/srv/irclogs.ubuntu.com/2014/02/13/#ubuntu-server.txt

=== freeflying_away is now known as freeflying
=== thumper-lunch is now known as thumper
tewardis there a reason ssh wouldn't try and serve my ssh key to a server automatically, when the filename is a custom filename?  it works fine when sshing to my servers from Ubuntu, but when SSHing to my servers from one of my other servers, it fails...01:00
=== arosales_ is now known as arosales
sarnoldteward: check group ownerships01:09
sarnoldteward: ssh is super picky about who can read or write files, and it won't go to the effort of figuring out that you're theonly user in your group..01:09
tewardsarnold: *what* group permissions?01:09
tewardthe permissions are 0600 user:user01:09
teward(where the user has their own group)01:10
sarnoldteward: on everything :) key, authorized_keys, etc01:10
tewardsarnold: i checked...01:10
sarnolddrat.01:10
tewardsarnold: the same key file works *fine* when it's id_rsa / id_rsa.pub01:10
tewardbut when it's a customized name, like, for me, since i have 4 different keys...01:10
tewardit fails01:10
tewardand ssh -vvvv shows it's never even *attempted*01:11
sarnoldteward: does your ~/.ssh/config contain match statements that match the host and say to not try?01:11
tewardsarnold: should i be concerned when ~/.ssh/config doesn't exist?01:11
sarnoldteward: no01:12
tewardsarnold: adding `IdentityFile ~/.ssh/keyfilename` to ~/.ssh/config worked01:16
tewardi guess i'll just need to add all the key files to that then01:16
sarnoldteward: or add them with ssh-add when you need them01:16
sarnoldyour choice01:16
=== ahs3|dentist is now known as ahs3
tewardtrue01:18
tewardsarnold: any idea why on a Desktop setup of $any_supported_ubuntu_release it automatically tries all the identity files in `/home/$USER/.ssh/` even though I haven't done ssh-add on those keys?  Or should I poke #ubuntu asking that?  (you seem to know the underlying ssh stuff though, hence the question)01:29
sarnoldteward: sorry, no idea there. :/01:32
tewardsarnold: meh.01:39
tewardit works now, so it's less of an issue01:39
sarnold:)01:39
tewardthanks though01:39
=== ryan`c is now known as ryan-c
=== cmagina_ is now known as cmagina
=== xnox_ is now known as xnox
=== markthomas_ is now known as markthomas
=== ValicekB_ is now known as ValicekB
=== fhd__ is now known as fhd_
=== Pici is now known as Guest56659
=== Jalen is now known as Guest54073
=== kursd is now known as 77CABFT4M
=== Southron_ is now known as Southron
=== njbair_ is now known as njbair
=== ejv_ is now known as ejv
=== TheLordOfTime is now known as teward
MavKenI have phpmyadmin installed on my vps, have 12 domains hosted.  How can I limit it so that phpmyadmin can only be accessed via my primary domain?03:47
=== _thumper_ is now known as thumper
=== thumper is now known as thumper-afk
=== blessd is now known as kursd
=== etzsch is now known as m6
=== torsten19032_ is now known as torsten19032
iggiAnyone have experience with multipath iscsi? Everything I can find says it is setup correctly, yet when I do a test only one NIC is ever used.08:31
=== Smedles_ is now known as Smedles
=== bigjools_ is now known as bigjools
_root_hello10:25
_root_I followed https://help.ubuntu.com/community/Postfix to set an mail delivery agent10:25
_root_But i am at lost here because I have a cms needs SMTP server and port and SSL/TLS choice to send the verification emails and I have no idea what port i have for smtp or even if i have SMTP server10:27
_root_could someone give a clue as to have should I do?10:27
caribou_root_: did you look in the Ubuntu Server Guide ?10:28
caribou_root_: there is a chapter on postfix10:28
caribous/chapter/section/10:28
_root_caribou: which one you mean i am on https://help.ubuntu.com/community/Postfix10:28
caribou_root_: this one : https://help.ubuntu.com/13.04/serverguide/index.html10:29
caribou_root_: even better URL : https://help.ubuntu.com/13.10/serverguide/email-services.html10:29
_root_caribou: is it the same as 12.4.04 LTS10:29
caribou_root_: there is one for 12.04, just put 12.04 in the URL above10:30
caribouwho maintains the cloud-tools repo ???10:31
_root_caribou: what you gave me is the same as https://help.ubuntu.com/community/Postfix that i used10:34
_root_but still what are my smtp server value port and so on10:34
caribou_root_: could be, I didn't check the content on both10:34
_root_SMTP server should be localhost but what about port and which one do i use SSL/TLS10:35
