/srv/irclogs.ubuntu.com/2010/05/14/#ubuntu-server.txt

theacolyteWhatI've found in 10.04 is if you do anything that interferes with the boot process, like in my instance, incorrectly adding an IP to a network interface, and you reboot00:04
theacolyteYou can't boot anymore00:04
theacolyteNot to sound unconstructive, but that seems pretty awful to me00:04
theacolyteAnd now I can't get into single user mode to fix it00:04
theacolyteSo I'd be more than glad ffor some suggestions.00:05
theacolytewonderful00:08
theacolyteHow do I access the drive on my ubutnu server if I can't  boot?00:30
theacolyteI need to edit /etc/network00:30
theacolytesince apparently that broke it00:30
Smehok, in bug reports / install guides etc for 10.04 i keep coming across people refering to choosing "advanced" at the end of the installer where you can choose / check what drive grub is going to be installed to01:59
Smehbut don't see any evidence of any advanced option myself? :|02:00
Smehalso, on a tangentially related note, say i'm aiming for a LAMP server with x-windows gui, which makes more sense02:03
Smehstarting with server and installing X, or using desktop and installing the lamp services?02:03
=== twister_ is now known as twister
=== twister_ is now known as twister
pmatulisSmeh: if your desktop environment will be GNOME i would choose the latter02:10
Smehprobably will be gnome02:15
STFhi03:12
STFi running my ubuntu-server on a Laptop, without x11, and now i'm looking for a way to shutdown the backlight of my screen, cause i administrat my server about ssh from another machine03:13
qman__closing the lid usually does the trick03:39
RickyWh1is it easy to switch out apache2 for cherokee ?03:42
RickyWh1is there some way I can test my apache server to find out how many requests it can handle before it gets overloaded?03:46
=== gospch_ is now known as gospch
fbc-mxdoes anyone know of a condition that would make everything even your root disappear then mysteriously come back after a reboot? ex."-bash: /bin/ls: Input/output error"03:51
fbc-mxa03:56
gkahlais hald enabled by default on ubuntu server 10.4?03:59
deslectorhi, what is the best way to run iFolder on Ubuntu?04:01
lord_koalaHi everyone: dmesg | grep wlan0 gives me wlan0: cannot get RID fd42 (len=6) - no PRI f/w  ... I am trying to connect with my prism 2.5 chip wi-fi card. ifconfig only shows eth0 and lo. I tried to load some firmware to /etc/network/ınterfaces for prısm 2.5 and no luck. lspci -v shows I have my network card ıs prısm 2.5. Any help is appreciated. thanks.04:09
lord_koalaI am running hardy 8.04 server edition.04:09
acerimmerWhen running Virtual Box on ubuntu server, how do I network connect to the virtual machine?04:10
f1ybackif it's in bridge mode04:34
f1ybackjust like any other real box on your lan acerimmer04:34
acerimmerf1yback: ah.  thank you. gottago and try it04:38
f1ybacksmoke me a kipper04:38
RickyWh1which file to I edit to top apache2 web server from loading up?04:47
acerimmerf1yback: whattaguy!04:52
f1ybackheheh04:53
chrismsnzhey guys, i'm installing security updates on my server05:18
chrismsnzis there a command that will show me a changelog for the affected packages before i install them?05:18
clearyhi folks, I'm setting up a ppa for the first time, dput is failing with a connection refused error, and I cannot ftp directly to ppa.launchpad.net from multiple connections (none of which are firewalled)05:19
clearyI'm assuming there is a service outage, but just wanted to confirm before I spend any more time on it05:20
clearychrismsnz: try aptitude changelog <package>05:22
chrismsnzcheers cleary _b05:25
chrismsnzit's a good start05:26
enavhello im new to this....   i want to set up a vsftpd server with multiple virtual user usin PAM authentication... i got a good guide but it use a weak password authentication i mean just password uptu 8 character... i want something stronger...  give some web site or guide pleas05:42
=== twister__ is now known as twister
