/srv/irclogs.ubuntu.com/2013/10/16/#ubuntu-uk.txt

diddledanone more day till the end of the world, otherwise known as ubuntu release day04:28
daftykinsoh deary me04:28
daftykinswhat are you doing up diddledan ?!04:28
diddledandaftykins: didn't go to bed :-/04:28
daftykinsD:04:28
daftykinswould you like to see a picture?04:29
daftykinshere is my friends trap-like home:04:29
daftykinshttps://www.dropbox.com/s/2yjdj6vtc8sq0hs/IMG_20131016_012728.jpg04:29
daftykinstoilet... hole to certain death04:30
diddledandoubleyoo tee eff04:33
diddledanthat's twisted04:33
daftykinsinorite04:34
diddledanwhat's down there?04:34
daftykinsmostly that friends central heating systems etc.04:57
daftykinsand two flats they rent out04:57
daftykinsbed time!05:16
popeyMyrtti: awww http://imgur.com/6oBRyyr06:53
Myrttiawwww06:54
popeydirecthex: bee and puppycat is odd07:10
MooDoomorning all07:12
diploMorning all07:18
MooDooorning dipl07:20
MooDoooh I give up with spelling today07:21
diplohah07:26
diploMorning mate07:26
TheOpenSourcereryo07:32
MooDoohowdo TheOpenSourcerer07:33
BigRedSGooood Morning!07:42
popeyYour new giant time waster is.. http://orteil.dashnet.org/cookieclicker/07:48
BigRedSHaha, I spent 20 billion cookies on a grandma yesterday07:53
=== schwuk_away is now known as schwuk
popey07:54
BigRedSI think I've spent more clock cycles on generating cookies in the past couple of weeks than I have ever contributed to scientific research07:59
MyrttiI'm so excited .____________.08:03
SuperMattand you just can't hide it?08:07
SuperMattrelease party tomorrow \o/08:07
BigRedSAh yeah, I need to make sure I leave at a reasonable time this time08:10
BigRedSI know I say that every time, but this time I do actually have stuff to do on the Friday08:10
BigRedSand, yeah, I say that each time, too08:11
bigcalmGood morning peeps :)08:17
MyrttiSuperMatt: nope, too excited!08:24
Myrttihttp://i.imgur.com/RtbbB.gif08:24
SuperMattI'm looking forward to the release party08:25
SuperMattI won't be drinking though, I've given up (again)08:25
Myrttioh yeah there's a release day tomorrow08:25
Myrttiwe'll be on the road08:25
Myrttia roadtrip to the office, no less08:25
bigcalmWow, forgot that tomorrow is Thursday. I have no idea when I am08:26
LaneyFrundesday08:27
Myrttibigcalm: dun dun DUUUUNNNN08:27
bigcalmMyrtti: 1st day back in the office to do work. As much as I hated being ill, I did get used to not having to think about days of the week08:28
bigcalmMorning JamesTait. What day is it today?08:29
SuperMattOscar Wilde was born in 185408:30
SuperMattBoromir reaches Rivendell08:31
SuperMattapparently08:31
SuperMattand apparently tomorrow is the Council of Elrond08:31
Myrttiooohhh!08:32
MyrttiBoromir.08:33
funkyHatAw man, I knew there was somewhere else I was meant to be08:33
SuperMattat the council of Elrond?08:33
funkyHatYes08:33
SuperMattwell you have a day to get to Rivendell08:34
SuperMattget cracking08:34
JamesTaitGood morning all; happy Global Dignity Day! :-D08:34
Myrttiin case anyone is interested in a Philips wet and dry shaver, there's one on Amazon lightning deals in half an hour. I'll be trying to get one for D myself.08:34
SuperMattif you go by car it shouldn't take you anywhere near as long as it took frodo08:34
SuperMattJamesTait: you just listed all the things I don't havae08:34
SuperMatt-a08:34
JamesTaitSuperMatt, maybe Feral Cat Day works better for you?08:35
SuperMattyes thanks08:35
JamesTait\o/08:35
brobostigongood morning everyone,08:37
bigcalmMyrtti: do you have a link?08:38
Myrttibigcalm: http://www.amazon.co.uk/deals-offers-savings http://www.amazon.co.uk/gp/product/B00D84IPF2/08:39
bigcalm100 quid now, what is it likely to be in the lightning deal?08:41
bigcalmThe deals-offers-savings link you pasted doesn't work for me08:41
bigcalmAha, I see08:42
bigcalmWorks via the site with extra gubbins08:42
bigcalmI'm in need of a new shaver08:42
MyrttiI'd say probably 60-7008:43
jpdsbigcalm: https://www.amazon.co.uk/gp/product/B008PPGHOA/08:44
jpdsNote that you do NOT want the newer version.08:45
Myrttioh man that page fails to load fully08:46
Myrttijpds: why?08:46
Myrttilolok "But more importantly, if you ever run out of charge mid-shave, there's no way of using it off the mains! It's cordless only."08:47
Myrttioh man, the leafblowers are back08:48
Myrttiabandon all hope all ye who enter08:48
bigcalmMy current shaver is mains only as well :(08:50
Myrttiyes well that's the exact opposite08:51
bigcalmOops08:58
bigcalmI mean doesn't work when plugged into mains08:58
bigcalmI r ill?08:58
bigcalm50s, hope it's a good deal08:59
shaunorewriting my windows keymap to support all the deadkeys I'm used to.  newfound appreciation for how weird keyboards are, but still too sober to try to this in xkbd (one day ...)08:59
bigcalm80 quid...09:00
bigcalmIs it worth it?09:00
Myrttidunno09:00
bigcalmOoo, with the trimmer attachment, I wonder if Hayley will cut my hair with it09:01
MyrttiDunc said he'd be fine if it's about 50quid09:02
Myrttibefore he boarded his plane09:02
jussiMyrtti: is he flying to TRE or HEL ?09:02
Myrttitre of course09:02
MyrttiStanstead and Pirkkala are so much closer than Heathrow/Luton/Gatwick and Helsinki09:03
* bigcalm drops it from his basket09:03
Myrttibigcalm: yeah I'm not sure it's worth it either09:04
bigcalmMyrtti: thanks for pointing it out though :)09:07
bigcalmI might look in on the deals now and then09:07
DJonesHeh, I ordered that shaver from amazon a couple weeks ago, ended up cancelling the order because they couldn't deliver it & getting a different one09:08
SuperMattI won't buy an electric shaver unless I can run ubuntu on it09:10
SuperMattalso, I would have to actually have to be able to grow a beard09:11
