgets how ubuntu configures that - looks in init.d02:05
nealmcbwhat is in /etc/init.d/ntpdate?02:06
godsyn40402:06
nealmcbhmm - I guessing that ntp has changed how it works since I last looked...02:07
godsyn /etc/default/ntpdate == "NTPDATE_USE_NTP_CONF=yes; NTPSERVERS="ntp.ubuntu.com"; NTPOPTIONS="";02:08
nealmcbany log info in /var/log/ntp or the like?02:08
godsynnothing conserning ntpdate. just ntp saying that it is changing the time.02:08
nealmcbhas this just happened twice, or for a while?02:08
godsyna while..02:08
godsyndovecot (kills itself if time changes for more than 5 secs) tipped me off about a ?week? or 2 ago.02:09
godsyntoday, i finially decided to research it.02:09
nealmcbwhat is mirror?02:09
kajeI've learned how to use ufw to configure my firewall. How do I set it up so that my rules will be applied when the system reboots? I think it resets to the default when it reboots.02:09
godsynI'd assume the 3rd ntp server. I'll remove it and see if it goes away.02:10
godsynwell, that was dumb.. I restarted ntpd to apply the changes.. turns out the ntp servers listed above point to wherever the hell they want. ntpq -p now returns :02:12
godsyn clock1.redhat.c .CDMA.           1 u    3   64    1   63.321   -6.123   0.00102:12
godsyn ntp2.your.org   216.218.254.202  2 u    2   64    1   57.787    3.215   0.00102:12
godsyn skywagon.kjsl.c 69.36.224.15     2 u    1   64    1   75.025    2.625   0.00102:12
godsyn europium.canoni 193.79.237.14    2 u    -   64    1  132.476    6.020   0.00102:12
nealmcbyeah - the pool effect02:12
nealmcbsorry - that's the best I can do right now - gotta run....02:12
godsynstill nothing over 7, but you can see, it is slowly getting worse..02:12
godsynthanks for the assistance!02:13
nealmcb:)02:13
godsynkaje, how are you making your changes?02:14
kajeufw allow ssh02:14
kajefor example02:15
godsynsee /etc/ufw/*02:15
godsynie :  /etc/ufw/before.rules02:15
kajewhat do I put in there? ufw allow ssh?02:16
QooleHi there, can anyone suggest a company to buy a PXE bootable thin client from (the mini-pc variety, preferably VESA mountable)?02:17
Qoolefor example: http://www.norhtec.com/products/mcsr/index.html02:17
godsynoh.. kaje :02:18
godsynufw allow ssh enable (enable / diable to enable / diable on boot)02:18
serafiniTrying to mount an nfs share from a hardy box with -t nfs4 is giving me the error of "Operation not permitted". Mounting it with -t nfs works fine. Could anyone point me towards why ?02:20
kajeoh, it does save it between boots... nevermind. Thanks for the help02:22
godsynsef : i'm assuming that is being ran with root priviledges, right?02:25
godsyncan I get the full error?02:25
kajeI'm trying to use the web interface to configure my cups server, but when I go to 192.168.1.5:631, it gives me a 403 Forbidden error... Any thoughts?02:36
godsynkaje : yep, sec.02:43
godsynsee /etc/cups/cupsd.conf02:44
godsynmuch like htaccess02:44
godsynbetter?02:45
godsynguess so02:51
linosis there a command to type to get a listing of computers on network??  thanks inadvance03:48
hadsarp?03:49
=== hessml|away is now known as hessml|away|away
nealmcblinos: even for a local network there is not a foolproof one.03:54
nealmcblinos: tell us more about what you're trying to do03:55
linosnealmcb, I was told smbtree would work.  does that sound correct?03:55
hadslinos: tell us more about what you're trying to do03:56
nealmcbthat might tell you something about computers that are connected to a samba server, but that is a different thing03:56
nealmcbbut it is sort of like network neighborhood.  but other computers could be lurking03:58
linoshads, well, I have a network here a home and I would like to rdesktop a windows pc from my ubuntu edgy system. so I was looking for an easy command to type to obtain the ip addresses on my network03:58
nealmcbavahi is another option - zero configuration networking03:58
nealmcbI use "service-discovery-applet" to find cooperative local machines03:59
nealmcbbut I think windows machines are less likely than macs or linux machines to be configured with avahi03:59
