/srv/irclogs.ubuntu.com/2008/10/21/#ubuntu-server.txt

sandstromI'm about to setup the firewall for my server. Do you recommend ufw or iptables?00:12
tonyyarussoIsn't ufw essentially just another frontend to iptables?00:15
tonyyarussoLooks like it, yeah.  So as far as security, it doesn't matter.00:15
uvirtbot`New bug: #286678 in samba (main) "Samba transfer of multiple files very slow" [Undecided,New] https://launchpad.net/bugs/28667800:23
osmosisdoes linux support AHCI RAID?00:23
=== golb_ is now known as golb
zulnijaba: yeah something like that but it has to be a built smarter because afaik xen is not configured in the -generic kernels02:07
krautmoin07:43
BlueT_moin07:53
scuserhi all, does any one know how to force a linux box not to use simple bind when trying to login ?08:12
uvirtbot`New bug: #286828 in samba (main) "CIFS share broken after upgrade from 8.04 -> 8.10" [Undecided,New] https://launchpad.net/bugs/28682808:12
scuserhi all, does any one know how to force a linux box not to use simple bind when trying to login ?08:29
RockHoundscuser: you are still at it?08:37
scuserRockHound: yes :'(08:37
RockHoundhave you asked in other chats? openldap, kerberos etc?08:37
scuserRockHound: I'm trying at ubuntu and openldap but in vain08:38
RockHoundscuser: maybe you should rethink how you phrase the question08:44
scuserRockHound: simply now I found that I need to let the client know somehow how to bind, I think the user to bind and the method but I don't know how or where to configure this08:46
scuserRockHound: the client now try to use simple bind and the server deny this and I want the client to use another method other than simple bind. This is the question now08:48
RockHoundagain: which tools / services are you asking your question for? No one here can read your mind of what your setup looks like.08:48
scuserRockHound: I'm using ubuntu 8.04 I have installed kerberos 5, slapd and ldap-utils as my client those are the tools I've installed08:50
scuserRockHound: In the startup of the system I want the system to contact ldap server to get the user info so I get it a ticket and I want the system to use it when It's trying to connect to ldap not to use simple bind as this is risky and insecure08:51
sorenscuser: I think you'll have more luck if you ask how to get it to "do X" rather than ask how to get it to "not do Y".08:58
sorenscuser: The answer to the latter is always simple: Turn the machine off. :)08:59
RockHoundsoren: ;)09:02
RockHoundscuser: to get a helpful answer, rephrasing the question to get a precise and accurate short description of what you want to do. I am sure that the openldap chat can help you then.09:03
scuserok thanks a lot :)09:04
RockHoundand googling for kerberos, sasl, ldap, pam should really show you something09:04
uvirtbot`New bug: #286851 in php5 (main) "CVE-2008-3658,2008-3659,2008-3660" [Undecided,New] https://launchpad.net/bugs/28685109:12
=== uvirtbot` is now known as uvirtbot
scuserhi all, does anyone know how to make a script that runs automatically and renews a kerberos ticket in certain time every day?10:06
nijabascuser: cron would allow you to run such a script on a regular basis.  now I have no clue what the kerberos ticket renewal would look like10:12
scusernijaba: It's just using kinit command to get a new ticket after the old one expires10:13
nijabascuser: then you should be set to add it to your user's cron10:13
scusernijaba: so what packages I have to install to have a cron and add my script to it?10:15
nijabascuser: nothing, should be installed by default.  see http://manpages.ubuntu.com/manpages/hardy/en/man1/crontab.html10:15
phaidroshi, where is the correct place to report a failing ubuntu mirror? (debian.charite.de doesn't have /ubuntu anymore)10:15
henkjanphaidros: #ubuntu-mirrors10:17
phaidroshenkjan: thx10:17
nijabaphaidros: see also http://www.ubuntu.com/getubuntu/mirror/410:17
=== golb_ is now known as golb
scusernijaba: I can't find cron.allow or cron.deny and I can't find any crontab for any user on my system how can I add a crontab for a user and add scripts to it?10:39
nijabascuser: crontab -e should add it for you, IIRC10:39
scusernijaba: and what to write in that file?10:40
hadsman crontab will show you10:40
wo0fyo12:02
wo0fhow easy is it to set up Ubuntu Terminal Services?12:02
wo0fis there just a meta package and gui interface?12:02
RockHoundwo0f: take a look at ltsp12:20
