/srv/irclogs.ubuntu.com/2009/08/22/#ubuntu-server.txt

qman__yes, pam is a wonderful thing00:23
qman__I wish samba used pam instead of just adapting to it00:23
Psi-Jack__Okay.. So my router, presently, has only a small annoyance.00:32
Psi-Jack__When eth1, my net interface, comes up, it replaces /etc/resolv.conf with that retrieved via the DHCP.00:33
Psi-Jack__I don't want that, I want it to stay as I put it, or to adjust it with resolvconf to settings specifically supplied by wherever it gets that.00:33
Psi-Jack__Cause, I have my own domains. I have my own DNS, I don't want my router out of sync with that.00:34
KillMeNowNot sure if you can change that for a single host00:36
KillMeNowi think there are DHCP options you can disable globally to not push DNS resolvers00:36
KillMeNowbut not sure about a single host...00:36
KillMeNowwhy are you having it grab an IP via DHCP?  why not do it statically?00:37
=== MianoSM4 is now known as MianoSM
=== clusty_ is now known as clusty
=== jerrcs2 is now known as jerrcs
uvirtbotNew bug: #417211 in tomcat6 (main) "package tomcat6 6.0.18-0ubuntu6.1 failed to install/upgrade: subprocess post-installation script returned error exit status 1 (dup-of: 417212)" [Undecided,New] https://launchpad.net/bugs/41721104:11
mushroomblueholy crap the OpenLDAP instructions are completely useless04:12
mushroombluefrom what I'm reading, slapd in 9.04 isn't built against openssl04:12
mushroomblueis this correct?04:16
mushroombluecos it sounds really really stupid.04:16
mushroombluethough it explains why the SSL/TLS section of the OpenLDAP instructions don't work.04:16
jerrcsif you want to see stupid04:19
jerrcshttps://bugs.launchpad.net/ubuntu/+source/proftpd-dfsg/+bug/33593304:19
uvirtbotLaunchpad bug 335933 in proftpd-dfsg "proftpd: Several SQL injection vulnerabilities" [Undecided,Confirmed]04:19
jmarsdenmushroomblue: You might want to read /usr/share/doc/slapd/README.Debian.gz04:19
jerrcswhy isn't that fixed yet? on ubuntu server edition.. your proftpd server is vulnerable...04:19
jmarsdenjerrcs: Go ahead and post the debdiff needed to fix it, if you want it fixed fast.04:20
Sam-I-Ammushroomblue: openldap is built against gnutls04:21
jerrcsjmarsden: I'm no good with that.. I'm just an ubuntu-server who is very pissed off that it's been half a year and a major ftp server package hasn't been fixed.. a security issue like this.. my home directory has been open to anyone who has used this.. luckily there's nothing too much on there, and i've only been running it for about a month.04:25
jerrcsan ubuntu-server user.04:26
subhttp://packages.ubuntu.com/search?keywords=proftpd&searchon=names&suite=jaunty&section=all04:31
subthat vulnerability is fixed in that version, 1.3.1-17ubuntu104:32
subas it states here: https://bugs.launchpad.net/ubuntu/+source/proftpd-dfsg/+bug/32916704:32
uvirtbotLaunchpad bug 329167 in proftpd-dfsg "Please merge proftpd-dfsg 1.3.1-17 (universe) from Debian unstable (main)" [Wishlist,Fix released]04:32
jerrcs"The ProFTPD Project team is happy to release 1.3.2 to the community. This is a bugfix release, including a SQL injection vulnerability fix. The RELEASE_NOTES and NEWS files contain the full details."04:32
jerrcsno it isn't04:32
sub#7    Launchpad Janitor  wrote on 2009-02-13:04:33
subThis bug was fixed in the package proftpd-dfsg - 1.3.1-17ubuntu104:33
jerrcsThere was another one then.04:33
jerrcssub: I just exploited my own server. I have all my packages up to date. How can you tell me it's fixed? Not to mention I did a clean install of ubuntu-9.04 just about a month ago04:33
subthen post the debdiff. its community-maintained software which means it doesn't get fixed until someone who uses the software (like you) fixes it04:34
jerrcshttp://pastebin.com/m1c726b6f04:36
jerrcssub: how can ubuntu penetrate the server market if they can't keep this up to date? I mean.. I understand. It's in a different repository.. but still.04:37
jerrcsJust bringing up a discussion.04:37
ScottKBecause much of Ubuntu's success has been not trying to do everything, but being the best at what they focus on.04:50
jerrcsI suppose.04:56
giovaniScottK: really? what does ubuntu focus on?05:09
ScottKGenerally we try to pick one package to support for each function.05:10
jerrcsan idiot-proof OS05:10
ScottKFor example we generally focus on Postfix as a mail server even though there are lots of others.05:10
ScottKjerrcs: Not possible.05:10
giovaniwell sure ... other distros tend to do that too05:10
ScottKJust more so here.05:11
ScottKSo if you're using packages that aren't supported (in Universe), don't expect them to be supported.05:11
ScottKSome of them are well supported by the community, but it's uneven.05:11
giovaniScottK: what's the main, supported-by-ubuntu ftp server?05:12
quizmehttp://cardinaleducation.thirdreplicator.com/  <--- trying to get mod_proxy to work.  Can somebody help?05:12
ScottKI don't actually know.05:12
jerrcsproftpd is pretty popular.05:13
ScottKI find I can use sftp for all my needs so it's been years since I worried about it.05:13
jerrcsyet there's a huge vuln in it.05:13
giovaniI can't seem to find a major ftpd that isn't in universe05:13
jerrcsYes.. I prefer sftp.. but I have clients which use regular ftp.05:13
