/srv/irclogs.ubuntu.com/2012/11/08/#ubuntu-server.txt

=== cpg is now known as cpg|away
=== cpg|away is now known as cpg
=== cpg is now known as cpg|away
=== n0ts_off is now known as n0ts
=== n0ts is now known as n0ts_off
fang0654Anyone know of any way of automatically updating tripwire when security updates are installed, or of a better means of checking that no system files are tampered with automatically?03:04
fang0654nevermind, looks like debsums will do what I need03:05
=== The_Pugilist is now known as DaveR
=== n0ts_off is now known as n0ts
BaldFatI have samba working on my server for printer but no file shares show04:42
=== Err404NotFound is now known as Error404NotFound
=== cpg|away is now known as cpg
=== smb` is now known as smb
=== codingenesis is now known as nerd
uvirtbot`New bug: #1076277 in rrdtool (main) "package rrdcached 1.4.7-1 failed to install: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 139" [Undecided,New] https://launchpad.net/bugs/107627708:51
=== mcclurmc_away is now known as mcclurmc
danieljsHello. I'm trying to install Phantomjs 1.7 on Ubuntu 11.04 x64. the hosting is mediatemple. I get "segmentation fault". Anyone can help? thank you.08:55
TheLordOfTimedanieljs:  you know 11.04 is end of life right?09:10
uvirtbot`New bug: #1076286 in puppet (main) "Puppet agent not correcly configuring facts synch'd from master" [Undecided,New] https://launchpad.net/bugs/107628609:21
cjsI did an install of a server from the Ubuntu alternate install disc with two mds: /boot and LVM container, and a root and swap inside the LVM container. However, when I try to boot that disk, it just hangs with a blank screen (apparently before or around the very start of grub). Any thoughts on what's wrong?09:25
cjs(And yes, I'm going to re-do the install from the server disk. Brain fart.)09:25
=== edamato-afk is now known as edamato
uvirtbot`New bug: #1076290 in cobbler (universe) "cobbler-web throws 500 internal server error" [Undecided,New] https://launchpad.net/bugs/107629009:36
=== caribou_ is now known as caribou
danieljsHello. I'm trying to install Phantomjs 1.7 on Ubuntu 11.04 x64. the hosting is mediatemple. I get "segmentation fault". Anyone can help? thank you.10:56
danieljsI can't install a newer version of ubuntu on mediatemple...10:57
guckigood morning10:59
guckiI'm using latest ubuntu quantal server and have a serious kvm memory problem.10:59
guckiA kvm guest i started with -m 2048 (so 2048 of ram) is actually taking 2700 (res) and 4700 (virt) as seen by top or ps on the host...?! :-(11:00
guckihow can i debug and fix this? :-)11:00
cjsgucki: That may not be a problem.11:01
guckicjs: why not? the guest is consuming much more resources than it should?11:02
cjsgucki: Possibly not. Let me just check my guests.11:02
cjsgucki: Though I am on an 8.04 system here.11:03
cjsgucki: Ok, so my guests set up for 1572864 bytes of memory have a VSS of 1787264 and RSSs ranging from 612600 to 78820011:04
cjsOh, wait, one has a VSS of 1818048.11:04
koolhead17here i am , this is me!!11:05
guckicjs: mh, so a little overhead but not that much as on my system...11:05
cjsgucki: I'm guessing that my RSS is considerably less than allocated because I rebooted yesterday and these VMs don't do much (and in particular, don't use much memory).11:06
cjsBut remember, with all memory in use, you'd expect RSS (when you're not paging to swap) to be the size of the memory allocated to the VM *plus* whatever KVM is using for its own code, data, etc.11:07
cjsAnd VSS may not all be memory that's actually in use. I believe that VSS represents all mapped pages, regardless of whether they've ever been backed by disk or physical RAM.11:08