hadsDNS?03:59
linosyes04:00
linosnealmcb, so there really is no direct command to type to obtain all ip addresses on my local lan04:01
nealmcblinos: correct - networking is a very diverse sort of thing04:02
linosok04:02
linosthanks for the tip04:02
nealmcbbut again it depends on what you want.  you can easily configure04:02
nealmcbmultiple machines to cooperate with avahi to make them all easy to find04:03
nealmcbbut you can't count on using that to find hackers on your wifi channel etc04:03
nealmcbavahi uses mdns, a form of dns04:04
=== hessml|away is now known as hessml|away|away
Kludge^WalesUKanyone lurking? =)06:11
exothello, I have installed a vpn server, and clients are successfully join the network, but they can only see the vpn server machine, the other two servers aren't accessible, any ideas ?09:28
=== freaky[t] is now known as fReAkY[t]
Deepsip forwarding isn't enabled10:21
Deepsand/or your routers dont know that the vpn subnet goes via the vpn server10:21
Deepsso the other 2 servers get a ping from an ip that they have no specific routing for, forward it to their default router, which doesn't know that it's supposed to to the vpn server and sends it on elsewhere / bins it10:21
Deepsexot: ^^10:30
exotDeeps, hi hi10:34
exotDeeps, u mean I should install a gateway server and vpn installed on , right ?10:34
Deepsexot: no, simply that your router needs to know the route for the vpn client's ip range10:35
exothmm10:35
Deepsif your network is on 192.168.0.0/24 and your vpn server on 192.168.0.200 and your vpn clients on 10.200.1.0/2410:35
Deepsyou'd need to tell your router that 10.200.1.0/24 is routed via 192.168.0.20010:35
Deepseasiest way is to configure that as a static route10:36
exotgreat10:36
exotI got it10:36
exotbut regarding to the dns server10:36
exotmy www server make some redirections10:36
exotso, I should tell the dns somehow to resolve special ip's for vpn clients10:37
Deepsif you need resolution based on query ip, BIND has a feature called 'views' that would probably serve you10:38
exotI see .. I will look for it10:38
exotthank you really Deeps10:38
=== fReAkY[t] is now known as freaky[t]
sigmai installed apache, how do i release the server to the world so that people can see it from my external ip address?12:38
Deepswww.portforward.com ?12:39
Deepsby default apache binds to 0.0.0.0:8012:39
Deepsso anyone can acccess it as long as your router/firewall permits12:39
Deepsdefault firewall rules tends to be very relaxed too afaik12:39
sigmamy external ip is http://196.38.218.25, it connects but times out, whats the problem there?12:51
Deepsyour router or firewall isnt allowing access (didn't i say that already?)12:54
Cahananyone else had the problem of networking seemingly just failing for no explainable reason? iwconfig thinks it's still connected, but the machine cannot be reached via ping, ssh or samba share, and needs to have it's network connection reset in order to function again. (Feisty)13:13
danilomhi, i need to setup a mail server (dovecot, postix, squirrelmail) and a proxy server (squid), and to login ina centralized openldap... so there is some web interface to manage openldap in ubuntu server?16:14
nealmcb!ebox | danilom16:36
ubottudanilom: ebox is a web-based GUI interface for administering a server. It is designed to work with Ubuntu/Debian style configuration management. See https://help.ubuntu.com/community/eBox16:36
nealmcb!ldap16:37
ubottuLDAP is the Lightweight Directory Access Protocol. For more information and installation instructions, see https://help.ubuntu.com/community/OpenLDAPServer16:37
danilomnealmcb, so it dont use phpldapadmin16:37
nealmcbdanilom: "it"?16:38
danilomnealmcb, i mean ubuntu server16:38
nealmcbubuntu server offers several gui admin tools for ldap, as noted in the help link above16:39
danilomnealmcb, thanks16:39
* nealmcb add eBox to https://help.ubuntu.com/community/OpenLDAPServer16:41
nealmcbdanilom: my pleasure16:41
nealmcbdanilom: and let us know how it works out for you and what you prefer!16:41
