/srv/irclogs.ubuntu.com/2009/03/06/#ubuntu-server.txt

AtomicSparkApparently I need to configure dns-sec and possibly apparmor prevents dhcp from updating stuff in /etc/bind00:10
giovaniwhy do you need dns-sec?00:11
giovani(it isn't a bad idea ... but need?)00:11
AtomicSparkI don't know. :P00:14
AtomicSparkAll the guides suggest it, but I really haven't found a decent looking guide on the topic.00:14
giovanihah00:15
giovanidon't bother00:16
giovaniit's an advanced topic00:16
giovaniit doesn't sound like you're ready for that00:16
AtomicSparkhttp://www.cahilig.org/debian-and-ubuntu-ddns-with-bind9-and-dhcp00:18
Deepsiirc, the preferred location for zones that need to be writable by bind is /var/cache/bind00:19
JanCAtomicSpark: is this for a large network?00:20
AtomicSparkJanC: No. ~10 computers, but not being able to resolve hostnames is annoying. espeically when there is a shared printer. :P00:20
Deeps/etc/apparmor.d/usr.sbin.named contains the apparmour profile, defining what dirs can be read, written to and executed from00:20
Deepsand by the sounds of things, you dont /need/ dnssec00:21
AtomicSparkDeeps: Yeah. I saw that.00:21
JanCAtomicSpark: then maybe use dnsmasq ?00:21
JanCit's much easier to setup for this sort of thing...00:21
JanCit does both (simple) DNS & DHCP00:24
AtomicSparkHmm. Can't find the key. AppArmor is probably hiding it.00:26
AtomicSparkDeeps: so I copy the local zones to /var/cache/bind then update the named.conf.local paths?00:27
AtomicSparkHmm. Time to try dnsmasq or just fall back onto the router. :P00:37
=== AtomicSpark_ is now known as AtomicSpark
=== JanC_ is now known as JanC
ryanpriorIf I start up a new Ubuntu Server instance with KVM, how do I ssh into it?04:42
hadsUse the IP address you gave it?04:44
twbryanprior: "with KVM" or "within KVM"?05:05
twbryanprior: in the case of the latter, you need to get its network up, using e.g. -curses or -vnc :0 long enough to tweak its network config.05:05
ryanpriorI start it like so: kvm -hda my.img05:05
ryanpriorSo, with kvm.05:06
twbEr, if my.img is your Ubuntu server, then that server is running *within* kvm.05:22
ZykoticK9Ubuntu 8.10 JOES - is it possible to install ssh-client without it brining in x11-common, and the various x11 libs?  or the ssh server for that matter?  or will I have to just install the full version of server for this to work?  I am testing with VirtualBox 2.105:47
=== rgreening_ is now known as rgreening
JanCheh05:49
JanCdon't install the recommends05:50
* JanC thinks "install recommends by default" should be disabled on ubuntu-server 05:52
ZykoticK9JanC, was that directed to me?  it includes these packeges in the "the following extra packages will be installed" section, there are more "suggested" but i'm not even including those???05:52
JanCZykoticK9: use the '--no-install-recommends' option for apt-get05:52
JanC"recommends" is stronger than "suggests"05:53
hadsMmm recommends can be annoying05:53
ZykoticK9JanC, thank you :)  that cuts the list down DRAMATICALLY.  thanks, great tip!05:54
JanCI disable this on my system by default  ;)05:54
JanCsystems05:54
JanCeven on desktops05:54
ZykoticK9JanC, how is that done?05:54
JanCput "APT::Install-Recommends "0";" in /etc/apt/apt.conf05:55
ZykoticK9JanC, Thank you.05:56
JanCthis behaviour is probably useful for many desktop users05:56
ZykoticK9JanC, even more so on server I'd imagine.05:57
JanCI mean that Install-Recommends "1" is probably useful for most desktop-users05:57
JanCthe default behaviour05:58
JanCbut on servers, it often sucks05:58
ZykoticK9gotcha :)  Thanks again.05:58
JanCand if you want a desktop that only has the dependencies you need/want, it's useful too05:59