caribou_root_: don't know if that can help, but SSL/TLS default port is 465; but I'm nowhere near an expert in MTA setup10:38
TJ-If you're using the localhost, then there's no reason not to connect on port 2510:41
=== rbasak_ is now known as rbasak
=== ikonia_ is now known as ikonia
catphishif i need to run a much newer kernel on ubuntu 12.04 (because the default kernel has a lot of lxc functionality missing), would i be better off using linux-image-3.11 from the repos, or a mainline kernel from the kernel-ppa?11:48
TJ-Use the LTS hardware enablement packs11:48
catphishinteresting, haven't see those11:49
TJ-see https://wiki.ubuntu.com/Kernel/LTSEnablementStack11:49
catphishso i likely want linux-generic-lts-saucy?11:51
catphishactually that just depends on linux-image-3.11 which makes perfect sense11:52
catphishthanks!11:53
adacDoes anyone experience problems with falsh player on ubuntu 12.04 desktop? I get a real high load average, even though memory and cpu are not used at all12:24
adacthis happens within firefox as well as chromium12:24
catphishadac: i think this is probably the wrong channel, try #ubuntu12:29
catphishadac: you may have disk IO issues12:29
catphishthat's the most common cause of high load, though flash could be doing something unusual12:30
adaccatphish, How can i debug a disk IO issue? is it hard to detect?12:31
catphish"iostat -x 1" will quickly show you your disk usage %12:32
catphishor top will show "%wa", the percentage of cpu time spent waiting for disk IO12:32
adaccatphish, here is a short excerpt: https://gist.github.com/anonymous/8974324 can you see a problem here already?12:35
catphishadac: %util is 0% so it's not disk IO12:35
catphishnow run "top" and see what the various % at the top say12:36
adaccatphish, https://gist.github.com/anonymous/897436412:37
catphishyour CPU load is reasonable, your load isn't "high"12:39
adaccatphish, isn't >1 already high?12:40
catphishnot particularly, i'd class that as "busy" but not problematic12:41
catphishflash isn't particularly efficient12:41
catphishuse top see how much CPU flash itself is using12:41
adaccatpish it is about 13% it is not that much.12:46
catphishadac: well i guess you have a few different things going on, but a load of 1.0 for an in-use system playing flash seems very reasonable12:49
=== yeats_ is now known as yeats
stefgHello channel, is anyone in here using a SSD-cache like bcache/flashcache/dmcache/enhanceio and likes to share some experience? I have a spare 40GB SSD partition on my xbmc-box/NAS running 12.04/32bit with a 3TB raid 1 as storage and wonder if it's worth to use that 40GB of SSD as  cache.13:42
=== jhobbs_ is now known as jhobbs
=== freeflying is now known as freeflying_away
caribousmoser: is there a way to tell cloud-init to use some squid-deb-proxy cache ?14:18
caribousmoser: other than writing the entry in /etc/apt/apt.conf14:18
zuljamespage:  oh so cinder needs a new dep14:22
rio_zentaHello folks14:24
rio_zentaMy VPS provider recently switched nodes and changed my IP address, after reconfiguring my domain records, I am still unable to access my domain at the new IP address. They recommended that I reconfigure networking, does anyone know what that means?14:25
mardraumwhat's the domain14:26
mardraumrio_zenta: they probably mean check you are really using the new IP. or did they do that all for you?14:27
rio_zentathe domain is: platform.devcroo.com14:27
rio_zentaI personally changed the ip address at my domain provider, but I am still unable to access the domain14:28
mardraumis "192.3.180.54" the new IP?14:28
rio_zentamardraum: they changed the ip address for me.14:28
rio_zentamardraum: Yes, that is the new ip address.14:29
mardraumdid the gateway IP change as well? does the vm have internet access?14:30
mardraumlog into it with whatever out of band access they provide (eg vnc) and check the networking14:30
mardraumin ubuntu, that is in /etc/network/interfaces14:31
rio_zentamardraum: I see that my provider is using SolusVM for the interface/control panel14:32
mardraumdoes it provide some sort of "console" access?14:32
rio_zentamardraum: It has a link to VNC14:32
mardraumgreat, are you logged into it?14:33
rio_zentamardraum: On the page that shows the VNC info, it has an address that is different to my IP address (with a port and password too). Is this the gateway IP?14:33
mardraumno, that will probably be the vnc host14:34
mardraumallowing you to connect to it and access your vm14:34
mardraumyou should use a vnc client to do so.14:34
rio_zentaoh ok. Will I be able to access the VNC from the commandline?14:35