giovaniScottK: but surely FTP is acknowledged as a major protocol still in use, for various reasons05:13
ScottKgiovani: Certainly, just saying I don't know.05:14
giovaniok05:14
giovanivsftpd05:14
giovaniis in the main repo05:14
giovaniso I guess that's the one ubuntu has chosen to support primarily05:14
ScottKOdds of it having issues left long unfixed are relativley low then.05:14
ScottKYou could also look in the Ubuntu server guide and see what it suggests.05:15
quizmeif i log into the server, and run "curl http://127.0.0.1:11000" it works, but when i access it via the URL. I get "Not found /"05:15
jerrcsI'll poke around with vsftp.05:15
jerrcsvsftpd*05:15
giovanivsftpd is security-focused anyhow05:15
giovaniimplied by the name ...05:15
quizmeanybody know how to mod_proxy here ?05:28
mushroomblueso wait. it's built against GnuTLS for a while now, but the documentation doesn't reflect this?05:44
mushroomblue8.10 and 9.04 server guide both give incorrect configuration steps for openldap, then.05:44
mushroomblueyou'd think someone would notice, and update the docs05:45
Sam-I-Amwhat its built against doesnt really matter for the config iirc05:45
Sam-I-Amcerts are certs05:45
mushroombluesteps to get a working system are different.05:45
mushroomblueand if you're planning on following the server guide to configure your system, you're sorta out of luck.05:46
mushroombluethat's poor documentation.05:46
Sam-I-Amwell, one of the fun parts of open source... you can volunteer to make it right :)05:46
jmarsdenmushroomblue: Thanks for volunteering to update the docs ... where can we see your proposed changes?05:46
Sam-I-Amtalk with sommer ... he's the docs guy05:46
mushroomblueoh, I'll be happy to submit changes05:46
mushroombluewhen I'm not drunk. :)05:46
mushroomblues/changes/docs/05:47
Sam-I-Ami've been planning to submit updates to it05:47
Sam-I-Amtodays fun was patching openldap though05:47
mushroombluejmarsden: you'll have to crack my skull open and take a peek.05:47
mushroombluesicko.05:47
jmarsdenmushroomblue: My machine seems to lack the skullcrack-and-peek package, and it;s not in the repositories.05:48
mushroombluejmarsden: thanks for the readme, tho. :)05:48
Sam-I-Ami think that package is called 'sendmail'05:48
mushroomblueI'd like to think my brain is a lot more like git05:48
RudyValenciahi06:33
RudyValenciaHow much space do I need to allocate to an Ubuntu Server running in a VM?06:33
RudyValencia(hard disk)06:33
RudyValenciawould 10GB be enough?06:33
jmarsdenRudyValencia: It depends what you want to do with it, but for testing and experimenting, yes, probably.06:35
RudyValenciajmarsden: Web serving.06:35
jmarsdenWell, if you want to serve 100GB of videos, then 10GB won't be enough... :)06:36
RudyValenciaI can't get Apache to work right on the Windows host so I set the VM up to run a LAMP stack06:36
RudyValenciaAs for storage, I use SMBFS shares06:36
jmarsdenThen you should be fine with 10GB for the server itself.06:36
RudyValenciaI notice no appreciable difference between storing the data in the VM and storing the data on SMBFS shares06:37
jmarsdenI have Ubuntu VMs with as little as 4GB for testing sometimes.06:37
RudyValencia(because my server is a low-volume server.)06:37
RudyValenciaIs it better to 'pre-allocate' the disk file?06:38
RudyValenciathat is, have it make one 10GB file vs. a file that grows with the contents of the VM06:38
jmarsdenNot usually; there is a slight disk performance gain by preallocating it.06:38
RudyValenciaAh06:40
RudyValenciaI set it up with 512MB of RAM allocated to it06:40
RudyValenciaand bridged networking06:40
RudyValenciaNo sound or other peripherals, except CD image access06:40
matttRudyValencia: you using xen?06:43
RudyValenciamattt: I don't have a computer capable of hardware virtualisation06:43
matttRudyValencia: same, i'm old school like that also :)06:44
RudyValenciaMy server is a repurposed 2.2GHz P406:44
RudyValenciaw/ 1GB RAM, 200GB and 250GB hard disks, DVD(+/-)RW drive, a cheap NIC, and a LaserJet 5L06:45
mattti wish the newer versions of ubuntu still supported exn06:48
mattt*xen06:48
jmarsdenmattt: I think newer versions of KVM can run on systems without hardware virtualization.  I know virtualbox-ose can.06:50
RudyValenciaI tried to setup VMware Tools on my Ubuntu Server 8.04 install that had been untouched for a while06:50
RudyValenciaand it failed :(06:50
matttjmarsden: oh, nice!06:50
jmarsdenmattt: I was running multiple virtualbox-ose VMs here on an Intel E5200 (no hardware virt) until a few weeks ago (upgraded to a Q9550 as a birthday present to myself!)06:51
RudyValenciaI'm getting some pretty good life out of this old Pentium 406:52
RudyValencia(I have a 2.8GHz as my main desktop)06:52
jmarsdenRudyValencia: Yes, I do that too... but I've not tried VM stuff on older machines, at home or at work.06:53
RudyValenciaah06:53
RudyValenciaI wish I could upgrade either of my systems06:53
RudyValencia(or both)06:53
matttjmarsden: so virtualbox-ose uses KVM?  i didn't know that.06:53
jmarsdenNo, they are independent.06:54
RudyValenciaThis 2.8GHz desktop is nice but doesn't run WinXP well06:54
RudyValenciaoops06:54
RudyValenciaI meant, Win706:54
RudyValenciaIt runs WinXP now06:54
