/srv/irclogs.ubuntu.com/2009/10/13/#ubuntu-server.txt

uvirtbotNew bug: #410379 in tomcat6 (universe) "Tomcat security configuration error prevents proper logging when used with Sun's JVM" [Low,Triaged] https://launchpad.net/bugs/41037900:32
sgroverhelp with Apache virtual host issue?  http://pastie.org/65228300:57
sgroverThe "standard" suggestions for vhost problems don't seem to apply - the server already has functional vhosts, the new one refuses to work...00:58
uvirtbotNew bug: #448656 in mysql-dfsg-5.1 (main) "CPU information is inaccessible for MySQL" [Low,Incomplete] https://launchpad.net/bugs/44865601:01
Nattgewtransmission-daemon keeps giving me a 401 unauthorized error... I edit the settings.json but every time I restart the daemon that file gets rewritten01:13
wizardslovakhello people01:22
wizardslovakdoes ubuntu server support sata to pci cards?01:22
=== freeflyi2g is now known as freeflying
sgroverResolved my problem.  Server name "projects"  so setting up a vhost with a server name of "projects.myserver.com" resolves to something different than you might be expecting... sighs...01:31
slampoudI've downloaded the image from http://cdimage.ubuntu.com/ubuntu-server/daily/current/karmic-server-amd64.iso , verified md5 sums, burned install CDs, and had them fail their internal md5 checks several times yesterday and today. This happened using two different CD burners, and media known to be OK, so it may be worth verifying that the ISO bits are actually OK.02:06
uvirtbotNew bug: #450008 in mysql-dfsg-5.0 (main) "mysql server crashes while installing for the second time" [Undecided,New] https://launchpad.net/bugs/45000802:45
uvirtbotNew bug: #450007 in mysql-dfsg-5.0 (main) "package mysql-server-5.0 5.1.30really5.0.75-0ubuntu10.2 failed to install/upgrade: sub-processo post-installation script retornou estado de sa?da de erro 1" [Undecided,New] https://launchpad.net/bugs/45000702:46
aubrehello, I've been on holiday but I will be back at work , I've seen Jono's call for testing Eucalyptus and I will be doing my part03:05
aubreI have one front-end and two nodes, they are working currently03:05
=== SyL is now known as Guest74631
maxagazif i need to run a command after all services of a server are started, i just have to put it in /etc/rc.local before "exit 0", right ?05:24
jtajimaxagaz: thats right05:31
mushroomblueanyone alive that can answer a hopefully-simple http question?06:07
Jeeves_mushroomblue: Ask the question and you will find out06:09
mushroomblueanyone know why ssh/http connection attempts would die when reaching my internal web server?06:10
mushroomblue like, I look in wireshark, and see syn requests that have my home IP as the source.06:10
mushroombluethey travel through the router, and seemingly through the switch.06:10
mushroombluewireshark is showing a SYN request.06:10
mushroombluebut the system itself doesn't ACK.06:10
Jeeves_A firewall? :)06:11
mushroomblueufw is configured to allow ports 80, 22, and 44306:11
mushroombluethough I disabled ufw just to check.06:11
mushroomblueand iptables -L isn't showing anything wrong.06:13
mushroomblueaccording to the firewall, everything's pretty goatse'd.06:13
uvirtbotNew bug: #450093 in mysql-dfsg-5.1 (main) "Root password prompt failing" [Undecided,New] https://launchpad.net/bugs/45009306:16
ssmmushroomblue: anything in the web server's kernel log?06:16
mushroombluelemme look.06:16
mushroombluenothing that I can tell.06:18
mushroombluelooks like UFW blocked an internal IP once or twice, but that's about it.06:18
ssmis it pingable either way?06:18
ssmfrom or to the server?06:19
mushroomblueI can connect to the box any other way than externally.06:22
mushroomblueon another box inside the firewall, it connects on ports 22 and 8006:22
mushroomblueI can see the traffic being sent to the box in wireshark.06:22
mushroomblueat least, SYN packets.06:23
mushroomblueso, the only things I can think of it being are something stoopid in the router's access control list, or something with the switch.06:23
mushroombluethe first, I think I've been able to rule out. nat translations are showing the connection being routed to the proper internal IP06:24
mushroombluea switch shouldn't be causing these problems, should it?06:24
ssmor a wrong arp entry, if you've recently moved the IP address06:24
ssmI've had a piece of network equipment randomly overwrite the target MAC address, making the system reachable only if it was running in promisquos mode.  as in "Why is the internet working only when I run tcpdump?"....06:25
mushroomblueright.06:26
_bubsywho ever use openfire ?07:18
artillerytxHey guys is SFTP enabled by default in an install ?07:33
livetodayrunning (sudo) apt-get <anything> gives me a segfault. can this be fixed? is it a known issue?07:40
cemchey. can I run an ubuntu 9.04 desktop 32bit with 12gb ram AND actually use the 12gb ram ?07:43
KurtKrautlivetoday, are you sure there isn't a hardware failure, like in RAM?07:48
livetodayhow would i identify such? the failure seems isolated to this one program, and occurs whenever it is run07:51
