/srv/irclogs.ubuntu.com/2008/11/11/#ubuntu-server.txt

jmarsdenababs213: Are you testing the port forwarding from *outside* your local network?00:00
ababs213outside00:00
ababs213so router port forwarding to local computer ip address00:00
jmarsdenababs213: Can the local server get out to the Internet OK -- ping yahoo.com works, for instance?00:01
ababs213yes that is fine00:01
owhSo, you can ping the machine behind the firewall?00:01
ababs213but externally they cant access my basic webside00:01
ababs213yes00:01
owhDoes your router port forward port 80?00:02
ababs213i havent actually got a website just the "it works!" on apache server00:02
owhababs213: Hold on, can they see that from the outside?00:02
ababs213no they cant00:03
ababs213tcp port forward to 8000:03
owhRight, so, is your router forwarding port 80?00:03
ababs213Protocol                           Port (or Range)                           Host Port                           Timeout (sec)                                                                                                                                                          TCP                           80                           0                           8640000:04
owhababs213: To the correct IP address?00:04
jmarsdenHost appears to be empty?00:04
owhAs in, forward incoming requests to port 80 on your server address.00:04
owhjmarsden: It does :)00:04
jmarsdenPut 192.168.1.88 in there (or whatever the local server IP was)00:05
owhababs213: Yeah, you're missing some bits :)00:05
ababs213ok let me do some changes i will also need to make sure that the port forward is going to the right ip address.00:06
=== cint is now known as joeno
=== ninja is now known as Guest88115
=== Pomiel is now known as DCPom
=== Guest88115 is now known as ninja
=== Pomiel is now known as DCPom
EressolarRight. When I direct a web browser to my server's SSH port, a page with the text "SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1.2" is shown. Is it possible to turn this ssh server signature off?05:22
jmarsdenEressolar: Only by turning sshd off.05:23
jmarsdenYou could set up some sort of "port knocking" security so the port is not open except after a "knock", if you are into doing that...05:24
jmarsdenSee https://help.ubuntu.com/community/PortKnocking for info on that.  But what are you really trying to achieve?05:26
Eressolarjmarsden: well, I prefer to have the signatures off in the (very unlikely) event a security hole is discovered in ssh, so any potential attacked would not be able to easily know which version I'm running.05:27
EressolarProbably paranoia overkill, I know. I've heard of port knocking, but I don't believe my humble server is quite worth the  effort and potential headache.05:28
jmarsdenEressolar: Trouble is many ssh clients use that signature to determine how to behave, so you really can't run SSH with no signature.  Port knocking would hide SSH from attackers, at the expense of every SSH uer havingto "kock" before sshing in to your server.05:28
hadsYeah, SSH requires the version banner05:28
ScottKGenerally SSH attackers hit servers fast enough I'm pretty sure they aren't optimzing for a particular target.05:29
hadsThere's also fail2ban and those type of things05:29
jmarsdenTheoretically you could patch and recompile openssh-server to display a different version banner, but I really doubt it's worth the effort.05:30
Eressolarprobably not :p I have faith enough in my ssh config, so I ought to not worry so much over it.05:31
=== RoAkSoAx_ is now known as RoAkSoAx
uvirtbotNew bug: #296630 in openldap (main) "Modification of cn=config prevents bind at next directory restart" [Undecided,New] https://launchpad.net/bugs/29663006:16
uvirtbotNew bug: #293539 in samba (main) "package samba failed to install/upgrade: Conflicts found! Please edit `/etc/samba/smb.conf' and sort them out manually." [Undecided,Incomplete] https://launchpad.net/bugs/29353907:23
Trustn01can any body help me with sql and freeradius07:43
krautmoin08:05
BergcubeI am in the process of setting up eGroupware on Ubuntu 8.10 server.  I want to do user authentication from M$ AD.  I do not want the Ubuntu server to act as a DNS or LDAP server on the LAN. Egroupware says "Checking extension ldap is loaded or loadable: False".  Does anybody know what package I should install to make eGroupware work without installing "too much"?08:26
