/srv/irclogs.ubuntu.com/2012/10/03/#ubuntu-server.txt

=== cpg is now known as cpg|away
zulhallyn: still around?00:11
zulhallyn: have you seen this before? http://pastebin.ubuntu.com/1257101/ when trying to do virsh iface-list?00:12
uvirtbotNew bug: #1060541 in ipsec-tools (main) "racoon: broken script env for IPv6" [Undecided,New] https://launchpad.net/bugs/106054100:46
SpamapSstgraber: yes, I did, and the problem does not seem to be resolved00:49
SpamapSstgraber: root     12367  0.0  0.0  27532  1108 ?        Ds   14:53   0:00 lxc-start --daemon -n clint-local-ci-u2-0 -l DEBUG -o /home/clint/.juju/data/clint-local-ci/units/u2-0/container.log00:50
=== cpg|away is now known as cpg
pmp6nlHey, all! Is unison a good way to backup my webserver to my laptop?01:01
=== n0ts_off is now known as n0ts
uvirtbotNew bug: #1060549 in maas (main) "maas-dns fails to install because maas user hasn't been created yet" [Undecided,New] https://launchpad.net/bugs/106054901:21
uvirtbotNew bug: #1060550 in lxc (universe) "lxc-ls with ephemeral containers reports too many containers" [Undecided,New] https://launchpad.net/bugs/106055001:21
=== matsubara is now known as matsubara-afk
bits8mybytespostfix or sendmail?01:59
sarnoldI'd go with postfix, but that's mostly because I think it is better documented and better designed.02:00
bits8mybytesok02:01
bits8mybytesI have used sendmail02:01
bits8mybyteshave not tried postfix02:01
bits8mybytesyet02:01
bits8mybytesand sendmail was a bitch02:01
sarnoldhow do you feel abou the m4? :)02:01
sarnoldhehe02:01
=== n0ts is now known as n0ts_off
bits8mybytessendmail never worked02:04
bits8mybytesand when I finally got it to work02:04
bits8mybytesI don't know how the hell I did02:05
sarnoldyeah. then you'll like postfix.02:05
bits8mybytescool does it do regex stuff?02:05
bits8mybyteson emails02:05
bits8mybytesobviously02:05
sarnoldand more :)02:06
sarnoldand all way easier than sendmail.02:06
bits8mybytessarnold thanks for the tip02:36
sarnoldbits8mybytes: have fun :)02:38
Skaagif I see this in my /sys/block/sda/queue/scheduler : noop anticipatory [deadline] cfq03:04
Skaagit means I'm on the 'deadline' scheduler right?03:04
SpamapSSkaag: yes03:20
hallynzul: that was the augeas bug for which you uploaded the fix.03:21
hallynzul: should nto be happpening any more03:21
hallynzul: it came from the /etc/modprobe.d/iw* file having a line split by '\', which the modprobe lens couldn't handle03:22
hallynso HOPEFULLY you're not seeing it in an uptodate quantal03:23
=== n0ts_off is now known as n0ts
level15hi. i have a server with a few KVM libvirt VMs. one of them is paused and refuses to be unpaused. any ideas?05:10
TLoTanyone here know why oidentd would spawn tons of processes?06:33
=== dendrobates is now known as dendro-afk
Fajkowskyhey can someone help me with maas? http://askubuntu.com/questions/195115/nodes-cant-connect-to-server-after-bootstrap08:59
bigjoolsFajkowsky: can you ssh to your node from your juju client machine?09:00
bigjoolsto 192.168.0.102 from the screenshot09:00
bigjoolsit looks like the machine has not booted yet.  You might be falling foul of the  Oauth time bug09:01
Fajkowskywitch machine?09:03
Fajkowskynode?09:03
bigjoolsFajkowsky: yes the node09:09
FajkowskyOk i know what i was doing wrong09:11
FajkowskyI was trying run node from old ubuntu instance09:11
FajkowskyNow i let install again ubuntu on node09:12
bigjoolsok09:13
Fajkowskycan I ask something about maas?09:14
Fajkowskyi go to #maas09:15
bigjoolsyup09:15
MacroManI'm trying to install Ubunutu-server 12.04 onto an old box as a test server, but I only have an i686 cpu so it won't install. Anyone know what version of ubuntu-server I need to install on this machine?09:19
