/srv/irclogs.ubuntu.com/2009/03/04/#ubuntu-server.txt

=== kansan___ is now known as kansan
tbielawaGreetings01:28
uvirtbot`New bug: #337534 in mysql-dfsg-5.0 (main) "install fail my video player" [Undecided,New] https://launchpad.net/bugs/33753401:35
tbielawaCan anyone point me at a definitive list showing the details between configuration of a linux-image-virtual kerbel and a generic kernel?01:35
tbielawaResearch so far suggests the -virtual flavor is mostly slimmed down in terms of devices compiled in01:36
tbielawa:)01:36
JanCtbielawa: exactly01:38
JanCtbielawa: VMs don't need a lot of devices01:39
tbielawaJanC, thanks for the confirmation. I just started to dig around package sources. you saved me some time :-)01:39
JanCthere might be some other changes, but in general, it's optimized for running in VMs01:40
tbielawaCan you speak on the delta between -server and -virtual?01:41
maxbtbielawa: the relevant bit of the source: http://kernel.ubuntu.com/git?p=ubuntu/ubuntu-jaunty.git;a=tree;f=debian/sub-flavours;h=f40a10bee9057abd5604a3fa8da6d7d918f1956f;hb=HEAD01:41
tbielawaThanks maxb01:42
tbielawaIn my work place we've set up enough infrastructure to finally roll out on a much bigger scale with the virtualization01:44
tbielawaSo last steps before that gets going fully is performance tuning and tweaking01:44
tbielawaI'd appreciate any helpful resources for that topic.01:45
^law^hello anyone can help me to make my db2 autostart in my ubuntu server?02:59
JanC^law^: eh, DB2 has no init script?03:00
uvirtbot`JanC: Error: "law^:" is not a valid command.03:00
JanCshut up uvirtbot`  :P03:00
^law^when i want to connect to my db2 db for each times i start my server i must invoke "db2start"03:01
^law^i want to make it autostart. have any idea?03:02
^law^anybody?03:03
JanClike I said, you proably need an init script03:06
JanCor if you have one, you need to mak sure it's started03:06
^law^hmm is  it possible to add some in inittab?03:06
^law^hmm is  it possible to add something in inittab?03:07
JanCnormally, init scripts go into /etc/init.d/* and they are symlinked from the directories that indicate what script to start or stop for a certain runlevel03:08
JanCdo you know how sysvinit works?03:09
JanC(in the future upstart should do this, but for now you need the sysvinit machinery)03:09
^law^hmm03:12
JanCI guess you didn't install DB2 from an Ubuntu-specific package...03:12
^law^my ubuntu is intreoid03:13
^law^intrepid03:13
^law^n it seems there is no db2 packge forit03:13
^law^so i install manually03:13
^law^formerly i can autostart my aolserver by adding a line in inittab03:14
^law^i found the line in the internet03:15
^law^but now cn't find for db203:15
JanChm, there were DB2 packages for Ubuntu in the past03:16
JanCmaybe you can steal something out of these03:17
^law^but now i already succeed install it03:17
^law^n now i just wanna make it autostart03:17
^law^JanC, for making one autostart we can do it by editing inittab or adding initscript in /etc/init.d rite?03:18
JanC^law^: I suggest writing an init script03:20
uvirtbot`JanC: Error: "law^:" is not a valid command.03:20
^law^wat is the diffrent by adding initscript n editing inittab?03:20
JanCthat way you can at least shut it down properly too03:20
^law^but now i can do db2start to start the dbmanager n db2stop to stop it03:21
^law^it just won'y autostart03:21
JanCyou want it to "autostop" too...03:22
^law^no03:22
^law^i'm wondering wat line must i add into my initttab03:23
JanCwell, if you don't care about possible dataloss, fine for me...  ;)03:23
^law^wat u mean by dataloss?03:27
JanCif you don't stop DB2 properly before a shutdown or reboot...03:28
^law^hmmm03:29
^law^when shutdown/reboot must stop db2?03:29
^law^i never do tat?03:30
twb^law^: Ubuntu has no inittab.03:32
uvirtbot`twb: Error: "law^:" is not a valid command.03:32
twb^law^: PS: please pick a less silly nick in future.03:32
uvirtbot`twb: Error: "law^:" is not a valid command.03:32
JanCtwb: if you create one, it's used03:32
^law^a?03:32
^law^my ubuntu server have inittab03:32
twbJanC: what package is responsible for that?  upstart-sysvinit-compat ?03:32
^law^i just fresh installed it 2 days ago03:33
JanCyeah, see  /etc/event.d/rc-default03:33
twbJanC: thank you, I did not know that.03:33
JanCif it has, ^law^, it's because you created it03:33
JanCit's not there by default03:34
twbJanC: unless he's running something ridiculously old, like 6.0403:34
JanCmaybe03:34
^law^no03:34
twbBut I suspect more likely is that he's done a third-party sharball install or something for db2, which has "helpfully" created it because "shucks, ALL systems are SysV dontcherknow"03:34
^law^i didn't create it03:34
^law^no03:34
^law^i install db2 manually03:35
^law^without any 3party03:35
twb^law^: that's what I'm saying.03:35
uvirtbot`twb: Error: "law^:" is not a valid command.03:35
* JanC kicks uvirtbot` :P03:35
twbJanC: its not uvirtbot`'s fault that people choose stupid nicks03:35
twbExcuse me, I'm a grumpy old man and I'm not used to "polite" channels like #ubuntu*03:36
