[00:01] New bug: #907518 in keystone "swift proxy cannot start when configured to use keystone" [Undecided,Triaged] https://launchpad.net/bugs/907518 [00:59] m_3, do the SRU stuff. ie, write justification and everything [00:59] and if you wanted, you could foward a debdiff to the debian bug that is there. [01:01] smoser: cool, thanks! [01:02] * m_3 looking up "SRUs for dummies" [01:02] m_3, ping me when you have justifcation done and I can do the upload to oneiric-proposed if there is no oneelse around. [01:02] i'm gonna mostly be out till budapest though so you might want to look for someone else. [01:02] good work on getting that fixed though [01:02] thanks, yeah it's been a ghost-town around here [01:03] I've got a ppa with it fixed for oneiric, so there's no particular hurry [01:03] have a great break man... see you in budapest [01:08] well, the archive is 100% broken for that package, so that is pretty bad. [01:23] * SpamapS will +1 it right into oneiric-proposed :) === sixstringsg|away is now known as sixstringsg [01:40] woooooooooooo [01:40] I love ubuntu! [01:50] Just curious if anyone could answer this for me. I can sftp into my server through the terminal and through filezilla. Through the terminal I transfer at 11mbps through filezilla I transfer at 8-9mbps. [01:50] does anyone know why that would be? [01:50] probably a math error in one program or the other [01:51] so one isnt actually slower then the other then? [01:51] not likely, they could also be negotiating different encryption sets, or filezilla could be measuring actual file throughput while the other program is measuring total connection throughput [01:51] lots of reasons those numbers can be different [01:52] gotcha sounds good. [01:52] the only real way to measure would be to download the same large file and time it [01:52] I do [01:52] Zanzacar, glad we could help ^_^ [01:52] I am going to test it out and see if there is any differences [01:53] also, IIRC, filezilla displays the average over the whole connection [01:54] the other program may be measuring the current rate instead [01:54] it is just sftp over the terminal [01:55] pangolin, HI! [01:55] pangolin, sorry for the ping! [01:58] smoser SpamapS: I think I have everything for an SRU on bug #854866 [01:58] Launchpad bug 854866 in ganglia "some ganglia packages won't install because of useradd" [High,Confirmed] https://launchpad.net/bugs/854866 [01:59] * m_3 sure hope that all works :) [02:00] m_3, just copy your comment to a section in the description [02:00] other than that, loooks good. [02:01] smoser: smoser ok, did that [02:02] Zanzacar: most likely case is one is measuring megabytes (1000) and one is measuring mibibytes (1024) [02:02] Zanzacar: it could also be scp vs. sftp -- the former has slightly less overhead. [02:10] m_3, ok. i just uploaded to oneiric-proposed. [02:10] then, it needs an SRU admin (SpamapS or pitti) to approve it into -proposed [02:10] the one change from the oneiric is (as you stated) the version number. [02:11] 3.1.7-2ubuntu0.1 is what i used, which is < anything in precise [02:11] following the chart at https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Update%20the%20packaging [02:15] smoser: ok, thanks === sixstringsg is now known as sixstringsg|away [02:37] :q === twister004_ is now known as twister004 [03:00] http://pastebin.com/RMpM2bdA <-- x2270 m2 sees only one disk.. any idea what I can do short from rebooting the server [03:01] tons of error like this http://pastebin.com/319gGafB for sdb [03:31] New bug: #907620 in openldap (main) "package slapd 2.4.21-0ubuntu5.6 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/907620 [03:32] during boot I saw both disks [03:33] http://pastebin.com/25STEpin <-- from /var/log/dmesg [03:33] but now only one [03:33] they both are internal disk [03:33] i wonder if my co-worker broke sdb while attaching it to raid1 [03:34] (parted) p [03:34] Error: /dev/sdb: unrecognised disk label [03:36] smartctl --all /dev/sdb -T permissive says [03:36] SMART Health Status: OK [04:22] rebooted the system [04:23] now I can see sdb === lifeless_ is now known as lifeless === bladernr_ is now known as bladernr_afk [09:24] hi guys... how can I automate reverse ssh on