cjsSo, you might be able to work out what's going on by looking at your total RAM+swap in use, and figuring out how much larger that is than the memory allocated to the guests.11:08
cjs(Oh, yeah, RSS may also represent shared pages, if I recall correctly. So four VMs would share the pages holding the KVM code that they're running.)11:09
guckicjs: yes, so i'd expect an rss of 2048mb + a few megs (not 700!) for kvm..11:17
guckicjs: guess i'll write to the kvm mailinglist..11:18
cjsgucki: Yeah, I guess 700 MB is a bit much.11:27
cjsgucki: But as I said, take a look at total memory usage of your system and see if there's hundreds of megs not account for there, too.11:27
Davieykoolhead17: Have you met evilnickveitch ?11:28
Davieykoolhead17: evilnickveitch is the evilest, bestest doc king in the world (second to you ofc.).11:28
koolhead17hello evilnickveitch :)11:28
evilnickveitchah! koolhead17 , yes, we have conversed briefly!11:29
Davieykoolhead17: he might be able to help you drive the docs you were talking to me about.11:29
koolhead17Daviey: we exchanged email11:29
koolhead17thanks Daviey :)11:29
koolhead17hello evilnickveitch again!! :D11:29
evilnickveitchso there Daviey, nobody needs you :P11:29
evilnickveitchhi koolhead17 , we should catch up sometime :)11:30
koolhead17evilnickveitch: yes sir!!11:31
koolhead17evilnickveitch: Daviey is Daviey :D11:31
Davieyevilnickveitch: I am just a dumb manager now, i know.11:33
koolhead17Daviey: so your saying manager role makes ppl dumb :D11:33
Davieykoolhead17: Yep.11:34
koolhead17evilnickveitch: pm?11:34
evilnickveitchok11:34
koolhead17Daviey: now that is harsh!! :D11:34
cjsSo when my 12.04 amd64 server install boots, I get a grub menu, and things seem to work ok if I do a rescue boot. But if I do a non-rescue boot, I end up with a blank screen. (The monitor's still getting a signal, but there's no text or anything else.) Ctrl-Alt-F1 through F8 don't bring up anything, either. Ideas?11:43
=== Ursinha is now known as Ursinha-afk
=== Ursinhal is now known as Ursinha
cjsAnybody here know how I change the option to abort or continue a boot when the RAID is broken?12:17
xnoxcjs: dpkg-reconfigure mdadm12:22
xnoxshould offer to answer boot-degraded question.12:23
xnoxor you can set boot option to boot-degraded.12:23
xnoxrebuild initramfs.12:23
=== Ursinha-afk is now known as Ursinha
ironmHello. I run buntu-server 12.04 based KVM host. I am not sure if it is my wrong configuration or a kvm networking issue. Both  <interface type='direct'> and <interface type='bridge'> *don't* work. Only  <interface type='network'> works as expected. Config files including description of the test environment are at http://rsync.it-infrastrukturen.org/.kvm/ and in this file: http://rsync.it-infrastrukturen.org/.kvm/README-kvm-networking-12:31
ironmissues.txt12:31
ironmhttp://rsync.it-infrastrukturen.org/.kvm/README-kvm-networking-issues.txt12:32
RoyKxnox: ut should be *default* to boot degraded!12:32
RoyK!bug 105954112:32
uvirtbot`Launchpad bug 1059541 in initramfs-tools "Change default behavoir to boot degraded RAID" [Undecided,New] https://launchpad.net/bugs/105954112:32
ironmIs there any possibility to run KVM in debug mode or other ubuntu specific trace possibilities? Thank you in advance for any hints.12:33
xnoxRoyK: the decision was from before my time. At the time there was a divide between: never boot system if it's known to not have assumed reliability vs always boot even if degraded.12:33
patdk-lapheh, every hardware raid I have ever worked with, boots degraded12:34
cjsxnox: Thanks!12:38
