/srv/irclogs.ubuntu.com/2014/06/23/#ubuntu-server.txt

Patrickdkyou can't do ftp via ssh00:00
Patrickdkyou can use sftp though00:00
whitepowderi'm trying to put together a recovery usb stick. It has 2 partitions (fat16 2gb and btrfs 14gb) I've got syslinux, freedos, grub4dos, and my preseed configs on it. I need to be able to install 12.04.4 from this, configured pretty much entirely automatically. I'd like to keep the preseed in the fat16 part, so it can be changed from a windows box if needed00:26
=== whitepow1er is now known as whitepowder
gambolguys, anyone know if there's some app/package will enable ip_forward by default?  I have a 14.04, seeing the ip_forward is 1 but I believe I never changed it manually.03:49
PryMar56gambol, check the mod time on /etc/sysctl.conf03:58
PryMar56gambol, do you see ip_forward setting here `sysctl -p` ?03:59
PryMar56gambol, maybe a kernel param?04:13
gambolThanks PryMar56 . Sorry I can't ssh the host atm.04:27
gambol`sysctl -a` will show the params04:28
gambolit is a standard 14.04 installation, with I followed the offical docs to build a kickstart server04:28
gambolso packages newly installed is tftp stuff only I think04:29
gamboloh and bind ,and dhcp04:30
gambolnothing touched for iptables or network details04:30
mnaserI have a server that seems to be stuck in the installation process (PXE boot).  How can I get a shell to look at why it is currently stuck?05:21
gambolmnaser, i guess Alt F405:52
mnaserctrl+alt+f2 worked05:52
gambolI am new to ubuntu 205:53
abhie2ehi06:56
AlisonChaikenGreetings from Hildesheim, Germany.    I need what I'm sure is a Frequently Answered Answer.06:57
abhie2ei installed ubuntu server in virtualbox vm, and connected bridged wlan0 to host. still no network in vm. help06:57
AlisonChaikenI have Ubuntu 12.04.    I type "do-release-upgrade", am told that there are no new releases!06:57
abhie2eping gmail gives unknown host06:57
AlisonChaikenAnd I tried "sudo apt-get dist-upgrade," nothing happens.06:57
AlisonChaikenWhat am I missing?06:58
AlisonChaikenabhie2e, what do you see if you type "ip addr list" in both host and VM?06:58
AlisonChaikenDoes your VM have an IP?   Are you using NetworkManager?06:58
abhie2eAlisonChaiken, host is connected to internet. thats how i am here in irc. ubuntu server vm gives lo and eth0 for ip addr list06:59
abhie2eboth do not have ip06:59
AlisonChaikenI don't follow you abhie2e.    If host doesn't have an internet connection, how would the VM?07:00
AlisonChaiken"ip addr list" is a command.   You type it at shell prompt to see what connections are up.07:00
abhie2eAlisonChaiken, both lo and etho in vm do not have ip. host have internet. thats why i am talking to you.07:00
abhie2evia irc07:00
AlisonChaikenSo eth0 is listed by "ip addr list" in VM, but there's no IPv4 address?07:01
AlisonChaikenTry "man brctl"    I recall you want to use brctl.07:01
abhie2eok07:02
abhie2eno manual entry brctl07:03
AlisonChaikenabhie2e you must need to install whatever package brctl is in.   Doing so will make life easier.07:05
abhie2eok07:05
AlisonChaikenMeanwhile I see that "do-release-upgrade -d" gets trusty even though it's not a development release.07:05
w\laiteAlisonChaiken: If I recall correctly, LTS upgrade is available only after 14.04.107:10
w\laite12.04 -> 14.04, that is07:10
AlisonChaikenAh, I see w\laite.   That explains it.07:10
AlisonChaikenWell, I'll get 14.04.1 when that comes along.07:11
AlisonChaikenI don't care that much about LTS, and I need the new binutils now!07:11
AlisonChaikenThx for the explanation.    The commands' error message is a bit unhelpful in that regard.07:11
w\laiteyeah, np07:11
fedcabHello, I just set up a ubuntu server. I can get a remote console via ssh but the local console doesn't appear although the getty processes show up in the process list. Where can I look for help?08:34
=== drupal212312 is now known as killdee
=== drupal212312 is now known as killdee
=== Solution-X is now known as Solution-X|AFK
pmatulismorning11:15
histo*yawn*11:47
=== FRA|kaitanya is now known as NED|kaitanya
zuljamespage:  keystone needs oslo.db now12:49
