/srv/irclogs.ubuntu.com/2010/08/13/#ubuntu-server.txt

arrrghhhso i've mounted a nfs share at /tmp, but not i can't umount it.  says device is busy - probably because it's /tmp... i can't even umount it with -f, what else can i do?00:02
patdk-lapkill any programs using /tmp :)00:06
arrrghhhpatdk-lap, none should be at present...00:07
patdk-lapverify with lsof?00:08
arrrghhhi just did...and there are some .nfs files open00:08
arrrghhhfrom .python.b00:08
arrrghhhhow do i know what process to kill tho?00:09
arrrghhhpatdk-lap, i can't kill all of the .python.bin processes...00:13
patdk-lapreboot? :)00:23
arrrghhhhahaha00:24
arrrghhhyea i guess so00:24
arrrghhhthis is a 'production' server so i was hoping to avoid that...00:24
patdk-lapheh00:25
uvirtbotNew bug: #611769 in eucalyptus "Can't create volume from snapshot with different size" [Undecided,Fix committed] https://launchpad.net/bugs/61176902:16
rcsheetsStandard Cloud Add-On - 1 Year: $350.0102:47
rasenganAnyone have an issue with pptpd GRE+ppp checksum errors?02:55
mewsictrying to setup vsftpd. can anyone help?03:06
mewsichelp with server03:14
mase_wkmewsic: sure we are in here to help, but you need to provide us with specific problems that your having03:18
=== lifeless_ is now known as lifeless
=== dendrobates is now known as dendro-afk
=== rmk_ is now known as rmk
MikeGuohi,05:02
MikeGuoeveryone. I got a UEC issue.05:02
MikeGuoI can't register my node.05:02
twb!ask05:02
ubottuPlease don't ask to ask a question, simply ask the question (all on ONE line and in the channel, so that others can read and follow it easily). If anyone knows the answer they will most likely reply. :-)05:02
MikeGuoand I found people have same problem with me.05:02
MikeGuothere is bug:https://bugs.launchpad.net/ubuntu/+source/eucalyptus/+bug/59818605:02
uvirtbotLaunchpad bug 598186 in eucalyptus "Unable to register nodes in eucalyptus" [Medium,Incomplete]05:02
MikeGuois there other people got this issue too?05:03
MikeGuothanks05:03
=== EvilTrek is now known as EvilPhoenix
alex88what is file /proc/user_beancounters? and where are the current values of that things?07:13
twbalex88: it's OpenVZ's exposure of resource limitations stats07:16
alex88twb: thank you, but there are the limits..where i can see the current values? i have some fails in tcprcvbuf and tcpsndbuf07:18
twbThe limits are configured in /etc/vz/conf/N.conf07:21
alex88is anything i can do with those buffers? i just download from my home when i get those errors07:25
twbalex88: ask #openvz.  I don't really feel like dealing with openvz stuff.07:29
alex88oh...sorry :) thank you07:31
uvirtbotNew bug: #617237 in mysql-dfsg-5.1 (main) "package mysql-server-5.1 5.1.41-3ubuntu12.3 failed to install/upgrade: Package is in a very bad inconsistent state - you should  reinstall it before attempting a removal." [Undecided,New] https://launchpad.net/bugs/61723707:51
WalterNfor some reason apache is not saving the log files...07:59
\shWalterN: hmm? elaborate? :)08:00
WalterNusing the same configuration as with 9.1008:00
WalterNwith virtual hosts08:00
binBASHmoin08:00
\shhey binBASH08:00
WalterNhmm.. lemme pastebin the config file08:00
binBASHHi \sh ;)08:00
alex88paste somewhere :)08:01
demon1981hi all)) how I can determin frequency of my graphic card on my 10.04 without X server?08:01
alex88demon1981: look at manifacturer specs :)08:02
demon1981alex88: I dont know what video card I use:)08:03
alex88lspci?08:03
WalterNhttp://pastebin.com/gq8THFcV08:04
WalterNwhere pool is a RAID508:04
WalterNit worked fine is 9.10 and on a single disk (didnt have RAID st up at the time)08:05
alex88WalterN: tried /var/log/apache2/error.log?08:05
alex88it shows startup errors08:05
WalterNchecking08:06
demon1981I have that in dmesg08:07
demon1981[    4.702355] [drm] nouveau 0000:02:00.0: Detected an NV50 generation card (0x0a5000a2)08:07
demon1981may be its nvidia08:07
demon1981how I can determ model of card?08:07
alex88demon1981: i told lspci not dmesg08:08
demon1981ups08:08
WalterNalex88: oh, it says it cant open /media/pool/website/error_jewelcreekkennels.com.log. Unable to open logs08:08
alex88WalterN: look why..can you access with root?08:09
alex88like touch /media/pool/website/error_jewelcreekkennels.com.log08:09
alex88look also at fstab permissions for the drive08:09
WalterNI chowned the drive I thought08:11
WalterNmaybe I should have -R ?08:11
alex88sure08:11
WalterNheh, that did it08:17
demon1981my card is GeForce 02:00.0 VGA compatible controller: nVidia Corporation GT216 [GeForce GT 220] (rev a2) very likely driver nouveau is used. How I can determine the frequency of output signal?08:17
WalterNstrange though, why would I need to own the directory that its saving the log to?08:17
WalterNnot sure who the owner was before, but could save anything I wanted before08:18
WalterNhmm, since I'm talking about it, what is a good website log viewer/analyzer thingy program?08:20
\shwebalizer / awstats / analog /modlogan it depends on your needs08:21
WalterNhobby server08:22
\shwebalizer08:22
WalterNas in, I dont know what I need :P08:22
alex88demon1981: you main monitor refresh?08:23
alex88WalterN: no, that not important...btw try to set log to debug in apache.conf, or ask in #httpd :)08:23
alex88gtg now08:23
soulstarhi, I'm having a problem setting up a router08:27
soulstarcan anyone help?08:27
WalterNsoloslinger: what kind of router, and for what?08:28
soulstari'm setting up my computer to serve as a linux router08:29
soulstari have ubuntu 10.04 installed08:29
WalterNoh, donno XD08:30
WalterNI could help with dd-wrt though :)08:30
WalterNwhich is not what you are using or want to use, so nevermind08:30
soulstarI'm using openwrt on my wireless routers...08:31
soulstarwhich I don't have a problem with08:31
eagles|workhey guys08:36
eagles|workmy question is this.08:36
alex88soulstar: what you want to have?gateway?08:36
eagles|worki have  my modem connected to a router and the router is getting dos'd is it possible to black list the ips on my server so they cant flood the server again?08:37
alex88eagles|work: you have firewall? how are you'r linux skills?08:37
qman__eagles|work, yes, but it's even easier/better to use iptables recent08:37
qman__it'll dynamically block addresses that are spamming08:38
eagles|workqman__:  and alex88 i have iptables setup08:38
eagles|workwould you like a pastebin of the iptables -L output08:38
alex88i use csf, and is awesome for ddos, bruteforces etc08:38
alex88try it08:38
qman__http://www.ducea.com/2006/06/28/using-iptables-to-block-brute-force-attacks/08:39
eagles|worki have in the past but had mixed feelings about it08:39
qman__that example is for ssh, but can be used for any type of traffic08:39
qman__it'll significantly reduce the impact of the DoS while not cutting off service entirely08:40
alex88eagles|work: i've always been fine with that..08:40
eagles|workqman__: someone pointed out somethign valid though even though the server is secured the router and my incoming connection will still be getting flodded08:41
qman__eagles|work, the way this works is, the server will simply drop packets being spammed in08:42
qman__so the DoS would have to have so many resources that only the single incoming SYN packets can max your line08:42