a_okI'm using lsyncd, but the ubuntu package only contains an old fashioned init script. how do I make it start on boot?12:42
RoyKxnox: I'm not blaming you, just saying that RAID is pretty useless if a server fails to boot with a single dead drive12:43
a_okRoyK: depends on why you are using it. If you are going for speed for example RAID can make quite a difference12:45
patdk-lapheh?12:46
patdk-lapa raid with one disk bad, working, is faster than a raid with one disk bad that won't boot12:46
cjsxnox: Actually, dpkg-reconfigure mdadm didn't seem to do the trick, because it didn't add bootdegraded=true to my linux line in the grub config.12:46
xnoxcjs: did you run update-initramfs ?12:47
cjsxnox: (Or at least, that's what I'm told on boot.)12:47
RoyKa_ok: it's no point in checking if a disk is missing - if you can mount it, mount it - if you can't, it'll throw you into single anyway12:47
=== cpg is now known as cpg|away
cjsxnox: I thought that dpkg-reconfigure did that for me.12:47
xnoxcjs: there are two interfaces one is a fine in the initramfs and the other one is linux-kernel boot option.12:47
a_okpatdk-lap: mmm guess I budded in a conversation without having all the background info sorry.12:48
xnoxcjs: can you unpack initramfs and check? Instructions here: https://wiki.ubuntu.com/Initramfs12:48
cjsSo I need either one, but not both? I.e., my system should work without the bootdegraded=true, so long as other things are set?12:48
cjsxnox: Ah, I just tried the reconfigure again, and it printed, afterwards: "update-initramfs: deferring update (trigger activated)".12:49
=== n0ts is now known as n0ts_off
* RoyK guesses Dell has hired high school kids cheaply to develop their iDRAC software12:49
cjsxnox: I use "update-initramfs -u"?12:49
cjsxnox: yeah, update-initramfs -u did it. Thanks.12:52
otfrom'lo all12:58
uvirtbot`New bug: #1076353 in nova (main) "nova [-] Could not find driver for connection_type None" [Undecided,New] https://launchpad.net/bugs/107635313:01
caribousmoser: thanks for the Merge on recordfailtimeout for Oneiric13:04
caribousmoser: anything else that is required ? You mentioned something about not being marked Merged13:04
uvirtbot`New bug: #1076306 in openssh (main) "Upgrading of OpenSSH on 10.04 LTS" [Undecided,New] https://launchpad.net/bugs/107630613:05
BaldFat_I have Samba serving printer fine but not files. Nothing in my samba logs and my smb.conf looks standard. What tools can I use to trace down my issue?13:30
smosercaribou, you must have requested merge review from some group, and i'm not in that group, so i couldn't mark the thing as "merged" . maybe you can.13:39
caribousmoser: lemme check...13:39
caribousmoser: if you meant the "Status" field switched to Merged, looks like I just did, so yes I can13:40
caribousmoser: anything else needed so it get uploaded to -proposed ?13:42
caribou(thought I think you mentioned that it had already been done)13:42
smosercaribou, i thought i uploaded. did i not?13:43
caribousmoser: maybe you did, but I thought it had to be flagged as Merged for the upload to happen13:44
* caribou is still getting familiarized with the whole SRU proces13:44
smosercaribou, its interesting...13:48
smoserubuntu distributed development has different levesls of acceptance.13:48
smoserin the end, the archive is definitive.13:49
caribousmoser: ok, just got your email. That's what I thought13:51
caribousmoser: just that I went to look at the SRU request queue and did not see anything related to grub213:51
smoseri just sent you an email. http://paste.ubuntu.com/1342560/13:51
smoser(for anyone playing along at home)13:51
caribousmoser: is the process different for packages in Universe (which is the case for grub2) ?13:54