SuperMattmy baby face doesn't allow it09:11
popeyi have hairdressers clippers09:16
popeymore robust09:16
bigcalmpopey: I'm guessing they don't see much action going by a recent mocking of your hair ;)09:19
popey:D09:19
popeyi only use it for beardy09:19
jussihehe09:19
jussipopey: I have those also for hair. need to dig them out again, getting to be a bit of a mop09:20
shaunoI had to get rid of my clippers.  poor impulse control.  More than once I woke up with a hangover and a conscript-cut.09:30
bigcalmHehe09:30
bigcalmUntil reading the whole line, I thought your clippers worked on impulse power09:31
shaunothat could be dangerous09:31
bigcalmImpulse power only Mr Crusher09:31
MooDoomake it sew09:32
shaunoI've been trying to grow my hair back out for years.  but it seems to go through the stages of short, the 60's, urgh, the 70's, and then long.09:33
shaunoit's not so easy to get through the middle stages without getting sick of it and lopping it all off09:33
Laneyit's been ten years since i had my hair cut :O09:34
jussiI hate having hair longer than a few CM09:34
jussioh, if there any kubuntu'ites here we now have polo shirts for sale :D09:35
shaunoI miss long hair.  but in between short and long, thar be dragons09:35
bigcalmI don't miss having a mop09:35
bigcalmMy hair grows quickly and thickly. Not good for anything09:35
directhexmy hair doesn't grow long, it grows curly09:37
directhexsideways nonsense09:37
jpdsMyrtti: Newer version has less battery life+lower quality blades.09:39
Laneyoh hoorah09:40
Laneythe spotify native client started working again09:40
popeywhat version you on?09:40
popeyi feel i should have an update somewhere09:41
popey1:0.9.4.183.g644e24e.428-109:41
Laney0.9.4.183.g644e24e009:41
* popey squints09:41
Laneyi copied it from the about dialog09:41
Laneydifferent machine09:41
directhexgit tag in ordered version number09:41
directhexOH GOD HOW DO I COMPUTER09:42
popey\o/ crashed09:42
Laneymainly checked because i noticed that lastfm scrobbling from the web client was knackered09:42
Laneyhttp://www.last.fm/user/lan3y/now09:43
Laneyace of base :>09:43
popeyhttp://www.last.fm/user/popeydc/now09:43
popey09:43
BigRedSI've had the Top Gun soundtrack on loop for a while, I'm not going anywhere near Last.fm for a bit09:44
Myrttijpds: right09:46
shaunoBigRedS: that's why I don't 'scrobble'.  some things shouldn't be admitted in public :p09:46
Laneybe proud09:46
ixxvilhi09:46
MooDoohi09:46
popeyhi09:46
Laneyhi09:46
Dave2hi09:46
bigcalmHi09:47
ixxvilhow do i set ubuntu t alert me of security updates in the terminal09:47
bigcalmapticron09:47
ixxvilmy previous vps had something like that during login09:47
MooDoobigcalm: oh you had to be different ;)09:47
popeysorry, we can only do "hi"09:47
popeyyeah, there's a motd thing that pops up on login?09:47
bigcalmMooDoo: sorry, can't help myself09:47
ixxvilbut i figured this was a default ubuntu thing09:47
ixxvilyeah09:47
bigcalmapticron09:47
ixxvilit used to tell me of security updates and recommended updates09:47
popeydoes that update motd bigcalm ?09:47
ixxvilwhat09:48
bigcalmpopey: does for me09:48
directhexyes, i know that, hang on09:48
directhexsomething related to landscape iirc09:48
Myrttihttp://www.last.fm/user/myrtti wheee09:48
ixxviloh i need motd?09:49
ixxvilhow do i install that09:49
jpdsixxvil: Yes, the feature is called 'update-motd'.09:49
LaneyYour musical compatibility with myrtti is Low09:49
Laney:(09:49
jpdsixxvil: sudo apt-get install update-motd09:49
directhexupdate-notifier09:49
directhexhm, just in update-notifier-common09:50
ixxvilok installed it09:50
shaunoappears to be update-notifier-common on mine, but I expect one requires the other?09:50
popeyReceived disconnect from 127.0.0.1: 2: Too many authentication failures for alan09:50
ixxvilrelogged in to my ssh, not seeing it09:50
popeyoof09:50
MooDoooops09:50
ixxvildo i need to set it up?09:50
bigcalmhttp://paste.ubuntu.com/6244774/09:51
ixxviljpds: not seeing it during login after installation09:51
ixxvilooh i need to write a script09:52
bigcalmIs what I have been suggesting not what is required?09:53
ixxvilare you talking to me09:53
bigcalmixxvil: I use apitcron. The pastebin paste above is what I see when I log into my servers09:54
ixxvilyes thats it09:54
ixxvilthats the same thing i had previously09:54
directhexi'm sure that info is from landscape-client or something09:54
ixxvili installed update-motd but it looks like i need to write a script09:55
bigcalmdirecthex: I don't use landscape09:55
directhexbigcalm, neither do i09:55
directhexbigcalm, regardless, check dpkg -l \*landscape\*09:55
bigcalmOkay09:55
shaunoyou shouldn't need to write a script, update-notifier-common provides it09:55
ixxvilbigcalm: so instaled that09:56
ixxvilapticron09:56
bigcalm:)09:56
bigcalmixxvil: sudo apt-get update;exit;login09:56
ixxvilok i still see nothing09:56
ixxvilrelogged in09:56
bigcalmOdd09:57
bigcalmI thought it came from apticron09:57
ixxviljust install apticron?09:57
ixxvilor i have to config it?09:57
bigcalmI know that apticron will email you daily if there are updates to install09:57
ixxvilE: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied)09:57
ixxvilE: Unable to lock directory /var/lib/apt/lists/09:57
shaunomy understanding is pam_motd should call run-parts /etc/update-motd.d/ at login, and you should have a 90-updates-available in /etc/update-motd.d/09:58
bigcalmixxvil: you need to install it as root09:58
ixxviloo09:58
popeyno09:58
bigcalmixxvil: you need to be root to install anything from the cli09:58
popeyapticron sends email09:58
bigcalmno?09:58
popeyixxvil: is asking about login screen09:58