qman__and if that's the case, there's nothing you can do about it08:42
eagles|workya im in the process of setting up another server as a dedicated firewall08:42
eagles|workqman__: would snort help mitigate those kinds of attacks or not really08:43
qman__no08:43
qman__snort is an IDS, it has no effect on this sort of thing08:43
qman__it will simply tell you what is happening08:43
eagles|workok08:43
qman__if the attacker can flood your line with SYN packets, there's nothing you can do on your end08:44
qman__contact your ISP08:44
qman__see if they can help08:44
qman__but, if they're only succeeding with the full handshake, a proper firewall will reduce the impact08:45
WalterNI should set up email sometime soon08:45
eagles|workqman__: im getting flooded with udp packets08:46
qman__eagles|work, is your server dropping them, or rejecting?08:47
qman__dropping is what you should be doing08:47
alex88reject will just generate more traffic08:47
qman__and if you are, that's all you can do08:47
eagles|workqman__: i have a router in between the outside and server08:47
qman__irrelevant08:47
alex88if the router can handle all the packets08:48
eagles|workand the router is just stopping the floods08:48
qman__well, it doesn't really matter where the packets are getting dropped, as long as they're getting dropped, and not rejected08:48
qman__that's all that can be done from your end08:48
eagles|workya08:48
mase_wkthats not exactly true, if you can get someone else upstream to drop them for you :)08:49
eagles|workhehe08:49
qman__exactly my point, nothing else can be done on his end of the line08:49
eagles|workwell i am in the process of setting up a dedicated firewall machien with 2 nic's08:49
qman__call the ISP, get them to help08:49
mase_wkyeh08:49
mase_wkor get the ip address, fly to their location and punch em in the face08:49
eagles|workya i am waiting to get an email back with contact number08:49
WalterNmeh08:50
WalterNjust launch ICBM with IP seeker firmware installed08:51
WalterNmake sure its not pointing to lo ;)08:51
qman__only two approaches there, get the ISP to drop the packets, or give you a fatter pipe08:52
twbIP address doesn't incidate elevation, which is critical for a targeted ICBM strike08:52
twb*indicate08:52
mase_wkqman__: i get hundreds of emails a day offering me a fatter pipe... =)08:52
WalterNtwb: a contact fuse would work, though yeah.. elivation would make it more ideal :P08:52
WalterNelevation*08:53
eagles|workqman__: whats funnier if you look at the internal ip which is assigned by router dhcp08:53
eagles|workthe ip they are attacking is the ip of my laptop08:53
twbSo, fun fact that I learned today08:54
twbIf localhost doesn't resolve, hardy won't enable NFSv308:54
twbIt'll silently fall back to NFSv208:55
eagles|worki have another question related to this if im setting up a firewall machine that will take the incoming connection on one nic route it to the 2nd nic and the internal network08:55
eagles|workdo i need to put the proxy on the server hosting the website or on the firewall server?08:56
twb"routing" isn't done by a firewall08:56
eagles|worktwb: i know but one of the nic cards in this other machine will be directly connected to the external connection08:57
eagles|workthe other to the internal network08:57
eagles|workmy question is more on which machine should the proxy be08:57
eagles|workthe one that has the firewall08:57
eagles|workor the server on the internal network08:57
twbproxy for what?08:57
eagles|workweb proxy08:58
eagles|worklike squid08:58
eagles|workas well as i want to provide some content filtering08:58
twbIf you're masquerading and not using -j TPROXY or -j DNAT, you'll need a proxy on the masquerading device.08:59
eagles|work!masquerading | eagles|work08:59
twbEr, that is, for exposing a local service to the internet.08:59
eagles|workgotcha08:59
twbIf you're just talking about providing a conventional caching HTTP proxy to browsers on the local network, squid can be deployed anywhere09:00
eagles|worktwb: this is going to need to be on the masquerading device as its also access by people on the outsdie09:00
eagles|workwould content filtering go on the masquerading device too09:00
twbFiltering of what content, from whom?09:01
=== maxb_ is now known as maxb
eagles|worktwb: like porno graphic content etc09:01
eagles|workfrom the internal network09:02
eagles|workim at a clinic and im working on providing wifi to the whole place09:02
eagles|workwifi with content filtering09:02
eagles|workbtw qman__ if your interested this is the router security log http://pastebin.com/Yhzg3wWx09:02
twbUnless you're operating a "default deny" policy, you won't block pornography.09:03
eagles|worknot even if i use dansguardian09:03
twbLet me rephrase: you won't block ALL pornography.09:04
eagles|workits better most then nothing09:04
twbWell, I can't comment on "most", but if that's your position then by all means adopt a "defalt allow" and a blacklist.09:05
eagles|workarent there some web based content filter where you tell the filter certain keywords are blocked etc09:05
qman__yes, but they're quite terrible and only marginally effective09:06
qman__nothing wrong with the software itself, the idea is flawed09:06
eagles|workok09:06
qman__whitelisting is the only truly effective way09:07
eagles|workok but using what something like dansguardian09:07
twbAFAIK dansguardian is just a blacklist and a squid hook.09:08
eagles|worktwb: ok09:11
eagles|workand i officially hate my isp09:11
eagles|workthey giving me the whole rubbish of they cant ddo anything09:11
eagles|workand only thing i can do is on my end with a firewall09:11
eagles|workand if they continue to contact the police09:11
twbqman__: the other one that screwed me at a prison was that they whitelisted google --- which happens to include all google's "cached page" pagse09:13
qman__yeah...you need to be a lot more specific than that09:13
twbReally the problem is the prison staff can be... not too bright09:14
huatsmorning09:49
eagles|workhey guys is it possible for a multicast to flood a connection?09:55
=== Barre_ is now known as Barre
frouddual nic. eth0 and eth1. eth0 connects to public internet. eth1 connects to GSM router. GSM router has Port Forwarding to eth1. eth0 has a gw defined, eth1 does not. ip_forwarding is enabled. If I ping eth1 from the GSM network I get answer,.if I ping eth1 from the GSM network I get no answer. Anyone good with routing that can help?10:06
_rubenwoah .. rereads it a couple of times10:06
froudlol10:06
_rubenhow about a nice diagram? ;)10:07
eagles|workfroud: you have a router involved in ur setup10:07
eagles|workand u want one nic directly on the internet right10:07
froudeagles|work: yes eth0 is on the internet10:07
froudeth1 connected to a BR970 GSM router10:08
_rubenweit .. your message is wrong: you're saying that pinging eth1 from GSM network does both work and not work10:08
eagles|workwell u could connect eth0 to the router10:08
_rubens/weit/wait/10:08
eagles|workbut then put eth0 on the dmz of the router directly exposing it to the net that way10:08
_rubenand also quite importantly: what are trying to achieve?10:08
froudokay here goes slowly10:09
froudeth0 <-> eth1 <-> GSM10:09
