/srv/irclogs.ubuntu.com/2008/09/22/#ubuntu-server.txt

xiownthisplacexhi all00:51
xiownthisplacexi have installed ubuntu 8.04 on a server, can i fxp on port 22? i've tried it and it doesn't work, do i need to config something? or do i need to install like glftpd?00:51
vk5fossxiownthisplacex: can you what on 22?01:44
xiownthisplacexi want to fxp from 2 servers that i have01:53
vk5fossfxp?01:54
xiownthisplacexyea, you know like, flashfxp01:55
xiownthisplacexsite-to-site transfer01:55
vk5fossnope, never heard of it before. (might hae heard of it actually, certainly never used it)01:59
PanzerMKZvk5foss it is ftp between two ftp servers not having the data pass thru the controller machine02:01
vk5fossPanzerMKZ: ah02:04
vk5fossxiownthisplacex: dare i ask why you want to run it on port 22?02:05
xiownthisplacexso i dont have to install a ftp server like proftd or glftpd02:05
vk5foss... is your question "can i copy files between two hosts directly over ssh" ?02:06
=== vk5foss is now known as kgoetz
Level15Hi: WHere can I suggest something to be added to Ubuntu server?03:42
dendrobatesLevel15:  the mailing list, or here during the week.03:45
lukehasnonamesomeone want to do a quick favor?04:10
EmmettWe changed the server IP of an ubuntu server install. ssh'ed into the machine, no problem. But now it's locking out ssh attempts when it worked fine minutes ago.05:47
EmmettSomeone just got in, ran an ls and it disconnected them.05:48
EmmettAny ideas?05:49
azteechreboot it and see if you can get back in?05:49
Emmettit's at a data center.05:50
kgoetzEmmett: are you using firewalling?05:50
Emmettno05:51
nxvlEmmett: check if you have ufw blocking stuff05:58
nxvlEmmett: it might be the problem05:58
Emmettnope.05:59
nxvlEmmett: are you sure? it's installed by default06:02
Emmettreally?06:03
Emmettsince I only have a minute on it, what are the chances that I could just06:03
Emmettsudo ufw disable06:03
Emmettand hit enter?06:04
Emmettwould that kill it all immediately?06:04
RoAkSoAxEmmett, it's supposed to06:06
nxvlyou can do "ssh $host $command"06:06
Emmettcan I ps -ef | grep ufw to see if it's running anywhere?06:07
Emmettlike, what daemon does it run?06:07
nxvlufw status06:08
EmmettI only have a second, I don't have time for that06:09
* ajmitch_ wonders if it's as simple as an address collision06:09
nxvlssh $host sudo ufw status06:09
twbIs it a bad idea (or even impossible) to include masquerading and other NAT chains and rules in /var/lib/ufw?06:21
RudyValenciaHi, I'm trying to setup a Postfix service on my server, for sending out notifications from PHP. How do I configure it in the menus?06:21
twbRudyValencia: if it's just going to send mail to a "real" mail server, you want the "satellite" option06:22
RudyValenciatwb: I'm setting it up to send out things like password reset, confirm account creation, etc. mails.06:22
RudyValenciaPHP mail(), basically.06:23
twbI realize that.06:23
RudyValenciaIt's basically going to send it directly to the other MX for delivery to the user.06:23
RudyValenciaWould it be a "Satellite system" then?06:24
twbRudyValencia: that's what I said.06:24
RudyValenciaOK06:24
RudyValenciaI think I may have it06:26
=== PanzerMKZ_ is now known as PanzerMKZ
sorenNCommander: hm?07:33
ghaleb__hello, I'm trying to get freeradius source, I get this problem E: Could not open file /var/lib/apt/lists/security.ubuntu.com_ubuntu_dists_hardy-security_main_source_Sources - open (2 No such file or directory)08:08
scuserhi all, I'm using ubuntu 8.04 and installed kerberos according to this tutorial http://doc.ubuntu.com/ubuntu/serverguide/C/kerberos.html, but when I type kinit I receive no tickets, can anyone help me with that ?08:13
scuserhi all, does this message mean that I have a ticket or not http://paste.ubuntu.com/49208/ ?08:32
twbkrbtgt/SC.BIBALEX.ORG@SC.BIBALEX.ORG is your ticket08:38
twbTry #kerberos (#krb?)08:38
twbscuser: so you have a TGT, but no other tickets (e.g. an NFS-specific ticket)08:38
scusertwb: I'm new to kerberos, so what does this mean ?08:40
twbscuser: #kerberos is an IRC channel.08:41
scusertwb: ok thanks :)08:41
Chipzzscuser: first thing you have to check when you have problems with kerberos is, like btw any document on kerberos will tell you, if you have a working DNS setup, both forward and reverse DNS09:42
uvirtbot`New bug: #273043 in apache2 (main) "/etc/init.d/apache2 routinely prints to stderr if few modules are enabled, causing logrotate to spam in cron" [Undecided,New] https://launchpad.net/bugs/27304310:11
ghaleb_hello, is there an alternative for freeradius in for EAP wireless authentication ?10:23
twbIs there a way to list existing ufw rules in "ufw format", as opposed to the raw iptables-save format?10:38
krautmoin10:41
henkjantwb: sudo ufw status10:42
twbhenkjan: oh!  That outputs useful information only if the thing is actually enabled10:43
twbhenkjan: thanks10:43
twbHow does it decide whether to be -p tcp, -p udp or both?10:44
twbDoes it just say "well, for 'ufw add www' there's a www entry for both in /etc/services" ?10:44
henkjanhmm, don't know if it gets the names from /etc/services10:47