uvirtbotNew bug: #580319 in dhcp3 (main) "dhcp3-server launches before upstart brings all interface, thus failing to start" [Undecided,New] https://launchpad.net/bugs/58031906:11
qman__enav, there's not much point to using strong passwords with FTP because it's a clear text protocol06:13
enavyeah yeah  im reading something like you said....   :S06:13
qman__you CAN, but you're still shouting them out for the world to see06:14
enavyou are right  ftp with password is just to preven noob hackers06:18
rahmanHi, I have setup a mail server with postfix + dovecot + squirrelmail. Here is my main.cf file: http://pastebin.com/2Uw64vTh07:03
rahmanI ave a problem, I can send email to aaaa@rahmanduran.net from bbbb@rahmanduran.net. But I can't send email from bbbb@rahmanduran.net to different domain like cccc@gmail.com.07:03
rahmanI get a "Relay access denied" error from postfix07:04
enavvirtual users and SFTP is possible???????07:08
rahmanenav: can you explain more? I use virtual users, and have a table virtual_users in mysql07:14
rahmanemail accounts of my domain can receive email from diffrerent  domains with success, btw07:15
enavcan you make a new system user that have access to SFTP but is not allowed to use SSH, and limit this SFTp to one folder????07:40
=== Guest8612 is now known as RoyK_wrk
qman__enav, yes, look up sftponly and chrootdirectory in sshd configuration09:03
qman__this is a new feature as of ~9.10 IIRC09:03
uvirtbotNew bug: #580375 in mysql-dfsg-5.1 (main) "package mysql-server-5.1 5.1.41-3ubuntu12 failed to install/upgrade: Package is in a very bad inconsistent state - you should  reinstall it before attempting a removal. cant stop mysql server to reinstall it" [Undecided,New] https://launchpad.net/bugs/58037509:12
realVhi to all09:21
realVI'm trying to setup an high availability system, really simple (account, ftp, file sharing, mail), with a pair of servers, one principal and one "backup", that switch on in case of failure.09:24
realVi've looked for UEC, but is really too big for my little infrastructure09:24
realVdrbd for sync data is a good solution, but there are too much ways.09:26
enavmy head is going to blow UP!!!!!!!!!!!!    this article say that Now alice can use SFTP to read from and write to her ~/public_html/ directory, but can't use OpenSSH to get a shell, nor even to read files outside of ~/public_html. ......... but is a lie   i can see and change all system folders.... what im doing wrong09:35
enavups this is the article http://is.gd/c8uMy09:35
=== lord_koala_ is now known as lord_koala
juanjoAHello, how I can remove the configuration of raid on 2 hd. I delete all partitions but when I reinstall, partman recognises old distribution of raid ...10:14
juanjoAmaybe MBR10:14
realVyou can use dd on the device10:15
realVif you have /dev/sda, you can remove mbr with 'dd if=/dev/zero of=/dev/sda bs=512 count=1'10:16
realVkeep in mind that all the data will be lost10:17
juanjoArealv: ok, thx, I will probe this10:18
juanjoAIs there a ubuntu 10.04 server guide on PDF?10:22
sommerjussi: I don't think there is at the moment, but there may be in the near future... I think there was an issue in generating the Lucid pdf.10:27
Jeeves_An issue creating a pdf? :)10:28
jussihrrr10:28
sommerwell automatically creating a pdf10:28
uvirtbotNew bug: #580424 in libpam-ldap (main) "package libpam-ldap 184-8.2ubuntu1 failed to install/upgrade: " [Undecided,New] https://launchpad.net/bugs/58042411:01
RoAkSoAxkirkland, by any chance do you have a copy of the testdrive gobby doc? Cause its gone from gobby :S :/11:46
kirklandRoAkSoAx: crap ....11:47
kirklandRoAkSoAx: i didn't copy it to the blueprint :-(11:48
RoAkSoAxkirkland, neither do I :S. Hopefully someone else saved it :/11:49
kirklandRoAkSoAx: you should /join #testdrive11:49
_chris_is it usual for apache2 to have about 10procs running ?12:00
guntbert_chris_: yes, they are running in because starting a new process takes "a lot" of time12:01
guntbert*running because ...12:01
RoyK_chris_: see StartServers/MinSpareServers/MaxSpareServers12:02
