[04:28] one more day till the end of the world, otherwise known as ubuntu release day [04:28] oh deary me [04:28] what are you doing up diddledan ?! [04:28] daftykins: didn't go to bed :-/ [04:28] D: [04:29] would you like to see a picture? [04:29] here is my friends trap-like home: [04:29] https://www.dropbox.com/s/2yjdj6vtc8sq0hs/IMG_20131016_012728.jpg [04:30] toilet... hole to certain death [04:33] doubleyoo tee eff [04:33] that's twisted [04:34] inorite [04:34] what's down there? [04:57] mostly that friends central heating systems etc. [04:57] and two flats they rent out [05:16] bed time! [06:53] Myrtti: awww http://imgur.com/6oBRyyr [06:54] awwww [07:10] directhex: bee and puppycat is odd [07:12] morning all [07:18] Morning all [07:20] orning dipl [07:21] oh I give up with spelling today [07:26] hah [07:26] Morning mate [07:32] yo [07:33] howdo TheOpenSourcerer [07:42] Gooood Morning! [07:48] Your new giant time waster is.. http://orteil.dashnet.org/cookieclicker/ [07:53] Haha, I spent 20 billion cookies on a grandma yesterday === schwuk_away is now known as schwuk [07:54] ☻ [07:59] I think I've spent more clock cycles on generating cookies in the past couple of weeks than I have ever contributed to scientific research [08:03] I'm so excited .____________. [08:07] and you just can't hide it? [08:07] release party tomorrow \o/ [08:10] Ah yeah, I need to make sure I leave at a reasonable time this time [08:10] I know I say that every time, but this time I do actually have stuff to do on the Friday [08:11] and, yeah, I say that each time, too [08:17] Good morning peeps :) [08:24] SuperMatt: nope, too excited! [08:24] http://i.imgur.com/RtbbB.gif [08:25] I'm looking forward to the release party [08:25] I won't be drinking though, I've given up (again) [08:25] oh yeah there's a release day tomorrow [08:25] we'll be on the road [08:25] a roadtrip to the office, no less [08:26] Wow, forgot that tomorrow is Thursday. I have no idea when I am [08:27] Frundesday [08:27] bigcalm: dun dun DUUUUNNNN [08:28] Myrtti: 1st day back in the office to do work. As much as I hated being ill, I did get used to not having to think about days of the week [08:29] Morning JamesTait. What day is it today? [08:30] Oscar Wilde was born in 1854 [08:31] Boromir reaches Rivendell [08:31] apparently [08:31] and apparently tomorrow is the Council of Elrond [08:32] ooohhh! [08:33] Boromir. [08:33] Aw man, I knew there was somewhere else I was meant to be [08:33] at the council of Elrond? [08:33] Yes [08:34] well you have a day to get to Rivendell [08:34] get cracking [08:34] Good morning all; happy Global Dignity Day! :-D [08:34] in case anyone is interested in a Philips wet and dry shaver, there's one on Amazon lightning deals in half an hour. I'll be trying to get one for D myself. [08:34] if you go by car it shouldn't take you anywhere near as long as it took frodo [08:34] JamesTait: you just listed all the things I don't havae [08:34] -a [08:35] SuperMatt, maybe Feral Cat Day works better for you? [08:35] yes thanks [08:35] \o/ [08:37] good morning everyone, [08:38] Myrtti: do you have a link? [08:39] bigcalm: http://www.amazon.co.uk/deals-offers-savings http://www.amazon.co.uk/gp/product/B00D84IPF2/ [08:41] 100 quid now, what is it likely to be in the lightning deal? [08:41] The deals-offers-savings link you pasted doesn't work for me [08:42] Aha, I see [08:42] Works via the site with extra gubbins [08:42] I'm in need of a new shaver [08:43] I'd say probably 60-70 [08:44] bigcalm: https://www.amazon.co.uk/gp/product/B008PPGHOA/ [08:45] Note that you do NOT want the newer version. [08:46] oh man that page fails to load fully [08:46] jpds: why? [08:47] lolok "But more importantly, if you ever run out of charge mid-shave, there's no way of using it off the mains! It's cordless only." [08:48] oh man, the leafblowers are back [08:48] abandon all hope all ye who enter [08:50] My current shaver is mains only as well :( [08:51] yes well that's the exact opposite [08:58] Oops [08:58] I mean doesn't work when plugged into mains [08:58] I r ill? [08:59] 50s, hope it's a good deal [08:59] rewriting my windows keymap to support all the deadkeys I'm used to. newfound appreciation for how weird keyboards are, but still too sober to try to this in xkbd (one day ...) [09:00] 80 quid... [09:00] Is it worth it? [09:00] dunno [09:01] Ooo, with the trimmer attachment, I wonder if Hayley will cut my hair with it [09:02] Dunc said he'd be fine if it's about 50quid [09:02] before he boarded his plane [09:02] Myrtti: is he flying to TRE or HEL ? [09:02] tre of course [09:03] Stanstead and Pirkkala are so much closer than Heathrow/Luton/Gatwick and Helsinki [09:03] * bigcalm drops it from his basket [09:04] bigcalm: yeah I'm not sure it's worth it either [09:07] Myrtti: thanks for pointing it out though :) [09:07] I might look in on the deals now and then [09:08] Heh, I ordered that shaver from amazon a couple weeks ago, ended up cancelling the order because they couldn't deliver it & getting a different one [09:10] I won't buy an electric shaver unless I can run ubuntu on it [09:11] also, I would have to actually have to be able to grow a beard [09:11] my baby face doesn't allow it [09:16] i have hairdressers clippers [09:16] more robust [09:19] popey: I'm guessing