MacroManDoes that just mean that the processor is 32 bit and not 64?09:19
rbasakAre you trying to install using the i386 version or the amd64 version?09:21
rbasakThe amd64 version probably won't work for you.09:21
rbasakYou may also need a non-PAE kernel, for which you'll need to use mini.iso and do a network-based install.09:21
MacroManErm, I just downloaded the recommended one from the UBuntu website. I'm getting the message 'This kernal requiers an x86-64 CPU'09:21
rbasakRight. So amd64 won't work for you.09:22
MacroManOK. So should I just try with the 32bit download?09:22
MacroManOr is that a waste of time?09:22
rbasakDepends on whether your machine supports PAE or not.09:22
MacroManPAE?09:22
rbasakIf you don't know, it's probably easiest just to try the 32 bit download09:22
rbasakIf it doesn't work, then look for instructions on installing 12.04 on a non-PAE machine09:23
MacroManAh yes, it does.09:23
MacroManCool, I'll try the 32bit one and see where I get09:23
MacroManTanks09:25
=== mcclurmc_away is now known as mcclurmc
eagles0513875hey guys i need to implement dovecot + postfix for use with multiple domains. I already have dovecot + postfix setup which works. does anyone have a good how to on how to do this10:10
=== KristianDK is now known as zz_KristianDK
eagles0513875:(10:32
eagles0513875anyone alive in here?10:56
tanathosyes10:57
eagles0513875tanathos: do you have any experience with dovecot + postfix and multiple domains10:57
tanathosjust that I have no ideea of dovecot + postfix unfortunately10:57
eagles0513875tanathos: no problem :(10:58
=== n0ts is now known as n0ts_off
=== cpg is now known as cpg|away
=== mcclurmc is now known as mcclurmc_away
uvirtbotNew bug: #1060900 in maas (main) "HTTP proxy config being created in /etc/apt/apt.conf on nodes" [Undecided,New] https://launchpad.net/bugs/106090012:08
vrturbohi all, any good howto's for juju + MAAS + openstack folsom + quantum ?12:17
=== dendro-afk is now known as dendrobates
Fajkowskyif someone will have time please check my problem with juju - http://askubuntu.com/questions/195901/juju-services-are-not-deplyoing-correctly12:32
zulhallyn: yeah works with augeas-lens installed12:34
=== mcclurmc_away is now known as mcclurmc
zulhallyn: shouldnt augeas-lens be a depends now then?12:49
hallynzul: doesn't it?13:02
=== n0ts_off is now known as n0ts
hallynaugeas-tools -> libaugeas0 -> augeas-lenses13:02
zulhallyn: doesnt look like it13:08
hallynzul: http://paste.ubuntu.com/1257929/   what do you see?13:16
zulhallyn: http://paste.ubuntu.com/1257931/13:17
hallynzul: oh!  yeah.  you want libvirt to depend on it.  i see13:18
hallynzul: so yeah, any reason not to have libvirt depend on libaugeas0?  it's in main...13:19
zulhallyn: nope not that i know of13:19
Davieyhallyn: what is the benefit ?13:20
hallynDaviey: 'virsh iface-list' doesn't bomb out13:20
hallyn00:14 < zul> hallyn: have you seen this before? http://pastebin.ubuntu.com/1257101/ when trying to do virsh iface-list?13:20
hallynDaviey: ^13:20
Davieyi see :)13:21
hallynsmb`: Daviey: ok, are we at the point where i should fire up a large compute instance and bisect the netdev-freeing 'lxc' bug?13:26
DavieyOne for smb i think.13:27
Daviey(as in, i don't know the state)13:27
hallynsmb`: ^13:31
hallynahs3: hi, debian bug 688167, have you had a chance to look at the 0.2.2-1 proposed pkg?13:33
uvirtbotDebian bug 688167 in src:libvirt "libvirt: Please port to libnl-3.x" [Normal,Open] http://bugs.debian.org/68816713:33
SpamapSsmb`: any ideas? I'm still running your 'smb2' kernel.. I can give you dmesg's or syslogs..13:49
