/srv/irclogs.ubuntu.com/2013/05/19/#ubuntu-server.txt

krysany vmlinuz or initrd gurus out there? I feel like mine might be corrupted and thats why i cant boot00:12
yofunhow can i search for "Failed launched: No such file or directory" in *.log files in ssh?02:29
=== thesheff17 is now known as thesheff17_
mardraumyofun: grep04:10
=== akashj87_ is now known as akashj87
bigbrovarHi guys trying to incease the ulimt on ubuntu for a tomcat user I created15:05
bigbrovarulimit -n for this users hows 102415:06
bigbrovarbut when I cat /proc/sys/fs/file-max the limit is set to 59919115:06
enragedIf I have, let's say, 10 servers that I want to control over SSH from a remote location, would it be more secure to have 1 server act as a key server which I access over the internet, and then after connecting to the key server, port forward to the other 9 servers OR simply carry keys for all 10 servers and connect to each one independantly?15:20
RoyKwell, if that one server is compromised, the attacker will have full access to the others ;)15:25
enragedExactly my concern.15:26
enragedSo you would agree it would be better to have each server accessed independantly?15:26
RoyKmaybe15:26
RoyKbut if you have a common ssh server, you can close ssh from the net from the others15:26
RoyKnot sure what's best15:26
enragedTheoretically couldn't I run clusterSSH to shutdown all 10 servers at the same time?15:28
enragedOfcourse I'd need to be local to bring them all back online, but in an emergency situation where security rather then accessibility is the concern, that should work?15:29
RoyKif  an attacker gets root, he or she probably won't shut down the systems but rather plant a rootkit there15:31
RoyKI guess a common login server should be easier to manage15:31
RoyKthen setup the others to block ssh access from the net15:31
RoyKsetup the login server with denyhosts/fail2ban/something15:31
RoyKand make sure it's updated regularly, and not running any other services15:32
enragedExactly my thinking15:34
enragedWhatever the setup for security was on the key server I was going to install on each of the 10 servers independantly if I didn't bother going with the key server15:35
enragedAnd then I hoped to manage them over cluster SSH15:35
enragedSo yeah, fail2ban, SSHkeys with no password access, standard stuff15:35
RoyKdenyhosts may be better - supports distributed ban lists15:36
enragedmm15:36
enraged1 last question - Since this is my first time having to remote SSH to my servers, I can normally run clusterSSH on a Ubuntu desktop which has a GUI, however, I am travelling with a Windows laptop. If I connect by SSH to the key server, with Putty, can I run clusterSSH in the terminal because all references I can find to it online mention the opening of a terminal for each server with 1 terminal acting as the main,15:40
enragedSorry, does Cluster SSH work over a Putty terminal?16:00
enragedAssumably if I connect to a key server with ClusterSSH installed16:00
RoyKhttp://paste.ubuntu.com/5681058/ <-- nice drive size17:26
qman__nice17:27
RoyKseems a disk died :)17:27
JeruvyTrying to ping INTO server, noticed shorewall is installed, is there a quick way to disable this for testing?18:25
RoyKJeruvy: iptables -F INPUT18:35
RoyKor something18:35
JeruvyRoyK thank you that worked.18:39
JeruvyI see I'm going to have to brush up on this.  Cheers!18:40
=== hachre_ is now known as hachre
SyriaHello! I have a VPS , Can I know if other users are using Tunnels and browsing websites using socks proxy through it?19:54
RoyKUser Capacity:        600,332,565,813,390,450 bytes [600 PB]19:57
=== ToBeFree is now known as matjohnson
=== matjohnson is now known as ToBeFree
James_EppHow can I make the tftpd-hpa service start on boot? I edited /etc/default/tftpd-hpa to include 'RUN_DAEMON="yes"' but this does not resolve my issue.22:51
=== racedo` is now known as racedo

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!