froudeth0 is public and available10:09
froudI can ping it10:09
eagles|workfroud: you want to route traffic from 0 to 110:10
froudeth1 is connected to a switch port on the GSM router10:10
eagles|workfroud: man route btw might help10:10
froudGSM router SIM gets IP 10.0.0.110:10
froudEth1 got 192.168.1.210:10
eagles|workyou are on entierly different subnets for one10:11
froudOn GSM host at 10.0.0.3 I can ping 10.0.0.110:11
froudbut I cannot reach 192.168.1.210:11
eagles|worketh1 needs lets say 10.0.0.0.4 for example10:11
eagles|workfroud: the ip is on a differrent network segment all together10:11
eagles|workbrb from laptop10:11
froudeagles|work: yes but the subnets are joined by router GSM10:11
froudeth1[192.168.1.2] - GSM ROUTER - 10.0.0.110:12
eagles0513875back10:13
* eagles0513875 shakes head froudeth1 has to be a 10.0.0. ip though10:13
froudeagles0513875: why the B970 does routing10:14
froudIf I route add default gw 192.168.1.2 to the server I can ping eth110:15
froudfrom 10.0.0.310:15
_rubendoes the gsm router have a router for 192.168.1. network and does your machine have a route for the 10.0.0. network ?10:15
froudbut then I will lose the eth010:15
eagles0513875humm10:15
_rubenhave a route meant10:15
_rubeni meant10:15
_rubengeesh, must be friday10:16
froud_ruben: default admin interface of router is 192.168.1.110:16
froudI think what I need to do is add some route that will send traffic detined for 10.0.0.0 via eth1 and not eth010:17
froudbut I am not sure how10:17
froudmy route knowledge is not that good :-)10:17
_rubenip route add 10.0.0.0/24 via 192.168.1.1 dev eth110:17
froudinvalid argument10:19
* froud goes to pastebin10:23
alex88oh..is there a ip command? i've always use route directly..10:29
=== oCean__ is now known as oCean_
oCean_ip is from 'iproute2', you could even add additional routing tables/rules10:30
alex88oCean_: i've seen the help..is a more complete command including also route10:30
alex88if i've seen right10:31
froud_ruben: http://pastebin.com/gdX2tUXn10:31
froudeagles0513875: http://pastebin.com/gdX2tUXn10:31
* froud needs to step away for 5 mins, nature, brb10:31
AlexC_morning10:40
AlexC_when setting up a chroot for SSH, it all seems very, very mesy. I mean - what happens when updates come in for the files you've had to copy across into your chroot?10:40
AlexC_I can't think of any sane way for a sysadmin to monitor which files and copy the new ones over. Surely there has to be a simpiler way, such as with SSH using SFTP - you can simply use the internal-sftp and chroot users, done.10:41
* eagles0513875 loves sftp so easy to setup compared to ftp10:42
* froud is back10:42
AlexC_indeed, FTP shouldn't be used really - such a crap protocol. However, that's a different discussion :P10:43
eagles0513875ya sry10:44
eagles0513875never worked with a chroot much AlexC_tbh so i dunno what to tell ya10:44
eagles0513875dealing with my own issues atm here at work10:44
AlexC_it's quite shocking really that such thing is so ... complicated to do, really10:44
\shAlexC_: why copy? hardlinking is a good way to go10:45
\shor softlinks if that works...10:45
AlexC_\sh: hum, all guides/references that I've seen said to copy. I didn't think it was possible to link them due to the path changes10:46
AlexC_to a person not in a chroot, the links will work. But how would it work for a user in the chroot if they can't access above their chroot, which is where the real files would be10:47
a_okis ther a known problem with logrotate in ubuntu 8.04 or am I mistaking in my configuration?10:48
AlexC_a_ok: how do we know you're making a mistake, when you tell us no problem?10:48
a_okthe files seem to be created with different rights (at random) and it does not seem to rotate daily properly10:49
a_okAlexC_: http://pastebin.com/BXVQx3Hi10:50
a_okAlexC_: as you can see /var/log/mail.log.6.gz modified date is wrong (checkt the content and it has entries of 1-8)10:51
AlexC_a_ok: not sure, only thing I can think of - is there another logrotate script using the same file?10:52
a_okchecked the configuration10:53
a_okno duplicates10:53
a_okAlexC_: there is only one logrotate installed. is there some other package that does rotating (perhaps sysklogd???)10:56
a_okand why is there an uncompressed file called /var/log/mail.log.0 ?10:57
AlexC_a_ok: that's normal, it'll become .1.gz upon next rotate10:58
AlexC_a_ok: however, one thing - why do you want your log files writable?10:58
AlexC_440 would do me10:58
a_okbut today its the 13th, and last change on mail.log.0 is the 8th...10:59
AlexC_ah, simple10:59
AlexC_your server has become aware it is 'Friday' and also the '13th'. Therefor, let it run wild and see what happens tomorrow11:00
a_oklol11:00
a_okAlexC_: don't need it writable actually in this case as syslog writes to it but its the default setting for all my logfiles11:01
a_okbe right back11:01
\shAlexC_: regarding http://ulf.zeitform.de/de/dokumente/sshchroot.html you can use hardlinking without any problems (sorry is in german but I think google will help to translate ;))11:12
AlexC_\sh: interesting, thanks :)11:15
uvirtbotNew bug: #617127 in eucalyptus "CacheConcurrencyStrategy should be READ_WRITE and not TRANSACTIONAL" [Undecided,Fix committed] https://launchpad.net/bugs/61712711:36
demon1981Hi! Where I can look for kernel boot param line in grub2?11:49
a_okAlexC_: there are some default settings in logrotate.conf (the toplevel config file instead of stuff in logrotate.d) like a weekly rotate and keeping it for 4 weeks11:49
a_okcould that be the problem11:50
a_okdemon1981: /boot/grub/grub.cfg11:50
a_okAlexC_: I noticed that the day's that are off are all sunday's11:50
a_okits like it does not rotate those files11:50
demon1981a_ok: grub.cfg seems as script file. how I can compile from it result params string? is it possible?11:51
a_okdemon1981: erm its just a config file. if you scroll down a bit you should see the kernel line11:53
a_okno compilation11:53
demon1981a_ok: I dont see here video params Where I can take those params? I want to decrease framebuffer frequency linux   /boot/vmlinuz-2.6.32-21-generic-pae root=UUID=c8b6c463-c05f-4f76-9a17-3d6d5b282d95 ro quiet initrd  /boot/initrd.img-2.6.32-21-generic-pae12:01
demon1981a_ok: this is line from /etc/grub/grub.cfg12:01
a_okthose are two lines i think12:03
a_okyou can edit the line starting with:  linux   /boot/vmlinuz-2.6.32-21-*12:04
demon1981a_ok:yes. it's 2 lines. if in kernel options we dont see video options then those options takes from other place. From what conf are they  takes? (I use nouveau framebuffer)12:31
hggdh<yawn/>12:31
Davieyhggdh: GOOD MORNING!12:46
Davieyhggdh: Thanks for your email last night.12:46
hggdhDaviey: Good morning12:51
Davieyhggdh: How are you this fine day?12:53
hggdhDaviey: so far I am fine... and I hope I will be able to find out what gives on the test rig12:56
Davieyhggdh: I have a PPA package enroute, but also expecting a new code drop to resolve a potential registration issue12:57
hggdhDaviey: right now I will try anything ;-)12:59
Johnnyxhey guys package dovecot-postfix contains full mailserver ready to run ? some kind of easy pack to install? am i right?13:11
zulmorning13:28
=== RoAkSoAx_ is now known as RoAkSoAx