=== verfidesigns39 is now known as verfistudios39
=== verfistudios39 is now known as verfidesigns39
smoserSpamapS, ping14:27
smoserhttp://paste.ubuntu.com/1258070/14:27
smoseror anyone, really14:27
smoserwhy does that job not respawn14:27
xslhello all , sorry this "noobish" question. but i want to use lxc to separate php from nginx and mailfilter from postfix .. but the thing is ... all stuff installed with apt-get wants to install dependencies14:34
xslcan i use a flag on apt-get to install stuff that i want14:35
xsllike .. on 1 lxc i want just mysql-server14:35
xslon lxc.2 i want nginx and mysql support .. no mysql-server again14:35
xslany tips pls?14:35
=== verfistudios39 is now known as verfidesigns39
Kniggediggehi guys, can someone give me some support on netatalk on ubuntu 11.4? http://pastebin.com/HSeTUMDp14:46
=== dendrobates is now known as dendro-afk
holsteinKniggedigge: you tried the suggestion at http://0pointer.de/avahi-compat?s=libdns_sd&e=afpd ?? i would want to be running a more recent version, or an LTS... 10.04 or 12.0414:53
Kniggediggehey holstein, do you think it might be, that afpd isnt running correctly? actually i tried to connect to the afp share with a mac, that does not work, but root      5998  0.0  0.0  65980  2532 ?        S    16:52   0:00 /usr/local/sbin/afpd -U uams_dhx.so,uams_dhx2.so -g -c -n  says that afpd is running… so i dont know if the error message above is important and blocking the whole thing....?14:54
Adri2000adam_g: hi, in what vcs is the keystone package maintained?14:55
holsteinKniggedigge: if it were me, i would start simple... ping the machines, check firewall settings... can the mac "connect" to anything? i usually just use ssh14:56
Adri2000adam_g: debian/control points to an essex branch and ~ubuntu-server-dev has no other up to date branch for this14:57
Kniggediggeyes i have a whole lan setup here with another smb share that works and im configuring the ubuntu machine via ssh… so that works, firewall does not block anything14:57
zulDaviiy: ping im just going to put instructions on how to configure the ceilometer stuff in a README.Debian14:58
Adri2000zul: hi. I think I should have asked my last question to you. any idea? :)15:00
zulAdri2000:  what question? i wasnt paying attention15:00
Adri2000in what vcs is the keystone package maintained? debian/control points to an essex branch and ~ubuntu-server-dev has no other up to date branch for this15:01
zulAdri2000: all the work is going into lp:~openstack-ubuntu-testing/keystone/quantal-folsom-proposed15:02
Adri2000ok thanks15:03
ahs3hallyn: whups.  completely spaced uploading that package.  i'll get to it this evening.15:13
hallynahs3: thanks!15:13
ahs3hallyn: sorry 'bout that.  my bad.15:13
hallynzul: back to libvirt and augeas - libvirt build-depends on netcf, so it should end up linked against libaugeas0.  i guess that does NOT end up pulling in the things libaugeas0 package depends on?  that'd be too much?15:15
hallynor is that a bug int eh builder?15:15
zulit doesnt15:15
chmacHow do I unfreeze an SSD on a server? Can't hotplug it as I don't have physical access... :-(15:16
zulhallyn: lets see what debian does15:16
xslguys, quick tip plz. i want to have 3 LXC containers lxc.mysql(mysql-server) lxc.php(php-fpm phpmyadmin) lxc.www (nginx) but i dont want for instance to install mysql-server on lxc.php wen i do apt-get install phpmyadmin ... any tips ?15:16
zulhallyn: i think we can get away with adding augeas-lens but im not 100% sure15:17
xslAPT::Install-Recommends "0";15:19
xslAPT::Install-Suggests "0";15:19
xslfound it15:19
xsli dont install the recommends15:19
xsljust the the stuff i rly think it needs and the Depends15:20