henkjanlooks like it does10:49
scuserhi all, can anyone tell me how to use .k5login to login without password ?10:49
henkjantwb: newer ufw in intrepid add support for application profiles10:50
henkjantwb: see http://ubuntuserver.wordpress.com/ and search for ufw package integration10:51
henkjantwb: also check http://doc.ubuntu.com/ubuntu/serverguide/C/firewall.html for the updated ufw documentation10:52
twbhenkjan: I asked because on Hardy I did "ufw add smtp" and "ufw add www"; and I got the following rules:10:52
twbtcp 25; tcp 80; udp 8010:53
henkjantwb:10:53
twb...I was weirded out that it added UDP only for www.10:53
henkjanIf the port you want to open or close is defined in /etc/services, you can use the port name instead of the number. In the above examples, replace 22 with ssh.10:53
twbhenkjan: yeah, I realize that.10:53
twbhenkjan: I'm trying to understand how it decides which protocol(s) to add if you don't specify any.10:54
twbOoh, a bug.10:55
twbhttp://hpaste.org/1059610:55
twbYeah, it does a different thing if you "add 25" to if you "add smtp".10:56
twbThe latter only adds TCP, not UDP.10:56
twbIt also doesn't understand "ufw add 25/icmp", which I just tried for kicks.10:57
scuserhi all, can anyone tell me how to use .k5login to login without password ?11:21
papyromancerI've gone through the goog and the book, but I'm having trouble getting outside network access to this samba share (local subnet access is great) there's no firewall installed (it think) on this (ubuntu) system, router is setup to DMZ to this server. I can ssh from client to server and vice versa. I try the 'echo "hello" telnet xxx.xxx.xxx.xxx 139' to the server from the client and get "telnet: Unable to connect to remote host: Connection tim12:13
ropetinpapyromancer: Are you sure your ISP is allowing 139 through?  I know a lot of residential ISPs will block it for security reasons12:19
ropetinI wouldn't be surprised if business class ones do too.  I can't see any immediate reason why one would want an Internet available samba share12:19
papyromancerropetin: I am business class... Let me call them up12:20
papyromancerhang on ;)12:21
ropetinOK :D12:21
=== ogra_ is now known as ogra
papyromancerropetin: comcast blocks those ports system wide at the request of homeland security and cannot unblock them... LOL .... time to build an ssh tunnel from my ec2 instance :D13:07
Deepsmight i recommend a vpn instead13:11
ropetinpapyromancer: yeah, as I thought.  I'd go with Deeps suggestion if it really has to be a samba share13:11
Deepsor infact, anything not tcp based unless you absolutely have to13:12
papyromancerDeeps: I'm going with the tunnel :)13:12
ropetinOpenVPN is so easy (relatively) to get running, I'd highly recommend it13:13
Deepspapyromancer: up to you, but tunnelling anything over tcp is best avoided unless absolutely necessary13:13
papyromancerDeeps: Why do you say so?13:13
Deepsdue to the nature of how tcp works - it's a "reliable" protocol13:13
Deepsif a packet gets lost, it rerequests it13:14
papyromancerDeeps: So service will be spotty?13:14
papyromancerand slow?13:14
Deepsin the mean time, your protocol that your tunnelling might also have error handling too, at which point that also rerequests over the tunnel13:14
Deepsso you get a fair bit of duplication and unnecessary slowdown13:15
papyromancerDeeps: I'm still gonna go for it, I'm stubborn13:17
papyromancerStarted a forum thread: http://ubuntuforums.org/showthread.php?p=5833814#post583381413:17
papyromancerI'll let you know how it goes.  And thanks for the advice :)13:18
Deepsalrighty13:18
Deepsgl, enjoy13:18
uvirtbot`New bug: #273099 in net-snmp (main) "No debug symbols package for net-snmp" [Undecided,New] https://launchpad.net/bugs/27309913:26
NCommandersoren, you are now running pinkie if your fully up to date13:30
sorenI believe I am.13:31
soren-> #xubuntu-devel13:32
psufanhey14:03
psufanhow do I compile newer 2.6.2x kernels on ubuntu 6.06lts if it's even possible, last time I tried it broke the system14:03
henkjanpsufan: why do you want to compile your own kernel?14:10
psufanbecause 2.6.15 has a nfs crash and burn bug and the nit wit developers don't feel it warrents a patch14:11
henkjanpsufan: any option to upgrade to the next lts (8.04) ?14:18
psufannot unless vmware server 1.x is supported on top14:18
psufanor I woul dhave dumped 6.66 already14:18
slicslak__how do i add a superuser (on the cli)?  is there a special command?  or just useradd and then add that user to a bunch of groups?14:50
sorenslicslak__: Just the "admin" grop.14:50
sorengroup, even.14:50
slicslak__soren, great thanks14:51
Chipzzhenkjan: just ignore psufan - iirc, he came insulting the developers on #ubuntu-dev a couple of weeks ago14:53
* soren greps irclogs14:54
Chipzzsoren: not 100% sure, but the name rings a bell and his behaviour matches14:54
Chipzzalso the "6.66" was something I recall from then14:55
Chipzzor something along those lines14:55
sorenChipzz: Yeah, just found it. *shrug*14:57
henkjanChipzz: ah, okay14:58
nxvlmorging14:58
slicslak__soren, if i want the user to have their own group, do i need to create that group first?   useradd doesn't seem to have that option.15:04