twbartificialexit: sftp is enabled by default within openssh; I think openssh-server is probably not installed by default.07:58
alex_jonicemc: surely not08:13
livetodayKurtKraut, how would i identify such? the failure seems isolated to this one program, and occurs whenever it is run.09:23
KurtKrautlivetoday, have you rebooted since the problem appeared?09:23
livetodayKurtKraut, no. i haven't rebooted this month.09:24
KurtKrautlivetoday, is aptitude working? Try aptitude update09:25
livetodayaptitude doesn't work either: it says that it gets a sigsegv, then closes with a segfault09:26
livetodayKurtKraut^09:26
twbcemc: IIRC what the kernel does is access 4GiB at a time, and then "page" between 4GiB areas of RAM.  If it works at all, it will be a filthy bodge.09:26
KurtKrautlivetoday, are you running Jaunty?09:26
livetodayKurtKraut, yes09:26
twbcemc: fortunately, your CPU probably supports x86-64 (amd64), so you can just install that.09:26
KurtKrautlivetoday, was your system up to date?09:27
livetodayKurtKraut, pretty sure it was. i login via ssh regularly, and do an apt-get update && apt-get upgrade whenever informed that there are package updates available.09:28
KurtKrautlivetoday, please tell me the output of md5sum /usr/bin/apt-get09:28
livetodayKurtKraut, 92759f1b80a768406e1ad6e87d057cfe09:29
KurtKrautlivetoday, this is the expected output. Your problem requires further investigation. Please, post all the details you already provided me in ubuntuforums.org09:30
KurtKrautlivetoday, in my experience, wierd segfaults or kernel panics are associated with hardware failure (hard disk or RAM)09:30
livetodayKurtKraut, would expect a reboot, or a reinstall to be useful?09:32
KurtKrautlivetoday, to determine if there is a hardware problem? Yes. If there is one, the effects would be wider and more evident.09:33
KurtKrautlivetoday, but no matter what is causing this, reboot wouldn't fix it.09:33
livetodayKurtKraut, diagnostically, would either step be useful?09:34
KurtKrautlivetoday, I would start with a RAM test.09:35
livetodayKurtKraut, there's one built in, that can be selected in the boot-loader, yes?09:35
KurtKrautlivetoday, yes.09:37
livetodayKurtKraut, guess i'm rebooting then. thanks for your assistance09:38
StrangeCharmKurtKraut, i'm livetoday's. it does appear to be the ram. memtest is throwing errors like nobody's business.09:41
KurtKrautStrangeCharm, several output with red background?09:41
StrangeCharmKurtKraut, several dozens of thousands of errors09:42
KurtKrautStrangeCharm, lol. I knew it! :D09:43
KurtKrautStrangeCharm, you can abort the RAM check. You already know it may be damaged.09:43
StrangeCharmKurtKraut, it does come as something of a surprise to see ram this broken09:43
StrangeCharmKurtKraut, yes, but the only solution i know of is purchasing new ram, which is never fun09:44
jmarsdenStrangeCharm: I'd say you just found your problem.  Replace your RAM and retest.  Worst case, you could try removing half of the RAM modules in the machine and test again, you might find you can determine which RAM module(s) have the problem and then use only know good ones...09:44
KurtKrautStrangeCharm, you may try to remove, clean them and put it back.09:44
StrangeCharmKurtKraut, you mean, clean the pins?09:46
StrangeCharmrather, the contacts09:46
KurtKrautStrangeCharm, exactly09:46
StrangeCharmhow does ram get damaged like this?09:46
KurtKrautStrangeCharm, the procedure jmarsden recomended is also important.09:46
StrangeCharmas a more general question, in terms of how to avoid it in future09:46
KurtKrautStrangeCharm, usage, oxidation, umidity, excessive heat etc.09:47
StrangeCharmKurtKraut, jmarsden i'm already starting09:47
KurtKrautStrangeCharm, this is one of the reasons datacenters have such controlled climate/enviroment09:47
StrangeCharmwell, i have a dormroom in a humid region, and a fan...09:48
StrangeCharmmy budget contends much better with downtime and ram replacements, than data-center-like control09:49
StrangeCharmgood news: one of the dimms is not generating a large number of errors immediately09:53
StrangeCharmKurtKraut, jmarsden, cleaning both dimms, and changing the slots in use seems to have completely eradicated the memory problem: memtest isn't givint me any more errors10:19
KurtKrautStrangeCharm, I'm glad to hear that.10:19
StrangeCharmif i use ubuntu to set up an encrypted softraid5 of n disks, and i suffer a catastrophic hardware failure which destroys all system hardware except but n-1 disks, will i be able to construct a new system and recover that data?11:35
=== baffle_ is now known as baffle
=== georg is now known as kwork
uvirtbotNew bug: #377356 in openssh (main) "ssh-askpass has no Option to save the Passphrase to a keyring" [Low,Incomplete] https://launchpad.net/bugs/37735612:31
myeggohello, this is my logrotate configuration: http://pastebin.com/m7020dffa - but it still stores the log weekly, someone could give me a link or any idea about how to make it working? thanks in advance13:15
myeggoi am being ignored in every channels :/13:16
uvirtbotNew bug: #450309 in qemu-kvm (main) "assertion failure when using i82551 network card emulation" [Undecided,New] https://launchpad.net/bugs/45030913:21
