/srv/irclogs.ubuntu.com/2009/11/10/#ubuntu-server.txt

qman__erichammond, yeah, what you're looking for is a replacement for active directory00:01
qman__samba 4 is designed to help with this, but samba 3 is a bit tougher00:01
qman__it basically requires ldap and a specific kerberos implementation00:02
qman__I've yet to actually get it to work, myself, but I've seen it done00:03
RoAkSoAxI've tested samba4 and created and AD Server, created users, groups, used windows tools to manage the AD and was able to log in computers to the AD00:06
qman__nice00:07
qman__good to know samba 4 is making progress00:07
fxhpqman__, I think that the user in need of that information has already left the chat.00:08
RoAkSoAxqman__, it was pretty impressive!!00:08
=== dendrobates is now known as dendro-afk
fxhpwhat would cause my jeos VM's built with vmbuilder to not have their harddrives linked in the config (xml)  I have to manually attach them using virsh edit00:09
erichammondqman__: Thanks. If you solve it, consider documenting the steps in a howto.  At this point, I think I can admit that my Windows foo is insufficient to tackle it alone.00:15
eqx311ok, so help me with this dissision. I need run bunch of virtuals on older xeon hardware without vmx00:15
eqx311what should I use to make it running00:15
eqx311I just spend 4 days of compiling and compiling of kernel 2.6.31.5 + xen 3.4.2-rc2 and I can not make that xen running :)00:17
micahgis there an issue with software raid and 2.6.31?00:33
StrangeCharmi seems to have made an arror writing my fstab, and have to manually mount my volumes. what's the correct way to mount volumes in an lvm on an encrypted volume?00:45
StrangeCharmhow do you mount an lvm stored on an encrypted volume?00:52
=== dendro-afk is now known as dendrobates
micahg1is there an issue with software raid and 2.6.31?01:25
=== micahg1 is now known as micahg
goosedoes anybody know why "mkdir ~/public_html" doesn't create a folder any longer at http://domain.org/~chris/ for me? :/01:31
fxhpgoose, It still works for me01:33
fxhpmkdir ~/asdf01:33
goose?01:34
goosefxhp: you want me to make a dir named "asdf" in my home folder?01:34
fxhpNo01:35
fxhpI was expressing that the syntax still creates a folder01:35
gooseah :p yes, the folder is created01:35
fxhpyour question was pretty ambiguous.01:35
goosebut it's no longer shown at http://domain.org/~chris/01:35
gooseis what I meant01:35
fxhpwhat do you use as a web server?01:36
fxhpapache?01:36
gooseyes01:36
fxhplighTPD?01:36
gooseapache201:36
fxhpDoes apache point at your home dir?01:36
gooseit does by default, iirc? I'll double check, though01:36
micahgis there an issue with software raid and 2.6.31?01:37
fxhpsoftware raid and the new kernal?01:38
fxhpkernel *01:38
goosedon't see anything off in my /etc/apache2/apache.conf, and my httpd.conf is blank :S01:39
fxhpblank...?01:41
fxhpDid youedit with sudo?01:42
gooseyeah... absolutely nothing in it01:42
micahgfxhp: yes01:42
micahgit wouldn't boot01:42
micahgcan't find /dev/md001:42
micahgI have a boot partition01:42
fxhpmicahg: did this happen after an upgrade?01:42
micahgyes, I upgraded from jaunty -> karmic01:43
fxhpeek01:43
micahgI got rid of the UUIDs and it didn't help01:43
micahgluckily I still had my old 2.6.28 kernel01:43
goosefxhp: the module to enable that dir to be transferred to HTTP wasn't enabled. fixed now.01:43
fxhpgoose: good to hear.01:44
fxhpmicahg, so that raid array still exists but grub is unable to load it?01:44
micahgyes01:44
micahgwell, it's not grub01:44
micahgit drops me into busybox01:45
fxhpmicahg, can you see the array in busybox?01:45
fxhpsee the files?01:45
micahgno, it can't find the array01:45
fxhpI don't know...01:46
fxhpI was planning on setting up raid5 on 5 drives.01:47
fxhpNever got around to it01:47
JerVAI know this is not support related channel01:51
JerVABut I have user that is having NIS related issue with server with 10+ clients01:51
micahgJerVA: this is a support channel for servers :)01:51
JerVAHi there again micahg01:51
* micahg is not usually in here01:51
JerVAShould I refer this user to this channel?01:51
JerVAI think this may be server related issue01:52
micahgif it's on the server side, yeah01:52
JerVAOk I'll refer this user01:52
micahgchannel seems quiet right now though01:52
JerVAHello thieusoai01:53
thieusoaihi01:53
JerVAmicahg - this is thieusoai that needs assistance with NIS related issue I mentioned01:53
thieusoaiI have problem with NIS ---  all my clients machine (which authenticates login etc via NIS) cannot open any network related apps (e.g., pidgin, xchat, firefox).01:53
thieusoaiif I log in a local account , then everything is fine.01:54
* micahg doesn't know about NIS unfortunately01:54
micahgmaybe someone else does01:54
tonyyarussoI set it up once, but I don't pretend to understand it.01:54
thieusoaiThe server runs Ubuntu-8.04 Server .   The clients run various OS including Debian / Ubuntu Hardy, Karmic, Jaunty, etc  _all_ face the same problems01:55
thieusoaiyeh -- been working on this for almost 10 hrs01:55
thieusoaiso frustrated :(01:55
JerVADid you try to do the server reset including clients?01:57
thieusoaiyeh I did,  I reboot the server as well as the clients01:57
JerVALike powercycling?01:57
thieusoaiI turn off all the clients,  and server, then start the server01:57
thieusoaiand one client01:57
thieusoaiand test on that client01:58
micahgthieusoai: have you seen this: https://help.ubuntu.com/community/SettingUpNISHowTo01:58
thieusoaiyeh micahg , I did01:59
thieusoaithe weird part is that I was able to log in using NIS just fine  ,01:59
thieusoaiit's just in X01:59
thieusoaiwhen all the network-apps hang01:59
thieusoaibut in tty's ,  everything works (e.g., I can use elinks and such)02:00
nxvlkirkland: around?02:02
thieusoaialso the home directory of user is mounted via nfs02:03
thieusoainot sure if it's related02:03
JerVAyou mean ntfs02:03
thieusoaino, nfs02:03
JerVAok02:03
thieusoaibut I am not sure if it's related02:03
thieusoaibecause I can see all those files just fine02:03
JerVANo updates or anything to do with Update Manager?02:04
thieusoainope, I don't think it is due to updating.   Because we didn't touch the Server at all for quite a long time02:05
thieusoaionly when this problem arises today02:05
thieusoaithen we decided to update it02:05
thieusoaibut it still the same02:05
JerVAMaybe it is hardware-related issue?02:05
JerVARun some network tests ?02:06
thieusoaion the server ?02:06
JerVAwhy not02:06
JerVAsee where in the end is the issue02:06
thieusoaiI am not sure what network test to run  ?02:06
thieusoaiyeh it would be good to localize where the problem is02:06
JerVAhttp://www.linuxhomenetworking.com/wiki/index.php/Quick_HOWTO_:_Ch30_:_Configuring_NIS02:07
JerVAI'm googling what I can :)02:07
JerVAI think this one may help out better02:08
JerVAhttp://www.yolinux.com/TUTORIALS/NIS.html02:08