JanCtwb: it could check nicks before sending error messages  ;)03:37
twbJanC: while we're at it, let's fix IRC03:37
HellsheepHey, i have a thread posted in the forums i was wondering if someone can look at please.04:26
Hellsheephttp://ubuntuforums.org/showthread.php?p=6833609#post683360904:26
HellsheepIs anyone here able to help with a networking issue?04:36
twbHellsheep: can you give a one-sentence description of the problem, so I can decide whether I can be bothered dealing with a web forum?04:47
HellsheepConnecting my network like this: Phone Line>Modem>Server>Router/switch>windows PC's so basically i want to know how to set something like that up, and configure the server to process the internet and route it out04:48
Hellsheepi can explain more if you like04:50
twbSorry, I'm not interested.05:01
HellsheepNo problem05:04
=== CaTeYe is now known as cateye
=== cateye is now known as CaTeYe
krautmoin08:37
pitiHi08:48
pitiI have a strange behavior: I'm not able to set on php core option "allow_url_fopen" to on. The conf file is already setted to on, but the configuration doesn't seem to reload08:49
pitiI use lighttpd so the conf file is /etc/php5/cgi/php.ini, and tried to reload with /etc/init.d/lighttpd restart08:51
pitiand it's on a gutsy box08:51
cemcpiti: other conf options do work ?08:56
pitihum good advice: it seems not to08:59
pitidoes it use an other conf file than the one I'm on ?09:00
cemcpiti: maybe you want to take a look in /etc/php5/cli/php.ini ?09:00
cemcdepends on how you're using php from lighttpd I think09:00
pitiI use fastcgi09:01
pitibut it hasn't changed anything with /etc/php5/cli/php.ini too09:01
cemchm, strange09:06
cemcnot working for me either09:07
pitihum, on a hardy box, I don't have any trouble09:09
Blank`laptopoh, lighttpd can only use the cgi php?09:09
Blank`laptopi've never used anything on linux other than apache2 so i've never fiddled with it09:10
Blank`laptopi manage to massively screw my intrepid installation up when i accidentally started chown'ing everything to www-data09:11
Blank`laptopexim is still stuffing up, but i'm not sure how to fix it... perhaps a apt-get purge exim4?09:12
_rubenreinstall? :)09:15
Blank`laptopa reinstall?!09:15
Blank`laptopentire server?09:15
_rubenfor the average server its faster to reinstall than trying to get all perms back in order09:15
pitiBlank`laptop: chown everything to www-data is a bad start09:16
Blank`laptopyeah that was accidental09:16
Blank`laptopi was meaning to type ./ as the folder to chown09:16
Blank`laptophowever i forgot the dot...09:16
cemcoops ;)09:16
Blank`laptopi managed to break the operation09:16
Blank`laptophowever i had no idea how far it got09:16
Blank`laptopso i started chowning most folders to root09:16
Blank`laptopthen got issues with mysql and exim...09:17
pitiI guess it's easier to reinstall instead of retrieving original owner of each file09:17
Blank`laptopi was trying to compare things to another installation of server i had on a spare drive09:17
Blank`laptopbrb09:18
piticemc: so you don't have any clue ?09:23
eolo999hi, i bought a new machine to experiment with kvm and i'm was worrying if 8.10 is the right choice. The machine should offer some prduction services too so i am tempted to stay with 8.04. The new kvm technologies developed in Intrepid justify going on a not LTS release?09:26
cemcpiti: no clue yet, it's not working for me either, but it did work at some point, so I have to check09:26
ttxeolo999: if the main purpose of the machine is testing kvm, I'd go for the latest. This is an area that sees quick improvements.09:27
ttxfwiw, "experiment with kvm" and "offer production services" on the same machine doesn't really sound right.09:28
eolo999ttx: thx, i know still a ihave to create a stable service while investigating kvm... it's not my choice...09:31
eolo999ttx: can i backport new vm tools to 804?09:32
ttxeolo999: I'd say the intrepid kvm is less likely to lock up your server, so it's probably a better choice to run intrepid09:32
ttxif you intend to upgrade that machine before intrepid support ends09:33
hadsHardy kvm doesn't do anything bad here.09:33
eolo999what do you mean with 'lock your server'?09:33
hadsI have a Hardy box running five KVM guests with 260 days uptime09:34
ttxhads: yes, it's pretty solid. Though looking at KVM changelog, they keep on nailing new kvm crash issues, so running a later version shouldn't hurt09:35
ttxeolo999: I'd say it's more a matter of how long you want to keep this machine without upgrading it.09:35
ttxhardy LTS has longer support (obviously) than intrepid.09:35
hadsYeah, I'm sure there are situations that I don't run into which cause issues.09:36
eolo999thx guys i go for 810!09:37
Doblejust out of interest hads - what guests are you running?09:38
Blank`laptopback09:38
ttxeolo999: have a great time with kvm ;)09:38
hadsDoble: A mixture of Hardy and Intrepid09:38
eolo999ttx: ;)09:39
Doblewhat do they run ?09:39
Dobleyour guests09:40
simplexioi saw one intrestin kvm patch on lkml, no idea if its in mainiline kernel though. it allowed run something like 64 windows client on 16G ram, it shared identical memeory blocks between virtual clients09:40