my ubuntu server?... I need to connect to this box using reverse ssh.... can I use a script at bootup?.. I tried this but it doesn't work [09:26] New bug: #907686 in squid3 (main) "CVE-2010-0308: DoS (assertion failure) via a crafted DNS packet that only contains header in lucid series" [Undecided,In progress] https://launchpad.net/bugs/907686 [09:26] New bug: #907687 in squid3 (main) "CVE-2010-0639: DoS (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port" [Undecided,In progress] https://launchpad.net/bugs/907687 [09:31] twister004: You can create some ssh keys [09:31] and create an upstart script for it [09:31] Jeeves_: ahem... how do I do that :D [09:36] twister004: ssh-keygen -t rsa on the box behind nat [09:36] Don't enter a passphrase [09:37] vi /etc/init/rssh.conf [09:37] Jeeves_... I did that... I want to know how I can automate this tunnel... how it can be auto-established upon reboot [09:37] exec ssh -i $homedir/.ssh/id_rsa [09:37] ?? [09:37] Create an upstart job [09:37] That will run ssh [09:39] /etc/init/udev.conf can be used as basic script [09:39] Jeeves_.. how do I create an upstart Job?.. I created a .sh file with 'autossh' running... and edited crontab.... @reboot /usr/local/bin/script.sh [09:39] New bug: #907690 in squid3 (main) "CVE-2011-3205: DoS (memory corruption and daemon restart) or remote Gopher servers." [Undecided,In progress] https://launchpad.net/bugs/907690 [09:39] replace exec udevd --daemon with 'ssh -i $path_to_id_rsa $remoteuser@$remotebox' [09:39] remove the 'expect fork' file [09:40] s/file/line [09:40] Jeeves_.. could you start from the beginning... I lost you somtime back [09:40] cp /etc/init/udev.conf /etc/init/rssh.conf [09:40] vi /etc/init/rssh.conf [09:41] replace exec udevd --daemon with 'ssh -i $path_to_id_rsa $remoteuser@$remotebox' [09:41] remove the 'expect fork' line [09:41] That should work, I think [09:42] Jeeves_... /etc/init/rssh.conf doesnt exist [09:42] Indeed [09:43] If you didn't do 'cp /etc/init/udev.conf /etc/init/rssh.conf', it won't exist [09:44] Jeeves_... $path_to_id_rsa should be the path to authorized_keys file correct? [09:44] No [09:44] id_rsa [09:45] Jeeves_... isn't id_rsa the local key? [09:45] Yes [09:45] And the ssh client on the local machine must use that specific keys [09:45] the authorized_keys on $remotebox should have the line in id_rsa.pub in it [09:46] Jeeves_... I lost you there... what about passwordless ssh? [09:47] That's what the keys are for [09:47] You create a ssh key [09:47] you end up with two files [09:47] yes [09:47] id_rsa and id_rsa.pub [09:47] the .pub file is the public key [09:48] You copy/paste the contents into authorized_keys on any remote box you want [09:48] yes [09:48] yes [09:48] id_rsa will be used by the local client to connect to the remote server [09:48] if the remote server can verify the local key with the public key [09:48] You are granted access [09:49] Jeeves_.. but then what should be edited in the id_rsa.pub file? [09:50] Jeeves_... in the rssh.conf file... is the following command correct?.. 'ssh -i /root/.ssh/ root@remote_hostname'' [09:51] Nothing should be edited in the .pub file [09:51] I never said that :) [09:51] -i should be /root/.ssh/id_rsa [09:52] ohk... so.. then... after the reboot of the source, the tunnel will be established... and how to I connect to to the source from the destination? [09:53] http://www.howtoforge.com/reverse-ssh-tunneling [09:54] Jeeves_... I followed that same link and did it manually... I dont know how to automate the process [09:55] twister004: You could think about combining my comments with the link you read [09:56] Jeeves_.. so instead of the command u specified, I just enter the command from the link? [09:56] Combine the two, yes [09:58] Here goes nothing... commencing reboot :) [09:58] You don't need to reboot [09:58] ? [09:58] You can also type 'start rssh' [09:59] Jeeves_... I want to test it during bootup [09:59] coz the machine is going to be moved behind a firewall, and we wont have access to it [10:01] it doesn't work... and when I do a 'start rssh'... it gives me the following error - 'start: Unknown job: rssh' [10:04] Jeeves_.. any inputs? [10:08] Oh [10:08] Ehm [10:08] did I do something