thieusoaithanks JerVA02:10
JerVAanytime02:10
thieusoaiI'll check them out -- but now I think gotta go dinner and come back02:10
JerVAOkay.02:10
JerVAthanks for helping out micahg02:13
micahgJerVA: sorry I couldn't be more help02:13
JerVAno problem02:14
JerVAI tried what I can02:14
JerVAI'm not an expertise on NIS either02:14
erichammondsmoser, mdz: My first time trying to use euca2ools and I found that to rebundle an image for EC2 I had to install ec2-ami-tools from multiverse anyway just to get the EC2 cert.  Seems like the Karmic AMI is not usable without ec2-ami-tools for rebundling which is the first thing most EC2 tutorials want you to try.02:24
smackdhi all... trying to send mail.. i have installed the postfix-dovecot package... it wont let me send... anyideas i can check on...?03:08
ScottKsmackd: Look in /var/log/mail.log.  It will tell you why03:10
smackdok it says this.. the same relay message what is that03:11
smackdNov  7 18:07:05 76 postfix/smtpd[1534]: NOQUEUE: reject: RCPT from unknown[76.199.50.233]: 554 5.7.1 <matt14213@yahoo.com>: Relay access denied; from=<matt@$03:11
maxagazhi03:17
maxagazon a server, I have : "/dev/sda1  142G  137G     0 100% /" the percentage doesn't look correct03:19
=== genii_ is now known as genii
oh_noesis there a boot screen/splash-screen for hardy?04:53
jmarsdenoh_noes: For Ubuntu server there is no graphical splash screen... there is no GUI :)04:54
oh_noeswell ive used hardy as a base for an appliance i made04:55
oh_noesi was looking into boot screen, preferbly text based04:55
oh_noesbut i wasnt sure what options are available04:55
jmarsdenoh_noes: You are creating appliances that assume a "PC" style VGA screen will be attached at boot time?  Usually appliances can't assume that, can they?04:57
jmarsdenFor example, when you start an instance of the appliance up in the cloud on Amazon EC2, where will the "boot screen" be displayed?04:58
FraxtilHow do I configure GRUB in Ubuntu 9.10 server? It seems there's no /boot/grub/stage105:01
russlarFraxtil: 9.10 uses grub2 on fresh installs05:01
jmarsdenFraxtil: If you did a fresh install it most likely used grub2 instead of grub05:01
russlar!grub205:01
ubottuGRUB2 is the default Ubuntu boot manager in Karmic. For more information and troubleshooting on GRUB2 please refer to https://wiki.ubuntu.com/Grub205:01
Fraxtilokay then05:02
FraxtilHow can I run update-grub, since I can't log in anymore?05:03
Fraxtil*or boot it in the first place05:03
jmarsdenFraxtil: Boot the machine from a CD, perhaps.  Sounds like there is a story behind your apparently simple question "How do I configure GRUB"... how did you break it in the first place?05:06
Fraxtiljmarsden: I thought I could backup everything from an encrypted LVM and put it onto a regular ext3 filesystem, but that changed partition orders and stuff05:12
jmarsdenOK.  Sounds like booting from CD would be a useful way to go (if the system is local to you), then mount your ext3 partition(s), chroot into the real system and use update-grub.05:14
=== robbiew is now known as robbiew_
twbIf grub is working, you can just pick "rescue" to immediately get root05:33
twbIf grub simply can't find the root partition or the kernel, you can also just edit it by hand enough to boot (the "e" key), and then get update-grub working from there.05:35
AliTarihiHi. anyone can help me with OpenFire installation. I'm newbie to server things. I've installed it but I get connection refused on admin console07:03
crohakonI would like to turn off the DHCP client and set my server to a static IP on my LAN. Anyone got a guide that will help me with that?07:17
Boohbahcrohakon: http://www.debianadmin.com/ubuntu-networking-for-basic-and-advanced-users.html07:18
=== FireCrotch is now known as michaeljackson
=== michaeljackson is now known as FireCrotch
crohakonBoohbah, thanks07:22
crohakonHow can I test of my DNS server is using, via the server itself over SSH?07:34
nagumoanyone have experience with kerberized nfs4?07:51
maxagazi have installed a mirror for hardy, jaunty and karmic on a server, and then removed the lines for karmic, but karmic packages are still here, how to clean my mirror ?08:02
crohakonwell, I must say, I think I have noticed in the speed of opening websites using my own DNS server rather then charters...08:08
crohakonnoticed an increase*08:08
KurtKrautcrohakon, are you also caching the DNS queries?08:09
crohakonHow do I check? I am just now setting this all up and testing.08:10
KurtKrautcrohakon, what software you're using to have your own DNS server?08:11
crohakonbind9?08:12
KurtKrautcrohakon, it does not cache queries by default. I recommend you to search for how to do that on Google.08:12
crohakonWhat is the benefit?08:12
KurtKrautcrohakon, I'd like also to request your vote on this: http://brainstorm.ubuntu.com/idea/20842/08:12
crohakonWhat is the benefit of enabling caching?08:14
KurtKrautcrohakon, to be short: much, much, much faster internet browsing.08:16
crohakonyou got my votes.08:19
KurtKrautcrohakon, thanks08:21
crohakonAll that is required is simply adding the IP numbers of your ISP's DNS servers. <--- To enable caching I need to use the IP of my ISP's DNS servers why?08:21
qman__crohakon, you don't need caching08:22
qman__you're running your own server with root hints08:22
qman__caching is if you want to cache from your ISP's DNS08:22
qman__it's a completely different setup08:23
KurtKrautcrohakon, no you don't. But using your ISP DNS and them caching its results are also an improvement of performance.08:23
KurtKrautqman__, saying 'you don't need caching' is like 'you don't need to use seat belts on cars'08:23
qman__both accomplish the same goal08:23
KurtKraut:D08:23
qman__he doesn't need a caching server, because he has a server that uses root hints08:23
qman__instead of his ISP's DNS08:23
crohakonYes, I am trying to avoid using charters DNS all together.08:24
KurtKrautqman__, even caching for local queries is a performance booster.08:24
crohakonKurtKraut, I believe caching for local queries is enabled by default with bind9... though, I could be wrong.08:25
qman__that's what I thought, too08:25
KurtKrautcrohakon, AFAIK, no. But you can do the test with the command dig. Do a 'dig www.google.com' twice and see how many miliseconds both queries took.08:26
qman__60ms; 0ms08:27
crohakon1ms; 1ms08:27
KurtKrautqman__, crohakon, so it is caching.08:27
qman__I think it caches for like 5 minutes08:27
crohakononly 5 minutes?08:28
KurtKrautqman__, if it does, it is not correct. It should cache until the TTL of the query. Each DNS query tells to the server when it is expected to expire and should be kept until that time.08:28
macnoHi, I need to install samba 3.2 o 3.3 on 8.04 LTS. I checked in backports but aren't there. any suggestions?08:29
qman__I don't know for sure, I was just guessing, because my server is pretty on top of DNS changes08:29