hadsDoble: mail/web/etc. nothing too exciting09:41
Doblealright, cheers, i have to head off now - seeya09:41
piticemc: you think I should fill a bug about it, or am I doing something wrong ?09:45
cemcprobably you're doing something wrong ;) I am sure it does work, I tested some clamav stuff and it worked then, not sure what's happening now, but right now I'm in the middle of something, will look at it later09:47
pitiok, no problem09:47
HellsheepHey09:50
HellsheepIs anyone available to help me with a networking issue09:51
blue-frogshoot09:52
pitihum, I tried launching the cgi from cli, and it seems to take care of my conf. maybe that's about old php threads which hadn't reload configuration10:07
pitiok, I manually killed every php-cgi threads then reload, and it is ok now10:11
cemcpiti: good to know10:15
piticemc: so you think it's like a bug ?10:23
_rubenrestarting lighttpd isntead of reloading it probably would've done the trick .. and i dont think its a bug, more a usability issue of sorts :)10:24
piti_ruben: I already restarted lighttpd, but this didn't worked10:27
pition a hardy box, all went fine doing that10:27
piti(I even tried to stop thhe server, then start it after few seconds)10:27
_rubenhmm .. if restarting lighttpd leaves rogue php-cgi processes behind, that i'd qualify as a bug10:30
olyhum, can some one direct me to the file to modify ldaps apparmour profile, not used app armour before but its stopping me creating a second database10:34
_ruben/etc/apparmor.d/path.to.file10:36
_rubento control the 'rules' for /path/to/file10:36
olycool, got it cheers10:37
Hellsheepblue-frog, thanks for the offer. :) I forgot about IRC, ended up asking my brother instead.10:39
olyhum, got another question regarding slapd if any one knows, when starting it, slapd ignores my slapd.conf file unless i pass it the -f parameter with a path10:47
olyanyone know what may be causing this ?10:47
mihhello ! to everyone ! I have an Intrepid with cups,samba,kerberos. I want to make from it - print server, release station, all authentication by kerberos, on Active Directory. All is ok except the xp station that doesn't authenticate to the CUPS server !10:47
olyi get the feeling its something todo with /etc/ldap/slapd.d folders10:48
mihI see the printers on the cups server but after installing the drivers I get access denied and none of the print jobs I send from the xp get to the cups...10:48
uvirtbot`New bug: #337037 in samba (main) "MS Office reports "Access Denied" when saving to samba share" [Undecided,New] https://launchpad.net/bugs/33703711:05
pitiwhen does uvirtbot` decides to tell there's a new bug ?11:12
_rubenwhen its a bug thats  assigned to the server team iirc11:13
pitiah, ok11:15
pitithank you11:15
Blank`laptophmm... i'm wondering if i've screwed up something else, look at what happens when i try to ping anything, even localhost11:15
Blank`laptop~$ ping localhost11:15
Blank`laptopping: icmp open socket: Operation not permitted11:15
Blank`laptophowever... just found out that if i sudo ping, it's fine... i'm almost 100% certain i've screwed something else up permissions wise11:16
cemcBlank`laptop: firewall ?11:16
cemcheh11:16
Blank`laptopchowning most things accidentally to www-data then chowning almost everything to root is a bad idea11:16
Blank`laptop>.<11:16
cemcreinstall :)11:17
cemcfor how long have you been trying to revive it now? :) a couple of hours maybe?11:18
cemcyou would've reinstalled it and configured it by now11:18
Blank`laptopcemc: about a month or two11:42
=== Kamping_Kaiser is now known as VK5FOSS
=== VK5FOSS is now known as Kamping_Kaiser
ubuntnoobif i have a file/print server, should i have it behind a router? or should i configure it to be the router itself?13:18
ubuntnoob!if i have a file/print server, should i have it behind a router? or should i configure it to be the router itself?13:28
ubottuError: I am only a bot, please don't think I'm intelligent :)13:28
mario_Hi, how can use Logical Volume with jeos?13:36
_rubendont recall jeos having any issues with lvm13:37
_rubenthen again, i havent used jeos that much13:37
mario_I want to assign a logical volume to a guest, i have to add it in the xml configuration file of libvirt?13:39
_rubenoh .. i thought you meant lvm within jeos13:40
_rubennever used libvirt13:40
yaduHi,i'm a student at CET, India.14:29
thewrathhey all14:29
thewrathanyone here?14:29
yaduWe, are planning to set up a mirror for Ubuntu in our college.14:29
yaduIt would be very nice if someone could help14:30
thewrathkool14:31
sommeryadu: do you have a specific issue?14:31
thewrathso people can download it i presume there yadu ?14:31
thewrathwhere is the apache2.conf file located in 8.04 lts14:35
thewrathi completely forget14:35
sommerthewrath: /etc/apache214:36
thewrathty14:36
thewraththought so but i must of had a misspelling14:36
sommerthewrath: tab complete is your friend14:37
thewrathyeap lol14:37
thewrathits not hard to set up a self signed ssl for ur web correct?14:37
