/srv/irclogs.ubuntu.com/2008/09/11/#ubuntu-server.txt

owhI'm getting "query (cache) [..] denied" errors in syslog. Google tells me that I can add allow-query { mumble }; to named.conf, but I have three files to choose from, named.conf  named.conf.local  named.conf.options - none of which have any obvious priority. The server guide is silent on the matter. Where should I do this?00:03
owhOr am I solving this in the wrong way?00:04
uvirtbot`New bug: #268816 in squid (main) "logrotate uses outdated sarg script" [Undecided,New] https://launchpad.net/bugs/26881603:21
szx0How can I completely remove then reinstall the Apache2.2 configuration of my Ubuntu 8.04/64Bit Server installation. I tried apt-get -f remove apache2 / apt-get --purge remove apache2 / .. then installing again and many different combinations with apache2 and apache2.2-common.. but nothing appears to make the /etc/apache2 directory or the init.d/apache2 file... ideas?04:06
NCommanderszx0, conffiles are not removed04:11
NCommanderszx0, you must remove them04:11
slangasekszx0: I believe the conffiles are owned by apache2.2-common, so that apt-get --purge remove apache2.2-common should give you a clean slate04:14
slangasekpurging apache2 will not automatically purge the packages that it depends on04:14
szx0Purging apache2.2-common does not work04:14
slangasekwhat files are left behind when you purge apache2.2-common?04:14
szx0hmm okay brilliant its doing something different now04:16
szx0last time I did sudo apt-get --purge remove apache2 apache2-common and it only remove 94kb of stuff04:16
szx0i meant apache2.2-common04:16
szx0now just doing sudo apt-get --purge remove apache2.2-common it got rid of 33megs of stuff04:17
kgoetzyou'd probably already removed it04:20
szx0\quit04:23
lukehasnoname`sooooooooooooren04:30
* kgoetz smacks lukehasnoname` for join-and-ping04:31
lukehasnoname`ow04:31
lukehasnoname`1) We need a better name for "Basic Ubuntu Server", as decided. 2) I was thinking, it would be cool to be able to choose your scripting language for a web server (I guess you're already on that path with RoR). As in, when you choose 'Web Server', you then choose PHP, Python, or Ruby for the language. 3) make the ubuntu server guide more easily accessible than "w3m /usr/shar/ubuntu-serverguide/html/c/index.htm04:35
kgoetz1. cant comment. 2. that would be more qustions asked,, which i think is not what ubuntu usually does, 3. how more accessable? in text?04:38
lukehasnoname`1) In intrepid, a new box in tasksel currently called "Basic Ubuntu Server" installs the server guide (HTML), w3m, patch, and something else. I suggested it needs a more suitable name. 2) Since PHP is no longer as dominant as it once was, I thought it would appeal to people looking to get their Python or Rails projects up quickly. 3) Perhaps a symlink or a w3m launcher in the original user's home directory to04:42
kgoetz1. i see, not tried intrepid. 2. you could try and support 'the big 4' - perl/python/php/rails (although rails needs more intgration work), but could turn into a lot of work. 3. if motd says 'for help run w3m' i dont think filling homes with rubish is needed04:51
lukehasnoname`I agree04:53
lukehasnoname`a modified motd (if server guide is installed) could say "For help, see /path04:54
lukehasnoname`"04:54
lukehasnoname`g2g do some homework before bed04:57
cchapmanhello05:38
toolfan2k4can ubuntu be used as a user server for windows?07:18
kgoetz'user server'?07:19
* _ruben thinks ADS07:20
toolfan2k4yeah like how businesses and schools give usernames to people to allow them to login on any pc on the network.07:20
slangasekYes; Ubuntu with Samba can be used as an NT4-style domain controller for Windows07:21
kgoetzand if your luck enough to have no doze boxes, you can probably use ldap07:23
toolfan2k4no doze boxes?07:23
slangasekpresumably that doesn't help with the use case he's interested in given the question he asked07:24
kgoetzyeah. but i thought i'd put it into the logs anyway07:26
lukehasnonameno doze?07:27
lukehasnonameelab.07:27
toolfan2k4ok thanks07:39
toolfan2k4what is no doze?07:40
slangasekdoze being slang for Windows07:40
lukehasnonameah07:42
lukehasnonameI thought he mean 24/7 uptime07:42
toolfan2k4ah so i figured.07:42
toolfan2k4ok so i will research samba07:42
toolfan2k4thnk slangasek07:43
slangaseksure07:43
toolfan2k4you wouldn't happen to know of a tutorial for how to set up samba as a username server?07:46
lukehasnonamehttp://doc.ubuntu.com/ubuntu/serverguide/C/index.html maybe07:47
lukehasnonameno clue07:47
