[00:10] Apparently I need to configure dns-sec and possibly apparmor prevents dhcp from updating stuff in /etc/bind [00:11] why do you need dns-sec? [00:11] (it isn't a bad idea ... but need?) [00:14] I don't know. :P [00:14] All the guides suggest it, but I really haven't found a decent looking guide on the topic. [00:15] hah [00:16] don't bother [00:16] it's an advanced topic [00:16] it doesn't sound like you're ready for that [00:18] http://www.cahilig.org/debian-and-ubuntu-ddns-with-bind9-and-dhcp [00:19] iirc, the preferred location for zones that need to be writable by bind is /var/cache/bind [00:20] AtomicSpark: is this for a large network? [00:20] JanC: No. ~10 computers, but not being able to resolve hostnames is annoying. espeically when there is a shared printer. :P [00:20] /etc/apparmor.d/usr.sbin.named contains the apparmour profile, defining what dirs can be read, written to and executed from [00:21] and by the sounds of things, you dont /need/ dnssec [00:21] Deeps: Yeah. I saw that. [00:21] AtomicSpark: then maybe use dnsmasq ? [00:21] it's much easier to setup for this sort of thing... [00:24] it does both (simple) DNS & DHCP [00:26] Hmm. Can't find the key. AppArmor is probably hiding it. [00:27] Deeps: so I copy the local zones to /var/cache/bind then update the named.conf.local paths? [00:37] Hmm. Time to try dnsmasq or just fall back onto the router. :P === AtomicSpark_ is now known as AtomicSpark === JanC_ is now known as JanC [04:42] If I start up a new Ubuntu Server instance with KVM, how do I ssh into it? [04:44] Use the IP address you gave it? [05:05] ryanprior: "with KVM" or "within KVM"? [05:05] ryanprior: in the case of the latter, you need to get its network up, using e.g. -curses or -vnc :0 long enough to tweak its network config. [05:05] I start it like so: kvm -hda my.img [05:06] So, with kvm. [05:22] Er, if my.img is your Ubuntu server, then that server is running *within* kvm. [05:47] Ubuntu 8.10 JOES - is it possible to install ssh-client without it brining in x11-common, and the various x11 libs? or the ssh server for that matter? or will I have to just install the full version of server for this to work? I am testing with VirtualBox 2.1 === rgreening_ is now known as rgreening [05:49] heh [05:50] don't install the recommends [05:52] * JanC thinks "install recommends by default" should be disabled on ubuntu-server [05:52] JanC, was that directed to me? it includes these packeges in the "the following extra packages will be installed" section, there are more "suggested" but i'm not even including those??? [05:52] ZykoticK9: use the '--no-install-recommends' option for apt-get [05:53] "recommends" is stronger than "suggests" [05:53] Mmm recommends can be annoying [05:54] JanC, thank you :) that cuts the list down DRAMATICALLY. thanks, great tip! [05:54] I disable this on my system by default ;) [05:54] systems [05:54] even on desktops [05:54] JanC, how is that done? [05:55] put "APT::Install-Recommends "0";" in /etc/apt/apt.conf [05:56] JanC, Thank you. [05:56] this behaviour is probably useful for many desktop users [05:57] JanC, even more so on server I'd imagine. [05:57] I mean that Install-Recommends "1" is probably useful for most desktop-users [05:58] the default behaviour [05:58] but on servers, it often sucks [05:58] gotcha :) Thanks again. [05:59] and if you want a desktop that only has the dependencies you need/want, it's useful too [05:59] if they want recommends installed by default, then this is a bug in the packaging anyway [06:00] so you might want to file a bug report [06:00] * JanC goes to sleep now [06:00] JanC: for Debian, at least, the Debian Policy manual's definition of Recommends makes it sound like it *should* be opt-out. The real problem is all the assholes who made packages using Recommends instead of Suggests because, at the time, they had the same semantics (opt-in). [06:00] ...that's my view, anyway. [06:00] JanC, with your tip I was able to install ssh client & server without brining down a bunch of stuff I did NOT want. I found it INSANE that you had to install X in order to have SSH on the console. [06:00] it's 7am here ;) [06:00] twb: agreed [06:01] twb: Language [06:01] hads: sorry. [06:01] np [06:02] wow, are we really that stuck-up about language here? [06:02] giovani: it's not worth arguing about. [06:02] but it's worth making people feel like they've done something wrong? [06:02] http://www.ubuntu.com/community/conduct [06:02] well, many of those people didn't do that because they are assholes, but because everybody else did it, I guess ;) [06:03] JanC: let us say they did it out of ignorance, then [06:04] hads: I didn't see any mention of "curse words" in there [06:04] something like that (and because the Debian guidelines weren't clear enough, probably) [06:04] but maybe I missed it [06:05] giovani: some people don't like "curse words", so avoiding them isn't bad [06:05] OTOH, nobody kicked or banned twb :P [06:06] JanC: I think making people feel like they've done something wrong by using certain words is counter-productive, but alright -- I'm going to bed [06:12] Personally, I consider it linguistic apartheid. [06:13] then why say sorry ;) [06:13] JanC: because it appeases the crazies who complain [06:14] JanC: and because I don't care particularly about #ubuntu-server [07:42] Hi Guys. [07:42] I'm having trouble with an Intel SDS2 + Intel Gbit Coppercable + Adaptec 2610SA SATA RAID. [07:42] Both PCIX Devices run extremely slow and i don't know why [07:43] running 8.10 server [08:01] New bug: #338556 in net-snmp (main) "[jaunty] libsnmp-python: Depends: python (< 2.6)" [Undecided,Confirmed] https://launchpad.net/bugs/338556 [08:33] my brain aint working today it seems, so ive got some possibly stupid DNS questions, I've just got a new vps running ubuntu server. could I run bind on it and use it as my master server? (and then set the name server to be the ip address of the vps) [08:36] harrisony: sounds like it should work [08:38] would that also work for RDNS? [08:40] if i was to go host would it respond with what I set it as? [08:40] That is for your provider to setup [08:41] got i [08:41] t [08:41] I don't know if I'd trust my DNS to a VPS but [08:42] I don't my provider (prgmr.com) offers dns for me so unless i find some free thing or another plan [08:42] Depends how important your services being up are really. [08:46] had a feeling it wouldn't work out :P === ogra_ is now known as ogra [11:04] lo === cjwatson_ is now known as cjwatson [11:50] New bug: #264808 in ant (main) "Package does not work with JDK 5" [High,Fix released] https://launchpad.net/bugs/264808 [12:03] 12:49 -!- stefan_can [n=stefan@83.217.112.50] has joined #ubuntu-server [12:03] 13:01 -!- DragonLord- [n=ask@84-217-68-182.tn.glocalnet.net] has joined #ubuntu-server [12:03] [13:02] [Barre(+ei)] [5:FreeNode/#ubuntu-server(+cnt)] [Act: 1] [165 nicks (@0 %0 +0 165)] [12:03] [#ubuntu-server] /hilight [12:03] sorry [12:25] New bug: #338720 in php5 (main) "Function lookup problem after calling setlocale(LC_ALL, "tr_TR")" [Undecided,New] https://launchpad.net/bugs/338720 [12:30] New bug: #338704 in nagios3 (main) "description missing in nagios config" [Undecided,Confirmed] https://launchpad.net/bugs/338704 [13:37] hi there. I get the impression the oom-killer is disabled on server kernels [13:38] anyone can confirm this ? [13:38] and maybe give a hint on how to enable/disable it ? [14:39] New bug: #333460 in libpam-ldap (universe) "[Hardy][LDAP]client authentication broken" [Undecided,New] https://launchpad.net/bugs/333460 [14:49] frzz: How is it you have this impression? [15:02] ScottK: wrote a simple program that mallocs and memsets memory [15:02] the system juste becomes unresponsive [15:02] if I do the same on a desktop kernel, the process just gets killed and I get a "out of memory killed" or something in dmesg [15:24] Hey [15:25] I'm wondering, can Debian be updated to Ubuntu? :P [15:28] Sarge -> Dapper was doable. After that, not so much as you need the sysv -> upstart transition we did in Edgy === JanC_ is now known as JanC [15:47] zul: Hi, I was wondering what was going on with the update to the redhat-cluster-suite package mentionned in LP#290399, I can't seem to find it, even in proposed [15:48] mjeanson: we are waiting for hardware to test its in my ppa right now [15:52] zul: hum, I only have production systems running redhat cluster which makes me a bit nervous to test this update [15:52] mjeanson: yes I realize that Ill see what I can do to speed the process up [15:53] zul: do you know if anybody is in the process of testing it? [15:53] mjeanson: not that I am aware of it [15:54] zul: I may be able to try it this evening, I have a maintenance window [15:55] mjeanson: if you can that would be great [15:55] zul: do you need specific testing done? [15:55] mjeanson: just needs to see if scsi_fencing works [15:56] BrunoXLambert: not on vacation? [15:56] zul: I'm not using this fencing method, is the fix specific to it? [15:57] mjeanson, sure am. [15:57] mjeanson: it is [15:58] zul: I have been running in a similar race condition with the gfs control deamon, I had hope the patch addressed that [15:59] mjeanson: ok the scsi_fence thing is something else then ttx ^^^ [16:01] mjeanson: wasn't accepted in -proposed yet. You can test the one in my PPA though. It's the same. [16:01] https://launchpad.net/~ttx/+archive/ppa [16:04] zul: just checked the patch and it definitely applies to the control daemons, so I'll try it tonigh [16:11] zul: I'll report the result of my tests in the launchpad bug, will that be enough to have it accepted? [16:16] mjeanson: it should [16:19] ttx: oups, had not notticed it wasn't zul talking anymore [16:20] ttx: have you tried the package yourself? [16:20] mjeanson: no, but someone else did already (on a private bug) [16:24] ttx: any additionnal information in the private bug which may be useful to me? [16:25] mjeanson: no, it's a copy of the public one. [16:25] except the tester data/ok [16:25] ttx: cause I haven't been able to steadily reproduce this problem [16:26] Hello, do any of you have experience with SPARC servers? Specifically a E5500 [16:38] sommer: hi - is there a section on auth-config-client in the server guide? [16:42] I am creating a preseed config for my servers, however I noticed i am having problems configuring my bonded network [16:42] so i thought i would cheat and wget http://server/net_`hostname` however that doesn't seem to work [16:42] mathiaz: yeppers [16:43] mathiaz: also ldap-auth-client [16:44] ttx: btw, why ins't it in proposed? [16:44] mjeanson: waiting for SRU review afaict [16:46] ttx: I may be all mixed up but I tought it needed to be in proposed to be reviewed? [16:47] mjeanson: yes, but the SRU rationale must be accepted for it to be accepted in -proposed. [16:47] zul: ^ am I right ? Is it the reason it's stuck in limbo right now ? [16:48] thats right [16:48] ttx: but also we didnt have the hardware to test it until recently as well [16:51] about that SRU thing for redhat-cluster-suite, according to https://wiki.ubuntu.com/StableReleaseUpdates the process seems to be that once the bug is valid on LP it should be uploaded to -proposed then will be reviewed by the archive admins when it's in the queue. Once validated it'll be added to -proposed. The SRU team then will make sure it fixes the issue and will +1 the bug to get it uploaded to -updates. [16:57] Hi. I'm having difficulties aggregating 3 connections with bonding driver. Is there anyone around who might have some experience with it? [16:59] 11:55 < sbeattie> hrm, well, the SRU team can't accept it until there's an upload. Wonder what happened there. [16:59] 11:55 * sbeattie goes to read the scrollback in #ubuntu-server as well. [16:59] zul: ^ [17:10] Some more specific info on the bonding driver setup: lan is on 192.168.0.X, dhcp served by eth0. eth1,eth2, and eth3 each connect to a router/modem and are static by router 192.168.1.(2,3,4) routers are static 192.168.1.