uvirtbotNew bug: #617053 in eucalyptus "on upgrade from 1.6.2, euca_upgrade should preserve DISABLE_ISCSI="Y"" [Medium,In progress] https://launchpad.net/bugs/61705314:01
hggdhhey Daviey, what was the URL for the wget on wrappers.conf?14:15
hggdhcannot find the email :-(14:16
uvirtbotNew bug: #617380 in munin (main) "Add apt_ubuntu plugin" [Undecided,New] https://launchpad.net/bugs/61738014:16
=== dendro-afk is now known as dendrobates
Davieyhggdh, Ah, you are back - i just mailed you the wget line14:25
hggdhDaviey: sorry, weechat had a moment here14:26
Davieyhggdh, heh14:27
jetole_Does anyone know how I can implement watchdog on Linux / Ubuntu Server and also find a list of which watchdog hardware is supported14:39
=== jetole_ is now known as jetole
jdstrandin order of request:14:48
jdstrandhallyn, Daviey, soren: I uploaded libvirt 0.8.3-1ubuntu1 yesterday. this morning I uploaded 0.8.3-1ubuntu2 to fix a ftbfs on armel, but I'm not planning other uploads (excepting an emergency), so have at it14:50
Davieyjdstrand, Super, i just wanted to test it - soren wanted to add a patch14:50
DavieyThanks jdstrand !14:50
jdstrandsure :)14:50
Davieyjdstrand, Have you documented the merge?  It seemed pretty intense?14:51
jdstrandDaviey: in the changelog (as per standard practice)14:51
DavieyGood Point Well Made.14:51
jdstrandDaviey: most of those patches have comments at the top. I didn't write most of those, but tried to make them DEP-3 when I could find the history14:52
Davieyjdstrand, Ok.. thanks.. i'll read the changelog14:52
jdstrandDaviey: I also try to put in the changelog when I expect something to be able to be dropped, to help with future merges14:52
Davieyjdstrand, We'll keep you! :)14:53
jdstrandheh14:53
v00lcanoguys, I have a newly installed 10.04 machine and am trying to follow this guide: https://help.ubuntu.com/community/LDAPClientAuthentication however there are looooots of inconsistencies, for example it asks to restart nscd but I have no /etc/init.d/nscd, also my /etc/libnss-ldap.conf is missing and I can't seem to find it anywhere else (updatedb && locate), I've found a libnss-ldap.conffiles in doc, but that just mentions /etc/init.d/libnss-ldap. Is15:00
v00lcanoI know it's not a server-related issue, but someone in #ubuntu recommended I ask here since you guys might be more up to date on this matter15:01
sherrv00lcano: there's a libnss-ldapd package. Might be something you want. There's also a libnss-ldap package ... a bit confusing. The fisrt appears to be a fork of the second.15:16
hggdhDaviey: shouldn't eucalyptus-*-publication be stopped when you 'sudo stop eucalyptus'?15:26
hggdhDaviey: and shouldn't they be started when you (later on) 'sudo start eucalyptus'?15:27
Davieyhggdh, technically yes - i haven't tried that15:30
hggdhDaviey: before I open a bug there -- can you try it?15:30
Davieyhggdh, Hmm15:30
Davieyyes i can :)15:30
Davieyhggdh, I am prepairing an upload now btw15:31
hggdhDaviey: also, what images did you use on your tests yesterday night (rather, today very early)? Current Maverick UEC ISO?15:31
hggdhDaviey: cool!15:31
* hggdh awaits happily15:31
Davieyhggdh, netboot, from archive.ubuntu.com15:31
Davieyso whatever was in the archive at that time15:32
hggdhDaviey: no, for the VM images15:32
Davieyoh..15:32
Davieyi used what was on uec-images.ubuntu.com15:32
jetoleCan anyone help me out with how I configure watchdog on ubuntu server?15:33
hggdhDaviey: the dailies, then, correct?15:33
Davieyhggdh, you expect, avahi-publish -s Walrus _eucalyptus._tcp 8773 txtvers=1 protovers=1.5.0 type=walrus ipaddr=10.0.0.100 <-- to be killed?15:33
hggdhDaviey: yes indeed15:33
hggdhwy publish something that is currently dead?15:34
hggdhjetole: I never used whatdogs, sorry15:34
ssureshotany experts on load balancing here today15:34
Davieyhggdh, CLC avahi went - still waiting on Walrus15:34
jetolessureshot: depends. Whats your question?15:34
Davieyhggdh, confirmed, walrus didn't go - this was on a CLC + Walrus box15:35
DavieyCLC did die15:35
ssureshotjetole: I have 2 servers setup and functioning with heartbeat / ldirectord all services set up that I need... My question is this.. When I turn on the backup load balancer first it doesn't transfer the server to the primary once it is turned on.. Is this normal?15:36
jetolessureshot: what is the backup load balancer?15:37
ssureshotbut if I turn the primary on first have the talking unplug primary services transfer accordingly and they transfer right back when I plug it back in15:37
ssureshotjetole: ubuntu 9.10 server15:37
Davieyhggdh, Hmm.. raise a bug - and i'll confirm it on a fresh box15:38
Davieyhggdh, Feel free to assign it to me,. and i would say Medium priority.. agree?15:38
jetolessureshot: how are you load balancing though? Are you using ipvs, haproxy or something else?15:38
ssureshotoh ipvs15:38
smoserhallyn, around ?15:38
jetolessureshot: I don't know. I have been meaning to switch to IPVS for a few months, I currently use HAproxy however I would ask this question in... what was that room? One sec15:39
jetole#linux-cluster15:39
hggdhDaviey: hum. Low should be fine15:39
jetole#linux-ha15:40
ssureshotjetole: awesome thank you sir15:40
jetolethose two rooms are really good when it comes to IPVS15:40
jetolessureshot: no prob15:40
Davieyhggdh, agreed15:40
resnoim planning on setting up a server to play with. what is the recommended intrusion detection software? snort? munit and mungin?15:42
zashresno: I use sshguard i think15:43
jetoleresno: suricata15:43
aljosai can't find truecrypt in lucid althought there are gui tools for truecrypt available. any idea why truecrypt isn't available in lucid?15:43
resnozash: heh you think ;)15:44
jetoleresno, used to be snort but afaik snort is... how do I put this? I guess snort isn't really being developed as actively anymore15:44
jetolesnort 3 seems to have been on the back burner for far too long15:44
resnojetole: ah, darn out of date information :(15:45
jetoleresno: suricata is a fork of snort created by The Open Information Security Foundation15:45
jetoleresno: http://www.openinfosecfoundation.org/index.php/download-suricata15:45
jetoleresno: actually, not a lot of people really follow snort closely enough to care so some people, in fact most people will still recommend snort15:46
resnoi see. im curious to see how much of my playing will register on it, etc15:46
jetolethe current snort release is 2.8.6.1 and, if I remember correctly, almost two years ago 2.8 was still being used and if I remember correctly, almost 2 years ago snort 3 was announced as the upcoming snort15:47
resnoheh nice15:47
jetoleresno: Well with both snort and suricata, you can always create custom rules plus some of the best rules don't come from snort. I think bleeding edge rules is the big one15:48
jetoleI would use oinkmaster to download the snort rules and the bleeding edge rules and write a rule for anything you can find that doesn't register15:48
resnojetole: this mainly will detect attacks not block them right?15:48
zashresno: I thougt that was what it was called, and it was15:48
jetoleresno: well that depends on you15:49
jetoleboth snort and suricata can be compiled as an IDS or IPS / detect or block15:49
jetolethe blocking is done via NFQUEUE via netfilter and iptables15:49