mardraumthe command line of what?14:35
rio_zentamardraum: I use linux as my client distro. The commandline being something like Terminal (the application).14:36
mardraumyou generally need some sort of software to connect to a VNC server14:36
mardraumno, terminal won't do it14:36
rio_zentaOkay so I need to find myself a VNC client14:36
highclassholeCan you use anything other than vnc?14:39
highclassholeperhaps ssh14:39
highclassholeoh sorry I didn't follow the whole conversation my bad, is there not a browser based java client to connect to the console for your VPS?14:40
mardraumjava, ugh14:42
rio_zentahighclasshole: I see that the interface on the web provides a plugin, which isn't visible to me because I am missing a java plugin ( :-( )14:43
highclassholejust install that you should be good to go14:44
mardraumjust install a basic vnc program14:44
rio_zentaafter checking the plugins, it says I need to install the Java runtime environment14:44
highclassholeyeah just install java on your local machine14:44
highclassholeand then bring up the console14:44
highclassholenbd14:44
mardraumdon't encourage people to install java plugins, jesus14:44
highclassholereally?14:44
highclassholeI mean...14:44
mardraumworlds most exploited browser plugin ever14:44
rio_zentahighclasshole, I think I have java installed though. I suppose it has to do with the different javas (7 and 6 make java weird)14:44
highclassholeonly run applets from trusted sources14:44
highclassholeand use shit like noscript14:45
highclassholeif you need it, you need it, just be smart about it14:45
mardraumdon't enourage java. ever.14:45
highclassholeoh man fun14:45
highclassholeI work in a huge java shop14:45
highclassholeso its a little funny for me14:45
mardraumI'm specifically talking about the web plugin14:46
mardraumit's nice your java shop is huge14:46
rio_zentaAfter Java 7 came out, it probably confused developers too.14:46
mardraumbut don't encourage people to install that broken shit. Hell ubuntu only just managed to get the latest version in after missing a openjdk security version or two across versions dating back to 12.0314:46
mardraum12.04*14:47
rio_zentaI'm confused about it too. Oracle is worse than MS.14:47
smosercaribou, cloud-init supports 'apt_proxy' 'apt_http_proxy' and 'apt_ftp_proxy'.15:03
caribousmoser: fine, thanks15:04
smoserit also supports the more general 'apt_config'15:04
smoserapt_config is just put whatevery you want and it will write that to /etc/apt/apt.conf.d/94cloud-init-config15:05
smosercaribou, the best way to find out such things is to just grep liberally through15:05
smoserdoc/examples/cloud-config.txt15:05
caribousmoser: yeah, I got that page on my browser15:06
=== lazyPower_ is now known as lazyPower
=== roaksoax_ is now known as roaksoax
cocoa117how did someone setup IP like this, without a brocast address?15:50
cocoa117eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 100015:50
cocoa117    link/ether f2:07:01:ff:ff:fd brd ff:ff:ff:ff:ff:ff15:50
cocoa117    inet 192.168.1.254/24 scope global eth015:50
cocoa117    inet 1.15.255.254/13 scope global eth015:50
toyotapieCan I run xinetd on a port not mentioned in /etc/services ?15:57
toyotapieit keeps telling me 'service/protocol combination not in /etc/services'15:58
toyotapienevermind, I added type = UNLISTED15:59
cocoa117is tcpdump be able to listen to traffic before firewall filter it?16:33
catphishcocoa117: yes16:36
cocoa117catphish, is it on by default?16:36
catphishyes, tcpdump connects to an interface, so it sees everything on that interface before it gets in to the firewall16:37
cocoa117catphish, great, got it, thanks16:37
Guest11875hey ubuntu17:02
Guest11875I've got an instance on EC2 running the latest ubuntu server, but it seems to think it's Ubuntu 12.04. When I do `lsb_release -a` it says 12.04, and when I do `sudo do-release-upgrade` it says "No new release found". what gives?17:04
=== TREllis_ is now known as TREllis
shaunoGuest11875: LTS will consider itself current until there's a new LTS.  the setting is in /etc/update-manager/release-upgrades  Prompt=lts vs Prompt=normal17:15
shaunoGuest11875: otherwise 12.04 *is* the most recent LTS until 14.04 releases17:16
Guest11875shauno: ahh I getcha17:16
Guest11875is there any way to stop upgrades from constantly breaking my ldap auth?17:17
Guest11875I always have to fix ldap authentication after doing an aptitude upgrade17:17
zulhallyn:  ping17:20
hallynzul: .17:25
zulhallyn:  we already have that aarch64 patch17:25