hallynzul: wanna file a bug real quick or should i?15:20
zulhallyn: please15:21
hallynk15:21
hallynzul: no, wait.  here you go.  libvirt-bin depends on libnetcf1, which depends on libaugeas0, which depends on libaugeas-lenses.  no?15:23
* hallyn fires up a new instance to test. this makes no sense15:24
zulhallyn: right but i have none of that installed15:25
hallynzul: why?15:25
zulhallyn: i had to manually install augeas-lenses and libaugeas015:26
hallynyes, but why didn't they get installed automatically15:26
hallynzul: http://paste.ubuntu.com/1258197/  are you sure you didn't mess around with your system?  do an 'apt-get autoremove' or something?  (i *hate* autoremove, it's so broken)15:30
zulhallyn: pretty sure lemme get back to you15:30
DarkStar1Hello. I have postfix/dovecot(mysql backend) installed on a webserver and use roundcube for the webmail front end. Only problem is I'd now like for each user to be able to change their own passwords. Is there an alternative to roundcube that has this functionality built in?15:34
=== n0ts is now known as n0ts_off
SpamapSsmoser: does it exit 0 ? (the maas job)15:44
SpamapSsmoser: respawn only happens on non normal exits15:44
smoserSpamapS, sorry. i figured it out.15:44
smoseryou have to say15:44
smoserrespawn15:44
smoser*and15:44
smosererr..15:44
SpamapSOH15:44
SpamapSrespawn is missing yes15:44
SpamapSdidn't see that15:44
SpamapSrespawn limit != respawn ;)15:45
smoseri read the man page and assumed that the defaults for the respawn meant that respawn by default15:45
smoserbut you have to state that.15:45
SpamapSyeah thats not the most clear distinction15:45
smoser(and it does respawn on non-zero exit)15:45
smoserthanks for the reply, though, SpamapS15:47
DarkStar1No ideas?16:07
RoyKDarkStar1: users and passwords stored in the mysql db?16:09
DarkStar1RoyK: Yeah16:09
RoyKthen I guess it should be fairly simple to write that in php16:10
RoyKusually the password is stored as a hash, so using that for authentication is trivial, and changing it even easier16:10
RoyKjust make sure access is over https16:10
DarkStar1I haven't done any php coding before and I doubt it is as trivial as you make it sound :D16:11
RoyKhave you any pratice in any other programming languages?16:11
DarkStar1RoyK: Yeah C, C++ Java16:12
RoyKthen php should be trivial indeed16:12
RoyKor perhaps writing the same thing in another language16:13
RoyKDarkStar1: can you create a bogus user, set a password, and pastebin the user entry from the database? it should show up now the password is stored16:14
DarkStar1RoyK: wish I can but I can't afford the time to code this. I'm working on two other projects as I speak. I was just told to look for a solution16:15
SpamapSDarkStar1: are you sure Roundcube doesn't have some kind of plugin to support it?16:15
RoyKit really won't take long, it's very simple indeed16:16
SpamapSYeah but I'd bet money its already done16:16
RoyKtrue16:17
DarkStar1SpamapS: I am currently searching but I was given to understand that my boss hadn't found any.16:17
RoyKbut perhaps I misunderstood - he was looking for an alternative to roundcube...16:17
DarkStar1which is why it gets passed down to me :)16:17
DarkStar1RoyK: I just wanted a solution that would allow a user to change their passwords. IF there is a plugin for roundcube, all the better16:18
RoyKDarkStar1: it's just a simple html form to authenticate the users, and then another to set a new password, and then some db connections and SQL to be passwd16:18
RoyKs/passwd/passed/16:18
DarkStar1I really can't afford a few hours to code this thing debug stuff, make sure it's secure etc.16:19