JanCif they want recommends installed by default, then this is a bug in the packaging anyway05:59
JanCso you might want to file a bug report06:00
* JanC goes to sleep now06:00
twbJanC: for Debian, at least, the Debian Policy manual's definition of Recommends makes it sound like it *should* be opt-out.  The real problem is all the assholes who made packages using Recommends instead of Suggests because, at the time, they had the same semantics (opt-in).06:00
twb...that's my view, anyway.06:00
ZykoticK9JanC, with your tip I was able to install ssh client & server without brining down a bunch of stuff I did NOT want.  I found it INSANE that you had to install X in order to have SSH on the console.06:00
JanCit's 7am here   ;)06:00
JanCtwb: agreed06:00
hadstwb: Language06:01
twbhads: sorry.06:01
hadsnp06:01
giovaniwow, are we really that stuck-up about language here?06:02
twbgiovani: it's not worth arguing about.06:02
giovanibut it's worth making people feel like they've done something wrong?06:02
hadshttp://www.ubuntu.com/community/conduct06:02
JanCwell, many of those people didn't do that because they are assholes, but because everybody else did it, I guess  ;)06:02
twbJanC: let us say they did it out of ignorance, then06:03
giovanihads: I didn't see any mention of "curse words" in there06:04
JanCsomething like that (and because the Debian guidelines weren't clear enough, probably)06:04
giovanibut maybe I missed it06:04
JanCgiovani: some people don't like "curse words", so avoiding them isn't bad06:05
JanCOTOH, nobody kicked or banned twb   :P06:05
giovaniJanC: I think making people feel like they've done something wrong by using certain words is counter-productive, but alright -- I'm going to bed06:06
twbPersonally, I consider it linguistic apartheid.06:12
JanCthen why say sorry  ;)06:13
twbJanC: because it appeases the crazies who complain06:13
twbJanC: and because I don't care particularly about #ubuntu-server06:14
SilberlingHi Guys.07:42
Silberling I'm having trouble with an Intel SDS2 + Intel Gbit Coppercable + Adaptec 2610SA SATA RAID.07:42
SilberlingBoth PCIX Devices run extremely slow and i don't know why07:42
Silberlingrunning 8.10 server07:43
uvirtbot`New bug: #338556 in net-snmp (main) "[jaunty] libsnmp-python: Depends: python (< 2.6)" [Undecided,Confirmed] https://launchpad.net/bugs/33855608:01
harrisonymy brain aint working today it seems, so ive got some possibly stupid DNS questions, I've just got a new vps running ubuntu server. could I run bind on it and use it as my master server? (and then set the name server to be the ip address of the vps)08:33
cemcharrisony: sounds like it should work08:36
harrisonywould that also work for RDNS?08:38
harrisonyif i was to go host <ip address of vps> would it respond with what I set it as?08:40
hadsThat is for your provider to setup08:40
harrisonygot i08:41
harrisonyt08:41
hadsI don't know if I'd trust my DNS to a VPS but08:41
harrisonyI don't my provider (prgmr.com) offers dns for me so unless i find some free thing or another plan08:42
hadsDepends how important your services being up are really.08:42
harrisonyhad a feeling it wouldn't work out :P08:46
=== ogra_ is now known as ogra
sergevnlo11:04
=== cjwatson_ is now known as cjwatson
uvirtbot`New bug: #264808 in ant (main) "Package does not work with JDK 5" [High,Fix released] https://launchpad.net/bugs/26480811:50
Barre12:49 -!- stefan_can [n=stefan@83.217.112.50] has joined #ubuntu-server12:03
Barre13:01 -!- DragonLord- [n=ask@84-217-68-182.tn.glocalnet.net] has joined #ubuntu-server12:03
Barre [13:02] [Barre(+ei)] [5:FreeNode/#ubuntu-server(+cnt)] [Act: 1] [165 nicks (@0 %0 +0 165)]12:03
Barre[#ubuntu-server] /hilight12:03