jamespagezul, that's good12:51
zuljamespage:  meh12:51
jamespagezul, the nova.conf we ship with needs a tidy - its has at least 4 removed configuration options :-)13:11
zuljamespage:  um?13:11
jamespagezul, http://paste.ubuntu.com/7690330/13:11
jamespagezul, I just merged that tidy into the charms13:12
zuljamespage:  ok ill get rid of it for power13:12
jamespagezul, no - that's in the debian/nova.conf as well13:12
jamespagezul,  inthe packaging13:12
zuljamespage:  k gimme a sec13:13
jamespagezul, its non-urgent13:13
zuljamespage:  im just cleaning up the packaging today13:13
zuljamespage:  everything must be blue! ;)13:14
tom[]does 14.04 by default scan /etc/network/interfaces.d or must i add 'source /etc/network/interfaces.d/*' to /etc/network/interfaces?13:42
nanderssonHi, Samba 4.1.9, a security-release just got released. Will that version flow into Trusty? (I am also interested in getting at least samba 4.1.8 because that version contains a fix that makes it possible to use realmd to join a Samba AD DC)13:46
nandersson...currently Trusty is on samba 4.1.6, and in Trusty-proposed for Ubuntu 14.04.1 I still see samba 4.1.6...13:47
rbasaknandersson: security fixes are usually backported. After a security update, you're likely to see the same base upstream version since only the relevant security patches will be applied.14:10
rbasakI don't see any seucirty updates for samba in Trusty right now. If you want to track one and a bug doesn't already exist, then please file one and mention the CVE.14:10
mdeslaurnandersson: I can confirm we won't be updating to 4.1.9, we'll be backporting the actual security fix14:12
nanderssonrbasak, mdeslaur Ok! Thanks a lot!14:22
zoraj_Hi all14:53
zoraj_I'm installing ubuntu server 14.04 on Dell PowerEdge14:55
zoraj_but I am unable to install the grub on MBR, there is an error, Unable to install Grub in /dev/sda14:55
zoraj_this is a fatal error14:55
zoraj_any clue ?14:55
=== niemeyer_ is now known as niemeyer
ashdhi all. i need to drop back to php5.4 from php5.5 on a 14.04 LTS new install - due to an ioncube ecoded set of php files.  brand new server - not running anything so can remove and re-install whatever is needed.. annoyed as i did not notice the requirements and cannot find out how to drop back a version15:26
pmatulisashd: will 5.3 do?  if so, consider installing Ubuntu 12.0415:28
ashdpmatulis: yes, realise that - just installed a fresh 14.04 LTS - know i can get it by re-installing 12.x15:33
pmatulisashd: otherwise, you can *try* removing php5, enabling the quantal repo, and installing php5.415:36
ashdpmatulis: that could be a way forward…15:36
pmatulisashd: hm, dunno if quantal stuff is still available, it's EOL15:37
pmatulisashd: anyway, it's a dubious way forward and could lead to problems later15:37
ashdpmatulis: think i will put that machine on hold and create another VM with 12.x - it will save time15:39
ashdback...15:41
nanderssonHi, does anybody know when we can expect vagrant cloud-images for Utopic? I.e here https://cloud-images.ubuntu.com/vagrant/ After release or during alpha-stage?15:44
jiffe98anyone running apache-mpm-itk on 14.04 successfully?  We're running it on 12.04 but in 14.04 with the same config it seems like it is trying to access the .htaccess file with the wrong user16:31
dannfjamespage, are you good w/ sponsoring the SRU for LP: #1320327? /me needs to make sure that gets in for 14.04.1 for new hw support16:32
jamespagebug 132032716:34
uvirtbotLaunchpad bug 1320327 in finish-install "configure getty properly on serial consoles using hardware flow control" [High,In progress] https://launchpad.net/bugs/132032716:34
jamespagedannf, already did - https://launchpad.net/ubuntu/trusty/+queue?queue_state=1&queue_text=16:35
jamespageits not been accepted by the SRU team yet16:35
dannfjamespage: ah, ok, thanks! i just confsued sponsoring w/ sru approving. many thanks! i'll go poke elsehwere16:36
jamespagedannf, np :-)16:36
jiffe98it must be trying to access the .htaccess file as www-data because if I change ownership to that and chmod 700 the directory it still works16:42