slicslak__right now i have:  useradd -G admin -m name15:04
sorenUse adduser instead.15:04
sorenI'm not sure about useradd, but I know that adduser creates a group for each user.15:05
slicslak__soren, right, thanks15:10
nxvlkirkland: ping15:18
pitihi. I'm experiencing some trouble with libpam-chroot. I'm experiencing the same kind of problem than https://answers.launchpad.net/ubuntu/+question/3370715:22
kirklandnxvl: pong15:22
pitimust I use the patch proposed ? why there isn't an update on the package ?15:22
nxvlkirkland: is it normal that my desktop show a "Private" icon?15:23
nxvlkirkland: i mean, i have an icon of a mounted drive called "Private" that calls to my Private crypted forlder15:23
nxvlkirkland: as if it were a flash drive or something15:23
kirklandnxvl: right, that's because "Private" is mounted15:23
kirklandnxvl: from a command line, run "mount"15:24
nxvlyup, that i know, but /home is also mounted and doesn't appear in there15:24
nxvlkirkland: because to have such an icon will be the first things people ask "why you have that, what you have inthere" and such stuff15:25
nxvlkirkland: so it will only raise and interest of other people (maybe system users) on try to break it15:26
kirklandnxvl: okay.15:30
zulmathiaz: does the patch to #273043 look reasonable to you it does to me16:30
mathiazbug #27304316:30
uvirtbot`Launchpad bug 273043 in apache2 "/etc/init.d/apache2 routinely prints to stderr if few modules are enabled, causing logrotate to spam in cron" [Undecided,New] https://launchpad.net/bugs/27304316:30
mathiazzul: seems like a good patch16:34
zulthats what I thought but I can see why you want those error messages to cron16:36
pitiHi I'm experimenting a trouble with libpam_chroot : I want to chroot someone from ssh, but when I login, I have the welcome message, but imediatly put me out. on the log side, I founded : http://pastebin.com/m7b33ccfb , and possibly a bugreport which may be linked (https://answers.launchpad.net/ubuntu/+question/33707 )16:38
pitithe same config worked with gutsy, but no longer with hardy. is it a regression ?16:38
psufanhow do I find out if a kernel update for 6.06lts includes the nfs crash and burn bug and root hole fix16:40
zulmathiaz: its for hardy by the looks of it16:41
mathiazpsufan: do you have a CVE number ?16:41
mathiazzul: hm - it's probably won't qualify for a SRU.16:42
psufanhang on16:42
psufanthis is what I have16:42
psufanhttps://lists.ubuntu.com/archives/dapper-changes/2008-June/012713.html16:42
zulmathiaz: probably not16:43
psufanhmm16:46
psufanbox is still only at -5116:46
zulpiti: it looks like it to me16:49
psufanalso16:50
psufanwhat the HELL is with nano in 6.06.2 lts16:50
psufanif you hit enter to start a new blank line it suddentely smashes all the lines together16:50
psufanthis has almost driven me to sucide16:50
sorenpsufan: Nano hasn't been touched in dapper.16:51
pitizul: I also found a package on that page : https://bugs.launchpad.net/ubuntu/hardy/+source/libpam-chroot/+bug/237308 . I'm trying it, but shouldn't it be on a repository ? (like -update or -security)16:52
uvirtbot`Launchpad bug 237308 in libpam-chroot "libpam-chroot broken" [Undecided,Confirmed]16:52
sorenIt's the exact same as it was when Dapper was first released.16:52
superdumphello16:52
superdumpis it reasonable to ask about caching dns server stuff here?16:52
zulpiti: its definently a SRU imho16:53
sorensuperdump: Probably :)16:53
superdumpi'm looking to set up caching dns on a server on my lan and use that for internet dns lookups16:54
superdumprather than always using my isp/opendns16:54
superdumpespecially as sometimes they seem intermittent16:54
pitizul: what do you mean by SRU ?16:54
superdumpfirstly, what dns server would people recommend for a caching dns server?16:54
superdumpi saw something about pdnsd but i was expecting that bind would do it16:54
zulpiti: it should be in -updates16:55
superdumpi haven't used a dns server before, but once i know what is recommended, i'll have a look around and try to get it working16:55
Deepsbind would do the job, and could happily bypass your isp's dns too16:55
zulpiti: ill have a look16:55
sorensuperdump: If all you're ever going to do is simply dns caching, it doesn't really matter much. I think both bind and dnsmasq come preconfigured to do caching.16:55
superdumpok16:55
superdumpthen i just have to figure out how to get bind working :)16:55
Deepsapt-get install bind? heh16:56
sorenWell, bind9, actually :)16:56
Deepsout of the box it pretty much does what you need16:56
Deepswell, yeah, i always forget that 916:56
superdumpyes, i read that it's supposed to16:57
superdumpwhat should i have in resolv.conf on the server? just "nameserver 127.0.0.1"?16:57
superdumpor also some public nameservers?16:58
kirklandzul: soren: I posted a pretty trivial debdiff that closes a KVM bug, https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/22526016:59
uvirtbot`Launchpad bug 225260 in kvm "control file description miss-leading" [Low,Confirmed]16:59