uvirtbotNew bug: #447585 in eucalyptus "Cached image not being flushed from the cache on deregister in some cases" [Low,In progress] https://launchpad.net/bugs/44758514:02
=== sommer_ is now known as sommer
ttxkirkland: howdy -- I have a merge to 925 in my PPA14:26
ttxkirkland: I wait for upstream ack to upload that14:27
VousDeuxDoes anyone know if thereis some way to monitor for a specific error condition and automatically execute a bash script in response to the error?14:27
bogeyd6VousDeux you could set a cron job every minute14:29
bogeyd6or you could use a nagios solution14:30
VousDeuxI'm trying to avoid the every minute thing if possible...I'll look into the nagios solution...thanks for your suggestion.14:31
uvirtbotNew bug: #422000 in postfix (main) "package postfix 2.5.5-1.1 failed to install/upgrade: subprocess pre-installation script returned error exit status 1" [Low,Incomplete] https://launchpad.net/bugs/42200014:32
VousDeuxnagios looks like a very good possibility...thanks again.14:34
bogeyd6yw14:34
kirklandttx: that sounds fair14:34
kirklandttx: hopefully the last upload?14:34
ttxkirkland: well, I want to prevent the "hey, 926 is so much better"14:35
kirklandttx: :-)  inevitable14:35
uvirtbotNew bug: #438565 in eucalyptus (main) "Eucalyptus Public IPs should be submitted in CIDR notation" [Wishlist,Triaged] https://launchpad.net/bugs/43856514:41
pnafternoon all14:55
pncan anyone comment on 'the best' way to set up identity management on ubuntu server? Perhaps using openldap or freeipa?14:56
_ruben!best14:58
ubottuUsually, there is no single "best" application to perform a given task. It's up to you to choose, depending on your preferences, features you require, and other factors. Do NOT take polls in the channel. If you insist on getting people's opinions, ask BestBot in #ubuntu-bots.14:58
pn*sigh*14:59
mushroomblueoutside of wireshark, is there a way to see if Apache is actually receiving connection attempts from the outside world?14:59
pnactually, I'd argue one of the things that differentiates something like ubuntu server from something like centos is the 'best' or most popular way of doing certain things: like file systems or package management - or in this case authentication15:00
pnthanks for the lecture just the same15:00
Picimushroomblue: see files in /var/log/apache2/15:00
mushroomblueI'll check. thanks.15:00
clustyhey15:02
clustysomething really weird is going on. my resolv.conf gets overwritten constantly with some default values. any clues what service could cause that?15:03
Jeeves_clusty: network manager or dhclient15:08
VousDeux...or openvpn15:08
clustythe machine is a local DNS and router box15:09
clustyi put the machine itself in the resolv conf cause i can never resolve local dns from the router itself15:10
clustygrrr15:10
clustyguess i need more digging15:10
ttxmathiaz: would you consider CIDR addressing that doesn't specify the right beginning for a segment: broken or acceptable ?15:21
ttxi.e. : 192.168.0.230/30 = 192.168.0.228 - 192.168.0.23115:21
ttxkirkland: Looking in the code to implement it myself, I discovered that euca kinda supports CIDR addressing for publicIP already15:22
mathiazttx: hm - acceptable. I wouldn't do it personally - because it makes my brain hurt15:24
acalvoa shot in the dark: does anyone know how to do a simple redirection with postfix? recipient_bcc_maps does not work, neither does modifing /etc/aliases15:25
VousDeuxI'm trying to follow the steps from the server guide for ldap and samba, but sldap-populate fails. I can do a ldapsearch on my active directory server just fine, so I'm not sure why sldap-populate fails...is there another way to accomplish what sldap-populate does?15:25
ttxmathiaz: have a look at bug 438565 then, and let me know if we should consider the current CIDR support in eucalyptus broken or usable15:25
uvirtbotLaunchpad bug 438565 in eucalyptus "Eucalyptus Public IPs should be submitted in CIDR notation" [Wishlist,Triaged] https://launchpad.net/bugs/43856515:25
acalvoVousDeux: mmm well, what's the output?15:26
VousDeuxI suspect that maybe my password is too complex and the sldap-populate script may not be reading it properly, but I would prefer not to have to change my password.15:26
acalvoI remember having some problems but they were related to incorrect credentials15:26
acalvoyou can create a script that execs the smbldap-populate, and store in a variable the password, so you know the password is ok15:27
* ahasenack can't figure out "ufw delete"15:27
ahasenackhow do I delete this rule?15:27
ahasenack0.0.0.0 5901/tcp           ALLOW       187.5.57.14315:27
VousDeuxIt says  LdapErr: DSID-0C090B38 a bunch of times...'Error in attribute conversion operation' From what I have gathered it seems to be an authentication problem, but I can authenticate manually with no problem.15:28
acalvoVousDeux: what version of smbldap-tools are you using?15:28
acalvoI think 0.9.6 was broken15:29
ahasenackI used "ufw allow proto tcp from 187.5.57.143 to 0.0.0.0 port 6001" to add it, just replacing "allow" with "delete" doesn't work15:29