sommerthewrath: nope not hard14:37
sommer!serverguide14:37
ubottuThe Ubuntu server guide may be found at http://help.ubuntu.com/8.04/serverguide/C/14:38
thewrathty14:38
sommerthewrath: there's a section on certificates in the serverguide that has instructions14:38
thewrathi did it on my old laptop that had issues so i am trying ot duplicat everything14:39
=== picturesque is now known as domas
thewrathhi domas14:39
thewrathPermission ddenied: make_sock: could not bind to address 0.0.0.0:80 no listening sockets avaiable, shuttind down unable to open logs14:40
thewrathapache failed to do force-reload14:40
thewrathwhy14:40
domashi!14:40
thewrathall i did was added this after the only <directory stuff>14:41
thewrathUserDir public_html14:42
thewrathUserDir disabled root14:42
thewrath<Directory /home/*/public_html> AllowOverride FileInfo AuthConfig Limit Options Indexes SymLinksIfOwnerMatch IncludesNoExec14:42
sommerthewrath: did you use sudo ?14:42
thewrathduh14:42
thewrathid idnt14:42
thewrathas you can see how tired i am atm14:42
thewrathsommer: genius and a life saver14:42
sommerthewrath: heh, I give you permission to take a nap14:42
thewrathlol14:42
incorrectI am trying to allow a user to sudo to another user without a password14:42
thewrathhmm14:43
thewrathnot sure if you are able to do that14:43
incorrectthewrath, is that directed at me?14:43
thewrathsommer: guide have how to install services for irc server?14:43
thewrathyes i always thought to sudo you needed a password14:43
incorrectNOPASSWD works14:43
sommerthewrath: not yet, but it's on my list for karmic14:43
incorrectjust i can't change the user14:43
thewrathkarmic?14:44
sommerincorrect: you might try giving sudo access to su14:44
sommerthewrath: the next ubuntu release14:44
thewrath9.04?14:44
thewrathi didnt think that was called karmic14:44
sommerthewrath: 9.1014:44
incorrectsommer, can you tell me how to run su over ssh?14:44
thewrathwhere can i find a good tutorial how to install services14:44
thewrathsommer: all right awesome14:44
incorrectsu complains that it needs a terminal14:44
sommerincorrect: well you'd ssh first then su to the other user... not sure if you can limit which user with su though14:45
yann2ttx > around?14:45
ttxyann2: yes14:45
incorrecti want to ssh host su - user -c script14:45
yann2I got issues with java on ubuntu hardy, I got pointed to you :) i suspect a memleak14:46
yann2I thought maybe you could help?14:46
yann2(related to: http://bugzilla.zimbra.com/show_bug.cgi?id=34040 )14:46
sommerincorrect: ah, ummmm I've done something similar, but what I did was ssh sudo -u user /usr/local/bin/script14:46
ttxyann2: Probably not, but tell me more :)14:46
uvirtbot`bugzilla.zimbra.com bug 34040 in Other - Server "Zimbra java consumes all memory on Ubuntu 8.0.4 64bit" [Blocker,New]14:46
incorrectsommer, can you do it with nopassword?14:47
yann2ttx > there is a bug on zimbra's bugzilla, that is ubuntu specific14:47
ttxlooking14:47
sommerincorrect: if you configure sudo to execute the script with NOPASSWD14:47
sommerincorrect: and setup ssh keys14:47
yann2beyond the fact that the bug is affecting me and is scary, I am a bit afraid that it may put some shadow over future support for ubuntu14:47
incorrectsommer, strange keeps asking me for a password14:47
thewrathany suggestions for installing irc server services14:47
thewrathnickserv, etc14:47
sommerincorrect: which part the ssh to the host, the sudo, or a command in the script itself?14:48
yann2looks like that in the end  http://monitoring.thehumanjourney.net/munin/server/zimbra.server-memory.html14:48
incorrectwell i set user ALL=(ALL) NOPASSWD  thinking this would let them sudo -i user214:49
sommerincorrect: do you want them to have an interactive shell?  or just execute a script then exit?14:49
ttxyann2: looks like a Sun JVM bug in the 1.5 version shipped in hardy14:49
* ttx looks more14:50
incorrectsommer, either14:50
yann2ttx > is what I think too :)14:50
ttxyann2: would it run with sun-java6 or openjdk-6 instead ?14:51
=== mike is now known as thewrathjr
yann2oh wait wait I think I pointed this to  you too early14:52
yann2I think they bundle their own java (ever heard of zimbra?)14:52
yann2sorry about that... got no idea why the bug then :(14:53
ttxwell they must bundle a buggy JVM version14:53
joe-machas anybody here ever noticed apt-proxy spitting out 404s when it's low on memory?14:53
sommerincorrect: you might try ssh user@host sudo -u user script14:54
ttxttx: doesn't seem completely ubuntu-specific, see "We have seen this behavior on SLES for a number of 5.0 versions." comment14:54
ttxyann2: ^14:54
yann2uh, missed that one.14:54
thewrathdoes anyone have experienc with setting up irc server?14:54
=== mike is now known as Guest72362
yann2right this is partly good news :)14:54
* incorrect goes and bangs his head against the wall14:55
yann2thx for your help ttx , sorry I should have remembered that java was bundled14:55
incorrectsommer, i am stupid14:55
ttxyann2: np14:55
thewrathttx: any knowledge of irc?14:55