RoyKin apache.conf12:02
RoyKapache2.conf12:02
_chris_ah okay12:03
_chris_5/5/1012:03
guntbert_chris_: if you don't expect many requests on you server you can reduce those values12:06
_chris_guntbert: ok, thanks :)12:08
musimarhello I have a problem with my email server12:38
musimarI can send emails in local but not outside12:39
musimarhttp://paste.debian.net/73252/12:39
musimarthis is the paste of the end of my /etc/postfix.cain.conf12:40
musimarmain*12:40
guntbertmusimar: why do you need a public smtp server?12:40
musimarbecause the server is at home12:41
guntbertmusimar: no, my question was: why does it have to be public? why not just (for learning ) confined to your private network?12:42
musimarhummmm12:42
musimardon't know ;-)12:42
musimarit's better to send emails outside no?12:42
musimar:-D12:43
guntbertmusimar: if you don't "*really* know what you are doing" don't run an smtp server with access to/from the internet - it can get you in troubles rather quickly (google for "open mail relay")12:44
dwightHola, I'm wondering what is the easiest way to recover the default apache ports.conf file for ubuntu 10.4... am I likely to find it on the wiki, community docs, or is there an aptitude command I can use to revert?12:56
jpdsdwight: Consider using etckeeper. :)12:57
dwightetckeeper looks like a nice solution!12:58
dwightbut won't help me out of the current jam.12:59
_chris_heja. having a small issue. i have an ubuntu-server in our firms network. before it was set to dhcp and i could access the webpage per servers hostname. now we gave it a fix ip adress and since then its not possible anymore to reach the website per the servers hostname, always have to enter the ip adress instead. maybe anyone has an idea ?13:10
_chris_well its not only the webpage, he isnt reachable by its hostname in any way. may it be putty, a ping or whatever13:11
egsomeIs there any Application that helps making my Ubuntu-Server a Router for my Office ?13:27
cloakableegsome: ipmasq13:29
egsomecloakable, Great, Thanks13:31
cloakableegsome: no problem13:31
cloakableegsome: if you want a more powerful solution, shorewall. but ipmasq will do the basics.13:32
egsomecloakable, Shorewall is to be installed on Ubuntu or as a distro ?13:33
cloakableegsome: shorewall is a program. it's in the ubuntu repo13:33
egsomecloakable, good13:34
cloakableegsome: but it isn't a fire-and-forget solution like ipmasq... it needs configuring.13:35
egsomecloakable, What do you recommend for me ? i only need the server to act as router, i need to restrict web access to some sites, and do more like that jobs13:36
cloakableegsome: hmmm. not sure. I don't know how to restrict access13:37
egsomecloakable, no problem, but generally what do you recommend ? and access restrict and suck jobs are done by iptables, no problems13:38
cloakableegsome: sounds more of a job for shorewall, it's more configurable than ipmasq13:39
egsomecloakable, OK Thanks, will look on it13:40
RoyKhi all. I have a package list from a 9.04 server - is there an easy way to install all _existing_ packages from that list on a 10.04 box?13:49
bogeyd6RoyK, im not sure they would all be compatible13:50
bogeyd6you could just make the list into one big line of text and apt-get install <paste files>13:50
RoyKbogeyd6: that's the probem - but an upgrade works, only I don't want to install 9.04 and then upgrade13:51
bogeyd6hmm13:51
bogeyd6RoyK, did you download all of the dpkg files?13:51
bogeyd6or .debs13:51
RoyKno, I'm trying to apt-get install `cat list.txt`, but it halt if it finds an unknown package13:52
RoyKit'd be nice for those to be simply ignored13:52
_chris_heja. having a small issue. i have an ubuntu-server in our firms network. before it was set to dhcp and i could access the webpage per servers hostname. now we gave it a fix ip adress and since then its not possible anymore to reach the website per the servers hostname, always have to enter the ip adress instead. maybe anyone has an idea ?13:54