gabryfan82I am A server for only apache and php, i use gmail (google apps), i should used the php mail function, what MTA I use, what configure this?12:59
gabryfan82thank's12:59
gabryfan82thank's13:01
gabryfan82I am A server for only apache and php, i use gmail (google apps), i should used the php mail function, what MTA I use, what configure this?13:01
gabryfan82I am A server for only apache and php, i use gmail (google apps), i should used the php mail function, what MTA I use, what configure this?13:03
henkjangabryfan82: try postfix13:03
gabryfan82ok i try this13:03
gabryfan82now13:03
gabryfan82apt-get install postfix13:04
gabryfan82I HOW CONFIGURE THIs?13:04
gabryfan82only local?13:05
henkjanplease, don't use CAPS13:05
gabryfan82yes sorry13:05
gabryfan82only local?13:05
gabryfan82i how configure this?13:05
gabryfan82only local?รน13:05
henkjani suppose you wan't to send mail from the server13:05
henkjando you want to use a smarthost (smtp server from your provider)13:06
henkjanelse choose internet13:06
gabryfan82only server -> user don't user -> server13:06
gabryfan82site internet?13:06
gabryfan82msarthost use ssl?13:06
gabryfan82for gmail?13:07
henkjandon't use smarthost13:07
henkjanuse internet site13:08
gabryfan82ok13:08
gabryfan82i try this13:08
gabryfan82function on NAT also?13:09
henkjanthat should also work behind nat13:12
gabryfan82dont work13:13
gabryfan82how configure php?13:13
henkjanwiki.ubuntu.com13:13
henkjanand search13:13
gabryfan82ok thank's13:13
ScottKAny documentation on which Sun boxen are supported by the sparc port?13:14
zulmodern sparc13:15
ScottKzul:  Is a 4800 modern (I've no idea about Sparc.  Just it's come up somewhere else)13:16
ScottKI don't even know if that's Sparc or x86 actually.13:16
zulno idea13:18
henkjan4800 looks like sparc highend (max 12 cpus)13:18
RockHoundhttp://en.wikipedia.org/wiki/Sun_Fire13:26
ScottKThanks.13:33
sandstromTrying to setup an SSH tunnel, using Localforward 3305 localhost:3306. but it doesn't work13:46
sandstromI've setup sshd to allow AllowTcpForwarding yes13:47
sandstromany suggestions?13:47
_rubenhmm .. what was that command again to map dm-X names to /dev/mapper/Y names ?14:58
=== sme2k8 is now known as andre
=== andre is now known as Guest59742
Helder_GeocreteHey15:49
Helder_Geocreteneed some advice here on a new server15:49
Helder_Geocreteanyone?15:49
ScottK!ask | Helder_Geocrete15:50
ubottuHelder_Geocrete: Please don't ask to ask a question, ask the question (all on ONE line, so others can read and follow it easily). If anyone knows the answer they will most likely answer. :-)15:50
Helder_Geocretethe question is simple...I need to install a new server on this new company i'm working on...and they want to use a MWSBS 2003 /2008. But i'm more inclined to use a linux distro, in this case, ubuntu... So i need to know more about the USE distro... in comparison to MSWSBS 2003/200815:52
Helder_Geocretethanks in advance :)15:53
ScottKWhat functionality are you interested in?15:53
=== Guest59742 is now known as sme2k8
Helder_Geocreteactive directory (seems I cannot find it in USE), mail server features, file server and security...15:55
Helder_Geocreteps: newbie in ubuntu...15:55
Helder_Geocrete:$15:55
KoonHelder_Geocrete: Full Active Directory features are not available, we can do a NT4 PDC at best, or a AD domain member afaict15:57
KoonHelder_Geocrete: for the other features see the Server Guide15:58
Koonhttp://doc.ubuntu.com/ubuntu/serverguide/C/15:59
Koonthat should give you information on how to set up things16:00
Helder_Geocretewell, i'm mostly interested in member login /authentication, printer server and file server...so maybe it will do the trick16:01
Helder_Geocretethanks for the info :)16:02
thefishHelder_Geocrete: thats all NT4 domain stuff anyway, samba does that but be aware that you wont have the nice windows GUIs to do it all (you also wont have to deal with SBS)16:02
Helder_Geocretewell...the gui's aren't the problem...i like some hardcoding from time to time :)16:03
brewmasterhas anyone ever gotten a "413 Request Entity Too Large" error for "/!svn/vcc/default" in subversion?16:03
Helder_Geocretethanks for the info once again...be going now16:04
brewmasteri'm using Apache/2.2.4 (Ubuntu) DAV/2 SVN/1.4.416:04
=== trashguy_ is now known as trashguy
kirklandmathiaz: intrepid amd64 server manual installation to raid1 on kvm disks succeeded17:11
mathiazkirkland: great - let's see if raid0 and raid5 are working17:12