qman__it's more accurate than my ISP's DNS, by a considerable margin08:30
crohakonI kept having issues where I would go to, say, www.ubuntu.com and it would not resolve. I would wait a minute, try again, and it would work... with charter. I was hoping running my own DNS server would make that less likely.08:32
qman__it will08:33
KurtKrautcrohakon, have you tried OpenDNS.com?08:33
qman__openDNS is alright, but not as fast as running your own server08:34
KurtKrautqman__, OpenDNS + local cache is as good as querying directly to root servers.08:34
sorensmoser: Done.08:34
crohakonKurtKraut, now that this is working and I can notice the improvement I think I am just going to stick with it. I already had the box running as a LAMP server using dyndns.com... so it it running when ever I have power anyway.08:35
ttxsoren: o/08:45
ttxsoren: haven't seen any blueprints from you yet...08:46
sorenttx: No, sorry about that. Last night didn't work out as planned :(08:49
ttxsoren: ok, please do it today then ;)08:49
ttxsoren: put yourself as assignee +drafter if you intend to do it, only as drafter if you want to lead the discussion about it, or leave blank if you don't really want to lead it or do it.08:50
sorenttx: Sounds easy enough.08:55
ttxsoren: doesn't mean you won't end up doing it, just that it's open :)08:56
sorenGah.08:56
=== gamla_ko1san is now known as gamla_kossan
sorenttx: What's the naming scheme for specs this time?10:10
ttxserver-lucid-*10:10
ttxthough it doesn't really help in getting their list, given how blueprint search "works"10:11
twbHaha, lucid name clash gets me again10:14
twbI was trying to work out when Lucid became a font foundry.10:15
twb(Lucid Inc, that is.)10:18
=== pipedrea1 is now known as pipedream
=== dendrobates is now known as dendro-afk
sorenttx: Who should I be defaulting to for approver? You? mdz?11:17
sorenMyself (if I'm not the drafter, of course)?11:18
ttxttx: mdz11:18
ttxsoren: mdz11:18
sorenttx: Got it, thanks.11:21
sorenttx: I'm not sure how to file the "automated testing" spec thing. It's vast and I doubt it will fit in a single session.12:26
sorenttx: Also, I'm not sure it makes sense to split it into e.g. "mail", "web", "databases", etc.12:27
sorenttx: Can we schedule a session on Monday, where we essentially schedule the next 3-4 sessions on the subject and reserve timeslots for those now?12:27
sorenI have a hunch that people more familiar with automated testing will have a better idea about how to split up this discussion.12:28
ttxsoren: i'll talk about it to mdz12:28
sorenThe first session may be about what we want to test... Another one could be about how, when, and where..12:29
sorenI don't know, really.12:29
sorenIt's rather new to me, to be honest.12:29
sorenI just know I want to do a lot of it for this cycle.12:29
ttxsoren: I think we should have a formal session about Automated testing to discuss the targets and methods, then several ad-hoc discussions on specific targets12:30
ttxHaving a blueprint on "automated tseting" will allow to schedule the first one12:31
sorenttx: Oh, right, you said there'd be plenty of open slots, right?12:31
sorenI forget about that for a minute.12:31
ttxand having it scvhedule relatively early will allow for several breakout sessions on the subject during the week12:31
sorenRight, exactly.12:31
ttxsoren: There should be open slots, yes12:31
sorenttx: Are you doing any of the scheduling or is it all mdz?12:31
ttxsoren: it's all mdz12:31
zulmorning12:39
python_rootnight12:39
sorenafternoon12:40
python_rootThis makes a complete MAN morning afternoon night12:41
alvinIs installation of ubuntu-server from USB stick officialy supported?12:50
ttxzul: do you plan to file a blueprint on calendaring ?12:51
sorenalvin: sure.12:53
sorenttx: I have an old spec: https://blueprints.edge.launchpad.net/ubuntu/+spec/server-karmic-virtual-appliance  I'd like to just start a new one on virtual appliances for lucid. What state should I put the old one (so that it doesn't show up in the usual lists)?12:55
ttxYou should make the new oe supersede the old one12:55
sorenttx: Clever.12:56
ttx(go to the old one, select mark superseded, then type really fast to select)12:56
=== sleeping`dragon is now known as error404notfound
alvinsoren: good, in that case I have found a bug (I think). This weekend, I installed an Atom 330 server with 4 disks. Ubuntu is installed FROM usb stick ON another USB stick. The stick containing the installer is /dev/sde and the target device is /dev/sdf. After the successful installation, I unplug the installation stick. Now, the root drive is the other stick and it becomes /dev/sde.... dun, dun, duuuun,... No boot.13:01
alvinI changed the value in /boot/grub/grub.conf and /etc/fstab, because they where both wrong.13:01
alvinShouldn't they both use UUID by default, (fstab and grub)13:02
=== ogra_ is now known as ogra
sorenalvin: Ah. You never said anything about installing /to/ a USB stick :) I'm not sure that's supported.13:11
sorenalvin: but yes, I would have thought everything would use UUID's.13:11
sorenalvin: which version of Ubunt uis this?13:11
alvinsoren: Well, true :-) (but it is handy if you want those 4 drives to work in RAID and have only 4 SATA connections)13:11
alvinsoren: karmic13:11
alvinsoren: On  EVERY new karmic installation of ubuntu-server I noticed UUID's are no longer used!13:12
alvinI did about 10 of those fresh installations. No UUID in sight. Not in grub and not in fstab13:13
sorenalvin: All of them from USB?13:14
alvinNo, only 1. The rest are normal disks.13:14
soren"from".13:14
sorenNot "to".13:14
alvinFrom cd, to sata or sas13:14
sorenOk.13:14
sorenThe server CD, I presume?13:14
alvinyes, the default one13:15
alvinoh, and also the kubuntu (alternate) cd13:15
alvinI thought it must have been a new policy. Upgraded installations still use UUID13:16
sorenUpgrades don't make changes to fstab.13:16
sorenUsually.13:16
sorenalvin: Are you using lvm?13:16
alvinsoren: Yes, but I always use a separate non-lvm /boot13:17
sorencjwatson: Oh, you're in here as well... Saves me the trouble of repeating everything to you :)13:18
cjwatsonas I said on #ubuntu-installer, the installer hasn't changed in this regard13:18
alvinIt hasn't?13:19
cjwatsonwell, let's say no intentional change13:19
cjwatsonwe've never used UUIDs for LVM, but continue to do so elsewhere, to the best of my knowledge13:19
alvinI did a fresh install today and this is in the /etc/fstab of that server:13:19
alvin/dev/cciss/c0d0p1       /boot           ext2    defaults                        0       213:19
cjwatsonplease post your fstab somewhere13:19
cjwatsoncciss I'm not sure about, although aren't those controller numbers stable?13:20
cjwatsonI wouldn't mind a quick look through /var/log/installer/syslog13:20
alvinCould very well be. It's only one server that uses it here. I'll find some other fresh installations.13:21