RoyKDarkStar1: find that user entry, and I may give it a try - I don't have much to do this very hour (home from work and a bit tired, but can't sleep yet)16:19
SpamapSDarkStar1: http://code.google.com/p/dovecotpfd/ this wouldn't work?16:20
SpamapSoh.. hrm.. only supports doevcot files, not db16:20
SpamapSdoh16:20
sarnoldDarkStar1: if you do wind up coding it yourself, here's a good set of guidelines: https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet16:20
RoyKdoesn't list dovecot, though16:21
sarnoldDarkStar1: http://www.openwall.com/phpass/ (I *love* the openwall.com work. Strong endorsement of anything they touch. :)16:22
RoyKsarnold: the hash() function is usually sufficient16:23
RoyKhttp://no2.php.net/manual/en/function.hash.php16:23
sarnoldRoyK: I strongly disagree.16:24
sarnoldRoyK: (a) too many people screw up the salting. Really. Check stackoverflow.com some time to see hudnreds of poorly written PHP password storage contraptions.16:24
sarnoldRoyK: (b) the iterations are nearly as important -- they drastically slow down targetted brute force attempts.16:24
sarnoldRoyK: Openwall's phpass handles these details correctly, once, in one place.16:25
RoyKok16:25
RoyKanyway16:25
RoyKI guess that may be incompatible with dovecot?16:26
DarkStar1Man I can't use anything that would require me getting my hands dirty with Php code atm. a) I haven't coded php before whilst I'm not against learning it, I don't think coding a password utility too is the best way to start. and b) I just simply can't spare the time16:26
sarnoldRoyK: perhaps; I thought we were talking about PHP? :)16:26
DarkStar1I'm solidly jammed for the next few months16:26
RoyKDarkStar1: erm - I didn't ask you to code php - I said just give me a dump of a bogus user :)16:26
RoyKDarkStar1: perhaps I can do some coding for free - I don't have much else to do atm16:27
bjfjamespage, do you every see http://pastebin.ubuntu.com/1258161/ with your jenkins jobs ?16:27
=== julian_ is now known as alamar
uvirtbotNew bug: #1061064 in keystone (main) "ubuntu-cloud.archive: swift3 is no longer in swift-proxy" [Undecided,New] https://launchpad.net/bugs/106106416:53
=== mcclurmc is now known as mcclurmc_away
bananapieHey, a while back I found a command that I execute instead of 'make install', it builds a .deb file instead of installing the package. I can't find the command, anyone know what I am talking about ?17:36
bananapiecheckinstall is the command, thanks17:36
bananapie'checkinstall -D make install'17:36
sarnold:)17:37
=== dendro-afk is now known as dendrobates
zulDaviey: ceilometer uploaded18:02
Davieythanks18:07
scsinutzis there an AMI creator tool sort of like boxgrinder for Ubuntu?18:09
SpamapSscsinutz: sort of18:20
SpamapSscsinutz: what you really want is just to pass in cloud-config as userdata and use the stock AMI's18:20
SpamapSscsinutz: https://help.ubuntu.com/community/CloudInit18:22
SpamapSscsinutz: also you might be interested in juju, which goes further and helps model the relationships between services18:25
SpamapSscsinutz: http://juju.ubuntu.com/ for that18:25
uvirtbotNew bug: #1061154 in nagios-plugins (main) "pgsql.cfg includes a check_pgsql_4 command, but check_pgsql does not actually take the -4 argument" [Undecided,New] https://launchpad.net/bugs/106115418:41
=== dendrobates is now known as dendro-afk
pmatulisanybody here manage to get sssd working with sudo rules in ldap?18:51
TheLordOfTimeso, on the mailing list, noticed a discussion on "Webmin", zentyal, and others.  Has the public-facing security implications of those been addressed yet?19:00
=== TheLordOfTime is now known as TLoT
=== LordOfTime is now known as TheLordOfTime
