[00:23] hello all, does a default server install not load modules needed to playback sound? [00:23] I built a NAS out of an MSI wind pc, now I want to also be able to use the onboard sound card to play music from it [00:24] I need to check when or @ what time a process in the ps falls away... how can I do this / [00:24] I installed cmus via apt-get, but when I try to play a track it says "error: opening audio device: No such file or directory" [00:30] luckyone: http://ubuntuforums.org/showthread.php?t=205449 that should get you where you need to go! [00:32] check out moc if you want to access it via ssh... or if you want a web based solution, jinzora is great. you can use the web interface, hit play, and it plays on your server box. [00:33] diffra: I am using cmus right now - pretty slick, I will check out moc [00:34] cmus may have to load the entire directory structure every time (which isn't good) [00:35] diffra: I was missing linux-sound-base, that is probably a pretty important package [00:50] hello, has anyone ever had a problem on ubunttu server 8.04.2 when it cant ping hosts, it is resolving dns [01:02] to whitelist a sender domain (using this set up: https://help.ubuntu.com/9.04/serverguide/C/mail-filtering.html), do I use the DKIM whitelist or an amavisd whitelist? [01:02] (I don't fully understand DKIM yet) [01:03] depends on what you're wanting to whitelist. [01:03] basically, short answer is both. [01:04] diffra: to clarify, I just want to prevent several addresses from being marked as spam, ever. [01:06] for amavis, 1) is the read_hash for the whitelist file valid syntax, and 2) where do I put that directive since there is no /etc/amavis.conf in ubuntu? -> http://flakshack.com/anti-spam/wiki/index.php?page=Installing+and+configuring+Amavisd-new [01:06] then, yeah, both. the page says that it's passing to dkim/spf seperately from amavis, so they'll each need to be whitelisted [01:07] FTA: "Amavisd-new can be configured to automatically Whitelist addresses from domains with valid Domain Keys. There are some pre-configured domains in the /etc/amavis/conf.d/40-policy_banks" [01:07] not sure about dkim.. never used it. [01:07] diffra: thanks, looking [01:09] diffra: the author_to_policy_bank_maps made me unsure; thanks, I'll give this a try [01:10] Sure. Check the sectino in the guide you linked... it gives several examples how to whitelist in amavisd. [01:10] section even. [01:12] diffra: I did notice that section, but the DKIM heading made me think it was tied solely to DKIM, while being unsure if DKIM and amavis are not the same thing, or closely connected, etc etc.. :D confusing [01:23] jeebus crisp, 125 processes with only 4 ports open. I guess this is teh new internets. [01:23] err, 131 [01:35] bc: yeah, i'm not really a fan of big configs like that. [01:35] I rock lighttpd, postfix/dovecot with RBLs, and run spamassassin client side. [01:37] diffra: I run spamassassin client side as well, but the other users were screaming halp before I put in a new server. [01:38] diffra: the server is about the size of a hard back book. I guess in about 5 years they'll be the size of a RJ45 plug or something. [01:38] bc: those exist you know. one second. [01:39] diffra: see, i'm already behind the curve [01:41] http://www.digi.com/products/embeddedsolutions/digiconnectme9210.jsp [01:42] diffra: sheesh, that's insane [01:43] sure, it's not x86 or anything, but you could probably make a passable static http server out of it. [02:20] diffra: Did you get your policy_banks question sorted out? [02:40] H ALL [02:41] есть кто русский [02:41] ? [02:41] VinchenzO, english in here === mobi-sheep__ is now known as mobi-sheep_ [03:56] ScottK: that was bc with the question, i was just trying to help [04:16] ScottK: thanks; yes, problem solved [04:29] Anyone can tell me how to make the server download vcards? [04:30] right not its just displaying in page === mobi-sheep_ is now known as kinja-sheep [04:36] right now Im linking to vcard but it opens in html file [04:37] are you using .vcf? [04:37] or .vcard? [04:37] I'm using .vcf [04:37] should I use vcard? [04:38] either way, this should work in your apache config: http://dpaste.com/59037/plain/ [04:39] Thank you diffra! [04:39] you could also do this in php/perl if you were so inclined, but i think this is the prettiest way to go about it. [04:40] np. i just googled something like "apache force download by file extension", found a page about doing the same thing for .pdf files, and changed the regex to match your .vcard files :) [04:40] diffra should I add this to the directory the vcards are held in? [04:40] in a .htaccess file? [04:41] that would work. [04:41] or under a tag in apache2.conf [04:41] man Ive been trying to do this for 3 days now :) [04:41] thank you! [04:41] np. let me know if it doesn't work... [04:41] will do :) === s_markow_ is now known as s_markow [04:43] You rock dude, it worked! [04:43] thank you diffra! [04:43] sa-weet [04:43] lol [04:58] quiet in here 'eh? [05:01] Does Ubuntu Server have a GUI Installer? [05:06] MrPockets: no. It's CLI only. The installer has a text-based 'gui' of sorts: http://images.howtoforge.com/images/samba_setup_ubuntu_5.10/img_22.gif [05:06] mhmm [05:07] I'm just having issues with this machine, and would like to revert back to a GUI noob-friendly install to try and sort out some issues. Might just put 8.10 Desktop version on and run as a server [05:09] MrPockets: there's really nothing too wrong with that. You lose some RAM to the gui, and there's the security risks entailed with all the extra software. [05:09] neologistically speaking, d-i is a "TUI", which basically means a GUI on a charcell display. [05:09] right. I'm only looking to use this box as somewhat of a security-camara server that i can term=service into and creep on whats going on in the data center via webcam [05:09] and download torrents [05:10] a desktop version with a firewall should be exactly what you want [05:12] Jesus. you are the nicest linux guys i've ever seen. [05:12] All of the linux guys (usually myself included) are all, BAH! you don't need a GUI on a server! HUmbug! [05:13] MrPockets: that's because most of the channel is newbie like you ;-P [05:13] under most circumstances, sure, you