jetoleresno: but I would strongly recommend against blocking15:49
jetoleIPS can be very dangerous15:50
jetolea false positive can block legitimate users15:50
jetoleit's better to do IDS and analyze the results15:50
resnojetole: yes, ive read15:50
jetoleAlso, with either snort or suricata, I would recommend the unified2 format and the barnyard 2 utility15:52
jetolefor front ends, you can look at BASE, Aanval or prelude prewikka15:52
resnojetole: thats quite a bit of information to get me started :)15:53
keltwhat is wrong with IPS blocking legitimate users?15:54
jetolekelt: It's too much work when you can just turn the server off to block legitimate users15:55
resnolets just suppose i blocked myself, how would you get back in?15:55
jetoleI find the poweroff command is quicker and easier then bothering with rules if I don't want people to access a service I am running. Plus you have the wasted time of developing and running a service that you don't want anyone to access15:55
jetoleresno: afaik, the system works on a per match basis for example if you block fragmented packets and you send a fragmented packet then that packet is blocked however if you don't send a fragmented packet then it will go through15:57
jetolethats in theoreom, clearly you will have more rules then that15:57
resnooh ok15:57
mathiazkirkland: o/15:57
jetolenow if you wanted to have matches block all further attempts to connect then I would advise you look into the iptables/netfilter recent module15:57
keltjetole: IPS only blocks "bad" things not everyone like powering off a system would do15:58
jetolefor example, through iptables/netfilter, I can write a couple rules so that if I get 50 syn packets from a host in a minute then that host is blocked for an hour15:58
jetole10:54 < kelt> what is wrong with IPS blocking legitimate users?15:58
jetolekelt: and no. An IPS blocks based on rules. If you have a rule which mis catagorizes a packet as an attack when that packet is really from a customer placing an order then you just lost a sale15:59
jetolekelt: Just to be clear, legitimate users are people who should be there. If you are wondering whats wrong with blocking people who should be there then turn your server off and save yourself the time of setting it up in the first place let alone configuring an IPS system16:00
jetoleand kelt: "IPS is bad" is the widely agreed upon frame of thinking for any IT security professional in the industry. In fast in any company of the right size, you have levels of security analysts who look at records from IDS and promote it to higher levels if it is suspicious hence why they have options like that built into both free and commercial IDS systems16:01
uvirtbotNew bug: #617428 in samba (main) "winbind_cache.tdb corrupt" [Undecided,New] https://launchpad.net/bugs/61742816:01
jetole"the right size": poor choice of words on my part. I meant any company that is profitable enough that they can afford to do security analysis properly16:02
jetolebbiab: going for a smoke16:02
resnojetole: so, even with these levels of ids, fail2ban is still important?16:02
keltjetole: if you have an attack that brings down your website that IPS could have prevented... then you lost 100 sales.16:03
patdk-wkheh, jetole, you mean like vonage, when they contacted me to stop hacking them over port 123, when vonage was using my server for ntp16:03
jetolekelt: if you have an attack that brings down your website that an IPS could have prevented then you have an attack that you are readily aware of that you did not patch or you are trusting 3rd party sites to supply IPS rules that you do not analyze so either you are not maintaining your servers in the first place or you are allowing for a high rate of false positives16:09
jetoleresno: I don't use fail2ban. If you are referring to ssh I run it on a alternate port and only use ssh keys as well as iptables rules to limit syn connections within allowed times so if I receive a certain number of syn packets consistantly to my ssh port then they are blocked at the firewall as well as that host from all further communication for the time I set in the recent module16:11
jetolepatdk-wk: that sounds like vonage16:11
patdk-wkatleast the guy that called was helpful16:12
jetolepatdk-wk: why were they using your NTP server?16:13
patdk-wkI dunno16:13
patdk-wkthey said they had a new admin setting up systems16:13
jetoleha16:13
patdk-wkand it sounds like they just left the default settings to use the pool.ntp.org16:13
jetolemakes sense16:13
jetoleyou run a pool.ntp.org server?16:14
patdk-wkya, several16:14
jetoleah that makes sense16:14
jetoleyeah, I use a default us.pool.ntp.org as one of mine16:14
jetoleafter two nist ones16:14
patdk-wkI never use nist16:14
patdk-wkeverytime I have checked it, I get horrible results from it16:15
jetolewell I have had good luck with ntp.org but it's user run16:15
patdk-wkdunno if they fixed it recently16:15
* jetole doesn't know16:15
jetoleaside from ntp.org, who do you recommend16:15
jetole?16:15
patdk-wkheh, well, back when I checked it, 5+ years ago, it felt like it was on a t1, with t3 amount of traffic attempting to use it16:15
jetoledhcpd.conf: option ntp-servers time-a.nist.gov, time-b.nist.gov, us.pool.ntp.org;16:15
patdk-wkI run my own ntp cluster16:16
patdk-wkso all my servers us my own pool16:16
jetoleI don't know if thats the case now but I monitor NTP via nagios and I don't often get alerts but I don't know off the top of my head how thats checked16:16
patdk-wkthe cluster heads, use some static and pool servers to help round them out16:16
jetoleI gotta get back to trying to figure out how to use watchdog with a hardware timer in linux16:16
jetoleeverywhere I have looked so far has directed me towards the software watchdog daemon16:17
jetole:(16:17
patdk-wkhmm, watchdog just worked for me, using an old scb2 motherboard :)16:17
jetoleWell I run a virtual cluster and want to set it up on the virtual machines but I had a bad experience once with a harware timer in a super micro board16:18
jetoleso I'm being cautious16:18
jetoleI know the watchdog package in ubuntu has nothing to do with physical watchdog16:18
patdk-wkhttp://buttersideup.com/docs/howto/IPMI_on_Debian.html16:19
patdk-wkall my watchdogs are ipmi16:19
patdk-wkall my server motherboards are currently intel though16:19
jetoleafaik, this watchdog is PCI16:20
jetoleit is intel, one sec, looking for the page that desribes it again16:20
jetolehttp://libvirt.org/formatdomain.html#elementsWatchdog16:20
jetoleIf you scroll down to model16:20
jetole'i6300esb' — the recommended device, emulating a PCI Intel 6300ESB16:20
patdk-wkoh, a vm watchdog16:20
jetolewell yes but it emulates the Intel 6300ESB16:21
jetoleso the vm guests see the Intel device16:21
jetolepatdk-wk: this looks promising: http://lkml.indiana.edu/hypermail/linux/kernel/0502.2/0908.html16:22
patdk-wkheh, dunno16:22
patdk-wkI haven't used kvm16:23
patdk-wkbeen using xen, but switching to vmware16:23
patdk-wkthe whole xen -> kvm switch thing really annoyed me16:23
jetoleI used to use ESX 316:24
jetoledidn't find it fast enough16:24
jetoleand Xen has always been the bain of my existance. I still have a few Xen hosts16:24