wrong? [10:09] No, something needs to be refreshed [10:10] initctl reload-configuration [10:10] wat's tjat? [10:10] That tells upstart that there is a new file, iirc [10:10] it didnt work [10:10] still the same [10:11] the file is called /etc/init/rssh.conf, right? [10:11] yes [10:12] Works for me [10:13] huh/ [10:13] If I copy /etc/init/udev.conf to /etc/init/rssh.conf [10:13] ? [10:13] I can run 'start rssh' without any issues [10:13] I did that [10:13] let me do it again [10:15] it didnt work [10:16] can you pastebin the command 'cat /etc/init/rssh.conf' ? [10:17] Jeeves_.. here you go : http://pastebin.com/hnxNAKYK [10:18] http://pastebin.com/C8yJMNBE [10:18] That might work better [10:18] http://pastebin.com/diff.php?i=C8yJMNBE [10:18] hello, when i created a ssh-key on my laptop, and copied the public part to the servers ~/.ssh directory the login via key works. will i be able to put my private key to my other machine or do i need to create a new key to connect with it? [10:19] Wolfsherz: Private key can be transferred [10:19] Jeeves_: ok, but the public key has the computers user@hostname in it. is that a problem when connecting with the private key from another host? [10:19] no [10:20] That's just a comment [10:20] Wolfsherz: You can copy your private key to the other machine, but really it is better/safer solution to create a new private key on the other machine. [10:20] andol: why is it safer do to so? [10:20] Jeeves_: thank you [10:20] Jeeves_.. ok.. the 'start rssh' worked... thanks!... but how do I connect back from the other side? [10:21] twister004: You said you read that page on howtoforge :) [10:21] Wolfsherz: In case you lose on of the computers, you can more easily revoke that public key. [10:21] s/on/one/ [10:21] Jeeves_... I did... and I tried 'ssh localhost -19999'... it refuses the connection [10:22] twister004: I'd try -p 19999 [10:22] andol: i have to paste that other pubkey to authorized_keys too then, right? [10:22] And check if the ssh connection is really up [10:22] Jeeves_.. oops I typed it correctly... it doesn't work [10:22] Wolfsherz: Yes [10:22] Jeeves_... using ps? [10:22] twister004: And where is autossh located? [10:23] andol: and to revoke a public key i just remove that key from authorized_keys, or is there another way? [10:23] Wolfsherz: exactly [10:23] andol: great, thank you [10:24] Jeeves_... I installed autossh [10:24] Ah, ok. [10:24] it's under /usr/bin [10:24] No clue what that is [10:24] replace 'autossh' with '/usr/bin/ssh' [10:25] Jeeves_.. ok [10:25] Jeeves_... 'ps -ef | grep ssh' shows the process [10:26] ok [10:26] Jeeves_... so, for some reason, the ssh is not working?.. even though the process is running in the background [10:27] twister004: I can't see that from here, can I? [10:27] Check if the proces you see still is the same [10:27] Jeeves_.. ill send u the output [10:28] Check if the command is actually working by executing it yourselve [10:29] Jeeves_... it worked!! [10:29] you're awesome!!!! [10:29] Jeeves_.. will it autorun at bootup? [10:29] it should, probably [10:29] You might need to change 'start on' [10:30] Jeeves_.. what's that :( [10:33] Jeeves_.. actually, it stopped workin again... please see the pastebin contents... it's the output of 'ps -ef | grep ssh' 'http://pastebin.com/a6zDRFgt' [10:34] Jeeves_ it works now... sorry! [10:37] Jeeves_... however, it doesn't run at bootup.... please advise how I need to modify 'start on' [10:38] set 'start on' to 'networking', I think [10:38] Jeeves_.. how do I do that... is that a command? [10:38] grmbl [10:38] Read the file /etc/init/rssh.conf [10:45] Jeeves_... sorry!... I changed it, but it still doesnt work on bootup [10:56] hi all [11:00] twister004: No clue then [11:55] Is 12.04 going to ship with ruby 1.9.1 ?? [11:57] Rails needs 1.9.2 and the latest stable is 1.9.3, it will be a major pain if it ships with 1.9.1 which few (if any) Ruby devs use... [12:53] 1.9.3.0 === Lcawte|Away is now known as Lcawte [16:28] New bug: #907816 in apache2 (main) "libapache2-mod-php5 forgets timezone definition after some time" [Undecided,New] https://launchpad.net/bugs/907816 === sixstringsg is now known as sixstringsg|afk [16:43] quiet here today [16:45] * genii-around