acalvoit was better to use 0.9.515:29
acalvo(correct me if I'm wrong with the version control)15:29
ahasenackVousDeux: are you trying to use smbldap-populate against an AD machine?15:29
VousDeuxahasenack, yes...AD.15:29
acalvoVousDeux: well, AFAIK smbldap was made to emulate an AD15:30
ahasenackVousDeux: why? That's unlikely to work, you need at least the unix related schema15:30
acalvoso the default config for an AD should work with samba15:30
VousDeux...still trying to figure out how to check version...15:30
ahasenackVousDeux: you already have a "samba" server with ldap in that AD machine, it's called windows15:30
VousDeuxLooks like smbldap-tools is version 0.9.4-115:31
acalvoahasenack: that's unlikely to work also...15:31
acalvoVousDeux: https://gna.org/projects/smbldap-tools/15:32
VousDeuxI'm trying to convert/migrate from Active Directory.15:33
VousDeuxI want to shut the Windows Server down.15:34
acalvooh, OK15:34
VousDeuxI'm trying virtualize my server environment, but I want to use Linux as a server instead of Windows.15:34
VousDeuxI just can't seem to figure out why sldap-populate fails.15:35
VousDeuxI've repeated the steps from the  Server Guide three times.15:36
acalvobut, you have to run that against the samba-ldap server15:36
acalvonot the AD server15:36
VousDeux...each time I purged the installation of both LDAP and Samba and started from scratch.15:36
VousDeuxIsn't is supposed to populate the samba-ldap from existing ad?15:37
VousDeux...cause that's what I need to do.15:37
ahasenackVousDeux: it will work only against openldap, or at least something other than AD15:38
VousDeuxI don't understand how I am supposed to get the LDAP data from AD to samba/ldap then.15:41
acalvoVousDeux: you've several options15:43
acalvodump all your AD tree15:43
acalvomaybe use the openldap as slave and wait until it finish the replication routine15:44
VousDeuxI'm not trying to populate AD, I'm trying to populate ldap-samba by reading from AD.15:45
VousDeuxHmmm...that slave option rings a bell... maybe.15:46
wizardslovakhello people15:48
wizardslovakwhen i want to find word in "nano" editor15:48
wizardslovakhow do i do that?15:48
acalvowizardslovak: #ubuntu15:48
wizardslovakno i am in #ubuntu-server15:49
zer0her0anyone running ubuntu server on EC2?15:49
VousDeuxit looks to e like sldap-populate is trying to execute as user root instead of admin.15:50
\shVousDeux, you need to merge the data...we did that in the past, reading AD users/groups and pushing them into LDAP via shell script15:51
wizardslovakis there a shortcut to find word in nano editor?15:52
\shwizardslovak, #ubuntu is the right channel to ask15:52
wizardslovakwhy if ubuntu-server uses too15:52
kworkwizardslovak, ctrl + w15:53
VousDeuxOkay, so  if I can't use the documents from the Server  Guide to figure this out, what document should I use. I'm sure you guys are offering very good suggestions, but I have no idea what you are talking about. Where can I learn more?15:53
wizardslovakthank you15:54
kirklandttx: i think CIDR is better than nothing, but a human readable range would be ideal15:56
VousDeuxHmmm....it also looks like sldap-populate is reading AD and finding OUs that were not defined...like Builtin. The document and config files only asked for Users, Groups, and Machines.15:56
ttxkirkland: hmm15:57
VousDeuxMaybe that's the whole problem.15:57
magellanHello15:57
detratehello15:58
\shkirkland, CIDR is human readable for admins ;)15:59
magellanI'm looking for someone that successfully setup network interface bonding on Ubuntu 9.04... as I'm not able to get it working :(16:00
kirkland\sh: that's "admin readable", then, not "human readable"16:00
magellanI seems that everything works fine, if I disconnect the active interface cable the active interface change, but no traffic is able to transit through the backup interface.16:02
Davieymeeting?16:02
magellanNo one familiar with bonding ?16:09
=== dendrobates is now known as dendro-afk
VousDeuxI'm trying to learn how to use Ubuntu Server, but I can't seem to find the beginning of the documentation. I started with the Server Guide Introduction, but now I'm having problems following along with the steps and it seems like there is something else I should already know. Where is the beginning of the documentation?16:23
saltybeaglezul: greetings.. ashnazg and I are some php-pear fellows16:23
zulsaltybeagle: hi!16:23
saltybeaglezul: so the package doesn't use the phar at all?16:23
zulsaltybeagle: im working on it right now, i just downloaded the phar file from pear.php.net and doing a rebuilding test16:24
saltybeaglezul: ah, ok.16:24
zulsaltybeagle: no since our buildds dont have a network connection they use the one with the tarball16:24
saltybeaglezul: let us know if you need anything. Other pear guys are in #pear on efnet16:24
zulsaltybeagle: ah i thought you guys might be on oftc but there was no one there ;)16:25
saltybeaglezul: yah,, efnet for historical reasons.  :-)16:25
zulsaltybeagle: ill pop by later to let you guys know16:25