patdk-wkall my stuff is esxi 4.1 now16:24
jetoleI loathe them16:24
jetoleCONFIG_I6300ESB_WDT=m16:24
jetolethats from the 10.04 kernel config so it's a module and just found this page with an explanation: http://cateee.net/lkddb/web-lkddb/I6300ESB_WDT.html16:25
jetolepatdk-wk: I'm personally quite happy with KVM. I didn't like ESX 3 and loath Xen but I haven't tried ESX 316:25
patdk-wkI have never used esx 3.516:26
patdk-wkattempted to use hyperv for a windows cluster16:26
patdk-wkbut the windows guests had tcp issues, for one 3rd party app16:26
patdk-wkwebserver would get request headers, but response would never make it out of hyperv16:27
jetolenever tried hyperV and I really don't want to16:29
patdk-wkI didn't either16:29
patdk-wkbut the server already had win2008 on it, and I needed 4 vm's16:29
patdk-wkso figured, why not16:29
patdk-wkand the 3rd party vender said it would be fine16:29
patdk-wknot so much16:30
jetolehaha16:32
jetoleyeah all my windows2008 are VM themselves on KVM via libvirt16:32
patdk-wktook the hyperv image, moved to vmware, worked perfectly16:32
jetoleyeah I remember migrating vmware esx images to kvm16:33
jetoleoh btw, as per watchdog, I remember that Xen had a proposed watchdog spec that they chose not to accept16:35
Kaeltenanyone know what boot option to pass in to install in textmode?16:55
patdk-wkit doesn't?16:55
patdk-wkoh, heh, I always net-install, so it's always text for me :)16:56
Kaeltenpatdk-wk: I'm net installing16:59
Kaeltenor is the annoying blue blocks everywhere the textmode?16:59
patdk-wkannoying blue blocks?16:59
patdk-wkyou mean color ascii stuff?16:59
Kaeltenpatdk-wk: http://grab.by/5Tgj17:00
Kaeltenthat thing17:00
zashKaelten: that is text mode17:00
Kaeltenah, k17:00
Kaeltenwas wondering if there was something less than that17:00
patdk-wknope :)17:01
patdk-wkmaybe a black/white version? :)17:01
KaeltenI'm testing in hyperv and it's driving me nuts because the redraw rate is so slow17:01
patdk-wkthat is hyperv issue17:01
patdk-wkhyperv is using graphics mode, even though the video card in the vm is in text mode17:01
Kaeltenadding "blacklist vga16fb" to modprobe.d/blacklist-framebuffer.conf fixes it17:02
Kaeltenbut that doesn't help me in the installer17:02
uvirtbotNew bug: #617461 in mysql-5.1 (main) "mysql-testsuite: testsuite fails due to unexpected installation layout" [Undecided,New] https://launchpad.net/bugs/61746117:06
uvirtbotNew bug: #617463 in mysql-5.1 (main) "mysql fails to load innodb plugin due to apparmor rejection." [Undecided,New] https://launchpad.net/bugs/61746317:06
JhonHola buenos dias17:11
Kaeltenanyone have any experiance with ubuntu and a QLogic 2560?17:11
JhonNecesito sugerencias osbre servidores17:12
Jhonpodria ayudarme17:12
=== RoyK^ is now known as RoyK
patdk-wkkaelten, nope, only using ubuntu with a qlogic 220017:13
Kaeltendid the kernel support it ok, or am I looking at something scary?17:13
Jhonse habla español aki o ingles?17:13
patdk-wkyep17:14
Kaeltenno habla español :(17:14
patdk-wkperfectly17:14
Kaeltenthat's good news, we have a fabric/storageworks from hp, but the hba's look like rebranded qlogics17:14
Kaeltenand I'm thinking they're 2560s but I'm not certain17:14
Kaeltengoing down week after next to set it up, so trying to at least have an idea17:15
patdk-wkqlogic has always been well supported17:15
patdk-wkI'm pretty sure it's direct support from qlogic17:15
Kaeltenthat's good to hear, I know hp mainly offers support for rehl and suse,17:16
Kaeltenbut I'm stuck in my ways on using ubuntu17:16
uvirtbotNew bug: #617466 in samba (main) "package samba 2:3.3.2-1ubuntu3.5 failed to install/upgrade: el subproceso post-removal script devolvió el código de salida de error 1" [Undecided,New] https://launchpad.net/bugs/61746617:17
Jhonpor que si hablan español17:19
Jhonhablan en ingles17:19
resnoJhon: porfavor hables en ingles aqui17:22
resnoJhon: hablamos ingles solamente17:23
Jhonhablan solo ingles aki en la charla????17:23
resno!es17:23
ubottuEn la mayoría de canales de Ubuntu se habla sólo en inglés. Si busca ayuda en español o charlar entra en el canal #ubuntu-es. Escribe "/join #ubuntu-es" (sin comillas) y dale a enter.17:23
Jhon:( ok es que yo casi no entiendo ingles17:24
resnoJhon: lo siento.17:25
* RoyK is building a "Lord Vetinari clock" to a friend of mine (like the one Vetinari has in his waiting room - it ticks unevenly, tick, ... tock .. ticktock ..... tick ... tock17:25
Jhonde todas maneras gracias17:25
resnoJhon: hasta luego17:25
RoyKresno, Jhon: kan ikke dere snakke engelsk? jeg forstår ikke et ord17:25
FunnyLookinHatOk guys - super strange issue - I have a cron'd PHP script that runs mencoder to rotate videos...  when I run the script as myself, i.e. php script.php - mencoder works fine.... but when cron runs the script as root, mencoder only converts the first second of the video - ideas???17:34
Kaeltennow if I could only figure out why my netinstall has a messed up hostname17:34
patdk-wkFunnyLookinHat, bad path setting? it can't locate the audio encoder?17:35
RoyKKaelten: just change it :þ17:35
KaeltenRoyK: I was hoping to be able to set it via the dhcp server17:35
kirklandmathiaz: o/17:36
patdk-wkI think it's storming outside17:36
patdk-wkmy ups is going nuts17:36
patdk-wknope, clear skys, how odd17:36
Kaeltenpatdk-wk: how do you handle hostnames with your netinstalls?17:37
patdk-wkI just type it in, during the install, when it asks for it :)17:37
patdk-wkreally rather difficult17:37
Kaeltenah, so you're not doing unattended17:38
patdk-wknope17:38
FunnyLookinHatpatdk-wk: How would I fix that?  I mean - ldconfig should take care of the audio encoder, etc. right?17:38
patdk-wkFunnyLookinHat, what does ldconfig have to do with it?17:38
patdk-wkthat is to locate lib's17:38
patdk-wkI dunno how mencoder works17:38
FunnyLookinHatWell ok - better question - why would it ONLY happen as root and not the user account ?17:38
RoyKKaelten: no, but you can with reverse dns17:39
patdk-wkbut normally the issue is always path related, if something doesn't work right in cron17:39
FunnyLookinHatkk17:39
KaeltenRoyK: ?17:39
RoyKubuntu looks up its hostname in dns17:39
RoyKif none is found, it defaults to ubuntu (iirc)17:39
Kaeltenmine seems to be defaulting to kickseed17:40
mathiazkirkland: mumble?17:40
kirklandmathiaz: k, let me grab a headset17:41
FunnyLookinHatpatdk-wk: more confusing - if I run the script as root, all is fine... if I let cron run it, cuts off at 1 sec.17:46
_rubenthat's usually an environment and/or tty problem17:52
FunnyLookinHatkk... great.  that's even a bigger problem to debug :)17:54
patdk-wkthere are hundreds of google hits for mencoder and cron17:57
patdk-wkall kinds of people having issues17:57
patdk-wklooks like strictly a env issue :)17:58
patdk-wkhttp://serverfault.com/questions/95729/difference-of-running-scripts-manually-or-with-a-cronjob17:58
zashPATH probably17:59
zashand PWD17:59
patdk-wkI said that hours ago :)17:59
zash"use absolute paths"18:00
zashpatdk-wk: then someone didn't listen/read :P18:00
FunnyLookinHatYeah I do use absolute paths, all the time, of course :)18:03
patdk-wkjust cause you do, doesn't mean the program does also :)18:03
FunnyLookinHathah true.18:04