sommerincorrect: did it work?14:55
incorrectsommer, i had it right apart from a typo14:55
sommerincorrect: heh, it happens14:55
ttxthewrath: yes, as in "I'm currently using it".14:56
thewrathwell i mean setting upa  irc server14:56
thewrathi think i found some stuff for the scripts14:56
thewrathbut i want to install the services14:56
ttxthewrath: then, no: no knowledge of setting up any irc server.14:57
thewrathdoes anyone?15:00
thewrathjrokay i think i got this working fine now can someone say something15:08
thewrathokay now try15:09
thewrathwhat is command to remove some things that the sudo-get remove didnt15:18
thewrathlike when you install something but it has to haev other things installed15:18
maxbPerhaps you are thinking of "apt-get autoremove" ?15:18
thewrathyes15:19
thewrathpefect15:19
thewraththank you15:19
thewrathhmm15:25
andolcjwatson: I must say I appreciated reading your bug rant on bug triage. To me it was definitely educational. Not sure how much I have "sined" so far, but I will very much try not to do so in the future.15:30
cjwatsonandol: thanks :-)15:59
giovanisomeone has claimed the $1000 djbdns prize!!16:44
domassbeattie: so strange to see whole bug description to be revamped16:46
domasgiovani: haha,how?16:47
giovanidomas: http://article.gmane.org/gmane.network.djbdns/1386416:47
sbeattiedomas: prepping for an SRU.16:51
sbeattiedomas: any chance you could test one of the kernels I pushed into my ppa and give feedback?16:52
domassbeattie: I tried them on a VM, it seemed to work, though I didn't try in live environment16:57
sbeattiedomas: but you didn't see the leak you were seeing before, right?16:58
domasnope16:58
domasyou have my testcase though :)16:58
sbeattiecool, can you add a comment to that effect?16:58
sbeattieyep, thanks for synthesizing it down to that, very much appreciated.16:59
kirklanddidrocks: http://blog.dustinkirkland.com/2009/03/ubuntu-encrypted-home-with-2-factor.html20:18
didrockskirkland: thanks a lot :)20:21
kirklanddidrocks: thanks for the nudge :-)20:21
axisyson a nvidia raid devicemapper how can I tell the raid1 disks are sync after putting a new disk? looking for a /proc/mdstats time file20:41
=== photon_ is now known as photon
ubuntnoobhello!21:09
ivoksgr... why did dell put ubuntu on worst hardware... ever21:35
giovani?21:35
ivoksafter two weeks a key droped from keyboard21:36
ivokstwo months after purchase - disk died21:36
ivokson the same dell vostro a86021:36
JanCif you want good hardware, why do you buy from Dell?  ;)21:39
HAN67431hello all21:40
HAN67431need help with dovecot and postfix saslauth21:40
ivoksJanC: they have good servers, so i tought.... :)21:41
ivoksHAN67431: just ask21:41
HAN67431k21:41
HAN67431i followed the server guide for postfix and saslauth with dovecot21:41
HAN67431everything work fine21:42
HAN67431outlook 2007 can authenticate using smtp auth and thunderbird but windows mail (vista) makes no attempt to authenticate, i have tried 2 diffrent pc's21:43
HAN67431and from the mail.log it only tries to send the mail21:43
HAN67431other client first authenicates then send the mail21:43
HAN67431windows makes not attempt21:43
ivoksthen vista mail is broken21:43
HAN67431i have a another server (centos with cyrus sasl) and with windows mail it work 100%21:44
giovaniget a packet trace21:44
ivoksmaybe you configured wrong auth mechanism on client?21:44
giovanithen we can see what's actually going on rather than guessing in the wind21:44
HAN67431well, i only select "my outgoing server requires authenication" with the username password...21:45
ivoksand did you configure postifx to accept plain text authentication?21:46
HAN67431and windows mail work fine with my other server21:46
HAN67431yes21:46
giovanionce again21:46
giovani a packet capture would remove all of the guesswork21:46
ivoksbroken_sasl_auth_clients = yes21:46
ivoks?21:46
HAN67431yes21:46
HAN67431broken_sasl_auth_clients21:46
HAN67431yip21:46
ivoksgiovani: there's not much you can see in crypted traffic :)21:47
giovaniivoks: who said it's encrypted?21:47
giovaniI didn't hear him mention encryption21:47
ivoksright, you have a point there...21:47
ivoksit should be crypted, anyway21:48
ivoksHAN67431: smtpd_tls_auth_only21:48
giovaniindeed it should -- however, for the purposes of troubleshooting, it would be helpful to remove that, so as to reduce the number of variables21:48
giovaniivoks: he has to set up TLS first ... but ok21:48
ivoksHAN67431: is that set?21:48
incorrectmy servers have 32gb of ram,  i don't feel like turning over 48gb of disk over for swap,21:48
ivoksHAN67431: if not, set it to no21:48
giovaniincorrect: then don't?21:48
HAN67431i have TLS Support21:48
ivoksJanC: smtpd_tls_auth_only = no21:49
ivoksdoh :)21:49
incorrectis there any reason why I should not just run with 2gb of swap, just in case i spill over a bit?21:49
ivoksJanC: sorry :)21:49
HAN67431tls_only is set to no21:49
HAN67431want to see my main.cf config?21:49
ivoksHAN67431: not really :)21:49
HAN67431lol21:49