alvinlet me see13:21
cjwatsonthe code involved contains no special-casing of cciss, though13:21
ca2satip a13:29
zulttx: https://bugzilla.samba.org/show_bug.cgi?id=688013:33
uvirtbotbugzilla.samba.org bug 6880 in libsmbclient "cannot list workgroup servers" [Major,Resolved: fixed]13:33
alvin/var/log/installer/syslog of a server, using cciss: http://paste.ubuntu.com/315068/13:36
alvinThis is from the 'usb stick install'. (note that I changed it from /dev/sdf1 to /dev/sde1):13:36
alvin/dev/sde1                       /               ext2    noatime,errors=remount-ro       0       113:36
alvinOther note: I didn't have to change it in order to boot. Only the grub root= had the be adjusted for that! (df showed /dev/sde1, while /dev/sdf1 was the value in /etc/fstab)13:36
alvinI'm now looking at a virtual karmic server, and /boot is UUID there, so it looks like I'm mistaken and I'm seeing this only in the case of cciss and an install on an USB stick. I do have another installation, but I'll check tonight. It can't boot currently, due to bug 46113313:38
uvirtbotLaunchpad bug 461133 in mountall "karmic: nfs shares are not mounted at boot" [Medium,Incomplete] https://launchpad.net/bugs/46113313:38
ttxzul: ew13:40
ttxzul: will it ever end13:40
zulttx: nope unless microsoft kills off windows which im hoping they do next week13:40
ttxzul: good plan13:41
zulttx: im pretty sure we have a bug open about that ;)13:42
zulsoren: i bet you would be glad to know that windows 7 works on kvm ;)13:45
sorenzul: Absolutely thrilled.13:45
sorenI'm beside myself.13:45
=== Ash-Fox_ is now known as Ash-Fox
uvirtbotNew bug: #468771 in php5 (main) "php5 crashed with SIGSEGV in _Unwind_ForcedUnwind()" [Medium,New] https://launchpad.net/bugs/46877114:08
alvinWell, I'm sorry for the wrong information. Apparently, UUID's are still used (except on cciss and unsupported USB-sticks). It would be nice to introduce it on USB sticks too.14:08
zulwell that made it choke14:08
alvinA related question: what is the official way to change root=/dev/sdX to root=UUID=...  in the new grub?14:09
Jeeves_alvin: Uh, edit /boot/grub/menu.lst?14:09
alvinJeeves: No, I mean in grub214:09
alvinThat file no longer exists and /boot/grub/grub.conf should not be altered manually14:10
sorenjdstrand: Ooh, two-factor authentication!14:12
=== dendro-afk is now known as dendrobates
=== dendrobates is now known as dendro-afk
jdstrandsoren: we all decided you would be both interested and a great asset in the session :)14:15
jdstrandsoren: so I subscribed you14:15
alvinThere is extensive documentation about adding new entries to grub, but there's nothing in there about changing an existing configuration.14:19
zuljdstrand: is that because he has it already?14:20
jdstrandzul: well, I know he's played with a lot of different auth methods, and I thought he did use it currently, yes14:22
ttxsmoser, kirkland: around ?14:24
kirklandttx: yup14:24
smoserhere14:24
ttxkirkland: mdz asked me to make sure the necessary blueprints were filed so that he can bootstrap scheduling14:25
ttxkirkland: are you planning to file one about appliances and one about bugfixes blitzes ?14:25
kirklandttx: wasn't planning on either14:26
ttx(the latter might be known as bugdays/bugweeks and could be discussed with QA)14:26
kirklandttx: i understood soren to own appliances now14:26
ttxsoren, kirkland: we need at least one session on the subject14:27
alvinAnother thing about the usb stick installation. blkid does not report /dev/sde. The drive is mounted, but I can not see the UUID. (it may not be supported, but I'm mentioning it anyway. I'm quite happy with the solution of installing Ubuntu on a stick to create a simple NAS. It's at least 3x faster than FreeNAS.)14:27
ttxFiling the blueprint doesn't mean you have to set yourself as drafter/assignee14:27
sorenttx: I'm filing one on appliances.14:28
ttxsoren: cool, thx14:28
smoserttx, i'm mostly in order, i wanted to go ahead and fill out 2 more blueprints regarding OVF, though.14:29
sorenttx: (That was the one where I wanted to mark the old one superseded a couple of hours ago.)14:29
smoseri'll start that now.14:29
sorenjdstrand: Sounds great.14:29
ttxsmoser: are you the one that suggested working on ec2-/euca- tools  compatibility on the IdeaPool ?14:32
smoseri dont know. if not i'll add quickly.14:32
smoseractually i think i did ad dthat last night.14:32
smoserunless i forgot to hit save14:33
smoserhold on14:33
smoseryeah, its there, ttx, search for bug 43514014:33
uvirtbotLaunchpad bug 435140 in euca2ools "euca2ools should provide ec2-* symlinks/alternatives" [Wishlist,Confirmed] https://launchpad.net/bugs/43514014:33
smoseroh. sorry,k i completely missed your question. yes, i added that last night.14:33
smoseri just added my name to it14:34
ttxsmoser: I'm not sure it warrants a blueprint by itself14:35
ttxbut I can't find anything to include it into14:35
smoseryeah, that was mainly  my reason for putting it there and not making a blueprint :)14:36
ttxsmoser: file it, because if we end up doing it, we'll be glad to have a blueprint -- we need a testing plan14:38
smoserttx, ok. blue print in the works.14:39
TeTeTsoren: Hi, I get an error when running 'vmbuilder xen ubuntu' on karmic - Soemthing is wrong, no valid xen kernel for the suite jaunty found by rmadison. Any ways to get around this?14:40
TeTeTsoren: think I figured it out - does not work behind a proxy by default14:42
sorenTeTeT: Ah.14:43
TeTeTsoren: setting http_proxy and all is good :) Was just confused by the error message14:45
sorenYeah, it's rather opaque.14:45
aubreWhere do I put an official SSL certificate for use with Eucalyptus (UEC) ?14:47
=== robbiew_ is now known as robbiew
\shanyone who was doing lately an dist-upgrade from jaunty to karmic server and having no network after that?14:49
soren\sh: Using bonding or bridging?14:50
\sh(without do-release-upgrade)14:50
\shsoren, yepp14:50
\shbonding + vlan14:50
sorenAdd a sleep 20 to /etc/init/networking before "ifup -a".14:51
sorenand..14:51
sorenErr...14:51
sorenSomething clever in rc2 to make sure it waits for lo.14:51
\shsoren, do we have a bug for that?14:52
soren\sh: I don't know. I kind of gave up on the issue after arguing for two hours whether it was even a regression.14:53
Carroarmato0My server keeps restarting sshd about 2-3 minutes after a connection, afterwards it's not available on the network anymore15:01
Carroarmato0It's a fresh install of 9.1015:01
zulCarroarmato0: are you using dhcp?15:01
Carroarmato0yes15:02
ttxsmoser: maybe extend the xc2 one15:02
Carroarmato0the server get's a static op from the routers dhcp15:02
zulCarroarmato0: try using a static connection15:02
Carroarmato0zul, I'll try15:02
zulttx: ^^^ thats another thing to fix for lucid15:02
ttxsmoser: rewording server-lucid-xc2 so that it includes both topics sounds good to me15:02