jiffe98this worked fine in 12.04, why do people have to go breaking things16:46
tom[]can the 14.04 installer write a preseed file?17:08
zorajHi,18:08
zorajI've just finished installing Ubuntu Server, I also installed OpenSSH server18:09
=== Lcawte is now known as Lcawte|Away
zorajwhen doing 'ssh localhost' it's ok but from other machine when doing something like ssh 192.168.1.2, I got a connection refused18:10
zorajdid I miss something ?18:10
RoyKzoraj: can you ping to/from the machine? did you setup ufw?18:11
sarnoldzoraj: there's lots of ways a connection can be refused; first, check netstat -tlp | grep :22 to see what interfaces sshd is listening on18:11
sarnoldzoraj: check firewalls on both machines as well as any firewalls that might be between the two18:12
zorajRoyK, from the server I can ping to my laptop, and vice versa, and what is ufw ?18:13
RoyK!ufw | zoraj18:13
ubottuzoraj: Ubuntu, like any other Linux distribution, has built-in firewall capabilities. The firewall is managed using the 'ufw' command - see https://help.ubuntu.com/community/UFW | GUI frontends such as Gufw also exist. | An alternative to ufw is the 'iptables' command - See https://help.ubuntu.com/community/IptablesHowTo18:13
zorajsarnold, netstat is not installed but sshd is listening on 2218:14
sarnoldzoraj: with which local addresses?18:15
RoyKzoraj: netstat is part of net-tools, which should be installed by default18:16
zorajsarnold, the server id address18:17
zorajRoyK, ok thx gonna check it out18:17
zorajip* address18:17
zorajI'm just editing /etc/ssh/sshd_config if I cound find out somthing to change, so I can be able to connect remotely to the server18:20
RoyKzoraj: the default config should be ok18:22
zorajdamn ! I had to put the option -l login18:24
zorajI just did ssh ip_address18:24
zorajand it asked me the login then the password18:25
RoyKzoraj: ssh username@host18:25
RoyKzoraj: that works too ;)18:25
zorajRoyK, oh yeah ! you rock18:26
zorajthanks guys18:26
zorajnext step, setting up the ftp server :P18:26
RoyKwhy ftp?18:27
RoyKftp is a rather old and crappy protocol to which there are lots of alternatives :P18:27
zorajRoyK, I will have to copy things from my laptop to the server, like sql file to run in mysql client18:27
patdk-wkftp is broken since the invention of nat18:27
RoyKsftp? rsync over ssh? webdav?18:28
patdk-wkand you want to send your password in plain text over that internet?18:28
zorajhmm... any suggestion18:28
zoraj?18:28
RoyKzoraj: what're you running on the laptop?18:28
RoyKzoraj: if on windows, use filezilla with sftp (ftp over ssh)18:28
RoyKzoraj: if on linux, there are several other choices18:28
zorajRoyK, Im using a mac18:28
sarnoldzoraj: sftp is thousand times better18:28
zorajok gonna check that out18:29
RoyKzoraj: then AFP or Samba or something is probably the easiest18:29
sarnoldzoraj: mac has sftp built-in, probably the "transfer" program can do sftp too if you want gui :)18:29
RoyKsarnold: filezilla works well on mac18:29
zorajbut I need a sftp daemon running on the server side right ?18:29
sarnoldzoraj: ah, transmit rather :)  http://panic.com/transmit/18:29
sarnoldzoraj: sshd provides one already.18:29
=== TDog_ is now known as TDog
zorajreally ?18:30
zorajlet me check that out guys18:30
zorajI'm installing things on a Dell PowerEdge18:30
zorajto make it as a server18:30
RoyKwebdav is supported by Finder in the first place18:31
RoyKso if you setup apache or whatever with webdav, it just works18:31
zorajRoyk, well, it wont be only me that will connect to the server, client that using Windows may use it too to transfer files18:31
RoyKzoraj: then use samba18:32
zorajsince, sshd is up and running, I'm gonna test filezilla to connect to it18:32
RoyKzoraj: it's not hard to setup, and both os x and windows will connect to it as though it were a windows server18:32
sarnoldI wouldn't want to use samba over the open internet18:32
RoyKsarnold: neither would I18:32
sarnoldsamba over a LAN is fine or within a VPN is fine..18:33
RoyKSMB[23] are quite good over slow links too18:33
sarnoldzoraj: winscp can also do sftpd.18:33
