/srv/irclogs.ubuntu.com/2012/05/11/#ubuntu-server.txt

Gallomimia_okay. i'm trying to get phpmyadmin up and running on a ubuntu server using apt-get to install all the fun things. i still get a 404 error and i'm really quite sure i broke it all. anyone who wants to try and help me? i feel it is hopeless but perhaps you will help me see the light00:46
nathwillman i'm stoked. just ordered an n40l for home :) dropping 12.04 on it as soon as it arrives01:10
=== bazhang_ is now known as bazhang
billybigrwhats an n40l?01:51
billybigrahh home nas01:52
virusuyhttp://h10010.www1.hp.com/wwpc/uk/en/sm/WF06b/15351-15351-4237916-4237917-4237917-4248009-5163346.html?dnr=101:52
twbBleh, not a fan of HP01:52
virusuytwb: me neither01:54
patdk-lapit's ok, just seems pricy for it's performance01:55
twbAfter all they bought compaq and we all remember what compaq units were like01:55
mgwhow can I get dhclient to override the local hostname?02:11
mgwjust delete /etc/hostname?02:12
twbmgw: only if you want to break everything.02:13
mgwok, that's what I thought02:13
mgwwhat's the right way02:13
mgw?02:13
twblive-config does it, but I don't remember how02:14
twbBCP is to do it the other way around -- the machine has a name and it tells the DHCP server what it is02:14
mgwhmm… ok…. I'm bringing up a number of VMs and the DHCP server (cobbler) knows their hostnames from the MACs02:15
mgw(isc actually, but controlled by cobbler)02:15
mgwIf that's really best practice, I can do it the other way… I'm pushing configs out in my bootstrap script02:16
twbIf they're all VMs provisioned from the same base image, that's the same class of thing as live-config02:16
twbMy BCP remark is about normal hosts that you install and then they run until they explode, not this new-fangled cloud shit where hosts are born and die automagically without any babysitting02:17
IdleOnetwb: Please keep the language clean.02:17
mgwbug 90388 has this posted: "We solved it by putting "hostname $new_host_name" into a file at /etc/dhcp3/dhclient-exit-hooks.d/"02:19
uvirtbotLaunchpad bug 90388 in dhcp3 "hostname supplied by dhcp server is not used" [Low,Fix released] https://launchpad.net/bugs/9038802:19
twbmgw: how does it know the FQDN, unless you also edit /etc/hosts ?02:19
twbMaybe if you are executing "hostname foo.example.net" instead of just "hostname foo", that becomes irrelevant?02:20
mgwtwb: yeah, that's the other side02:20
twbmgw: oh sorry, I thought you were one of the regulars, didn't realize you were the OP :-)02:21
mgwtwb: lol… I'm a 'regular' once or twice a week02:21
mgwI think I'll just template out /etc/hosts & /etc/hostname02:22
mgwAnd not worry about dhcp02:22
mgwThese VMs do keep the same hostname for life02:22
=== JonEdney is now known as Jon|AFK
Zanzacarhow can i list who is connected via ftp or sftp?04:57
Zanzacarwho -a seems to be a dead end. lastlog seems to only be for ssh.04:57
twbZanzacar: look at the process table05:01
twbpgrep internal-sftp or something05:01
Zanzacarwell thats just going to give me the process id wont it. it wont really tell me who is connected or anything like who would do for ssh05:07
twbZanzacar: so then find out who owns the process05:08
lickalotthello all.  I have an issue I was hoping someone could assist with.05:34
lickalottI just upgraded to 12.04 and it randomly dies.  the machine stays on, but I can't access it, either directly or ssh05:34
lickalotti have to constantly cold boot it to get it back.05:34
lickalottanyone else having this issue or know what's going on?05:35
lickalottso.......no05:53
Zanzacartwb: I think I figured everything out ps aux | grep ftp06:02
Zanzacarthis lists both the sftp through openssh and the ftp through vsftpd06:02
Zanzacarthank you for your help06:02
twbWhatever06:05
=== Arc_ is now known as a5m0
=== almaisan` is now known as al-maisan
agnostichello09:09
=== al-maisan is now known as almaisan-away
=== almaisan-away is now known as al-maisan
=== al-maisan is now known as almaisan-away
=== sanderj_ is now known as Sander^work
kantlivelongwhen someone logs into a server behind a router via SSH it always shows the routers WAN ip as the connected from address.. is there a way to fix that?13:49
mardraumare they using a rfc1918 address (using NAT)?13:52
mardraumunless they are specifically proxying via that IP, that's all I can think you want to "fix". And you can't.13:54
_rubenit's a "bug" in the router .. it should only touch the destination address, not the source address13:59
mardraumsounds pretty rare, source?14:00
_rubenmardraum: common sense :)14:01
kantlivelongmardraum: i figured it out :P some doofus translated the srcaddr14:01