detrateanyone here have experience with NFS?16:26
saltybeaglezul: excellent.. we've got at least 3 or 4 ubuntu users in there at any moment, if you need any testers ofr anything16:26
zulsaltybeagle: cool thanks16:26
mushroomblueugh.16:26
mushroomblueI have an issue.16:26
mushroomblueI have webservers plugged into two different switches, on two different internet connections.16:27
mushroombluessh and apache will only respond if one of the interfaces is completely disabled.16:27
uvirtbotNew bug: #361819 in linux (universe) "Frequent random KVM host kernel OOPS " [Medium,Triaged] https://launchpad.net/bugs/36181916:32
=== dendro-afk is now known as dendrobates
uvirtbotNew bug: #450463 in vm-builder (universe) "acpiphp module needs to be loaded on first boot" [Medium,Confirmed] https://launchpad.net/bugs/45046316:56
ttxnurmi: about bug 43856517:06
uvirtbotLaunchpad bug 438565 in eucalyptus "Eucalyptus Public IPs should be submitted in CIDR or range notation" [Wishlist,Triaged] https://launchpad.net/bugs/43856517:06
ttxnurmi: I didn't realiaz that there was some CIDR support in eucalyptus already17:06
ttxrealize, even17:07
ttxmathiaz: would you consider writing up the minutes ? What's your current load average ?17:08
nurmittx: well, there is, but it probably should not be considered as stable enough at this point17:08
ttxmathiaz: I think I can do it, but I may be late in doing so17:08
nurmittx: I believe that a 'range' would be more solid17:08
ttxnurmi: if implemented server-side, yes17:09
ttxbecause anything that translates into 254 IP addresses into a shell variable gives me creeps17:09
nurmittx: I can quickly add range parsing to the CC17:09
ttxcould you comment on that bug ? I think range is more readable (and also more correct, since current CIDR translates to network - 2 addresses)17:11
nurmittx: however, i'm going to restrict any one range specification to the last octet17:11
ttxnurmi: works for me17:12
uvirtbotNew bug: #449244 in mysql-dfsg-5.0 (main) "package mysql-server-5.0 5.1.30really5.0.75-0ubuntu10.2 [modified: /var/lib/dpkg/info/mysql-server-5.0.list] failed to install/upgrade: subproces pre-installation script gaf een foutwaarde 1 terug" [Undecided,New] https://launchpad.net/bugs/44924417:12
nurmittx: i can comment on that bug now detailing 'the plan'17:12
nurmittx: i think we need a similar bug/commentary from your side on the plan for the upstart scripts17:12
ttxnurmi: that would be perfect, and allow kirkland to ack that it would look better than half-CIDR17:13
nurmittx: nod17:13
ttxnurmi: sure, once it's posted as a bug :)17:13
ttx(if not already)17:13
nurmittx: there are a few bugs that are related17:13
ttxposted as multiple bugs, then17:13
nurmittx: yes17:13
nurmittx: plus, some issues pointed out in email reports17:14
ttxnurmi: btw I hit and fixed bug 449530, was preventing any email sending17:15
uvirtbotLaunchpad bug 449530 in eucalyptus "Missing JARs make user registration impossible" [High,Fix released] https://launchpad.net/bugs/44953017:15
nurmittx: I did see that, good catch17:15
ttxnurmi: it also resulted in a borked user list in the web UI17:16
ttxi.e. after a failed email send, the user list would be returned empty17:16
ttxeven if you fixed the missing JARs, the user list would stay borked17:16
ttxbut I couldn't reproduce it on a fixed setup17:16
ttx(just so that you know about it)17:17
nurmittx: okay, good to know - i'll file a bug against eucalyptus about that issue17:17
ttxnurmi: to reproduce, remove the two JARs, attempt and fail to "apply", then log in as admin and look at the user list17:18
wizardslovakdoes anyone using clamav ?17:18
nurmittx: thank you17:18
=== Vog_ is now known as Vog
davmor2Hey guys good news current docs have worked successfully twice on the trot now.  I'd say that was pretty stable and testable :)17:33
VousDeuxOkay, so I change all of my samba-ldap config options to only use the openldap server, but when I try smbldap-populate it returns several error lines that all say "failed to add entry: modifications require authentication." Does mean that it is failing to read the password from /etc/ldapscripts/ldapscripts.passwd?17:33
wizardslovakhow do i move to some line in nano editor?17:34
KaeltenHi, I have an init script that's trying to run a script on a mount and it doesn't work during startup, is it possible the mount doesn't exist at that point?17:57
smoserit is definitely possible18:02
Kaeltenhrm, I just added some echo statements and that doesn't seem to be it :/18:02
BilgeWhere are ufw rules stored?18:02
jpdsBilge: iptables -L18:05
jpdsBilge: Or /etc/ufw/*.rules18:05
KaeltenI just have this init script http://paste.wowace.com/wa9b6pqiretn70sx/18:05
Kaeltenworks fine when I run it manually18:05
Kaeltenand it's getting called during boot18:06
Kaeltenbut it doesn't seem to work :/18:06
VousDeuxIt seems like all of this documentation is purposfully designed to fail so that us newbies are left scratching our head and searching for days on end trying to find solutions for errors.18:11
VousDeuxIt just seems like no matter how carefully I try to follow the steps I end up spending days and days trying to figure out why it didn't work.18:13