mathiazkirkland: it may just be an issue with partman-auto-raid that gets stuck17:12
kirklandmathiaz: let me check booting degraded right quite17:12
kirklandquick17:12
kirklandmathiaz: boot degraded continues to work, great17:14
kirklandmathiaz: in all of my tests, i have one large / filesystem, and one small swap17:18
mathiazkirkland: right - for raid0 and raid5 you'll have to create another partition for /boot17:19
kirklandmathiaz: right17:19
nijabanealmcb: A quote for you "It's not about who votes, but about whom is counting the votes" - attributed to Joseph Stalin17:19
nealmcbnijaba: yup - very true.  I've got something like that on a t-shirt17:36
nealmcbif there are any django, setuptools, xml, or windows gurus out there who want to help us do a world-class audit of the election this year in Boulder CO, check out http://neal.mcburnett.org/blog/2008/10/18/electionaudits-software-help-audit-election/17:40
mdzkirkland: bug 284107 has a request for your input17:51
uvirtbotLaunchpad bug 284107 in partman-target "Filesystem on iSCSI should have the _netdev option in /etc/fstab" [Medium,Confirmed] https://launchpad.net/bugs/28410717:51
mdzkirkland: dendrobates seems to say that it's not necessary yet17:52
kirklandmdz: i'll add a comment there, but here's the skinny...17:52
kirklandmdz: when we rsync with debian open-iscsi for jaunty, there will be some significant improvements in terms of the boot procedures, including a blip of code in the init script that says:17:53
kirkland        log_daemon_msg "Mounting network filesystems"17:53
kirkland        MOUNT_RESULT=117:53
kirkland        if mount -a -O _netdev >/dev/null 2>&1; then17:53
kirkland                MOUNT_RESULT=017:53
kirkland                break17:54
kirkland        fi17:54
kirkland        log_end_msg $MOUNT_RESULT17:54
kirklandmdz: we don't currently have that code in intrepid (and I'm not proposing we add it)17:54
kirklandmdz: however, if we do add _netdev to iscsi fstab entries, it could help us on upgrades from intrepid -> jaunty17:54
kirklandmdz: otherwise, we'll need some logic to figure out what fstab entries are iscsi and need _netdev added at upgrade time17:55
kirklandmdz: https://bugs.edge.launchpad.net/ubuntu/+source/partman-target/+bug/284107 updated accordingly17:59
uvirtbotLaunchpad bug 284107 in partman-target "Filesystem on iSCSI should have the _netdev option in /etc/fstab" [Medium,Confirmed]17:59
zulmathiaz: are you handling that bacula bug?18:01
mathiazzul: yes18:03
zulk18:03
mathiazzul: I've already answered18:03
mathiazzul: I'm able to boot a AMI18:03
mathiazzul: but not able to log into it18:03
zulcool18:03
mdzkirkland: ok, so there's no point at all in changing it for Intrepid unless we add the new init script code as well, which we aren't going to do18:07
kirklandmdz: fair enough18:08
mdzkirkland: I was just echoing back my understanding of what you said :-)18:12
kirklandmdz: yes, that is my recommendation18:12
kirklandmdz: i will be syncing/merging open-iscsi and working on it for Jaunty when the archive opens18:13
kirklandmdz: but I don't think it's worth change it for Intrepid now18:13
kirklandmathiaz: verified lvm install works18:15
kirklandmathiaz: RAID0 isn't working so well18:15
mathiazkirkland: does it get stuck?18:15
kirklandmathiaz: if i have a separate /boot partition, yeah gets stuck18:15
mathiazkirkland: where?18:16
kirklandmathiaz: if i don't have a separate /boot partition, it finishes, but it's not bootable18:16
mathiazkirkland: well - it's normal;18:16
mathiazkirkland: grub doesn't support raid0 AFAICT18:16
kirklandmathiaz: okay, but the hang isn't normal18:17
mathiazkirkland: could you run a ps -ef in the vm during install?18:17
mathiazkirkland: agreed. I've seen the same thing.18:17
mathiazkirkland: are you testing on an intrepid host?18:17
mathiazkirkland: and are you doing a manual partition of raid0?18:17
kirklandmathiaz: intrepid host, yest18:17
mathiazkirkland: ok - I was thinking it may be an issue with the virtualization stack18:18
kirklandmathiaz: manually partitioned, sda1 = 2G, sda2 = 128M, sdb1 = 2G, sdb2 = 128M18:18
mathiazkirkland: as we're using more then one block device to do that experiment18:18
kirklandmathiaz: sda1+sdb1 = raid0 of 4G, with /18:18
kirklandmathiaz: sda2 = /boot18:18
kirklandMatBoy: sdb2 = swap18:18
mathiazkirkland: ok - so if you don't put /boot on a separate partition the installer proceed correctly?18:19
kirklandmathiaz: it completes18:19
