[00:11] anyone has a good postfix reject_rbl_client config for recipient/helo/sender restriction? === PrivateVoid is now known as PV_Away [03:22] I have set up a samba share on my ubuntu server. My windows pc can connect to it just fine. However, my ubuntu desktop can't seem to connect/mount it [03:36] hiya, anyone here familiar with reprepro? [05:01] Greetings.. [05:02] allo [06:04] Is there a 'pdf' for the 'Ubuntu Server Guide anywhere? [06:05] i think it is [06:05] somewhere [06:05] not sure where [06:15] pschulz01 - try this link dl2.foss-id.web.id/dokumen/ubuntu/serverguide.pdf [06:16] or this link ... http://www.linuxinet.com/free-linux-ebooks/download-free-pdf-ebooks-ubuntu-server-guide.html [06:28] azteech: Ta. [06:28] azteech: The first link seems a leetle slow. [06:29] all the pdf's i have tried are slow ... but then again, i am on dial ... [06:30] if you want to find another one ... google for it and use pdf+ubuntu server guide .... [06:30] azteech: Second link was quick.. done.. [06:30] k [06:30] azteech: Looks a little dated as well. [06:30] Copyright 2006 [06:31] well the ubuntu server doc site only shows the 5.10 and 6.10 versions ... of the doc ... so the pdf's might be as well ... [06:31] the 8.04 version I found a little while ago is still in draft form .. [06:32] and as such, probably not a pdf out there for it .. [06:33] Ta. Looks like it should submit some updates :-) [06:33] agreed ... and am sure they will when draft doc is done .. [06:50] Is there an ImageMagick page that doesn't rely on X? [08:02] i am planning on install ubuntu server on my desktop for testing purposes, i understand that for security no GUI is installed by default, i agree that is a great idea for security on most servers but is there a way (easy way) to install a gui and it be all set up like it was default so i dont have to get another computer [08:02] i was guessing sudo apt-get install gnome [08:03] thats an #ubunttu question (the answer is to run tasksel and chose the desktop task) [08:03] * #ubuntu [08:04] lol sorry [08:04] <_ruben> or just use some virtualization product [08:08] moin === freaky[t] is now known as fReAkY[t] [09:28] hello all, I have installed pptp VPN server, but my clients suffer from a very slow connections, is that necessary for VPN server to be a gatway ? === freaky[t] is now known as fReAkY[t] [10:31] New bug: #261066 in mysql-dfsg-5.0 (main) "mysql-server 5.0.67-0ubuntu1 not starts" [Undecided,New] https://launchpad.net/bugs/261066 === fReAkY[t] is now known as freaky[t] === andreas__ is now known as ahasenack [13:44] Can anyone in here help me setup BIRD please? i have downloaded and installed it through KPackage Manager, but i am unsure of how to proceed from here. [14:02] hey folks. IM putting together a server, does anyone have a list of compatible motherboards, or recommendations on a relatively cheap (entry level) motherboard? [15:01] New bug: #260291 in openvpn (universe) "Network Manager 0.7, openvpn, VPN Connection Failed" [High,Confirmed] https://launchpad.net/bugs/260291 [15:24] kirkland: update-motd is great, it'd make an excellent little blog post subject [15:28] hello all, I really have a big problem, I posted many times, I have a very slow pptp vpn connection and don't know why, any leading points? [15:36] Koon: ping [15:36] zul: pong [15:37] Koon: does this look sane to you: http://pastebin.com/d38ca8862 [15:37] its for the openvpn/network manager fix [15:39] * Koon looks [15:41] zul: i don't know that much rc7, but that looks sane, yes [15:41] coolio [15:42] thanks [15:42] (haven't tested it so ymmv) :) [15:43] Koon: I already have [15:43] ok cool ;) [15:47] hello all, I really have a big problem, I posted many times, I have a very slow pptp vpn connection and don't know why, any leading points? === gsalah__ is now known as gsalah [17:22] Hello. [17:23] Anyone running a mail server with imap and server-side filtering? [18:05] New bug: #261198 in apache2 (main) "Add UFW profile integration with apache2" [Undecided,Confirmed] https://launchpad.net/bugs/261198 [18:19] Pupeno: Yes. [18:45] hey, I've installed Ubuntu Server through parallels on my mac successfully, but how would I access the localhost