smoserttx, the reason i didn't put that there...15:03
aubreI'm trying to test landscape cloud management with UEC, I got a real certificate for my front-end, where do I put it and how do I get the front page to use it?15:03
smoseris that we definitely *could* just add another layer of indirection and fix the compatibility there.  however, i would think that for many things, euca2ools needs to be fixed.15:04
smoserie, i think there is one argumetn i ran into recently where euca2ools only takes '-K' not '--key' or something... stuff like that, you could work around in 'xc2' but would be better done in euca2ools15:04
Carroarmato0zul, also something I've noticed is that whenever that problem occures, the server behaves as if it were frozen (not shutingdown when pressing the power button)15:04
ttxsmoser: I think its part of the same discussion15:04
ttxsmoser: its an and/or15:05
smoserwell.. i dotn know. but i'm ok with adding it to the xc2 blueprint.15:05
zulCarroarmato0: the reason probably why its restarting every 2-3 minutes is that your dhcp lease time is pretty short and there is a hook to restart network services when dhcp queries a new ip address you should be fine with a static IP address15:06
ttxsmoser: gives more chance that both subjects will be discussed15:06
ttxsmoser: ... I think15:06
smoserwell, done15:06
Carroarmato0zul, I never had that issue before with the previous release, might the dhcp default settings have been changed with the latest one?15:06
zulCarroarmato0: maybe I cant say for sure15:07
aubrewhat is the actual software within UEC that runs on port 8443?15:07
soren\sh: Sorry, I want to help, but I can't. See #ubuntu-devel, if you're in the mood.15:07
Carroarmato0zul, thx I'll report back when I'm confident the problem doesn't happen anymore15:07
zulCarroarmato0: thanks15:07
* soren goes to pick up daughter at day care.15:08
aubrelooks like I'll be writing some more documentation when I figure this out15:08
\shsoren, I'll try to get a solution there...because it's really a nasty thing15:09
=== jfluhmann_ is now known as jfluhmann
uvirtbotNew bug: #480048 in eucalyptus (main) "euca-register fails with syntax error" [Undecided,New] https://launchpad.net/bugs/48004815:12
Carroarmato0zul, It seems like the server droped off the net again15:16
zulCarroarmato0: oh well that sucks15:16
Carroarmato0zul, I've set the static address in and did a  /etc/init.d/networking restart15:17
zulCarroarmato0: changing the ip is something you want to do at the console anyways15:17
Carroarmato0zul, oow I have leaned a lot from changing ip's on a remote connection ;)15:17
Carroarmato0zul, It's all about preparation and scripting against worse case scenarios :D15:18
Carroarmato0but I'll hook the server to a screen15:18
Carroarmato0zul, some other weirnesse's that happen when the server gets knocked off the net, keyboard doesn't respond anymore15:20
_rubensounds more like crash to me than15:22
_rubens/than/then15:22
soren\sh: Yes, it is. I spent a lot of time trying to explain this, but the answer was simply "it was racy before, too".15:22
uvirtbotNew bug: #479990 in mysql-dfsg-5.1 (main) "Causes MySQL to get "temp file operation failed" errors" [Undecided,Incomplete] https://launchpad.net/bugs/47999015:23
zullamont: ping15:28
\shsoren, there needs to be a sane solution...if not, udev + whatever magic we are doing today is nothing for a server linux ;)15:29
\shwhile the releases before karmic it worked (luck or not)15:30
soren\sh: We know what the solution is. It just hasn't been implemented yet.15:30
\shsoren, where would you place the call to if-up if not /etc/init/networking.conf ? I'll can test and confirm or say it doesn't work out15:31
sorenI would probably change network-interface.conf to call "ifup -a" instead of whatever it does now.15:32
\shwell..15:35
* soren /really/ goes to pick up daughter at day care15:37
Carroarmato0zul, I think it was a combination of short dhcp lease time and openVPN causing some havok with bridging that gave all those problems15:41
zulCarroarmato0: ah good15:41
Carroarmato0I'm going to try loging out of the server and using it as usual incase it's being sneaky and stop working again after I logout of the console15:42
Carroarmato0zul, everything seems to work fine, thanks for your help :)16:04
zulCarroarmato0: no probs16:04
acalvohi16:13
acalvodoes anyone uses openldap monitor capability=?16:13
TeTeTttx: hi, any chance to get the euca2ools backported to Ubuntu 8.04?16:14
ttxTeTeT: I have no clue. Not sure how many build-deps are missing16:17
ttxTeTeT: ... and can't look into it right now16:17
TeTeTttx: ok, any chance to have a look before end of november? I need to know if I need to install ec2 tools on the virtual servers for training, or wait for euca2ools to appear in a PPA or so.16:18
ttxTeTeT: oh sure!16:19
ttxsoren: any hint on how difficult that would be ? ^16:20
eradicushi I'm using ubuntu 9.04 is there a way to install ubuntu-server packages?16:26
azteecheradicus: just use apt-get from a terminal, and install which ever server package you want to. Or you can use synaptic package manager to select the packages you want installed.16:30
bogeyd6eradicus the server is the 9.04 desktop without the desktop :)))) you can use apt to manage the software and install any server software you like16:39
bogeyd6!server16:40
ubottuUbuntu Server Edition is a release of Ubuntu designed especially for server environments, including a server-specific !kernel and no !GUI. The install CD contains many server applications. Current !LTS version is 8.04. For more info see https://help.ubuntu.com/community/ServerFaq/ and https://help.ubuntu.com/8.04/serverguide/C/index.html - Use the #ubuntu-server channel for support16:40
zulttx: can you have a look at  bug #472785?16:40
uvirtbotLaunchpad bug 472785 in eucalyptus "can't register SC" [Undecided,New] https://launchpad.net/bugs/47278516:40
ttxzul: not today, sorry :)16:40
zulttx: at your leisure :)16:41
eradicusbogeyd6, yeah I figured, it was just before there's a single-liner apt-get command for installing the ubuntu server packages on ubuntu desktop, the package name was ubuntu-server I think.16:42
googais there other type of mail servers then MTA:s?16:44
NRVatein 9.x i think it's broken out.. like lamp-server, etc.16:46
uvirtbotNew bug: #475354 in eucalyptus (main) "Hostname not set correctly on UEC cloud due to IP address in local-hostname manifest data" [Medium,Incomplete] https://launchpad.net/bugs/47535416:47
eradicusNRVate, lamp-server is non-existent too, so selecting packages manually is the way to go16:51
aubreNew Documentation - How to Connect UEC to Landscape - https://help.ubuntu.com/community/UEC/Landscape16:52
aubrecomments/criticisms are welcome16:52
aubreis there a way to make stunnel commands persistent across reboots?16:54
aubreor an Ubuntu-standard way?16:55