slangasekthere are probably a number of tutorials out there; the keywords are samba+pdc+nt407:49
slangasekhttp://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/samba-pdc.html looks promising07:50
kgoetzIIRC sambas package (or its -docs package) contains lots of info on the subject - i'll be looking into it this weekend myself07:50
toolfan2k4thank everyone....im gonna give it a try...beats the price of windows server07:51
slangasekyes, the above samba.org link points to the Samba-HOWTO-Collection, which is also in the samba-doc package07:51
kgoetzah, nod.07:52
emgentkirkland: ping07:55
uvirtbot`New bug: #268868 in apache2 (main) "[Intrepid Alpha 5] NameVirtualHost entry in ports.conf causes "NameVirtualHost *:80 has no VirtualHosts" warning" [Undecided,New] https://launchpad.net/bugs/26886808:31
spiekeyMorning!08:43
spiekeyCan someone recommend a tool to monitor and analyse network traffic (mith mrtg or alike?)08:43
spiekeyi need to find out where my network bandwith peaks are, and the ports which are beeing used ;)08:43
_rubenspiekey: iftop for realtime stats, pmacctd for longterm info09:06
incorrectI was wondering what the best mail/group ware type system was these days?  or is there even one that ubuntu promotes use of?09:36
_ruben!best10:07
ubottuUsually, there is no single "best" application to perform a given task. It's up to you to choose, depending on your preferences, features you require, and other factors. Do NOT take polls in the channel. If you insist on getting people's opinions, ask BestBot in #ubuntu-bots.10:07
Koonquestion: likewise-open in hardy shipped /usr/lib/libwbclient0.so. In intrepid, libwbclient0 (samba dep) ships /usr/lib/libwbclient0.so, while likewise-open uses one in /usr/lib/likewise-open/libwbclient0.so. Hardy (with samba+likewise-open installed) -> Intrepid upgrades fail, because libwbclient0 is installed before likewise-open is upgraded. Is there any way of making dist-upgrade process likewise-open upgrade before libwbclient0 is installed ?10:52
sorenKoon: Yes.10:55
Koonsoren: good news. How ?10:56
sorenKoon: You add "Conflicts: likewise-open (some version specifier)\nReplaces: likewise-open (some version specifier)" to the new libwbclient0 package.10:57
Koonsoren: ok so that would be a fix in libwbclient rather than in likewise-open. After all, it's the one stepping on the other's toes.10:58
sorenRight.11:00
sorenI'm surprised this is not adresssed in some kind of FAQ somewhere. At least not one that I can find.11:00
* Koon reads debian policy 7.6.1 which has a clean explanation11:01
uvirtbot`New bug: #264943 in samba (main) "gvfsd-smb crashed with SIGSEGV in strlen()" [Medium,New] https://launchpad.net/bugs/26494311:33
ghalebhello, is there a way to pass the ssh password to the ssh command ?11:52
Kamping_Kaiserghaleb, waht do you mean?11:53
Kamping_Kaiseriirc 'expect', but if you need ot enter a password, why not use keybased logins?11:53
ghalebI want to execute a command from a server, but the ssh client asks for password , is there a way to pass the password to the login ?11:54
nijabaghaleb: as Kamping_Kaiser said, generate a ssh key and use this instead11:55
ghalebI made it, but I have a problem that I tried to solve11:55
ghalebbut it didn't work11:55
ghalebI create public an private keys11:55
nijabaghaleb: https://help.ubuntu.com/community/SSHHowto should explain this in detail11:55
ghalebnijaba: I know how to do it, but it didn't work for one client only11:56
ghalebI mean, I made it manytimes , but one client can't connect , the server asks for password, despite it has the public key copied11:56
nijabaghaleb: so you have other clients that can connect using the same key to the same server but not this one?11:57
ghalebexactly11:57
nijabaghaleb: and all client should be identical, or are there some differences?11:58
Kamping_Kaiserall clients using the same key? o_011:58
ghalebno, I generated keys using ssh-keygen11:58
ghalebcopied the public key to authorized_keys211:58
ghaleband connect using private11:58
ghalebI made that on three clients, but one of them doesn't work11:58
Kamping_Kaiserdid you use ssh-copy-id?11:59
nijabaghaleb: I really like ssh-copy-id to avoid mistakes11:59
nijabaKamping_Kaiser: :)11:59
ghalebno, cat xyz.pub > /home/.ssh/authorized_keys211:59
ghalebactually >> not >11:59
* Kamping_Kaiser slaps ghaleb about a bit11:59
Kamping_Kaisernijaba, :)11:59
ghalebthis is what i did12:00
ghalebhttp://www.csua.berkeley.edu/~ranga/notes/ssh_nopass.html12:01
Kamping_Kaisernot loading for me *g*12:03