RudyValencia(I still have to use Windows, for Creative Suite 3 does not run well on Linux w/ Wine)06:54
RudyValenciaI would've switched to Linux completely already if it were capable06:55
jmarsdenRudyValencia: Run Ubuntu on the hardware, and Windows in a VM for the occasions when you need it :)06:55
RudyValenciaI need Windows to do development for IE06:56
RudyValencia(I no longer support IE6, only 7+)06:56
RudyValenciaThe Web browser has become an application platform with the advent of AJAX and other new technologies06:57
jmarsdenSure, but you can do that (run IE and whatever) in a Windows VM.  You don't need to run it on the physical hardware.06:58
RudyValenciaI also do 3D with SketchUp06:58
RudyValencia(which a VM can't handle)06:58
RudyValenciaand play the occasional 3D game06:58
jmarsdenVirtualBox is supposedly able to do 3D in the VM for Windows guests now, although I have never tried it.07:00
spowersis it possible to run top on the console of a server with upstart or getty or something?07:00
jmarsdenspowers: Sure.  I think that is part of what the top "secure mode" stuff is all about... ensuring you can leave it running in a way that random passers-by can't abuse your server07:03
spowersthe problems i'm having are more to do with terminal control07:04
spowersand how to run it at boot07:04
spowerson a real server, i'd stick it on tty12 and chvt to it in rc.local, but i'm running in xen so there's only one tty07:05
spowerswhat would be really awesome is to make a screen profile for boot time that had a secure top and could only spawn /bin/login instead of bash directly07:05
spowersscreen itself would have to be more secure probably, so that might not be the right approach07:06
spowersand it's not like this is a real PROBLEM07:06
spowersper se07:06
jmarsdenspowers: aybe set up a user called top whose shell is top ... and log in on the console as top ?07:07
spowersi'll give that a shot, it works well enough for an x server on my mythtv box, i'd forgotten about that07:07
matttspowers: what are you trying to accomplish with this anyway (not fully understanding here)07:07
spowersboy, if i had a nickel for every time someone asked me that...07:08
mattt:)07:08
spowersi'm just hacking around07:08
mattttho it is an interesting idea, i used to work at a hosting company and if that info was visible (even if hte machine was hung and the info stale) it'd be really helpful to support07:09
spowersi've got this mental image of a console that cycles through top/iptraf/some other monitor on the console07:09
mattt(and by visible i mean visible on the console)07:09
spowerslike arcade games cycle through demos and logo screens07:09
RudyValenciaSorry, network cable broke07:09
jmarsdenmattt: leaving top running on a spare terminal was an oldtimers trick a decade or two ago, so when things went bad on your server you could see why... even when it was so bad you couldn't log in and run top because the server was so bogegd down...07:10
spowerstop has existed for a decade or two? wow07:10
spowersi'm always in awe of unix tradition07:10
jmarsdenSure.  I'm pretty sure I was using it in 1994 or so...07:10
matttjmarsden: yeah, that's exactly what i'm thinking ... dunno why we never thought to do that :/07:10
Boohbaheven better, top in a screen session so you can disconnect07:10
matttBoohbah: yeah, but if the system is unresponsive so is screen :)07:11
mattt(or the load's too high or whatever the case)07:11
spowersmain thing would be to have something on the main console more useful than the last handful of boot messages and a login prompt07:11
Boohbahwell then, remote serial console07:11
spowerseven old netware had that silly snake that represented the load average07:11
matttspowers: good idea, i like your thinking07:11
spowerswhen i boot up our linux vms, the console is always a mess07:12
spowerstop looks nice and tiday07:12
spowerstidy07:12
spowersjmarsden: the 'top' user thing works a charm07:14
jmarsdenGood :)07:15
spowersi remember hacking around with getty several years ago trying to start dosemu to run a WWIV bbs system07:16
spowersthat did not work so well07:16
RudyValenciaI put the wrong hostname for my server in when I reinstalled08:08
RudyValenciaHow do I change the hostname?08:09
_rubendoing a find/replace in /etc with the old -> new name should cover most stuff .. depends on how much stuff is already installed as well though08:12
RudyValenciaprobably easier to reinstall at this early stage08:13
_rubendepends .. if its a clean install with not much extra tasks installed .. covering /etc/ would do just fine .. a simple sed/perl oneliner .. then again, reinstalls can be fairly quick as well depending on the method used08:14
subnah08:14
RudyValenciaNothing installed yet08:14
subjust /etc/hosts and /etc/hostname should cover it08:14
RudyValenciaah08:14
_rubensub: unless for example postfix is installed as well as a task08:15
jmarsdensub: Maybe /etc/mailname if an MTA is installed08:15
_rubenthere's quite a few packages that use the hostname in postinstall scripts08:15
subthen you can either reboot or use the "hostname" command to set the new hostname08:15
RudyValenciaI'll redo it08:15
subPerhaps08:16
subI have a new system running as well and I just did grep -Hr `hostname` /etc08:16