=== dendrobates is now known as dendro-afk
smosergrub2 is not in universe.13:54
smoserbut it is no different for packages that are.13:55
Davieytyhicks: Hey, are you looking to merge acpid? :)13:57
Mez313:59
=== dendro-afk is now known as dendrobates
Aisonit looks like some service on my server is blocked by ufw14:08
Aisonfileserv kernel: [876531.112366] [UFW BLOCK] IN=bond0.10 OUT= MAC= SRC=10.0.0.2 DST=239.255.255.253 LEN=131 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=UDP SPT=34570 DPT=34570 LEN=11114:08
Aisonthis is logged on my server14:08
Aisonand the source is my server, destination some multicast address14:08
=== edamato is now known as edamato-brb
patdk-wkaison, and your question?14:28
Aisonpatdk-wk, oh yes :P well, why is something blocked coming from the same machine?14:30
Aisonit is sent by 10.0.0.2 and received bei 10.0.0.2?!?14:31
patdk-wkcause that is not *coming* from your machine14:31
patdk-wkIN=bond0.10 OUT=14:31
patdk-wkso it came IN bond0.10 and to you14:31
Aisonbut src is 10.0.0.214:31
Aisonhmm14:31
patdk-wkyou have never heard of address spoofing, or more than one machine configured with the same ip?14:32
Aisonand I read the logs on 10.0.0.214:32
Aisonpatdk-wk, it is just a small testing network14:32
Aisonthere is by sure no other machine with same ip14:32
patdk-wkif it was going OUT from your machine it would say14:32
patdk-wkIN= OUT=bond0.1014:32
patdk-wkbut it's multicast, it might be looping your outgoing packet back in to you14:33
patdk-wkI'm not sure on the rules about that14:33
Aisonyes, that's what I think also, but then I wounder what application on 10.0.0.2 creates this multicast packet14:34
=== edamato-brb is now known as edamato
=== Err404NotFound is now known as Error404NotFound
=== n0ts_off is now known as n0ts
uvirtbot`New bug: #1076442 in nova (main) "nova-novncproxy has a missing dep on websockify" [Undecided,Confirmed] https://launchpad.net/bugs/107644216:25
SirScottmdadm --device --scan is giving me an ARRAY of '/dev/md/0' and not '/dev/md0'.  Is that really what I want in my mdadm.conf?16:27
xnoxSirScott: sure, it's valid name.16:29
xnoxSirScott: read the manpages. It could be that you have a partinionable md device.16:29
SirScottxnox: thanks, don't know why i didn't bother noticing it in /dev/md/16:29
=== matsubara is now known as matsubara-lunch
SpamapSSirthe question is, why doyou want an mdadm.conf ?16:39
SpamapSdoh16:39
SpamapSI hate when they leave16:39
xnoxSpamapS: that was what I was thinking as well... but hey it was easier to answer the question that was asked =)16:40
tyhicksDaviey: Hey - I'll take a look at the merge today17:04
uvirtbot`New bug: #1076464 in logwatch (main) "unmatched entries for gnome-screensaver" [Undecided,New] https://launchpad.net/bugs/107646417:10
uvirtbot`New bug: #1076461 in logwatch (main) "unmatched entries for smartd" [Undecided,New] https://launchpad.net/bugs/107646117:14
=== alamar is now known as julian
Davieytyhicks: thanks!17:31
=== matsubara-lunch is now known as matsubara
tempspaceHas anybody run into any issues with Ubuntu Server and the Intel Xeon SandyBridge E E5-465017:44
=== n0ts is now known as n0ts_off
zulhallyn: im going to upload libvirt 1.0.0 if you have any objections17:59
=== julian is now known as alamar
NotLarryI did a reboot -n on ubuntu 11.04 server this morning and now I get "ALERT! /dev/mapper/MachineName-root does not exist" and a busybox, initramfs prompt.  Raid array, which checks out at boot.  Nothing strange has happened (i applied not updates or installs) and the system had already rebooted twice today.  Can someone point me to what is going on?  No encrypted drives  or directories.  and ls /dev/mapper/ shows a link to ../d18:12