mushroomblueVousDeux: if you'd like, I could /msg you some urls that were helpful.18:15
VousDeuxI would appreciate that very much...thank you.18:15
VousDeuxI don't mind reading, it's just that I seem to have a very difficult time trying to to figure out what I should be reading. :)18:16
uvirtbotNew bug: #450518 in samba (main) "Wine failed to install properly and won't run applications" [Undecided,New] https://launchpad.net/bugs/45051818:17
arooniwe're trying to track down performance issues on our server.  we cant scale beyond 20-30 requests/per/second.  we're running a scaling test now.  our stack is apache/mod_rails/rails/mysql.  on ubuntu 8.10 64bit server.  any suggestions on WHERE to look and track down our errors?18:19
mushroomblueVousDeux: don't worry. the official documentation is focused on teaching you LDAP while setting up a server, and it makes it a chore to read/understand.18:21
mushroombluenot to mention, the SSL section is completely broken.18:21
VousDeuxAhhh...that explains it...I sure wish I could find the beginning of the documetation I should read to learn all of this stuff. It just seems like I'm forever searching for a document to learn how to do something, but every document I find assumes I should already know something else, so I end up in an endless circle of trying to find a document to explain the other document.18:24
uvirtbotNew bug: #446841 in image-store-proxy (main) "Unable to start images installed/registered via the image store" [High,Triaged] https://launchpad.net/bugs/44684118:27
mushroomblueVousDeux: yeah. I experienced that hell back in June.18:30
HexGhosthello18:32
HexGhostim migrating my company's current mail server from freebsd to ubuntu and im wondering what suggestions anyone has for backing up a mail server18:33
HexGhostright now i make a weekly tarball but that isn't very optimal18:33
orozcan someone help me turn off "Emulate3Buttons"?18:34
uvirtbotNew bug: #450534 in samba (main) "package samba 2:3.3.2-1ubuntu3.2 failed to install/upgrade: il sottoprocesso post-installation script ha restituito un codice di errore 1" [Undecided,New] https://launchpad.net/bugs/45053418:36
Bilgejpds: the /etc/ufw/*.rules seem to have nothing to do with the rules that I've set up18:46
uvirtbotNew bug: #347211 in authbind (main) "authbind unreasonably fails to address ports 512 through 1023" [Undecided,Fix released] https://launchpad.net/bugs/34721118:46
VousDeuxShould I be concerned that after running 'dpkg-reconfigure slapd' there is no /etc/ldap/slapd.conf?18:53
ahasenackVousDeux: ubuntu uses /etc/ldap/slapd.d by default since jaunty or so18:53
VousDeuxahhh...thanks18:54
VousDeuxvi /etc/ldap/slapd.d18:54
VousDeuxoops18:54
ahasenackVousDeux: it's a bit more complicated than that18:54
VousDeuxOh for pete's sake.18:56
iarplol18:57
=== dendrobates is now known as dendro-afk
=== dendro-afk is now known as dendrobates
VousDeuxSo, basically, there are no accurate, up-to-date instructions for how to install and configure ldap/samba???18:58
ahasenackthe server guide talks about slapd.d usage18:58
ahasenackdon't know about samba, but since smbldap-tools uses just ldap commands, the config backend doesn't matter18:58
hydrozenHi. I just installed Ubuntu 8.04 LTS on amazon using the latest AMI. I can login as root using the key I generated, but I can't seem to login using any other accounts that I created. It says "Permission denied (publickey)." Any ideas what I need to change? Is it in the SSH configuration?19:03
ilowehydrozen: That's either because you don't have the right key installed on your client, or because the user on the server is not configured to allow logins with that key19:06
ilowehydrozen: you would need to add the key to authorized_keys for each account that should support logins19:06
hydrozenilowe: what would I need to check on the server?19:06
hydrozenilowe: yes I did that. and i checked the permissions they seem fine too.19:06
ilowehydrozen: so those users have a .ssh/authorized_keys? chmod'd to 600?19:07
ilowehydrozen: double check for differences between those users and root (if root is working for you)19:07
ilowehydrozen: and you are logging in as the same user on the client-side, right?19:07
hydrozen-rw------- 1 patrick patrick  668 2009-10-13 17:56 authorized_keys19:08
hydrozenilowe: yes, same username on my mac and on the server19:08
ilowehydrozen: OK, and the authorized_keys file is the same as for root?19:10
hydrozenilowe: naw. For root im using a key that i generated using the amazon tools. For my personal account I generated a key myself using ssh-keygen.19:11
ilowehydrozen: OK, fair enough19:11
ilowehydrozen: hmmm, and this is all out of the box?19:11
hydrozenwait i think i know where i fucked up19:12
hydrozenerr nope still doesnt work19:13
hydrozenilowe: yeah pretty much out of the box... i dont get it19:16
ilowehydrozen: crap, you're two releases behind me so I don't know if it's 8.04-specific; it sounds like you have all your ducks in a row19:17
hydrozenilowe: hehe... I'll figure it out I guess... I'm sure it has to do with the SSH configuration19:17