kirklandzul: soren: if one of you could sponsor that, i'd appreciate it16:59
sorenI don't agree with the change, FWIW.17:00
sorenThe x86 architecture includes both x86 and x86-64.17:00
psufanwell something is causing nano to spaz17:02
psufandunno if it has to do with being over telnet to a virtual serial port on the blade or not17:03
kirklandsoren: i understand that x86 includes x86_64, but it seems some users are confused17:03
sorenkirkland: Also, kvm works on powerpc, s390 and ia64 now as well.17:03
kirklandsoren: mark the bug as "Invalid" then, with your reason17:03
kirklandsoren: that's a good point, i was wondering about17:03
sorenkirkland: Well, we can certainly clarify the description somehow.17:03
sorenPerhaps change it to "i386 and amd64" or "x86 (both 32 and 64 bit)"17:03
kirklandsoren: shall i rework the text more generically?17:03
sorenI think that's probably the best choice.17:04
sorenI never liked the original description.17:04
kirklandsoren: should i bother mentioning ppc or s390, since we don't really support those?17:04
sorenkirkland: I don't think leaving them out and explicitly mentioning i386 and amd64 seems right.  If you could come up with something more generic, that would be cool.17:06
kirklandsoren: uno momento17:06
Fenix|workGreetings and Salutations17:09
Fenix|workI have a ufw question and legacy iptable rules17:09
Fenix|workI'm going to add some prerouting rules to before.rules17:10
Fenix|workI'm looking at the server guide but have a question17:10
Fenix|workthey show :POSTROUTING ACCEPT [0:0] then have their postrouting rules17:10
Fenix|workwould I use :PREROUTING ACCEPT [0:0] before placing my prerouting rules?17:11
jdstrandFenix|work: just put :PREROUTING ACCEPT [0:0] and :POSTROUTING ACCEPT [0:0] right next to each other, and first in the *nat table, then you can have the rules in any order after those two17:12
jdstrands/right next to each other/one after the other/17:12
kirklandsoren: http://pastebin.ubuntu.com/49347/17:13
kirklandsoren: see if that looks any better to you17:13
Fenix|workjdstrand, thanks17:13
Fenix|work:)17:13
jdstrandnp17:13
sorenkirkland: Hmm... I kind of see your point about not mentioning the ones we don't support. We don't actually currently build the s390, ia64 and powerpc versions right now.17:17
kirklandsoren: yeah, that's awkward, IMHO17:17
sorenYes, "currently right now".17:17
Fenix|workjdstrand, you wouldn't happen to know which protocols/ports that squid can actively and safely cache would ya? :)17:17
kirklandsoren: another option: http://pastebin.ubuntu.com/49349/17:18
lukehasnonamekirkland: editing the 8.10 server guide kvm section?17:18
kirklandlukehasnoname: no, kvm package description17:18
jdstrandFenix|work: it listens on 3128, by default IIRC it can cache for 80, 443 and ftp, but you'll likely need to check the docs for that (or at least squid.conf)17:19
sorenkirkland: That works. Only problem is that we have to change it when we add the new architectures. meh, that's probably fine. Let's go with that.17:19
Fenix|workjdstrand, yeah, I'm looking at the docs now17:19
sorenkirkland: How about I give you a day or so to come up with more patches, so that we can batch them together?17:19
kirklandsoren: Okay.  I think that control file will be the least of our changes if/when we add s390 :-P17:19
Fenix|workhttp/https, ftp, rsync, gopher, wais, http-mgmt, gss-http, filemaker, multiling http, cups, rsync, SWAT17:19
kirklandsoren: that's perfectly fine17:20
Fenix|workjdstrand, where does ufw log to?17:26
jdstrandkern.log17:26
jdstrand(it's just iptables logging)17:27
jdstrandsudo ufw logging on17:27
Fenix|workthat's already on17:27
jdstrandsee 'man ufw' for details17:27
Fenix|workany way to fine tune what gets logged?17:27
Fenix|workmy network generages a tonne of broadcast traffic, and it's a waste of log file to see it17:28
jdstrandFenix|work: not via the ufw command, no17:28
jdstrandFenix|work: you can add rules to /etc/ufw/after.rules if that makes sense for your environment17:28
Fenix|workjdstrand, would -A ufw-after-input -m pkttype --pkt-type broadcast -j RETURN sufficient?17:36
Fenix|work... perhaps adding multicast in there as well17:36
jdstrandFenix|work: there are example of using BROADCAST and MULTICAST in after.rules and before.rules17:38
jdstrandyou might check there and 'man iptables' for what will be most appropriate for your environment17:38
Fenix|workjdstrand, I didn't see any examples in my after.rules ... so I went IPTables style instead... I noticed the "don't log noisy services by default" used RETURN instead of DROP17:39
kirklandsoren: I'm closing https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/89399 as "Wont Fix"17:40
uvirtbot`Launchpad bug 89399 in kvm "kvm update fails, if group "kvm" already exists and has non-system ID" [Undecided,Won't fix]17:40
kirklandsoren: i added a note as to why...  let me know if you disagree17:40
Fenix|workbut adding -A ufw-after-input -m pkttype --pkt-type broadcast -j RETURN eliminated broadcast from my log file17:41
Fenix|workso I'll settle with that17:41
jdstrandFenix|work: that is simply to get out of the ufw-not-local chain and back into ufw-before-input for processing17:41