uvirtbotNew bug: #479493 in gnome-system-tools (main) "NTP services installation crashes" [Undecided,New] https://launchpad.net/bugs/47949316:57
jmarsdenaubre: Configure it in /etc/stunnel/*.conf and it should be started as a daemon at boot time for you, I think.17:01
aubrejmarsden: thanks17:01
jmarsdenaubre: Also /etc/default/stunnel4 (set ENABLED=1 in there)17:03
aubrejmarsden: thanks again17:04
jmarsdenaubre: You're welcome17:05
* soren pauses for dinner17:11
=== robbiew is now known as robbiew_
aubrejmarsden: looks like /etc/default/stunnel4 is ENABLED=1 by default17:34
jmarsdenaubre: Nice.  It wasn't for me on Jaunty.17:35
aubrejmarsden: Updated https://help.ubuntu.com/community/UEC/Landscape with a method that should be persistent across reboots.17:35
jmarsdenaubre: OK.  I'm more familiar with  stunnel than with UEC :)17:35
=== dendro-afk is now known as dendrobates
aubrejmarsden: I'm the other way around lol.17:42
uvirtbotNew bug: #480151 in sysstat (universe) "Package sysstat with Ubuntu Server" [Undecided,New] https://launchpad.net/bugs/48015117:46
uvirtbotNew bug: #480152 in samba (main) "Samba service doesn't start automatically" [Undecided,New] https://launchpad.net/bugs/48015217:46
=== aubre is now known as aubre_afk
kirklandhowdy mathiaz :-)18:01
kirklandmathiaz: ttx was looking for you earlier18:01
kirklandmathiaz: he left about an hour ago18:01
mathiazkirkland: yeah - send an email instead18:01
mathiazkirkland: about blueprints18:01
kirklandmathiaz: right-o18:02
kirklandmathiaz: basically, they're due today18:02
* mathiaz nods18:02
uvirtbotNew bug: #480173 in munin (universe) "Missing dependency for tomcat plugins (libxml-simple-perl)" [Undecided,New] https://launchpad.net/bugs/48017318:26
=== aubre_afk is now known as aubre
=== Carroarmato0_1 is now known as Carroarmato0
mcashi is anyone still using 8.04 server?18:51
mcasi have a strange problem with squid and logrotate18:52
mcasit doesn't work :-(18:53
kane_mcas: since it's an LTS, i'm sure people still do :) what's happening to your squid & logrotate?18:53
mcasi have a logfile of 2gb ... that doesn't sound like daily logrotes18:54
kane_mcas: that depends on your traffic and verbosity. checking the head & tail of that would let you know for sure18:55
mcasok kane_ i check it18:59
sommerwho is the lucid blueprint approver?19:10
=== robbiew_ is now known as robbiew
zulmdz19:12
sommerah, thanks :)19:13
cemcI've configured dspam+postfix according to https://help.ubuntu.com/community/Postfix/Dspam19:40
cemcquestion: what's the real diffenrence in puttin dspam below smtpd_client_restrictions as opposed to smtpd_recipient_restrictions ?19:41
cemcif you have /./, is there really any difference?19:42
jcastrokirkland, your plenary is on thursday, followed by eucalyptus. So thursday is all -server plenaries19:46
kirklandmathiaz: https://bugs.edge.launchpad.net/ubuntu/+source/eucalyptus/+bug/45890419:52
uvirtbotLaunchpad bug 458904 in eucalyptus "When installing a node, euca_find_cluster fails to locate the cluster controller if instances are running" [High,Fix committed]19:52
IcyPolecathiya anyone here familier with KVM for virtualisation?19:52
mathiazkirkland: lp:~ubuntu-core-dev/eucalyptus/ubuntu-karmic/19:53
cemcIcyPolecat: you should try over at #ubuntu-virt19:54
IcyPolecatcemc, did that - no one home19:54
kirklandIcyPolecat: ask your questions19:55
kirklandIcyPolecat: if someone knows the answer, they will respond19:55
IcyPolecatkirkland, thanks19:55
IcyPolecat I have a massive prolem with my KVM host - after 188 days of uptime I finally did some patching, rebooted and now none of the VMs are accessible via network. They're showing as up in virsh but no ping nothing19:55
kirklandUbuntu Server discussion and support | For general (not server specific) support visit #ubuntu | Get involved: https://wiki.ubuntu.com/ServerTeam/GettingInvolved | Guide to asking questions on IRC: http://www.sabi.co.uk/Notes/linuxHelpAsk.html | http://www.catb.org/~esr/faqs/smart-questions.html | Be patient.  Don't ask to ask, just ask. | server guide: http://tinyurl.com/65jzxw | https://wiki.ubuntu.com/ServerTeam19:55
uvirtbotNew bug: #480234 in mysql-dfsg-5.0 (main) "package mysql-server-5.0 (not installed) failed to install/upgrade: subprocess new pre-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/48023419:55
kirklandIcyPolecat: sounds like your bridge configuration might have gotten eaten19:56
IcyPolecatkirkland, how would I verify?19:56
kirklandIcyPolecat: what were you upgrading from and to?19:59
IcyPolecatkirkland - updating packages mostly - load of updates to lib-birt and kernel19:59
kirklandIcyPolecat: what version of ubuntu are we talking about20:00
IcyPolecathost is 8.10 guests are all JEOS 8.0420:01
IcyPolecat64bit host 32 bit guests20:01
kirklandIcyPolecat: it's probably the libvirt update that affected your network configuration20:01
paul__whats the next android phone for t-mobile ?20:03
IcyPolecatkirkland, ok ... any ideas how I can verify / discover the problem?20:04
kirklandIcyPolecat: find out what version you upgraded from and to20:06
IcyPolecatkirkland, how? does apt keep an audit log?20:08
kirklandsmoser: ping20:09
kirklandsmoser: regarding https://bugs.edge.launchpad.net/ubuntu/+source/eucalyptus/+bug/46115620:09
uvirtbotLaunchpad bug 461156 in euca2ools "User data is not parsed correctly by Eucalyptus in some cases" [High,In progress]20:09
kirklandsmoser: ttx indicated that he wanted this fixed in an SRU at a high priority20:10
kirklandsmoser: do you know if he has a proposed fix for this?20:10
kirklandsmoser: b/c I don't know how to solve it right now20:10
kirklandIcyPolecat: yes, dpkg and/or apt keeps logs.  all logs are in /var/log20:10
IcyPolecatkirkland, ok found them - am looking for the relevent log entry now20:12
PleXuSanyone else having issue's with Palimpsest SoftRaid tool ?20:12
smoserkirkland, no. we really need a fix from euc20:14
kirklandsmoser: okay, thanks.20:15
smoseror just to sit down and do it.20:15
smoseri have pinged nurmi and nekro in irc, but never gotten anything back20:16
uvirtbotNew bug: #319656 in nmap (main) "nmap script engine error" [High,In progress] https://launchpad.net/bugs/31965620:27
micahgmy software raid array won't boot in 2.6.31, drops me into busybox20:51
micahgI have the /boot partition on an ext2 drivee20:51
geniimicahg: Did you put the raid driver names in the list of stuff that initramfs is supposed to have available at boot?20:52
micahggenii: is that new for karmic?20:52
geniimicahg: No, it's been the same for a while.20:53
micahggenii:  it boots fine under 2.6.2820:53
micahgeven under karmic20:53
geniimicahg: The 2.6.28 raid driver would be loading from the initrd then, but not on the new kernel unless you specified in the /etc/initramfs-tools/modules    the raid drivers to include for every new kernel you install20:55
micahggenii: why isn't that happening by default20:59