ghalebokay, then there is no way to ask a server for sth unless I create keys12:05
ghalebhhmm12:05
nijabaghaleb: can't load the page either12:09
ghalebhttp://linuxproblem.org/art_9.html12:09
ghalebanother one, but the same issue12:09
Kamping_Kaiserthis might be harsh of me, but something that has "automize" isnt something i take seriously.12:10
ghalebokay12:10
ghalebwhat do u suggest12:10
Kamping_Kaiserghaleb, those are kind of old instructions - i belive even upstream openssh ship ssh-copy-id these days.12:11
Kamping_Kaiserghaleb, follow the SSHowto nijaba sugested. you'll have keys, you just need to look at the copying bit. https://help.ubuntu.com/community/SSHHowto#Public%20key%20authentication12:11
Kamping_Kaiserwaho.12:11
Kamping_Kaiserthe new wiki doesnt have crappy links!12:12
Kamping_Kaiserit does have a fail login system though, so i guess it balances out12:12
ghalebso, u mean, the problem in the ssh server , right ?12:12
Kamping_Kaiseri suspect doing everything manually you've made a mistake of some sort. i'm suggesting ssh-copy-id (or whatever) might fix it up12:13
ghalebokay, thank you, I will try it out12:13
Kamping_Kaisergl12:14
ghalebwhat is that q option, silence ssh-keygen means ?12:15
ghalebKamping_Kaiser: it's not working :(12:39
AnRkeycan i use ufw 0.22 on hardy?13:16
sorenI belive it depends on a more recent iptables than hardy provides, so I'm guessing no.13:18
Kamping_Kaiseri guers you could backport both13:21
didrocksAnRkey: I am curently backporting it13:50
didrocks(with iptables)13:51
finalbeta_Hello, I have an Ubuntu server running with MySQL. The data in the MySQL database is the only thing that changes on the server. I need to backup this server. I need minimal down time. I was thinking to use dd to clone the full disk to a second drive in the server (can I do this while the server is running). And to backup the MySQL database seperatly at scheduled intervals. When the disk fails, I should be able to just boot from disk 2 14:18
AnRkeydidrocks, will it have port forwarding?14:18
finalbeta_I'm new at this, does this sound good to you? Any suggestions?14:19
AnRkeydidrocks, i have test box's here if you want me to make it work a bit14:19
AnRkeyi found the debs but they need iptables 1.414:19
incorrectI was wondering what the best mail/group ware type system was these days?  or is there even one that ubuntu promotes use of?14:19
AnRkeywill it lose anything in the backport?14:19
AnRkeysince it wont have 1.414:20
Kamping_Kaiserfinalbeta_, rsync > dd i expect14:25
jdstrandfinalbeta_: if you want no downtime, use replication to a slave server, then backup the slave14:26
Kamping_Kaiserfinalbeta_, it comes down to 'how bad is downtime'14:26
Kamping_Kaiseras to what you use to avoid it14:26
Kamping_Kaiserincorrect, groupware in what way?14:26
finalbeta_Kamping_Kaiser, I don't understand the rsync, doesn't seem to help me in this case. Wont backup the mysql or give me a booting disk.14:27
incorrectKamping_Kaiser, like zimbra14:27
finalbeta_jdstrand, Kamping_Kaiser, downtime o a couple of hours max is not that much of a problem. the shorter the better, but I can compromise14:27
finalbeta_I have a single server running a sort of web server with mysql backend. Only the MySQL changes. I need to be able to recover when the disk fails.14:28
finalbeta_so I was thinking dd the disk every few months at maintainances. and backup the database to a remote server every night. allowing me to put in the disk when the server fails, and just restore the database.14:30
finalbeta_rsync wont be able to correctly backup the mysql, unless I shut down the database. (which is an option at night). but it wont leave me with a bootable disk.14:32
Kamping_Kaiseri doubt dd will give you a bootable disk either tbh14:35
* Kamping_Kaiser splits14:36
spiekeyin my syslog i get iptables infos like: (...) kernel: IN= OUT=eth0 (...)  --> why is the Input information empty?14:38
spiekeydoes it come from nowhere? :P14:38
sorenOriginating interface is unknown in the OUTPUT chain.14:40
finalbeta_Kamping_Kaiser, for what I read, it does, that's the whole point of it. But I'll run that this evening.14:41
Adri2000does anyone know why vsftpd didn't get updated to the 2.0.7 upstream version?14:53
spiekeyhey...i need some help using ftp proxy on a command line:15:54
spiekeyhttp://pastebin.com/m77548bf015:54
spiekeyi do not unserstand why i dont get any traffic on port 2121 on my firewall15:54
snitkohi, what could be the reason for a service not to start at boot time, when it starts just fine manually with 'service name start' and has all appropriate symlinks in rcN.d dirs?16:11