jdstrandFenix|work: that is likely what you want to do, as IIRC, you are using default ACCEPT17:42
Fenix|workcorrect17:42
jdstrandso you avoid the 'BLOCK NOT-TO-ME' logging17:42
Fenix|workso far working as expected17:44
Fenix|workotherwide I'd drop it17:44
Fenix|worktime to test out my new gateway / proxy server17:46
Fenix|workthanks jdstrand17:46
sorenkirkland: Looks fine. Thanks.17:47
kirklandsoren: zul was about to sponsor that description debdiff... did you want him to hold off on that?17:48
sorenkirkland: I'm not really insistant either way.17:50
kirklandsoren: regarding https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/193531, you were suggesting a README.PXE-boot since we don't have the source to a working PXE bios for an emulated card?17:50
uvirtbot`Launchpad bug 193531 in kvm "pxe booting not supported" [Undecided,Confirmed]17:50
kirklandsoren: I can try to hack up that README and add it too, to close that bug, if you think that's sufficient17:51
sorenkirkland: Oh, since then, I've added a new package called kvm-pxe which solves the problem.17:51
kirklandsoren: ah, nice17:51
kirklandsoren: i'll close that bug pointing to that package17:51
zulkirkland: soren gave his blessings on that bug?17:55
kirklandzul: he blessed the text, said he'd sponsor a stack of kvm changes in a few days, if i wanted, or you can do them incrementally17:55
kirklandzul: personally, i'd rather my changes sponsored incrementally if possible17:56
kirklandzul: i'm trying to reduce the kvm queue17:56
zulkirkland: okies17:56
kirklandsoren: looking at https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/188878, do you mind if I add liw's kvm-ok shell script?17:59
uvirtbot`Launchpad bug 188878 in kvm "Utility to see if kvm acceleration can be used" [Undecided,New]17:59
Fenix|workjdstrand, how do I open up ufw to allow everything18:20
Fenix|workI appied ufw default accept and still it blocks18:20
Fenix|workerr allow18:20
jdstrandFenix|work: yes, you need to follow that with 'sudo ufw disable ; sudo ufw enable'18:20
Fenix|workstill is blocking18:20
Fenix|workdo I have to clean up the before and after rules?18:21
jdstrandFenix|work: you shouldn't with the defaults18:22
jdstrandof course you'll need to check anything added18:22
jdstrandby you18:22
Fenix|workI only added *nat prerouting rules18:22
Fenix|workI have a single homed box so I didn't add any forwarding/masquerading rules18:22
zulkirkland: lemme know which ones you want uploaded18:23
Fenix|work(there's a COMMIT right after my prerouting rules... and *nat is before *filter18:23
jdstrandFenix|work: can you paste it somewhere?18:23
kirklandzul: the last debdiff in https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/22526018:24
Fenix|workmost definately18:24
uvirtbot`Launchpad bug 225260 in kvm "control file description miss-leading" [Low,In progress]18:24
Fenix|workjdstrand, http://rafb.net/p/frMr8C26.html18:27
zulkirkland: done18:28
lhnnnothing like deleting one's /bin dir, eh?18:28
kirklandzul: sweet18:28
kirklandzul: i might have a few more coming today18:28
zulkirkland: lemme know so I can queue them up18:28
kirklandzul: no problemo!18:28
jdstrandFenix|work: the format looks fine (though you probably don't need the POSTROUTING line since you aren't doing that18:29
Fenix|workjdstrand, my kern.log has the following for all gateway operations...18:30
Fenix|workSep 22 13:09:11 proxy kernel: [ 1213.921916] [UFW BLOCK INPUT]: IN=eth0 OUT= MAC=00:1f:29:0e:e9:48:00:0c:29:0c:75:ea:08:00 SRC=172.16.0.223 DST=172.16.0.4 LEN=52 TOS=0x00 PREC=0x00 TTL=128 ID=762 DF PROTO=TCP SPT=49251 DPT=8000 WINDOW=8192 RES=0x00 SYN URGP=018:30
jdstrandFenix|work: one word of caution. because ufw doesn't manage these rules, it won't actually flush them when doing 'ufw disable' and the like18:31
jdstrandFenix|work: so if you want to start fresh, do 'iptables -F -t nat'18:31
jdstrandFenix|work: and you disabled and enabled?18:32
Fenix|workyes18:32
Fenix|workand rebooted a couple of times :)18:32
Fenix|workI see the ufw-not-local DROPS all18:33
jdstrandFenix|work: can you access port 8000 directly? eg 'telnet proxy 8000'18:34
psufanwhere do I go18:34
psufanto browse updates released for a ubuntu version18:34
jdstrandFenix|work: or nmap -Po -p 8000 proxy18:34
psufanso I can check changelogs etc18:34
Fenix|workjdstrand, the proxy works fine18:34
Fenix|workit's when acting as gateway that doesn't18:34
Fenix|workso bypassing the proxy18:34
Fenix|workalthough kern.log says that all traffic destined to 8000 is blocked as well18:35
Fenix|workUFW BLOCK INPUT18:35
jdstrandFenix|work: can you paste 'iptables -L -n -v' somewhere?18:36
Fenix|workhttp://rafb.net/p/nw41S616.html18:37
Fenix|workjdstrand, nmap says 8000 is http-alt18:37
Fenix|workand it's open18:37
jdstrandFenix|work: and iptables -L -n -v -t nat18:39
Fenix|workhttp://rafb.net/p/pCjaOf41.html18:40
jdstrandFenix|work: I feel silly. what you are seeing is from an unfinished item on the TODO list: "Default allow logging messages aren't correct in after*.rules"18:43