SpamapSTheLordOfTime: what implication would that be? That zentyal/webmin are less likely to be secure than ssh?19:03
TheLordOfTimeSpamapS, that it opens up more brute-forcing attempts.  that, and it can break how configurations work with certain webserver packages which are likely to run19:03
TheLordOfTimeSpamapS, i find it a tad too insecure... in SSH, you can key-restrict connections19:04
TheLordOfTimein webmin, its password-restricted only19:04
TheLordOfTimethat protection gap, in my opinion, makes it a risky package (note i've not worked with zentyal, talking strictly webmin atm)19:05
TheLordOfTimewhile i don't care if people load it up manually by source, it default listens on *:10000 which makes it even less secure because it can be publicly accessed19:05
SpamapSTheLordOfTime: I don't think it opens up any more brute forcing than ssh (you can use cert based auth just as easily with HTTPS as with SSH)19:06
SpamapSTheLordOfTime: but frankly, what sane person would *ever* put their management interface on the internet?19:06
TheLordOfTimeSpamapS, define "sane" to be the server team, and i'll agree19:06
SpamapSWhich server team?19:06
TheLordOfTimeSpamapS, any sane team of server administrators19:07
TheLordOfTimeSpamapS, my concern is with the less sane / less experienced crowd of server admins19:07
TheLordOfTimenamely the newbies19:07
SpamapSAre going to install a server.. on the internet.. without a firewall?19:07
SpamapSI don't think even newbies make that mistake.19:07
* TheLordOfTime coughts19:07
TheLordOfTimecoughs*'19:07
TheLordOfTimeyou'd be surprised what i see cross my desk :p19:08
SpamapSBecause even if they do.. its a mistake that corrects itself rather quickly with a remote compromise.19:08
TheLordOfTimebut i'll not argue :P19:08
sarnoldyou never know when hyou might want to admin your erver from a local starbucks...19:08
SpamapSsarnold: right, and there are ways of doing that without just leaving it wide open to the whole net.19:08
SpamapStho I acknowledge that a newbie may make that mistake..19:08
SpamapSstill, this is no different than opening ssh19:09
zuladam_g: thats *not* good (re: 1061166)19:09
TheLordOfTimei think we just need to look into practical use cases for it, and whether its "default" of listening on *:10000 with nothing but a password is sane.19:10
TheLordOfTime(IMO that default is evil)19:10
SpamapSTheLordOfTime: why is that evil?19:10
TheLordOfTimealthough openssh-server also suffers from a similar issue.19:10
SpamapSOk, so basically you want training wheels on your servers.19:10
TheLordOfTimeSpamapS, i lock down my servers, i'm far beyond using webmin :p19:10
SpamapSThats a very backwards way of thinking.19:11
SpamapSA web based interface is going to be a lot easier to tweak via a smartphone than ssh'ing and vim'ing files19:11
SpamapSThere are lots of use cases for things like zentyal19:11
SpamapSand port 10000 is.. meh19:11
SpamapSits not ever going to be installed by default19:12
SpamapSso user's who install it are expected to think about what they're installing19:12
SpamapS(which is why we fought so hard to not have openssh enabled on the CD's)19:12
SpamapSTheLordOfTime: I think its a molehill.. not a mountain.19:13
TheLordOfTimeperhaps i'm just over-analyzing, maybe just over-analyzing the general population of ubuntu/ubuntu-server users *shrugs*19:13
SpamapSYou want to protect people from themselves. Don't.19:13
SpamapSMake good sane defaults, and help them discover their options. But please don't treat people like children.19:13
TheLordOfTimeindeed, i shall do so.19:15
TheLordOfTimeoh, while you're here... can you test/confirm a php5-fpm bug for me?  its so low a bug it wouldnt even get low IMO, but i'd like it tested/confirmed/reviewed by someone other than me :P19:15