don't need it. but it's not like if you apt-get install ubuntu-desktop Canonical kills a kitten. [05:13] Wouldn't say I'm a noob. Just tired and wanna get this at least on the network so i can leave this god forsaken dungon and go home :-( [05:14] That's why I keep a sleeping bag and a pillow in the office... [05:14] LOL [05:14] ...no joke? [05:15] Once I was up all night fixing a server for deployment, then I spent the whole next day out at the prison deploying the damn thing [05:15] Though that's a pathological case. [05:16] WTF. I get a BusyBox v1.1.3 Built-in Shell enter Help for a list of commands [05:16] Now that I have a bicycle, I tend not to sleep in the office anymore -- back when I took public transport, I'd have to wait until 6am for the trains to start again anyway. [05:16] MrPockets: you have messed up bootstrapping somehow [05:16] MrPockets: busybox is part of the ramdisk; you get dumped there if it can't find your root partition. [05:16] I just reformatted both drives [05:16] but i just booted live to the Ubuntu CD.. [05:17] twb: been there. Spent the night in a not-really-cold-enough room triaging a win2k machine that got pwned. [05:18] one of those boxes that's always been around, deployed before my time, i had no idea half the shit that was on there. [05:18] Bleh, at least I don't have to touch Windows [05:18] hah [05:18] all but two of the servers we administrate are windows [05:18] administer? [05:18] MrPockets: "admin" vt. [05:19] Any of you have experience imaging machines with Acronis? [05:20] Hi, I can't seem to be able to remove the package doc-base [05:20] I keep getting circular dependencies and errors about removal [05:22] seems like the post removal script wants to use install-docs and that file was just removed [05:27] http://pastie.org/522520 [05:29] This isn't fun any more. [05:29] I wanna go home. [05:31] LiraNuna: this is a hack, but maybe just drop a bash script in /usr/local/bin/install-docs that returns true and exits to satisfy apt? [05:32] i'm sure that install-docs is supposed to do something, but if it's already being removed, i don't see that it could be that important. [05:32] diffra, that was my last resort [05:32] google doesn't come up with anything too [05:33] I guess it's bug filing time [05:50] When a 8.04 server boots, what happens between "Starting" and "Loading, please wait"? [05:55] on one box I have it on, I've found if I dont have the VGA monitor cable plugged in, it stops at "Starting" and doesnt continue [05:55] Even adding debug to kernal doesnt help .. because it hasnt loaded it yet [06:24] I am building a network for a class that needs to be a secure as possible and still provide a few basic services (http,smtp,imap,dns). I have only one computer that can be used to provide these services. I want to seperate them into VM's but while the computer has ok hw it doesn't have any intel-VT. I was thinking about using xen but I wanted to see what others thought. [06:26] A little more info. Right now it is running 2k3 with dns and virtual server on the host and 2k3 with http, smtp, and imap in a guest. I don't need to keep the same os's I just need to provide the same services on the same "public" ip's. [06:27] Xen would probably work for what you need. [06:28] But as far as security goes, avoid running any kind of services on the dom0/host. [06:28] I mean, I'd probably only go as far as running SSH with password logins disabled [06:34] nick125, I was planning on leaving the host as empty as possible. I would really like to be running something baremetal but I think that xenserver is the only baremetal hyperviser that will support linux guests without hvm. I don't have any previous experiance with that product. [06:34] I know ESXi will support without HVM (I believe), but it's missing a lot of features compared to Xen. [06:38] nick125, yes but ESXi is VERY picky about what hw it runs on. Will ubuntu's current set of tools for KVM host jeos without hvm? [06:38] yeah, true...not to mention the lack of swraid, which is why I ultimately decided against ESXi. [06:39] I'm not too familiar with JeOS. [06:41] It appears that JeOS's vmbuilder supports Xen without issues [07:23] how do I configure postfix's root redirection? [07:24] ^ ignore that please, I should've google [07:24] LiraNuna: Error: "ignore" is not a valid command. [07:24] Is there any point in trying to do SMARTd on a SATA disk? [07:24] They seem to hate one another (smart and sata) === maxb_ is now known as maxb [12:22] New bug: #391540 in mysql-dfsg-5.0 (main) "mysql client at x86_64 cannot find /etc/mysql/my.cnf" [Undecided,New] https://launchpad.net/bugs/391540 [12:41] New bug: #391551 in openssh (main) "package openssh-server 1:5.1p1-5ubuntu1 failed to install: sub process post-installation script returned error code 1" [Undecided,New] https://launchpad.net/bugs/391551 [13:44] Anyone using KVM? [13:46] heath|work: yes [13:46] sommer, I am torn between going xen or kvm. It looks like Ubuntu choose kvm over xen? [13:46] heath|work: yep, kvm is great [13:47] sommer, do you use opennebula ? [13:47] heath|work: I've done some testing with it, and worked on some documentation, but I've never used it in production [13:48] heath|work: mostly because I don't currently have a shared storage solution... if I did I'd probably use opennebula [13:50] We have a NFS ready to go, it looks like KVM encourages nfs use which is attractive. So far I like everything I have seen. Our biggest fear is choosing something that dies out, but if Conical is behind it, it makes for an easier decision. [13:50] heath|work: Not to mention the fact that RHEL is behind it. [13:51] That sounds good as well. I see that Citrix is running with Xen, but there OS support is limited. [13:52] heath|work: ya, I don't think KVM is going to die out anytime soon [13:52] heath|work: but really the hypervisor isn't as important as being able to access the VM image, as long as future virt technology can migrate, read, etc the VM is the important thing [13:53] least in my view ;-) [13:53] It also looks like OpenNebula can control KVM, Xen, and Amazon servers. What I want to know is if it is possible to migrate between the different hosts. [13:53] That would be total freedom and rid any fear