ixxvilso should i uninstall it and then reinstalll?09:59
popeyupdate-motd is the thing that updates the motd, as mentioned by jpds ☻09:59
ixxvilif so how do i uninstall09:59
ixxvilpopey: what bigcalm mentioned is exactly wht im looking for, the same thing09:59
popeyhang fire dude09:59
bigcalmI thought it came from apticron, I could be wrong10:00
popeyupdate-notifier-common is the thing that actually provides the script which gets updates10:00
popeyso you need update-notifier-common and update-motd10:00
ixxvili need to install these as root?10:00
ixxvilnot sudoer?10:00
popeysudo apt-get install update-motd update-notifier-common10:00
popeydone10:00
ixxvilmotd is already done10:00
bigcalmAh, just had a thought. I'm referring to server installs. Are you doing this on a desktop install? It might not include what I've been talking about by default10:01
ixxvilno ssh10:01
bigcalm?10:01
ixxvilits not a desktop, it's a vps10:02
ixxviland im doing via ssh10:02
bigcalmI have no idea then :(10:02
* bigcalm goes back to pretending to work10:02
ixxvilyay10:03
ixxvilthanks10:03
ixxvilthat worked10:03
ixxvilhoweverim not seeing system info like in bigcalm 's paste10:04
popeythats from landscape-client I believe10:04
ixxviland landscape isnt free last i checked10:04
popeyyes, it is10:04
popeythe client10:05
ixxviloh so what would i be paying for10:05
jpdsThat's not landscape.10:05
popeyyou're right, it's not10:05
ixxviloh10:05
ixxvilso what is it then10:05
ixxvilcould that be the apticron thingy?10:06
popeyno.10:06
popeyapticron sends emails when there are system updates10:06
ixxvilah10:07
jpdsStop guessing random things.10:07
MooDooanyone going to linuxcon next week?10:07
ixxviljpds: so what is it then?10:07
jpdsixxvil: 'man update-motd'.10:08
ixxvilhttp://askubuntu.com/questions/7949/where-does-the-system-information-information-come-from-on-login10:08
ixxvillandscape-sysinfo..10:08
jpdsAnd everything comes from /etc/update-motd.d/ .10:08
ixxvili have to install landscape-common10:09
ixxvilsays that article10:09
ixxvildo i?10:09
jpdsYeah, why not.10:09
jpdsYou shouldn't actually need landscape-client.10:09
bigcalmIf this was a server install, why isn't it all there by default?10:10
bigcalmI swear that I haven't had to configure this myself10:10
popeyyeah, it's landscape-common, not landscape-client10:11
popeybigcalm: depends who created the vps image10:11
popeymight not be stock10:11
bigcalmOkay10:11
popeyoften isnt on a VPS10:11
ixxvilyay10:11
ixxvillandscape-common it is10:11
ixxvili did10:11
ixxvilits a fresh install of 12.0410:12
ixxvilwith basic things10:12
ixxvilim not running 100 websites10:12
ixxvilwel thats odd10:13
ixxvilusers logged in : 010:13
ixxvilshouldnt it show me as 1?10:13
bigcalmI have Ubuntu 12.04.3 installed on a virtualbox vm from yesterday. I can confirm that apticron does not edit the motd. Sorry about that. Though I do wonder if apticront is running apt-get update on a daily basis - or is this done anyway on servers?10:13
bigcalms/apticront/apticron10:14
ixxvilok the user thing is 0 as usual10:15
ixxvilbigcalm: well for me apticron isnt going to do anything nless i install it as root so10:16
ixxvili dont think its fetching anything for me at the moment10:16
ixxvilthe one popey  and jpds mentioned seems to have done it10:16
ixxvil+ commons10:16
bigcalmixxvil: I meant that to install anything from the CLI one has to have elevated privileges. Either by being root or using sudo10:17
ixxviloh right10:17
ixxvili do10:17
bigcalmThe line you pasted meant 1 of 2 things. 1. you were not root or didn't use sudo when you did apt-get install apticron. 2. you had another package manager running that was locking the file10:18
bigcalmThe error line that is10:18
ixxvili used sudo10:19
ixxvilbut it says i need to be root10:19
ixxvili installed apticron after installing update-motd10:20
popeyixxvil: you dont need to "be root", you just need to have the privs of root, which sudo gives you10:20
ixxvilright10:21
ixxvilbut this is weird10:21
popeywhat is?10:21
ixxvili get the system info now but not the security alerts10:21
popeymaybe you have no pending security updates?10:22
ixxvilif so shouldnt it say at the bottom?10:22
ixxvil: 0?10:22
bigcalmNo, it doesn't appear to do so10:22
bigcalmIf you run sudo apt-get update; exit; login10:22
popey0 packages can be updated.10:22
popey0 updates are security updates.10:22
bigcalmYou will then see the magic numbers again10:22
ixxvilyeah i dont see that10:22
bigcalmI don't always see the numbers if I've recently logged in or run dist-upgrade I think10:23
ixxvili jsut ran that10:23
ixxvilit fetched a bunch of stuff10:23
popeyso you have no updates?10:23
ixxviland logged me out10:23
popeyhttp://reviews.cnet.co.uk/video-streamers/sky-now-tv-box-review-50011842/  +  http://community.mediabrowser.tv/permalinks/14670/guide-to-installing-mediabrowser3-onto-the-now-tv-box10:24
bigcalmSo if you now ssh back into the server, you might see something10:24
ixxvilah it shows up now10:24
popeylooks interesting10:24
ixxvil59 packages can be updated.10:24
ixxvil25 updates are security updates.10:24
bigcalmRight10:24
ixxvilfor updating those 25 seurity updates10:24
ixxvilhow do i do it10:24
popeysudo apt-get update10:25
popeysudo apt-get dist-upgrade10:25
ixxviloh10:25
ixxvilok10:25
Dave2that would pull in all of the updates though10:25
bigcalmAm I thinking that apticron does a daily "apt-get update" or should that already be happening?10:25
popeytrue10:25
popeyit already happens10:25
ixxvillright thx10:26
popeyas I said (a few times) apticron is for mailing you when there are updates ☻10:26
ixxvilwhich bigcalm does10:26
ixxvili saw that in the paste10:26
popeyya, i do as well10:27