they don't see much action going by a recent mocking of your hair ;) [09:19] :D [09:19] i only use it for beardy [09:19] hehe [09:20] popey: I have those also for hair. need to dig them out again, getting to be a bit of a mop [09:30] I had to get rid of my clippers. poor impulse control. More than once I woke up with a hangover and a conscript-cut. [09:30] Hehe [09:31] Until reading the whole line, I thought your clippers worked on impulse power [09:31] that could be dangerous [09:31] Impulse power only Mr Crusher [09:32] make it sew [09:33] I've been trying to grow my hair back out for years. but it seems to go through the stages of short, the 60's, urgh, the 70's, and then long. [09:33] it's not so easy to get through the middle stages without getting sick of it and lopping it all off [09:34] it's been ten years since i had my hair cut :O [09:34] I hate having hair longer than a few CM [09:35] oh, if there any kubuntu'ites here we now have polo shirts for sale :D [09:35] I miss long hair. but in between short and long, thar be dragons [09:35] I don't miss having a mop [09:35] My hair grows quickly and thickly. Not good for anything [09:37] my hair doesn't grow long, it grows curly [09:37] sideways nonsense [09:39] Myrtti: Newer version has less battery life+lower quality blades. [09:40] oh hoorah [09:40] the spotify native client started working again [09:40] what version you on? [09:41] i feel i should have an update somewhere [09:41] 1:0.9.4.183.g644e24e.428-1 [09:41] 0.9.4.183.g644e24e0 [09:41] * popey squints [09:41] i copied it from the about dialog [09:41] different machine [09:41] git tag in ordered version number [09:42] OH GOD HOW DO I COMPUTER [09:42] \o/ crashed [09:42] mainly checked because i noticed that lastfm scrobbling from the web client was knackered [09:43] http://www.last.fm/user/lan3y/now [09:43] ace of base :> [09:43] http://www.last.fm/user/popeydc/now [09:43] ☻ [09:44] I've had the Top Gun soundtrack on loop for a while, I'm not going anywhere near Last.fm for a bit [09:46] jpds: right [09:46] BigRedS: that's why I don't 'scrobble'. some things shouldn't be admitted in public :p [09:46] be proud [09:46] hi [09:46] hi [09:46] hi [09:46] hi [09:46] hi [09:47] Hi [09:47] how do i set ubuntu t alert me of security updates in the terminal [09:47] apticron [09:47] my previous vps had something like that during login [09:47] bigcalm: oh you had to be different ;) [09:47] sorry, we can only do "hi" [09:47] yeah, there's a motd thing that pops up on login? [09:47] MooDoo: sorry, can't help myself [09:47] but i figured this was a default ubuntu thing [09:47] yeah [09:47] apticron [09:47] it used to tell me of security updates and recommended updates [09:47] does that update motd bigcalm ? [09:48] what [09:48] popey: does for me [09:48] yes, i know that, hang on [09:48] something related to landscape iirc [09:48] http://www.last.fm/user/myrtti wheee [09:49] oh i need motd? [09:49] how do i install that [09:49] ixxvil: Yes, the feature is called 'update-motd'. [09:49] Your musical compatibility with myrtti is Low [09:49] :( [09:49] ixxvil: sudo apt-get install update-motd [09:49] update-notifier [09:50] hm, just in update-notifier-common [09:50] ok installed it [09:50] appears to be update-notifier-common on mine, but I expect one requires the other? [09:50] Received disconnect from 127.0.0.1: 2: Too many authentication failures for alan [09:50] relogged in to my ssh, not seeing it [09:50] oof [09:50] oops [09:50] do i need to set it up? [09:51] http://paste.ubuntu.com/6244774/ [09:51] jpds: not seeing it during login after installation [09:52] ooh i need to write a script [09:53] Is what I have been suggesting not what is required? [09:53] are you talking to me [09:54] ixxvil: I use apitcron. The pastebin paste above is what I see when I log into my servers [09:54] yes thats it [09:54] thats the same thing i had previously [09:54] i'm sure that info is from landscape-client or something [09:55] i installed update-motd but it looks like i need to write a script [09:55] directhex: I don't use landscape [09:55] bigcalm, neither do i [09:55] bigcalm, regardless, check dpkg -l \*landscape\* [09:55] Okay [09:55] you shouldn't need to write a script, update-notifier-common provides it [09:56] bigcalm: so instaled that [09:56] apticron [09:56] :) [09:56] ixxvil: sudo apt-get update;exit;login [09:56] ok i still see nothing [09:56] relogged in [09:57] Odd [09:57] I thought it came from apticron [09:57] just install apticron? [09:57] or i have to config it? [09:57] I know that apticron will email you daily if there are updates to install [09:57] E: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied) [09:57] E: Unable to lock directory /var/lib/apt/lists/ [09:58] my understanding is pam_motd should call run-parts /etc/update-motd.d/ at login, and you should have a 90-updates-available in /etc/update-motd.d/ [09:58] ixxvil: you need to install it as root [09:58] oo [09:58] no [09:58] ixxvil: you need to be root to install anything from the cli [09:58] apticron sends email [09:58] no? [09:58] ixxvil: is asking about login screen [09:59] so should i uninstall it and then reinstalll? [09:59] update-motd is the thing that updates the motd, as mentioned by jpds ☻ [09:59] if so how do i uninstall [09:59] popey: what bigcalm mentioned is exactly wht im looking for, the same thing [09:59] hang fire dude [10:00] I thought it came from apticron, I could be wrong [10:00] update-notifier-common is the thing that actually provides the script which gets updates [10:00] so you need update-notifier-common and update-motd [10:00] i need to install these as root? [10:00] not sudoer? [10:00] sudo apt-get install update-motd update-notifier-common [10:00] done [10:00] motd is already done [10:01] Ah, just had a thought. I'm referring to server installs. Are you doing this on a desktop install? It might not include what I've been talking about by default [10:01] no ssh [10:01] ? [10:02] its not a desktop, it's a vps [10:02] and im doing via ssh [10:02] I have no idea then :( [10:02] * bigcalm goes back to pretending to work [10:03] yay [10:03] thanks [10:03] that worked [10:04] howeverim not seeing system info like in bigcalm 's paste [10:04] thats from landscape-client I believe [10:04] and landscape isnt free last i checked [10:04] yes, it is [10:05] the client [10:05] oh so what would i be paying for [10:05] That's not landscape. [10:05] you're right, it's not [10:05] oh [10:05] so what is it then [10:06] could that be the apticron thingy? [10:06] no. [10:06] apticron sends emails when there are system updates [10:07] ah [10:07] Stop guessing random things. [10:07] anyone going to linuxcon next week? [10:07] jpds: so what is it then? [10:08] ixxvil: 'man update-motd'. [10:08] http://askubuntu.com/questions/7949/where-does-the-system-information-information-come-from-on-login [10:08] landscape-sysinfo.. [10:08] And everything comes from /etc/update-motd.d/ . [10:09] i have to install landscape-common [10:09] says that article [10:09] do i? [10:09] Yeah, why not. [10:09] You shouldn't actually need landscape-client. [10:10] If this was a server install, why isn't it all there by default? [10:10] I swear that I haven't had to configure this myself [10:11] yeah, it's landscape-common, not landscape-client [10:11] bigcalm: depends who created the vps image [10:11] might not be stock [10:11] Okay [10:11] often isnt on a VPS [10:11] yay [10:11] landscape-common it is [10:11] i did [10:12] its a fresh install of 12.04 [10:12] with basic things [10:12] im not running 100 websites [10:13] wel thats odd [10:13] users logged in : 0 [10:13] shouldnt it show me as 1? [10:13] I have Ubuntu 12.04.3 installed on a virtualbox vm from yesterday. I can confirm that apticron does not edit the motd. Sorry about that. Though I do wonder if apticront is running apt-get update on a daily basis - or is this done anyway on servers? [10:14] s/apticront/apticron [10:15] ok the user thing is 0 as usual [10:16] bigcalm: well for me apticron isnt going to do anything nless i install it as root so [10:16] i dont think its fetching anything for me at the moment [10:16] the one popey and jpds mentioned seems to have done it [10:16] + commons [10:17] ixxvil: I meant that to install anything from the CLI one has to have elevated privileges. Either by being root or using sudo [10:17] oh right [10:17] i do [10:18] The line you pasted meant 1 of 2 things. 1. you were not root or didn't use sudo when you did apt-get install apticron. 2. you had another package manager running that was locking the file [10:18] The error line that is [10:19] i used sudo [10:19] but it says i need to be root [10:20] i installed apticron after installing update-motd [10:20] ixxvil: you dont need to "be root", you just need to have the privs of root, which sudo gives you [10:21] right [10:21] but this is weird [10:21] what is? [10:21] i get the system info now but not the security alerts [10:22] maybe you have no pending security updates? [10:22] if so shouldnt it say at the bottom? [10:22] : 0? [10:22] No, it doesn't appear to do so [10:22] If you run sudo apt-get update; exit; login [10:22] 0 packages can be updated. [10:22] 0 updates are security updates. [10:22] You will then see the magic numbers again [10:22] yeah i dont see that [10:23] I don't always see the numbers if I've recently logged in or run dist-upgrade I think [10:23] i jsut ran that [10:23] it fetched a bunch of stuff [10:23] so you have no updates? [10:23] and logged me out [10:24] http://reviews.cnet.co.uk/video-streamers/sky-now-tv-box-review-50011842/ + http://community.mediabrowser.tv/permalinks/14670/guide-to-installing-mediabrowser3-onto-the-now-tv-box [10:24] So if you now ssh back into the server, you might see something [10:24] ah it shows up now [10:24] looks interesting [10:24] 59 packages can be updated. [10:24] 25 updates are security updates. [10:24] Right [10:24] for updating those 25 seurity updates [10:24] how do i do it [10:25] sudo apt-get update [10:25] sudo apt-get dist-upgrade [10:25] oh [10:25] ok [10:25] that would pull in all of the updates though [10:25] Am I thinking that apticron does a daily "apt-get update" or should that already be happening? [10:25] true [10:25] it already happens [10:26] lright thx [10:26] as I said (a few times) apticron is for mailing you when there are updates ☻ [10:26] which bigcalm does [10:26] i saw that in the paste [10:27] ya, i do as well [10:27] ye im not superanal about that unless i was a sysadmin [10:28] one last thing [10:28] you guys got a decent iptabnle ruleset