nomoahi, anyone can explain to me what is causing /proc permissions restrictions like this : http://pastebin.com/m14b89bf4 ?16:23
sorennomoa: What is the problem?16:27
nomoanormal user cannot see others process16:27
jdstrandScottK: re clamav/apparmor> ok16:28
nomoaI've never seen that before16:28
ScottKjdstrand: Thanks.  So far it's quiet, I just don't want upstream bugs to get blamed on the profile.  I just finished the libclamav5 transition last night.16:29
jdstrandScottK: sounds great :)16:29
ScottKHurray.  hppa down under 300 builds waiting ...16:30
nomoathe main problem is for stuff like zabbix-agent which need to access /proc/PIDs for monitoring process information, I have to hack its user to uid:0, I really can't understand how I can disable such security feature... uid 0 for zabbix user is really risky work-around :(16:34
keesnomoa: most things in /proc/$pid is world-readable.  what are you trying to access that you can't?16:42
jdstrandumm, my kernels don't do that. that sounds like openwall's restricted /proc patch16:42
jdstrandnomoa: ^16:43
nomoakees, I can't: dr-x------ 6 root root 0 2008-09-05 17:51 /proc/116:43
nomoajdstrand, hum?16:43
LiferHi. Has anyone performed an "apt-get upgrade" with today's upgrades?16:43
keesnomoa: yeah, you're not running a standard kernel.16:44
jdstrand(I checked hardy -generic and -server, and intrepid -generic)16:44
kees$ ls /proc/1 -lda16:44
keesdr-xr-xr-x 7 root root 0 2008-09-10 16:44 /proc/1/16:44
nomoakees, I would like the same :)16:44
jdstrandnomoa: 'uname -a'16:44
nomoaLinux ________ 2.6.24.5-grsec-xxxx-grs-ipv4-64 #3 SMP Tue May 27 19:09:58 CEST 2008 x86_64 GNU/Linux16:45
ivoksoh lol16:45
jdstrandwell, there you go ;)16:45
LiferHello. Can I get help here with an unbuntu V71.0 server problem?16:45
ivoksLifer: if that's v7.10, then yes, v71.0 is scheduled for ~ 60 years16:46
ScottKLifer: Possibly.  Describing the actual problem increases your odds.16:47
jdstrandjdstrand: your grsec kernel will almost certainly carry the restricted /proc patch16:47
jdstrandheh16:48
jdstrandnomoa: ^16:48
jdstrandnomoa: if it's your own kernel, check the docs and see if there is a sysctl setting or recompile it without restricted /proc16:48
nomoajdstrand, thank you to point me to this grsec stuff... I'll look at there16:48
nomoajdstrand, nope it was installed by our provider16:49
nomoajdstrand, annoying parano stuff16:49
ivoksgrsec is actually great, imho16:49
LiferScottK:ivoks: I installed ircd-hybrid: "apt-get install icrd-hybrid", then did and upgrade and update: "apt-get upgrade", "apt-get update". Now cygwin does not connect via xwin from my Windows box to the unbuntu server.16:50
* ScottK isn't the right guy to help with IRC stuff.16:50
nomoaivoks, it breaks many things, not so linux philosophy IMHO16:50
jdstrandit is in certain situations, but it is interesting that in this instance, a user may end up with less security because of working around restricted /proc (eg, running zabbix as root)16:50
ivoksnomoa: it does break things; already broken things :)16:50
ivoksLifer: i doubt it's realted to ubuntu16:51
nomoaivoks, not sure : look at zabbix, is it broken to monitor stuff? :)16:51
Liferivoks: I installed ircd-hybrid: "apt-get install icrd-hybrid", then did and upgrade and update: "apt-get upgrade", "apt-get update". Now cygwin does not connect via xwin from my Windows box to the unbuntu server.16:52
LiferScottK: Not irc prob, but upgrades prob, IMHO16:52
ivoksnomoa: i've never looked at zabbix, but i can tell for sure that zenos is totally broken16:52
ivoksLifer: did it upgrade anything?16:53
LiferYes. Is there a log I can inspect?16:53
ivoks /var/log/dpkg.log16:53
Liferivoks: Yes. Is there a log I can inspect?16:53
ivokser.. zenoss, not zenos16:54
Liferivoks: upgraded: postfix, triggeres-pending, libc616:56
ivoksso, nothing relevant for network16:57
ivoksi'd bet on windows firewall...16:57
Liferivoks: no change to windows.  Cygwin/Xwin works with other unbuntu server.  Other Client Cygwin/Xwin does not work, also.17:05
ivoksLifer: it's ubuntu17:06
ivoksnot unbuntu17:06
ivokstry 'telnet your_ubuntu_server 6000'17:07
ivoksand see it that works; if you can connect, than everything is ok, if you can't connect then x11 service is not started on ubuntu server17:08
Liferivoks: I removed ircd-hypbrid, rebooted server. XWin now works17:08
ivokswhich brings us to question 'how come we talk about GUI on server channel?'17:08
ivoksright, reboot usually starts all services :)17:08