cloakable_chris_: you might want to add the server to your dns.13:56
RoyKerm... " rsyslog: Conflicts: linux-kernel-log-daemon" - wtf is this? rsyslog is installed, but I have no linux-kernel-log-daemon in my list13:59
RoyKklogd...13:59
RoyKgot it13:59
RoyKhttp://pastebin.com/hCHtteKt14:05
uvirtbotNew bug: #579274 in postfix (main) ""unknown job" trying to restart postfix" [Undecided,Invalid] https://launchpad.net/bugs/57927414:08
axisysfailing to upgrade14:11
axisyshttp://pastie.org/private/9vlrulhrxx9a55pvahxpya14:11
axisyshow do I change my repo ?14:11
axisysmay be will have better luck w/ another repo14:12
bogeyd6axisys, edit /etc/apt/sources.list14:12
bogeyd6anl.gov is the fastest for most people14:12
bogeyd6sometimes down for maintenance14:12
axisysbogeyd6: it is not down.. i can talk to port 8014:12
bogeyd6also it looks like you fudged the sources.list file14:12
bogeyd6all of these are 404 messages14:13
bogeyd6axisys, pastebin your /etc/apt/sources.list14:13
axisysbogeyd6: ok14:13
bogeyd6file guinely doenst exist14:14
bogeyd6axisys, that file does exist in another mirror14:15
axisysbogeyd6: http://pastebin.com/znsKxZih14:15
bogeyd6axisys, looks ok to me14:16
bogeyd6prob just need to go ahead and switch to the ubuntu.cs.wisc.edu14:17
=== thefish_email is now known as thefish
slipper1024UEC CC CLC SC Walrus on 1st server14:28
slipper1024NC on 2nd and 3rd server14:28
slipper1024as per guide https://help.ubuntu.com/community/UEC/CDInstall14:28
slipper1024cant --discover-nodes14:30
slipper1024 or --synckey14:30
slipper1024any ideas guys, Lucid 32bit14:31
axisysbogeyd6: so like this?14:38
axisysbogeyd6: sed 's/mirror.anl.gov/ubuntu.cs.wisc.edu/' /etc/apt/sources.list > /tmp/list; cp /tmp/list /etc/apt/sources.list ?14:38
axisysi backed it already14:38
axisysbogeyd6: or there is an elegant ubuntu tool there, like for desktop ?14:39
axisysbogeyd6: did just that.. lets see if do-release-upgrade works now14:40
axisysbogeyd6: you were right. noticibly slower14:41
bogeyd6kk14:43
bogeyd6axisys, anl.gov is the fastest for anyone in the midwest14:43
jpdsmirror.anl.gov is awesome.14:44
jpdsaxisys: sed -i...; would save you the cp.14:44
bogeyd6axisys, they run an oc192 out of the argonne laboratory14:45
bogeyd6jpds, sorry, i meant they now run a dual oc192 out or argonne14:49
jpdsbogeyd6: I know.14:49
jpdsbogeyd6: I've spoken to the admins in the past before. :)14:50
bogeyd6i dont speak to them14:52
bogeyd6:)14:52
bogeyd6probably never would or have cause to14:52
bogeyd6but they are a public entity and as such everything they do is online14:52
dindaivoks: ping15:16
ivoksdinda: pong :)15:18
=== Owner_ is now known as wizardslovak
wizardslovakhello people15:47
wizardslovakwhy is apache showing "index of.." instead of actual website?15:47
cloakablewizardslovak: Have you put a website into /var/www?15:49
aoeuhtnswizardslovak, probably because the "Indexes" option is on and there is no index document (index.html)15:50
wizardslovaki actually made folder with website name and put everything in it15:50
wizardslovakthen in sites-available/website  i changed document root to website flder15:50
cloakablewizardslovak: did you then do 'sudo a2ensite website'?15:51
wizardslovakoh no15:51
wizardslovakdo i have to wrtie "a2ensite /etc/apache2/sites-available/website?15:52
cloakableNo15:52
wizardslovakcause i am geting error "no site found matching15:52
cloakablewizardslovak: are you doing as root or regular user?15:53
wizardslovakroot15:53
wizardslovakprobably i did something wrong in sites-available/website conf15:54
cloakableUnlikely15:55
wizardslovakhmm15:55
cloakablewhat is the name of the file in sites-available?15:56
wizardslovakso whats the corrent command for a2ensite15:56
wizardslovakwizzy15:56
cloakablesudo a2ensite wizzy15:56
wizardslovakok got it16:00
wizardslovaki forgot to put correct folder in "directory" ;) thank you people16:00
wizardslovakyea one more think16:00
wizardslovakcan i connect usb printer and use it with CUPS in ubuntu?16:01
ivoksin ubuntu server?16:02