of support dieing out for one. [13:53] I wouldn't think so... at least not automatically [13:54] and at this time... maybe in the future [13:55] Thanks for the input... We really didn't want to stray away from Ubuntu and I think we are going to try the KVM route. [13:56] VMware pricing is crazy and I am didn't like having to search for fixes for Ubuntu and xen every 10 minutes [14:00] np, I've been very happy with KVM... well KVM+libvirt and friends [14:01] Ubuntu has documented it very well. I will run through those and get my virts up! [14:06] Hi all I need some help with postfix and dynamic IPs, i get a DNS fwd/rev mismatch... === genii_ is now known as genii [14:17] im trying to set up mail with a dynamic ip using no-ip.com but currently get a DNS mismatch can someone point me in the right direction please? [14:31] oakbox: sounds like a configuration problem? ask no-ip.com? [14:38] oakbox: you're not going to be able to reverse something on no-ip because they don't control the reverse zones [14:38] dynamic dns providers simply do A records [14:38] giovani, thanks for a reply [14:39] Sam-I-Am, Hi no-ip,com gives me MX records [14:39] they can do MX too [14:39] but not PTR [14:39] :( sorry you will have to forgive me, im still new to this :) PTR? [14:40] ptr is the reverse record [14:40] a.b.c.d -> name [14:41] ok, so does that mean that I will never be able to get a mail server with no-ip.com? Im trying to set up a play by email server.... [14:41] well, thats not what i mean [14:41] :) well thats good news [14:41] it sounds like something (perhaps postfix) notices that your A record points to your IP, but that IP doesnt point to the same PTR [14:41] so it gripes [14:42] you just have to tell it to ignore that... or you can try putting your IP and no-ip hostname in /etc/hosts [14:43] ok let me give you some more details, I can connect to postfix through netcat localhost but when i try the same thing with my domain name i get the mismatch. [14:45] where are you connecting from? [14:45] and what host does postfix think its using? [14:46] connecting from the local machine on port 25 so im assuming it thinks its SMTP [14:47] no... [14:48] so you're connecting to localhost:25 and it works, but blah.no-ip.com:25 and it doesnt? [14:48] correct [14:48] what error does it return on the latter? [14:49] DNS fwd/rev mismatch: blah.no-ip.com != 80-47-161-104.come_more_garbage.com [14:50] and thats returned by postfix? [14:50] how can i enable IMAP support in php ? [14:50] thats returned by netcat (the program im using to test if its working) [14:50] oakbox: btw, you might want to use "swaks" to test your mail server... very useful utility over telnet/netcat [14:50] what happens if you telnet to no-ip:25 ? [14:51] i will try 1 sec [14:52] Trying 80.47.xx.xx... [14:52] and then just waits [14:53] it's possible your ISP is blocking the SMTP port [14:54] humm, not thought of that, suppose its possible. let me see if i can dig up anything on their site. I will get back to you in a bit if you dont mind??? [14:55] someone will be here :) [14:56] heh [14:56] most isps block 25 incoming [14:56] and often outgoing to !their smtp servers [14:59] ScottK: Do you happen to know if the "Local only" config option in postfix lets you send mail *out*? [15:00] ScottK: I.e. does the "local only" part only refer to its not listening for outside connections? [15:00] soren: I do not. I've never used it. [15:00] soren: a little, mayber [15:00] depends on the release [15:01] lamont: Jaunty? [15:01] humm looks like port 25 is blocked, damn, so no way i can set myself up a play be email server then... [15:01] should set default_transport=error [15:02] lamont: So not delivery to the outside world? [15:02] oakbox: most ISPs block port 25 outbound these days [15:02] soren: right. [15:02] at least until you tweak the config at all [15:02] lamont: Sure, sure. [15:02] lamont: This used to be different? [15:03] soren: fixed in 2.5.1~rc1-1 [15:03] * postinst: also set relay_transport=error on Local Only systems [15:03] So since Hardy? [15:03] postfix | 2.5.1-2ubuntu1 | hardy | source, amd64, i386 [15:03] yep [15:04] Lovely. thanks. === TeLLuS_ is now known as TeLLuS [15:12] how can i enable IMAP support in php ? [15:12] what kind of imap support? [15:13] theres some libraries for accessing imap, or you can install something like horde/imp to serve as a php-based webmail client [15:14] oakbox: you can use a different port, you just need to have your client use that port instead of the standard one [15:15] sgsax, cool :) but will i need to change something on my MX record for that? [15:15] no [15:16] no, DNS is for Ips only, not ports [15:16] fantastic [15:16] and you probably dont need an MX record either since your no-ip thing just points to a single host [15:16] if you had a domain thats another story [15:16] :) [15:17] 1 story is enough for now [15:18] so I think I have found out how I can use my ISP's smarthost to send mail, (or is there a way for people to recieve mail from another port no (i think not)) [15:19] oakbox: that'll work for sending mail from your box... but not receiving... it'll need to go to your isps mail server. [15:19] at that point theres really no reason to run your own :/ [15:19] I pay for hosting for that [15:20] humm, my budget doesn't know what 'pay for' is hehehe [15:21] $5/mo aint bad [15:21] hosting has become quite cheap [15:22] or is it $8, I forget, it's on autopay for theyear [15:31] I have problems with ufw not allowing outbound traffic (I have tried ufw allow from 127.0.0.1 to any) [15:31] sandstrom: ufw does not support egress filtering via the cli [15:32] (it is planned) [15:32] sandstrom: is this for routing or host-based firewall? [15:32] firewall for webserver [15:33] sandstrom: by default, it will allow all outgoing connections with connection tracking [15:33] ufw, iptables or ubuntu? [15:33] sandstrom: did you change /etc/default/ufw? [15:33] sandstrom: uf [15:33] ufw [15:33] no, but my vps provider may have [15:34] sandstrom: verify /etc/default/ufw has DEFAULT_OUTPUT_POLICY="ACCEPT" [15:34] ok, very embarrassed now.... I didn't have port 25 pointing to my server in my router..... I can receive email from the outsite world at last! I'm 1/3 of the way there [15:34] jdstrand: it has [15:35] oakbox: good find [15:35] sandstrom: if you do 'sudo ufw disable' are you able to connect to what you want to? [15:35] yes [15:36] sandstrom: what are you trying to connect to? [15:36] smtp-servers, the apt-get servers [15:36] so port 25 and 80 [15:36] yes [15:37] this is my iptables (setup using ufw): [15:37] ACCEPT tcp -- localhost anywhere tcp dpt:smtp [15:37] ACCEPT tcp -- localhost anywhere tcp dpt:www [15:37] ACCEPT all -- localhost anywhere [15:37] (Chain ufw-user-input (1 references)) [15:37] (well, it's some of it) [15:38] sandstrom: you don't need allow rules for the localhost by default [15:38] sandstrom: did you modify /etc/ufw/before.rules? [15:38] hi , i've setup my own mirror on a http server and signed the Release file with my own public gpg key [15:39] jdstrand: no, but my vps host may have [15:39] but if I install over the net it can't find my public key... [15:39] sandstrom: diff /usr/share/ufw/before.rules /etc/ufw/before.rules [15:39] sandstrom: if it comes back to the prompt, it wasn't changed [15:39] and to download my key with preseed does not work [15:39] its changed [15:40] sandstrom: those changes may have introduced the issue [15:40] anybody setup a local mirror with preseed? [15:41] jdstrand should I reset things to the defaults? [15:41] sandstrom: that would be by far the easiest thing to do [15:42] I guess I copy from usr/share to /etc/ufw and make a backup. then start/stop the firewall, right? [15:43] sandstrom: yes, that should work fine. make sure that before*.rules and after*.rules go to /etc/ufw and user*.rules go to /var/lib/ufw. that will completely reset your rulesets [15:44] will do, thanks alot for your time and help! [15:44] np, and good luck! [15:49] Didn't work unfortunately. apt-get update still doesn't work. [15:52] while we're talking about email today, can somebody point me in the direction of some good recipes for having postfix bounce spam-tagged messages? [15:52] we had something working with sendmail, but since we switched to postfix, that solution doesn't seem to work [15:54] sgsax: You mean as in bounce back to the sender? [15:54] yes [15:55] sgsax: Please don't do that. Virtually all spam has a forged mail from so you're sending it back to the wrong place. [15:56] Accept then bounce is a bad strategy. [15:56] normally, I would agree, but this is for my RT server [15:57] so if I just discard fals positives, it's possible an actual important request would get dropped [15:57] and we have been getting literally hundreds of spam message daily [15:59] Hello. Where can I find the string to add to my sources.list for the karmic repo server? [16:02] good morning [16:03] hi [16:03] how can i enable IMAP support in php ? [16:03] aptitude install php5-imap [16:06] jmedina-> done, anything i should do to enable it ? [16:06] oruwork: just write code that uses the libs [16:06] is there any reason why I would not receive and email from postfix (relay) to an outside email address, my logs say the status = sent [16:06] does vbox support 64 bit emulation? [16:07] I just downlaoded ubuntu amd64 version but when I load it in vbox it gives an error [16:07] rags45: did you install virtualbox for 64bits? [16:08] hmmm..there are separate vbox for 64bit??..oh..I guess I got the 32 bit then [16:08] jmedina: thx ..I'll get the 64 bit one [16:11] jdstrand: I tried to move in the new files. Doesn't work unfortunately. apt-get still fails [16:11] jmedina-> apt-getin install php5-imap, is that imap2 or imap4 protocol ? [16:12] sgsax: My advice would be to deliver them to a spam box and then have some search for a legit request. [16:12] oruwork: I eally dont know [16:17] sandstrom: it should work with a default install of ufw and simply doing 'ufw enable' [16:17] and running iptables -L will show all firewall rules in effect? [16:18] sandstrom: perhaps some other files changed. perhaps 'dpkg --purge --force-depends ufw ; apt-get install ufw' [16:18] sandstrom: yes [16:19] RT already generates an automatic reply to these addresses [16:22] jdstrand: just did. still don't work [16:22] jdstrand http://pastie.org/523002 [16:22] ERROR: problem running init script [16:22] Did throw a few “shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory” during installation too. [16:23] that (or the ERROR: problem…) is the cause perhaps? [16:23] sandstrom: what does ufw --version show you? [16:23] jdstrand ufw 0.16.2.4 [16:24] sandstrom: and this is on a non-Ubuntu kernel? [16:24] sorry, I don't know [16:24] sandstrom: uname -a [16:24] Linux k226741 2.6.18-028stab053.17 #1 SMP Mon Jun 9 20:42:43 MSD 2008 x86_64 GNU/Linux [16:25] so that would be a yes [16:26] sandstrom: I have a feeling you are hitting bug #289906 [16:26] Launchpad bug 289906 in ufw "ufw fails when connection tracking is not available" [Medium,Fix released] https://launchpad.net/bugs/289906 [16:27] yes, nf_conntrack is not present [16:27] sandstrom: in /etc/ufw/before.rules, adjust this: [16:27] -A ufw-before-input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT [16:28] to be: [16:28] -A ufw-before-input -m state --state RELATED,ESTABLISHED -j ACCEPT [16:28] then adjust -A ufw-before-input -m conntrack --ctstate INVALID -j DROP [16:28] to be: [16:28] -A ufw-before-input -m state --state INVALID -j DROP [16:29] and finally: [16:29] -A ufw-before-input -m conntrack --ctstate INVALID -j LOG --log-prefix "[UFW BLOCK INVALID]: " [16:29] to be: [16:29] -A ufw-before-input -m state --state INVALID -j LOG --log-prefix "[UFW BLOCK INVALID]: " [16:31] error running init script still shows, after that edit running stop/start [16:32] but I think that regarding this error running init script we have already checked through something on my system, you told me a bunch of commands that I ran, which helped you to file a bug. This was probably 3-4 months ago. [16:32] So if that is what causes the outbound connections to fail it's the same problem. [16:32] sandstrom: what is the bug #? [16:32] don't remember [16:33] if you have irc history, search yours and my name back in time [16:33] I thought that the outbound connections not working may be something else, which it still may be. [16:34] sandstrom: can you paste the output of '/etc/init.d/ufw stop' and '/etc/init.d/ufw start'? [16:35] jdstrand: shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory [16:35] * Stopping firewall: ufw... [16:35] ...done. [16:35] sandstrom: feel free to 'cd /' [16:37] jdstrand http://pastie.org/523002 [16:38] sandstrom: can you also paste /etc/ufw/before.rules and /etc/ufw/after.rules? [16:39] sandstrom: incidentally, this is all due to running on a non-Ubuntu kernel. later versions of ufw handle this situation better [16:40] jdstrand http://pastie.org/523002 [16:44] sandstrom: adjust /etc/default/ufw to have: [16:44] IPT_SYSCTL= [16:45] IPT_MODULES= [16:45] sandstrom: then paste the output of '/etc/init.d/ufw stop ; /etc/init.d/ufw start' [16:48] jdstrand: http://pastie.org/523002 [16:48] sry, wrong [16:49] hi all, why am I getting Relay access denied when trying to send an email from postfix? [16:49] jdstrand this is it: http://pastie.org/523002 [16:51] sandstrom: I found our irc conversation [16:51] (from the past) [16:51] you dropped out and I never heard back [17:09] sandstrom: just recapping for irc logs-- your kernel doesn't support 'state' either [17:10] sandstrom: so you are reduced to stateless packet filtering. You'll need to adjust before.rules and after.rules accordingly or just write your own iptables script [17:10] I'd talk to your vps because stateless filtering is not nearly as useful (or secure) as stateful [17:14] hey guys. [17:20] So i attempted two Ubuntu-server installs last night on a poweredge 2450 [17:21] I got a relay access denied when trying to email out from postfix, can anyone help? [17:23] oakbox: Possibly. If you can provide the output of postconf -n and a log snipped for /var/log/mail.log showing when you attempted to send in a pastebin, I can probably help. [17:23] lovely thanks i will get on it :) [17:31] ScottK, postconf -n --> http://paste.ubuntu.com/202988/ & log ---> http://paste.ubuntu.com/202990/ [17:31] * ScottK looks [17:32] hi, i'm trying to connect with virt-manager to a remote xen domain with xen+ssh. I always get a libvirt error: 'server closed connection' and even if i try from the command line i get 'failed to connect to the hypervisor'. Any hints? [17:32] i have no problems when connecting to kvm servers. [17:36] damn. ADD. So i attempted this install three times, actually. Once with manually partitioning the drive in Ubuntu's Setup. Seccond time with the guided partitioning, and thirdly I booted to gParted to partition it, and used the pre-existing partition layout to install upon [17:36] all three times, it comes up to a busybox shell [17:37] ScottK, typo at end of line 12 of postfix config should be mydomain.org not myftp.org [17:37] Just wondering if someone can help me understand what this shell is, and why I may be continually coming into it [17:38] MrPockets: does this machine have virtual devices? as in... ones connected to a management device like an ILO or DRAC? [17:39] MrPockets: the shell is what comes up when the kernel can't find your root partition... its an initrd thing. [17:39] oakbox: You either need to add your IP address (range) to mynetworks if it's a IP address you control or connect with smtp auth. [17:39] Did you set up smtp auth? [17:40] Sam, it doesn't. It does, however have two SCSI drives connected with a SCSI controller [17:41] MrPockets: so you see it boot the kernel, then it says can't find root partition? or some other error before dropping you to the shell? [17:41] ScottK, yes i have [17:41] Sam-I-Am, yes. IIRC. [17:42] does it give an error or is that it? [17:42] ScottK, I can log in with user and passwd fine (using swaks -a) [17:42] mmm swaks [17:42] oakbox: OK. If postfix was trying to use smtp auth there would be evidence in the log. [17:42] thats it [17:42] grrrr [17:42] 27mb/s through I/O [17:42] Sam-I-Am, thanks for the tip on that app [17:43] what a bologne [17:43] MrPockets: how big are the drives? and how are you partitioning them? [17:43] oakbox: How about pastebin the relevant smtpd entry from master.cf in a pastebin? [17:43] what would cause a scsi drive to read at 28mbs [17:43] Sam-I-Am, 9.8 gig a piece [17:43] ScottK, 1 sec [17:43] Timing buffered disk reads: 90 MB in 3.27 seconds = 27.56 MB/sec [17:44] 10K RPM SCSI drive capable of doing 320mb/s [17:44] its only doing 27 mb/s [17:44] I partitioned drive 0 with a 8.9 gig / partition and ~1gig swap. Left the seccond drive alone, but its formatted at EXT3 [17:44] MrPockets: so no raid? [17:44] same hard-drive thats non mounted and no filesystem runs at [17:44] Timing buffered disk reads: 186 MB in 3.01 seconds = 61.84 MB/sec [17:44] no raid [17:45] so whats the device it sees on install? sda? sdb? [17:45] sda [17:45] and it also sees sdb? (the other drive) [17:45] i tried pulling the drives out and swapping them around, thinking maybe its setting ubuntu up on one drive, and booting to the other, but it gets a "non system disk" [17:46] but yes, it sees both sda and sdb [17:46] hmm [17:46] and you installed grub to the MBR of sda right? [17:47] Does the install not do that? [17:47] ScottK, is this what you mean? http://paste.ubuntu.com/203002/ [17:47] or rather, does that need to be done seperatly from the install? [17:47] * ScottK looks [17:48] anybody know what could be hindering performance [17:48] of SCSI disks? [17:48] maybe single scsi raid controller? [17:48] damn IBM x345 [17:48] MrPockets: the install asks you before its done [17:49] oakbox: No. Like http://paste.ubuntu.com:80/203003/ (look in master.cf, not main.cf) [17:49] MrPockets: after it installs all the software [17:49] oops sorry 1 sec [17:50] a1fa, hw- or sw-raid? [17:50] hw raid [17:50] raid 1 i think [17:50] Primary, Secondary, and Hot Swap [17:51] Sam-I-Am, to my reocllection, it simply said "the install is complete, its time to reboot to your new OS, remove all media and reboot the machine" [17:51] ScottK, I have this but its all commented :s http://paste.ubuntu.com/203005/ [17:51] a1fa, anything suspicious in the kernel log? maybe one of the drives is semi-defunct. that would explain the stall, since iirc hw raids stall easily when the io-ops are out of sync. [17:52] Hecate : nothing that stands out [17:52] hect: [ 12.376284] sd 2:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA [17:52] only one