hydrozenits prolly too secure for my needs19:17
ilowehydrozen: I know I had to fiddle the order of passwords and so on at some point19:18
ilowehydrozen: I mean in the global conf; but I haven't had to do it in a while (and I set up about 3-10 boxen a month)19:18
hydrozenthe AMI might have some particular settings to make it more secure on amazon19:19
VousDeuxGreat...all the install/uninstall stuff with this slapd/samba and now my server won't shutdown again...just keeps coming back to this recovery menu.19:21
uvirtbotNew bug: #450449 in eucalyptus (main) "fix whitespace in eucalyptus update-motd url" [Wishlist,Fix committed] https://launchpad.net/bugs/45044919:22
VousDeuxLast time this happened I had to reinstall the server all over again...I'm getting sick of starting over before I can even really begin.19:24
uvirtbotNew bug: #306369 in autofs (main) "autofs cannot mount remote directory path with space" [Low,Incomplete] https://launchpad.net/bugs/30636919:37
ruben23hi any optimization on ubuntu networks19:47
ruben23or the sever itself19:47
arooniour load right now is 8.72  ... how do we find out WHY this is ?  i.e what specifically is causing a high load... should load always be below 1?19:51
Jaggedarooni: top19:55
Jaggedarooni: you can use < and > to change your sort until you get %cpu or cpu time19:56
arooniis load only based on cpu utializiation?19:56
Jaggedhttp://blog.scoutapp.com/articles/2009/07/31/understanding-load-averages19:58
jdstrandahasenack: re ufw delete> put delete 'before' the rule, not instead of 'allow'. eg: to delete 'ufw allow OpenSSH', use 'ufw delete allow OpenSSH'20:04
ahasenackjdstrand: got it, thanks20:04
jdstrandBilge: re where ufw stores rules> rules added with the 'ufw' cli command are stored in either /var/lib/ufw/*rules or /lib/ufw/*.rules (depending on the version you are using). /etc/ufw/*.rules are for customization. see 'man ufw'20:05
ahasenackjdstrand: is there an ufw command to clear all rules so one can start fresh?20:07
jdstrandahasenack: not at present. there is a wishlist bug on it and it will probably be in the next release of ufw. what version of Ubuntu are you using ufw on?20:08
ahasenackjdstrand: ok, thanks20:08
jdstrandahasenack: what version  of Ubuntu are you using ufw on?20:09
ahasenackjdstrand: oh, all of them :P20:09
ahasenackjdstrand: hardy, intrepid, jaunty, karmic and even dapper if it's available there, didn't check yet20:10
jdstrandahasenack: ok, the easiest thing to do to reset ufw is to do 'sudo ufw disable ; sudo cp /usr/share/ufw/user*.rules /valib/lib/ufw'20:10
jdstrandahasenack: err, /var/lib/ufw20:10
ahasenackok20:10
jdstrandahasenack: if /var/lib/ufw doesn't exist, then put them in /lib/ufw20:11
mushroombluearooni: load is based on cpu percentage required to do tasks, IIRC.20:11
mushroombluearooni: and each number is a duration of time.20:11
jdstrandahasenack: ufw 0.29-1 is the first release to put rules in /lib/ufw (that should be Ubuntu 9.10 only)20:11
uvirtbotNew bug: #449814 in samba (main) "amule" [Undecided,New] https://launchpad.net/bugs/44981420:12
ahasenackso karmic20:12
mushroomblueif your system load is at 8.xx, that means it's doing a ridiculous high load.20:12
Jaggedmushroomblue: it also depends on the number of cores20:12
mushroomblueI suppose.20:12
Jaggeda dual-quad core server should be able to handle a load of 820:12
mushroomblueright. 1.00 == 100% of one CPU20:13
mushroombluethanks.20:13
mushroombluearooni: running something big that's constantly spanking your CPU?20:14
Bilgejdstrand: thanks! I am including them in my backup script now20:22
uvirtbotNew bug: #436977 in eucalyptus "euca_rootwrap makes eucalyptus user equivalent to root" [Undecided,Confirmed] https://launchpad.net/bugs/43697720:22
uvirtbotNew bug: #445105 in eucalyptus (main) "uses unsafe /tmp files" [High,Triaged] https://launchpad.net/bugs/44510520:22
uvirtbotNew bug: #318495 in autofs (main) "Patches for documentation" [Wishlist,Incomplete] https://launchpad.net/bugs/31849520:33
=== dendrobates is now known as dendro-afk
=== MenZa_ is now known as MenZa
uvirtbotNew bug: #317400 in openldap2.3 (main) "TLSCACertificateFile ignored" [Low,Incomplete] https://launchpad.net/bugs/31740021:27
VousDeuxIt doesn't seem to matter how many different ways I try, the smbldap-populate fails.21:37
VousDeuxIt tells me 'modifications require authentication' and it looks like it is trying to authenticate as root. I tried using smbldap-populate -a admin, but I get the same errors.21:38
VousDeuxOn google I found where some others were seeing this, but the solution seems to be to modify the smb.conf, but this file doesn't exist and I dont know where it's supposed to be or what's supposed to be in it.21:40
VousDeuxAbout the only thing I can think of that I have not tried is installing slapd and leaving the admin password blank.21:41
VousDeuxI don't even know where smbldap-populate is getting the password from that it is trying to use, and I see no way to specify a password to be used for the modifications.21:43
=== dendro-afk is now known as dendrobates