BergcubeOr maybe even: How do I get Ubuntu 8.10 server to authenticate from M$ AD?08:31
jmarsdenBergcube: I suspect that is just looking for a php ldap extension.  Did you try installing php5-ldap ?08:31
jmarsdenThe second question is harder :-)08:31
Bergcubejmarsden~  Maybe.  No, I didn't try installing anything yet......  I am googling.  Usually I find it's best to read first and install later....08:32
jmarsdenSee https://help.ubuntu.com/community/ActiveDirectoryHowto for some clues on that08:32
BergcubeThe second Q need not be answered if I get the first under control.  :-D08:33
jmarsdenBergcube: OK.  Installing php5-ldap is safe, it doesn't change how normal Ubuntu user auth is done or anything like that.08:34
BergcubeWill try that then!08:35
Bergcube:-)08:35
BergcubeTurns out it was already installed.  So then it probably wasn't it.08:36
jmarsdenOK.  So is there and egroupware extension called ldap that it could be looking for?08:42
BergcubeCould be.  But AFAIK I have installed ALL the EGW packages.  At least the EGW metapackage description says it does so.  But good idea!  I will search the respository.08:43
BergcubeHah!  The solution was a true nobrainer.  I am ashamed.  A quick reboot and the error was gone.08:50
jmarsdenIt's nice when the answer is that simple :-)08:52
BergcubeVery nice.  And a lot simpler.08:53
ascentRebooting solves all the problems!08:54
BergcubeThen somebody should reboot the US economy.  I hear there are some rumours of trouble over there.08:54
ascentPerhaps we should reboot the world.08:54
Deepsproblems aren't just in the usa :/08:55
BergcubeWorld 2.0 !08:55
ascentAJAX!08:55
BergcubeWell, back to configuring.  TTFN good people!08:56
maxstirner1hello, i am having problems getting the standard hardy ubuntu courier pop3/imap going (as installed by tasksel) - any pointers for post-install configuration?10:15
sannnnWhen I install bugzilla3 on ubuntu 8.10 server edition I end up with a fine installation according to ubuntu but where to configure or how to use the thing is totally unclear. Anyone here got some experience?10:48
sannnnFor instance I found /usr/share/bugzilla3/debian/apache.conf which sets up a virtual host.. this doesn't work by default. For phpmyadmin I didn't have to do anything. I could really use some help10:51
Trustn01who can help me with setting up a internet server11:04
sannnnAn internet server? What do you mean router, http, ssl, mail?11:05
Trustn01have a server connected to internet want to give internet to clients and need to monitor it11:06
sannnnsomething like this: https://help.ubuntu.com/community/Router11:07
Trustn01something like that i have every thig setup server gets internet from eht0 gives out internet using dhcp on eth1  only problem is that i need to monitor connections and setup accounts11:10
Trustn01what will be the best to use to control client login and bandwith usage11:28
Deepssounds like you need some cybercafe-esque software11:29
Trustn01something like that but would like to run it on ubuntu11:30
Trustn01is there something for ubuntu11:30
Deepspersonally i have no idea, google might11:31
Deepsgoogling 'cyber cafe ubuntu' indicates other people have asked this before11:31
Deepshttps://answers.launchpad.net/ubuntu/+question/12168 looks particularly relevant to your interests11:31
Trustn01will have a look11:32
Deepsgl11:32
yann2hello11:33
yann2anyone using munin here? I am looking for feedback on runin munin with the rrds in ramfs, if anyone is doing that..11:33
ascentI'm just running it in disc-mode :)11:35
yann2I've got terrible disk issues, it may be a combination of munin and poor i/o, but I am trying to improve it11:35
Omahnkirkland: I have a question about your degraded RAID test case if you're available..12:56
wB3hello, E: method http has died unexpectedly! in guest os(kvm with ubuntu intrepid)13:12
wB3python-urllib can fetch from the same mirror normally13:12
=== Chipzz_ is now known as Chipzz
ScottKleonel: Did you also see the patch discussed on the pkg-clamav list?14:24
leonelScottK: http://lists.alioth.debian.org/pipermail/pkg-clamav-devel/2008-November/000177.html14:38
ScottKYes.  That's the one.14:39