giovaniincorrect: not that I know of -- the guidelines are just that, guidelines -- and most of them are antiquated anyway -- you have to do what's best for your environment21:49
incorrectgiovani, thanks for that, I was in that frame of mind too21:50
giovaniI haven't used more than 25-50% swap in nearly 10 years :)21:50
HAN67431well this is that i test enviroment21:50
HAN67431i have been using centos21:50
HAN67431testing out ubuntu21:50
ivoksincorrect: guideliness: if server_has_ram =< 2GB; then SWAP = server_has_ram * 2; else: SWAP = 2GB21:50
giovaniHAN67431: I've told you what would make troubleshooting easy21:50
ivoksHAN67431: ok, then put your main.cf somewhere21:51
giovaniincorrect: afaik, in 2.6, swap files are just as fast as swap partitions -- would give you more flexibility -- http://lkml.org/lkml/2005/7/7/32621:52
HAN67431http://pastebin.com/m26fceb4921:52
incorrectgiovani, the idea is I am never going to touch swap21:52
incorrectif i do something has gone wrong21:53
incorrectbut i don't want the system to die21:53
giovaniincorrect: swap will be used sometimes, even if you don't run out of ram21:53
HAN67431its really weird that only windows mail saslauth wont work...21:53
giovaniso, having none would not be great -- but 2GB is probably plenty21:53
incorrectgiovani, you can set swappiness to 021:53
giovaniHAN67431: not really ... microsoft breaks stuff all the time21:53
giovaniincorrect: yes, you can21:53
HAN67431lol21:53
ivoksand apple too21:53
incorrectgiovani, 2gb was what i was thinking21:53
giovaniincorrect: I'd go with that then -- report back if there are any issues -- I'll be curious if there are21:54
ivoksapple mail will at some point just refuse to connect to server21:54
ivoksand spit that 'server is broken'21:54
giovanismtpd_banner = $myhostname ESMT21:54
giovaniI think you accidentally lost a "P" there21:54
ivokswithout even establishing tcp connection21:54
HAN67431lol yes21:54
incorrectgiovani, i will have 200 odd machines this year, so its got to be right21:54
giovaniincorrect: you have 200 machines with 32GB of ram?21:55
giovanismtp_use_tls = yes21:55
incorrectgiovani, i have 90 with 8 right now, 25 with 32, and 5 with 16 but 6tb per box21:55
giovaniyou've also duplicated this line21:55
incorrectill be buying another 60 next month21:56
ivoksgiovani: um...not?21:56
giovaniincorrect: gotcha -- well, if you have a network that large, you should know that you should have non-production machines to do stress-testing on before deploying anything21:56
ivoks#21:56
ivokssmtpd_use_tls = yes21:56
ivoks#21:56
ivokssmtp_use_tls = yes21:56
giovanioh sorry21:56
giovanimy mistake21:56
HAN67431?21:56
incorrectgiovani, sort of, but nothing of the larger machines21:56
giovaniHAN67431: nothing, ignore it21:56
HAN67431i am using tls21:56
giovaniso you've told us21:57
incorrectI really should publish my openldap packaged 2.5.15, and bdb 4.7,  I have n-way replication working21:58
jmedinaincorrect: how is your n-way setup?21:59
incorrectjmedina, works pretty well22:00
HAN67431something tells me that it is a config issue with dovecot because why would cyrus saslauth work?22:00
giovaniHAN67431: doubtful22:00
HAN67431on my centos box22:00
jmedinaincorrect: have you been monitoring your contextCSN?22:00
giovanibecause your config is probably slightly different22:00
giovaniHAN67431: why is it that I've asked like 10 times for a packet capture ...22:01
jmedinaI have seee a lot of inconsitencies with earlier versions22:01
incorrectjmedina, i backported bdb4.7 and built new packages for 2.5.15 where the contextCSN problem was fixed22:01
=== photon is now known as graviphoton
=== graviphoton is now known as photon
jmedinaincorrect: do you have hardy packages? :D22:01
HAN67431i am on it22:01
incorrectjmedina, i do22:01
incorrectjmedina, its for hardy22:01
incorrecti need to setup reprepo22:02
giovaniHAN67431: it's just a quick tcpdump server-side22:02
jmedinaincorrect: I can test them, I only use openldap on hardy22:02
jmedinaincorrect: are you using any load balancer?22:02
incorrectjmedina, don't need to, i have loads of servers around the place, so i have all the local ones to each data centre/network setup22:03
ivoksHAN67431: dovecot sasl doesn't support MD5 and others22:03
ivoksHAN67431: it supports only 'login'22:03
ivoksHAN67431: cause you can't decrypt user password from shadow22:04
=== st37 is now known as appletree
incorrectjmedina, i am using haproxy to load balance my data centre's that works pretty well22:04
incorrectnext i've got to get bonding configured during my pxe install22:06
HAN67431i am not using secure password authentication on the server22:06
jmedinaincorrect: so you point your apps to a local replica?22:07
incorrectjmedina, yes, if you list them, they fail over22:07
jmedinaincorrect: lets write a wiki about thease I can help testing22:07
incorrectthere is already plenty on it22:07
jmedinabut not the ubuntu way :D22:08
incorrectI should fix the errors on the official guide22:08
jmedinaI have used simple syncrepl using two servers in apps configs, with only one master22:09
jmedinahow is the setup in the clients? lets say a proxy squid22:09