ivoksyes16:02
Wack479good morning!16:03
wizardslovakhuh somehow when i connect usb printer i dont see it16:05
Wack479I am having issues with my 9.04 server running kernel 2.6.28-18-server. About 2-3 times a week my networking service has to be restarted. It happened again this morning and i got this in the kern.log http://pastebin.com/iHfL1DVL16:06
axisysbogeyd6: ubuntu.cs.wisc.edu is working .. no 40416:08
axisysbogeyd6: thanks for your help16:08
iKbis there a simple way to install php 5.2 on ubuntu server 10.04?16:08
Wack479ikb: apt-get?16:09
iKbapt-get install php 5.316:10
iKbi need php 5.216:10
Wack479oh ok sry16:10
iKbis apt-get pinning the only solution?16:11
axisys=pkg_version_number have you tried that?16:12
axisysiKb: ^16:12
axisysiKb: man apt-get will show you the syntax16:12
iKbaxisys: there is no 5.2 version for 10.0416:13
iKbthis is why i need pinning16:14
wizardslovaksu16:14
wizardslovakthats weird16:17
wizardslovakhttp://pastebin.com/v08atfZ416:18
axisysiKb: check man apt_preferences16:20
iKbaxisys: this is for pinning no?16:22
axisysiKb: yes16:22
stas_hi, can somebody help me, I got an entry like this in aliases>test :include:/etc/postfix/lists/test and postfix appends @$mydomain to that entry each time a new mail is received. what Iam doing wrong?16:42
uvirtbotNew bug: #580565 in dbconfig-common (main) "package dbconfig-common 1.8.44ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/58056516:47
Wack479I am having issues with my 9.04 server running kernel 2.6.28-18-server. About 2-3 times a week my networking service has to be restarted. It happened again this morning and i got this in the kern.log http://pastebin.com/iHfL1DVL16:56
wizardslovakis there software in which i can connect with web browser to check status/traffic on server?16:56
tannerbOk, I'm going slightly mad. I'm installing 10.4 on a new server using 4 750 GB drives. 2 of those I pulled out of an old server that was using some nvidia fakeraid. I fdisked the previously used discs to the partition table I want, but the ubuntu installer keeps wanting to activate the old raid configuration on those discs. Is there a place I'm not thinking of where that stuff would be hidden that fdisk wouldn't touch?17:08
tannerbMy apologies if that's a silly question, but I can't think of where that configuration would be hidden after a whole new partition table had been written to the disk...MBR or some such? Have I gone entirely insane?17:12
Bart_I'm now running 2.6.32-22-generic-pae. How do I switch to the server kernel?17:17
failoverQuestion about hardware requisites for a mail server, Lucid + Postix + MailScanner + SpamAssasim + Dovecot, 7k incoming mail , 4k outgoing mails, 800 users. Which should be the minimum hardware to run this setup ?17:19
failovera virtual machine with 1 GB of ram do the trick ?17:20
ninjaihow do i set up phpmysqladmin? I downloaded it through apt-get but find no php page anywhere17:38
uvirtbotNew bug: #580590 in squid (main) "Squid no longer uses $SQUID_MAXFD" [Undecided,New] https://launchpad.net/bugs/58059017:41
AmokPauleninjai try to locate phpmyadmin then do a link to that folder17:51
uvirtbotNew bug: #580611 in puppet (main) "variable scope problem" [Undecided,New] https://launchpad.net/bugs/58061118:21
bkingxGreetings! Quick question: a script that runs at startup is run under what user?18:28
RoyKroot18:31
bkingxthanks RoyK18:36
bkingxNext question, trying to script some gpg decryption in that script and I am thinking it can't access the .gnupg folders/files.18:37
bkingxSo how can a script at startup, running as root, can't access those files?18:38
mr_danielI use ubuntu since 5.10; before I tried debian several times, which was a lot fun. I want to setup my first root server, both for fun but also to start building cool web apps with tools I like to use and without any limitations from web hosters; I am at a point where a simple LAMP configuration is not enough.18:38
mr_danielbut the problem is: I never owned a root server, and I don't know where to start?18:39