geniimicahg: Possibly because you made your array after you (originally) installed.21:00
ttxmathiaz: yo21:12
mathiazttx: o/21:12
mathiazttx: registering blueprints21:12
ttxlooking...21:13
mathiazttx: "Etckeeper system integration" <- not sure what you mean about that21:14
micahggenii: I made it during install21:14
micahgof jaunty21:14
ttxmathiaz: its more about missing steps before we can integrate etckeeper more generally (like by default)21:15
mathiazttx: ok21:15
ttxmathiaz: for example bug 37638821:15
uvirtbotLaunchpad bug 376388 in etckeeper "~/.bazaar created owned by root (when run under sudo)" [Medium,Confirmed] https://launchpad.net/bugs/37638821:15
mathiazttx: I was thinking about dpkg conffile integration as well21:15
ttxwe can talk about it in the etckeeper/puppet session21:16
mathiazttx: right21:16
mathiazttx: I almost named the blueprint -puppet-etckeeper-dpkg-integration21:17
mathiazttx: that would require someone from fondations team though21:17
mathiazttx: as it requires a dpkg expert :)21:17
ttxmathiaz: right21:18
mathiazttx: "Login experience - for corporate environments" should probably be pushed to the desktop team21:18
mathiazttx: IIRC pitti was on a call about that last spring21:18
ttxmathiaz: we'll have the desktop team at the likewise session at UDS21:19
mathiazttx: ok - so this point can be discussed during the session as well21:19
majukHey guys. I just got my Ubuntu box set up as a Windows PDC. After I ran the command "net groupmap list" via SSH, I lost all login capabilities to the box under normal operation. Recovery booting works, but smbd is unable to start and keeps reporting that it is re-reading smb.conf21:21
majukIf anyone can save me from re-rolling out this box, I will love you forever.21:21
cemcI don't have any apparmor in /etc/rcX.d, still it starts up. how can I disable it for good? (karmic)21:27
=== robbiew is now known as robbiew_
mathiazttx: anything else to discuss?21:30
ScottKcemc: You really should fix the broken profile and not disable it.21:30
mathiazttx: I'm about to jet out for lunch21:30
ttxmathiaz: no, sounds good21:31
mathiazttx: hold on21:31
mathiazttx: this is dustin21:31
mathiazttx: i just shut my laptop down21:31
mathiazttx: so i uploaded another eucalyptus to -proposed, fixing your avahi-daemon.conf issue21:31
mathiazttx: i didn't see any obvious, easy fix for the userdata one, though21:32
ttxmathiaz: you sound texan21:32
mathiazttx: so i uploaded what i had21:32
mathiazttx: okay, kirkland -> is done21:32
ttxmathiaz/kirkland: ok will test tomorrow21:32
mathiazttx: cool - have a nice evening21:33
majukI only get "Ubuntu v9.0.4 tlpserv tty1" and another log in prompt when attempting to log in. The box and its services are running, I am able to access the Apache served pages without issue.21:33
mathiazttx: sea ya!21:33
majukRemote sessions are terminated as soon as they're established...21:34
cemcScottK: it just pissed me off, spent an hour trying to figure out why some kvm guest didn't want to start up :)21:34
jdstrandcemc: add apparmor=0 to the kernel command line or remove the apparmor package. that said, if you are having a problem with a specific profile, you might consider disabling only the problematic profile instead of all of apparmor (there is quite a bit protected these days)21:34
jdstrandcemc: if you are having problems with the libvirt profile, please file a bug against the libvirt package21:35
cemcjdstrand: found apparmor=0. is that also valid for desktops? apparmor on desktops I mean.21:36
cemcjdstrand: I will, as long as I'm messing with it :)21:36
jdstrandcemc: you can disable the apparmor driver for libvirt only. see /usr/share/doc/libvirt-bin/README.Debian21:36
jdstrandcemc: but yes, apparmor=0 for any Ubuntu kernel21:37
jdstrandagain, that is not recommended21:37
cemcI ment using apparmor in general on desktops21:37
jdstrandcemc: a lot is protected by apparmor on the desktop21:38
jdstrandcups, guest-session, evince, dhclient21:38
jdstrandpossibly firefox-3.5 is you enabled it21:38
jdstrandsudo aa-status21:38
jdstrand^ that will show what is being protected21:38
uvirtbotjdstrand: Error: "that" is not a valid command.21:38
jdstrand ^ that will show what is being protected21:39
* ttx disappears21:42
cemcfunky stuff21:42
cemcwith libvirt apparmor profiles21:42
cemcooooh, I think I got it now21:42
jdstrandall the kvm processes run as root when using qemu://system21:42
cemcholy cr*p.... yeah21:42
jdstrandit was imperative that they be confined21:43
cemcI'm using whatever.ovl as a disk in the xml, there's a reference to it21:43
cemcbut ovl is just an overlay to something else,21:43
cemcwhich doesn't appear in the xml file,21:43
cemcso it's not added to the profile21:43
cemcso apparmor doesn't know about it,21:43
cemcand it doesn't allow it to be opened21:43
jdstrandthat sounds like a known bug21:43
* jdstrand goes to find it...21:43
cemcmyeah, it's all in the syslog, one just has to know how to read it and what to look for21:44
jdstrandcemc: are you using a backing store with libvirt storage pools? or just created a pristine image with the snapshot/overlay listed as the disk file?21:45
IcyPolecatkirkland, you still online?21:45
cemcjdstrand: just used kvm-img create21:46
cemcno pools21:46
jdstrandcemc: yeah, that is bug #47063621:46
uvirtbotLaunchpad bug 470636 in libvirt "AppArmor security driver does not support backingstore" [Medium,Triaged] https://launchpad.net/bugs/47063621:46
jdstrandcemc: well, the title doesn't reflect that, but you are hitting the same problem the reporter is21:46
jdstrandcemc: the problem is that the pristine file isn't known to libvirt at all21:47
cemcyes, I got that now21:47
cemcit does complain about it in syslog21:47
cemcI just didn't realize21:48
jdstrandcemc: I can't fix that, but I will fix the driver so that users can use a <backingstore> (which lets libvirt know about it)21:48
jdstrandcemc: backinstore doesn't work atm either21:48
jdstrandcemc: but, it is easy to work around-- just edit /etc/apparmor.d/libvirt/libvirt-<uuid>21:48
cemcI'm fairly new to kvm too, I don't really know about that21:48
cemcjdstrand: mhm, now that I know what the problem is, I should be able to fix it21:49
cemchm, thanks a lot21:49
jdstrandcemc: I suggest subscribing to the bug. I'll likely put a test case in there that will show how to do all the backingstore stuff21:49
cemcdone21:49
jdstrandcemc: but I won't be fixing that bug super soon-- definitely for lucid though21:49
cemcjdstrand: no problem, I'll do testing when needed21:51
jdstrandcemc: excellent. sorry you hit this issue. I'll appreciate the testing21:51
jdstranddepending on the changes, I may SRU it21:52
cemccool21:52
jdstrandI need to write the patch, and I need to decide the best way to rework the xml given to virt-aa-helper (since the <backingstore> is represented in the machine definition21:53