suspicious thing [17:54] MrPockets: hmm... well, for some reason what grub is seeing is not where your root partition really is [17:54] MrPockets: does it say what partition its trying to use for root? [17:54] oakbox: The general recommendation is to submit mail via the submission port (587). If you uncomment the lines associated with submission, postfix stop, postfix start (reload won't pick up new services) and then connect to port 587, it ought to work. [17:55] Hecate : resycns is in progress.. but why are other drives getting 60mb/s [17:55] a1fa: is the cable bent? that tends to slow down the 1's [17:55] resync is a serious performance bitch [17:56] ScottK, thanks I will give it a go. [17:56] oakbox: OK. Let me know if there are still problems and we'll keep working on it. [17:56] ScottK, thanks very much for your help :) [17:56] No problem. [17:57] a1fa, if you're still getting the bad performance when the resync's done, disabling the raid and checking on the drives (e.g. read speed) individually might be worth a shot. [17:58] Hecate : its IBM's raid.. you cant disable it [17:58] Hecate : i guess i can take the drives out [17:58] well, i got veeeeery little experience with hw-raids, so i can only recomment, not to offend your raid-controller ;) [17:59] [ 9.458637] scsi target2:0:3: FAST-160 WIDE SCSI 320.0 MB/s DT IU QAS HMCS (6.25 ns, offset 127) [17:59] 320mb/s hard drives down to 60mb/s ;( [17:59] if all of the drives are on a single bus it'll divide up the speed quite a bit when building the raid [17:59] i am about to go to bios and start disabling crap [17:59] a1fa, ehm ... the 320 MB/s denotes the bus-speed, not the drive speed [18:00] not to mention raid building is inherently slow anyway [18:00] a1fa, but wait until the resync's over. as i said resyncs tend to be a huge performance killer. [18:01] so can KVM run paravirtualized or is it strictly HVM ? [18:02] Sam-I-Am, I'm not sure. And unfortionatly I don't have the machien in front of me [18:02] MrPockets: that makes troubleshooting a bit hard [18:02] MrPockets: i have a meeting to hit anyway... [18:02] oh right, but at least now i'm awair of what is happening and know what to look at when i go there tonight [18:02] ok [18:02] sure [18:02] thanks hectate [18:03] youre welcome [18:03] how long does it take to syncup 32GB? [18:03] and is there anyway to check raid status though OS? [18:03] can't tell. actually your crontroller should give you some hints on that. [18:04] but i really can't tell due to my lack of experience with hw-raids. [18:04] :P [18:06] ioc0 vol_id 0 type IM, 2 phy, 33 GB, state DEGRADED, flags ENABLED RESYNC_IN_PROGRESS [18:07] i wonder if you can force raid sync [18:08] ScottK, humm I dont think that has helped :) [18:09] scsi_id:0 20% [18:09] scsi_id:1 20% [18:09] ok [18:09] at least i know what i sit on [18:09] :) [18:09] thanks Hecate [18:09] ScottK, I now get a message "*** No acceptable authentication types available [18:10] oakbox: OK. You need to look at your smtp auth configuration. [18:11] ok [18:11] oakbox: Are you using dovecot or cyrus? [18:12] ScottK, saslauthd ? [18:13] ScottK, from this page https://help.ubuntu.com/community/Postfix [18:13] That's cyrus [18:14] If I set an RSS limit for a process/user in /etc/security/limits.conf, will that make that user/process completely unable to use more than e.g. 20MB of RAM, or would swap beyond 20MB still be possible? [18:14] oakbox: Please pastebin /etc/postfix/sasl/smtpd.conf [18:15] http://paste.ubuntu.com/203019/ [18:16] oakbox: How about edit /etc/default/saslauthd [18:17] Ignore the word edit there. [18:17] ScottK, 1 sec [18:17] Paste error [18:18] ScottK, http://paste.ubuntu.com/203022/ [18:18] * jmedina has experience with saslauthd [18:18] jmedina: If you could take over then, that would be great. I use auxprop. [18:19] ScottK and what is the problem to solve? [18:19] ScottK, thank you for your help [18:19] jmedina: His smtp auth isn't working. "No suitable mechanisms found" or something similar [18:19] jmarsden, I am having trouble sending emails out from postfix [18:20] oakbox: My guess would be uncommenting line 48 and restart saslauthd [18:20] oakbox: where do you get that message? [18:20] the one fro no suitable mechanisms? [18:20] do you have libsasl2-modules installed? [18:21] from swaks and yes i do [18:23] from swaks? [18:23] oakbox: are you using system users? [18:23] from /etc/passwd? [18:23] yes [18:24] swaks - SMTP transaction tester [18:24] yesterday I configure a system like yours [18:24] I use MECHANISMS="pam" [18:24] not shadow [18:25] did you create /var/spool/postfix/var/run/saslauthd? [18:25] what is the difference? [18:25] well is the default ubuntu authentication/authorization method [18:25] I only use shadow for systems that dont support pam like slacwkare or openbsd :) [18:26] oh should i use that instead? [18:26] well I know that works [18:26] re did you create... there are files there so im assuming so [18:27] I use [18:27] dpkg-statoverride --add root sasl 710 /var/spool/postfix/var/run/saslauthd [18:28] ok im now using pam [18:28] and then restart saslauthd and the init script will create the directory automatically [18:28] i used dpkg-statoverride --force --update --add root sasl 755 /var/spool/postfix/var/run/saslauthd [18:28] it is ok [18:29] could you show output from ps aux | grep saslauthd? [18:29] just to be sure [18:29] :) http://paste.ubuntu.com/203029/ [18:31] good [18:31] now what about? [18:31] cat /etc/postfix/sasl/smtpd.conf [18:31] I use [18:31] pwcheck_method: saslauthd [18:31] mech_list: PLAIN LOGIN [18:32] yep exactly what i have here [18:33] ok [18:33] now postfix [18:33] main.cf [18:34] you should use at least somthing like this [18:34] http://paste.ubuntu.com/203031/ [18:36] http://paste.ubuntu.com/203032/ [18:38] ok [18:38] thats all [18:38] :) [18:38] restart postfix and try [18:38] you could test with [18:38] telnet localhost 25 [18:38] and see if AUTH is announced [18:39] yep auth is announced [18:40] now [18:40] try to send a mail and keep one eye in your logs [18:40] oakbox: just a tip: when you post your postfix configs use: postconf -n [18:41] what will show only new configs [18:41] we all can get the defaults using postconf -d [18:41] New bug: #389722 