TheLordOfTimehttps://bugs.launchpad.net/ubuntu/+source/php5/+bug/1059272  <-- that's the bug19:16
uvirtbotLaunchpad bug 1059272 in php5 "php5-fpm init.d script does not return when php5-fpm  is started or stopped" [Undecided,New]19:16
TheLordOfTimemore of an aesthetics thing than anything else.19:16
TheLordOfTimes/aesthetics/reporting/19:16
TheLordOfTimeafaict, that's on precise, i havent loaded up a quantal VM that hasnt imploded.19:17
=== cpg|away is now known as cpg
=== dendro-afk is now known as dendrobates
zuladam_g: is that ec2 bug on the openstack-ci?19:47
adam_gzul: what do you mean?19:49
zuladam_g: https://bugs.launchpad.net/bugs/106116619:50
uvirtbotLaunchpad bug 1061166 in nova "ec2 instance IDs are broken after folsom upgrade" [Undecided,New]19:50
adam_gzul: what do you mean is it on the openstack-ci? was it triggered there? no19:50
zulok19:51
zuljust checking19:51
zuladam_g: mind if i use the openstack-ci lab to test it out?19:54
adam_gzul: sure, if you trigger the precise_essex_deploy_proposed you'll get an essex install you can upgrade19:59
zulcool thanks19:59
=== dendrobates is now known as dendro-afk
uvirtbotNew bug: #1061212 in vsftpd (main) "package vsftpd  not installed  failed to install/upgrade: subprocess installed post-installation script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/106121220:30
howdypartnerHowdy all. I set up a small lan and I have a client that can ping the server through the switch but I can't seem to get it to access the internet. Do I have to do some port forwarding on the server or ?20:42
unlesshey hi!20:42
holsteinhowdypartner: you'll need to congigure your router to allow it to be "seen"20:44
holsteinhowdypartner: you can forward a port around the router's firewall, or put the machine in the "dmz" and run a firewall out there20:44
howdypartnerholstein: My server is acting as the router. I set it up as a dhcp server20:44
howdypartnerholstein: modem -> dhcp server -> switch -> client is how i have it set up20:45
holsteinhowdypartner: i doubt the server is the only thing between you and the internet.. i would confirm the ip address, and check what ports your isp might be blocking20:45
holsteinwhat did i do? i forwarded a port in my ddwrt's router config.. and i use a dyndns address20:46
howdypartnerholstein: Well, I can ping from the server but the client can only ping the server. So I assumed it might be an iptables issue?20:47
howdypartnerping google*20:47
unlessI am accessing my remote server and I need to run from inside it a ssh localhost. I did generate a public key and renamed it to authorized_keys but it still asking me for password from a remote connection point of view.20:47
baarthor@unless access rights for authorized_keys are ok?21:31
baarthorthink 600 should be ok21:31
uvirtbotNew bug: #1061244 in samba (main) "Fix net rpc share allowedusers to work with 2008r2" [Undecided,New] https://launchpad.net/bugs/106124421:31
=== dendro-afk is now known as dendrobates
axisyshow to provide default answers to apt-get install libpam-ldap ?21:50
=== Skaag_ is now known as Skaag
uvirtbotNew bug: #1061277 in openssh (main) "ssh ignores ssh_config" [Undecided,New] https://launchpad.net/bugs/106127722:01
=== cpg is now known as cpg|away
=== cpg|away is now known as cpg
cincinnatusI noticed that Webmin is showing signs of aging... but did anything replace it?22:41
SpamapScincinnatus: Zentyal is the closest thing22:42
cincinnatusSpamapS: It doesn't even come close though :( It creates a basic virtual server, and that's it. It has very little knowledge of Apache22:44