RudyValenciavery very easy08:16
_rubenredoing install surely is the cleanest way .. but also a tad overkill ;)08:16
RudyValenciatime is unimportant here08:17
subi've changed hostnames more often than i'd like to admit ;p08:17
_rubeni only looked into it once when looking into the options for 'templating' my virtual machines .. in the end i just setup a pxe environment with preseeded installs :p08:18
RudyValenciahm, I have Remote Installation Services on the Windows side of my server08:20
RudyValenciaI wonder if it can install other OSes than Windows08:20
RudyValencialike Ubuntu or whatever08:20
RudyValenciaWow08:21
RudyValenciaI entered the static IP address in the installer and my network information and it picked up the hostname08:22
RudyValencia(from my DNS)08:22
quizmehttp://cardinaleducation.thirdreplicator.com/  <--- I'm doing a proxy pass thing with webrick but i'm getting this....08:22
quizmeanybody know why ?08:22
quizmemy mod_proxy is set up correctly cuz i'm using the same configuration on another site.08:22
RudyValenciawhich is the best setting: relatime, noatime, or no option for such?08:23
_rubeni use noatime for dedicated /var/log/ partitions on busy servers08:24
RudyValenciaah08:26
RudyValenciaWhat exactly is a "Label"08:27
RudyValencia?08:27
_rubenjust that .. a label :)08:27
RudyValenciaIs that like the "volume label" on a FAT or NTFS volume?08:27
_rubenkinda, yeah08:27
RudyValenciaah08:27
RudyValenciaHm, do you change /etc/issue or /etc/motd on your server(s)?08:28
RudyValenciaI like to change /etc/issue to display a warning08:28
RudyValencia"WARNING: THIS SYSTEM IS RESTRICTED TO (COMPANY NAME) AUTHORIZED USERS, FOR LEGITIMATE BUSINESS PURPOSES ONLY..."08:30
jmarsdenRudyValencia: If the logins are from the network, edit /etc/issue.net  .  For a standard warning text, see http://pastebin.com/f7098d62308:30
RudyValenciajmarsden: I already have one of my own08:31
* RudyValencia pastebins it08:31
* jmarsden hopes you are a good lawyer, if you write it yourself and want it to be legally correct :)08:31
_rubeni never bother to edit those .. or read them if i'd log into a remote system (usualy, unless it does a good job on drawing attention)08:32
subcowsay tends to catch my attention08:32
RudyValenciajmarsden: I borrowed it from another computer at a place I used to work at08:34
RudyValenciahttp://pastebin.com/m2d02cbe708:34
RudyValenciaI substituted [COMPANY] where my business' name goes08:35
jmarsdenOK.  Your notice gives away info to the (hypothetical) hacker... you tell him who owns the system.  Why give away that info?08:36
RudyValenciaI should remove the company name and reflow it to make sense08:36
subis that not already given away by ARIN registrations and reverse DNS?08:37
jmarsdensub: is it?  Try it sometime?  Usually you get the ISP, not the company or end user.08:38
RudyValenciajmarsden: http://pastebin.com/m16f51a1d (amended)08:38
subdepends, some ISPs update the registration for their netblocks08:38
subI work for an ISP, so I guess that's a moot point in my situation :)08:38
jmarsden:)08:38
_rubenhighly depends on the customer base too .. i doubt much isp would swip their adsl blocks :p08:39
subof course not, but most ISPs swip the blocks they give with leased/dedicated circuits08:40
jmarsdenRudyValencia: Looks OK to me, but I am not a lawyer.08:40
_rubenexactly08:40
RudyValenciaI forwarded my SSH port to a different number than 2208:41
RudyValencia(I hate getting SSH scans08:41
RudyValenciaalso, my VM seems to be stuck at 'Validating libklibc'08:42
RudyValenciaHm, I wonder what Linux does for consoles on computers that don't support text-only modes08:44
RudyValencia(e.g. 68k/PPC Macs, etc.)08:44
RudyValenciamy VM has stalled :/08:56
RudyValenciaI'm trying to get Ubuntu to install and the VM keeps stalling08:56
RudyValencianevermind08:57
RudyValenciait returned08:57
Psi-Jack__Okay.. So my router, presently, has only a small annoyance.09:21
Psi-Jack__When eth1, my net interface, comes up, it replaces /etc/resolv.conf with that retrieved via the DHCP.09:21
Psi-Jack__I don't want that, I want it to stay as I put it, or to adjust it with resolvconf to settings specifically supplied by wherever it gets that.09:21
Psi-Jack__Cause, I have my own domains. I have my own DNS, I don't want my router out of sync with that.09:21
subone sec, I do the same thing here at home09:24
subYou're going to want to edit /etc/dhcp3/dhclient.conf09:27
subAnd you can either add a prepend line to add your static servers before the ones given by dhcp, or you can just not request the DNS info09:27
Psi-Jack__Hmm09:40
Psi-Jack__I'd tried taking out requesting it, and it still overwrote my resolv.conf file.09:40
Psi-Jack__But, so far, supersede domain-name-servers fixed my nameserver entries, but now I Just need to fix domain and search.09:41
RudyValenciahm, I think there's a problem09:44
RudyValenciaW: Failed to fetch http://mirrors.kernel.org/ubuntu/dists/hardy/Release  Unable to find expected entry  main-updates/source/Sources in Meta-index file (malformed Release file?)09:45
RudyValenciaE: Some index files failed to download, they have been ignored, or old ones used instead.09:46
jmarsdenRun sudo apt-get update again, or pick a different mirror and then try again.09:46
