/srv/irclogs.ubuntu.com/2014/03/24/#ubuntu-server.txt

omfgitsasalmonHai, I'm new to networking and I'm curious about setting up a mail server with my Ubuntu server01:15
omfgitsasalmonCan anyone assist me?01:15
fraqomfgitsasalmon: in the past I have used sendmail as the MTA01:27
fraqwhat exactly are you trying to accomplish?01:27
omfgitsasalmonfraq: my server can't send email using PHP01:42
omfgitsasalmonI tried following tutorials but none of them work. Is it because I'm hosting it on a domestic network?01:42
fraqwhat tutorials have you tried?01:43
fraqbear in mind, I'm no expert at this. I just built a sendmail server as part of a larder experiment01:43
fraq*larger01:43
neild64Your isp could be blocking smtp01:56
=== RaptorJesus_ is now known as RaptorJesus
=== RaptorJesus_ is now known as RaptorJesus
=== RaptorJesus_ is now known as RaptorJesus
=== soren_ is now known as soren
PupenoIs ntpd running enough to have the clock adjusted? I changed the time on a machine to see it in action and I'm not seeing ntp fixing it.10:03
mardraumpastebin ntpq -p10:05
Pupenomardraum: https://gist.github.com/pupeno/973757610:07
rbasakPupeno: IIRC ntpd refuses to change the time by more than a few hours by default in case that breaks things. It also slews the clock slowly; you'll need to wait a day or two to see it come into sync again anyway.10:07
PupenoI just want to make sure it's working since I change it to bind only lo. It shouldn't stop it from working, but just in case. Is there a way for me to do it? I can't find any logs that say "hey! clock is wrong, slowly fixing it." or sosmething like that.10:08
mardraumwhat rbasak says is 100%. Thought from your output you don't seem to be able to reach any ntp servers.10:08
mardraumthough*10:08
mardraumbind only lo why? are you expecting to NAT it out from localhost?10:09
Pupenomardraum: I just don't want ntp to be reachable by anybody (as a server), I'm just running it to keep the clocks synced.10:10
mardraumfirewall it then?10:10
Pupenomardraum: I'll firewall it too, but I prefer to have a close configuration as well for all services.10:11
PupenoSo, apparently I have to bind it to public IPs for it to reach ntp servers.10:12
PupenoWhy is that?10:12
ogra_Pupeno, you could just run ntpdate by a cron job once a day instead ... that saves you from having to run a daemon10:15
mardraumare you expecting to NAT it from localhost?10:15
Pupenomardraum: no.10:15
mardraumthen how could it possibly route to the public internet10:15
Pupenomardraum: I'm not familiar with the NTP protocol, maybe it has some callback mechanism I'm not aware of, but my server doesn't need to bind 0.0.0.0:25 in order for it to open connections to port 25 in other servers and deliver email. I was expecting ntpd to open connections to my time servers without having to bind and listen in port 123.10:18
mardraumI'm not having a go at you. At least you didn't claim you hadn't made any changes and then fess up an hour later you made it only run on lo10:18
PupenoI'm fine with ntp using other interfaces, I just don't want it to listen on them. The same way postfix is not listening on eth0, but it's using it to reach the Intenet.10:19
mardraumyou run a MTA on localhost only that works fine sending and receiving mail?10:19
mardraumto internet hosts10:19
Pupenomardraum: there's an MTA running listening only on 127.0.0.0:25 that routes email to the internet, yes.10:20
PupenoI meant lo, port 25.10:20
mardraumcool, you must have some translation happening10:21
Pupenomardraum: nope.10:21
mardraumperhaps NTP just refuses to work like that. I've never tried10:21
mardraumnope?10:21
mardraumpastebin some mail logs10:21
Pupenomardraum: you don't need to listen on port 80 to connect to port 80. My browser doesn't listen on port 80 and connects to port 80 of any server out there.10:22
mardraumI never suggested that it did?10:22
mardraumbrowser will always use a high port anyway, but we are off topic10:22
PupenoWell, so does postfix.10:23
mardraumyour 127 address is not valid on the internet. If it can send email to an internet host, something is translating the address.10:23
PupenoBut also, they open the port to connect, not to listen, which is different.10:23
Pupenomardraum: no, nobody is doing NAT. You don't need to do NAT. Program X talks to postifx on 127.0.0.1:25, postfix stores the email, then opens a random high port to connect to whatever:25 and delivers said email.10:24