jdstrandFenix|work: is it actually blocking or just saying it is blocking, but everything works fine?18:43
Fenix|workgoing to gmail.com fails18:44
kirklandzul: I just attached a debdiff to solve https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/188878 ... i'd be interested to know if soren is strongly against it18:44
uvirtbot`Launchpad bug 188878 in kvm "Utility to see if kvm acceleration can be used" [Wishlist,In progress]18:44
kirklandzul: assuming soren isn't -1 on it, i think it's ready to sponsor18:44
Fenix|workjdstrand, and windows update isn't working either18:45
jdstrandFenix|work: so does this work:18:47
jdstrandhttp_proxy="http://proxy:8000" elinks -dump http://www.google.com18:48
jdstrand(assuming http://proxy:8000 is correct18:48
zulkirkland: cool18:48
zullemme go check18:48
jdstrandFenix|work: you can check /var/log/squid/access.log on proxy to see if it is connected there18:48
Fenix|workjdstrand, the proxy is working...18:49
Fenix|workthe box as a gateway isn't working properly18:49
jdstrandFenix|work: ok, then it is a problem with the redirection18:49
Fenix|workwhat redirection?18:49
zulkirkland: little overkill me thinks but we'll see what soren says18:49
Fenix|workif it isn't squid, it should go straight through18:49
jdstrandFenix|work: you are redirecting ports18:49
Fenix|workno, only have one adapter18:49
kirklandzul: how so?18:49
* jdstrand is confused18:50
Fenix|workjust redirecting 80/443 and 2118:50
Fenix|workok18:50
Fenix|workI'm redirecting 80/443 and 2118:50
Fenix|workthey're fine18:50
Fenix|workbut when it's a non-squid port (ie, no redirection) its is failing18:50
Fenix|work(like windows update for instance)18:50
zulkirkland: its just easier to put it in the init script I agree with soren on that one18:50
Fenix|workjdstrand, I've tried to set up this box as a transparent proxy18:51
jdstrandFenix|work: what is the network topology for the affected systems?18:51
Fenix|workI'm replacing my default gateway with this box18:52
KapliHello18:52
Fenix|workjdstrand, star18:52
kirklandzul: okay, if you think so, then close the bug as a "Wont Fix" with your justification.  i thought the binary was small, simple, and correct enough to just drop in place for anyone who might find it useful.18:52
Fenix|work1000-BaseT18:52
zulkirkland: i think soren should have the last word though18:53
KapliI have a problem, my server was working fine until today when i rebooted it using the command reboot, when it came back up i couldnt connect to it through the outside and i couldnt connect to it any way and now i try to type ifconfig but nothing shows up18:53
kirklandzul: true.18:53
zulkirkland: soren will turn green with rage if we did that ;)18:53
zulhulk...smash..18:54
kirklandzul: did what?  applied that patch?  or closed "Wont Fix"?18:54
zulapplied the patch18:54
kirklandzul: k18:54
kirklandzul: well, i kinda noted that soren should probably look at that one first ;-)18:54
zulyep I agreee :)18:54
kirklandzul: i mean, the patch "solves the bug", but soren should probably decide if the bug is valid or not18:55
trashguyKapli, did u try enabling the device?18:55
zulkirkland: of course18:55
Kaplienabling what device?18:55
jdstrandFenix|work: so the ufw firewall that I have been looking at is on a different machine than the squid proxy?18:55
trashguyKapli, liek ifconfig eth0 up18:56
trashguyor whatever its labeled as18:56
Kaplii dont really understand whats going on now because i type ifconfig and nothign shows up usually it would show up loads of info18:56
trashguyno loopback?18:56
Kaplino it doesnt say the ip and the mac address and stuff18:56
Kapliit just goes back to the stuff18:57
Kapliit doesnt even say wrong command18:57
Kaplibe right back18:58
Fenix|workjdstrand, same machine18:59
Fenix|workwithout ufw running and iptables set manually, everything works19:00
Fenix|work(after clearing iptables)19:00
jdstrandFenix|work: can you give me all the commands you used for getting it to work outside of iptables?19:01
Fenix|worksure19:01
jdstrandFenix|work: (just paste them)19:01
Fenix|workok19:01
Kaplitrashguy, ifconfig eth0 up19:04
Kaplididnt work either19:04
Kaplithe command just doesnt give any result, doesnt even say wrong command or anything19:04
Ali_ixKapli: try: sudo ifconfig -a19:05
trashguyheh, me runs as root forgets that stuff rawr19:06
Kapliis there any other command19:07
Kaplito check internal ip19:07
trashguywhat does sudo /etc/init.d/networking restart19:07
trashguysay19:08
Kaplisec, u see im on the phone with my dad hes the one typing the commands since im not at the server location hehe19:08
trashguybrutal19:08
trashguyIP kvm is handy now and then ^^19:08
Fenix|workjdstrand, http://rafb.net/p/7j9FVs51.html19:09
Kapliwhat is IP kvm19:10
trashguyKeyboard video mouse i think19:10
trashguyKVM switch19:10
trashguybut works over ip19:10
trashguyessentially works like you are at the local machine19:11
Kaplihuh19:11
Kapli:S19:11
Kaplidont understand19:11
Kaplianyways he typed ifconfig -a19:11
Kaplinothing happened19:11
Kapliand he also typed /etc/init.d/networking restart19:11
trashguywhat kind of server hardware?19:11