in mysql-dfsg-5.0 (main) "skip-name-resolve is not included in default my.cnf" [Wishlist,Triaged] https://launchpad.net/bugs/389722 [18:41] jmarsden, cool thanks for explaining :) [18:42] oakbox: I do this everyday, I know the procedure from memory :) [18:43] oakbox: jmarsden thanks for helping oakbox :) [18:43] yay for postfix [18:43] ok I have tried sending an email and my logs say status=sent..... which is better than i had, but it didnt ask for a user and password and i have not got my test email :'( [18:43] shh, dont tell ivoks I help you configuring saslauthd, he is anti cyrus and pro dovecot [18:43] hehe [18:43] i'm not anti-anything :) [18:44] dovecot is just way easier :) [18:44] oakbox: show the logs!!! [18:44] you see, dovecot as sasl would already work :) [18:45] http://paste.ubuntu.com/203038/ [18:45] more logs [18:45] mmm [18:45] :s what more do you want [18:45] yeap [18:46] setting up connection [18:46] at leas 10 lines before [18:46] yes starting from setting up connection :) [18:46] oakbox: all lines containing '2C8ED48341' [18:46] New bug: #391410 in mysql-dfsg-5.0 (main) "package mysql-server-5.0 5.1.30really5.0.75-0ubuntu10 failed to install/upgrade: subprocess new pre-removal script returned error exit status 1" [Undecided,Incomplete] https://launchpad.net/bugs/391410 [18:46] the lines from postfix/smtpd [18:47] they are the only lines that contain '2C8ED48341' [18:47] oakbox: one question? where are you sending mail from? [18:47] a cliente? from command line? [18:47] *client [18:47] command line, same machine [18:47] to the outside world [18:48] mmm [18:48] ok show the logs [18:50] ok heres the last so much of my log file http://paste.ubuntu.com/203040/ [18:51] so, you see [18:51] those weren't all the lines with 2C8ED48341 [18:51] but i did a grep :) [18:52] ah sorry 1 line [18:52] missing :) [18:53] well, you didn't authenticate [18:53] which ubuntu is that? [18:53] latest [18:53] you do know that installing dovecot-postfix would set up everything for you? :) [18:53] imap, pop, smtp, smtp-auth [18:56] I dont actually need imap or pop, its going to be a play by mail server.... (hopefully) [18:57] how do i get it to do authentication? [18:57] sorry brb need to check on dinner.... i smell burnt sausages..... [19:02] bk [19:09] hey guys. im using likewise-identity 4 to auth my ubuntu machines to win2k AD domain. everything workes well, except I am trying to set a local root pawword on a worksation, and it is not lettin gme. [19:09] arrgh. root is an AD user. [19:09] crap [19:10] or, more specific, I have an AD user named root [19:14] slestak: sorry, i don't know about AD, perhaps ask mathiaz ? [19:15] kirkland: ok, tyvm [19:16] I use krb5 for AD auth [19:17] sgsax: likewise open uses krb5 as well. it just has a little gtk front end and some other reporting capability. i found out my problem, I have an AD user named "root". [19:18] I saw that [19:18] we do too [19:18] only set up the local root password on initial setup [19:18] but if your AD is unreachable, if you setup pam right, auth should fall back on to local [19:23] sgsax: well, ad is reachable, but I would like to have the ability to use the local root user when needed. [19:24] thanks all see you later [19:24] i setup my vmware admin to be root, and I havent set a password for it yet. [19:25] this for the free vmware server? [19:26] yes [19:26] gotcha [19:26] last time I set that up, I created a local user account just for that purpose [19:27] ok, i'll follow suit [19:27] seemed easier that way, esp if you have multiple admins [19:27] id is showing ad user root has uid 0, so its mapping to local user root [19:27] could be, and then the password is getting clobbered by AD [19:28] unless your AD root user is also gid 0 [19:28] unix properties are not revealed by default in Windows [19:28] there are add-ins to do it, or you can roll your own code [19:28] i didnt set the user up, so i dont know what server or service needs it. [19:29] i'll prob end up broking BackupExec or something [19:29] don't want that :) [19:29] actually, i wouldnt mind, its a big pita [19:30] go office space on it. wtf, pc load letter, bang [19:31] I'm planning on moving my backup to amanda [19:31] don't have any windows hosts to backup, thankfully [19:32] currently using rdiff-backup, makes me want to cry sometimes [19:32] so to reset the admin user, I have to run the whole vmware-config script again [19:32] don't think so [19:33] the remote console only needs a valid user to login [19:33] yeah, i used rdiff-bnackup for some personal stuff. great idea, but ddnt work to well for me [19:33] and the dirs that the vm disks live in need to be writable by your vmadmin user [19:33] the web interface on 8222 is not letting any local or ad users auth [19:33] my biggest problem with rdiff-backup is a nearly complete lack of recovery from errors [19:34] I only used the remote console, never the web interface [19:34] but I would think they would use the same auth mechanism [19:34] i know its not really sufficeint, but i am moving to kind of a SaaS idea at work, and one majot app per vm, and just getting /var, /etc, sql dump and any app config out nightly. I can get the os reinstalled faster than I can restore. [19:34] hello [19:35] How do I extract the contents of a zip file? [19:35] rsr: besides unzip? [19:35] ok [19:35] sorry for being such a newbie [19:35] slestak: same here, I don't have bare-metal backups, and all configs are pushed out via cfengine [19:36] rsr: no problem, gotta start somewhere :) [19:36] yes [19:36] but unzip isnt a command [19:36] unzip or gunzip [19:36] you can do sudo aptitude install unzip to get unzip [19:36] ok [19:37] is it a literal zip file, or a tar.gz? [19:37] gzip/gunzip should be able to handle standard zip files [19:53] sgsax: im having a heck of a time with the admin user. i dont know that i want my vm admin to be an ad user, but it makes sense. i'd basically like anyone who can sudo to be able to admin the vm's [19:56] New bug: #318679 in net-snmp (main) "snmpd error" [Undecided,Won't fix] https://launchpad.net/bugs/318679 [19:56] hmm. 2.6.28 kernel is gettign a build error for vsock.o [19:59] found some relevant google hits [20:04] hello anyone know any gui alternatives to