mardrauma random high port on an interface it doesn't listen on?10:25
Pupenomardraum: yes.10:25
PupenoThat's how TCP/IP works.10:25
mardraumTCP/IP specifies interfaces now?10:25
mardraumyour postfix config would allow this to happen.10:26
Pupenomardraum: no, TCP/IP specifies that you open a local port on a local IP to connect to a remote IP on a remote port.10:26
mardraumwhy you expect ntp to work the same I don't really know10:26
Pupenomardraum: because that's how most tcp/ip clients work.10:27
mardraumguess you found the only one in the world that doesn't then?10:27
Pupenomardraum: well, I have no proof one way or another, I will not just assume that I found an exception only because something I expected didn't happen. I need more information.10:28
rbasaklamont: any news on bug 1288823 please?10:56
uvirtbotLaunchpad bug 1288823 in bind9 "Trusty bind9 RRL " [High,Triaged] https://launchpad.net/bugs/128882310:56
lamontrbasak: let me get that uploaded12:42
rbasaklamont: thanks!12:45
zuljamespage:  when you get a chance https://code.launchpad.net/~zulcss/nova/2013.1.5/+merge/21221412:59
zuljamespage:  fixed13:09
=== cmagina-away is now known as cmagina
=== Haven|Weekend is now known as Havenstance
jamespagezul, +113:12
zuljamespage:  thanks13:13
zuljamespage:  ill double check the changelogs and start uploading in a couple of minutes13:13
zuljamespage:  forgot one from friday https://code.launchpad.net/~zulcss/neutron/2013.1.5/+merge/21222613:14
jamespagezul, double space in changelog13:14
zuljamespage:  fixed13:15
jamespagezul, +113:15
jamespagezul, we need to ditch the distro tasks on https://bugs.launchpad.net/nova/+bug/129567413:17
uvirtbotLaunchpad bug 1295674 in nova "Meta bug for tracking Openstack 2013.1.5 Stable Update" [Undecided,New]13:17
jamespageand just have one for Cloud-Archive13:18
=== cmagina is now known as cmagina-away
=== cmagina-away is now known as cmagina
zulcoreycb: lemme know when you are done13:31
coreycbzul,  wil do13:31
coreycbzul, jamespage: https://code.launchpad.net/~corey.bryant/cinder/2013.1.5/+merge/21221713:37
zulcoreycb: -113:39
coreycbzul, should I drop all the "pin" change logs?13:41
coreycbzul, for glance and horizon13:41
zulcoreycb: the non user facing ones so like sphinx yes13:41
coreycbzul, ok13:42
coreycbzul, I also noticed the logs are in reverse order vs the tracking branches in case that makes a difference13:43
zulcoreycb: ye13:43
coreycbzul, cinder is ready for re-review13:57
zulack13:58
zulCorey:  +1 from me13:59
=== caribou_ is now known as caribou
=== RoyK is now known as RoyK^_^
coreycbzul, thanks  jamespage ^14:02
coreycbzul, jamespage: glance https://code.launchpad.net/~corey.bryant/glance/2013.1.5/+merge/21242314:02
zulcoreycb: i thought we were going to skip glance14:03
jamespagecoreycb, skip it14:03
jamespagethe upstream changes are nullified by my patch14:03
coreycbzul, jamespage: that's right, forgot about that14:03
jamespagecoreycb, hey - np :)14:03
coreycb:)14:03
coreycbzul, jamespage : horizon https://code.launchpad.net/~corey.bryant/horizon/2013.1.5/+merge/21222514:08
jamespagecoreycb, I think the final commit is e6a4653 not b14debc14:14
coreycbjamespage, ok that is probably the similar case for cinder too14:15
coreycbzul: ^14:16
zulcoreycb: arrgh14:17
coreycbzul, jamespage : I pushed horizon again14:18
zulcoreycb: ill fix up cinder14:19
coreycbzul, I'm ready to push if it's easier14:19
zulcoreycb: sure14:19
coreycbzul: pushed14:19
zulcoreycb: thanks14:21
coreycbjamespage, when you get a second: https://code.launchpad.net/~corey.bryant/charm-helpers/1294140/+merge/21243014:28
jamespagecoreycb, commented14:36
=== mist__ is now known as mist
jamespagesmb, I'm going to propose we backport the current iscsitarget to 12.04,12.10 and 13.1014:40
jamespageso we don't have todo this again for the 3.13 kernel14:40
coreycbjamespage, thanks, responded14:41
smbjamespage, Guess that works for me. So I could close my tracking bug and you can drive the other. If you have a bug number I can refer to in my report, just let me know.14:42
jamespagesmb, lets just do it under bug 126271214:43
uvirtbotLaunchpad bug 1262712 in iscsitarget "[SRU] Backport iscsitarget 1.4.20.3+svn490 into Precise" [High,Triaged] https://launchpad.net/bugs/126271214:43
smbjamespage, NAK, that is just plain confusing14:44
jamespagesmb, why?14:44
smbjamespage, The current iscsitarget for me is 1.4.20.3+svn499-0ubuntu1 orin at least 496. This is not what the original tracking bug was for. And then we got some stuff in the comments from the old request and some from the new one14:46