hallynzul: ok, cool.  we do seem to get a lot of redundant requests for those...17:26
hallynzul: did you get the ftbfs straightened out?17:26
zulhallyn:  just uploaded it17:26
hallyncool, thanks.  fwiw dannf gave me a patchset to make qemu-user-aarch64 work as well, so we're doing pretty well for aarch64 in trusty17:27
zulsweet17:28
hallynzul: now the big thing in the new libvirt is the nwfilter locking patch right?17:28
hallyni.e. no fix there for bug 1274995 ?17:29
zulhallyn:  yeah im going to wait on that patch until the next release is out17:29
hallynok17:29
zuli think im missing something else with regards to that patch17:29
=== FunnyLookinHat_ is now known as FunnyLookinHat
=== klaas_ is now known as klaas
=== aslaen is now known as aslaen_
=== aslaen_ is now known as aslaen
=== _monokrome is now known as monokrome
=== mjeanson_ is now known as mjeanson
ruben231hi guys i have 60 units and same specs wanted to install ubuntu desktop at one time, any idea how to do it..?20:16
SJrWith a static ip address setup how do I configure a dns server, I tried putting it in my /etc/network/interfaces file, but resolv.conf is empty. resolv.conf also gets rewritten by something on reboot, and I can't set chattr +i on it for some reason20:18
geniiruben231: Probably then a pxe boot server and lots of switches20:20
sarnoldSJr: the resolvconf package is doing the re-writing; you can either work with it or uninstall it20:20
sarnoldSJr: check out the resolvconf(8) manpage, look for dns-nameservers20:20
SJrAh I was missing the s20:20
sarnoldfatal flaw of the silly thing, it's too easy to make pointless typos there because it doesn't match the syntax used elsewhere. sigh.20:21
sarnoldruben231: investigate preseed files and investigate fai-quickstart20:22
smoserhallyn, around ?21:03
hallynsmoser: yup21:03
smosercan you quick verify for me that if i run an lxc container, by defualt there is no cgroup limiting cpu or disk io or anything21:03
smoserright?21:03
smoserie, it should have all the performance of the host21:03
hallynsmoser: we don't set default  limits.  however, there is something about all tasks in a cgroup being scheduled as one entity21:04
smoserhm.. i dont knwo what htat means.21:04
smosercan i turn that off ?21:04
* knoxy is away: auto-away21:04
hallynsmoser: no.  and I don't knwo if it depends on our chosen scheduler21:04
hallynmight ask in #ubuntu-kernel.  it's possible it's nothing, i've just heard it mentioned somehwere21:05
* knoxy is back (gone 00:00:53)21:05
hallynsmoser: but what it would mean is that if you  have 10 non-lxc tasks and 10 lxc tasks, the 10 lxc tasks would get as much cpu time as oen of the non-lxc taskss21:05
smoserreally?21:06
smoserthat sounds not good generally.21:06
sarnoldhallyn,smoser, I think you might be recalling the kernel's sched_autogroup_enabled feature21:08
hallynsarnold: is that off by default?21:09
hallynsmoser: waht i can tell you is that a kernel build in a contaienr is much faster than kernel buidl in kvm on the same machine...  if that helps21:09
sarnoldhallyn: on by default, iirc21:10
smoserhallyn, is it also faster on amd64 than a a 486 ?21:10
smoser(ie, i would have expected that :)21:10
smosersarnold, can i turn it off?21:10
hallynsmoser: <shrug>21:10
hallyni would've expectd it to be closer than it is21:10
* hallyn googles21:11
sarnoldsmoser: echo 0 > /proc/sys/kernel/sched_autogroup_enabled21:11
hallynwould have been nice if that was availalbe through /sys/fs/cgroup/cpu/cpu.*21:11
smosersarnold, thanks.21:12
smoserhallyn, would i need to start a new container for that to take affect ?21:14
smoserthe change of sched_autogroup_enabled21:14
hallynsmoser: don't thinkn so21:14
smoseri suspect not21:14
smoseryeah. ok.21:14
hallynlooks like a global sysctl21:14
hallyni'm looking through /proc/$$/autogroup right now, trying to figure out what it means21:15
hallynsomeone forgot to write the Documentation/ for it21:16
hallynhm, does it require CONFIG_FAIR_GROUP_SCHED for that to make a difference?21:17
Joe_knockHello, I am trying to VNC into my VPS using RealVNC but I get this error: main:        unable to connect to host: Connection refused (111)21:24
sarnoldJoe_knock: do you have firewall rules on your host that would prevent it? does your ISP have firewall rules that would prevent it (see also amazon's "security groups")? Is the VNC daemon running on your host?21:26
Joe_knocksarnold: I am not sure. I suppose there must be a firewall installed. What the VPS provider did was to move most of the nodes and change the IP addresses, since then I am unable to access my domain.21:27