ixxvilye im not superanal about that unless i was a sysadmin10:27
ixxvilone last thing10:28
ixxvilyou guys got a decent iptabnle ruleset i can use?10:28
davmor2Morning all10:28
ixxvilthe one that comes with my vps is absolute trash10:28
jpdsixxvil: ufw ?10:28
ixxvilit drops eveything10:28
ixxvilye i heard about ufw10:28
bigcalmMorning davmor210:28
ixxvilwhat is it10:28
popey$MORNING10:28
jpds!ufw | ixxvil10:28
lubotu3ixxvil: Ubuntu, like any other Linux distribution, has built-in firewall capabilities. The firewall is managed using the 'ufw' command - see https://help.ubuntu.com/community/UFW | GUI frontends such as Gufw also exist. | An alternative to ufw is the 'iptables' command - See https://help.ubuntu.com/community/IptablesHowTo10:28
ali1234why am i still playing this cookie game10:28
davmor2ali1234: because it's cookies10:29
ali1234this game reminds me a lot of eve online, except without the griefers10:29
jpdsixxvil: So, to allow SSH, you would do: sudo ufw allow 22; sudo ufw enable10:29
popeyoh, crud10:29
popeyleft that running10:30
ixxviloh my god10:30
jpdsixxvil: Then do: sudo ufw status verbose --- to see it running.10:30
ixxvilufw is so easy10:30
popey30 million cookies later10:30
jpdsixxvil: And that's the point. ;-)10:30
ali1234i am about to hit 500 million cookies10:30
ali1234there it goes10:30
jpdsixxvil: Of course, you can do: "sudo iptables -L -vn" to see what it does under the hood.10:31
popeyheh10:31
ali1234ufw is good. it's syntax is a little confusing when you try to do advanced things like allow incoming connections only from one IP10:31
BigRedSis that an advanced thing to ask of a firewall?10:32
ali1234it is for ufw, yes10:33
jpdsali1234: Really?10:33
ixxvilso deny all and allow only 1 ip?10:33
ixxvilhow do flush it like in iptables if something goes wrong10:34
bigcalmixxvil: I hope you have a serial console to your VPS, just in case you lock yourself out with incorrect firewall rules :)10:35
davmor2ali1234: sudo ufw allow from <ip address> hows that hard?10:35
ixxvilbigcalm: you mean have to two opened at the same time?10:35
ixxvilye i learnt that yday10:35
jpdsdavmor2: But no port.10:35
ixxvilcause i messed up on iptables twice and couldnt ssh back in10:35
ixxvilit DROPPed everything10:36
ali1234davmor2: that's not hard, but it also doesn't work10:36
bigcalmixxvil: that's one way, but I do mean a serial console via a web interface provided by your hosting company10:36
ixxviloh10:36
jpdsali1234: sudo ufw allow proto tcp from 192.168.0.1 to any port 2210:36
ixxvillike cpanel10:36
ixxvilye i do10:36
jpdsali1234: That's what it is, it's in the man page.10:36
ixxvilmighthave to read up on ufw a bit10:36
ixxvilbut it's certainly easier10:36
ali1234jpds: yeah. which is not the same as the "simple" syntax10:36
bigcalmI like rackspace's network policy manger for their cloud servers. That's a simple interface10:37
ixxvilthats simple10:38
davmor2ali1234: that's pretty simple in comparison to an iptables rule to do the same thing10:38
ixxvilcompared to the weird flags in iptables10:38
ixxvilI ia i -A10:38
ixxviland what not10:38
ali1234davmor2: i never said it wasn't i said it is the most complex thing ufw can do10:38
ali1234simple commands in ufw look like "ufw allow 80/tcp"10:39
ali1234you might expect that you can extend the simple commands like "ufw allow 80/tcp from <ip>" but this does not work10:39
ali1234instead you have to use the "extended" syntax which puts everything in a totally different order10:40
ixxvilwhats the extended syntax10:42
=== alan_g is now known as alan_g|afk
BigRedSixxvil: "ufw allow proto tcp from 192.168.0.1 to any port 22" at a guess10:48
BigRedSbigcalm: shorewall's got a lovely notion of 'safe-restart' which is a godsend on remote machines10:49
BigRedSit applies the new rules and prompts for a 'Y/N'; if it doesn't get that in a few minutes it reverts the rules10:49
BigRedSfew minutes? I think it's 30 seconds actually10:49
davmor2ixxvil: https://help.ubuntu.com/community/UFW this is a good guide on ufw10:50
ixxviltx10:50
ixxviljust wondering10:50
ixxvilufw cant do rate limiting?10:50
ixxvilsomething like this - "I want to block everything for Z seconds after X connection in Y seconds10:51
=== alan_g|afk is now known as alan_g
davmor2http://serverfault.com/questions/368523/rate-limiting-with-ufw-setting-limits10:54
davmor2ixxvil: that was the first google hit for ufw rate limiting10:55
davmor2ixxvil: there were plenty of others if that was what you were after10:55
ixxvilye10:56
ixxvilreading10:56
popeyNoodles O'clock11:22
ixxvilalright later!11:22
Laneyhttp://ubuntuone.com/0oxAT8t52o9p3U2wrtjUGP11:24
popeyoops11:24
Laneywas planned :-)11:25
popeyi mean oops for the bandage11:25
popeyi assume you didn't plan to hurt your toe11:25
Laneyit's been ingrowing for years11:25
Laneyfinally decided to get it sorted11:26
bigcalmOuch11:30
mungbean_not gonna click11:34
bigcalmmungbean_: nothing bad about the photo11:34
bigcalmJust feel ouch for Laney11:34
mungbean_my toe went manky and the doc couldn't grow a culture from it so not really sure what to do now11:34
LaneyShould be smaller after Friday :P11:35
Laneywant to know when I can go climbing again though11:35
=== alan_g is now known as alan_g|lunch
ixxvilis it recommended to drop all incoming connections ?12:04
BigRedSGenerally, yeah - default to dropping everything and then explicitly permit that which you actually want12:08
ixxvilthats the issue12:09
ixxvili dunno want to permit12:09
ixxvilfor outgoing12:09
BigRedSwhat sort of computer is this? a server?12:09
ixxvilvps12:09
ixxvilive just got my site on it, nothing else12:09
BigRedSyeah, what's it doing?12:09
ixxviljust hosting a bunchof html, css, php pages12:09