Barresorry12:03
uvirtbot`New bug: #338720 in php5 (main) "Function lookup problem after calling setlocale(LC_ALL, "tr_TR")" [Undecided,New] https://launchpad.net/bugs/33872012:25
uvirtbot`New bug: #338704 in nagios3 (main) "description missing in nagios config" [Undecided,Confirmed] https://launchpad.net/bugs/33870412:30
frzzhi there. I get the impression the oom-killer is disabled on server kernels13:37
frzzanyone can confirm this ?13:38
frzzand maybe give a hint on how to enable/disable it ?13:38
uvirtbot`New bug: #333460 in libpam-ldap (universe) "[Hardy][LDAP]client authentication broken" [Undecided,New] https://launchpad.net/bugs/33346014:39
ScottKfrzz: How is it you have this impression?14:49
frzzScottK: wrote a simple program that mallocs and memsets memory15:02
frzzthe system juste becomes unresponsive15:02
frzzif I do the same on a desktop kernel, the process just gets killed and I get a "out of memory killed" or something in dmesg15:02
RainCTHey15:24
RainCTI'm wondering, can Debian be updated to Ubuntu? :P15:25
ScottKSarge -> Dapper was doable.  After that, not so much as you need the sysv -> upstart transition we did in Edgy15:28
=== JanC_ is now known as JanC
mjeansonzul: Hi, I was wondering what was going on with the update to the redhat-cluster-suite package mentionned in LP#290399, I can't seem to find it, even in proposed15:47
zulmjeanson: we are waiting for hardware to test its in my ppa right now15:48
mjeansonzul: hum, I only have production systems running redhat cluster which makes me a bit nervous to test this update15:52
zulmjeanson: yes I realize that Ill see what I can do to speed the process up15:52
mjeansonzul: do you know if anybody is in the process of testing it?15:53
zulmjeanson: not that I am aware of it15:53
mjeansonzul: I may be able to try it this evening, I have a maintenance window15:54
zulmjeanson: if you can that would be great15:55
mjeansonzul: do you need specific testing done?15:55
zulmjeanson: just needs to see if scsi_fencing works15:55
mjeansonBrunoXLambert: not on vacation?15:56
mjeansonzul: I'm not using this fencing method, is the fix specific to it?15:56
BrunoXLambertmjeanson, sure am.15:57
zulmjeanson:  it is15:57
mjeansonzul: I have been running in a similar race condition with the gfs control deamon, I had hope the patch addressed that15:58
zulmjeanson: ok the scsi_fence thing is something else then ttx ^^^15:59
ttxmjeanson: wasn't accepted in -proposed yet. You can test the one in my PPA though. It's the same.16:01
ttxhttps://launchpad.net/~ttx/+archive/ppa16:01
mjeansonzul: just checked the patch and it definitely applies to the control daemons, so I'll try it tonigh16:04
mjeansonzul: I'll report the result of my tests in the launchpad bug, will that be enough to have it accepted?16:11
zulmjeanson: it should16:16
mjeansonttx: oups, had not notticed it wasn't zul talking anymore16:19
mjeansonttx: have you tried the package yourself?16:20
ttxmjeanson: no, but someone else did already (on a private bug)16:20
mjeansonttx: any additionnal information in the private bug which may be useful to me?16:24
ttxmjeanson: no, it's a copy of the public one.16:25
ttxexcept the tester data/ok16:25
mjeansonttx: cause I haven't been able to steadily reproduce this problem16:25
DiscipulusHello, do any of you have experience with SPARC servers? Specifically a E550016:26
mathiazsommer: hi - is there a section on auth-config-client in the server guide?16:38
incorrectI am creating a preseed config for my servers,  however I noticed i am having problems configuring my bonded network16:42
incorrectso i thought i would cheat and wget http://server/net_`hostname`  however that doesn't seem to work16:42