mardraumcommon sense says that lots of routers have bugs where they modify the source address?14:01
kantlivelongyeah14:01
kantlivelongwas driving me mad14:01
mardraumkantlivelong: translated how14:02
kantlivelongin the NAT14:02
_rubenmardraum: i didn't say lots, i said it does happen, wouldn't know anything about the scale of it :)14:02
mardraum...14:02
mardraumkantlivelong: that's what NAT is, you know right?14:02
kantlivelongits a crummy sonicwall :O14:02
kantlivelongyes but they translated what the sourceaddr was14:02
mardraum_ruben: if it does happen, show some evidence14:02
kantlivelonginstead of keeping the orig14:02
_rubenmardraum: kantlivelong did14:03
mardraumdid he?14:03
mardraumhe said a doofus, not a bug.14:03
kantlivelongyeah14:03
_rubeni said "bug" .. as in: crappy implementation of router software14:03
kantlivelonga doofus set it up wrong14:03
kantlivelongtranslated it to the WAN ip14:04
kantlivelongdunno why :(14:04
* kantlivelong hates sonicwall14:04
gary_posterhallyn hi.  I don't think you filed a bug for the lxc-start-ephemeral quoting issue (the one like lxc-clone).  I couldn't find it in Launchpad.  IS is asking me to give them a bug number.  I could file it myself, but I'm not sure what the quoting issue is exactly.  I did some experiments with echo $line and couldn't seem to get it to misbehave.14:04
kantlivelonggranted any router can do it..14:04
_rubensome routers have it hardwired, others have it configurable through the settings14:04
kantlivelongi got a nice shiney new router to replace it soon anyway14:04
kantlivelong8 port gbe pfsense running box14:05
kantlivelong*winning*14:05
mardraumkantlivelong: if you are using NAT, the source address is *always* translated.14:05
_rubenmardraum: wrong14:05
kantlivelonggoing out.. it typically is14:05
kantlivelonginbound no14:05
_rubenif you are using SNAT, sure .. if you are using DNAT, no14:05
kantlivelongatleast now i can run fail2ban again :)14:06
mardraumoh jeez14:06
mardraumSNAT, DNAT14:06
kantlivelongSNOT14:07
kantlivelong:)14:07
mardraumSNAT is a bullshit term, first thing14:07
_rubenhow so ?14:07
kantlivelongperhaps time to resume this in #networking14:07
mardraumhah! even wikipedia agrees14:08
kantlivelong:)14:08
Psi-JackDoes Ubuntu have any CLI tools to see if there's any currently-installed packages against the security advisories, kind of like Gentoo does?14:08
mardraum"The meaning of the term SNAT varies by vendor. Many vendors have proprietary definitions for SNAT. A common expansion is source NAT, the counterpart of destination NAT (DNAT). Microsoft uses the acronym for Secure NAT, in regard to the ISA Server. For Cisco Systems, SNAT means stateful NAT."14:08
mardraumSNAT is meaningless.14:08
kantlivelongmardraum: aka SNOT14:08
_rubenNAT should be meaningless14:08
* _ruben welcomes our IPv6 overlords14:08
kantlivelongPsi-Jack: unsure :)14:08
* kantlivelong misses gentoo14:09
mardraumNAT is a fact of life14:09
kantlivelongindeed14:09
kantlivelongeven without computers :)14:09
iggiI'm having a problem with a virtual machine host running Ubuntu 12.04, the machine can ping the outside word and I can run a apt-get update/upgrade successfully, the virtual machines connect to the internet just fine, but I still cannot SSH or ping from outside the machine. I have turned off ufw and flushed iptables, but still cannot get it to work.14:10
iggifwiw, it worked prior to a reboot.14:11
ikoniaiggi: it's probably your routing14:14
ikoniaiggi: the setup is to masqurade or nat out, not nat back in14:15
iggiikonia, it would have to be on the machine itself as it is a globably routeable IP and the router on the other end of the cat5 cable can't even ping or SSH to the machine14:15
ikoniaiggi: can you connect to the host (not the virtual machines) from the outside world ?14:16
igginope14:16
ikoniaok, so then it's nothing to do with the virtual machiens14:16
ikoniayour public IP address is not setup to route to the physical machine14:16
iggiI was just using them as an example of traffic moving across the interface. As for it not routing, I'm not sure why it wouldn't the router sees the interface's MAC in the ARP table entry.14:18
hallyngary_poster: bug #99768714:19
uvirtbotLaunchpad bug 997687 in lxc "lxc-start-ephemeral needs to quote $line when echoing" [Critical,Fix released] https://launchpad.net/bugs/99768714:19
ikoniarouter seeing a mac doesn't mean it's setup to route/nat traffic to that device14:19
ikoniaiggi: sorry that was for you14:19
gary_posterhallyn, yeah, sorry, was just about to say that we found it.  Sorry, was looking in https://bugs.launchpad.net/ubuntu/+source/lxc and it is not there14:20
hallynright bc it's fixed released in q14:20