sarnoldNotLarry: cut off at "../d"18:14
NotLarry../dm-0, which seems to exist18:15
uvirtbot`New bug: #1076489 in php5 (main) "Cannot be uninstalled without installing Apache2" [Undecided,New] https://launchpad.net/bugs/107648918:16
Davieyjamespage: ceph ftbfs in precise, expected18:25
Daviey?18:25
Davieyjamespage: armel, armhf still building18:26
=== mcclurmc is now known as mcclurmc_away
ironmhello. Please allow me one question. Is it possible to bring during the boot "unused" eth interfaces up? (without giving them an IP address)?18:27
ironmI run ubuntu-server 12.04.1 LTS18:27
ironmI have in iterfaces like:18:28
ironmauto eth118:28
ironmiface eth1 inet manual18:28
zulDaviey: i think its a build ordering issue for ceph18:30
Davieyzul: took 1 hour, 38 minutes, 0.1 seconds18:31
Davieysadly i can't tell you the milliseconds, which are vital18:31
zulheh18:31
NotLarrythanks all, after about the 4th reboot it came up18:39
=== edamato is now known as edu-afk
jamespageDaviey, it may be fussy about leveldb18:48
jamespageinfact it is - I remember now18:49
=== peterrus- is now known as peterrus
cornfeedis there a way to tell apt to make sure installs fresh copies of all the config/init/default files again?19:03
cornfeedfor a certain package?19:03
escottcornfeed, http://serverfault.com/questions/82801/linux-how-to-restore-config-file-using-apt-get-aptitude19:05
cornfeedfancy, good find, thanks!19:05
cornfeedhmm didnt work19:07
cornfeedbrb19:07
cornfeedwow, i ended up having to extract it manually19:24
=== yofel_ is now known as yofel
BaldFat_cornfeed: apt-get purge <package> then apt-get install <package>19:55
cornfeedyep didnt work either19:55
sarnoldreally?19:55
BaldFat_purge should get rid of everything. What package may I ask?19:55
sarnoldI've never seen that one fail; though you're not always in a position to be able to _use_ it...19:55
cornfeedcouldnt make this stuff up19:55
cornfeedyeah the weirdest thing is the file it was complaining about didnt even exist19:56
BaldFat_cornfeed: fact is stranger then fiction19:56
cornfeedinspircd19:56
escottBaldFat_, purge doesnt forget config modifications for some reason19:56
BaldFat_so this is a package and not something you built?|19:56
cornfeedi have compiled it manually, then that didnt work so i removed all the files I had in place, rebooted, and tryed installing through apt, which resulted in that error19:57
cornfeedcorrect19:57
cornfeedbuilt, removed (entirely), then did apt19:57
BaldFat_purge should and I swear it has before but who knows. I really find apt and aptitude as not the best (DUCKS) I love zypper for the last 5 years it has been great for me and the one server tht uses it.19:57
cornfeedyeah, apt leaves alot to be desired19:58
cornfeedi like gentoo's portage soooo much19:58
escottcornfeed, something like --force-confnew should work for you19:58
BaldFat_cornfeed: yeah that makes sense then. I hate building stuff because you have to manually look at the sh and figure out what got sent where. PC-BSD and Mac has the solution but no one will ever do it in Linux I am afraid19:58
escottor a purge followed by a --force-confmiss19:58
BaldFat_cornfeed: Google says they use Ubuntu mainly because apt and aptitude is MUCH better then yum and zypper :P19:59
cornfeedlol19:59
cornfeedlinux and opinions20:00
cornfeeda source of endless hilarity and argument20:00
BaldFat_make it so much more fun. We can fight among ourselves for decades instead of the OS wars20:01
BaldFat_also VIM20:01
cornfeedlol20:01