RudyValenciaIt happens with several mirrors.09:47
RudyValenciaTried Easynews, kernel.org, and OSUOSL09:48
jmarsdenOdd.  I should be asleep (almost 2am here), but I'll check it on an old Hardy VM I have... booting now...09:48
RudyValenciaAlmost 3 here.09:49
jmarsdenSeems to work fine from here (using us.archive.ubuntu.com as the mirror).09:50
RudyValenciaMaybe the mirrors are broken09:51
RudyValenciaNot working here09:52
jmarsdenI just tried with mirrors.kernel.org and that worked for me too.09:53
jmarsdenAre you out of disk space somehow on /var ?  Not really sure what else to check...09:54
RudyValenciadf says only 8% of the disk is used09:56
jmarsdenAnd you just created a single partition, not a separate /var ?  Then that's not it...09:57
jmarsdenThat's not an absolutely show-stopping warning, it just means you may not be getting the very latest updates...09:58
jmarsdenBut it shouldn't be happening, at least not reliably and on multiple mirrors.09:59
* RudyValencia reboots the VM09:59
* jmarsden goes to bed :) Goodnight all.09:59
_rubencould be a flakey (transparent) proxy interfering10:02
RudyValenciaNo proxies here10:03
RudyValencia_ruben: I made a typo.10:14
RudyValenciaThat was why it failed10:14
RudyValenciaI shouldn't be writing a configuration file at 3AM10:15
LiraNuna"passwd: Authentication token lock busy" any idea what that means?10:15
LiraNunaI upgraded libpam-mysql from a working config, now I get this10:15
LiraNunaI'm sure common-password is configured right as with old pam-mysql I could change the password (only as root, though)10:16
Boohbahhi RudyValencia10:43
Boohbahdid you find a job yet?10:43
RudyValenciaStill at Walgreens10:44
Boohbahwhat location?10:45
RudyValenciasame as before10:46
Boohbahi forgot where that was10:47
RudyValenciaGreeley10:48
RudyValencia23rd Avenue and 16th St.10:48
BoohbahNebraska?10:48
RudyValenciaCO10:49
RudyValencia(Colorado)10:49
RudyValenciaalso, how do I prepend the output of uname -a to a text file?10:49
Boohbahi don't know about prepend with bash10:50
Boohbahi can append10:51
foolanoRudyValencia: using sed?10:52
RudyValenciaany method10:52
_rubennasty way: file=/some/file ; uname -a > $file.tmp ; cat $file >> $file.tmp ; mv $file.tmp $file10:52
foolanoi prefer: sed 1ifoo file.txt10:53
Boohbahthat's a really nasty way10:53
RudyValenciaI got it10:53
_ruben"any" also covers "really nasty" in my book ;)10:53
RudyValenciaecho `uname -a` > newfile; cat originalfile >> newfile10:54
foolanosed 1i"$(uname -a)" file.txt10:54
Boohbahfoolano: nice!10:58
foolanosudo dumpe2fs -b /dev/sda3 | wc -l11:02
foolano6511:02
foolanoarhhh, it aint looking good11:02
RudyValenciaAnyone here having difficulty building VMware Tools or open-vm-tools on Ubuntu Server 8.04?12:03
RudyValenciaI can't get them to build12:03
RudyValencia:(12:30
RudyValenciaWhy won't VMware Tools build on Ubuntu 8.04.2 Server?12:30
LMJI've create a lvm volume a couple of months ago and store datas on it. I rebooted today after an simple upgrade, no more LVM ! pvdisplay, vgdisplay & lvdisplay are empty, What could I do to get back my files ?12:43
AlexC_morning12:54
AlexC_I've recently stopped using SpamAssasin, and instead just using Postfix restrictions (which is working very well), however I just saw in my logs this: postfix/smtpd[14337]: NOQUEUE: reject: RCPT from openzula.org[72.14.177.55]: 504 5.5.2 <localhost>: Helo command rejected: need fully-qualified hostname; from=<noreply@tangocms.org> to=<users-email@example.com> proto=ESMTP helo=<localhost>12:55
AlexC_how come it is blocking openzula.org (which is a domain I own, and is 'on' this server), for not being a FQDN? How is that not a FQDN?12:56
AlexC_this email would have been a forum notification email to a user, from the board its self12:56
giovaniAlexC_: because it's not identifying itself as openzula.org, it's identifying itself as "localhost" as far as I can tell13:31
pmatulisAlexC_: perhaps pastebin the output of 'postconf -n'13:35
AlexC_pmatulis: sorry, was away: http://paste2.org/p/39549713:43
giovaniAlexC_: output of 'hostname -f'?13:49
AlexC_'localhost' .... that'll be why then, giovani =)13:55
AlexC_editing /etc/hosts to have the one I want first, made 'hostname -f' return what I wanted. I assume that would have fixed it now13:56
giovaniwhat?14:00
giovanidon't edit /etc/hosts14:00
giovanithat's not where the hostname belongs14:00
giovaniyou want to edit /etc/hostname14:00
AlexC_I know, however that is not where hostname -f and where it looks up is from14:00
giovanihuh?14:01
AlexC_as stated in 'hostname --help': "Unless you are using bind or NIS for host lookups you can change the FQDN (Fully Qualified Domain Name) and the DNS domain name (which is part of the FQDN) in the /etc/hosts file."14:02
giovaniyou don't need to that, but ok14:03
AlexC_well, /etc/hostname is already set to 'cypher.openzula.org', so it wasn't getting it from there14:03
giovanihad you rebooted since that had been set?14:04
giovaniit absolutely gets it from there14:04
giovani       The host name is usually set once at system startup in /etc/rc.d/rc.inet1 or /etc/init.d/boot (normally by  reading  the  conĂ¢14:04
giovani       tents of a file which contains the host name, e.g.  /etc/hostname).14:04