Liferivoks: It didn't work when I rebooted with ircd-hybrid installed17:09
ivoksmaybe you've configured ircd to listen on port 6000?17:09
Liferhmmm17:10
ivoksit should listen at 6665, 6666, 6667, 6668 and 666917:11
Liferivoks: I configured nothing wrt ircd-hybrid. Does that use the same ports as Xwin? I thought IRC used 666717:11
Liferivoks: BTW, IRC did not work wither17:12
Lifer*either17:12
ivoksLifer: well, i don't know17:12
Liferivoks: is there a file that lists who is using which ports?17:13
ivoks /etc/services17:14
Liferivoks: I'll reinstall ircd-hybrid and see which ports it tries to use. be back in a bit.17:15
ivoksi've told you which it uses17:16
Liferivoks: It should also work. But it got that wrong, too.17:17
spiritssighthow much different is the server verison over the desktop17:20
Liferivoks: The install sequence was different this time (post upgrade).17:20
Liferivoks: is /etc/services the ports that this installation is using, or a list of recommend/supported ports?17:25
ivokstoo many questions and i don't have time17:26
nomoais there a way to know kernel config options without the .config nor /proc/config.gz file...? (desperate)17:34
jmedinanomoa: what is the problem with those files?17:41
nomoajmedina, I need to know the value of a kernel config parameter, but the guy how installed the system did not leave the config files17:43
jmedinanomoa: which parameter?17:44
jmedinamaybe someone here know how to check it17:44
nomoajmedina, CONFIG_GRKERNSEC_PROC_GID17:44
jmedinaisnt there any grsec specific option to check that?17:45
nomoaall grsec config is done inside the kernel, but ovh (our provider) do not give the .config17:46
nomoaso I don't know what is the right group to put zabbix in in order to have access to /proc17:46
jmedinanomoa: dont you have any other app integrated with grsec? maybe you can compare it17:48
* jmedina loves that kind ob obscurity, I mean security....17:49
nomoajmedina, it's a unmodified ubuntu 8.04 server with the only exception of this grsecurity kernel17:50
jmedinanomoa: did you ask at ##grsecurity?17:50
jmedinabu, emty channel17:50
nomoathat was my intention :)17:50
nomoaarf17:50
nomoaI will try #give-me-rope-chair-paper-pen then :)17:51
nomoaI give up, thank you all17:52
leonelis  AMD  recomended for  ubuntu server ?? i've only used  intel  so   there's a new server comming and I'm thinking for an AMD dual core ..18:50
sdhruns fine on my amd x2 6000+18:53
=== mcasadevall is now known as NCommander
uvirtbot`New bug: #269085 in apache2 (main) "apache2ctl refers to APACHE2_RUN_USER instead of APACHE_RUN_USER" [Undecided,New] https://launchpad.net/bugs/26908518:55
jmedinasame here, with about 50 virtual machines running in amd servers since 3 years with xen18:57
Goosemoosewhen writing a preseed file: d-i preseed/late_command string wget http://10.0.2.131/post_install_tasks && chmod +x ./post_install_tasks && ./post_install_tasks returns 'failed with exit code 127'. but if i run it on the machine after install it works fine19:22
Goosemooseany idea why?19:22
Smelnei have aproblem with pure-ftpd none of my users can login20:06
jmedinaSmelne: what kind of users?20:09
jmedinalocal? virtual?20:09
SmelneI'm sorry, i was afk for a bit. They are virtual users, and all of them recieve a 530 authentication failure20:16
jmedinaSmelne: what do the logs says?20:16
SmelneIt says "[INFO] New connection from 192.168.0.241, [INFO] PAM_RHOST enabled. Getting the peer address, [WARNING] Authentication failed for user [sfmbeheer], [INFO] Logout."20:18
SmelneThe joke is that no passwords have been changed, no users removed or anyhing. We've had to restart the server yesterday after a kernel update, and this is hwat we were met with after the server came back up20:19
jmedinathat is no a pure-ftpd message20:21
SmelneI've got it straight from PureAdmin, so i'm fairly sure that it is20:21
jmedinaSmelne: can you show a user with purepw?20:21
jmedinathat is a pam message, are you sure you are still using virtual users?20:22
jmedinacan you show the output from ps aux | grep pure-ftpd20:23
jmedina?20:23
SmelneHmmm.... Just a sec...20:23
SmelneUnable to open the password file, what the....20:23
jmedinasomething in the config files changed?20:24
SmelneNot that i know of. We've just rebooted the server.20:24
Smelnesmelnefm@ariadne:~$ ps aux | grep pure-ftpd20:28
Smelneroot     11320  0.0  0.0   4840   636 ?        Ss   21:27   0:00 pure-ftpd (SERVER)20:28
Smelnesmelnefm 11412  0.0  0.0   2884   760 pts/2    R+   21:28   0:00 grep pure-ftpd20:28
jmedinahat about your options?20:29