BigRedSright, so you'll want to allow inbound connections to port 8012:09
ixxvilbootstrap12:09
BigRedSand perhaps 443 if you've got SSL12:09
ixxvilye i do have ssl havent set it up yuet12:10
BigRedSyou'll probably want to ssh in on port 22, too12:10
BigRedSand if you're not running any other services that's about it12:10
BigRedSPersonally I wouldn't bother with outbound restrictions generally12:11
BigRedSsafest is to block all of them and again open up holes as you need them, but wgets not JustWorking gets quite tedious pretty quickly12:11
ixxvilhold on12:13
ixxvilssh is allowed12:13
ixxvilsudo ufw allow 2423/tcp12:14
ixxvilso for outbound deny all?12:15
ixxvilsorry12:15
ixxviloutgoing allow all?12:15
BigRedSI'd allow all outbound12:17
BigRedSand only permit inbound on ports 80 and 2212:18
ixxvildone12:20
ixxviland for rate limiting sudo ufw limit 2323/tcp?12:20
ixxvilcause i changed the ssh port, nt sure why but i did12:21
ixxviljust one last thing12:24
ixxvili was allow certain incoming like ssh and 8012:24
ixxvilbut if i set the rule now to deny all incoming12:24
ixxvilwhich would have more precedence?12:24
ixxvilor it doesnt matteR?12:24
ixxvilalso in the ufw status, why does it replicate the same rules twice?12:26
ixxvilis it replicated for both incoming and outgoing?12:26
AzelphurDoes Ubuntu touch run on the N7 2013 (dual boot) yet?12:33
mungbean_anyone know why i get "insufficient storage space available" on my tablet when installing twitter app?12:38
mungbean_i have loads of space12:38
Azelphurmungbean_: which tablet12:39
mungbean_touchpad12:39
Azelphur(os, really)12:39
mungbean_runnig cm12:39
Azelphurmungbean_: checked settings > storage?12:39
mungbean_4.1.212:39
daftykinscheck the status of the /data partition12:39
mungbean_149MB internal availabel, 1GB SD card available12:39
mungbean_most other apps update OK some don't12:40
daftykins#cyanogenmod-touchpad <--- may be more use12:40
daftykinsi own one but i'm still running CM912:40
mungbean_twitter app is utter fail12:43
mungbean_used to use tweetdeck but they blocked it. but i have to sign in with password every time i reboot my phone12:43
=== alan_g|lunch is now known as alan_g
mungbean_fixed the install issue12:46
mungbean_moved the kindle app to sd card, even tho i had loads free already12:46
daftykinsanyone done much by way of diagnosing freezing (mid-2010) macbook pros?12:47
daftykinsi don't even know any apple channels on yonder freenode12:47
daftykinscertainly my usual PC experience applies - so my first step would be to memtest this sucker once i'm near it later this afternoon12:48
popeymine used to freeze sometimes12:52
popeyit's a 2010 MBP 13"12:52
daftykinspopey: core 2 duo sucker? trouble is the variables are that i put an SSD in and doubled the RAM for this-un13:00
mungbean_i sold a broken powerpc macbook so a fiver13:00
mungbean_broken mobo, broken power switch, no disk, no ram13:01
popeyyeah, mine is a c2d, still in daily use by wifey13:04
popeydaftykins: i identified the problem as a manky chrome install13:06
daftykinsoh really 0o13:06
popeyhad to do a lot of clearing up to wipe it away and start again13:06
daftykinsi'll give the ol' fix permissions thing a run anywho13:06
popeybeen fine since13:06
daftykinsthis'un doesn't use anything besides Safari13:07
popeyinitially thought it was overheating given it's on wifeys lap13:07
daftykinsheh13:07
bigcalmIs there much difference between the latest snapshot of 13.10 and what will be released tomorrow?13:17
bigcalmPondering installing it in a VM and having a play13:17
BigRedSI'd hope not13:19
popeynope13:19
bigcalmVMs are very pleasing13:19
=== Lcawte|Away is now known as Lcawte
daftykinsno risk to VMs, why not do five! XD13:22
daftykinsthen have fun tomorrow as the repos crawl as usual :>13:22
popeynot if you use a mirror13:25
popeyI'm using goscomb which is super speedy13:25
jpdssquid-deb-proxy++13:30
shaunoit's a shame squid-deb-proxy doesn't work out of the box.  seems silly having to install from the public mirrors before you can get to it13:32
bigcalmI appear to have chosen goscomb as well13:44
bigcalmOr the mirror choose did13:44
popeyhttp://www.polygon.com/2013/10/15/4843366/nintendo-2ds-teardown-reveals-its-big-single-screen-construction13:44
popeygosh13:44
bigcalmGoodness13:46
bigcalmJust got around to listening to the latest uupc. Still no mention of an event on the 25th. Maybe it'll be in next week's episode ;)13:47
bigcalmThis is odd13:48
bigcalmRunning the software updater in the vm. The details window is showing static content with no scroll bar. expanding/contracting the details area, using the icon, updates the content13:49
bigcalmBut it's not actively updating the details area13:49
bigcalmdavmor2: ^^13:50
bigcalmI don't know if this is a problem with the updater or the fact it's running in a VM13:50
bigcalmThere's no scroll bar either13:50
davmor2bigcalm: update manager is naff all to do with me sunshine ;)  It scrolled here this morning on HW if that is any help?13:51
bigcalm:P13:52
bigcalmFair enough13:52
bigcalmHow on earth can you be too busy to come to the LUG tonight?13:52
ixxvilnyone knows where you change the ServerName from 127.0.0.1 to the hostname?13:54
ixxvildo I add line in sites-enabled with Servername localhost?13:54
davmor2bigcalm: I've no idea, right.  I mean it's not like there is a release or anything tomorrow.............Oh wait13:59
bigcalmdavmor2: shouldn't everything have been frozen already so that tomorrow's release is nice and relaxed?14:01
ixxvilany ideas?14:02
=== Lcawte is now known as Lcawte|Away
BigRedSixxvil: in Apache?14:39
BigRedSwhat's the larger problem you're trying to solve?14:39