i can use? [10:28] Morning all [10:28] the one that comes with my vps is absolute trash [10:28] ixxvil: ufw ? [10:28] it drops eveything [10:28] ye i heard about ufw [10:28] Morning davmor2 [10:28] what is it [10:28] $MORNING [10:28] !ufw | ixxvil [10:28] ixxvil: Ubuntu, like any other Linux distribution, has built-in firewall capabilities. The firewall is managed using the 'ufw' command - see https://help.ubuntu.com/community/UFW | GUI frontends such as Gufw also exist. | An alternative to ufw is the 'iptables' command - See https://help.ubuntu.com/community/IptablesHowTo [10:28] why am i still playing this cookie game [10:29] ali1234: because it's cookies [10:29] this game reminds me a lot of eve online, except without the griefers [10:29] ixxvil: So, to allow SSH, you would do: sudo ufw allow 22; sudo ufw enable [10:29] oh, crud [10:30] left that running [10:30] oh my god [10:30] ixxvil: Then do: sudo ufw status verbose --- to see it running. [10:30] ufw is so easy [10:30] 30 million cookies later [10:30] ixxvil: And that's the point. ;-) [10:30] i am about to hit 500 million cookies [10:30] there it goes [10:31] ixxvil: Of course, you can do: "sudo iptables -L -vn" to see what it does under the hood. [10:31] heh [10:31] ufw is good. it's syntax is a little confusing when you try to do advanced things like allow incoming connections only from one IP [10:32] is that an advanced thing to ask of a firewall? [10:33] it is for ufw, yes [10:33] ali1234: Really? [10:33] so deny all and allow only 1 ip? [10:34] how do flush it like in iptables if something goes wrong [10:35] ixxvil: I hope you have a serial console to your VPS, just in case you lock yourself out with incorrect firewall rules :) [10:35] ali1234: sudo ufw allow from hows that hard? [10:35] bigcalm: you mean have to two opened at the same time? [10:35] ye i learnt that yday [10:35] davmor2: But no port. [10:35] cause i messed up on iptables twice and couldnt ssh back in [10:36] it DROPPed everything [10:36] davmor2: that's not hard, but it also doesn't work [10:36] ixxvil: that's one way, but I do mean a serial console via a web interface provided by your hosting company [10:36] oh [10:36] ali1234: sudo ufw allow proto tcp from 192.168.0.1 to any port 22 [10:36] like cpanel [10:36] ye i do [10:36] ali1234: That's what it is, it's in the man page. [10:36] mighthave to read up on ufw a bit [10:36] but it's certainly easier [10:36] jpds: yeah. which is not the same as the "simple" syntax [10:37] I like rackspace's network policy manger for their cloud servers. That's a simple interface [10:38] thats simple [10:38] ali1234: that's pretty simple in comparison to an iptables rule to do the same thing [10:38] compared to the weird flags in iptables [10:38] I ia i -A [10:38] and what not [10:38] davmor2: i never said it wasn't i said it is the most complex thing ufw can do [10:39] simple commands in ufw look like "ufw allow 80/tcp" [10:39] you might expect that you can extend the simple commands like "ufw allow 80/tcp from " but this does not work [10:40] instead you have to use the "extended" syntax which puts everything in a totally different order [10:42] whats the extended syntax === alan_g is now known as alan_g|afk [10:48] ixxvil: "ufw allow proto tcp from 192.168.0.1 to any port 22" at a guess [10:49] bigcalm: shorewall's got a lovely notion of 'safe-restart' which is a godsend on remote machines [10:49] it applies the new rules and prompts for a 'Y/N'; if it doesn't get that in a few minutes it reverts the rules [10:49] few minutes? I think it's 30 seconds actually [10:50] ixxvil: https://help.ubuntu.com/community/UFW this is a good guide on ufw [10:50] tx [10:50] just wondering [10:50] ufw cant do rate limiting? [10:51] something like this - "I want to block everything for Z seconds after X connection in Y seconds === alan_g|afk is now known as alan_g [10:54] http://serverfault.com/questions/368523/rate-limiting-with-ufw-setting-limits [10:55] ixxvil: that was the first google hit for ufw rate limiting [10:55] ixxvil: there were plenty of others if that was what you were after [10:56] ye [10:56] reading [11:22] Noodles O'clock [11:22] alright later! [11:24] http://ubuntuone.com/0oxAT8t52o9p3U2wrtjUGP [11:24] oops [11:25] was planned :-) [11:25] i mean oops for the bandage [11:25] i assume you didn't plan to hurt your toe [11:25] it's been ingrowing for years [11:26] finally decided to get it sorted [11:30] Ouch [11:34] not gonna click [11:34] mungbean_: nothing bad about the photo [11:34] Just feel ouch for Laney [11:34] my toe went manky and the doc couldn't grow a culture from it so not really sure what to do now [11:35] Should be smaller after Friday :P [11:35] want to know when I can go climbing again though === alan_g is now known as alan_g|lunch [12:04] is it recommended to drop all incoming connections ? [12:08] Generally, yeah - default to dropping everything and then explicitly permit that which you actually want [12:09] thats the issue [12:09] i dunno want to permit [12:09] for outgoing [12:09] what sort of computer is this? a server? [12:09] vps [12:09] ive just got my site on it, nothing else [12:09] yeah, what's it doing? [12:09] just hosting a bunchof html, css, php pages [12:09] right, so you'll want to allow inbound connections to port 