AlexC_giovani: yes, server was rebooted yesterday in fact. However, the output of 'hostname' did give cypher.openzula.org - it was only when doing 'hostname -f' it gave 'localhost'14:05
giovaniok, 'hostname' shouldn't be providing the FQDN14:06
giovani/etc/hostname should contain just the first section of the hostname (the machine-specific part)14:07
giovanithen you can add an entry in /etc/hosts with both the FQDN, and the hostname14:07
AlexC_giovani: so /etc/hostname to be just 'cypher'?14:09
=== roaksoax_ is now known as RoAkSoAx
tdnHow do I run a script everytime I boot the machine, after the network has been brought up. I have tried putting the script in /etc/network/if-up.d/, but appearently, this does not work. How do I solve this?15:21
AlexC_tdn: there is the special cron '@reboot' value, though I am not sure if that is genearlly considered bad practice to do so15:24
tdnAlexC_, how do I find out?15:27
tdnAlexC_, is reboot not on shutdown? I need to run it on start up.15:27
AlexC_tdn: man 5 crontab, scroll down "@reboot        Run once, at startup."15:28
tdnAlexC_, ok. How do I find out if it is bad practice?15:29
AlexC_ask people ;)15:29
tdnOk :)15:29
tdnHere?15:29
AlexC_this is an asky place, so yeah I guess so15:33
Boohbahtdn: i would append it to /etc/rc.local15:40
tdnBoohbah, how? Just symlink the script in there? Do I need to do something else? _How do I make sure that it is run after network is up?15:41
Boohbahiirc /etc/rc.local runs last15:42
Boohbahtdn: not symlink, just call the script from there15:42
tdnBoohbah, /etc/rc.local is empty, so I just put it in there?15:42
Boohbahyup15:42
tdnBoohbah, ok. Thanks.15:43
XiXaQseveral times now, when setting up a system with raid or lvm, the installation stops, complaining it can't find any cd-rom and that no repository has been configured. I'm using 9.04 i386. Does anyone know why? The cd-rom has been tested ok.15:50
BoohbahXiXaQ: probably the raid controller driver. what model is it?15:52
XiXaQI'm using software raid.15:52
Boohbahoh15:52
XiXaQhowever, when the partitions are setup and I reboot, the install finishes properly.15:55
XiXaQoh, I think maybe my cd-rom drive is trying to tell me something.16:08
madalinhello. I really need help setting up a dhcp server and make my fresh installed ubuntu, a gateway..17:32
=== mdz_ is now known as mdz
MeikiHi - could someone help me with an IP address issue that I'm having. Please look at http://pastebin.com/m575e62fd, I can bind public services to the first IP, but not to the others (*.87- onwards).18:11
RoyKheh - Meiki waited for three minutes before he left :)18:20
MeikiRoyK: huh18:22
RoyK[19:11]  <Meiki> Hi - could someone help me with an IP address issue that I'm having. Please look at http://pastebin.com/m575e62fd, I can bind public services to the first IP, but not to the others (*.87- onwards).18:24
RoyK[19:14]  * Meiki (i=568092bf@gateway/web/freenode/x-nylzhfnikmfuvzyp) has left #ubuntu-server18:24
RoyKhow do you try to bind to those IPs?18:24
RoyKbtw, the old eth0:x is not recommended anymore18:24
subsays who?18:24
RoyKrather use ip addr add 10.0.1.12/24 dev eth118:25
RoyKor so18:25
RoyKsub: the new method has been around for a while18:25
RoyKwell, it works, but I guess it'll be removed some day, since ip "aliasing" is something that were phased out close to 10 years ago18:26
RoyKMeiki: anyway - how do you try to bind to those IPs?18:27
RoyKit should work18:27
subThe application should have a bind address of 0.0.0.0 to bind on all interfaces and you should doublecheck to ensure that you don't have any firewall rules that could block traffic to those other IPs18:28
RoyKsub: possibly an application should bind to a specific ip18:29
RoyKif using apache, bind to all, and add the respective address in the virtualhost18:30
RoyKbut if Meiki doesn't want to specify any details, he can't really get most help18:30
subRoyK: Right about binding to a specific IP, depends on what the requirements are =) and I agree18:32
ipauldevI run Ubuntu 8.04 LTS Server. apt-get is painfully slow when downloading large files. It starts out fast and goes down to under 25B/sec. I've tried using apt-mirror to make my own local repo, it starts out downloading fast, but that too, starts to be Bytes/second if I "du" the directory and watch the size. I've used multiple mirrors with the same issue. I can start again fast, and it slows down. Connected via a DS-318:46
ipauldevAlso is happening with multiple installs of it... they18:47
ipauldevthey're all running on the same box, vmware.. 64MB ram, 30 some GHz available18:48
ipauldevAny ideas?18:48
PhotoJimipauldev: sounds like network issues.  just keep trying different mirrors.  or do a speed test to some other site that should be fast and see what performance you get.18:51
ipauldevyeah it doesn't happen anywhere else on the network with other instances, so I wonder if it's a vmware issue or the networking on the vmware cluster18:53
ipauldevthanks18:53
PhotoJimit could be, but that doesn't seem likely.18:54
user1_ have kubuntu 6.10 dgy. how can i upgrade it to the latest.(the option of uqgrade doesnot appear when i fetch updates in adept package manager)>19:24