cincinnatusIs there an advanced Apache module out there?22:45
cincinnatus(to configure redirects, etc)22:45
cincinnatusfor Zentyal, that is22:45
SpamapScincinnatus: dunno.22:51
cincinnatusAt work, I usually administer Linux boxes with CLI... However, it feels like so last century... It's hard to believe things have gone backwards since the last time I used Webmin22:55
cincinnatusSo I'm probably missing something22:55
SpamapScincinnatus: well, the whole "admin a single box" paradigm is kind of going away :)23:01
Eitanhey gents, quick question on ulimits, i am having the darnest time getting the ulimit changed permanent. I can change stach size by doing ulimit -s XXX size. but when i change /etc/security/limits.conf  * hard stack 10240 it wont affect ulimit even after restart. I also went ahead and made the cahnge to /etc/pam.d/common-sessions23:08
Eitandont know what i could be missing23:08
SpamapSEitan: /etc/security/limits only affects logged in users with a pam session23:11
SpamapSEitan: so if you're trying to affect the limits for services, thats the wrong way23:11
Eitanok23:16
Eitani see23:16
Eitani was trying to affect the limit for user: postgres23:17
Eitanor a number of other users23:17
Eitanso that would not be the way to do it?23:17
sarnoldEitan: depends upon how the user postgres is running the processes in question; if they are started via init (upstart), put the ulimit commands in the initscript / config file. If they are started via a user logging in via ssh or getty, make sure pam_limits is configured for whichever service they use to log in.23:20
Eitanwell postgresql runs upstart23:21
Eitanoh i see23:21
Eitanthats makes sense to add the ulimit commnads to the initscript23:22
RoyKwhy do you want to ulimit postgres?23:23
Eitanthe guy developing the application wants those tweaks made to postgres23:24
Eitani dont thinks nessesary23:24
Eitanbut thats what he wnats23:24
RoyKit will probably make postgres crash23:24
Eitanwell, he will have problems with his application then, lol23:25
Eitanill let him know23:25
RoyKpostgres tries to allocate memory and gets an error and crashes23:25
RoyKENOMEM - boom23:25
sarnold10megs of stack may be plenty23:26
RoyKbetter fix the application23:26
sarnoldI don't know postgres specifically, but stack use tends to be higher on "unbounded" applications, especially ones that may make recursive calls. databases aim for more predictability.23:26
sarnoldI bet there's a reasonable number you can pick -- maybe 10 megs, maybe 100 megs -- that a non-broken postgres will always stay within.23:27
RoyKpgsql calls can be recursive23:27
RoyKand all languages can be written uglily ;)23:27
sarnoldRoyK: not SQL queries -- the C implementation23:28
RoyKsarnold: is that what Eitan is doing?23:28
sarnoldRoyK: yeah23:29
RoyKsarnold: there may be plenty of pgsql fun in an sql statement...23:29
sarnoldRoyK: indeed :) I just have a feeling that the pgsql team's execution engine wouldn't go through unlimited stack to execute it :)23:30
Eitanill let him know guys23:31
Eitanthanks23:31
RoyKsarnold: I have a feeling there might not be much stack checking in pgsql...23:31
sarnoldRoyK: it wouldn't be explicit in their code; it'd be in how they write their function calls.23:33
sarnoldit'd be answerable probably wit ha static code analyzer :)23:33
* RoyK is a wee bit worried about sdb http://munin.karlsbakk.net/munin/karlsbakk.net/smilla.karlsbakk.net/index.html#disk23:38
DavieySpamapS: hey, can you work out if you or Norvald should be drafter for https://blueprints.launchpad.net/ubuntu/+spec/servercloud-r-mysql please23:56

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!