mathiazkirkland: ok18:20
mathiazkirkland: http://people.ubuntu.com/~mathiaz/intrepid-i386-raid5-ps-ef.png18:20
mathiazkirkland: this is the output of ps -ef when the installer is stuck18:20
kirklandmathiaz: hmm, 07root_on_raid is mine....18:20
kirklandmathiaz: i've tested the crap out of that on raid118:20
kirklandmathiaz: let me look at that code again18:21
mathiazkirkland: the fact that the install completes when you have /boot on the same partition may point to an issue with boot18:21
mathiazkirkland: you don't have a process fstab.d/hostboot?18:21
mathiazkirkland: I think that's where the problem may be18:22
mathiazkirkland: both raid{0,5} install are stuck with the same processes running18:22
mathiazkirkland: both installs have /boot on a raid1 array in order to be able to boot18:22
mathiazkirkland: I'm gonna head out. Could you investigate this raid install problem?18:31
kirklandmathiaz: yeah18:31
erichammond1mathiaz: just saw your question of long time ago: I am able to boot vmbuilder EC2 image but not connect to it.18:31
mathiazkirkland: great - I may check back later18:31
mathiazerichammond1: right - it seems that we need to get the kernel modules somehow.18:32
mathiazerichammond1: zul knows more about it18:32
erichammond1mathiaz: Been working with him over email, but our communication loop is pretty slow.  We might have different work hours.18:33
zulerichammond: hey18:33
erichammond1zul: 'lo!18:33
mathiazerichammond1: I think there is a small pond between both of you18:34
zulerichammond1: im working on it now and already have a solution and just trying to clear some stuff up18:34
zulmathiaz: nah just a border18:34
erichammond1zul: nice, look forward to it.18:34
erichammond1I'm on the US West coast, but basically keep Hawaii hours :)18:34
zuland different timezones18:35
mathiazhm - right - anyway I'm off for now. see ya later18:35
zulerichammond1: check your /msgs18:36
=== _shoot^ is now known as shoot^
ivokshi all19:08
ivokssorry, i didn't make it for the meeting :/19:08
=== _backenfutter is now known as backenfutter
jcastrolooking for -server sessions: https://wiki.ubuntu.com/UbuntuOpenWeek/Prep19:45
=== MenZa_ is now known as MenZa
cyris|i need to install some ldap tools that will allow me to do some queries against an ldap server. isn't their a package called openldap-tools or something that will give me ldapsearch?20:29
henkjancyris|: there is a package ldap-utils20:31
sommerkirkland: I keep getting a grub error 17 when trying to install raid5 using the latest iso... just fyi21:04
kirklandsommer: hey, i'm working an issue related in #ubuntu-installer, at the moment21:04
kirklandsommer: also, see bug 28711221:05
uvirtbotLaunchpad bug 287112 in mdadm "intrepid installer hangs when installing to raid0 or raid5" [High,In progress] https://launchpad.net/bugs/28711221:05
kirklandthat's just been sponsored, not on the iso yet21:05
kirklandglad to hear someone else is testing this ;-)21:05
sommerkirkland: ah cool, just wanted to make sure21:05
kirklandsommer: what does your partitioning look like?21:06
sommerkirkland: 3 6.5G ide drives, with one 12.5G partition on the raid array21:06
kirklandsommer: raid5 on / ?21:06
sommerkirkland: yep21:07
kirklandsommer: and where's /boot?21:07
sommerkirkland: on the same partition, it wouldn't let me create multiple on the raid array... or did I miss configure something?21:07
kirklandsommer: oh, that's a problem....21:07
kirklandsommer: we may need to add something to the documentation21:07
kirklandsommer: /boot can't be on a RAID0 or a RAID5 device21:08
kirklandsommer: must be on it's own partition, or a RAID121:08
sommerkirkland: ooohhh... I figured it may be something like that21:08
kirklandsommer: when I use a RAID5, I usually create /boot on my RAID1 devices21:08
kirklandsommer: but that's what's broken, at the moment21:08
sommerkirkland: the serverguide is frozen, I asked the other day to correct a typo and was denied21:09
kirklandsommer: bummer21:09
kirklandsommer: sorry, i should have thought about that21:09
sommerkirkland: ya, could we add something to the release notes?21:09
kirklandsommer: let's put an agenda item for the server guide to discuss raid5/raid1 best practices21:09
kirklandsommer: yeah, it'll need to go there21:09
sommerkirkland: sounds good21:10
kirklandsommer: i wouldn't say it's "common knowledge", but a lot of system admins understand the raid5 limitation of grub/bootloaders21:10