danilomnealmcb, well im asking first, i need to install postfix, dovecot, squirrelmail, squid, samba.. and authenticate it to a openldap.. so im listening for some suggestion...16:43
nealmcbrun tasksel to get most of the mail stuff nicely integrated, then add stuff like squirrelmail etc16:44
nealmcbbut I don't know the details of getting mail using ldap - the experts like scottk may be more active during the week16:44
danilomnealmcb, the thing is, after i setup all the servers with openldap... some people remain, and need to manage accounts.. but more of these people really dont know what a console is...16:44
nealmcb...getting mail *servers configured* using ldap16:45
danilomso im looking for a nice interface...16:45
ScottKnealmcb: I've never had to do ldap myself.  From what I've read, it's not so hard from a Postfix perspective once you get the ldap stuff set up.16:59
=== jjesse_ is now known as jjesse
ScottKThere are quite a number of how-tos for using ldap to get valid recipients out of an Exhange box, so I suspect they'd be useful as well for a more general case.17:00
nealmcbScottK: ok.  I was wondering about using ldap for stuff like squirrelmail and dovecot also17:00
nealmcbdanilom: ^17:00
* ScottK is not the guy to ask about ldap.17:00
Kludge^WalesUKheyyyyyyyyyy guys \o/17:00
Kludge^WalesUKScottK <317:00
* ScottK has a project in mind that'll need it, but I haven't actually gotten to that stage yet.17:00
ScottKHeya Kludge^WalesUK17:00
danilomok im reading nealmcb17:01
Kludge^WalesUKhowdy dudey! \o/ i has my server now. It's all up and running and was almost painless apart from a few things virtualization didn't account for :D17:01
nealmcbso who are our best ldap+mail gurus?  I wonder if ispconfig does anything like that17:01
Kludge^WalesUKnext lil thing is trying to get a file web-server set up (done that bit) just want it to be authenticated =/17:01
ScottKnealmcb: ispconfig does a LOT of things, so it's probably not the best way to figure it out.17:03
ScottKnealmcb: Did sommer put anything in the server guide about it?17:03
Kludge^WalesUKare you at all familiar with apache, ScottK?17:04
ScottKKludge^WalesUK: No.  I'm more of a mail server guy than a web server guy.17:04
nealmcbScottK: about ldap and mail?  I don't know.  But he's highlighted now :)17:04
ScottKThere are others here that are.17:04
ScottKnealmcb: Yeah.  That was my intent.  We'll see.17:05
Kludge^WalesUKhmm cool. I've googled for a few hours, and as far as i can see its something to do with .htpaccess and .htpasswd17:05
Kludge^WalesUKI have webmin installed to see if it'd help me any, it helped a little but doesn't do what i need it to do with apache </317:05
* nealmcb cheers for the ubuntu server team, where name dropping can be a good thing :)17:06
Kludge^WalesUKi'm hoping to learn quite a bit here, and to eventually be able to give advice =) google IS my friend, but gugh, sometimes i've googled for 2hrs or more just to get something to work because some tutorials miss out a step that a techy would just naturally fill-in, a n00b wouldn't know theres a step missing :P17:15
ScottKKludge^WalesUK: I'd encourage you to work from the Ubuntu Server guide as much as possible and where you find such holes, report them so we can fix them.17:18
Kludge^WalesUKthere's a server-guide?!17:19
ScottKKludge^WalesUK: http://doc.ubuntu.com/ubuntu/serverguide/C/17:23
* Kludge^WalesUK clicketh17:23
Kludge^WalesUKnice one! book marked and will definitely look over :D17:27
nealmcb!serverguide17:27
ubottuSorry, I don't know anything about serverguide17:27
* nealmcb remembers he was gonna talk to sommer about that factoid - oops17:28
jpds!search server17:30
ubottuFound: aptproxy, ftpd, mldonkey, mda, smtp, teg, ubuntu-server, identify, torrents, compiz17:30
* ScottK wonders why the server guide is still stamped draft.17:30
jpds!serverguide is <reply>The Ubuntu server guide may be found at http://doc.ubuntu.com/ubuntu/serverguide/C/17:30
ubottuI'll remember that, jpds17:30
jpdsnealmcb: There you go.17:31
nealmcbjpds: you rock!17:31