sommermathiaz: yeppers16:42
sommermathiaz: also ldap-auth-client16:43
mjeansonttx: btw, why ins't it in proposed?16:44
ttxmjeanson: waiting for SRU review afaict16:44
mjeansonttx: I may be all mixed up but I tought it needed to be in proposed to be reviewed?16:46
ttxmjeanson: yes, but the SRU rationale must be accepted for it to be accepted in -proposed.16:47
ttxzul: ^ am I right ? Is it the reason it's stuck in limbo right now ?16:47
zulthats right16:48
zulttx: but also we didnt have the hardware to test it until recently as well16:48
stgraber_about that SRU thing for redhat-cluster-suite, according to https://wiki.ubuntu.com/StableReleaseUpdates the process seems to be that once the bug is valid on LP it should be uploaded to -proposed then will be reviewed by the archive admins when it's in the queue. Once validated it'll be added to -proposed. The SRU team then will make sure it fixes the issue and will +1 the bug to get it uploaded to -updates.16:51
genii-aroundHi. I'm having difficulties aggregating 3 connections with bonding driver. Is there anyone around who might have some experience with it?16:57
stgraber_11:55 < sbeattie> hrm, well, the SRU team can't accept it until there's an upload. Wonder what happened there.16:59
stgraber_11:55  * sbeattie goes to read the scrollback in #ubuntu-server as well.16:59
stgraber_zul: ^16:59
genii-aroundSome more specific info on the bonding driver setup: lan is on 192.168.0.X, dhcp served by eth0. eth1,eth2, and eth3 each connect to a router/modem and are static by router 192.168.1.(2,3,4) routers are static 192.168.1.(12,13,14) bond0 gets 192.168.1.1  mode517:10
genii-aroundDefault route is bond0. Masquerading is on. No router IPs are in resolv.conf or routes, only actual nameserver IPs. Dhcp sever passes bond0 IP as gateway,and actual nameserver IPs.This setup is currently working but lookups can take anywhere upwards of 60 seconds. Clients are various OS17:16
genii-aroundWork requires me, but if anyone has thoughts/insight on the subject I'll check scroll on returning17:17
J_P1hi all17:23
uvirtbot`New bug: #338411 in samba (main) "Cannot retreive share list if samba client and server have the same hostname" [Undecided,Confirmed] https://launchpad.net/bugs/33841117:49
ewookwhaat.. that shouldn't even be possible.17:49
cemc;)17:49
ewookwho in the world filed that..17:49
cemcsomething should complain if that's the case, ain't it ?17:50
ewookwell, yes..17:50
ewookI live Steve Langasek for explaining the obvious.17:55
dantalizingthats a bug in the network administrator18:00
JanCI think the installer proposes the same name each time...  ;)18:04
JanCsame hostname18:04
=== jussio1 is now known as jussi01
tx2650AJ247, if he`s using remote desktop stuff, then gui is obligatory or not18:50
tx2650Hi. Has anyone any experience on building promise tx2650 driver? I cant build it on .27 kernel.18:58
DiscipulusAnyone have experience with Sparc Servers? Specifically E5500?19:07
TravelerHey I'm trying to install on an old Dell PowerEdge 6450.  The install fails so I try a media check.  I know the CD is good, but the media test is failing.  (I actually have two of these 6450s and they behave the same.)19:25
dguitarTraveler, How do you know they are good? Are they burned discs?19:26
TravelerYes, I checksummed the image, the disk, and read the media check on two separate computers.19:27
dguitarBurn them @ a slower speed19:27
Travelers/read/ran19:27
dguitarLike 4x19:27
TravelerCan we just assume the disk are ok?  I ran the check on other computers.19:27
Travelerdguitar, i burned them at 1x19:27
dguitarhmmm, nm then ;)19:28
Traveleroops19:29
TravelerI think the problem might have to do with old hardware.19:29