hallynunfortunately the fix isn't even in precise-proposed yet, bc the existing SRU lxc package is waiting for its vetting period to end14:21
hallyn(so it's in the unapproved queue for precise-proposed)14:21
gary_posterah ok hallyn, gotcha14:21
gary_posterthank you14:21
iggiikonia, If you don't mind I'll PM the routing info, I'd prefer not to post the IP in a public channel14:22
ikoniaiggi: have you set it up to route the public IP address to your servers physical interface ?14:22
gary_posterPsi-Jack, I was curious about your question.  I haven't tried this so it may be useless, but have you checked out tiger and its "deb_checkadvisories" command? sounds close to what you want.  http://www.nongnu.org/tiger/tiger.8.html OTOH, you could maybe just enable unattended-upgrades if that's all you really want.  http://askubuntu.com/questions/194/how-can-i-install-just-security-updates-from-the-command-line14:42
Psi-Jackgary_poster: No, I want to be able to check IF specific packages currently installed have been pacthed against known security advisories, because one thing about Ubuntu LTS is, you may be running older versions of specific software, but they have security patches applied to them constantly when advisories are out. This makes a LOT of false posatives from IDS/Analysis systems like Alert Logic that don't know this.14:45
gary_posterah I see Psi-Jack.  Sorry couldn't help.14:46
Psi-Jackhehe14:46
Psi-JackGentoo has this handy dandy tool that used the Gentoo security advisory system they have setup, against all the packages you have installed from the ebs.14:47
oCeanPsi-Jack: not entirely the same, but you are not alone: http://ubuntuforums.org/showthread.php?t=196212914:53
oCeanthere is apt-get changelog <packagename> but I don't think there is an automated checking tool :(14:54
Psi-JackHmmm15:07
Psi-JackWow... That's quite surprising that there is no such tool that at least utilizes even the Ubuntu Security Notices.15:07
oCeanthere is CVE tracker from the securit team, but I guess that is the software that actually is the tracker15:08
Psi-JackHeh yeaaah...15:10
Psi-JackPretty darned bad, IMHO!15:10
eeinsorry first time using ubuntu server, where do you set static dns? i would have thought /etc/resolv.conf but it warns me it will be overwritten15:13
Psi-Jackeein: dns-nameservers entry in /etc/network/interfaces15:15
eeinPsi-Jack, thanks15:16
sanduz2every time i start up, i get a few errors and cant login. '[drm] nouveau 0000:00:0d:0: === misaligned reg 0x0060081D' and '[drm] nouvea 0000:00:0d.0: unknown connector type: 0xff!!'15:19
sanduz2not sure what it means or why it happened, i was able to login fine a few minutes ago15:20
sanduz2im on 12.04 amd6415:20
=== Lcawte|Away is now known as Lcawte
=== EvilResistance is now known as Resistance
=== matsubara is now known as matsubara-lunch
=== fenris is now known as Guest56365
kpettitin Apache can I make it so each one of my virtualhosts have a same subdirectory.  For example I'd like it so I have a "/docs" that's the same for every virtualhost.  ANy ideas?16:37
altjkpettit: you can add this line to each vhost config...   Alias /docs /path/to/docs/dir16:40
kpettitAh, Alias.  THat's the command I was forgetting.  Thanks!16:40
=== Jon|AFK is now known as JonEdney
dimitrighi, i was using fdisk -l command to see some new disks ive added, can anyone tell me why the "disk ident" is 0x0000000017:09
dimitrigwhen the live used disks have numbers..17:10
=== Taftse2 is now known as Taftse
=== matsubara-lunch is now known as matsubara
=== ropetin_ is now known as ropetin
=== daker is now known as daker__
zaitzevanyone around?18:13
zaitzevwhat do I do to have my server eth0 act as dhcp client, instead of static ip which it has now?18:14
zaitzevand how do I "refresh" the DHCP ip? It gets .142, but in my router I have reserved its MAC to get .10018:16
nathwillzaitzev: sudo dhclient -r to release, sudo dhclient to renew18:52
nathwiller. might be sudo dhclient ethX where X is whatever18:53
zaitzevhm, i tried18:54
zaitzevbut it keeps getting .142..18:54
zaitzeveven though my router has defined a static lease to the server eth0 MAC, to .10018:54
nathwillzaitzev, cat /etc/network/interfaces?18:54
nathwillbbiaf, gotta grab some food18:56
zaitzevhttp://paste.ubuntu.com/982157/18:56
zaitzevI might as well just drop the whole idea of using dhcp on the server, and set it back to static..18:56
nathwillgenerally best if you want it to be18:57
zaitzevI get another issue now tho19:00
zaitzevcan't login with ssh19:00
zaitzev"permission denied, please try again" even though I do use the correct password19:01
zaitzevI did ssh-keygen -f here, do I need to do something similar on the server?19:02