mr_danielI hope you guys can give me some tips where I can start, maybe18:40
mr_daniela good book18:40
Hypnozmr_daniel: apt-get update && apt-get install apache2 && apt-get install mysql-server && apt-get install php5 && apt-get install phpmyadmin18:40
mr_danielHypnoz: :)18:41
mr_danielwait, why not use aptitude?18:41
Hypnozbecause aptitude takes longer to type than apt-get of course18:41
Hypnozmr_daniel: after you've installed the LAMP stack, and have a more specific question, that might be good18:43
Hypnozmr_daniel: just asking how to create a server that hosts a webpage is too broad, and something that should probably be googled for since it takes quite a few steps18:43
mr_danielI guess you are right Hypnoz18:44
Hypnozis "googled" a recognized verb of the english language yet?18:45
Hypnozmr_daniel: really creating the web hosting server isn't the hard part. programming the site in php/javascript/etc is what takes skill18:46
Hypnozmr_daniel: there are some frameworks that might be worth learning like cakephp or django18:47
Hypnozmr_daniel: or maybe installing something like wordpress18:47
Hypnozmr_daniel: something like wordpress would cut waaay down on the web programming aspect required18:47
mr_danielI want to go further18:48
mr_danielfor example I want to build a web app with CoucDB, or with J2EE, and want to be prepared for high traffic, etc.18:48
Hypnozmr_daniel: why couchdb instead of mysql?18:51
mr_danielbecause I want to learn new things18:51
mr_danieland CoudhDB is cool :) and sounds very interesting18:52
Hypnoztry django I got a friend that loves it, and its a very popular thing to put on a resume18:52
Hypnozand you'd get to learn python too18:52
mr_danielnever used django, but I used python for a few things and I like the language18:54
vkramarI have some troubles enabling PHP in userdir on 10.04. Already tried both /etc/apache2/mods-enabled/php5.conf and /etc/apache2/conf.d/php-in-homedirs.conf ways as described on wiki, but no success. Can anybody point me right way?19:02
RoyKhttp://pastebin.com/hCHtteKt <-- fine, new box19:03
storrgieanyone using tomato firmware?19:08
RoyKwhat is that ?19:08
storrgierouter firmware for wrt routers19:08
vraastorrgie, i use tomato firmware, i switched from dd-wrt becaue dd-wrt was too complicated19:14
RoyKhow many cpus does linux support these days?19:15
RoyK256 or so?19:15
storrgievraa: it seems that all of my traffic, when QoS is on I only get 10% thoroughput19:15
vraamaybe your qos settings are not correct? did you set your inbound and outbound speeds correctly? btw i dont think this is related to ubuntu-server :)19:15
storrgievraa: I know its not related to ubuntu-server but tomato has ZERO irc community19:16
vraaRoyK can't you use BFS for more than 1000 core support?19:16
storrgieI cant find anyone to help me19:16
vraa:) try to double check your inbound/outbound maxes, also check how you are classifying your traffic19:16
RoyKvraa: http://en.wikipedia.org/wiki/Brain_Fuck_Scheduler?19:16
vraayah19:17
vraai believe it's designed more NUMA or something19:17
RoyKwhat a nice name :)19:17
therianis it any good?19:17
vraaif it ain't broke, dont fix it19:22
vraain regards to "is it any good"19:22
vraaif you have 500 cores and things aren't working well, i'm sure BFS would be a viable thing to try out19:22
vraabut me, on my single core pIII laptop? i'll stick with whatever is default19:22
RoyKjust installed this 16-core thing - it'll be interesting to see how the load is distributed when they start the models19:23
vraadual 8core opteron right RoyK ?19:24
RoyKyes19:24
RoyK64 gigs of ram19:24
RoyKchewing volcanic ash transport models19:24
RoyKor simply particle transport models19:25
enavgood morning19:44
RoyKgood evening19:45
aoeuhtnsgood afternoon19:45
theriangood afternoon19:45
therianfuck19:45
aoeuhtns:-)19:45
therian;p19:45
RoyKgood localtime();19:46
therianlol19:46
_3iesGood morning, and in case I don't see ya, good afternoon, good evening, and good night!19:48
therianoh night19:49