80 [12:09] bootstrap [12:09] and perhaps 443 if you've got SSL [12:10] ye i do have ssl havent set it up yuet [12:10] you'll probably want to ssh in on port 22, too [12:10] and if you're not running any other services that's about it [12:11] Personally I wouldn't bother with outbound restrictions generally [12:11] safest is to block all of them and again open up holes as you need them, but wgets not JustWorking gets quite tedious pretty quickly [12:13] hold on [12:13] ssh is allowed [12:14] sudo ufw allow 2423/tcp [12:15] so for outbound deny all? [12:15] sorry [12:15] outgoing allow all? [12:17] I'd allow all outbound [12:18] and only permit inbound on ports 80 and 22 [12:20] done [12:20] and for rate limiting sudo ufw limit 2323/tcp? [12:21] cause i changed the ssh port, nt sure why but i did [12:24] just one last thing [12:24] i was allow certain incoming like ssh and 80 [12:24] but if i set the rule now to deny all incoming [12:24] which would have more precedence? [12:24] or it doesnt matteR? [12:26] also in the ufw status, why does it replicate the same rules twice? [12:26] is it replicated for both incoming and outgoing? [12:33] Does Ubuntu touch run on the N7 2013 (dual boot) yet? [12:38] anyone know why i get "insufficient storage space available" on my tablet when installing twitter app? [12:38] i have loads of space [12:39] mungbean_: which tablet [12:39] touchpad [12:39] (os, really) [12:39] runnig cm [12:39] mungbean_: checked settings > storage? [12:39] 4.1.2 [12:39] check the status of the /data partition [12:39] 149MB internal availabel, 1GB SD card available [12:40] most other apps update OK some don't [12:40] #cyanogenmod-touchpad <--- may be more use [12:40] i own one but i'm still running CM9 [12:43] twitter app is utter fail [12:43] used to use tweetdeck but they blocked it. but i have to sign in with password every time i reboot my phone === alan_g|lunch is now known as alan_g [12:46] fixed the install issue [12:46] moved the kindle app to sd card, even tho i had loads free already [12:47] anyone done much by way of diagnosing freezing (mid-2010) macbook pros? [12:47] i don't even know any apple channels on yonder freenode [12:48] certainly my usual PC experience applies - so my first step would be to memtest this sucker once i'm near it later this afternoon [12:52] mine used to freeze sometimes [12:52] it's a 2010 MBP 13" [13:00] popey: core 2 duo sucker? trouble is the variables are that i put an SSD in and doubled the RAM for this-un [13:00] i sold a broken powerpc macbook so a fiver [13:01] broken mobo, broken power switch, no disk, no ram [13:04] yeah, mine is a c2d, still in daily use by wifey [13:06] daftykins: i identified the problem as a manky chrome install [13:06] oh really 0o [13:06] had to do a lot of clearing up to wipe it away and start again [13:06] i'll give the ol' fix permissions thing a run anywho [13:06] been fine since [13:07] this'un doesn't use anything besides Safari [13:07] initially thought it was overheating given it's on wifeys lap [13:07] heh [13:17] Is there much difference between the latest snapshot of 13.10 and what will be released tomorrow? [13:17] Pondering installing it in a VM and having a play [13:19] I'd hope not [13:19] nope [13:19] VMs are very pleasing === Lcawte|Away is now known as Lcawte [13:22] no risk to VMs, why not do five! XD [13:22] then have fun tomorrow as the repos crawl as usual :> [13:25] not if you use a mirror [13:25] I'm using goscomb which is super speedy [13:30] squid-deb-proxy++ [13:32] it's a shame squid-deb-proxy doesn't work out of the box. seems silly having to install from the public mirrors before you can get to it [13:44] I appear to have chosen goscomb as well [13:44] Or the mirror choose did [13:44] http://www.polygon.com/2013/10/15/4843366/nintendo-2ds-teardown-reveals-its-big-single-screen-construction [13:44] gosh [13:46] Goodness [13:47] Just got around to listening to the latest uupc. Still no mention of an event on the 25th. Maybe it'll be in next week's episode ;) [13:48] This is odd [13:49] Running the software updater in the vm. The details window is showing static content with no scroll bar. expanding/contracting the details area, using the icon, updates the content [13:49] But it's not actively updating the details area [13:50] davmor2: ^^ [13:50] I don't know if this is a problem with the updater or the fact it's running in a VM [13:50] There's no scroll bar either [13:51] bigcalm: update manager is naff all to do with me sunshine ;) It scrolled here this morning on HW if that is any help? [13:52] :P [13:52] Fair enough [13:52] How on earth can you be too busy to come to the LUG tonight? [13:54] nyone knows where you change the ServerName from 127.0.0.1 to the hostname? [13:54] do I add line in sites-enabled with Servername localhost? [13:59] bigcalm: I've no idea, right. I mean it's not like there is a release or anything tomorrow.............Oh wait [14:01] davmor2: shouldn't everything have been frozen already so that tomorrow's release is nice and relaxed? [14:02] any ideas? === Lcawte is now known as Lcawte|Away [14:39] ixxvil: in Apache? [14:39] what's the larger problem you're trying to solve? [14:39] each virtualhost has exactly one servername [14:40] normally when you add a virtualhost it gets its own