makes more coffee [16:50] idk y but i got booted and banned from the ubuntu channel... [16:51] enrichedd: Please use #ubuntu-ops if you'd like to get that resolevd. [16:53] ty [16:55] New bug: #907828 in openvpn (main) "tun-based VPNs using the "subnet" topology are wrongly sending ICMP redirects" [Undecided,New] https://launchpad.net/bugs/907828 [16:55] robbiew: I've been poking the debian experimental version of openmpi today. It FTBFS on armel. I'm just trying a rebuild of 1.4.x to check its not my environment [16:56] (but also it failed on Debian) [16:56] https://buildd.debian.org/status/package.php?p=openmpi&suite=experimental [16:56] rbasak: cool...well if it's crap, then this will be an easy blueprint :) [16:56] we have some time, given the package is in universe [16:56] robbiew: hopefully won't be too hard to fix :) [17:13] RoAkSoAx, pushed cobbler update with that fix from yesterday and 2 more to cobbler-ubuntu-import [17:31] Hi, I have two Ubuntu server installations with the same sudoers file, being that one as a root login and the other not. [17:31] Now I have a user X, and in the sudoers I have "X ALL = NOPASSWD: /usr/sbin/puppetca" on both machines. [17:31] If I run the command puppetca with user X without sudo or pass on one of the machines it works, on the other I need sudo. What is the difference? [17:36] "being that one has a root login" [17:39] genii-around: thats the difference? in the machine with a root login I have to use always the sudo command ? [17:44] PedroGomes: The other way around, likely. [17:45] If you're logged on as root, any command you issue automatically has the elevated rights that the sudo command is supposed to be used for. [17:45] genii-around: thanks, but I already found my error after an half a day… [17:46] I forget to add the user to the group that owns most of the folders affected by the command [17:52] hallyn, did you read the bug ? [17:52] i described how i triggered it. [18:02] smoser: you said "i ran an instance". [18:02] inside devstack [18:02] did you try that ? [18:02] with that image? [18:02] /var/lib/tftpboot/pxelinux.cfg/01-00-16-3e-3e-aa-03 [18:03] RoAkSoAx, ^ how do i make cobbler udpate that file [18:03] I don't know what devstack is. Is it a wrapper around euca-build-iamge? [18:03] smoser: change a setting in cobbler, like "netboot enabled" [18:04] hallyn: devstack is the current fav' flavour for setting up a development openstack cloud [18:04] if you're gonna use your little codewords than don't get snarky when i ask for detailed reproduction steps [18:04] with all the different componets [18:04] hallyn, only because i like you, i'll give you alink [18:04] yay! [18:05] http://lmgtfy.com/?q=devstack [18:05] Daviey, i want it to fix all of that garbage [18:06] i'll get to that next year then [18:06] hallyn, and i'll give you a user-data scrript for Canonistack. just a minute. [18:06] smoser: i think 'cobbler sync' will regenerate those tftp files as well as dnsmasq, dhcp, etc [18:06] thats what i wanted [18:06] gracias adam_g [18:06] be back tomorrow for a sponsors gig. out. === sixstringsg|afk is now known as sixstringsg === sixstringsg is now known as sixstringsg|noms [19:01] New bug: #907873 in samba (main) "smbd crashed with SIGABRT in close_file()" [Undecided,New] https://launchpad.net/bugs/907873 [19:35] anyone know where I can find more information on this, like when it will be "removed": [19:35] http://www.omgubuntu.co.uk/2011/12/java-to-be-removed-from-ubuntu-uninstalled-from-user-machines/ === sixstringsg|noms is now known as sixstringsg [19:39] gondoi: the browser plugin has already been disabled. We haven't decided yet when the other packages will be removed from the archive. [19:39] gondoi: is there anything else you would like to know? [19:40] mdeslaur: okay, well i was thinking more in the terms of a server that is running apps with it [19:40] i.e. tomcat and such [19:40] gondoi: I'd suggest trying to migrate to either openjdk or to oracle's java sometime in january [19:41] i work at a hosting provider and I am trying to figure out the impact for our customers [19:41] okay [19:41] thank you mdeslaur [19:41] gondoi: you're welcome === sixstringsg is now known as sixstringsg|afk === dendro-afk is now known as dendrobates === dendrobates is now known as dendro-afk [20:26] New bug: #907905 in php5 (main) "php5-cli scripts not running in background, stays stopped." [Undecided,New] https://launchpad.net/bugs/907905 [20:43] hello, i have got a serious problem after fiddling with ssh-keys on my server. i can not connect anymore with the error: ssh_exchange_identification: Connection closed by remote host [20:44] i already booted the server in rescue mode to delete the authorized_keys in my home-directory. i also removed the private and public key on my machine at home. [20:53] ok server people, RoAkSoAx adam_g SpamapS . [20:53] i'm almost EOY [20:53] but i just pushed to lp:~orchestra/orchestra/odev [20:54] its largely a work in progress, but i'm sure that each of you, if wanted could get it going [20:54] * kirkland waves at smoser === Lcawte is now known as Lcawte|Away [20:54] (cobbler-devenv -> odev) [20:54] hola crypto people [20:55] Wolfsherz: can you do ssh -vv (that's two v's)? that'll tell you why its being closed at the remote host. [20:57] EvilResistance: I dont think that is possible as i can not connect to that server anymore. I can only boot a rescue-system [21:06] i get a lot of these: http://paste.ubuntu.com/779112/ [21:06] in /var/log/auth.log [21:11] this is my /etc/ssh/sshd_config http://paste.ubuntu.com/779121/ === alaing is now known as funkmonk === sixstringsg|afk is now known as sixstringsg === sixstringsg is now known as sixstringsg|afk [22:24] can someone please help me with some syntax [22:25] I can't get stab to mount my NAS hdd, I can do it manual, but not fstab [22:25] sudo mount -t cifs //192.168.1.129/GoFlex\ Home\ Public/ /media/GoFlex -o username=matthew,password=4546413,iocharset=utf8,file_mode=0777,dir_mode=0777 [22:25] that works fine [22:26] /192.168.1.129/GoFlex\ Home\ Public/ /media/GoFlex cifs username=matthew,password=4546413,iocharset=utf8,file_mode=0777,dir_mode=0777 0 0 [22:26] and that cases /home to not mount…. [22:32] ??? === sixstringsg|rdlB is now known as sixstringsg === sixstringsg is now known as sixstringsg|afk [23:01] yakster: What errors are you getting on the attempt to mount the cifs with /etc/fstab ? [23:16] error line 13… line 13 is the //192 line [23:18] line 13 is stab is bad === erichammond1 is now known as erichammond === erichammond1 is now known as erichammond === EvilResistance is now known as Resistance [23:40] Is it possible on a dedicated server that I do not have physical access to to increase the size of the / partition? [23:41] New bug: #907945 in nova "Enabling keystone caching results in type errors in middleware" [Undecided,New] https://launchpad.net/bugs/907945 [23:46] sixstringsg|afk: if it's not under lvm control, no [23:47] Can I symlink it to part of another partition to increase it? [23:47] It's 10Gb right now, I don't know how big it should be honestly. [23:47] no [23:47] Or if I can clean some stuff out. === sixstringsg|afk is now known as sixstringsg [23:47] can someone help me out with some stab syntax? [23:47] sixstringsg: you can symlink dir's - but you still can't change it's size [23:48] fstab syntax [23:48] sixstringsg: you certainly can clean stuff out [23:48] /192.168.1.129/GoFlex\ Home\ Public/ /media/GoFlex cifs username=matthew,password=4546413,iocharset=utf8,file_mode=0777,dir_mode=0777 0 0 [23:48] ikonia, suggestions on what to clean? [23:48] sixstringsg: depends on your machine and what you're not using [23:48] sixstringsg: what other seperate mount points you have too [23:49] All I have are / /home and swap. [23:49] sixstringsg: ok, so look at creating new partitions for things like var, mount that on a new partition and reboot, same for /tmp [23:50] sixstringsg: look at what you are using software wise, open the package manager and clear down things you don't need/want [23:50] just apply a logical common sense approach [23:50] Ok, thanks. [23:50] New bug: #907952 in munin (main) "Unnecessary log message when listing local services" [Undecided,New] https://launchpad.net/bugs/907952 [23:51] does anyone know why a bad line in stab will cause /home to not mount? [23:52] yakster: if the lines are wrong, they can't be used [23:53] it's that simple,