jamespagesmb, ?14:49
jamespageI'm a bit confused14:49
jamespagethe original bug for for +490 - upstream trunk (as I just uploaded to 14.04) is only 9 commits on from that14:50
=== roaksoax_ is now known as roaksoax
smbThe tracking bug was opened to push the S version of it into older releases. Now you want to push the T version. It may only be a few commits but it is a different version and to be honest for me that is a new request.14:51
zuljamespage/coreycb: cinder and horizon uploaed14:58
coreycbzul, thanks14:58
zuljamespage:  https://code.launchpad.net/~zulcss/keystone/2013.1.5/+merge/21223215:13
zuljamespage:  im dealing with kazoo right now15:42
=== cmagina is now known as cmagina-away
raj__Is plymouth  anyway useful on server ? i see several plymouth entries in the processes listing ..15:51
jamespagezul, ack15:56
jamespagezul, niggle on the keystone MP - other than that +115:57
=== cmagina-away is now known as cmagina
rbasakraj__: http://web.dodds.net/~vorlon/wiki/blog/Plymouth_is_not_a_bootsplash/ provides a good explanation of why plymouth is also useful for server.16:00
=== rcj` is now known as rcj
railsraiderHi im trying to make upstart pre-stop stanza to sleep for x seconds before sending the sigkill but it seems that upstart doesnt accept it and kill imiddiately16:17
railsraiderhttp://pastebin.com/2ruUqdav16:17
railsraiderany idea how to wait before upstart do sigkill16:18
zuljamespage:  fixed16:18
jodhrailsraider: 'kill timeout SECONDS' - see init(5).16:21
railsraideri tried that16:21
jamespagezul, +116:24
zuljamespage:  well need the new oslo.rootwrap as well (#1081795)16:25
rbasakrailsraider: looks like your problem is "exec". What's inside a "... script" stanza in an upstart job is just normal shell.16:26
railsraiderseems like upstart ignores my sleep command and the kill timeout is how long to wait after sigterm to send sigkill16:26
rbasakrailsraider: in shell, lines after a successful "exec" will never execute.16:26
rbasakrailsraider: I don't know why you had "exec" there, in the first place, but try dropping it.16:27
railsraiderrbasak: i have to make sure the processes exit gracefully how would i achive that16:27
railsraiderthanks im trying that now16:28
railsraiderrbasak: thanks so much worked on this all day i simply copy pasted the line from the script section16:31
railsraiderit works now16:31
=== mjohnson15_2 is now known as mjohnson15
=== cmagina is now known as cmagina-away
=== NomadJim_ is now known as NomadJim
=== cmagina-away is now known as cmagina
jamespagehallyn, seeing some lxc oddness in the OpenStack CI lab - "lxc-start: command get_cgroup failed to receive response"17:12
jamespagethat's coming from lxc machines that juju is trying to start on one of the servers17:12
hallynjamespage: do you have any more info from syslog, auth.log, or a container.log?17:14
jamespagehallyn, syslog, auth.log - nothing17:16
jamespagewhere do I find container.log?17:16
vlad_starkovQUESTION (cross-post): Can't boot on freshly installed 12.04.4 64bit. Got multiple CPU soft lockup messages. Could someone point me how to boot in verbose/debug mode to figure out what's going on?17:19
rbasak!crosspost|vlad_starkov17:21
ubottuvlad_starkov: Please don't ask the same question in multiple Ubuntu channels at the same time. Many helpers are in more than one channel and it's not fair to them or the other people seeking support.17:21
vlad_starkovrbasak: Yep. For that I market question as "cross-post"17:23
hallynjamespage: you can check /var/log/lxc/ ..  it depends where juju is directing it to put them17:24
hallynjamespage: can you try createing and starting a contaienr by hand, see if htat fails too?17:24
jamespagehallyn, http://paste.ubuntu.com/7147289/17:25
hallynjamespage: oh, i think that's a knwon bug in apparmor today.  tyhicks was assigned one17:27
jamespagehallyn, OK  - so long as someone knows :-)17:27
hallynprobably bug 129645917:27
uvirtbotLaunchpad bug 1296459 in apparmor "Upgrade from 2.8.0-0ubuntu38 to 2.8.95~2430-0ubuntu2 breaks LXC containers" [Critical,New] https://launchpad.net/bugs/129645917:27
jamespagehallyn, that is latest everything17:27
hallynjamespage: yeah try downgrading apparmor17:27
jdstrandhallyn, jamespage: fyi, tyhicks is assigned and knows the cause. he is working on a fix now17:31
jamespageack17:31
hallyncool, thx17:32
hazmatdo nested containers need trusty kernel?17:51