VousDeuxWhat am I missing...it's no fun to sit here for 12 hours and try to find an answer to why something in a tutorial didn't work...where should I be looking?22:01
geniiVousDeux: Have you consulted the main server guide?22:03
VousDeuxYes, that's the tutorial that's not working.22:03
mushroombluehah. main server guide.22:03
bogeyd6vous your directory/file permissions are not correct for this database22:04
bogeyd6VousDeux make sure that the database22:04
bogeyd6directory and all files it contains are writable by22:04
bogeyd6slapd22:04
VousDeuxI don't know where the database directory is.22:04
bogeyd6VousDeux /var/lib/ldap22:07
VousDeuxCan you tell me how you found that?22:07
bogeyd6ill do you one better22:09
bogeyd6VousDeux https://help.ubuntu.com/8.10/serverguide/C/openldap-server.html22:09
bogeyd6if you are using 9.04 for a server, shame on you :(22:09
VousDeuxOh, really????22:09
VousDeuxDo tell, please.22:09
VousDeuxWhat should I be using?22:10
bogeyd6Ubuntu 8.04.3 LTS22:11
uvirtbotNew bug: #450501 in apache2 (main) "ab crashed with SIGSEGV in main()" [Undecided,New] https://launchpad.net/bugs/45050122:11
bogeyd6VousDeux and i meant, https://help.ubuntu.com/8.04/serverguide/C/openldap-server.html22:11
bogeyd6copy and paste was broked22:11
VousDeuxOkay, I thought I downloaded the current, stable release.22:12
bogeyd69.04 is current and stable22:13
bogeyd6but by the time you are settling in, support will end for it22:13
VousDeuxWhat is LTS?22:13
bogeyd6VousDeux https://wiki.ubuntu.com/LTS specifically With the Long Term Support (LTS) version you get 3 years support on the desktop, and 5 years on the server.22:13
bogeyd6so they will release updates for 8.04 for 5 years22:14
VousDeuxOkay...much for me to learn...I would have thought the newest version would have the best support.22:15
bogeyd6easy to misunderstand22:16
bitprophetremind me again, how long are the non LTS releases supported for? A year? Or only the ~6 months till the next release?22:19
bitprophetjust an academic question, of course, I've been using 8.04 since it came out =)22:19
mushroombluebah. 9.04 is fine if most of your enterprise is virtualized.22:20
bitprophetwhat's virtualization got to do with it?22:21
mushroombluemakes upgrading trivial.22:21
bitprophetnot everyone has the time to constantly upgrade, nor to deal with breakage from setting up an OS that you haven't verified works for your apps or situation22:21
mushroomblueoh.22:22
mushroomblueI bill by the hour.22:22
mushroomblue:)22:22
bitprophetHa22:22
bitprophetHow does virtualizing make upgrading trivial, just the abiltiy to snapshot/clone/rollback? or is there some other angle I'm missing22:23
mushroombluecloning and rolling back is enough.22:24
mushroombluebut I can clone the entire network.22:24
mushroombluemake changes, test, etc.22:24
mushroomblueit's made testing new updates trivial.22:25
slibuntuhello all, inexperienced admin here, wondering what is a good policy for permissions on users home folders?22:26
=== slampoud_ is now known as slampoud
=== dendrobates is now known as dendro-afk
=== dendro-afk is now known as dendrobates
maakueucalyptus devs: my node install fails to detect the cluster on the local network, giving an error code that seems to indicate it was pulling the preseed file from a self-assigned ip address.  would like to file a bug report, but not sure which information is relevant22:34
maakuforgot the mention: 9.10 beta UEC install22:34
maakuand both node and cluster/cloud controller are manually assigned static IPs, no DHCP server exists on the network22:35
bogeyd6bitprophet 18 months22:37
bogeyd6!permissions22:38
ubottuAn explanation of what file permissions are and how they can be manipulated can be found at https://help.ubuntu.com/community/FilePermissions22:39
bogeyd6!home22:39
ubottuYour home directory is where all of your personal files are usually kept. For moving your home directory to a separate partition, please see: http://psychocats.net/ubuntu/separatehome22:39
blistovAnyone know of a way to force a directory to force its subdirectories to inherit its permissions?  IE: like setgid/setuid, but for say... 775?22:56
bitprophetblistov: afaik only ACLs can do that22:58
bitprophetbut I'm not an expert in that particular area22:58
blistovbitprophet: I expect you are correct, but I've been told there may be a way.22:59
bitprophetI know ACLS _can_ do it, for sure. just don't know if there's a non ACL method like sticky bit or whatever22:59
blistovsticky bit is what I'm investigating now.22:59
bitprophetI think that's largely for executing, though. can't recall.22:59
bitprophetalso, umask, but only if you can control all your users and trust them not to override their own umasks23:00
blistovRight. But I can't trust them. And incidentally  "the Linux kernel ignores the sticky bit on files." according to chmod man23:00
bitprophetinteresting.23:02
=== dendrobates is now known as dendro-afk
captainkirkhi folks.  I need advice on how to track down a memory leaking program on my 9.04 32bit system23:54

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!