jdstrands/is/isn't/21:53
jdstrandanyhoo-- I'll fix it21:53
cemccould you just do a 'kvm-img info' -like thing on the images present in the xml and read out all the backing file paths? or that's what you mean?21:54
jdstrandcemc: yes, I could but this would allow an avenue for the attacker to escape the VM, or at least overwrite arbitrary files on the host. If the VM is compromised, the attacker has write access to the disk file, which could be modified to point to another file on the disk21:57
jdstrandcemc: ie, libvirt shouldn't be looking at the attacker controlled file for information21:58
cemcI see21:58
cemcjdstrand: for a quick(er) fix, could I just add a /dir/** rw to usr.sbin.libvirtd where /dir is where I keep all the images for all current (and future) guests?22:03
jdstrandcemc: sure. just keep in mind it is a security trade off, and you won't have guest isolation, only host protection22:04
jdstrandcemc: that may be all you care about (eg, if these VMs are accessible via the network and aren't likely to be under attacker control)22:04
cemcyou mean the guests won't be protected from each other and this could be an issue (not for me in this case, it's just a home desktop for me)22:05
cemcyes22:05
cemcjust in this case, generally is not a good idea, I got it22:05
jdstrandcemc: yes22:05
jdstrandcemc: you said to usr.sbin.libvirtd though-- it should be /etc/apparmor.d/abstractions/libvirt-qemu though22:06
jdstrandcemc: usr.sbin.libvirtd is for the libvirtd daemon, for the guests, it is a combination of files-- to affect all guests, modify /etc/apparmor.d/abstractions/libvirt-qemu22:07
cemcright22:07
cemcjdstrand: it worked. thanks again.22:13
jdstrandcemc: sure, np!22:13
=== dendrobates is now known as dendro-afk
majukSo I enabled Samba as a Windows domain controller and elected it browse master for my subnet. Unfortunately, apparently something was not set up correctly with tbdsam (I'm guessing because I hadn't added a user for Samba yet) because it proceeded to take down ALL authentication for the server. I am now totally unable to log in, either remotely or locally. Attempts to change passwords for current users fails. Any ideas for trouble shooting this situatio22:25
majukn from the recovery root console would be greatly appreciated.22:25
majukThe prospect of starting over makes me physically ill.22:26
twbmajuk: you can't log into the Ubuntu server on which Samba is running?22:27
majuktwb, Correct22:27
twbmajuk: then you have broken the Ubuntu part, irrespective of what you've done to Samba22:28
majuktwb, Well, I can log in, but I am just kicked back out to another login prompt22:28
majuktwb, Right22:28
twbmajuk: boot a live CD and fix /etc/pam.d22:28
twbOh, you CAN log in.22:28
twbThat suggests your default shell is busted or something22:28
majuktwb, Yea, I thought that as well. But adding new users with different shells makes no difference22:29
majuktwb, And as root I am able to SU to the other users22:29
twbmajuk: you said you couldn't log in22:30
twbmajuk: if you can get root, then you CAN log in: as root.22:30
majuktwb, ok22:30
twbAre you doing "su majuk" or "su majuk -"?22:30
majuktwb, But only through the recovery console22:30
majuktwb, su majuk22:30
majuktwb, Any ideas for troubleshooting? I am open to anything.22:34
twbmajuk: OK, so you can't log in as root normally, only by picking "rescue" from the bootloader, and then picking "shell" or similar in the popup dialog that has other options like "resume booting" and "fix xorg"?22:38
twbI suppose if root has no password, you wouldn't be able to log in as root anyway.22:39
twbYou should be trying "su majuk -", since that will use a *login* shell.22:39
majuktwb, You are correct.22:39
majuktwb, That works. I am given a command line as the user majuk22:40
majukBut if I try to change the password, it requests my current PW and then drops me down to a new command line, never prompts me for the new password22:40
twbYeah, that indicates you have busted pam.d up22:41
majuktwb, Yea, and I didn't touch it personally. Any idea how to restore or cleanse it?22:41
majukI'm not a PAM guru. :(22:41
twbOne moment22:41
majukkk22:41
twbmajuk: run "auth-client-config --show-system" and pastebin the results22:42
majuksec22:42
twbIf you're transcribing by hand, newlines are important, but you needn't preserve spacing.22:42
majuktwb, Yea, gonna have to transcribe, gimme a minute to type this out22:44
majuktwb, http://pastebin.com/macf1c1e22:49
twbYeah, someone has put samba stuff in there22:51
twbSo that your user accounts come out of the Samba database22:52
majuktwb, that would explain it, the samba DB is not complete.22:52
twbI don't know how they would've gotten there if you didn't ask for them to get there22:52
majukI might have. I'm moderately new to Samba and everything is so automated. I've been reading howTos and running commands I'm not 100% sure what they do.22:53
twbOK, grasshopper.  Today's lesson is not to blithely run whatever some web page tells you to run.22:53
majuk'$net groupmap list' was the last thing I ran before everything went south22:54
twbFor example, when I told you to run auth-client-config before, you should have checked the manpage first, to make sure it wasn't a totally stupid thing to do22:54
twbSince neither I nor you know what else has happened to this system, if you haven't got anything important on it, I would advise you to blow it away and start again.22:55
majukYea22:56
majukThis is ridiculous. 'net' only does samba admin stuff. And before that all I was doing was editing the Samba config and rebooting it's daemon22:59
majukwhat22:59
majukthe22:59
majukexpletive22:59
majukSo twb, how'd you deduce it's referring to samba for it's user info?23:00
twbmajuk: that pastebin refers to "smb", i.e. samba (or Windows)23:02
majukYea. It has 'optional' in there though23:03
majukWhatever23:03
twbYes, but the whole rest of the file is wacky23:04
majukah23:04
twbIt wouldn't surprise me if whichever blog you pulled that from, the author hadn't even tried to log in with a non-Samba account after configuring it23:04
twbPAM is a massive bitch to get right23:05
majukYea. Oh well. And me without my install USB23:05
majukSomeone come to Texas and end me.23:06
twbJust go out into the street and talk about healthcare for all23:12
mathiazkirkland: http://www.stgraber.org/2009/11/06/lxc-containers-or-extremely-fast-virtualization23:37
majuktwb, LOL, yea. I just re-rolled out the server. Commencing config and self-loathing. Thanks again for your help.23:41
twbmajuk: no worries23:41
twbI recommend etckeeper to help you keep track of what changed in /etc and why.23:41
majukNoted.23:42
majukI'm out. Later man23:42
uvirtbotNew bug: #479614 in samba (universe) "Nautilus hangs from time to time" [Undecided,New] https://launchpad.net/bugs/47961423:46

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!