lickalotthello all.  I have an issue I was hoping someone could assist with.19:03
lickalottI just upgraded to 12.04 and it randomly dies.  the machine stays on, but I can't access it, either directly or ssh19:03
lickalotti have to constantly cold boot it to get it back.19:03
lickalottanyone else having this issue or know what's going on?19:03
Resistancezaitzev:  you need to get your publickey info from your system to the remote server's authorized_keys file for your user19:04
=== smb` is now known as smb
Resistancebut you'd need to be logged in first on the remote server19:04
smbstgraber, Where art you?19:05
zaitzevResistance: I'm at the server console19:05
med_stgraber, LXC in Jr ballroom 219:05
zaitzevResistance: but the rest of the stuff you said is sort of greek to me xD19:06
Resistancezaitzev:  did you generate the key pair on your end?19:10
zaitzevI didn't manually generate anything tho19:12
Resistancehmm, i might have misread the backlogs then19:12
zaitzevI'll try reinstalling openssh19:12
* Resistance glances as his local server monitoring panel, realizes a primary server cluster went down.19:12
Resistancedarn, i'll have to fix that...19:12
* Resistance disappears19:13
zaitzevI reinstalled openssh-server19:15
zaitzevso I'm back to where I was before messing with the ip settings :)19:15
=== Lcawte is now known as Lcawte|Gaming
nathwillzaitzev19:30
nathwillon your remote system, if you've generated your ssh keys19:30
zaitzevI purged openssh-server and reinstalled it, that made it work again :)19:31
nathwillrun ssh-copy-id -i ~/.ssh/id_{rsa,dsa}.pub user@server19:31
nathwillfrom the remote system19:31
zaitzevin case the same thing happens again, I can do that instead?19:32
nathwill?19:33
nathwillthat's how you authorize access w/ that key19:33
nathwillssh-copy-id copies your pubkey into ~/.ssh/authorized_keys on the server19:34
nathwillso that the ssh server can verify you when you try to log in19:34
stgrabermed_, smb: sorry was leading another session before that took a bit longer than it should have ;)19:41
med_no worries.19:42
med_someone said ping you in this channel, so I did.19:42
nathwillzaitzev, don't disable password-based logins until you've verified that key-based logins work :)19:42
hazmatsmoser, what's the name of device-id that cloudinit searches for19:45
smoserits in that script that i sent you19:45
smoser'cidata' maybe19:45
smoserprobably19:45
=== Lcawte|Gaming is now known as Lcawte|Away
hazmatsmoser, yup thanks, got it19:51
hazmattis cidata indeed19:51
jkyleattempting to uninstall haproxy with apt-get remove results in the daemon being started in the foreground and hanging. no joke. http://pastie.org/389701520:59
jeeves_mosswhat causes postfix (and dovecot) not to log to mail.log and mail.err?21:40
=== Lcawte|Away is now known as Lcawte
lickalott hello all.  I have an issue I was hoping someone could assist with.   I just upgraded to 12.04 and it randomly dies.  the machine stays on, but I can't access it, either directly or ssh22:23
lickalottI have to constantly cold boot it to get it back. Anyone else having this issue or know what's going on?22:23
lickalottlemme try a different way...  is there a command to roll back the version?22:32
cc77I assigned a static ip to my server but dns is not working. opening resolv.conf in nano the comment shows I should edit that file. But if I do anyway it works. What file should I edit for dns then?22:46
cc77correction: the comment shows that I SHOULD NOT EDIT that file22:47
mahmohdoes anyone know if qemu-arm-static can be called via libvirt in precise? hallyn?23:30
mahmohqemu-system-arm that is23:33
poseidonSo I'm new to ubuntu.  Any suggestions for a getting started with server guide, or a suggestion for firewalls?23:34
JonEdneyIs there a specific command to update 12.04 server?  I run apt-get update, and it's still indicating 18 packages and 1 security update, even after I run the update.23:45
=== Arc_ is now known as a5m0
FireboltJonEdney, you'll want apt-get upgrade, not update23:49
Fireboltupdate just reads new entries in your sources.list/ppas you've added23:51
JonEdneyFirebolt, I didn't know that, thank you23:54
Fireboltnp23:54
FireboltI remember that confused me thoroughly when I was new to ubuntu23:55
JonEdneyYeah I can see why.  Desktop is different, the update manager pops up, it dont for the server since it's console-based.23:56
JonEdneyIf I run apt-get upgrade on a 11.10 server, will it try and upgrade to 12.04?23:57
JonEdneyI have an 11.10 server on a VPS, and the host runs openvz and isn't supporting 12.04.23:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!