BigRedSeach virtualhost has exactly one servername14:39
BigRedSnormally when you add a virtualhost it gets its own file in sites-available14:40
BigRedSand you neable it with a2ensite14:40
ixxviloh i fixed it14:40
ixxvilthanks14:40
ixxvilBigRedS: trying to setup SSL14:41
ixxviltry8ing to get the private key but i need root and i forgot14:42
ixxvilso waiting on the admin14:42
trilitheus /leave14:46
trilitheus\leave14:46
diploGuys, SSL you have to give your number over14:50
diploDoes anyone know if it has to be a DDI or can it be a switchboard number ?14:50
directhex?14:51
diploBasically we're wanting to register an ssl cert for a customer14:52
diploThey want a contact number, a direct line number and as far as I know a business number will do, you don't need to give them a Direct line number14:52
directhexdepends on the SSL vendor's automation levels14:53
directhexchances are the number will be used for EV14:53
=== Lcawte|Away is now known as Lcawte
diploBut if you can get hold of that person through generic reception that is the same thing imo, trying to find info on the web but not succeeding yet :)14:54
BigRedSour SSL people are out; I can check when they get back14:56
diployeah found it, so basically it needs to match with business register ( company house ? ) and whois14:56
BigRedSit'll be comodo's, but generally everything has to match something publically available - company registration, domain whois etc.14:56
BigRedSoh14:56
diploSo sounds to me like the main number to me ( can you tell this is the first time I've registered an official cert :D14:56
diploSo yeah what you said14:56
directhexwe use 2 different registrars14:58
directhexstartcom are cheap and mostly automated, but not particularly trustworthy14:58
directhexdigicert are much nicer and shiner, but omgexpensive14:59
diploOK thanks15:01
bigcalmWe've used RapidSSL, can't comment on their trust level though15:02
bigcalmIf you want to pay though the nose, go with VeriSign or Thwart15:02
bigcalmT - 9 days15:03
bigcalm\o/15:03
dwatkinspeople actually check WHOIS information?15:07
AzelphurI do15:08
dwatkinsas do I, but I didn't expect that they would be checked 'officially' when registering an SSL certificate, I guess it makes sense, though.15:08
dwatkinsit's also a handy way to look up the address of a friend of mine in Michigan15:09
directhexyes15:09
directhexwith startcom, they only let you get certs for a domain if you can confirm that you receive email to the address in whois15:09
BigRedSyeah, I think comodo do that15:10
BigRedSI try to not go anywhere near that bit of ssls15:10
MooDooi work in hosting so do all the time.15:10
BigRedSyeah, I put the certs in place, but we have People to do the ordering :)15:11
diploI've found part of the issue, one of my colleagues is rectifying it now.15:17
dwatkinsI work in support, when people ask me about the prices, I can honestly say I have no idea about that side of things and refer them to sales.15:17
=== schwuk is now known as schwuk_away
=== schwuk_away is now known as schwuk
shaunoheh, we do the same, but it seems to be taking some internal pushing and shoving15:20
dwatkinsI was told in a previous job that being a technical support representative, there were reasons why I shouldn't give out pricing information, some legal and some relating to current discounts I might not be aware of.15:22
dwatkinsI'm much happier not having to deal with that sort of thing if it means I get the occasional question passed on to me about where customers have to go to find their invoice on the website.15:23
directhexi don't deal direct with clients15:23
shaunoI'm happy enough that we don't touch sales at all, but someone's pushing us to call customers who's contracts are expiring, "just to make sure they're aware".  which is waay too close for my liking15:24
shaunoand typically a very awkward call because even if they want to do something about it, I can't renew them15:24
shaunojust one of those silly things where there's way too many people involved15:25
dwatkinsshauno: yeah, that should be the job of the salespeople, for sure.15:25
dwatkinsI was encouraged a few years ago to try and "upsell" things like hard disk replacements, which was always a pretty awkward conversation in itself when someone's machine is down because their disk has died.15:26
dwatkins"Would you like an 8GB disk as an upgrade?" "No, I just want the bloomin' thing to work again, and I can't spend any money myself anyway" was the usual way the conversation went15:27
shaunothe biggest wall I hit is that we're looking at datacenter-scale customers, so the people I'm talking to are rarely the people sales want to talk to anyway.  and the people I talk to are just as wary of salesmen as I am15:28
dwatkinsindeed15:28
shaunooh well.  place I'm interviewing for is even bigger, so better get used to it I guess15:36
ixxvilapache is so confusing15:39
ixxvilive got no httpd.conf15:39
ixxviland inside of apache2.conf there is nothing about ssl15:39
ixxvilany idea where you see or amend the SSL section in apache2.conf??15:40
shaunothere won't be .. anything that's global will be in mods-available/ssl.conf, and anything that's site-specific will be in sites-available/15:40
directhexwhat shauno said15:40
Dave2what directhex said15:41
directhexmods-enabled and sites-enabled possibly more relevant though ;)15:41
shaunopossibly ;)  I just grepped ssl because I don't know the filenames offhand, so grep answers the actual file rather than the symlink15:41
ali1234what happens if your domain registrar goes bust?15:42
Dave2I imagine you'd be able to transfer to somewhere else15:43
ali1234how specifically do you go about doing that though?15:43