TravelerI've tried enabling and disabling every combination of optios in the BIOS.19:31
orudiehi question. I installed roundcube webmail client a few weeks ago, how can i now find out which version i installed19:48
oomkillercan anyone tell me how to allow any ipv6 forwarding from ipv6 interface20:00
oomkilleri am getting this in the logs: L Mar  6 13:57:24 router kernel: [ 1144.038605] [UFW BLOCK FORWARD]: IN=eth0 OUT=sixxs SRC=2001:4830:1600:013a:71c2:9ee6:c701:6ad5 DST=2001:4860:a003:0000:0000:0000:0000:0068 LEN=80 TC=0 HOPLIMIT=63 FLOWLBL=0 PROTO=ICMPv6 TYPE=128 CODE=0 ID=0 SEQ=2420:00
oomkillerwhen trying to ping from an internal compute20:00
jdstrandoomkiller: adjust /etc/default/ufw to have: DEFAULT_FORWARD_POLICY="ACCEPT"20:02
jdstrandoomkiller: you'll also want to adjust /etc/ufw/sysctl.conf to have:20:02
jdstrandnet/ipv4/ip_forward=120:02
jdstrandnet/ipv6/conf/default/forwarding=120:02
oomkilleryeah i already have the sysctls, lemme see if the forward policy setting makes it work20:04
jdstrandoomkiller: that assumes you want to route all traffic on the FORWARD chain. if not, leave the default policy alone and add ip6tables-restore style rules to /etc/ufw/before6.rules as necessary20:04
oomkillerjdstrand: well that would be ok, i only want to enable all for ipv620:04
jdstrandoomkiller: be warned, DEFAULT_FORWARD_POLICY does both ipv4 and ipv6 when ipv6 is enabled20:05
oomkillerwell what do i need to put in before6.rules to only do it on ipv620:05
jdstrand-A ufw6-before-forward -j ACCEPT20:07
oomkillerhmm i had that and it didnt work20:07
oomkillerdidnt block the packets, but didnt work20:07
jdstrandI'd verify your sysctls20:08
jdstrandsysctl net/ipv6/conf/default/forwarding20:08
oomkiller net.ipv6.conf.default.forwarding = 120:11
oomkilleri know its forwarding, or at least trying to, since it was blocking it before20:11
oomkillerand it works from the box20:12
oomkillerand i can ping6 the router20:12
oomkillerfrom this machine20:12
jdstrandis this for NAT? do you have POSTROUTING setup? If not, see /usr/share/doc/ufw/README.gz and/or https://help.ubuntu.com/8.04/serverguide/C/firewall.html20:14
oomkilleri dont want NAT on ipv6, but i do want it on ipv420:15
oomkillerall i want to do is route all my LAN ipv6 over my tunnel which is running on the router20:15
jdstrandnot sure what the problem is. seems clear ufw is no longer blocking though20:28
oomkilleryeah20:29
oomkillerits just not forwarding20:29
=== StevePearce_ is now known as StevePearce
joinADi am trying to add some ubuntu machines to a active directory domain21:04
joinADusing likewise21:04
joinADheres my syntax..21:04
joinADsudo domainjoin-cli join syrtime-local ACCOUNT PASS21:04
joinADwith a - i get a message telling me to make sure ports are open to syrtime-local21:05
ttxjoinAD: you should have complete domain name instead of "syrtime-local"21:05
ttxsomething like test-ad.company.com21:06
joinADok.. so the server name, then domain like smallbiz.syrtime.local?21:06
ttxno. The domain name21:06
ttxdomain name is syrtime.local ?21:07
joinADyes21:07
ttxthere is a bug with .local domains... let me check it up21:07
joinADactually i think its syrtime-local21:07
ttxthen it's incorrect, you need a fqdn there21:08
ttxhttp://doc.ubuntu.com/ubuntu/serverguide/C/likewise-open.html21:08
joinADyes... when i use the - i get the message about ports21:08
joinADi wonder if server08 is not playing nice with a non windows machine21:09
ttxhttps://bugs.launchpad.net/ubuntu/+source/likewise-open/+bug/20523621:09
uvirtbot`Launchpad bug 205236 in likewise-open "Joining .local domains doesn't work out of the box in Hardy" [Low,Confirmed]21:09
joinADthanks for link21:09