FunnyLookinHatbastard of a program is erroring out with some random dependency...  I fixed one (was missing a random font file, which threw an error message but allowed it to keep running) - but now it's erroring out at a different point, hah18:05
* patdk-wk is it sad, I install japanese fonts, to find a good english font I like for ssh18:06
=== dendrobates is now known as dendro-afk
FunnyLookinHatlol?18:07
FunnyLookinHatHow do I get a bash script to include/source specific include files ?18:16
zashFunnyLookinHat: source path/to/script.sh18:19
FunnyLookinHatzash: thanks18:22
zashFunnyLookinHat: and . path/to/script.sh is equivalent18:23
gnoobHi,  anyone knows about a good way of making infoscreens? Is there any preconfigured distros out there?  Would like to have e.g two terminals. tty1 for administration from shell and tty2 for X where impossible to log on.  tty2 shows a buch of web pages from a spesific folder..  Anything like this out there? :)18:26
patdk-wkgnoob, dunno of anything, but sounds like something that only takes a few min to make18:27
gnoob:)  would take me a minimum a couple og hours I think :)18:32
hallynsmoser: was flyin'.  wazzup?18:46
Davieyhggdh, Hey.. have you had a chance to try the packages from today?18:47
Davieyhggdh, i see you have \o/18:47
smoserhallyn, i have a fun bug for you18:47
smoserhttps://bugs.launchpad.net/ubuntu/+source/qemu-kvm/+bug/61552918:47
uvirtbotLaunchpad bug 615529 in eucalyptus "eucalyptus instance reboot fails: Guest moved used index from 0 to 2639" [Medium,Fix released]18:47
FunnyLookinHatSo tell me this - I ran set > setopts and then included . /path/to/setopts within a wrapper bash script - still no luck, does that mean it isn't an ENV variable issue ?18:50
hggdhDaviey: I still see some instances failing to start18:53
Davieyhggdh, In what topology?18:53
hggdhDaviey: right now all-in-one, 170 started, about 6 failed18:54
hggdhthis run should end in ~15 minutes, and I will then test volumes, then test distributed18:54
Davieyhggdh, OK.. Those numbers are *awful*.. better than Lucid release!  But i think that is a seperate bug to the one that has been fixed.18:55
Davieyerm, AREN'T awful. i mean;t to say18:55
RoyKDaviey: sorry to barge in, but what numbers are these?18:56
DavieyRoyK, Instances not starting when requested with UEC.18:58
gnoobpatdk-wk: for a hommade "info screen project"  What should I do to start showing html pages automaticly after the automated login? Ill be able to start firefox, but cant see how to start firefox in fullscreenmode switching between htmlpages with e.g 30 second delay. Is firefox scriptable? of is there another tool I should use maybe?18:59
hggdhDaviey: I agree, the signature seems different19:00
patdk-wkmaking firefox reload on 30seconds doesn't even need firefox, just use a refresh in the html page :)19:00
hallynsmoser: that's not an easy bug to follow, but iiuc you're saying booting from floppy is not working as a workaround in uec?19:02
hallynhave you chatted with Daviey about it?19:02
smoseryes, in the end it looks like the work around doesn't work as i thought it did.19:03
hallynI've not really used uec (other than as user of ec2) so not sure how to reproduce myself19:03
hallynsmoser: the bug never says what happens now.  does reboot fail?19:04
smoseri haven't actually tested on eucalyptus, (and I did test the work around there). it seems like it may not be 100% failure rate, and i got "lucky"19:04
smoseryes, in my local tests, reboot fails the same way.19:04
hallynso the first boot works, and reboot fails?19:04
smoseryes.19:04
smoseri'm working on getting an easier recreate together.19:05
hallynok19:05
uvirtbotNew bug: #617515 in openssh (main) "/etc/init.d/ssh stop doesn't work (sshd just won't die)" [Undecided,New] https://launchpad.net/bugs/61751519:06
gnoobpatdk-wk: sorry the noobing, but I dont think I understood how.  If I have a couple of html pages I want to be shown on info screen, and I want all pages to be shown and each one for 30 secs, before looping :)  Is this easily done?19:09
RoyKuvirtbot: pastebin19:11
uvirtbotRoyK: Error: "pastebin" is not a valid command.19:11
=== dendro-afk is now known as dendrobates
RoyKuvirtbot: pastebin?19:12
uvirtbotRoyK: Error: "pastebin?" is not a valid command.19:12
RoyK!pastebin19:12
ubottuFor posting multi-line texts into the channel, please use http://paste.ubuntu.com | To post !screenshots use http://tinyurl.com/imagebin | !pastebinit to paste directly from command line | Make sure you give us the URL for your paste - see also the channel topic.19:12
RoyKshouldn't ubottu be in #ubuntu-virt as well?19:12
kman_Hi all.  Anyone able to assist with getting a network card working in Ubuntu Server?  Can see it using lspci but not talking to the network.19:18
RoyKkman_: doesn't ifconfig -a show it?19:20
kman_Royk yes it shows there as well.19:21
RoyKkman_: if ifconfig -a shows the nic, just edit /etc/network/interfaces19:22
kman_OK will try.19:23
RoyKkman_: https://help.ubuntu.com/8.04/serverguide/C/tcpip.html is good reading :)19:25
cautionI've had more memory added to my server but I don't see it in `top`, what might I need to do to start using it?19:37
cautiona mount?19:37
giovanicaution: is it reflected in the BIOS?19:37
cautionit's a hosted server19:38
giovaniis it a VPS, or a physical server?19:38
cautionvps19:38
giovaniask the VPS provider19:38
giovaniwho knows how they handle it19:38
giovania reboot is certainly required19:38
cautiontried that19:38
giovanicontact your provider19:39
kman_Royk.  Read through that.  looked at interfaces.  My ifconfig shows eth2 and eth4 but the interfaces refers to eth0. Could this be the problem?19:40
RoyKkman_: ubuntu links ethx to a mac address - to reset it, rm /etc/udev/rules.d/70-persistent-net.rules and reboot19:42
RoyKkman_: if you changed the NIC or something, it'll turn up as a new ethX19:42
kman_NOt only did I change the nic the mobo died and it's a whole new mobo.  There is a PCI nic and a mobo nic.  Thus eth2 and eth4.19:44
RoyKthe new mobo will have new mac addresses19:44
RoyKremove that file and restart19:44
shebalomai have been to #ubuntu-virt here is a past bin http://paste.ubuntu.com/477563/19:58
shebalomait has to deal with virt-manager19:59
thesheff17shebaloma: on your virt box type virsh and see if you can get in.20:00
shebalomahttp://paste.ubuntu.com/477577/20:02
thesheff17can you ping & ssh from the virt-manager machine to the virsh running machine?20:03
shebalomaican manage the box from laptop using ssh <ip_addy)20:04
cemcI have a network interfaces question20:05
thesheff17shebaloma: I would restart libvirt and check the logs.20:05
cemcwhen I installed Lucid, I had eth0, eth1 autodetected, right? now I would like to reverse them, how do I do that?20:05
thesheff17cemc: what do you mean about reverse?20:06
shebalomawhere do i find the log for libvirt20:06
cemcthesheff17: I mean, I have eth0 say a realtek card, and eth1 say a 3com, but I want them reversed, so that eth0 would be the 3com20:07
cemcbut obviously the realtek one got detected first, so it got eth0 assigned to it20:08
thesheff17shebaloma: I think by default it goes to syslog...there is also /var/log/libvirt20:09
thesheff17shebaloma: but that looks like just logs for vm.20:10