frithhi, I've been setting up the ldap replication,  however i have found a weird bug, if i delete or create an object the local cn=admin user get deleted19:12
Kapliit worked then went back to normal and he typed ifconfig again afterwards still no response19:12
Kapliwell this is just so confusing ive never had this problem before19:12
trashguyshit happens when you party naked19:12
trashguymurphys law19:12
Kaplii was at school connected through ssh changed some ssh settings and wrote reboot, it came back up but net doesnt seem to be working ...19:12
trashguycould be coincidence with some sort of hardware failure19:13
Kapligod damnit now is the worst time19:14
Kaplibut there isnt any other command than ifconfig to check ip19:14
jdstrandFenix|work: I'll look at it and see what the problem is19:14
trashguyKapli, have him do a lspci19:15
trashguysee if he sees any ethernet controller19:15
Kapliis that a command?19:15
trashguylspci19:16
Kapliomg he wrote "if config" now he doesnt know where he is19:17
trashguyu can do it anywhere19:17
trashguylspci19:17
trashguyhit enter a few time space out the prompts19:17
Kapliit says command not found he says :S19:22
trashguylspci19:22
trashguyWhat ver are you running?19:22
Kapliubuntu server19:23
Kaplithe latest19:23
trashguyhrm19:23
Kaplihowever he says lsusb worked19:23
trashguymight help if ur ethernert controller was usb :/19:24
Kapliits not :/19:24
Kapliwell how come  lspci is giving command not found :S19:24
trashguyi have no idea19:25
trashguymaybe your path is fucked?19:26
trashguytry /bin/lspci19:26
trashguylol19:26
trashguybut that would make no sense19:26
Kaplino such file or directory19:27
trashguylol19:27
trashguy/usr/bin/lspci19:28
Kaplisame error19:29
Kapli:S19:29
trashguyi dunno what to say man19:29
trashguydid the server not boot up correctly?19:29
Kaplii dont know19:30
Kaplihow can i know if it starts up correctly or not19:30
Kaplilook for errors in the startup?19:30
trashguylokoa orund in /var/log19:30
Kaplitoo difficult i think19:31
Kaplisince im on phone and i cant see it and stuff and my dads english = shit19:31
trashguycouldalso look at dmesg19:32
trashguysee if you see anything for your nic19:33
Kapliwhat do u mean by my nic19:35
trashguynetwork interface card19:35
Kaplihe cant find anything with network in there, i think my network card name is SiS something.. but he cant find anything by it19:38
trashguymaybe go in tot he bios and see if it got disabled or something :/19:39
Kaplihow19:39
Kaplii dont understand how a reboot made all this trouble :S19:39
Kaplibut considering that ifconfig19:40
Kaplidoesnt return anything19:40
Kapliat all19:40
Kapliwhat does it indicate19:40
trashguysomething is wrong lol19:40
Kaplibut what is wrong19:40
Kaplior wrong with what19:40
Kaplithe network card?19:40
trashguyis it an onboard?19:40
Kaplii think so yes19:41
trashguygo in to bios and see if its enabled19:41
Kaplioh i see19:41
Kaplihm he says that behind the computer19:41
Kapliwhere the network cable is plugged in19:41
Kaplithe light is yellow19:41
Kapliisnt it usually green19:41
Kaplior no maybe its supposed to be yellow i dont know19:41
trashguyi dunno19:43
jdstrandFenix|work: can you try:19:49
jdstrandhttp_proxy="http://proxy:80" elinks -dump http://www.google.com19:49
jdstrandFenix|work: basically, I took a stock ufw installation running only ssh, and did:19:51
jdstrand*nat19:52
jdstrand:PREROUTING ACCEPT [0:0]19:52
jdstrand-A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 2219:52
jdstrandCOMMIT19:52
jdstrandin /etc/ufw/before.rules, then did 'ufw default allow; ufw disable ; ufw enable'19:52
jdstrandand could then successfully 'ssh -p 80 host'19:52
jdstrandwhere 'host' is my virtual machine19:53
jdstrandFenix|work: yes, the logging still shows 'UFW BLOCK INPUT', which is because of the TODO item I mentioned earlier (I'll file a bug btw)19:53
jdstrandbut it all actually works19:53
Fenix|workI've been doing some testing as well, and yes it all works19:56
Fenix|worknow my only problem is squid handling windows update requests19:56
Fenix|workwhich I think I just fixed19:57
Kaplitrashguy he says theres some weird errors or sometihng on startup it says something eth0 then rs packet error something19:58
Kaplisomething loads of weird stuff19:58
Kaplithink it might be something?19:58
trashguyyes19:59
Kapliim afraid what us aid at the beginning might be right20:01
Kaplii restarted it and the network card or the pc or whatever some of the hardware is malfunctioning20:01
Kaplii guess ill have to buy a new server20:02
slicslak__i need to add a second ip address.  i'm assuming editing /etc/network/interfaces and restarting networking is still the way to go?20:02
Kaplithe one i use is just my old computer its like 6 years old20:02
trashguyconsumer hardware is known to fail20:03
trashguyyou might be able to get by adding a pci ethernet controller20:03
Kaplii will try20:03
Kapliwith another network card20:03
Kaplibut how do i go forward with that20:03
Kapliadd it and what to do20:03
trashguyid disable20:03
trashguythe onbaord in the bios20:03
Kaplilike how to install drivers and stuff20:03
trashguytypically the autodetect20:04