shaunoif it's a .uk, you can get nominet to sort you out for a small fee (10-quid-ish)15:43
Dave2I've had domains through a company that was so badly managed that ICANN stepped in15:43
ali1234supposing it's a .com...15:43
Dave2I think they gave you the option to transfer, or after a while they all got sent to godaddy15:43
Dave2Also, it's reasonably likely that if you're worried about your registrar going bust, they're probably just reselling someone else15:45
shaunoI only know .uk offhand because I've been there, nominet will retag it for a small fee & proof of id15:46
shaunohad some registrar that went pop in 2008 or so.  messy.15:47
Dave2I assume it wasn't RegisterFly15:47
shaunodoesn't ring a bell15:47
Dave2They were the one that I mentioned that went down in flames15:48
diploI had an email when 123 got bought out by whoever it is now saying it's all being transferred to X15:48
Dave2Bad flames15:48
Dave2Flames which resulted in the latest news on the customer panel being the owner's ex-partner saying how bad it was and how all customers should move away now before they get screwed out of more money (I rephrased it to be slightly more polite).15:49
shaunoI wish I could remember who I had, but it was quite messy.  they were meant to renew with the card on file, didn't, and then offered to sell it back to me for just shy of 5 digits15:50
shaunowell, 9 hours, and I finally have a keymap I'm happy with.  I really should look into translating this to xkbd some day15:52
ixxvilthis is so damn confusing16:01
ixxvileveryone calls it httpd/conf16:01
ixxviland then suddenly outta nowhere there's an ssl.conf hidden away16:01
ixxvili just broke my shit16:02
directhexyou're reading RHEL tutorials16:02
shaunoyou'll find this all-over the place in debian/ubuntu-land.  if you're expecting one big configuration file, and don't find it, take a look around.  it's almost always been broken down piecemeal16:02
directhexsplitting into per-module and per-site config allows an entire site to be shipped with configuration, rather than "now, copy-paste this chunk into the single config file" in the manual16:03
ixxvilthe ubuntu oneso my httpd.conf file where i can see the SSL section is actually ssl.conf?16:04
ixxvilso my httpd.conf file where i can see the SSL section is actually ssl.conf?16:04
ixxvilther eis no mention of ssl.conf in like about 30 links ive been reading16:05
ixxvileveryone just refers to httpd.conf or apache2.conf16:05
ixxviland for those using apache2.conf you have no httpd.conf but ive read cases where theyve created one for adding user modules into /conf.d16:06
directhex"everyone"16:06
ixxvilso goddamn confusing16:06
shaunothere's a few paragraphs of comments at the top of apache2.conf that explain what you're looking at16:06
directhexmodules are configured per-module. sites are configured per-site. this makes more sense than a single 3000-line config file16:07
ixxvili cant find it on then top of apache2.conf16:08
ixxvil SSLCertificateChainFile does this come with ssl.conf?16:10
ixxvilor with apache2.conf16:10
ixxvilthe ssl.conf has none of it16:10
bigcalmYou might have better luck doing your SSL config via vhost files16:11
ixxvilyou mean sites-available?16:12
bigcalmThat's where they should be stored, yet16:12
bigcalmThere might also be a default-ssl vhost in there16:12
ixxvilye16:12
bigcalms/yet/yes16:13
ixxvilwhat about change namehosts in ports.conf?16:13
ixxvilNameVirtualHost16:13
ixxvilit says if you change it there which i have then you need to change it in default-ssl16:14
directhexixxvil, certificates are per-site. if i host foo.com and bar.com i might have a different certificate file for both, with a different chain16:15
directhexso certificate configuration is per-site, logically16:15
ixxvilive got just one site16:15
bigcalmYou can have ssl directives in vhost config files. Makes sense to keep them together16:15
ixxvilwhich i have16:16
ixxvili should be modify8in default-ssl?16:17
BigRedSno16:17
BigRedSyou should be making a new vhost file for this one16:17
BigRedSwell, you *can*16:17
BigRedSthere's a lot of scope for opionion here, does anyone else look after this machine with you?16:18
directhexdefault and default-ssl is an example file16:18
directhexyou're missing the point by editing it16:18
ixxvilno they dont16:18
funkyHatI thought there was also a per-host certificate if you support HTTP1.1 properly? Old browsers won't know to tell the host the hostname in the ssl handshake16:24
directhexyes, for http 1.116:24
directhexso all those msie 2 users16:24
ixxvilok so the default-ssl actually already has these SSL derivatives16:24
ixxvilso why is there a need to put it in the vhosts?16:25
ixxvilthere's an entry for it already there in /default-ssl16:25
ixxviljsut change extension and it should work?16:25
directhexchange what extension?16:25
ixxvilSSLCertificateFile    /etc/ssl/certs/ssl-cert-snakeoil.pem16:26
directhexixxvil, you want to serve using a self-signed autogenerated certificate?16:28
ixxvilis the default-ssl just a sample?16:28
ixxvilno i dont16:28
ixxvili hjave a commercial one16:28
directhexdefault-ssl is a basic example config to serve /var/www over ssl, if you enable the ssl module16:28
directhexdefault is a basic example config to serve /var/www without ssl16:29
ixxvilas of now16:30
ixxvilwhich one do i need to edit16:30
ixxvilenabled?16:30
directhexsite configs live in sites-available16:31
directhexthe "a2ensite" command creates a symlink to them in sites-enabled16:32
ixxvilye si did that enable that16:32
directhex(and a2dissite to delete those symlinks)16:32
directhexmuch like a2enmod enables modules from mods-available16:32
ixxvilive enabled a2ensite16:32
