/srv/irclogs.ubuntu.com/2014/01/02/#ubuntu-server.txt

=== freeflying is now known as freeflying_away
=== freeflying_away is now known as freeflying
krababbelHi, why is there a relative path in openssl.cnf for CA_default? Where should I keep my files like certs if I want to be my own CA for a LAN? Some say in /root/ca but others suggest /etc/ssl03:09
krababbelAlso I want to create a certificates for my webserver and mailserver. Without my own CA signing both certs, I'd need to install multiple certificates on clients, correct? With my CA, a client could verify both mail and web certs using only the CA cert, correct?03:14
patdk-lapdepends on what you do03:16
patdk-lapyou could have some other ca sign them03:17
krababbelpatdk-lap: I need to sign them myself, it is just a test LAB.03:17
krababbelpatdk-lap: So if I sign them myself, my clients in the lab could verify all server certificates, which were signed by my CA, and the clients would only need to install my CA certificate, correct? I am a bit unsure now.03:19
krababbelpatdk-lap: Otherwise I could just self sign the certs on the mailserver and webserver for example each.03:20
patdk-lapyes03:20
patdk-lapbut the server would need it's certificates and any intermediate certs (that doesn't sound like your making)03:20
krababbelpatdk-lap: OK, thank you a lot.03:23
rsdany good suggestions for a MON replacement (if any)?03:48
patdk-lapwhat is a mon03:49
rsdsystem monitoring, alert, etc03:49
krababbelI am unsure about LDAP authentication and /home on an NFS server. If the LDAP and NFS servers are different machines on the network, could pam_mkhomedir create the homedirs on the NFS server on first login?05:31
krababbelWhy is it a problem with having both local and LDAP homedirs in /home? I read that usually you should separate them, but I don't see why. Aren't UID and GID enough?05:39
krababbelMaybe that's only for users which already exist locally.05:45
krababbelOr is the problem that a local user trying to login and mounting their /home/... could be rejected by the NFS server because NFS may not find that user in LDAP and locally, I guess.05:49
krababbelSo if the same local user already exists on all machines, and the only additional users in /home would be LDAP users, then separating /home wouldn't be necessary?05:51
=== sivatharman__ is now known as psivaa
=== ikonia_ is now known as ikonia
Rar9morning. need some help with an Error 503 for installing Solr4 with Tomcat7  .. Anyone?09:25
ikoniaRar9: 503 is service unavailable suggesting that it's not listening on the port you have defined, or it is listening but the application is not configured (which is common with solr)09:43
=== Ursinha_ is now known as Ursinha
=== gary_poster|away is now known as gary_poster
=== highvolt1ge is now known as highvoltage
krababbelWhy is it a problem with having both local and LDAP homedirs in /home? I read that usually you should separate them, but I don't see why. Aren't UID and GID enough? But if there is only the same local user on all machines, and the only additional users in /home would be LDAP users, then separating /home wouldn't be necessary?13:08
=== mjohnson15_2 is now known as mjohnson15
=== dannf` is now known as dannf
zulrbasak/hallyn: im adding that arm64 patch before uploading a new libvirt (1.2)15:52
ahnklei am thinking of getting a Proliant DL140 G3 for personal use. there is an Ubuntu 10.04 release. is this retired now?15:54
rbasakzul: I'm not sure we should right now.15:54
rbasakzul: I don't want to cause a future conflict with a Linaro patch.15:54
rbasakI emailed Clark (Linaro) to get his view.15:55
zulrbasak:  arrgh after i rediffed it15:55
rbasakSince he's doing the libvirt armhf/arm64 enablement work which involves pushing it upstream.15:55
rbasakzul: well, I did say in the bugĀ·15:55
zulrbasak:  yes but im not awake yet :)15:55
hallynzul: bug 1264955 - any objections to nfs-common being in libvirt build-dep?16:25
uvirtbotLaunchpad bug 1264955 in libvirt "libvirt: find-storage-pool-sources work unexpected" [Undecided,New] https://launchpad.net/bugs/126495516:25
zulhallyn:  nah16:28
zulhallyn:  1.2.0 has been uploaded like a half hour agao16:28
hallynyeah - and on the one hand i don't want a new uplaod just for that, but otoh if we don't do it now we'll never remember :)16:34
hallynwell i've added it to my long list of libvirt bugs to work on when i have time16:35
zulhallyn:  sweet...just batch them up :)16:35
krababbelHi, is there a problem sharing one public folder over samba and nfsv4 at the same time?16:50
jrwren_no, no problem.16:51
krababbeljrwren_: OK thanks, I'll try that.16:51
jrwren_why would there be a problem :)16:51
krababbeljrwren_: I asked because NFSv4 uses usually this special folder /exports16:52
krababbelSo I was unsure if they'd work nicely together. (samba and nfs)16:53
jrwren_oh no.16:55