ScottKmathiaz: I have to give regrets for the Server Team meeting today.  The main thing needed for the libdb migration task is someone to go through the rdpends and move them up to 4.6.15:01
ScottKThe only trick is packages that use transcations need special care.15:02
ScottKSince Debian has migration as a release goal for Lenny, mostly there should be patches in Debian for this.15:02
sorenScottK: I thought we already consolidated libdb to 4.6?15:07
ScottKsoren: I think Main got done.15:07
ScottKMaybe it's done and I failed to notice.15:08
sorenMaybe I'm making this all up.15:08
sorenMaybe there is no libdb at all.15:08
zuli remember doing alot of them15:08
ScottKNope.  4.2 - 4.5 are still there in Intrepid.15:08
ScottKExcept for slapd it looks based on casual observation of the apt-cache rdepends output that Main is done.15:10
sorenYeah, not even main is done. slapd depends on libdb4.215:10
sorenOh, ok :)15:11
BrunoXLambertIs there any kind of "official" inventory program in ubuntu? I mean something like ocsinventory-ng but that actually works15:20
Omahnkirkland: You're clarification on the degraded RAID booting makes perfect sense. I've run out of time for today but I'll be updating the bug report tomorrow to report that everything works successfully on both virtual hardware (VMware) and physical tin.15:30
Omahn*Your15:30
kirklandOmahn: ah, cool, thanks so much for testing15:30
kirklandOmahn: was that you, that I was responding to?15:31
Omahnkirkland: Yep.15:31
kirklandOmahn: it's a sensitive topic, "newly degraded"15:31
Omahnkirkland: I can imagine :-)15:31
kirklandOmahn: but we figured that just begged more explanation15:31
kirklandOmahn: we'll need to document it better, though ;-)15:31
Omahnkirkland: I think it's the right behaviour, just needs documenting on wherever the documentation ends up.15:31
kirklandOmahn: agreed15:31
kirklandOmahn: i think it *might* be in the mdadm manpage15:32
Omahnkirkland: And on a Ubuntu wiki page I'm guessing?15:32
sannnnIs there information (for ubuntu) or someone with experience with a bugzilla setup15:34
kirklandOmahn: well, probably the Ubuntu Server Guide, which has the "official" RAID section15:34
kirklandOmahn: and perhaps help.ubuntu.com/community, which is a wiki15:34
kirklandOmahn: there are some RAID pages there15:34
kirklandOmahn: feel free to take the lead on that one ;-)15:34
* kirkland is swamped as it it :-)15:34
Omahnkirkland: :-)15:34
* Omahn adds to the TODO list15:34
OmahnActually, I was going to ask you something earlier..15:35
OmahnI've done a slightly different test case to the one you mention in the SRU bug report.15:35
kirklandk15:35
kirklanddifferent how?15:35
OmahnIn the bug report you have both disks running independently at different times.15:35
OmahnI have always rescrubbed the array after breaking it each time.15:35
OmahnIf each disk is used independently then the user is always going to have some data loss.15:36
zoopsterspeaking of docs - will the 8.10 Official ServerGuide be posted soon?15:36
Omahn(Even if it's only a couple of minutes of logs)15:36
OmahnI suspect my results are still valid though.15:36
* Omahn heads home15:41
kirklandOmahn: yes, you're absolutely right ...  if you boot off of each disk independently (without the other), and then you boot with both attached, that's a bad scenario ;-)15:44
kirklandOmahn: i suspect that mdadm will use the more recently touched disk15:45
kirklandOmahn: but I can't confirm that15:45
\shScottK: taking care of the rest of the libdb* to 4.6 crap15:47
\shnew buildserver needs something to do ,)15:47
\shhmm...why don't we have openNMS in our repos?15:49
mncvnHi.15:56
mathiazkirkland: right - mdadm will use the most recently touched disk15:57
mathiazkirkland: I think we've already talked about that some weeks ago15:57
kirklandmathiaz: right, Omahn, mathiaz confirmed this15:57
kirklandmathiaz: howdy!15:57
mncvnEveryone can help me???15:58
mathiaz!ask | mncvn15:58
ubottumncvn: Please don't ask to ask a question, simply ask the question (all on ONE line, so others can read and follow it easily). If anyone knows the answer they will most likely reply. :-)15:58
mncvnI want study how to configure Ubuntu Server. Where should i start????15:58
zoopsterhttps://help.ubuntu.com/8.04/serverguide/C/index.html is a great place to start15:59