RoyKsarnold: better use filezilla - better UI18:33
sarnolds/sftpd/sftp/18:33
sarnoldRoyK: .. and the same ui on all platforms. nice. I've never used it before..18:34
RoyK:)18:35
=== TDog_ is now known as TDog
zorajit works guys :) I didn't know that having sshd running, you could transfer files to it18:36
RoyKzoraj: you can tunnel a *lot* of stuff over ssh18:36
zorajRoyK, okey18:36
RoyKsetup a squid proxy and let a friend, currently in vietnam, to create an ssh tunnel to the box and use localhost as her proxy - suddenly she could reach things like facebook :P18:37
zorajthey blocked facebook in Vietnam ?18:38
RoyKzoraj: apparently, yes18:42
RoyKzoraj: nothing formal, just informal blocking :P18:42
zorajah ok18:43
RoyKzoraj: and then - she'd better use IRC from a box/vm in Norway than using the local network from there18:43
=== NomadJim_ is now known as NomadJim
zorajRoyK, I will probable take a look at setting up proxy next time, my next step is currently setting up Ruby and RoR because I will have to install Redmine that requires them18:45
RoyKzoraj: shouldn't be too hard. a proxy isn't necessary unless you need it for some reason18:46
zorajokey18:48
zorajto install web app like phpMyAdmin, redmine, where is the best way to put it out ?19:13
PiciCan you rephrase that question?19:14
RoyKzoraj: apt-get install phpmyadmin # ?19:15
zorajPici, well, I've just downloaded phpmyadmin code source so I can install it on my server as a mysql client19:16
Picizoraj: Do you have a good reason for doing that instead of installing the package that is in our repositories?19:16
zorajPici, I didn't know I could install it from the repo, I'm a beginner19:17
Picizoraj: You should assume that everything is in the repositories first. :)19:17
zorajPici,:) hopefully Redmine WebApp is also there because having to follow all of these instruction (http://www.redmine.org/projects/redmine/wiki/HowTo_Install_Redmine_on_Ubuntu_step_by_step) to make it work,19:19
Pici!info redmine19:19
ubotturedmine (source: redmine): flexible project management web application. In component universe, is extra. Version 2.4.2-1 (trusty), package size 4434 kB, installed size 13445 kB19:19
zorajlet me check that out guys, anyway thanks19:20
PiciI'm not sure how up-to-date that is though... mysqladmin should work fine though.19:20
zoraj!info redmine19:20
ubotturedmine (source: redmine): flexible project management web application. In component universe, is extra. Version 2.4.2-1 (trusty), package size 4434 kB, installed size 13445 kB19:20
zoraj^^ looks like I am an irc beginner too19:20
=== TDog_ is now known as TDog
zorajsound like I messed up with /etc/resolv.conf. this link (http://www.howtogeek.com/howto/ubuntu/change-ubuntu-server-from-dhcp-to-a-static-ip-address/) suggests me to change this file to set up the dns server19:57
zorajI rebooted the server and the file is now empty,19:58
zorajso I couldn't resolve any website address name19:58
zorajhow I could regenerate the old setting ?19:59
zorajwithin this file19:59
zorajit warns me that ANY CHANGE WILL BE OVERWRITTEN20:00
lordievaderzoraj: /etc/resolv.conf is dynamicly generated. The config files are in /etc/resolvconf/.20:03
zoraj:q20:05
zorajoups :P20:05
zorajlordievader, ok20:05
lordievaderdynamicly*20:05
lordievaderdynamically* pff...20:05
zorajlordievader, I'm browsing the directory, but I didn't find which one is the the file to modify20:06
lordievaderzoraj: I usually put my changes in /etc/resolvconf/resolv.conf.d/head20:07
zorajthere is a text on the header of this file that YOUR CHANGES WILL BE OVERWRITTEN20:08
lordievaderzoraj: Correct, that is where the message in /etc/resolv.conf comes from ;)20:09
zorajlordievader, so where I supposed to put the dns server address ?20:09
geniiAlternately, add something like dns-nameservers 8.8.8.8 8.8.4.4       to /etc/network/interfaces and then resolvconf will act accordingly and use that20:10
lordievader^ that is another approach.20:10
genii( to the stanza for the adapter you want to use those dns, like eth0 or so on)20:10
zorajgenii, ok, let me do that and will back to you20:11