emgentkirkland: ping20:30
Smelnejmedina, which ones?20:30
jmedinayour pure-ftpd config files20:30
jmedinathe ones that set the autentication20:30
jmedina /etc/pure-ftpd/auth/20:31
jmedinals -l /etc/pure-ftpd/auth/20:32
kirklandemgent: pong!20:32
kirklandemgent: sorry dude, got your ping while i was sleeping, and forgot ;-)20:32
emgentheya kirkland can i query you little bit ? :)20:32
Smelnejmedina, Well, what do you need to know about the config files?20:32
jmedinaSmelne: the order of the files20:33
jmedinals -l /etc/pure-ftpd/auth/20:33
jmedinathat one20:33
kirklandemgent: sure20:33
jmedinaI do Have20:33
jmedina$ ls -l /etc/pure-ftpd/auth/20:33
jmedinatotal 020:33
jmedinalrwxrwxrwx 1 root root 26 2007-07-30 17:43 45puredb -> /etc/pure-ftpd/conf/PureDB20:33
jmedinalrwxrwxrwx 1 root root 26 2007-07-30 17:22 65unix -> ../conf/UnixAuthentication20:33
jmedinalrwxrwxrwx 1 root root 25 2007-07-30 17:22 70pam -> ../conf/PAMAuthentication20:33
jmedinasorry for the flood20:33
Smelne65unix, 70pam20:33
jmedina:(20:33
SmelneI habve no puredb there though20:34
jmedinawhere are you storing your virutal users?20:34
Smelnea locate revealed that on this system, puredb is located in20:35
jmedinabecause with taht configs, says taht you are using unix auth by default20:35
Smelnein /etc/pure-ftpd/conf/PureDB i mean20:35
jmedinayeap, they are symlinks, look at my example20:36
SmelneThat's what io thought. So why it's spitting out PAM messages is beyond me20:36
jmedinaif you want to enable puredb virtual users you need to add a symlink in auth directory with a lower number, like mine (45)20:36
SmelneBut that still doesn't explain why it used to work20:37
jmedinanop, Im not trying to explain that, just wanted to check if you really was using puredb virtual users20:38
SmelneTrying with the symlink now. Fingers crossed20:41
nxvlsoren: http://paste.ubuntu.com/45897/20:42
nxvlsoren: why is ubuntu-vm-builder don't letting me use "intrepid" as hostname saying is not a valid vm?20:42
Smelnejmedina, Ha! Now it won't connect at all!20:44
* Smelne laughs hysterically20:44
jmedinajeje20:45
jmedinaSmelne: first, could you see your virtual users?20:45
SmelneI just noticed a strange discrepancy. pure-pw is looking for pureftpd.passwd in /etc/pure-ftpd, but that file is located in /etc20:49
jmedinamy 45auth file points to /etc/pure-ftpd/pureftpd.pdb20:50
SmelneGot it, finally got the user infpo20:50
jmedinaSmelne: try -f  option with pure-pw20:50
SmelneI have, that gave me the user info20:51
fozillaI "successfully" installed jailkit, but ssh session closes immediately after logging on. auth.log show 1) accepted password, 2) session opened, 3) entering jail and 4) session closed... all within a second. Any ideas why I can'r keep a session open?20:53
Smelnejmedina, ever since i made the symlink, all connections are refused to the FTP server.20:55
Smelnejmedina, are you still there?20:58
jmedinayeap20:58
w8tahgettin an error when i boot up -- eth0: ERROR while getting interface flags: No such device - -where to start _ the device is there21:01
Smelnejmedina, I've removed the symlink, and instead of flatout resetting the connection, it again fails to authenticate. Call me crazy, but it looks like progress to me.21:02
jmedinaSmelne: did you restart pure-ftpd?21:02
fozillaw8tah, what does dmesg say about the device?21:03
Smelnejmedina, Several times. I'll try to re-create the symlink21:03
jmedinastop it, check that there is no pure-ftp remaining, and then start it again, somethings it does not dies21:03
jmedinait happened to me21:03
w8tahfozilla: looking21:03
SmelneThe system monitor shows that it's not running, and so does top, and pidof21:03
jarloNewbie to IRC channel: I'm unable to update server -Errors were encountered while processing:21:05
jarlo /var/cache/apt/archives/mysql-server-5.0_5.0.51a-3ubuntu5.3_i386.deb21:05
jarloany advice?21:05
jmedinajarlo: is that all?21:09
jmedinajarlo: do you have free space?21:10
w8tahfozilla: i see the drivers for both nicks initializing, and a rather cryptic message about udev changing the name of eth0 to eth321:10
w8tahthats it21:10
w8tahfozilla: in addition -- lspci shows both nicks21:10
NCommanderjarlo, what error came up before that?21:11
Smelnejmedina, thanks for your help, i think we'll just have to go with another FTP server to replace pure-ftpd. Any suggestions?21:11
jmedinaSmelne: I dont recomend other than pure-ftpd21:11
jmedinasmelne, could you try to run pure-ftpd manually?21:12
SmelneMaybe, but pure-ftpd just don't seem to want to play nice anymore21:12