theriani forgot that one19:49
_3ies:))))))))))))))))))))))))))))))))))))))))))))))))19:49
_3iesit is from the truman show19:49
RoyKhttp://karlsbakk.net/top-16.png19:57
guntbert!language | therian20:01
ubottutherian: Please watch your language and topic to help keep this channel family friendly.20:01
ziesemer_I've been looking into denyhosts or fail2ban to help prevent some server attacks.  Both appear to only work by parsing log outputs from /var/log/syslog, etc.  Isn't there a more efficient method?  I.E., is there a syslog "consumer" that can be used?20:01
aoeuhtnsRoyK, 48GB of swap?!20:01
RoyKno, 1620:01
therianmy bad20:01
RoyKbut ubuntu 10.04 comes with this compcache thing, swapping to compressed memory20:01
aoeuhtnsinteresting20:02
RoyKplanning to use some SSDs for the swap20:03
RoyKsome of the models can use way more memory than the 4GB per core that's in there now20:03
lolufailhi20:09
lolufail!20:09
lolufailwhat does the "virtualsiation" checkbox during installation do? just that networkbridge?20:10
=== twister_ is now known as twister
uvirtbotNew bug: #580674 in irqbalance (main) "Not stoppable/restartable via initctl" [Undecided,New] https://launchpad.net/bugs/58067420:16
=== failover is now known as failover_no_blin
=== failover_no_blin is now known as failover_noblink
axisyshow do I install sun storage CAM (common array manager) in ubuntu ? i need to manage my sun storagetek 614020:37
=== twister_ is now known as twister
bluethundr_I am trying to use standard networking tools like nslookup and dig on an 8.0.4 Hardy box... but they are curiously absent. what package installs these?21:20
RoyKbind-utils21:21
tannerbI'm not sure about hardy, but probably dnsutils.21:21
RoyKor bind9-utils21:21
tannerbOr exactly what RoyK said.21:21
RoyKnslookup is old - use 'host' or 'dig'21:22
=== erichammond1 is now known as erichammond
bluethundr_RoyK, thx!21:29
* RoyK just got an email from the CEO congratulating a server setup - not bad21:31
uvirtbotNew bug: #580700 in cyrus-sasl2 (main) "Package is actually called "sasl2-bin"" [Undecided,New] https://launchpad.net/bugs/58070021:41
bluethundr_I have updated my serial number in my dns db and restarted bind and made sure my mx was correct, but when I use dig -mx it doesn't see the mx record21:45
bluethundr_http://pastebin.com/KH3adera21:45
RoyKperhaps $ORIGIN hasn't been set before the MX line21:46
RoyKset $ORIGIN to your domain name in the start21:47
enavi need help.... i want to limit a SSH user to specific folder "/home/www".... i have 2 days trying to do this reading manuals and articles but nothing works21:47
RoyK$ORIGIN mydom.tld21:47
guntbertbluethundr_: all on the same machine?21:47
RoyKenav: you need to chroot the user - not trivial21:48
RoyKenav: use a vm instead21:48
enavi tried that several times in several ways and still not working propertly21:49
bluethundr_guntbert, yes, and this config file is an exact copy of another dns db file that works, only with the values for this machine subtituted21:49
RoyKenav: see message above21:49
guntbertbluethundr_: I asked because dns propagation can take surprising long time :-)21:50
enavRoyK use a vm instead???21:50
RoyKenav: chrooting ssh is not trivial21:50
enavRoyK what that means21:50
RoyKeither use other access methods or use a virtual machine21:50
bluethundr_this one works and I can't see any substantive difference between this one and the one that doesn't21:51
bluethundr_http://pastebin.com/dVDVRyWn21:51
bluethundr_guntbert, ah ok.. yes but this is all local the machine having the issue21:51
uvirtbotNew bug: #580708 in cyrus-sasl2 (main) "Can't run multiple saslauthd daemons as per the documentation" [Undecided,New] https://launchpad.net/bugs/58070821:51
RoyKbluethundr_: add $ORIGIN mydomain.com. around $TTL21:52
guntbertbluethundr_: ok - sorry to hear - no solution from me either21:52
bluethundr_RoyK: on it, I'll let ya know21:52
enavRoyK i though chroot limit a specific user to a specific folder... but this not works21:54