HAN67431http://pastebin.com/m69fb136e22:09
HAN67431tcpdump22:09
incorrectI have pretty much all my systems slaving off ldap now22:10
jmedinaand how is managed fail over?22:11
jmedinathat is my doubts22:11
incorrectjmedina, try setting multiple uri's in your ldap.conf22:11
jmedinaok22:12
incorrecti have it a bit like my /etc/resolv.conf22:12
incorrecta master and then if that isn't there it fails over22:12
incorrectyou could use a load balancer22:12
incorrecthaproxy would work nicely for it22:12
HAN67431pop3 work 100% with windows mail its just smtp-auth that it wont do,22:13
HAN67431like i said tried it on two pc with windows mail same thing22:13
HAN67431outlook 2003/2007 no issues22:14
HAN67431using debug_auth in dovecot.conf22:15
ivoksHAN67431: http://www.vistax64.com/vista-mail/88396-smtp-auth-windows-mail.html22:15
ivoksHAN67431: you are not alone22:15
HAN67431outlook auths but windows mail makes not attempt to auth22:15
HAN67431yes i did have a look at that but why does it work with cyrus-saslauth22:16
HAN67431i have no issues22:16
ZerqentHAN67431: .. smtp-auth and dovecot.. are you trying to use an imap/pop3 server for smtp?22:16
ivoksZerqent: dovecot can export authentication to postfix22:17
Zerqentivoks: aha, didn't know that =)22:17
HAN67431no dovecot has its own sasl mechimisn22:17
ivoksHAN67431: users are in sql, ldap?22:18
ivokson in passwd?22:18
HAN67431no normal system users22:18
HAN67431passwd22:18
HAN67431this is the guide i followed step by step22:19
HAN67431https://help.ubuntu.com/8.10/serverguide/C/postfix.html22:19
ivoksHAN67431: did you check 'Lon on using Secure Password Authentication'?22:21
HAN67431yes22:21
ivokswhy?22:21
ivoksuncheck it22:21
HAN67431tried it22:21
ivoksit must be off22:21
HAN67431it is22:21
jmedinaincorrect: are you uploading the packages?22:22
HAN67431anyway in the log file it show no attempt to authenticate22:22
HAN67431where with outlook it show sasl authenication=plain ....etc22:22
incorrectjmedina, not sure where a good location would be22:22
ivoksHAN67431: i don't know... i'll have to test that on my own; but i don't have vista22:24
jmedinaincorrect: lauchpad?22:24
incorrectjmedina, not used it22:24
HAN67431log file windows mail22:25
HAN67431http://pastebin.com/m686cad6522:25
jmedinaincorrect: maybe in a PPA22:25
jmedinathat is the place afaik22:25
HAN67431outlook 200722:26
HAN67431http://pastebin.com/m7bbb246122:26
incorrectjmedina, ill make you a tar.bz222:27
HAN67431anyway if someone have vista please test it with windows mail and ubuntu with this guide22:27
jmedinaincorrect: thanks22:27
ivoksHAN67431: you are missing couple of lines in first one22:27
HAN67431if someone sees something can i they drop me a email jancarel.putter@gmail.com22:27
jmedinaivoks: it looks like copy paste doesnt work22:27
jmedina in the wikis :D22:27
giovaniHAN67431: where's the packet capture?22:28
ivoksjmedina: :)22:28
jmedinaHAN67431: why not debuging smtpd in postfix (master.cf)22:28
HAN67431http://pastebin.com/m69fb136e22:28
HAN67431the first one is windows mail22:28
giovaniuh22:28
giovanibut that doesn't show us the actual contents22:28
HAN67431second one is outlook 200722:28
giovaniheh22:28
giovanithat's just the summary view22:28
ivoksHAN67431: and you are missing couple of lines on it22:28
giovaniwhat good is that?22:29
HAN67431?22:29
giovanisigh22:29
ivoksHAN67431: log doesn't start with 'NOQUEUE'22:29
giovaniwe need a PCAP22:29
giovaniso we can see what the client is trying to do, if anything22:29
giovanito authenticate22:29
ivoksHAN67431: it starts with clien=unknown...22:29
ivoksclient22:29
giovanitcpdump -i ethX -s0 -w file.pcap22:29
incorrectjmedina, there is a little bug with the packaging of bdb utils, you have to chmod the executables into running,, I was lazy when i backported it22:30
incorrectjmedina, also i've only built 64bit debs, you should be able to compile 32bit ones if you need22:31
jmedinaincorrect: which executables? db4-restore and like that?22:31
incorrectjmedina, yes22:32
HAN67431where can i send the file to or upload it>22:32
incorrectjmedina, chmod 755 is easy enough22:32
jmedinaincorrect: there is a launchpad service for upload22:32
giovaniHAN67431: I don't know -- you tell me -- a web server ... somewhere22:32
jmedinaivoks: you know where can incorrect upload some packages for testing?22:32
ivoksjmedina: ppa?22:32
ivoksor they are already binaries?22:33
jmedinaivoks: I dont know how do it with ppa, binaries22:33
incorrectjmedina, ill drop them on my server,22:33
jmedinadamn, when I was tring to learn how to contribute con server team this crisis bring me a lot of work, more time out of office22:34
ivoksi'm not sure there's anything for binaries :/22:34
ivoksanyway... 23:35; time to leave22:34
giovaniHAN67431: you made sure SSL/TLS was off when you did the packet capture right? because that's the only way we can read it22:34
HAN67431yes22:35
HAN67431but i vim the file cant read anything but i disabled SSL/TLS on the client22:36
HAN67431the file is in pcap format22:36
giovanivim? it's a pcap, it's a binary22:36