jmedinanot with the debian/ubuntu scripts (pure-ftp-wrapper)21:12
Smelnejmedina, If i run pure-ftpd manually, i get a permission denied. Running it as root (*shudder*), gives no feedback21:14
jarloyes plenty of space21:14
jmedinaSmelne: wait, did you tell it to use pure-ftpd?21:14
jmedinapure-db21:14
fozillaw8tah: not sure how that happened, but a few posts seem have similar issues... they solved it by editing the persistent net rules in /etc/udev/rules.d21:15
jarloprevious error21:15
jarloPreparing to replace mysql-server-5.0 5.0.51a-3ubuntu5 (using .../mysql-server-5.0_5.0.51a-3ubuntu5.3_i386.deb) ...21:15
jarlo * Stopping MySQL database server mysqld                                 [fail]21:15
jarloinvoke-rc.d: initscript mysql, action "stop" failed.21:15
w8tahfozilla: ok - thanks21:15
fozillaw8tah: did you change any hardware recently?21:15
Smelnejmedina, We've been using pureadmin from day one, i have no idea what the command line should look like21:15
w8tahyes sort of - -i moved the hdd adn memory to an identical chassis after the previous one had a mobo issue21:15
jmedinatry something like21:17
jmedina /usr/sbin/pure-ftpd -l puredb:/etc/pure-ftpd/pureftpd.pdb21:17
jmedinanever used pureadmin21:17
Smelnejmedina, someone should tell you everyday that he or she loves you. I'm in!21:20
MattJHi all21:20
jmedinaSmelne: I prefer a beer21:20
jmedina:P21:20
MattJDid I completely imagine that there was a metapackage for a lamp server?21:21
jmedinaSmelne: so , is it working?21:21
SmelneThen consider yourself loved by a keg of beer ;-)21:21
Smelneyes21:21
SmelneNow... Time to put that command in a script for easy starting.21:21
jmedinaSmelne:  please, run this21:22
jmedinastop pure-ftpd manually, double check that there is no pure-ftpd process running21:22
jmedinaand then21:22
jmedinabash -x /etc/init.d/pure-ftpd start21:22
jmedinaand give me the last line, the one whose launches /usr/sbin/pure-ftpd bla bla bla bla21:22
jarloAlso should probably include the final two errors. Which suggests the process could not remove the older mysql version. I'm new to linux server admin so struggling a bit. Any help would be great. dpkg - trying script from the new package instead ...21:22
jarlo * Stopping MySQL database server mysqld                                 [fail]21:22
jarloinvoke-rc.d: initscript mysql, action "stop" failed.21:22
jarlo subprocess new pre-removal script returned error exit status 121:22
jarlo * Stopping MySQL database server mysqld                                 [fail]21:23
jarloinvoke-rc.d: initscript mysql, action "stop" failed.21:23
jmedinaSmelne: that is to check how is invoked by the script maybe something is wrong with the configs21:24
Smelnejmedina, I guess i'll have to edit that init.d script21:24
SmelneIt says "/usr/sbin/pure-ftpd-wrapper: Invalid configuration file /etc/pure-ftpd/conf/PureDB: "/etc/pure-ftpd/pureftpd.pdb": No such file"21:24
jmedinammm21:25
jmedinawhere is your pureftpd.pdb file located at?21:25
danielm_mcholas21:25
jmedinaSmelne: mine is: Running: /usr/sbin/pure-ftpd -l puredb:/etc/pure-ftpd/pureftpd.pdb -u 1000 -E -A -j -O clf:/var/log/pure-ftpd/transfer.log -C 2 -H -I 4 -B21:25
SmelneMine is in /etc21:26
jmedinaSmelne: only change your /etc/pure-ftpd/conf/PureDB file21:28
jmedinachange the path to the file21:28
SmelneRight-o21:29
jmedinaand start again with the script and bash -s21:29
jmedinabash -x21:29
SmelnetHIS TIME, THAT DOES NOT THROW ANY ERRORS21:30
SmelnewOOPS21:30
SmelneArgh!21:30
jmedinawhat?21:31
jmedinais it working?21:31
SmelneLOL, sorry, i was attacked by a killer caps lock key. Yes, it's working. I have started the daemon from pureadmin again, and it's running, and logins are working again21:32
w8tahfozilla: can you point me to one of the entries about udev changing the interface name - im not sure how to edit those rules -- but its driving me NUTS21:33
jmedinaSmelne: Im not sure, but I think pureadmin is the one who created the puredb file in /etc21:33
jmedinabecause afaik, pure-pw creates it in /etc/pure-ftpd/21:34
fozillaw8tah: let me bring up my rules21:34
SmelneWell, at any rate, you have helped getting it running again. Consider yourself treated to two kegs of beer! :-))))21:34
w8tahthank you21:34
Smelnejmedina, i hope we'll meet IRL one day, so i can really give you that beer. But for now i will have to say goodnight21:35
jmedinaIRL?21:35
jmedinawhat is that?21:35
SmelneIn real Life21:35
Smelne:-)21:36
jmedinaohh, when you come to mexico city, call me :P21:36
danielm_mchey can you use iptables w/ dns ?21:36
Smelne:-))21:36