system-config-lvm that are currently maintained ..it does work but it lacks features [20:06] slestak: seems to me I had trouble using AD accounts/groups and that it had to be a local account [20:07] and I also had to create a special pam.d profile for vmware-authd [20:26] sgsax: tyvm [20:28] slestak: np, my new vmware server is ESXi and I plan on moving my previous free server to ESXi later this summer [20:28] so it's a different set of problems, but at least I don't have to deal with this one :) [20:50] Timing buffered disk reads: 192 MB in 3.03 seconds = 63.33 MB/sec [20:50] damn bullshit [21:05] sgsax: is using lvm inside of vmware a good idea? is thre a best pracice that will allow flexibilty later? [21:09] is there a decent web gui for bind? [21:11] tlol [21:11] bind is so simple [21:12] slestak: don't think I've heard specific reports, but I think I'd stay away from it, myself [21:12] It is, but to edit 4 files every time I need a new zone is madness [21:13] bind takes some getting used to [21:13] heath|work: how often do you find yourself having to add zones? [21:13] or are you just editing existing zones? [21:14] Withing the next month or so, hopefully a couple every day [21:14] starting up a hosting service? [21:14] the thing is, I may not be the only one adding them [21:14] yeah [21:15] well sorta [21:16] I'm a web dev and built a system for some around town businesses and I would like to control there DNS from inhouse [21:17] so to add a new zone, you need to edit /etc/bind/bind.conf [21:17] and then add forward and reverse zone files [21:18] I have run through the ubuntu server guide and got the concept, I was just wondering if any of youz guyz were using a web tool or just hacking it out [21:18] webmin may have plugins for managing dns, but if I were you, I get a copy of the O'Reilly DNS & Bind book and get cozy with it [21:19] I also read through the AppArmor stuff [21:19] apparmor is firewall and acl type stuff [21:19] Yeah, but it is time I understand it more. [21:19] once you do it a couple-dozen times, it's not so hard :) [21:20] All the tutorials I have run across for bind recommend disabling AppArmor and I would rather become familiar with what it is doing and embrace it [21:20] if you read the O'Reilly book from cover to cover (and can comprehend it), you'll know everything there is to know about how bind works [21:21] I found that apparmor gets in my way, and I usually disable it anyway [21:21] sgsax, do you run bind chroot? [21:21] nope [21:21] but I do make sure all my packages are up-to-date and patched [21:21] sgsax: We'd really rather you'd file bugs about problems in apparmor profiles than just turn it off. [21:21] why would you disable apparmor for bind? [21:22] just fix the profile and file a bug if it is a problem in the default configuration [21:22] iirc, it got in the way of my AD auth [21:22] heath|work: The Ubuntu packages shouldn't require it to be turned off. [21:22] the AD boxes were unable to query it for some reason [21:23] ScottK, That's what I figured, there are several complaints about it from Googling. I have read that most of them are people using the wrong dir for cache [21:23] sgsax, ^^ [21:23] If there are problems, we'd really rather fix the profiles. [21:23] sgsax: file a bug following https://wiki.ubuntu.com/DebuggingApparmor and we can get it fixed if it is a problem in the default profile [21:23] I need a way to test that doesn't break my production systems [21:24] heath|work: if there is a non-default but common directory for cache directories, file a bug and we can get it fixed [21:24] sgsax: complain mode [21:25] sudo aa-complain /usr/sbin/named should do it (assuming apparmor is still running on your system) [21:25] Kudos to the ubuntu server guide. It is looking very strong. [21:25] sommer: ^^^ [21:27] jdstrand: If I run aa-complain, do I need to start the aa service? [21:28] hey [21:28] anyone ever set up a vpn [21:29] heath|work: thanks\ [21:29] ScottK: hey I'm about to expire from the clamav team [21:29] sgsax: apparmor needs to be running, yes. if apparmor profiles are keeping you from doing your work, disable the profile but not all of apparmor [21:29] sgsax: see https://help.ubuntu.com/8.04/serverguide/C/apparmor.html for details [21:29] sommer, you are responsible for the guide? [21:29] sgsax: the short answer is 'yes' it needs to be started [21:30] heath|work: I've been working on it for the past few releases [21:30] wow... [21:30] heath|work: along with help/input from others [21:30] sommer: Fixed. [21:30] ScottK: cool, thanks :) [21:31] that's impressive [21:31] i'm having trouble getting my mediawiki install configured. i'm trying to replace the alias with a virtualhost, but the virtual host doesn't seem to work. [21:33] work|dana: do you have a seperate vhost file in /etc/apache2/sites-available? and if so did you enable the vhost with a symlink to /etc/apache2/sites-enabled, or with a2ensite? [21:33] sommer, no i just edited my mediawiki.conf [21:33] http://pastebin.com/d7605a60c [21:33] you can check loaded vhosts with apache2ctl -D DUMP_VHOSTS [21:35] http://pastebin.com/d17ad4f9d [21:35] vhost seems to be loaded [21:35] work|dana, do you get an error when apache is reloaded? [21:37] heath|work: no [21:44] You guys are kinding when you say JeOS is stripped down [21:46] heath|work: i use jeOS almost exclusively, it can be annoying depending on what you're doing [21:46] Now that I realize not even nano is installed I will be ok [21:47] Just started on KVM today, so far so good [21:47] Where is bind's error logs? [21:51] grep named /var/log/syslog [21:51] or /var/log/messages, depening on your setup [21:54] thanks sgsax . Looks like typo city [21:56] heath|work: once you get your basic zone layout figured out, I'd strongly recommend creating templates [21:56] so when you add a new zone, just copy your templates over with the basic info, and edit as necessary [21:56] I will, I'm thinking about scripting it out with some reads already === asac__ is now known as asac === mcasadevall is now known as NCommander === erichammond1 is now known as erichammond === erichammond1 is now known as erichammond === asac_ is now known as asac === tain is now known as tainspam === tainspam is now known as io