jrwren_that /exports is just a default config. you can export anything16:55
krababbeljrwren_: Thank you a lot. :)16:55
hallynzul: is ppa:ubuntu-cloud-archive/havana-staging "the havana cloud archive" ?17:23
zulhallyn:  its the staging area http://www.ubuntu.com/download/cloud/cloud-archive-instructions17:24
hallynwhere is the real havana cloud archive then?17:24
hallynoh i see, thx17:25
hallynhow do i add the apt-key?17:25
hallyneh, nm.  no matter for the test17:26
=== gaughen_ is now known as gaughen
=== justizin_ is now known as justizin
hallynzul: are you doing anything right now on libvirt apparmor bugs?17:44
hallynjdstrand: can I (later today/tomorrow) point you to some debdiffs relating to libvirt-apparmor?17:45
zulhallyn:  nope just getting libvirt-python ready for mir17:46
hallynoh i thought with merge from debian you didnt' have to17:46
hallynok.  just one more lxc thingie and then i'm hitting libvirt-apparmor hard.17:46
zulhallyn:  nah i wish it was like that17:46
=== gary_poster is now known as gary_poster|away
=== gary_poster|away is now known as gary_poster
adam_gzul, if you get some minutes today could you plz take a look at the 2013.2.1 branch updates at https://code.launchpad.net/~ubuntu-server-dev/+activereviews ?18:43
zuladam_g: 2013.2.1?18:44
adam_gzul, the first havana stable release18:44
zuladam_g:  cool gimme a sec18:45
adam_gzul, no rush18:45
zuladam_g:  +118:48
adam_gzul, nice thanks18:49
=== melter_ is now known as melter
=== pHcF_ is now known as pHcF
krababbelI want to export /home directories over NFS. Why do people say it is a problem if I do not separate the remote home folder from the local home?20:02
krababbelFor example like described here in the second paragraph: http://nickportertech.blogspot.co.at/2010/02/ubuntu-machine-with-nfs-home-and-ldap.html20:02
jrwren_krababbel: its only a problem if you want to login to an nfs client system when the nfs server is down20:04
krababbeljrwren_: OK thanks a lot, of course, I am tired. :)20:05
jrwren_if that is not a requirement, then it is no problem.20:05
krababbeljrwren_: I see, yes.20:06
=== cmagina_ is now known as cmagina
=== Guest35485 is now known as Rasmus`
hallynjdstrand: in qrt test-libvirt.py, there are two lines restoring "/etc/apparmor.d/abstracations/libvirt-qemu" <sic>.  Is that some intended genius, or a typo?21:45
tclarkeI'm setting 12.04 MAAS and I'm having trouble following the install docs...I get to the point where I need to d/l initial boot images and run "maas-cli mynam node-groups import-boot-images" where mynam is the name of my login profile21:49
tclarkenode-groups: error: argument COMMAND: invalid choice: u'import-boot-images' (choose from 'register', 'list', 'refresh-workers', 'accept', 'reject')21:49
=== tclarke is now known as tclarke|AFK
stdarohttps://bugs.launchpad.net/ubuntu/+source/openjdk-6/+bug/257857 is pretty unpleasant, still applies today22:01
uvirtbotLaunchpad bug 257857 in openjdk-6 "openjdk-6-jdk should depend on openjdk-6-jre-headless too" [Low,Triaged]22:01
=== gary_poster is now known as gary_poster|away
bravvve22hello am newbe,in a vps ubuntu 10.04 is installed and if config gave me venet0:0,no eth0 what meen?22:20
bigjoolstclarke|AFK: you need to run the version of maas in the cloud archive23:06
adam_gzul, ping23:41
krababbe1Hi, if I enable no_root_squash on an export, could it be dangerous for the NFS server, or would that "just" allow a remote root to do anything within that export folder?23:44
bekkskrababbe1: yes, it could dangerous, dependingon what you are sharing.23:45
krababbe1The problem is, that I want to have an NFS server export /home to clients. These clients are LDAP accounts, and I want to use pam_mkhomedir to create their homes on first login. But I get 'permission denied', and I guess it has to do with the fact that remote machines are restricted by root_squash. With no_root_squash it seems to work.23:47
krababbe1bekks: The NFS server, LDAP server and client are three different machines on the LAN.23:48
bekkskrababbe1: Which doesnt matter, and doesnt clarify which shares you are going to share with no_root_squash23:49
krababbe1bekks: The /home folder would be shared with no_root_squash.23:49
krababbe1bekks: On the NFS server it would be /mnt/home, since I separated local home from LDAP user's homes23:50
bekkskrababbe1: Unless root isnt going to use stuff from /home, it's nasty, but somehow safe.23:50
krababbe1bekks: I guessed so. :) Is there an similar alternative?23:51
krababbe1using pam_mkhomedir I mean23:52
krababbe1I am doing this for the first time.23:52
hitsujiTMOkrababbe1: i'd also ensure subtree_check is used23:52
krababbe1hitsujiTMO: Thanks, I'll try that.23:53
adam_gzul, anyway, /me needs sponsorship for http://people.canonical.com/~agandelman/heat-2013.2.1/ . can you help? guess heat is not seeded properly?23:54

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!