(12,13,14) bond0 gets 192.168.1.1 mode5 [17:16] Default route is bond0. Masquerading is on. No router IPs are in resolv.conf or routes, only actual nameserver IPs. Dhcp sever passes bond0 IP as gateway,and actual nameserver IPs.This setup is currently working but lookups can take anywhere upwards of 60 seconds. Clients are various OS [17:17] Work requires me, but if anyone has thoughts/insight on the subject I'll check scroll on returning [17:23] hi all [17:49] New bug: #338411 in samba (main) "Cannot retreive share list if samba client and server have the same hostname" [Undecided,Confirmed] https://launchpad.net/bugs/338411 [17:49] whaat.. that shouldn't even be possible. [17:49] ;) [17:49] who in the world filed that.. [17:50] something should complain if that's the case, ain't it ? [17:50] well, yes.. [17:55] I live Steve Langasek for explaining the obvious. [18:00] thats a bug in the network administrator [18:04] I think the installer proposes the same name each time... ;) [18:04] same hostname === jussio1 is now known as jussi01 [18:50] AJ247, if he`s using remote desktop stuff, then gui is obligatory or not [18:58] Hi. Has anyone any experience on building promise tx2650 driver? I cant build it on .27 kernel. [19:07] Anyone have experience with Sparc Servers? Specifically E5500? [19:25] Hey I'm trying to install on an old Dell PowerEdge 6450. The install fails so I try a media check. I know the CD is good, but the media test is failing. (I actually have two of these 6450s and they behave the same.) [19:26] Traveler, How do you know they are good? Are they burned discs? [19:27] Yes, I checksummed the image, the disk, and read the media check on two separate computers. [19:27] Burn them @ a slower speed [19:27] s/read/ran [19:27] Like 4x [19:27] Can we just assume the disk are ok? I ran the check on other computers. [19:27] dguitar, i burned them at 1x [19:28] hmmm, nm then ;) [19:29] oops [19:29] I think the problem might have to do with old hardware. [19:31] I've tried enabling and disabling every combination of optios in the BIOS. [19:48] hi question. I installed roundcube webmail client a few weeks ago, how can i now find out which version i installed [20:00] can anyone tell me how to allow any ipv6 forwarding from ipv6 interface [20:00] i am getting this in the logs: L Mar 6 13:57:24 router kernel: [ 1144.038605] [UFW BLOCK FORWARD]: IN=eth0 OUT=sixxs SRC=2001:4830:1600:013a:71c2:9ee6:c701:6ad5 DST=2001:4860:a003:0000:0000:0000:0000:0068 LEN=80 TC=0 HOPLIMIT=63 FLOWLBL=0 PROTO=ICMPv6 TYPE=128 CODE=0 ID=0 SEQ=24 [20:00] when trying to ping from an internal compute [20:02] oomkiller: adjust /etc/default/ufw to have: DEFAULT_FORWARD_POLICY="ACCEPT" [20:02] oomkiller: you'll also want to adjust /etc/ufw/sysctl.conf to have: [20:02] net/ipv4/ip_forward=1 [20:02] net/ipv6/conf/default/forwarding=1 [20:04] yeah i already have the sysctls, lemme see if the forward policy setting makes it work [20:04] oomkiller: that assumes you want to route all traffic on the FORWARD chain. if not, leave the default policy alone and add ip6tables-restore style rules to /etc/ufw/before6.rules as necessary [20:04] jdstrand: well that would be ok, i only want to enable all for ipv6 [20:05] oomkiller: be warned, DEFAULT_FORWARD_POLICY does both ipv4 and ipv6 when ipv6 is enabled [20:05] well what do i need to put in before6.rules to only do it on ipv6 [20:07] -A ufw6-before-forward -j ACCEPT [20:07] hmm i had that and it didnt work [20:07] didnt block the packets, but didnt work [20:08] I'd verify your sysctls [20:08] sysctl net/ipv6/conf/default/forwarding [20:11] net.ipv6.conf.default.forwarding = 1 [20:11] i know its forwarding, or at least trying to, since it was blocking it before [20:12] and it works from the box [20:12] and i can ping6 the router [20:12] from this machine [20:14] is this for NAT? do you have POSTROUTING setup? If not, see /usr/share/doc/ufw/README.gz and/or https://help.ubuntu.com/8.04/serverguide/C/firewall.html [20:15] i dont want NAT on ipv6, but i do want it on ipv4 [20:15] all i want to do is route all my LAN ipv6 over my tunnel which is running on the router [20:28] not sure what the problem is. seems clear ufw is no longer blocking though [20:29] yeah [20:29] its just not forwarding === StevePearce_ is now known as StevePearce [21:04] i am trying to add some ubuntu machines to a active directory domain [21:04] using likewise [21:04] heres my syntax.. [21:04] sudo domainjoin-cli join syrtime-local ACCOUNT PASS [21:05] with a - i get a message telling me to make sure ports are open to syrtime-local [21:05] joinAD: you should have complete domain name instead of "syrtime-local" [21:06] something like