file in sites-available [14:40] and you neable it with a2ensite [14:40] oh i fixed it [14:40] thanks [14:41] BigRedS: trying to setup SSL [14:42] try8ing to get the private key but i need root and i forgot [14:42] so waiting on the admin [14:46] /leave [14:46] \leave [14:50] Guys, SSL you have to give your number over [14:50] Does anyone know if it has to be a DDI or can it be a switchboard number ? [14:51] ? [14:52] Basically we're wanting to register an ssl cert for a customer [14:52] They want a contact number, a direct line number and as far as I know a business number will do, you don't need to give them a Direct line number [14:53] depends on the SSL vendor's automation levels [14:53] chances are the number will be used for EV === Lcawte|Away is now known as Lcawte [14:54] But if you can get hold of that person through generic reception that is the same thing imo, trying to find info on the web but not succeeding yet :) [14:56] our SSL people are out; I can check when they get back [14:56] yeah found it, so basically it needs to match with business register ( company house ? ) and whois [14:56] it'll be comodo's, but generally everything has to match something publically available - company registration, domain whois etc. [14:56] oh [14:56] So sounds to me like the main number to me ( can you tell this is the first time I've registered an official cert :D [14:56] So yeah what you said [14:58] we use 2 different registrars [14:58] startcom are cheap and mostly automated, but not particularly trustworthy [14:59] digicert are much nicer and shiner, but omgexpensive [15:01] OK thanks [15:02] We've used RapidSSL, can't comment on their trust level though [15:02] If you want to pay though the nose, go with VeriSign or Thwart [15:03] T - 9 days [15:03] \o/ [15:07] people actually check WHOIS information? [15:08] I do [15:08] as do I, but I didn't expect that they would be checked 'officially' when registering an SSL certificate, I guess it makes sense, though. [15:09] it's also a handy way to look up the address of a friend of mine in Michigan [15:09] yes [15:09] with startcom, they only let you get certs for a domain if you can confirm that you receive email to the address in whois [15:10] yeah, I think comodo do that [15:10] I try to not go anywhere near that bit of ssls [15:10] i work in hosting so do all the time. [15:11] yeah, I put the certs in place, but we have People to do the ordering :) [15:17] I've found part of the issue, one of my colleagues is rectifying it now. [15:17] I work in support, when people ask me about the prices, I can honestly say I have no idea about that side of things and refer them to sales. === schwuk is now known as schwuk_away === schwuk_away is now known as schwuk [15:20] heh, we do the same, but it seems to be taking some internal pushing and shoving [15:22] I was told in a previous job that being a technical support representative, there were reasons why I shouldn't give out pricing information, some legal and some relating to current discounts I might not be aware of. [15:23] I'm much happier not having to deal with that sort of thing if it means I get the occasional question passed on to me about where customers have to go to find their invoice on the website. [15:23] i don't deal direct with clients [15:24] I'm happy enough that we don't touch sales at all, but someone's pushing us to call customers who's contracts are expiring, "just to make sure they're aware". which is waay too close for my liking [15:24] and typically a very awkward call because even if they want to do something about it, I can't renew them [15:25] just one of those silly things where there's way too many people involved [15:25] shauno: yeah, that should be the job of the salespeople, for sure. [15:26] I was encouraged a few years ago to try and "upsell" things like hard disk replacements, which was always a pretty awkward conversation in itself when someone's machine is down because their disk has died. [15:27] "Would you like an 8GB disk as an upgrade?" "No, I just want the bloomin' thing to work again, and I can't spend any money myself anyway" was the usual way the conversation went [15:28] the biggest wall I hit is that we're looking at datacenter-scale customers, so the people I'm talking to are rarely the people sales want to talk to anyway. and the people I talk to are just as wary of salesmen as I am [15:28] indeed [15:36] oh well. place I'm interviewing for is even bigger, so better get used to it I guess [15:39] apache is so confusing [15:39] ive got no httpd.conf [15:39] and inside of apache2.conf there is nothing about ssl [15:40] any idea where you see or amend the SSL section in apache2.conf?? [15:40] there won't be .. anything that's global will be in mods-available/ssl.conf, and anything that's site-specific will be in sites-available/ [15:40] what shauno said [15:41] what directhex said [15:41] mods-enabled and sites-enabled possibly more relevant though ;) [15:41] possibly ;) I just grepped ssl because I don't know the filenames offhand, so grep answers the actual file rather than the symlink [15:42] what happens if your domain registrar goes bust? [15:43] I imagine you'd be able to transfer to somewhere else [15:43] how specifically do you go about doing that though? [15:43] if it's a .uk, you can get nominet to sort you out for a small fee (10-quid-ish) [15:43] I've had domains through a company that was so badly managed that ICANN stepped in [15:43] supposing it's a .com... [15:43] I think they gave you the option to transfer, or after a while they all got sent to godaddy [15:45] Also, it's reasonably likely that if you're worried about your registrar going bust, they're probably just reselling someone else [15:46] I only know .uk offhand because I've been there, nominet will retag it for a small fee & proof of id [15:47] had some registrar that went pop in 2008 or so. messy. [15:47] I assume it wasn't RegisterFly [15:47] doesn't ring a bell [15:48] They were the one that I mentioned that went down in flames [15:48] I had an email when 123 got bought out by whoever it is now saying it's all being transferred to X [15:48] Bad flames [15:49] Flames which resulted in the latest news on the customer panel being the owner's ex-partner saying how bad it was and how all customers should move away now before they get screwed out of more money (I rephrased it to be slightly more polite). [15:50] I wish I could remember who I had, but it was quite messy. they were meant to renew with the card on file, didn't, and then offered to sell it back to me for just shy of 5 digits [15:52] well, 9 hours, and I finally have a keymap I'm happy with. I really should look into translating this to xkbd some day [16:01] this is so damn confusing [16:01] everyone calls it httpd/conf [16:01] and then suddenly outta nowhere there's an ssl.conf hidden away [16:02] i just broke my shit [16:02] you're reading RHEL tutorials [16:02] you'll find this all-over the place in debian/ubuntu-land. if you're expecting one big configuration file, and don't find it, take a look around. it's almost always been broken down piecemeal [16:03] splitting into per-module and per-site config allows an entire site to be shipped with configuration, rather than "now, copy-paste this chunk into the single config file" in the manual [16:04] the ubuntu oneso my httpd.conf file where i can see the SSL section is actually ssl.conf? [16:04] so my httpd.conf file where i can see the SSL section is actually ssl.conf? [16:05] ther eis no mention of ssl.conf in like about 30 links ive been reading [16:05] everyone just refers to httpd.conf or apache2.conf [16:06] and for those using apache2.conf you have no httpd.conf but ive read cases where theyve created one for adding user modules into /conf.d [16:06] "everyone" [16:06] so goddamn confusing [16:06] there's a few paragraphs of comments at the top of apache2.conf that explain what you're looking at [16:07] modules are configured per-module. sites are configured per-site. this makes more sense than a single 3000-line config file [16:08] i cant find it on then top of apache2.conf [16:10] SSLCertificateChainFile does this come with ssl.conf? [16:10] or with apache2.conf [16:10] the ssl.conf has none of it [16:11] You might have better luck doing your SSL config via vhost files [16:12] you mean sites-available? [16:12] That's where they should be stored, yet [16:12] There might also be a default-ssl vhost in there [16:12] ye [16:13] s/yet/yes [16:13] what about change namehosts in ports.conf? [16:13] NameVirtualHost [16:14] it says if you change it there which i have then you need to change it in default-ssl [16:15] ixxvil, certificates are per-site. if i host foo.com and bar.com i might have a different certificate file for both, with a different chain [16:15] so certificate configuration is per-site, logically [16:15] ive got just one site [16:15] You can have ssl directives in vhost config files. Makes sense to keep them together [16:16] which i have [16:17] i should be modify8in default-ssl? [16:17] no [16:17] you should be making a new vhost file for this one [16:17] well, you *can* [16:18] there's a lot of scope for opionion here, does anyone else look after this machine with you? [16:18] default and default-ssl is an example file [16:18] you're missing the point by editing it [16:18] no they dont [16:24] I thought there was also a per-host certificate if you support HTTP1.1 properly? Old browsers won't know to tell the host the hostname in the ssl handshake [16:24] yes, for http 1.1 [16:24] so all those msie 2 users [16:24] ok so the default-ssl actually already has these SSL derivatives [16:25] so why is there a need to put it in the vhosts? [16:25] there's an entry for it already there in /default-ssl [16:25] jsut change extension and it should work? [16:25] change what extension? [16:26] SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem [16:28] ixxvil, you want to serve using a self-signed autogenerated certificate? [16:28] is the default-ssl just a sample? [16:28] no i dont [16:28] i hjave a commercial one [16:28] default-ssl is a basic example config to serve /var/www over ssl, if you enable the ssl module [16:29] default is a basic example config to serve /var/www without ssl [16:30] as of now [16:30] which one do i need to edit [16:30] enabled? [16:31] site configs live in sites-available [16:32] the "a2ensite" command creates a symlink to them in sites-enabled [16:32] ye si did that enable that [16:32] (and a2dissite to delete those symlinks) [16:32] much like a2enmod enables modules