trashguyespecially if its an intel20:04
Kapliits asus20:04
trashguyhttps://wiki.ubuntu.com/HardwareSupportComponentsWiredNetworkCards20:05
Kapliasus isnt there :/20:07
trashguyprob dif chipset?20:07
trashguyjust liek asus makes20:08
trashguynvidia stuff20:08
Kaplii dont know20:08
Kapliits a ASUS Wireless PCI Card 11b/g Retail (WL-138g V2) i have that i can try on it20:09
trashguy...20:09
trashguyoh20:09
trashguywireless20:09
Kapliwell i dont need to use the wireless do i20:09
trashguyhttps://help.ubuntu.com/community/WifiDocs/WirelessCardsSupported20:10
Kaplihaha, my card is actually there20:10
Kapliwell whatever im so confused at the moment20:10
Kapliill postpone it until i go there myself and can look into it myself20:11
trashguyi dont generally use wireless for anything but laptops and smart devices20:11
Kaplithanks for all the help20:11
trashguynp20:11
Kaplii will be back when im there :D20:11
Kaplihave been thinking about buying a proper server from like dell or something anyway20:11
Kaplionly thing is that ill have to do all the install and config and shit again :(20:11
Kaplianyways bye bye :)20:12
trashguyi dont think he knew what nic ment20:12
Fenix|workjdstrand, ftp doesn't seem to be working20:17
jdstrandFenix|work: ftp will likely be problematic due to how it uses ports20:18
jdstrandFenix|work: I don't have the fix for it, but imagine passive connections are the way to go20:18
Fenix|workjdstrand, understandable... but if the firewall should be blocking nothing.20:18
jdstrandFenix|work: check the squid docs for transparent ftp (I'm not totally sure it's possible)20:19
Fenix|workI'm avoiding squid and FTP20:19
Fenix|worknot really worth the effor20:19
Fenix|workt20:19
jdstrandFenix|work: you had 21 redirected in one of your earlier pastes20:20
Fenix|workD'oh20:20
Fenix|workhow can I use ufw to find out which ports are disabled?20:20
jdstrandFenix|work: which ports are disabled?20:20
Fenix|workhow do I find out which ones are disabled20:21
Fenix|workbesides ufw allow 2120:21
Fenix|worketc20:21
jdstrandufw status20:21
jdstrand'man ufw'20:21
Fenix|workFirewall loaded20:21
jdstrandFenix|work: but that only works for ufw managed ports20:21
jdstrandFenix|work: right now, you'll have to do iptables -L -n...20:21
jdstrandto see all the stuff you added in before.rules20:22
jdstrand(this is also documented in the man page)20:22
Fenix|workjdstrand, ugh... I've fubar'ed this. :(20:56
Fenix|workufw isn't working as a gateway20:57
Fenix|workI removed everything and now have a stock ufw and it isn't working20:57
Fenix|workI'm reading the ufw serverguide ... makes the assumption that it's multi-nic20:58
frithwhy is it now the default not to send the hostname in dhclient?21:09
=== Nicol is now known as NicolAnEt
kirklandmathiaz: jdstrand: I see both of you commented on https://bugs.launchpad.net/ubuntu/+source/kvm/+bug/21932622:11
uvirtbot`Launchpad bug 219326 in kvm "a reboot issued from the guest shutdowns the guest instead of rebooting it" [Undecided,Confirmed]22:11
kirklandmathiaz: jdstrand: can either of you reproduce this?22:11
kirklandmathiaz: jdstrand: I'm doing some kvm housecleaning of bugs, and I suspect this one has been fixed22:11
mathiazkirkland: looking at it22:25
mathiazkirkland: FYI I still have a hardy host22:26
kirklandmathiaz: cool!  i'm copying over my image to a hardy machine i have now22:26
mathiazkirkland: you have to systems - one running intrepid as a kvm host and one running hardy as a kvm host ?22:39
nxvlmathiaz: to or two?22:39
kirklandmathiaz: i've tested hardy-guest on intrepid-host, reboot works fine22:39
kirklandmathiaz: i'm now scp'ing the hardy.img guest over to my hardy-host22:40
mathiazkirkland: nxvl: 222:40
kirklandmathiaz: as soon as that scp completes, i'll test there too22:40
kirklandmathiaz: if that works, i'm going to close the bug with 'Fix Released', unless someone else can reproduce the problem22:40
mathiazkirkland: hmm - I cannot reproduce it for now.22:44
kirklandmathiaz: you booted what kind of guest in a hardy host?22:44
mathiazkirkland: however my current setup is slightly different as I'm not using a bridged network22:44
mathiazkirkland: hardy guest on a hardy host22:44
kirklandmathiaz: i can't imagine bridged network would cause reboot to shutdown22:45
mathiazkirkland: using a logical volume with an ide bus22:45
mathiazkirkland: well - IIRC it was the kvm process that was crashing on the host22:45
kirklandmathiaz: ah22:45
mathiazkirkland: so anything could trigger this crash.22:45
kirklandmathiaz: okay22:45
mathiazkirkland: OTOH a couple of things have changed since then - a new hardy kernel22:46
kirklandyeah22:46
mathiazkirkland: the kernel guest may not be crashing the kvm host process anymore22:46
kirklandmathiaz: right.  it seems that's worthy of re-testing22:47
=== ajmitch_ is now known as ajmitch
mathiazkirkland: hm - I wasn't able to reproduce that bug.22:50
mathiazkirkland: you can mark it Fix Released AFAICT22:50
kirklandmathiaz: cool, thanks.22:51
kirklandmathiaz: i couldn't reproduce it on hardy either22:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!