BaldFat_the newer people aka the last 2 years or so have no idea the rpm vs deb and vim vs everything wars were. That's a good thing.20:02
BaldFat_cornfeed: This seems like a solution: dpkg -i --force-confmiss <package>20:04
cornfeedtried that too20:10
cornfeedno luck20:10
zulhallyn: ping20:11
escotti think the force confmiss only forces the installation of missing config files. so you would have to remove the file in question first20:24
=== r0tha is now known as r0tha|wrk
cornfeedokay, so this leads to another question. who do I contact to get a package updated?20:35
autifI have hit this bug while customizing an installation. https://bugs.launchpad.net/ubuntu/+source/debootstrap/+bug/100113121:24
uvirtbot`Launchpad bug 1001131 in debootstrap "debootstrap fails to install customized Ubuntu" [Undecided,Confirmed]21:24
autifI was hoping someone could point me to how to go about repackaging debootstarp from a deb file21:25
autifinto a udeb21:25
Davieydave@voodoo:~$ curl http://libvirt.org/news.html 2>/dev/null | grep "Chuck Short"21:31
Daviey      ARMHF: implement /proc/cpuinfo parsing (Chuck Short),<br />21:31
Daviey      ARMHF: CPU Support for armhf. (Chuck Short),<br />21:31
Davieywoot!21:31
zulwhee!21:31
jamespagenice one zul!21:32
jamespagezul, are you or hallyn planning a libvirt upload for raring anytime soon?21:32
zuljamespage: im sitting on one right now but i have to talk to hallyn first probably monday21:33
jamespagezul, any chance you could enable the rados pool support?  I think it just needs a bd on librbd-dev21:34
zuljamespage: it runs win28k just fine :) sure..21:34
jamespagezul, lo21:34
jamespagel21:34
jamespagecan't type21:34
zultoo much karaoke21:34
=== cpg|away is now known as cpg
tboathey all! I'm currently trying to configure OpenVPN on my 12.04 server, and I get the following server when attemting to create ssl authentications: ./easy-rsa/build-ca: 8: ./easy-rsa/build-ca: ./pkitool: not found21:46
tboator does anyone have a link to a good OpenVPN setup guide?21:51
=== cpg is now known as cpg|away
sarnoldtboat: looks like pkitools is packaged in /usr/share/doc/openvpn/examples/easy-rsa/2.0/pkitool in the openvpn package21:54
=== cpg|away is now known as cpg
tboatyes, and it i moved it to the openvpn/easy-rsa folder, where i am running the build-ca command21:56
tboatso it is there, but doesn't pick it up21:57
sarnoldit is perhaps not executable in a documentation directory :)21:59
tboati copied it from the doc directory to /etc/openvpn22:03
tboathad to edit /vars, got it figured out :)22:06
ironmhello. Is there any other possibility on ubuntu-server 12.04.1 LTS for interface bondind (teaming/aggregation) than using ifenslave ?22:07
Davieyzul: can you triage bug 1076442 pls22:08
uvirtbot`Launchpad bug 1076442 in nova "nova-novncproxy has a missing dep on websockify" [Undecided,Confirmed] https://launchpad.net/bugs/107644222:08
Davieybug 1052677 , bug 1073289 , bug 107327522:09
uvirtbot`Launchpad bug 1052677 in horizon "Error when clicking on OpenStack logo" [Medium,Fix released] https://launchpad.net/bugs/105267722:09
uvirtbot`Launchpad bug 1073289 in nova "nova-common has an incorrect dep on python-nova (= 2012.1-0ubuntu2)" [Undecided,New] https://launchpad.net/bugs/107328922:09
uvirtbot`Launchpad bug 1073275 in python-glanceclient "python-glanceclient has a bad version dep on python-prettytable" [Undecided,New] https://launchpad.net/bugs/107327522:09
AaronHomeHello.  I have an Ubuntu10 server that has its one ethernet port config'd in /etc/network/interfaces as "eth0". I've built a new Ubuntu12 server on another disk, attached to another machine.  Now time to swap.22:18