zorajgenii, it works like a charm :) thanks, I needed to restart the server to get it work though, the 'sudo /etc/init.d/networking restart' was useless20:19
geniizoraj: Better to use sudo service networking restart     .....but anyhow, glad to assist20:20
zorajgenii, ok thanks for your time guys20:22
bluefrog'lo, my server is ipv6 only, if the website I want to reach (from that server) only has ipv4 then I'm screwed, correct?20:22
geniibluefrog: As I understand, you can use nat64/tayga for this, but I am not familiar with it's configuring.20:30
bluefrogto be honest with you i have no idea, set up a ubuntu server on an internet provider (gandi) with ipv6 only. no big deal, i will ask some network friends of mine20:32
bluefrogbut i think i'm screwed. don't see why there would be some "reverse" ipv6 to ipv420:33
genii!info tayga20:33
ubottutayga (source: tayga): userspace stateless NAT64. In component universe, is optional. Version 0.9.2-6 (trusty), package size 34 kB, installed size 119 kB (Only available for linux-any)20:33
geniiMeh, not much info there.20:34
bluefrogthat's ok gonna have a read about that20:34
maswanbluefrog: in the general case you are screwed. there are ipv6<->ipv4 nat-like translators, but those require a gateway that has both. you could also imagine using a dual-stacked http proxy to acces v4-only from a v6-only machine, etc.20:34
bluefroggenii thx. gonna read http://www.bitprocessor.be/2011/05/31/setting-up-nat64-dns64/20:35
bluefrogmaswan, thx.  I like to move forward generally so will have a quick look but won't waste too much time on it. thx for the answers20:36
bluefrogipv6 is the future. ipv4 is dead except that most peeps don't accept that fact.20:36
TJ-bluefrog: how about https://www.sixxs.net/tools/gateway/20:36
bluefrogTJ-, cheers will read as well20:37
maswanat least I'm at the point where most of the services I run are dual-stacked, except for some that have a very limited community20:37
bluefrogcool20:38
maswan(se.archive.u.c is most relevant here, I guess)20:38
maswan17% of requests came in over ipv6 the last 7 days20:39
bluefrognice number20:39
maswanthat's mostly running ubuntu system hitting dists etc for apt-get update20:40
maswanin bytes it is 4.4%, and that's mostly debian cd downloads20:40
maswanhuh, 75% of downloaded bytes is debian cd, 75% of hits is ubuntu/dists20:41
bluefrogi like what TJ- page says :) "When they get enough hits they might be hinted that IPv6 use is rising and maybe we can pursuade them this way to start making their websites natively IPv6 accessible. "20:42
shodan45is there a reason that the /initrd.img symlink uses an absolute path?20:50
TJ-shodan45: on what release, which kernel?20:52
shodan45TJ-: 12.04 "mythbuntu" install, 3.8.0-31-generic20:54
shodan45but I'm testing with a plain 12.04 server install inside a vm20:55
shodan45oh heh, the goal here is to pxe boot :)20:55
TJ-shodan45: I don't have a 12.04 bare VM install to hand, but here with 14.04 the links aren't absolute20:55
shodan45TJ-: hm, interesting20:55
TJ-shodan45: "initrd.img -> boot/initrd.img-3.13.0-29-generic"20:55
shodan45I wouldn't mind upgrading to 14.04, except that this is an "appliance" type box, and it works 100% as-is20:56
shodan45TJ-: any idea where that symlink gets created?20:57
tgm4883shodan45: which is 100% what I would recommend as well :)20:57
TJ-shodan45: Via update-initramfs I'd suspect20:57
tgm4883shodan45: I can check my 12.04 box if you just tell me what I'm looking for (installing a sophos email appliance right now)20:57
shodan45or, alternately, is there another symlink pointing to the "current" kernel & initrd?20:58
shodan45tgm4883: I'm not really "looking" for anything - I'm trying to create a symlink to the current kernel, but the whole FS is going to be NFS mounted21:00
tgm4883Yea we really haven't had any good instructions/tools since laga left the project21:01
tgm4883*for pxe bootin21:01
TJ-shodan45: Not sure quite what you're requiring to do, but I wrote an article and support scripts for auto-config of PXE boot server @ http://tjworld.net/wiki/Linux/Ubuntu/NetbootPxeLiveCDMultipleReleases21:03