fozillaw8tah: do you have your eth1 (or whatever you don't want) entry?21:36
w8tahyes - -one moment please21:36
jmedinadanielm_mc: yes, but I wont trust it21:37
danielm_mcwhat if you want to block a host by ddns ?21:37
fozillaw8tah: basically change that to eth0, and your second card to eth1... if that's appropriate, making sure the mac is correct for each entry21:38
w8tahok - let me post my rules file real quick for u21:38
w8tahhttp://pastebin.ca/120040421:39
jmedinadanielm_mc: dns names can trivially be faked by an atacker21:40
danielm_mcyah true21:41
jmedinaand I'm not sure if iptables/netfilter cache the names un utils iptables reload or something21:42
jmedinaI would better use public keys authenticacion...21:42
w8tahfozilla: i see a prob - the mac is diff - should i change it to match the one being reported? -- ahh - -its different motherboard - -so hence diff mac21:42
w8tahthe light is dawning21:42
fozillaw8tah: find which mac addresses are correct using ifconfig -a, then comment out the other two using #... If the last two are correct, then change eth2 to eth0 and eth3 to eth121:45
fozillaw8tah: yeah, you got it21:45
w8tahok - thanks21:45
Goosemoosei have one screen that pops up when doing preseed pxe install that says the 'selected device already contains logical volumes'. I thought that this would take care of it, but it doesn't: d-i partman-auto/purge_lvm_from_device boolean true21:52
Goosemooseany idea on what im missing?21:53
slangasekdendrobates: ping22:10
dendrobatesslangasek: sup22:10
slangasekdendrobates: hi, I didn't get a response from coffeedude to my pings on bug #262264 and he doesn't seem to be around now; do you have a notion of what the "right" fix for this is?22:12
uvirtbot`Launchpad bug 262264 in likewise-open "Fails to join a domain: Unknown pam configuration" [Critical,In progress] https://launchpad.net/bugs/26226422:12
slangaseki.e., should likewise-open integrate itself completely with pam-auth-update, meaning that the PAM config is changed as soon as the package is installed, or should it just be updated to handle prepending itself to the new config layout?22:13
slangasek(I have a preference for the former, of course; we could probably even make it possible to toggle the config via likewise-open using debconf-communicate...022:13
slangasek)22:13
dendrobatesslangasek: I agree, have you looked at the patch Jerry provided?  I have not yet.22:14
slangasekdendrobates: the one Jerry did, or the one Thierry did?  Jerry's patch seems to be to only update the pattern matching and continue twiddling by hand22:15
dendrobatesslangasek: ah, I had hoped he would use pam-auth-update.22:16
dendrobatesslangasek: jerry made the change and Koon made a diff between the two versions.22:16
slangasekok; I think I'll test out Jerry's patch and make sure things get added in the right place with that option22:17
dendrobatesslangasek:  Do you want me to ask Jerry to use pam-auth-update?  We seem short of time.22:18
slangasekif not, I'll dive into a pam-auth-update solution22:18
dendrobatesslangasek: Koon can help, if necessary.22:18
slangasekI imagine that at this point, it would be faster for me to do a pam-auth-update fix since I've fully internalized the semantics of that tool and I don't think anyone else has yet :/22:18
dendrobatesslangasek: true, but we have to learn it sometime.  :)22:19
NCommanderhey slangasek, I took a look at NM for you22:20
NCommanderslangasek, its cleanly written so adding the code to add search domains w/ DHCP should be straightforward enough22:23
slangasekNCommander: does that mean you're writing and submitting a patch? :)22:24
NCommanderslangasek, sometime this weekend, I have a life tonight and tommorow22:24
NCommanderslangasek, you will of course sponsor the upload into Ubuntu as it works its way through the NM SVN :-)22:24
slangasekwell, no, I'll let asac handle that actually22:25
hadshadley Rich22:26
hadsExcuse me.22:26
* NCommander found a rather stupid bug with a backport22:27
NCommander  pbuilder-satisfydepends-dummy: Depends: etl-dev (>= 0.04.11) but it is not installable22:27
NCommanderBAH, dpkg sees 0.04.11~hardy1 lower than  0.04.1122:27
Quark_Is this the right place for help with IRCD-Hybrid server installation?23:39
slangasekQuark_: in practice, probably not23:46
BaryonHi. Can anyone help with a connectivity issue with a newly installed ircd-hybrid IRC server?23:46
Quark_The server is working like a champ (V7.10), but I cannot connect to the ircd-hybrid server I installed today.23:50

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!