HAN67431o22:36
giovanijust post it somewhere22:36
HAN67431ok22:37
giovanithen we'll see what type of auth the client is attempting, if any22:37
HAN67431but the contents or the fiel itself22:37
giovanithat'll tell us if the server is misconfigured, or the client22:37
giovanithe file itself22:37
HAN67431where?22:37
giovanithe contents aer the same thing as the file -- it's a binary22:37
ivoks'night22:37
giovaniyou don't have a webserver?22:37
HAN67431mmmm...22:38
HAN67431no22:39
giovanihah22:40
giovanigood luck then22:40
HAN67431http://196.212.34.107/file.pcap22:42
incorrectjmedina, you can get them at http://www.badape.net/ldap/22:43
giovaniHAN67431: problem found22:43
giovaniyour client is not attempting to authenticate AT ALL22:43
giovaniit simply connects and begins sending mail22:43
jmedinaincorrect: where did you backported these p[acagkes?22:43
giovaniand is getting relay denied22:44
giovaniHAN67431: either you've misconfigured your client, or the client is broken22:44
HAN67431yes22:44
incorrectjmedina, they were built on my opertons22:44
jmedinaincorrect: 114M?22:44
giovaniHAN67431: this is not a server problem whatsoever22:44
incorrectjmedina, that is the source22:44
giovaniyour client makes no attempt to authenticate22:44
HAN67431i have permit sasl_authenicated22:44
incorrectand everything you need to rebuild22:44
giovaniHAN67431: that's not the problem, please read what I just wrote22:45
HAN67431as i said it work with outlook 200722:45
HAN67431cant be the client22:45
giovaniit is the client22:45
giovaniI can tell you without a doubt22:45
HAN67431two pc cant have the same issue22:45
giovaniyes they can22:45
giovaniif you'd like to argue with me ... go ahead ... I'm going to stop here22:45
giovaniyour pcap trace shows very clearly the client making no attempt to authenticate whatsoever22:45
HAN67431thank you...anyway for your help22:45
HAN67431yes22:45
HAN67431i know22:46
giovaniyour client is broken, or doesn't support PLAIN auth22:46
giovanisince that's all you're offering it22:46
HAN67431but ok i hear what you say and its all good22:47
giovaniit's not all good :)22:47
jmedinaincorrect: could you please leave the files until tomorrow?22:47
jmedinaI cant download them right now22:47
HAN67431but why does it work with cyrus-sasl22:47
incorrectjmedina, not a problem22:47
jmedinathanks22:47
giovaniHAN67431: possibly because cyrus is offering something more than PLAIN auth -- it's possible windows mail doesn't support PLAIN auth22:47
incorrectjmedina, i might get organised and setup a repository22:48
incorrecti built one for my server farm22:48
incorrectits 11pm here22:48
jmedinaincorrect: that will be good, but for backports I think the better way is usea a PPA22:48
HAN67431so dovecot can only do plain auth22:48
giovaniHAN67431: no ... you've just not configured it to do anything else22:48
jmedinahere 1722:48
incorrectjmedina, a ppa?22:49
ScottKjmedina: What's wrong with backports?22:49
giovaniHAN67431: you need to edit /etc/dovecot/dovecot.conf22:50
jmedinaScottK, sorry, there is nothing wrong, it was my english22:50
incorrecti've been building my own packages for 10 odd years22:50
giovaniand edit the part that says "mechanisms = plain" and add something else -- like cram-md622:50
giovanimd5*22:50
giovani"mechanisms = plain cram-md5"22:50
giovanilike that22:50
ScottKActually it's probably login you want.22:50
giovaniI don't know that this will solve your problem -- but it's possible22:50
jmedinaI have digest auth, /me preferes starttls22:51
ScottKOlder MS clients don't support plain, they support login22:51
giovaniScottK: this is a new ms client22:51
giovaniScottK: Windows Mail22:51
giovani(visa equivalent of Outlook Express)22:51
ScottKDunno about that one.22:51
giovanivista*22:51
ScottKMight still need login then.22:51
giovaniHAN67431: add "login" for good measure then as well22:52
ScottKcram-md5 is a shared secret mechanism, so it would take additional setup.22:53
giovanii.e. "mechanisms = plain login cram-md5"22:53
giovaniScottK: shared secret? it's a challenge-response22:53
giovanibased on the password and the challenge being md5ed22:53
giovanino additional setup -- most clients support it out of the box22:54
HAN67431lol thats the issue22:56
giovaniwhat is? :)22:56
HAN67431windows mail uses login22:56
HAN67431lol22:56
HAN67431not plain22:56
giovaniHAN67431: ok ... so less arguing next time about how it's the server22:57
HAN67431thank you very much22:57
HAN67431lol22:57
giovanipacket captures save the day once again :)22:57
giovanipeople get too caught up in their high-level troubleshooting tools22:57
HAN67431i think you did22:57
giovaniScottK came through with the windows loving login-only knowledge, never knew that myself22:58
HAN67431thanks scottK22:58
Hans67521sorry i am still very noob when it comes to ubuntu/linux23:11
Hans67521but thank for helping me solving my problem....23:12
giovaniyou're welcome23:12
ScottKHans67521: You're welcome.23:14
=== rgreening_ is now known as rgreening

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!