mncvnzoopster: Thanks, I'll start from this.16:03
zoopstermncvm: if there are specific q's just ask, but this will get you installed and configured with the basics16:03
mncvnzoopster: Yes thanks, I want to begin from the basic. And after that, if i've any problem, may i personal ask you???16:05
zoopstermncvn: you are best to ask the question in this channel - I may or may not be available to answer but someone will16:08
mncvnah...........yes, sure16:13
mncvnzoopster: Thanks, bibi16:14
zulkirkland: do you want to merge php5 again?16:37
* zul is trying to spread the pain around again16:37
kirklandzul: arg....16:37
kirklandzul: yeah, i suppose i can16:37
zulkirkland: thanks ;)16:37
uvirtbotNew bug: #225919 in openldap (main) "package update-manager 1:0.87.24 failed to install/upgrade: ErrorMessage: SystemError in cache.commit(): E:Sub-process /usr/bin/dpkg returned an error code (1), E:Sub-process /usr/bin/dpkg returned an error code (1)" [Medium,Triaged] https://launchpad.net/bugs/22591916:39
=== nealmcb1 is now known as nealmcb
=== samuraipengui1 is now known as samuraipenguin
slicslaki just used tasksel to deselect mail and it also uninstalled all my LAMP stuff!!!17:22
slicslaki just duplicated this on another server.  is this a bug or what?17:26
scientescan i do two exec lines in upstart?18:25
mynousis there a way to disable the ebox web configuration page?19:12
zulwhat do you mean by disable?19:17
mynousthe http config page, make it inaccessable19:17
mynousalso, does ebox use postgresql?19:18
zulmynous: not that I know of and it uses mysql19:26
mynousweird, for some reason i have postgresql AND mysql running. i only installed mysql19:26
ivokszul: ebox uses postgre19:27
zulivoks: i could have sworn it uses mysql19:27
mynousis there an easy way to uninstall ebox, i know when i installed it the server needed to be manually restarted19:28
ivoksapt-get purge ebox.*19:28
mynousshouldnt need a restart?19:29
ivoksrestart?19:29
ivokswhat's restart?19:29
ivoksremoving programs on linux doesn't require restart of computer19:29
mynouswell doing apt-get install ebox-all, the server locked up and required a manual reboot19:29
ivoksunless we are talking about kernel or libc19:30
mynousok19:30
ivoksthat didn't lock up server, something else might have19:30
mynousdunno i got : Setting up ebox-network (0.11.99-0ubuntu1) ...    and then no response until a restart of the server19:32
ivoksebox set network and firewall :)19:34
mynousyeah that sucked19:34
=== dantalizing_1 is now known as dantalizing
albertuxhello21:04
albertuxquick question21:04
gravity1187albertux: wassup21:04
albertuxHey gravity, is there a way to setup encrypted folders on hardy server as in intrepid ibex?21:05
albertuxi see a huge dependency list when i try to install ecryptfs-utils on hardy21:06
albertuxi think even sudoku is required21:07
albertuxlol21:07
gravity1187I remember talk about it, but I don't remember what the final answer was21:07
gravity1187googling now21:07
gravity1187your trying to just to the user homefolder correct21:09
gravity1187albertux: the short answer is yes it just wasn't supported in main in hardy as it is in Ibex21:13
albertuxwell i just need to store some config files21:14
albertuxi haven't yet chosen a folder21:15
albertuxbut just because i need to install ecryptfs-utils without the thousand dependencies21:15
albertuxit looks like is tied to the desktop install21:15
gravity1187looking at the dependents now21:16
gravity1187http://packages.ubuntu.com/hardy/ecryptfs-utils21:17
andolalbertux: Well, there is always the option of using EncFS instead. Still, it's a bit hackish, so I wouldn't use it on lots of users.21:19
andolalbertux: http://www.andreasolsson.se/2008/08/21/my-private-eee-folder/21:19
albertuxthat's basically what i need, i'll give it a try. thanks a lot.21:21
uvirtbotNew bug: #296952 in mysql-dfsg-5.0 (main) "mysqlhotcopy failed on table with hyphen in name" [Undecided,New] https://launchpad.net/bugs/29695221:21
espacioussome packages are not upgraded how can i force the upgrade?22:22
espacioustrought apt-get22:22
espaciousok found out just had to apt-get install those packages22:24
=== jdstrand_ is now known as jdstrand

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!