AaronHomeBut the old Ubu10 bug, with the new Ubu12 disk in it boots ok, but inisist on 'talking' to the ethernet port that used to be "eth0" as "eth2".22:19
AaronHomeI've no idea why, but would _like_ to keep it as, or change it back to, "eth0".22:19
AaronHomeCan I do that somehow?22:20
erichammondsmoser, utlemming: http://cloud.ubuntu.com/ami/ is showing the AMI id for the old 099720109477/ubuntu/images/ebs/ubuntu-precise-12.04-amd64-server-20120424 instead of the newer 099720109477/ubuntu/images/ebs/ubuntu-precise-12.04-amd64-server-20121026.122:22
smosererichammond, unfortunately thats a known issue.22:22
lifelessAaronHome: you have udev rules that are pinning the new boxes ethernet ports as eth0/eth122:22
erichammondsmoser: It came up here: http://askubuntu.com/questions/214431/22:23
AaronHomelifeless: Those are autogenerated then?  _I_ never created them intentionally/manually.22:25
lifelessyes22:25
AaronHomelifeless: Found it (/etc/udev/rules.d/70-persistent-net.rules) Changed it.  Thanks.22:29
lifelessno probs22:30
=== Shehrazad is now known as ElxirVitae
=== ElxirVitae is now known as ElixirVitae
=== Shehrazad is now known as ElixirVitae
uvirtbot`New bug: #1076656 in mysql-5.5 (main) "mysql --ssl-capath option doesn't work" [Undecided,New] https://launchpad.net/bugs/107665623:06
jorenIs there a recommended way to setup an apt cache/proxy server these days? What's the best tool to use for that?23:39
patdk-lapapt-get install apt-cache-ng23:40
lifelessapt-get install squid-deb-proxy23:40
patdk-lapI always have issues using squid to cache apt repo's23:41
jorenk, thank you both23:41
jorenI'll use the ng thing, I think that's what I was looking for23:41
patdk-lapthen for existing systems, you need to add someting like:23:42
patdk-lapAcquire::http::Proxy "http://xxxx:3142";23:42
patdk-lapinto /etc/apt/apt.conf23:42
jorencool23:42
joreneasy enough23:42
jorenwould be easier if puppet was everywhere :P23:42
patdk-lapheh, I do it at system install, so not bad23:43
patdk-lapand use different dns overrides for local or general internet caches23:43
jorencool, ya, I'll have to add it to my preseed23:43
jorenlocal mirror is long over due23:43
jorener local cache23:43
jcastro_just put the same cache server in your preseed23:43
bananapieI installed fail2ban, it doesn't work because I don't accept passwords on ssh.23:43
jcastro_and after the first installation you'll be good23:44
jorenwell, *seems* to work23:45
jorenI guess the really test will come later on23:46
jorenreal, rather23:46
jorenbananapie, http://serverfault.com/questions/248376/fail2ban-bans-me-after-a-series-of-successful-logins <- perhaps?23:49
jorenthough, you probably don't need fail2ban on ssh if you only allow ssh keys.23:50
bananapiejoren: Nice :D23:50
bananapieI stopped using passwords years ago.23:50
patdk-lapjoren, still need it :(23:50
patdk-lapI have had people dos a t1 line, doing ssh attempts23:51
jorenI guess if you only have 1.5mbit, then ya :P23:51
patdk-lapso just to keep bandwidth under control :)23:51
jorenand ya, I guess it's still useful23:51
bananapieHow can I simulate ssh hacking on my server ?23:52
bananapieI did for i in `seq 1 50` ; do ssh serverip; done;23:52
bananapieBut it didn't ban me23:53
bananapieI didn't even see anything in the logs :(23:53
jorenoh, if it's *not* banning you, that server fault thing probably wouldn't do it23:53
beeg98I would just use ssh randomuser@myserver23:54
jorenhis for thing shoulda done it23:54
jorenbananapie, nothing shows up in /var/log/authlog ?23:56
bananapiedat's right23:59
bananapienothing shows up in auth.log, even though I see the traffic with ngrep23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!