hallynsmoser: so does experiment show that it works?21:28
sarnoldJoe_knock: was your instance rebooted during the move?21:28
hallynI did notice a 3.12 bug report about setting it to 0 crashing the host, so i'm gun-shy :)21:28
Joe_knockI think so sarnold. I've tried rebooting it myself from the web-based CP21:28
sarnoldhallyn: hahaha21:29
sarnoldhallyn: yeah...21:29
sarnoldJoe_knock: oh, okay, well that means it ought to have had a chance to re-bind to the correct IP on the way back up. perhaps it doesn't automatically restart?21:29
smoserhallyn, i'll let you know in a bit. but i dont think i'll know for sure really.21:30
hallynok - thanks21:30
Joe_knocksarnold, I installed the JDK web-based plugin and now I am in VNC from the web-based JDK tool. Do you know how to reconfigure networking?21:30
smosersince i'm not (by design) heavily affecting the outside-container21:31
sarnoldJoe_knock: ifdown <interface name> ; ifup <interface name>21:31
Joe_knockinterface name?21:32
sarnoldJoe_knock: yeah, whatever your network interface name is .. edit /etc/network/interfaces to make whatever changes you need to make..21:33
Joe_knocksarnold okay I went into cd /etc/network and I see if-down.d and if-up.d21:35
sarnoldJoe_knock: those directories allow you to run scripts when interfaces come up and down21:35
Joe_knockI see interfaces but I can't cd into it for some reason. Would it be a file?21:36
sarnoldyes, it is21:37
Joe_knockSo in order to reconfigure networking I need to run if-down first and then if-up ?21:37
sarnoldJoe_knock: be aware that when you run ifdown, it -means- it. you need to have an ifup command already queued up and ready to execute, or have access to the console via some other mechanism.21:38
Joe_knocksarnold: I am currently accessing via VNC and there is no other way to get in (I tried SSH). Can you tie the 2 commands together?21:39
sarnoldJoe_knock: ifdown foo ; ifup foo21:39
sarnoldJoe_knock: some administrators will put an 'ifup' command in a cronjob or at job just incase..21:39
Joe_knocksarnold, I can't seem to find the interface name. When looking in /etc/network/ the only name I see is "interfaces"21:40
sarnoldJoe_knock: "ip addr" should show you21:40
sarnoldJoe_knock: see "man 5 interfaces" for more information on that configuration file21:40
Joe_knockdamn this is confusing. lol21:42
sarnoldJoe_knock: what are you trying to accomplish? there might be a better way there..21:46
Joe_knocksarnold, according to my VPS, I need to "reconfigure networking". in the web-based CP, it is a single button, but it keeps giving me an error, although the logs say it is complete. So now I am trying to do it from within the server itself.21:47
sarnoldJoe_knock: ah. it might be worth asking your VPS what your "reconfigure networking" is supposed to achieve :)21:48
Joe_knocksarnold: The problem is that they don't communicate very well. I'm pretty much on my own (based on the price I pay).21:49
sarnoldJoe_knock: do you need to do this because they assigned new IPs?21:50
Joe_knockYes, they moved me to a new node and changed my IP address21:51
Joe_knocksarnold: ^21:51
sarnoldJoe_knock: aha. so, you need to change your ip -- and maybe netmask? nameserver? -- in your /etc/network/interfaces file.. then bring the interface down and up and hope it works..21:52
Joe_knockhmmm, I think I will be able to do that sarnold. So it is a 3-step process. Change interfaces file, find interface name and run if-up, if-down.21:53
sarnoldJoe_knock: right21:54
Joe_knocksarnold: I checked interfaces file, all seems okay there. (showing new ip address, gateway, etc.)22:00
sarnoldJoe_knock: nice22:00
Joe_knocksarnold: I left the QEMU window open and hit the "Reconfigure Networking" button to see what it is doing. It looks like it reset the server and logged me out.22:04
sarnoldJoe_knock: hahahahahahaha22:05
sarnoldsigh :)22:05
sarnoldwell22:05
sarnoldso much for being 'gentle' about it..22:05
Joe_knocksarnold, I think it is working almost all the way, but in the end it gives me an error message.22:06
Joe_knocksarnold, well the least I can say from this experience is that it is taking me out of my comfort zone (and I am learning).22:12
Joe_knocksarnold: It suddenly started working now :'D22:34
sarnoldJoe_knock: sweet! yes, it's great to be pushed a little bit from time to time; it's just nice if you get to plan for it when you've got some spare time to work on things..23:37

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!