shodan45TJ-: I'm worried that when a kernel or initrd update happens (while pxe/tftp/nfs booted), the pxelinux config will be pointing at the wrong files21:05
shodan45TJ-: make sense? or need more details? :)21:05
TJ-shodan45: Yes, I can see what you're getting at... you need to manage that on the NFS server. a cron job, or a startup-script with inotify that checks the exported directory links would be my solution.21:07
shodan45TJ-: ahh I think I see what you mean... make a script that runs on shutdown that "fixes" the symlink21:11
TJ-shodan45: Well, that, or if the rootfs on NFS has been changed, update the pxeconfig itself to point to the updated kernel/initrd pair21:12
shodan45true21:12
shodan45hmm21:12
TJ-shodan45: You could unconditionally update the PXE config using inotify watches, so that any new boot after the update uses the updated kernel/initrd pair. Are multiple systems sharing the rootfs? Is it read-only for some or all clients? There are several issues to consider in doing it.21:14
=== Lcawte|Away is now known as Lcawte
shodan45TJ-: nah, single NFS client... I'm just trying to stop using a cheap USB stick to run the OS :)21:19
TJ-ahhh :)21:19
shodan45I've done it before, and they inevitably die21:20
shodan45and I have a nice 3TB raid array with gig-e network, so.... :)21:20
Randy_OAnyone have any experience repairing server ports? I have a server that can't connect or be connected to over port 80. I have apache2 running and had an http proxy running, removing the proxy broke the server.21:48
maswannetstat or lsof can tell you what process is listening on a particular port21:49
Randy_OI've got that, it says it's just apache2 but I cant apt-get or wget, but I can ping any host.21:50
shodan45Randy_O: sounds like a firewall... why did you get rid of the proxy?21:50
Randy_Oshodan45, the firewall is completely disable at this time, and I got rid of the proxy because it was for a local network at home but I don'21:51
Randy_Odon't need anymore21:51
shodan45can you connect to apache over localhost?21:52
shodan45aka telnet localhost 8021:52
sarnoldRandy_O: iptables -n -L  shows you no rules that get in the way?21:52
Randy_Owget : Connecting to 10.0.1.200:80... failed: Connection refused.21:52
histoRandy_O: what's iptables -n -L show?21:53
shodan45could also be a firewall external to the server21:53
Randy_Ohttp://paste.ubuntu.com/7692405/21:54
sarnoldnetstat -tnlp ?21:54
TJ-Randy_O: !! did you see my last couple of messages in #ubuntu, much earlier?21:55
Randy_Osarnold, http://paste.ubuntu.com/7692411/21:55
Randy_OTJ-,  no, I scrolled back to find it, but didnt catch it21:55
Randy_OTJ-, supper time for me :)21:55
Randy_OTJ-, back now21:55
TJ-Jun 23 21:17:59 <TJ->   Randy_O: If you can get a listing on .200 of what avahi is seeing that may be useful: "avahi-browse -akrt"21:55
Randy_OTJ-, http://paste.ubuntu.com/7692417/21:56
sarnoldRandy_O: most irc clients have something like /lastlog -hilight21:56
sarnoldtxt = ["Machine Name=Thomas Ross’s Library" "Password=0" "iTSh Version=196618" ....  ?21:57
Randy_Osarnold, itunes media sharing21:57
sarnoldRandy_O: I'm just hoping "password=0" means "no password necessary" rather than "the password to use is 0"  :)21:58
Randy_Osarnold, ha, yeah, it's no password. 0 would be an easy password to guess21:58
TJ-Randy_O: Nothing obvious there. I've installed and removed squid-deb-proxy and squid-deb-proxy-client here to try to recreate your scenario, but been unable to22:00
sarnoldyeah I certainly expected to see some iptables rules or at least see apache bound to something other than 0.0.0.0:80.22:01
TJ-Randy_O: The bit that constantly brings me back to netfilters/nftables, is that *outgoing* connections to tcp port 80 are being refused, but when "iptables -S" shows no local netfilters rules at all22:01
sarnoldwhich then makes me think in crackpot land that perhaps there's a rootkit on the machine. that's a mighty big jump to make though..22:02