ixxvilwhere do i add the virtualhost with the ssl directives ?16:33
funkyHatActually IE6 doesn't support SNI, and apparently neither do IE7 or IE8 if you're on Windows XP16:34
ixxvilyou said default and default-ssl were just samples16:34
directhexsigh.16:35
directhexokay, here's a freebie.16:35
ixxvilshould i edit the SSl derivatives in default-ssl?16:36
funkyHatixxvil: copy one of them to a new file (yoursite.com or something) and edit the details in the new copy? Then run a2ensite yoursite.com16:36
funkyHatDoesn't the file have a comment to that effect?16:36
directhexhere's an example vhost: http://paste.debian.net/hidden/c4ebcfb8/16:36
directhexuses SSL with a cert chain, serves a basic path over ssl, redirects non-ssl to ssl, uses a specific vhost domain.16:37
directhexall the things you need.16:37
ixxvilthe last part16:40
ixxvilthe SSL engine on, etc16:40
ixxvili have that already in the vhosts file16:41
directhex"the vhosts file"?16:42
ixxvilwell in sites-available/default16:42
ixxvila the very end ive added those ssl directives16:42
bigcalmixxvil: at the end of the file or within the </VirtualHost> tag?16:43
ixxvilwithin16:43
ixxvilbut at the very last16:43
ixxvilshould i have to add #?16:43
bigcalmA # is a comment16:44
bigcalmixxvil: it's possible that you are trying to configure systems that are currently at a higher level than your current knowledge allows. I suggest reading a tutorial such as: https://help.ubuntu.com/10.04/serverguide/httpd.html16:49
bigcalmHopefully you will see that it's written for Ubuntu 10.04, but a lot of the information is still relevant16:49
ixxvili had this working previously16:50
ixxvilbut with the new vps things are a lil different16:50
ixxviland the naming conventions clearly fucked things over a bit more16:50
bigcalm!ohmy | ixxvil16:51
lubotu3ixxvil: Please remember that all Ubuntu IRC channels share the same attitude of providing friendly and polite interaction with all users of all ages and cultures. Basically, this means no foul language and no abuse towards others.16:51
ixxvilye16:51
ixxvilsorry16:51
ixxvilbeen sitting at this crap for hrs now16:51
ixxviland this isnt even my job lol16:51
bigcalmAha, there is an updated version: https://help.ubuntu.com/12.04/serverguide/httpd.html16:53
ixxvilye thats the issue16:56
ixxvilthis one has a different approach to what my vps said16:56
ixxvilso i followe the vps method,didnt work16:56
ixxvilthe commercial ssl method, didnt work16:58
ixxvilbecause of the naming thing16:58
ixxvillinode has it written differently about mucking aorund with ports.conf16:58
ixxviland now we have this that goes back to modifying the virtualhosts file16:59
ixxvili need coffee16:59
bigcalmpopey: what was the command mentioned in Command Line Lurv that will open a file in the appropriate gui app?17:04
popeyxdg-open <file>17:05
bigcalmYay :)17:06
bigcalmTa17:06
bigcalmI will forget it soon enough17:06
ixxvilso the issue is i kept modifying default17:08
ixxviland then did a2enmod17:09
ixxvilmy sites-enabled and default are the same now17:09
ixxvili didnt create a copy and then modify it as your link says17:10
ixxvilor rather i didnt know17:10
ixxvilcansomeone paste me the sites-available/default config that comes without changes?17:11
ixxvilcause i made some changes and not sure how to revert to the original to fix things17:11
bigcalmixxvil: I think you need to brush up on your google skills. Something like "ubuntu revert apache configuration to default" gives lots of help17:14
ixxvilye reinstall17:16
DJones @online accounts stop opening multiple blank browser windows to tell me that I need to reausthorise my account17:40
=== schwuk is now known as schwuk_away
ixxvilok17:50
ixxvilso sites-available/default vs sites-available/default-ssl17:50
ixxvilits the essentially the same thing but one is without ssl and the other is?17:50
ixxviland i need to put all of them together in one file is that it?17:51
ixxvilok i reverted things18:08
ixxvil000-default is for port 8018:08
ixxvilyes!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!18:16
* ixxvil takes a few shots in the air18:16
popeyheh18:26
ixxvilthat took 6 hrs rofl18:28
ixxvili coud've found 2 deisgn jobs by then18:28
ixxvilpaid someone to fix this and still saved an hr18:29
ixxvilguess i learnt something though18:29
ixxvilthanks all!18:33
ixxvilyou guys have been very patient18:33
mungbean_yay, got £12.50 in vouchers for filling in a survey that i suspect was spam18:40
mungbean_s/pect/pected/18:40
mungbean_was an unsolicited email sent to vmware customers \o/18:41
ali1234i've been getting a lot of weird email lately18:42
ali1234today i got one from http://www.gymnasticsuk.org/ which looks completely legit in that it is highly specific18:43
mungbean_usually i bin anything like that cos i get a lot of targeted stuff via linkedin ppl looking up my address in the public company directory18:44
mungbean_is there any point updating firmware on kindles?18:45
mungbean_the kindle app gets new features like "time to finish" but unsure about the hardware ones18:45
ali1234my mum's kindle would crash all the time until i updated the firmware18:47
mungbean_cant find changelogs18:49
mungbean_seems there's only been a minor udpdate since 2012 june18:50
=== slvr is now known as hearn
=== hearn is now known as slvr
ixxvilso ufw check, ssl check, what else19:40
ixxvilanything else for security?19:40
ixxvilssh check19:40
ali1234if you are running a php cms, make sure you set it up right19:49
ixxvilive got php running here and there19:51
ixxvilbut not like a full grown cms19:51
=== Lcawte is now known as Lcawte|Away

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!