ttxI test with w2k8 server. it works21:09
ttxgood luck ;)21:10
joinADnice21:10
joinADthese older win 2k machines run nice under hardy21:11
joinADyeah a nslookup on the IP returns smallbiz.syrtime.local21:12
joinADso i guess it is the syrtime.local21:12
orudieif i installed package with dpkg , can i remove it with apt-get purge ?21:24
AdamDVHey, I need some update-motd help.21:25
orudiei installed roundcube with dpkg and got hacked21:28
orudiethe package that ubuntu provides is insecure21:28
orudiewhich is old version21:28
AdamDVNo, it is't21:28
AdamDVThen build from source.21:28
orudiehow can i completely remove roundcube ?21:29
orudieif i installed it with dpkg21:29
orudiei tried apt-get purge roundcube, it removes, but then when i do apt-get install roundcube it installs and the database and other stuff is still there21:30
orudielike i didnt even have to configure any files21:30
AdamDVsudo apt-get remove roundcube-webmail --purge && sudo apt-get autoremove21:30
orudieand it still works21:30
AdamDVHow bout instead of installing from repo, you install from source, its quite easy.21:31
AdamDVI did.21:31
AdamDVhttp://go-techo.com/staff/mail21:31
orudieAdamDV, cool i will21:32
orudieAdamDV, that completely removed roundcube thanx21:32
AdamDV:D21:32
orudieAdamDV, do you think you can help me out with installing the latest version 2.0 ?21:33
AdamDVNo problem, you managing a server first time?21:33
orudieAdamDV, its for my company21:33
AdamDVSUre21:33
AdamDVNo problem :D21:33
orudieAdamDV, lol no, just not used to installing from source21:33
AdamDVfirst, go to http://roundcube.net21:33
orudieAdamDV, never needed to21:33
AdamDVHeh :D21:33
AdamDVDoes this server have a GUI?21:34
orudieok i'm there21:34
ScottKAdamDV: Are you going to be around to help him with security updates?21:34
AdamDVYes21:34
hadsheh21:34
orudiewhy ?21:34
AdamDVYou like being hacked?21:34
orudiedude21:34
AdamDV:D21:34
orudiethis host I assume is not hacked yet21:34
AdamDVThats what security updates are for.21:35
orudiemy other one is , which is not as important as this one21:35
ScottKAdamDV: Because what you're recommending is not supported here21:35
AdamDVAlso, ScottK: The 2.0 release is much more secure.21:35
AdamDVAlright, orudie, join #techo21:35
AdamDV:D21:35
ScottKGenerally we try to use the packaging system here.21:35
AdamDVBut, it isn't always best21:36
ScottKYes, but it didn't purge the way he thought it would seems a pretty trivial reason to throw out the whole system.21:37
AdamDVErr...21:38
orudieAdamDV, back21:41
AdamDVALright21:41
SuperQI don't know if anyone here cares about this, but I have been doing some tests of kvm performance22:28
SuperQI built 2.6.28-8 on my hardy based kvm-84 server22:28
SuperQ(yea, I backported kvm/libvirt/kernel from jaunty)22:28
SuperQI added hugepages=7000 (16G opteron machine) to the host kernel22:29
SuperQand I booted a test VM with and without hugepages support (-mem-path /hugepages)22:31
SuperQadding -mem-path /hugepages (with the appropriate hugepages mount path) improves a linux build speed by ~5-6% inside the VM22:31
orudieAdamDV, thanx for your help22:32
orudiei'm out22:32
orudiegotta drive home22:32
orudieits friday22:32
AdamDV:D22:32
AdamDVNetsplit!22:43
roy_hobbsHey.  I just installed Kerberos5 according to the Ubuntu Server Guide.  When I went to test it by doing "kinit user/admin" I got the message kinit(v5): Cannot contact any KDC for realm 'TEST.LOC' while getting initial credentials23:09
roy_hobbsI ran kinit from the same machine the server is running on23:09
* oli_ 23:31
oli_exit23:31
olcafome23:45
* olcafo 23:45
orudiehi23:54
orudiedave23:54
orudiearound ?23:54

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!