ipauldevYeah, it does it with a wget too, of a large iso. If it re-establishes the connection, The router shows throughput on the interface of 10,000 Mbps, the limit setup.. then after a 30 or 60 seconds it drops off into nothingness... Foobar! lol19:24
ipauldevuser1_ I think an apt-get dist-upgrade might get you there.19:25
user1_ok19:26
user1_not working19:26
user1_ where are the files that contain the server address to download programs and updates by package manager or apt?19:26
ipauldev/etc/apt/sources.list19:26
RoyKuser1_: do-release-upgrade19:27
RoyKuser1_: you also may need to change /etc/update-manager/release-upgrades19:28
RoyKthere you can set the upgrade policy19:28
user1_ what is the name of the lates kubuntu distro? may be i can toogle the name in sources.list with it at 'egdy'?19:30
giovaniuser1_: this is #ubuntu-server not #kubuntu19:38
RoyKuser1_: read what I wrote above19:48
RoyKuser1_: also, like giovani said, this channel is for server-specific questions, not general ubuntu stuff19:48
ipauldevFUI, I've got that local mirror running and things work fine using that, so my guess is that it's the router or the intrusion protection system blocking/slowing down the requests. I'll be looking at that with our netowrking/IPS team Monday. Thanks for the help.19:51
ipauldevYUI=FYI19:51
DelphiWorldhi20:50
Tsapoc^hello there ! Why does all the other computers on network have internet but my server doesn't? I can ssh to it (ip:192.168.2.3) but when i try to tell him to ping www.google.com it doesn't respond... Anyone have any ideas ?20:59
giovaniTsapoc^: likely to be misconfigured/non-configured DNS21:03
Tsapoc^yeap i figured that out just fixed it :)21:08
Tsapoc^but thanks m8 :)21:08
Acshello23:10
AcsI just logged in to my ubuntu-server machine and got this23:10
Acs3 packages can be updated.23:10
Acs6 updates are security updates.23:10
Acslittle strange23:10
Acsbut how can I see wich packages can be updated?23:11
jmarsdensudo apt-get -s upgrade       will do a simulated upgrade23:11
Acsthanks23:11
jmarsdenNo problem.23:11
Acsbut can you tell me why it says 3 packages can be updated and then tells me 6 are security updated23:12
jmarsdenNot really... that text is from the landscape-sysinfo client, right?  If you run it directly     landscape-sysinfo     what does it say then?23:12
Acsjust this23:13
AcsSystem load: 0.0 Swap usage: 0% Users logged in: 123:13
AcsUsage of /: 0.7% of 226.26GB Temperature: 28 C23:13
AcsMemory usage: 11% Processes: 11423:13
AcsGraph this data and manage this system at https://landscape.canonical.com/23:13
Acsnothing related to the updates23:13
jmarsdenso... where did the text about updates come from that you quoted earlier?23:13
Acsbelow the info of the landscape-sysinfo23:14
Acsbut it only appeared when I logged in23:14
Acsnot now when I ran the command23:15
Acshhumm I ran the apt-get command23:15
jmarsdenThen either something changed, or there is some other piece of software running at login displaying that information for you23:15
Acsthe updates are for apache2 apache2-mpm-prefork apache2.2-common23:16
Psi-Jack__Hmm23:16
jmarsdenWell, if appropriate you can do    sudo apt-get upgrade    to install those, and then see what happens when you log out and in again?23:16
Psi-Jack__ubuntu 9.04 Server doesn't have IPP2P MATCH support?23:16
Psi-Jack__The kernel that is.23:17
Acsjmarsden ok23:17
AcsI upgraded23:17
Acsbut if I loggin again23:17
Acsnothing will be shown23:17
jmarsdenPsi-Jack__: That might be in a module you need to load?23:17
jmarsdenAcs: Then I'd say you are now up to date :)23:17
Acsjmarsden indeed :D23:18
Psi-Jack__jmarsden: Hmm, what would the module be named to load, then?23:18
jmarsdenThat's not something I have used, but there are a bucnh of modules related to IP and netfilter that start with ip or nf respectively...23:19
Acsjmarsden thanks again for the help23:19
jmarsdenAcs: No problem.23:19
jmarsdenPsi-Jack__: Look under /lib/modules/2.6.28-15-generic/kernel/net/ipv4/netfilter/ and see if anything likely is there?23:20
Psi-Jack__Well, according to a wordpress site, I'm seeing for Hardy at least, ipp2p match support has to be patched in, but I'm using 9.0423:21
Psi-Jack__But the wordpess articles' not in English, so hard to truely grasp what it's talking about. ;)23:22
jmarsdenIt may be the same for 9.04... you can always just apt-get install linux-source and see how it is configured.23:23
* Psi-Jack__ nods.23:23
Psi-Jack__Heh, basically trying to figure out how to get shorewall to tc torrent traffic. ;)23:24
Psi-Jack__and ipp2p, is the suggested method.23:24
Psi-Jack__Otherwise, I won't know how I'd set the port stuff appropriately.23:24
Psi-Jack__don't*23:24
jmarsdenHmm, there is an xtables-addons source package that might be relevant, in Jaunty and Karmic.  But its only there as a source package, not binary package.23:27
Psi-Jack__Hmm, apt-cache search doesn't find that for me.23:28
Psi-Jack__!find xtables-addons23:28
ubottuPackage/file xtables-addons does not exist in jaunty23:28
jmarsdenTry   rmadison xtables-addons23:28
Psi-Jack__I don't have rmadison? heh23:29
jmarsdensudo apt-get install devscripts    will fix that.23:30
Psi-Jack__Gotcha. I'm seeing in in jaunty/universe as you said, as source only.23:32