test-ad.company.com [21:06] ok.. so the server name, then domain like smallbiz.syrtime.local? [21:06] no. The domain name [21:07] domain name is syrtime.local ? [21:07] yes [21:07] there is a bug with .local domains... let me check it up [21:07] actually i think its syrtime-local [21:08] then it's incorrect, you need a fqdn there [21:08] http://doc.ubuntu.com/ubuntu/serverguide/C/likewise-open.html [21:08] yes... when i use the - i get the message about ports [21:09] i wonder if server08 is not playing nice with a non windows machine [21:09] https://bugs.launchpad.net/ubuntu/+source/likewise-open/+bug/205236 [21:09] Launchpad bug 205236 in likewise-open "Joining .local domains doesn't work out of the box in Hardy" [Low,Confirmed] [21:09] thanks for link [21:09] I test with w2k8 server. it works [21:10] good luck ;) [21:10] nice [21:11] these older win 2k machines run nice under hardy [21:12] yeah a nslookup on the IP returns smallbiz.syrtime.local [21:12] so i guess it is the syrtime.local [21:24] if i installed package with dpkg , can i remove it with apt-get purge ? [21:25] Hey, I need some update-motd help. [21:28] i installed roundcube with dpkg and got hacked [21:28] the package that ubuntu provides is insecure [21:28] which is old version [21:28] No, it is't [21:28] Then build from source. [21:29] how can i completely remove roundcube ? [21:29] if i installed it with dpkg [21:30] i tried apt-get purge roundcube, it removes, but then when i do apt-get install roundcube it installs and the database and other stuff is still there [21:30] like i didnt even have to configure any files [21:30] sudo apt-get remove roundcube-webmail --purge && sudo apt-get autoremove [21:30] and it still works [21:31] How bout instead of installing from repo, you install from source, its quite easy. [21:31] I did. [21:31] http://go-techo.com/staff/mail [21:32] AdamDV, cool i will [21:32] AdamDV, that completely removed roundcube thanx [21:32] :D [21:33] AdamDV, do you think you can help me out with installing the latest version 2.0 ? [21:33] No problem, you managing a server first time? [21:33] AdamDV, its for my company [21:33] SUre [21:33] No problem :D [21:33] AdamDV, lol no, just not used to installing from source [21:33] first, go to http://roundcube.net [21:33] AdamDV, never needed to [21:33] Heh :D [21:34] Does this server have a GUI? [21:34] ok i'm there [21:34] AdamDV: Are you going to be around to help him with security updates? [21:34] Yes [21:34] heh [21:34] why ? [21:34] You like being hacked? [21:34] dude [21:34] :D [21:34] this host I assume is not hacked yet [21:35] Thats what security updates are for. [21:35] my other one is , which is not as important as this one [21:35] AdamDV: Because what you're recommending is not supported here [21:35] Also, ScottK: The 2.0 release is much more secure. [21:35] Alright, orudie, join #techo [21:35] :D [21:35] Generally we try to use the packaging system here. [21:36] But, it isn't always best [21:37] Yes, but it didn't purge the way he thought it would seems a pretty trivial reason to throw out the whole system. [21:38] Err... [21:41] AdamDV, back [21:41] ALright [22:28] I don't know if anyone here cares about this, but I have been doing some tests of kvm performance [22:28] I built 2.6.28-8 on my hardy based kvm-84 server [22:28] (yea, I backported kvm/libvirt/kernel from jaunty) [22:29] I added hugepages=7000 (16G opteron machine) to the host kernel [22:31] and I booted a test VM with and without hugepages support (-mem-path /hugepages) [22:31] adding -mem-path /hugepages (with the appropriate hugepages mount path) improves a linux build speed by ~5-6% inside the VM [22:32] AdamDV, thanx for your help [22:32] i'm out [22:32] gotta drive home [22:32] its friday [22:32] :D [22:43] Netsplit! [23:09] Hey. I just installed Kerberos5 according to the Ubuntu Server Guide. When I went to test it by doing "kinit user/admin" I got the message kinit(v5): Cannot contact any KDC for realm 'TEST.LOC' while getting initial credentials [23:09] I ran kinit from the same machine the server is running on [23:31] * oli_ [23:31] exit [23:45] me [23:45] * olcafo [23:54] hi [23:54] dave [23:54] around ?