sommerkirkland: heh, most of my experience is with hardware raid5 :)21:10
sommerkirkland: the whole disk formating filesystem thing can get complicated pretty quick :)21:11
* sommer is just going to use fat32 from now on21:12
kandjarhi22:51
kandjarI'm having an issue with my ubuntu server, I can't seem to forward X11 app22:53
kandjarthrough ssh22:53
kandjaranyone?22:55
sommerkandjar: do you have a gui installed?22:56
kandjarno22:58
kandjarnot on the server22:59
kandjardo I need to have a X server on the server box?22:59
kandjarI m only logging through ssh to it22:59
sommerisn't that what you're trying to do?22:59
kandjarI m trying to ssh to the server23:00
kandjarusing ssh -X or -Y23:00
kandjarand having the display redirected to my remote client23:00
sommerthe server's display?23:00
kandjarbasically, I m log on a client machine23:01
kandjarand I'm trying to get: 'ssh -X server xlogo' working23:01
trashguywhats wrong with plain old SSH23:02
kandjar?23:02
kandjarI have some xapp I wanna run :)23:02
sommerI'm not sure what that is, but without a gui on the server the only thing to display is  console23:02
kandjarI m remotely logged on the server23:02
soundraysommer, trashguy: haven't you heard of X11 forwarding?23:06
sommeryes, but the machine you're forwarding needs a gui... at least when I've done it23:07
sommersince by default ubuntu-server has no gui...23:08
sommerby default anyway23:08
soundraysommer: that's what I'm wondering. I regularly forward a machine that doesn't have a full GUI installation -- but it must have some base X packages that kandjar is missing.23:09
nikkolayhi guys. I need to move some instalation, but i need to backup a few mysql db... can i copy the /var/lib/mysql to the new server?23:16
nikkolayor that doesn't work?23:17
sommernikkolay: I'd use mysqldump23:18
nikkolayok23:22
trashguysoundray, X11 on a server?23:22
nikkolaymaybe something like: mysqldump --all-databases > /home/nikko/bakcups/mysql.sql23:22
nikkolay?23:22
trashguywhat kind of insanity is this23:22
soundraytrashguy: not everything that you cannot immediately relate to is insanity23:26
soundraytrashguy: I'll give you an example, if you're interested23:26
trashguyI can see23:26
trashguyno reasoning of waisting server resources on x23:26
soundrayThat's the point, there is no wasting of resources23:27
trashguyunless you are doing some sort of thin client thing and the soul purpose is centralized desktop etc23:27
soundrayI'm running CPU intensive processes on a remote cluster. It outputs images to a filesystem local to the cluster.23:28
trashguyokay23:28
soundrayTo view those images, I log into the login server of the cluster with X forwarding enabled and launch a viewer that displays selected sections from 3D or 4D image volumes.23:28
soundrayThe graphical output is forwarded through an encrypted tunnel to be displayed locally on my (full) X server.23:29
soundrayThe remote machine needs only basic X functionality installed, e.g. xauth23:30
trashguyi did something similar with a render cluster23:30
trashguyi just set up webdav to remotely open the images23:30
soundraywhich, btw, was what was missing on kandjar's server. Now it's installed -- problem fixed23:30
soundraytrashguy: doesn't that mean that you have to transfer the entire file before it can be displayed?23:33
trashguyyes23:34
trashguyi can see23:34
soundrayThat would be a clear disadvantage for my scenario23:34
trashguyyes23:34
trashguyi agree23:34
trashguymajority of the people i see running x is to avoid command line though23:34
soundrayBurn them at the stake!23:36
soundray:)23:36
trashguyi been using freebsd to long im a cli nazi23:36
trashguy^^23:36
uvirtbottrashguy: Error: "^" is not a valid command.23:36
trashguyZimbra doesn't play nice23:37
trashguywith FreeBSD23:37
trashguyso here I am ;)23:37
soundrayContent management?23:38
trashguyExchange alternative23:38
soundrayOh, groupware23:38
soundraytrashguy: do you have a suggestion for calendar and todo lists that works well on the command line?23:40
soundrayA PIM application?23:41
trashguysoundray, not somuch on CLI23:54
trashguyi been inundated by the bras on how much they loved outlook at their old jobs23:54
trashguys/bras/brass/23:54
soundraytrashguy: I'll try 'when'23:56
trashguywe are currently using oracle calendar23:57
trashguyit iwll be nice when that is gone and I have one less solaris machine to deal with ^^23:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!