jmarsdenIt has project pages on LP, too, at https://launchpad.net/ubuntu/+source/xtables-addons ... but I've not found online docs saying exactly what is in it...23:32
Psi-Jack__http://ubuntuforums.org/showthread.php?t=122187723:32
Psi-Jack__This is one thing I found about ipp2p for jaunty.23:33
Psi-Jack__So far, everything''s leading to rolling a custom kernel.23:33
jmarsdenThat post grabs sources from all over the place... be *careful* if you follow that!23:34
Psi-Jack__Yeah, exactly my thoughts23:34
Psi-Jack__Does it look to appear to make a .deb package out of it all, to you, in the end?23:35
jmarsdenI'd say either a custom kernel or at least a custom compiled kernel module, yes.  I wonder if that xtables-addons package will let you build this capability as a module?23:36
jmarsdenNo, it looks like the post builds a kernel module and loads it.  no package in sight.23:36
jmarsdenVery 1990s :)23:36
Psi-Jack__Wait..23:36
Psi-Jack__But it uses make-kpgk23:36
Psi-Jack__Isn't that the ubuntu way to roll your own into .deb files?23:37
ycyis there a way to see very change in /var/log files? a sort of multi-tail of every file?23:37
ycya sort of... cruise?23:37
Psi-Jack__ycy: Hmmm., sounds to me like you would benefit with rsyslog.23:37
Psi-Jack__ycy: With rsyslog, you could log into pgsql or mysql, and use phplogcon to view it.23:38
Psi-Jack__jmarsden: YIKES! This posting, links /usr/src/linux to /usr/src/linux-2.8.2623:39
Psi-Jack__Heh23:39
* Psi-Jack__ scratches this off the list, quickly!23:39
jmarsdenPsi-Jack__: Ah, yes, so he does make a custom kernel package... but then after that he removes iptables and copies a kernel module directly into the filesystem and loads it... it looks... "interesting"23:40
Psi-Jack__Hmmm23:40
Psi-Jack__I don't like that either, then. LOl23:40
Psi-Jack__So basically, for sure, getting ipp2p support is a chore.23:41
Psi-Jack__Prolly worth it if ya need it, but a chore, regardless.23:41
jmarsdenycy: sudo apt-get install multitail23:41
jmarsdenPsi-Jack__: Looks that way.23:41
Psi-Jack__multitail? interesting.23:42
jmarsdenhttp://www.vanheusden.com/multitail/23:42
Psi-Jack__Impressive. ;)23:43
Psi-Jack__I still like my phplogcon method though.23:43
jmarsdenYes... look at the example: http://www.vanheusden.com/multitail/images/sd/lotsofwindows.png23:43
Psi-Jack__That helped me determine my pgsql server box was having issues with acpi and the cooling fans.23:43
Psi-Jack__End result, I had to pretty much annoyingly disable acpi altogether, which is sad.23:43
jmarsdenI had an HP server tell me "fan 4" was dead and rebooting... trouble was, there were only 3 fans in the thing... I think we just replaced the chassis :)23:44
Psi-Jack__Yep.23:44
Psi-Jack__Mine only had FAN, 1 fan, and it couldn't turn it on. Every 6 seconds.23:45
Psi-Jack__It thought the CPU needed to be -266 C23:45
Psi-Jack__And it was hellfire bent on making it happen. ;}23:45
jmarsdenAll that server hardware smarts is great when it works... but sometimes it just doesn't23:45
Psi-Jack__Yeah.23:46
Psi-Jack__I just can't see -266 C being a good thing for a CPU. ;}23:46
jmarsdenWell, that's a few degrees above absolute zero... might be able to overclock it quite a bit :) :)23:46
Psi-Jack__I think it was the common problem that it used the 5-byte ACPI message codes, instead of the standardized 6-byte.23:46
Psi-Jack__And Linux to current date, I don't think has workaround stuff for that, where-as FreeBSD does.23:47
Psi-Jack__Anyway, I guess I'll try to tc torrent another way for now.23:48
Psi-Jack__Without ipp2p, just to see if it'll work.23:49
Psi-Jack__ERROR: SOURCE/DEST PORT(S) not allowed with PROTO all : /etc/shorewall/tcrules (line 15)23:51
Psi-Jack__Bleh23:51
xenoterracideI've got a command set to run in cron at  45 *  *   *   *23:52
xenoterracidewhen I run the command by hand it works23:52
xenoterracidehowever it doesn't seem to be running by cront23:52
xenoterracidecron*23:52
xenoterracideany idea's why?23:52
Psi-Jack__Blah! Even more blah!23:52
jmarsdenPATH or environment variable differences, most likely.23:52
xenoterracideI used the full path to the command23:53
Psi-Jack__At least ubuntu, has shorewall 4.2.x, but gentoo, looking at my work servers, only has ebuilds up to 4.0, unmasked, 4.2 masked.23:53
jmarsdenxenoterracide: what is the command in question?23:53
xenoterracideit's a custom backup script I wrote23:53
xenoterracide /var/www/oblivionet.com/scripts/backup.sh < that's the path23:54
jmarsdenThen check the #! line at the top, and that all paths within the script are full paths or in a PATH you set at the beginning of the script.23:54
xenoterracide#!/bin/bash23:54
jmarsdenxenoterracide: You can also to  MAILTO=me@mydomain.com   in the crontab file before the line concerned and see if it sends you email about any errors...23:55
xenoterracidethat cron is right to run every hour at the 45 minute mark right?23:55
jmarsdenLooks right to me.23:55
jmarsdenTest with   40 * * * * /bin/date23:57
Psi-Jack__Ayup. It's right.23:57
jmarsdenand see if MAILTO=me@excample.com  mails you the date and time, so you know cron itself is working.23:57
xenoterracideok I changed that to 0 and put the MAILTO at the top of the crontab for my user23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!