RoyKas I said, chrooting ssh sessions is not trivial21:54
RoyKuse a vm for that21:54
enavRoyK  what do you mean with trivial???21:55
* RoyK points enav to dictionary.com21:55
enavRoyK do you mean chroot is not easy to configure?21:58
RoyKnot for ssh clients21:59
RoyKwhat are your needs?21:59
RoyKisolating all clients inside a jail?21:59
enavRoyK do you know a good text or website to chroot ssh users???21:59
RoyKif so, why?21:59
enavwell i have an Admin account and a Webmaster account... i just whatn to jail webmaster accoutn to "/home/www" folder that is all22:01
enavi have 2 days trying to do this22:01
RoyKuse ftp22:01
qman__no, use sftp-only22:01
RoyKftp over ssl is secure22:02
RoyKand trivial to configure22:02
RoyKftp over ssh means the user will be given access to whatever's open22:02
RoyKenav: I'd guess securing your system, home directories and so on, will be easier22:03
RoyKjust give www or whatever access to the files needed22:03
qman__not if you configure ssh correctly22:03
qman__recent versions can limit it to sftp and chroot right in the sshd config22:04
enavim give up with SFTP22:04
qman__no special jailing setups required22:04
RoyKhow do you chroot ssd/sftp?22:04
enavlet me try that you say now22:04
RoyKqman__: url?22:04
qman__I'm looking for the doc22:04
qman__http://www.debian-administration.org/articles/59022:05
RoyKqman__: thanks22:07
qman__it's way easier than the old style jailing22:07
RoyKseems so, yes22:07
RoyKthought it was harder22:07
qman__the version of openssh in hardy is older and doesn't support that22:09
qman__but the current versions do22:09
qman__I've set up a few old style jails with jailkit, no simple task22:10
enavqman__ is a hell22:10
enavqman__ your article look great but can i use this to jail an user not a group to a specific folder not a home folder????22:12
qman__enav, yes22:13
enavqman__:   Match group sftponly  --->   Match user webmaster    really?22:14
qman__not sure if that's the syntax, but you can match per user22:14
qman__let me find more information22:14
enavwait a sec22:15
enavyour article work for you? i mean did you try it before?22:15
qman__http://prefetch.net/blog/index.php/2006/09/05/limiting-access-to-openssh-directives/22:15
qman__Match User username22:16
qman__the way Match blocks work, is they include all of the directives below it until there is another Match block or the end of the file22:17
qman__so place them at the bottom22:17
enavok  let me try again22:17
enavbecause i did this a lot of times22:17
qman__the one caveat I'm noticing is that the chroot directory must be owned by root22:18
qman__other than that, it's straightforward22:18
enavok22:18
tannerbWow, I hadn't looked at doing chrooted stuff securely for years and that's about a bah-jillion times easier.22:20
qman__you're telling me22:20
qman__the old way was a total pain22:20
tannerbYeah, and by the time one would get close to getting it working properly, you'd have to find another goat to sacrifice.22:21
enavim feeling the pain now22:21
enavqman__  chek this http://pastebin.com/YmgedfRg22:25
qman__that's correct22:25
qman__but where's the rest of the configuration file?22:26
enavi just copy paste an little section22:26
qman__ok22:26
qman__I noticed that the default configuration has this in it22:28
qman__Subsystem sftp /usr/lib/openssh/sftp-server22:28
qman__you will want to change that over/remove it22:28
enavyes you ned to change it22:28
qman__two Subsystem sftp lines will break it for sure22:28
enavi delet the original 1 and add the new 122:28
qman__ok22:29
qman__then, chown root:root /home/www, and service ssh restart22:30
ziesemer_What is the impact of the "owner" provided to tunctl ?22:48
=== unreal_ is now known as unreal
Jeeves_Mossafternoon all!23:12
=== twister_ is now known as twister
gregcoitis it possible that S99mysql isn't waiting for S98rc.local to finish in lucid?23:26
gregcoitand is this somehow related to upstart?23:27
=== AntORG_ is now known as AntORG

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!