TJ-Randy_O: On .200, try connecting to my own server with this and I'll watch the incoming connections "FQDN="tjworld.org"; PORT="80"; exec 4<>/dev/tcp/$FQDN/$PORT; echo -e "GET / HTTP/1.1\nHost: $FQDN\r\nConnection: close\r\n\r\n" >&4; RESPONSE=$(cat <&4); echo "$RESPONSE"; exec 4<&-;"22:03
Randy_OTJ-,  I havent messed around with the firewall much. The server is mostly local, and only goes outside the network for https traffic (owncloud)22:03
TJ-sarnold: Yes, and we checked for arp cache poisoning and negated that22:03
Randy_OTJ-, done, -bash: /dev/tcp/tjworld.org/80: Connection refused22:04
TJ-Randy_O: what's your network's public IP - my server gets hit alot so I'm not sure if I saw a connection or not!22:04
Randy_O99.240.178.102 it's dynamic, but usually the same22:04
Randy_Oyou could connect to it on https://99.240.178.10222:05
TJ-Randy_O: no, no connections22:05
TJ-Randy_O: is apache still listening on 0.0.0.0:80 on .200?22:06
TJ-Randy_O: if so, also from .200, try a localhost connection: "FQDN="127.0.0.1"; PORT="80"; exec 4<>/dev/tcp/$FQDN/$PORT; echo -e "GET / HTTP/1.1\nHost: $FQDN\r\nConnection: close\r\n\r\n" >&4; RESPONSE=$(cat <&4); echo "$RESPONSE"; exec 4<&-;"22:06
Randy_OTJ-, tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      2259/apache222:07
Randy_OTJ-, -bash: /dev/tcp/127.0.0.1/80: Connection refused22:07
TJ-Randy_O: Right, so a local loopback *should* succeed22:07
Randy_OTJ-, it didnt22:07
TJ-Randy_O: So, definitely something on .200 then22:08
Randy_Ointerfaces?22:08
Randy_Oresolv?22:08
Randy_Ohosts?22:08
TJ-Randy_O: At least we are sure now that it is a local issue. Can't be a resolver issue since we're using IP addresses22:08
Randy_Osorry, didnt' mean to spam. I've checked all those, and I'm pretty sure they're all done correctly22:08
Randy_OTJ-,  ok, so not resolv.22:08
sarnoldTJ-: checking arp cache was a good one.22:09
sarnoldTJ-: maybe the tc traffic-control stuff? (yes, a huge guess..)22:11
sarnoldRandy_O: can you pastebin ip addr list   and ip route list  ?22:12
TJ-Randy_O: Rationally, despite everything we've seen, it still *feels* like a firewall issue. On that working assumption, lets explore some more. Can you show us "sudo iptables -t nat -S && sudo iptables -t filter -S && sudo iptables -t security -S && sudo iptables -t mangle -S"22:12
Randy_Osarnold, http://paste.ubuntu.com/7692451/22:13
shodan45what about apparmor or selinux?22:13
Randy_OTJ-, http://paste.ubuntu.com/7692454/22:14
Randy_Oshodan45, checked, and both still default config22:14
TJ-sarnold: here are the pastebins: iptables: http://paste.ubuntu.com/7691344/   port 80 tcpdump from a client .202: http://paste.ubuntu.com/7691434/   "ip route ls table all" http://paste.ubuntu.com/7691465/  "netstat -plnt" http://paste.ubuntu.com/7691508/22:14
sarnoldshodan45: it'd take some effort to get apparmor to block outgoing connections and it currently couldn't deny access to only outgoing port 8022:15
TJ-HAHA! I was correct at our first investigation! There's amasquarading rule still in place for a transparent proxy22:15
sarnoldoooh, -A FORWARD -i p4p1 -j ACCEPT ...22:15
TJ-Randy_O: -A PREROUTING -i p4p1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 312822:16
TJ-Randy_O: OK, do this to see just that table: "sudo iptables -t nat -S"22:16
shodan45sarnold: yeah, I'm not familiar with apparmor, other than it's a competitor to selinux22:16
Randy_OTJ-, http://paste.ubuntu.com/7692463/22:17
TJ-Randy_O: "sudo iptables -t nat -F && sudo iptables -t nat -F OUTPUT"22:19
Randy_OTJ-,  good, I'll reboot to see if it holds22:19
TJ-Randy_O: not yet!22:20
Randy_OTJ-, oops, I did.22:20
TJ-Randy_O: Test it to be sure it works now, then we'll remove it from the saved settings :)22:20
TJ-Randy_O: >> Jun 23 18:23:29 <TJ->   Randy_O: Did you have any transparent proxy netfilters rules set by iptables ?22:20
Randy_OTJ-,  ok, so it did work, I was able to apt-get. reboot un did it. so to make permanent change?22:21
TJ-Randy_O: If it works after the reboot, then something is saving the current iptables rules at shutdown and reloading them at start-up, so you'er fixed22:21
Randy_OTJ-,  it failed on reboot, and I issed that command line again and it's working again. rebooting undoes something22:21