from mods-available [16:32] ive enabled a2ensite [16:33] where do i add the virtualhost with the ssl directives ? [16:34] Actually IE6 doesn't support SNI, and apparently neither do IE7 or IE8 if you're on Windows XP [16:34] you said default and default-ssl were just samples [16:35] sigh. [16:35] okay, here's a freebie. [16:36] should i edit the SSl derivatives in default-ssl? [16:36] ixxvil: copy one of them to a new file (yoursite.com or something) and edit the details in the new copy? Then run a2ensite yoursite.com [16:36] Doesn't the file have a comment to that effect? [16:36] here's an example vhost: http://paste.debian.net/hidden/c4ebcfb8/ [16:37] uses SSL with a cert chain, serves a basic path over ssl, redirects non-ssl to ssl, uses a specific vhost domain. [16:37] all the things you need. [16:40] the last part [16:40] the SSL engine on, etc [16:41] i have that already in the vhosts file [16:42] "the vhosts file"? [16:42] well in sites-available/default [16:42] a the very end ive added those ssl directives [16:43] ixxvil: at the end of the file or within the tag? [16:43] within [16:43] but at the very last [16:43] should i have to add #? [16:44] A # is a comment [16:49] ixxvil: it's possible that you are trying to configure systems that are currently at a higher level than your current knowledge allows. I suggest reading a tutorial such as: https://help.ubuntu.com/10.04/serverguide/httpd.html [16:49] Hopefully you will see that it's written for Ubuntu 10.04, but a lot of the information is still relevant [16:50] i had this working previously [16:50] but with the new vps things are a lil different [16:50] and the naming conventions clearly fucked things over a bit more [16:51] !ohmy | ixxvil [16:51] ixxvil: Please remember that all Ubuntu IRC channels share the same attitude of providing friendly and polite interaction with all users of all ages and cultures. Basically, this means no foul language and no abuse towards others. [16:51] ye [16:51] sorry [16:51] been sitting at this crap for hrs now [16:51] and this isnt even my job lol [16:53] Aha, there is an updated version: https://help.ubuntu.com/12.04/serverguide/httpd.html [16:56] ye thats the issue [16:56] this one has a different approach to what my vps said [16:56] so i followe the vps method,didnt work [16:58] the commercial ssl method, didnt work [16:58] because of the naming thing [16:58] linode has it written differently about mucking aorund with ports.conf [16:59] and now we have this that goes back to modifying the virtualhosts file [16:59] i need coffee [17:04] popey: what was the command mentioned in Command Line Lurv that will open a file in the appropriate gui app? [17:05] xdg-open [17:06] Yay :) [17:06] Ta [17:06] I will forget it soon enough [17:08] so the issue is i kept modifying default [17:09] and then did a2enmod [17:09] my sites-enabled and default are the same now [17:10] i didnt create a copy and then modify it as your link says [17:10] or rather i didnt know [17:11] cansomeone paste me the sites-available/default config that comes without changes? [17:11] cause i made some changes and not sure how to revert to the original to fix things [17:14] ixxvil: I think you need to brush up on your google skills. Something like "ubuntu revert apache configuration to default" gives lots of help [17:16] ye reinstall [17:40] @online accounts stop opening multiple blank browser windows to tell me that I need to reausthorise my account === schwuk is now known as schwuk_away [17:50] ok [17:50] so sites-available/default vs sites-available/default-ssl [17:50] its the essentially the same thing but one is without ssl and the other is? [17:51] and i need to put all of them together in one file is that it? [18:08] ok i reverted things [18:08] 000-default is for port 80 [18:16] yes!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! [18:16] * ixxvil takes a few shots in the air [18:26] heh [18:28] that took 6 hrs rofl [18:28] i coud've found 2 deisgn jobs by then [18:29] paid someone to fix this and still saved an hr [18:29] guess i learnt something though [18:33] thanks all! [18:33] you guys have been very patient [18:40] yay, got £12.50 in vouchers for filling in a survey that i suspect was spam [18:40] s/pect/pected/ [18:41] was an unsolicited email sent to vmware customers \o/ [18:42] i've been getting a lot of weird email lately [18:43] today i got one from http://www.gymnasticsuk.org/ which looks completely legit in that it is highly specific [18:44] usually i bin anything like that cos i get a lot of targeted stuff via linkedin ppl looking up my address in the public company directory [18:45] is there any point updating firmware on kindles? [18:45] the kindle app gets new features like "time to finish" but unsure about the hardware ones [18:47] my mum's kindle would crash all the time until i updated the firmware [18:49] cant find changelogs [18:50] seems there's only been a minor udpdate since 2012 june === slvr is now known as hearn === hearn is now known as slvr [19:40] so ufw check, ssl check, what else [19:40] anything else for security? [19:40] ssh check [19:49] if you are running a php cms, make sure you set it up right [19:51] ive got php running here and there [19:51] but not like a full grown cms === Lcawte is now known as Lcawte|Away