through my mac when it is on the Ubuntu server? [19:07] is anyone tried mod_authnz_external with Apache 2.2 ? [19:07] Got a 500 error [19:26] i'm not sure if i should ask here, or main chan [19:27] i'm having some issues making a minimalist desktop for a mpc [19:27] htpc [19:28] the software I'm using is xbmc and I set up a dual boot between ubuntu server and ubuntu desktop for testing [19:28] on desktop, the program works fine, on server it is very slow and xorg uses 100% cpu [19:31] so, i'm missing something on server, that is not included with apt-get install xorg [19:31] also, i'm trying to avoid a window manager, so while installing gdm might fix it, I would rather not [19:40] if anyone is here, i found out the difference... on the desktop glxinfo says it is using direct rendering... on server it is indirect [19:52] jdstrand: I updated the ufw sections this weekend, wasn't 100% sure I understood the --add-new option for the application integration [20:00] sommer: you are not the only person to have said that, so I clearly need to be more, well, clear [20:00] sommer: if you don't mind entertaining me-- how do you understand it? [20:01] (it may help me to clarify it if I know how people are currently interpreting it) [20:01] jdstrand: if you add a port rule to an application profile it won't be enabled until you specifically enable it, unless you set the option to default [20:02] jdstrand: or at least that's close to my interpretation :) [20:02] sommer: yes, if I understand your phrasing correctly :) [20:03] sommer: adding a profile in /etc/ufw/applications.d simply makes the profile available to use when adding rules [20:03] sommer: eg 'ufw allow Apache' [20:03] ScottK: https://bugs.edge.launchpad.net/ubuntu/+source/clamav/+bug/261249 [20:03] Launchpad bug 261249 in clamav "MIR report for CLAMAV" [Undecided,New] [20:03] sommer: the 'app update' command allows a maintainer or admin to change the profile, and then update all referenced rules with one command [20:04] sommer: eg, user does 'ufw allow WebApp', which simply opens port 8080 [20:04] sommer: admin then changes the profile to have '8080,8081' [20:05] sommer: a user can then run 'ufw app update WebApp' and now both 8080 and 8081 are open [20:05] jdstrand: ah, that makes sense, and if they've set --add-new to default they don't need to do the "app update" part? [20:06] sommer: a package maintainer can take advantage of this for long-term maintainablity [20:06] sommer: exactly [20:06] sommer: 'update --add-new' does all that 'update' does, and it will add a new rule to the firewall depending on how DEFAULT_APPLICATION_POLICY is set [20:07] (which is skip by default) [20:07] jdstrand: okay makes sense now, I'll double check what I wrote... probably needs clarified, heh [20:07] sommer: when the DEFAULT_APPLICATION_POLICY is skip, 'app update' and 'app update --ade-new' are equivalent [20:08] jdstrand: gotcha [20:08] sommer: the nice thing about this is for example samba [20:08] sommer: it might have a profile that is 137,138/udp|139,445/tcp [20:08] sommer: if a user did: [20:09] ufw allow to any app Samba from 192.168.0.0/16 [20:09] ufw allow to any app Samba from 10.0.0.3 [20:09] then if change the profile, you only have to run 1 command, as opposed to (at least) 8 [20:10] (4 ports * 2 rules) [20:11] cool, so are any profiles currently shipping? I believe I saw a bug for apache... [20:11] jdstrand: something to use as an example anyway [20:11] sommer: a community member has approached me and said he'd work on apache and openssh initially [20:12] soren: What do you use for that? [20:12] sommer: I might also add that the average user will likely only need to use 'app list', 'app info ' and then references the profiles in the rules [20:13] sommer: the 'app update' command is really to make sure there is some way a maintainer can update the profiles sanely [20:14] though, an admin may find it useful... [20:15] jdstrand: for new profiles is the procedure to file a bug against the application? [20:15] Pupeno: Dovecot. [20:15] sommer: yes, you can see UbuntuFirewall for developing them, and ServerTeam/Roadmap for targeted applications [20:15] soren: and postfix I presume, right? [20:16] jdstrand: awesome, I'll update the guide this evening, thanks [20:16] Pupeno: Postfix is somewhat involved, yes. IMAP and server side filtering is all dovecot, though. [20:17] sommer: thank you! :) [20:17] soren: I'm reading Dovecot page at the moment. How do you perform and/or set the server-side filtering? [20:17] leonel: Thanks. [20:18] Pupeno: I tell postfix to use Dovecot's LDA. Dovecot then reads a sieve script from my home directory. [20:48] jdstrand: are you there? [20:51] didrocks: yes, hi! [20:52] hi :) [20:52] I think the first debdiff is ready [20:52] didrocks: for apache? I haven't looked at it yet, but saw it come in [20:52] I just have one question before: is it delibaretly for ufw that we do not remove the rules after purging the package ? [20:52] (I haven't uploaded it at the moment :)) [20:54] didrocks: well, we remove the profile, but don't remove the rule if the user had DEFAULT_APPLICATION_POLICY set to something other than skip and a rule was automatically added [20:54] yes, that's what I say [20:54] /say/saw [20:55] this one is located on /var/lib/ufw/user.rules apparently :) [20:55] didrocks: oh, I thought we were talking about application rules [20:56] no no, firewall rules, sorry for the misleading term :) [20:56] didrocks: so /var/lib/ufw is not deleted on purge? [20:57] yes, the rule corresponding to the removed profile is not removed (as described in https://wiki.ubuntu.com/UbuntuFirewall#Integrating%20UFW%20with%20Packages) [20:57] didrocks: I think we are talking about different things [20:57] hum, I am speaking about rules visible through ufw status [20:58] didrocks: on apt-get remove --purge ufw, what are you expecting to happen, and what is happening? [20:58] hi. does anyone have a good hardy preseed file. especially one that joins an AD domain? [20:59] jdstrand: on --purge, the profile (so, the file in /etc/ufw/applications.d/... is removed), but the firewall rule (which is shown by "ufw status") is not purged [20:59] and I don't find it logical (for me, both has to be removed) [20:59] didrocks: ok-- now I know what you are talking about [21:00] didrocks: 'apt-get remove --purge apache2.2-common' removes the profile, but does not update the running firewall [21:00] didrocks: that is intentional [21:00] why? [21:03] didrocks: the stance I took is that if the administrator added rules referencing a profile, then the admin should update the firewall when that package is removed [21:03] didrocks: I was trying to avoid ufw making policy decisions on its own, which it could very easily do wrong [21:04] yes, that's understandable [21:05] didrocks: it's also possible that a profile might not be package specific for some people/distributions [21:06] that makes sense. ok, that was my last question I think. I have ust uplodaded apache2 debdiff. It build well and I tried it on my intrepid VM (playing with ufw ;)) [21:06] didrocks: eg, profiles could be distributed by someone in a 'ufw-profiles' package, that has things such as 'Web Server'. [21:06] yes, some common profiles between packages [21:07] jdstrand: thanks a lot :) [21:07] then the install appache, do "ufw allow 'Web Server'", then remove the ufw-profiles package and apache is not longer accessible [21:07] (if we automatically removed the rules on profile removal) [21:07] yes yes, I understand [21:07] regarding terms [21:07] rules is for firewall [21:08] profiles for application-port association [21:08] is it correct? [21:09] didrocks: yes [21:09] didrocks: rules as in 'iptables rules' [21:10] jdstrand: that's what I was assuming :) [21:11] it's a really great tool as iptables configuration is very difficult the first timeā€¦ (then, it seems easier, but well ^^) [21:11] thanks! :) [21:12] jdstrand: when you will have time (after your move, for instance ;)). Keep me in touch about this package and when it will be ok (maybe some changes has to be done), I will try to put some efforts on other packages [21:12] it is very straightforward [21:13] didrocks: I sure will-- I will definitely look at it this week [21:13] didrocks: thanks again for your work! [21:13] :) [21:13] jdstrand: you're welcome :) [21:14] have a good evening (or day) :) [21:14] you too [21:14] thanks [21:16] emgent: thanks ;-) [21:16] sommer: thanks ;-) [21:55] jdstrand: someone uploaded ubuntu1 during this time, I have to update my package :/ [21:55] kees is the guilty ^^ [21:56] didrocks: which package? [21:56] apache2 :) [21:57] oh, did we just collide? [21:57] I _just_ uploaded an ubuntu1 version :( [21:57] yes, but no problem, I will provide a new version :) [21:57] (and hate you secretly :)) [21:57] okay, cool, sorry about that. I didn't realize one was in the works. [21:57] hehe [21:59] mathiaz: hrm, slapd isn't installable for me under intrepid. it yells about existing directories. [22:02] kirkland: yay for superpowers! Congratulations! [22:03] kees: hm - which ones ? [22:04] is anyone using a lot of bandwidth ? [22:04] PumpkinPie: what for? [22:05] mathiaz: http://pastebin.osuosl.org/21869 [22:07] kees: seems like an issue with the rootpassword - can you share the root password ? [22:07] kees: or look into /tmp/slapd_init.ldif.SAhzi17406 ? [22:07] mathiaz: er, there's no root password (running in a schroot) [22:08] 105 lines in that tmp file... what am I looking for? [22:08] * kees starts over in his schroot [22:08] kees: olcRootPW [22:08] kees: no root password -> that's why [22:10] kees: there is probably a line similar to this: olcRootPW: [22:10] New bug: #261274 in redhat-cluster-suite (main) "clustat(8) truncates columnar output when stdout is not a TTY" [Undecided,New] https://launchpad.net/bugs/261274 === nxvl_ is now known as nxvl [22:11] mathiaz: [22:11] olcRootDN: cn=admin,cn=config [22:11] olcRootPW: [22:11] # olcRootDN: cn=admin,dc=outflux,dc=net [22:11] # olcRootPW: [22:12] what should I do to work around this? [22:13] kees: can you set a root password ? [22:13] kees: or is it part of an automated install ? [22:14] this is an automated install. [22:14] db_get slapd/internal/adminpw [22:14] adminpass=$(echo $RET | sed -e 's|/|\\/|g') [22:14] that appears to be the place it's getting that password from? [22:14] kees: correct - slapd/internal/adminpw is the debconf template [22:14] mathiaz: so this is a debconf prompting level problem? [22:15] kees: hm - which level are you running deconf ? [22:15] kees: the password is prompted at level high [22:15] mathiaz: critical. ;) [22:16] mk-sbuild-lv uses: [22:16] echo set debconf/frontend Noninteractive | debconf-communicate [22:16] echo set debconf/priority critical | debconf-communicate [22:16] kees: right [22:16] kees: so you [22:16] kees: so you'd have to preseed the admin pw value [22:16] <_jpierre> Guys I have setup DHCP, but my clients can't access the internet. Can anyone help [22:16] kees: that should work [22:17] mathiaz: I think this is a bit of a bug, actually -- a randomized default should be chosen in the case that debconf can't prompt. [22:19] Anyone know if this effects ubuntu? http://blog.vipul.net/2008/08/24/redhat-perl-what-a-tragedy/ [22:19] mathiaz: and this needs a -p I think: Creating initial slapd configuration... mkdir: cannot create directory `/etc/ldap/slapd.d/': File exists [22:25] mathiaz: hrm, seems that test-openldap.py in the regression testing suite still fails on intrepid. it's complaining about a missing pid file note. [22:28] osmosis: somone said in a comment that debian isn't affected (which is where we get our perl). I tried the sample code and have: [22:28] real 0m0.314s [22:28] user 0m0.136s [22:28] sys 0m0.004s [22:28] (so under a second and not affected) [22:28] kees: I'll have a look at it [22:29] mathiaz: okay, thanks. [22:58] Anyone around that would know who may be aware of possible ubuntu mailing list chokes? For the past couple of months there has began to be some several day delay in receiving email from some of the addresses to my mailbox (ubuntu-devel is the most recently one and I don't encounter similiar issues with any other incoming email). [22:59] zul: looks like mysql failed on amd64: http://launchpadlibrarian.net/17049756/buildlog_ubuntu-intrepid-amd64.mysql-dfsg-5.0_5.0.67-0ubuntu1_FAILEDTOBUILD.txt.gz [23:00] antdedyet: check with folks in #canonical-sysadmin -- they manage the infrastructure machines [23:03] zul: but I wasn't able to reproduce it on my amd64. [23:03] kees: alright. thanks! [23:14] baffle: ?