lutostaghazmat: you can do nested lxcs pre-trusty with root17:53
lutostagjust add lxc.aa_profile = lxc-container-default-with-nesting to your /var/lib/lxc/<top-level container name>/config17:57
hazmatlutostag, thank you17:58
lutostaghazmat: np :)18:01
zulhallyn/smb: libvirt xl fails to start because there wasnt a /var/log/libvirt/libxl/libxl-driver.log btw18:22
hallynzul: meaning if the .log file doesn't exist, libvirt xl won't start?  it opens without O_CREAT ?18:37
zulhallyn:  yeah the directory is missing from the libvirt-bin.dirs18:48
hallynzul: pushing a new package to fix that?19:03
zulhallyn:  yeah19:04
zulhallyn:  do you have anything else?19:04
zulsmb: do you have any documentation on libvirt and xl?19:10
hallynzul: oh, sorry, no i don't19:17
zulhallyn:  ack19:17
zulhallyn:  ok uploaded19:18
adarhi. do you know anyone know a good tutorial about security nginx ??19:39
=== Ursinha is now known as Ursinha-afk
=== Ursinha-afk is now known as Ursinha
=== FreezingAlt is now known as FreezingCold
=== cmagina is now known as cmagina-away
=== cmagina-away is now known as cmagina
sarnoldhallyn: congratulations on core-dev :)22:07
=== ajmitch_ is now known as ajmitch
thumperhallyn: when I run 'lxc-start', does that immediately put the container into STARTING mode?22:09
thumperI have an "lxc-wait -n ubuntu-local-machine-1 -s RUNNING|STOPPED" running after the lxc-start and it returns immediately22:11
thumperand lxc-info says stopped22:11
thumperbut 8s later, it is started22:11
Valduarehi all22:22
=== cmagina is now known as cmagina-away
=== cmagina-away is now known as cmagina
Valduarewhats the word on using these arm devices for bare metal servers in maas22:39
sarnoldValduare: I'd say "no" to pandaboards, my personal pandaboard hangs often; they fell over often when we used them for builders, too22:42
sarnoldValduare: I hope you're talking about real servers though :) I suspect they'd be quite a lot nicer.22:43
ValduareI havnt used a panda board myself22:43
ValduareI have a few mk808 devices that have been real solid22:43
Valduarebut these mk902 have rj45 and quad core22:44
Valduaresarnold: anyways just wondering if I can get them under maas to play with22:45
sarnoldValduare: try asking in #maas -- the little I've played with it, it looks pretty flexible, if you can figure some way to remotely power them on and off..22:46
Valduarehalf a watt idle, they could stay on :P22:47
sarnoldniiiiice22:47
=== cmagina is now known as cmagina-away
hallynthumper: yes, lxc calls it started when init has started23:15
hallynthumper: you're probably interested in bug 1266808.23:16
uvirtbotLaunchpad bug 1266808 in lxc "No mechanism to wait until a started container is ready and has finished booting" [Wishlist,Triaged] https://launchpad.net/bugs/126680823:16
blottofaceI did an aptitude install mediawiki and uncommented out the Alias line in /etc/mediawiki/apache.conf.  Then I did a a2enconf mediawiki.  Then I restarted apache2 services.  It complains about permissions when I try and visit the site.  :(  The www-data user and group has read permissions.  The error in the log says "client denied by server configuration"23:44
Valduare#maas is dead channel tonight..23:46
RallyballMy pc won't read my flashdrives but the system will recognize it, anybody know why?23:48
sarnoldblottoface: that could be the server configured to deny or not allow based on IP address, or any other number of reasons.. it'd be nice if it could tell you -why- it was denied...23:50
sarnoldRallyball: perhaps they are formatted with a filesystem your kernel can't read?23:51
RallyballYes, that's probably it, thanks.23:51
RallyballDo most flashdrives load a default file system depending on the OS?23:52
RallyballOr is there something I have to do to load them from the pc?23:52
RallyballIn other words, are most flash drives compatible with Linux?23:53
sarnoldRallyball: most flash drives come formatted with vfat, because it is the only filesystem that mac os x and windows have in common23:53
sarnold(vfat more or less equals fat32..)23:54
RallyballThat makes sense.23:54
RallyballHow do I format it to accept linux files?23:54
sarnoldRallyball: mke2fs on the /dev/whatever block file23:54
RallyballOk, thanks.23:55
sarnoldRallyball: if it is partitioned you may wish to change the filesystem type tag in the partition table using fdisk or gdisk23:55
RallyballYes but I will need to dump the data first.23:56

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!