=== dendrobates is now known as dendro-afk
thesheff17cemc: this isn't a typical thing to do.  I would look here to starthttp://www.debianhelp.co.uk/udev.htm20:12
cemcthesheff17: thanks, this actually help20:16
cemcs20:16
thesheff17cemc: np20:16
DUEDAHLis it possible to manage your ubuntu servers (ssh) through ubuntu-landscape?20:30
shebalomai looked in /var/log all is fine in all the log files<thesheff17>20:33
thesheff17shebaloma: and this works from the command line? and not in the GUI? virsh -c qemu+ssh://root@192.168.1.5/system20:37
DUEDAHLis it possible to manage your ubuntu servers (ssh) through ubuntu-landscape?20:43
shebalomahttp://paste.ubuntu.com/477595/ the what happens on the server20:45
shebalomahttp://paste.ubuntu.com/477596/ this is form the client20:47
shebalomahttp://paste.ubuntu.com/477598/ virsh -c qemu+ssh://shebaloma@192.168.1.3/system what happens if i change usre from roo to shebaloma20:52
shebalomahttp://paste.ubuntu.com/477604/ and this is run from cliant20:55
shebalomadose that help you <thesheff17>20:55
jacob_Hello everyone. I've been using ubuntu desktop for a few years now. I work at godaddy.com and have been using godaddy shared hosting for a while, now I want to use ubuntu server and host my site myself. Is there a control panel I can install on ubuntu server to make management of DNS and email a little easier?20:56
thesheff17shebaloma: use root20:59
thesheff17shebaloma: you prob have a permissions problem20:59
shebalomaon the server root login is disabled21:00
thesheff17jacob_: I just use the godaddy web site and point it to my public IP's for the web site...as far as I know there is no control panel.21:00
shebalomai could enable but i forgot how21:00
thesheff17shebaloma: http://www.sunmanagers.org/pipermail/summaries/2002-June/001802.html21:02
thesheff17shebaloma: change your /etc/ssh/sshd_config file with those two lines in that link.21:02
thesheff17shebaloma: and restart /etc/init.d/ssh restart21:03
jacob_Hello everyone. I've been using ubuntu desktop for a few years now. I work at godaddy.com and have been using godaddy shared hosting for a while, now I want to use ubuntu server and host my site myself. Is there a control panel I can install on ubuntu server to make management of DNS and email a little easier?21:03
CharlieSujacob_: look at ISPConfig21:05
IVerbNounsCharlieSu: Thanks I'll check that out.21:09
shebalomaok works on the server21:09
shebalomabut not from clint21:09
cemcwhen enabling unattended upgrades, how can I exclude the kernel?21:12
cemccan I exclude 'linux-image*' ?21:12
jdstrandzul: hey. I was wondering if you could look at bug #578922, comment #1, points 2 and 3 and consider them for Ubuntu and pushing to Debian. I have not tested them at all and in the bug simply stated 'it could be done'21:22
uvirtbotLaunchpad bug 578922 in apparmor "mysql configuration should be adjusted to help prevent against chained attacks against LAMP stack" [Medium,Fix released] https://launchpad.net/bugs/57892221:22
qman__cemc, running "sudo apt-get upgrade" will not install kernel updates21:24
qman__you need to use "dist-upgrade" or equivalent for them to install21:24
cemcriight21:24
cemcof course21:24
cemcqman__: thanks21:25
FunnyLookinHatWith a cron script, how can I make sure a pty is allocated for it ?  I'm using a bash-script wrapper to launch a php script that requires all sorts of junk so that mencoder will run21:25
=== unreal_ is now known as unreal
dominicdinadawhat is the safe way to remove xorg, gnome desktop from someones server. And what will be lost by way of say conf for samba, network, etc21:37
hallynwell this is weird.  I swear yesterday there were two commeetns on old qemu-kvm bzr branch proposed merges about whether they were still needed, but now i can't find them either in email or in launchpad...21:44
kman_Royk.  I removed the file, restarted the system and still no internet.  It now shows only the eth0.21:50
tyskahi guys im working with cups on ubuntu, i wanna put authentication on my printers but my windows machines cannot access the printers with authentication, can someone help me?21:52
RoyKkman_: reconfigure /etc/network/interfaces21:52
RoyKif the interface is visible, it should be configurable21:52
kman_right now it is set for autoconfig.  I am a little surprised it does not see the two network cards.21:54
kman_Only one has a network connection so maybe that explains it.21:54
RoyKkman_: ifconfig -a21:55
RoyKpastebin that21:56
kman_I've never used pastebin sorry.  The results do show the two cards. One is a RTL-8139 which has known problems in Ubuntu.  The other is National Semiconductor DP03815.22:01
kman_Is there some help guide or info related to pastebin somewhere?22:01
guntbert!pastebin22:02
ubottuFor posting multi-line texts into the channel, please use http://paste.ubuntu.com | To post !screenshots use http://tinyurl.com/imagebin | !pastebinit to paste directly from command line | Make sure you give us the URL for your paste - see also the channel topic.22:02
guntbertkman_: ^22:02
glen1this is a bit unrealistic xD but if I happened to own one of the cray jaguar supercomputers. Could I use it as a personal computer xD22:04
glen1http://en.wikipedia.org/wiki/Jaguar_%28computer%2922:04
kman_No need to pastebin.  It started working.  Not sure why.  I did switch the cable back and forth perhaps that triggered something.22:06
kman_Maybe I need to check for the cable.22:06
Patrickdkheh, I had issues like that with a realtek card22:07
PatrickdkI replaced it, no more issues :)22:07
PatrickdkI was planning on replacing the whole computer cause of it, but it hasn't come in yet22:07
=== oubiwann is now known as oubiwann-away
glen1does anyone know about subdomans?22:43
glen1how is images.google.com different from google.com/images/22:43
rcsheetswell, google.com/images/ doesn't exist22:44
rcsheetsand images.google.com does22:44
alex_joniimages.google.com is a subdomain22:45
alex_joniit can live on a different server, have a different IP, whatnot22:45
alex_jonigoogle.com/images/ is just a folder on google.com/22:45
tagetglen1:  what are you trying to do with your subdomain ?22:51
glen1I was just curious about it22:52
glen1alex_joni, oh I see22:52
glen1thanks22:52
tyskaim trying to use a samba server in a 10.04 ubuntu but i get this error when trying to access it: samba tree connect failed: NT_STATUS_ACCESS_DENIED. Someone can help me?23:19
tyskaguys?23:20
tyskasomeone can help me?23:21
tyska=(23:22
shebalomahello <thesheff17> i figered it out i was using the wrong ssh-askpass23:47
JordiGHHow do you get rid of command-not-found?23:49
JordiGHRemoving the package left me with :23:49
JordiGHjgutierrez@ubuntuServer:~$ sdfdsf23:49
JordiGH/usr/bin/python: can't find '__main__.py' in '/usr/share/command-not-found'23:49
JordiGHI guess I can just nuke any mention of it in /etc/bash.bashrc23:51
JordiGHAh, there we go.23:53
JordiGH"-bash: fasdfds: command not found"23:53
JordiGHThanks!23:53
thesheff17shebaloma: yea it sounded like it was outside a connection issue with virt.23:54
shebalomai had ssh-askpass but this was the problem them i installd gtk-led-askpass and works fine23:57
shebalomaso i think ssh-askpass is outdated23:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!