nealmcbKludge^WalesUK: note also the reference to the serverguide in the /topic, and many other handy things17:34
Kludge^WalesUKi've been idling here for a few days, I didn't notice the topic :X maybe an ONJOIN /notice would be better noticed?17:35
nealmcb!ntfs17:36
ubottuTo view your Windows/Mac partitions see https://help.ubuntu.com/community/AutomaticallyMountPartitions - For NTFS write access, see /msg ubottu NTFS-3g or /msg ubottu FUSE17:36
GodSyn_BBIs there an "easy" way to convert from 32bit to 64bit installs? I have a couple of machines I'd like to go 64bit with 32 bit installs.17:36
nealmcbubottu: ntfs is <reply> To view your Windows/Mac partitions see https://help.ubuntu.com/community/AutomaticallyMountPartitions - For write access, see !NTFS-3g or !FUSE17:36
nealmcbjpds: I guess I'm still not on the approved list, so if you want to update that one also, be by guest17:37
nealmcb(since some channels use other bots like ubot3)17:37
nealmcb!fuse17:38
ubottuFUSE (Filesystem in Userspace) is a !kernel driver that allows non-root users to create their own filesystems. See http://en.wikipedia.org/wiki/Filesystem_in_Userspace for more on FUSE.  Some examples of filesystems that use FUSE are !ntfs-3g, sshfs and isofs. A full list of Filesystems that use FUSE is here:  http://fuse.sourceforge.net/wiki/index.php/FileSystems17:38
jpds!ntfs is <reply> To view your Windows/Mac partitions see https://help.ubuntu.com/community/AutomaticallyMountPartitions - For write access, see !NTFS-3g or !FUSE17:38
ubottuBut ntfs already means something else!17:38
jpds!no, ntfs is <reply> To view your Windows/Mac partitions see https://help.ubuntu.com/community/AutomaticallyMountPartitions - For write access, see !NTFS-3g or !FUSE17:38
ubottuI'll remember that jpds17:38
nealmcb:)17:39
GodSyn_BBgoing to assume noone knows of a way. Thanks anyways.17:39
nealmcbGodSyn_BB: I doubt it17:40
GodSyn_BBwas afraid of that.17:40
nealmcbexcept remembering packages via dpkg --get-selections for remembering packages etc17:41
jpds/1317:41
* nealmcb wonders about easy ways to sync changes from /etc - and whether any packages have configs that differ between 32 and 64 bit17:42
* delcoyote hi18:13
Kludge^WalesUKanyone adept with apache about? =)18:22
nealmcbKludge^WalesUK: You'll rarely hear a response to that sort of question here, as discussed in the Guide to asking questions on IRC.  Just ask your question.  (And I find sometimes that just forcing myself to actually ask a good question leads me to find out the answer myself)18:33
nealmcb(see /topic again)18:33
Kludge^WalesUKokie. i'll re-read, thankies18:34
=== ScottK2 is now known as ScottK
Cahananyone else had the problem of networking seemingly just failing for no explainable reason? iwconfig thinks it's still connected, but the machine cannot be reached via ping, ssh or samba share, and needs to have it's network connection reset in order to function again. (Feisty)19:07
Dediseems compression does not work even its enabled in the backuppc config, anyone any ideas?21:10
will01is it possible to run an ftp server over port 110?22:23
hadsAnything is possible22:26
Kludge^WalesUKi have a really serious problem, my /var/logs are 2.2GB, including kernel log of like 700MB. I'm currently locked out even over SSH. the / is 100% full, and the swap is 72% full... Can i safely reboot? =/23:05
hadsQuite possibly not. If / is full bad things will happen.23:05
Kludge^WalesUKi have no idea what's been writing such huge logfiles. I'm thinking its the "monitoring" function of my OVH manager23:06
hadsRunning mysql?23:06
Kludge^WalesUKno, i think i was trying to install that and it failed... to the point eventually i got a message that the device was full =/23:07
Kludge^WalesUKwhat exactly is likely to happen if i issue a "hard reboot" nothing is responding, not the httpd SSH, or VNC23:17
hadsUnsure, you may need console access to access to bring it back up.23:26
phaidroswhere would one best request a backport of an intrepid package to hardy?23:28

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!