TJ-Randy_O: I wonder if you have UFW installed?22:22
Randy_OTJ-,  I do22:22
TJ-Randy_O: OK, lets find out the brute-force way, looking for all port 3128 mentions: "sudo grep -rn '3128' /etc/*"22:23
Randy_OTJ-,  mostly webmin, http://paste.ubuntu.com/7692480/22:24
sarnoldeeeek22:24
Randy_OTJ-,  line 2-3 seem odd22:24
TJ-Randy_O: Yes, that's it "etc/firewall.conf"22:24
Randy_OTJ-, cat /etc/firewall.conf http://paste.ubuntu.com/7692483/22:25
TJ-Randy_O: So, with the rules now removed, simply do "sudo iptables-save >/etc/firewall.conf"22:27
Randy_OTJ-,  -bash: /etc/firewall.conf: Permission denied22:27
TJ-Randy_O: oh of course, silly me!22:28
TJ-Randy_O: So, with the rules now removed, simply do "sudo iptables-save | sudo dd of=/etc/firewall.conf"22:28
sarnoldhaha, dd22:28
TJ-Randy_O: Then, we'll find out which service/helper is configured to write to that file22:28
Randy_OTJ-,  done, reboot?22:28
TJ-No need22:29
TJ-Randy_O: I think you may have got the instructions for that from here: http://www.debian-administration.org/article/445/Getting_IPTables_to_survive_a_reboot22:29
Randy_OTJ-, no, I know it'll take effect without reboot, but I want to reboot to check if the config holds22:29
TJ-Randy_O: Or, it is possible that in webmin, under Network > Linux Firewall, you've configured it to save the rules to that file. You'd need to access the webmin web interface on port 10000 to check that, though22:30
=== Lcawte is now known as Lcawte|Away
TJ-Randy_O: It will, just re-read the /etc/firewall.conf file to make sure those rules for 3128/80 ports are gone22:30
Randy_OTJ-, that page is in fact in my history, but I dont recall doing any of that. I rebooted, it's all good now. So, thanks again, I dont think I could have figured that out on my own. Now I know :)22:31
TJ-Randy_O: Let's be sure it is webmin doing it, so you know22:31
Randy_OTJ-, Ive done 3 reboots now and It seems to be good. I went into webmin and tried to reset the firewall, and it's still working ok22:33
TJ-Randy_O: You should be able to get to it with "http://10.0.1.200/config.cgi?module=firewall&section=line1"22:33
TJ-Randy_O: That takes you to the Firewall module configuration page22:34
TJ-Randy_O: on that page there is an option to use the OS default location, or set your own. "IPtables save file to edit Use operating system or Webmin default  "22:34
TJ-Randy_O: My guess is, you have a manually set path there of "/etc/firewall.conf"22:34
Randy_OTJ-, it was set to use OS or webmin default22:37
TJ-Randy_O: OK, maybe it's here then: "cat /etc/network/interfaces"22:38
TJ-Randy_O: I have, for example, "    post-up /sbin/iptables-restore < /etc/iptables.up.rules"22:39
Randy_OTJ-, yep, that line is there22:40
Randy_OTJ-, below iface lo inet loopback22:40
TJ-Randy_O: OK, so you know now how /etc/firewall.conf is loaded at startup, and you know how to save the current rules with "iptables-save > /etc/firewall.conf"22:40
Randy_OTJ-, I do now22:41
TJ-Randy_O: :D blimey, that was a stiff test!22:41
Randy_OTJ-, haha, for sure, I'm pretty good with this kind of stuff, but this issue was way out of my league.22:41
Randy_OTJ-, thanks again for the help22:42
TJ-Randy_O: you're welcome; thanks for the brain-teaser :)22:42
=== thesheff17_ is now known as thesheff17
autojackI just had a strange problem that doesn't jive with my knowledge/experience of apt.23:44
autojackI'm on Precise. my company has our own apt repo that we use in addition to the default Ubuntu ones. we have a newer-than-standard version of bind9 in there. apt-cache showpkg bind9 shows me that version, as well as two older ones from the Ubuntu apt repos. yet when I tried to do apt-get install bind9=9.8.1.dfsg.P1-4ubuntu0.8 (one of the Ubuntu versions) it tells me that version is not found.23:46
autojackcommenting out our internal apt repo and doing an apt-get update allowed me to install that other version.23:46
autojackbut I don't understand why I had to do that, since showpkg displayed it as an available version.23:46
autojackthoughts?23:46

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!