/srv/irclogs.ubuntu.com/2014/08/14/#ubuntu-server.txt

=== Sachiru_ is now known as Sachiru
=== Sachiru is now known as Guest59613
=== Sachiru_ is now known as Sachiru
=== Sachiru_ is now known as Sachiru
=== peter is now known as Guest17135
phunyguyhey in mdadm, what does "2 near-copies" mean on a RAID10 array?01:56
Patrickdkit's the type of raid103:09
Patrickdkbasically means, normal raid1 where each disk is identical03:09
Patrickdkwhere far, would be kindof useful for high seeks03:09
=== ayr_ton is now known as ayr-ton
=== CripperZ- is now known as cripperz
=== cripperz is now known as CripperZ-
=== Nivex_ is now known as Nivex
=== arrrghhhAWAY is now known as arrrghhh
=== mikal_ is now known as mikal
kernel13is there a way to generate preseed file from existing server..just like kickstart file in centos. i need for cobbler.thanks05:30
=== arrrghhh is now known as arrrghhhAWAY
=== arrrghhhAWAY is now known as arrrghhh
=== arrrghhh is now known as arrrghhhAWAY
=== Sling_ is now known as Sling
linuxgeek_RoyK, looks like there was a physical connectivity issue. we plan to wire the ports and check.06:42
abhishek__I want to install ubuntu-server in blade that will go for production.Please give me tips for partition06:43
abhishek__I am planning to give /boot swap and / partitions only06:43
=== urda is now known as Guest96095
=== ttx` is now known as ttx
sebastianlutterI need to install nginx, but I need to avoid that it tries to start on port 80 / 443 while it installes (ports are already used). Is there a way to tell apt-get that it should NOT start the service after installation?08:04
dasjoesebastianlutter: imho the cleanest way would be to manually configure nginx to use a different port before installing it, by having /etc/nginx/sites-available/default exist before starting the install08:16
=== CripperZ- is now known as cripperz
=== ikonia_ is now known as ikonia
sebastianlutterdasjoe, very nice, thanks08:42
=== cripperz is now known as CripperZ
=== Pupeno_ is now known as Pupeno
=== CripperZ is now known as CripperZ-
irgendwer4711 hello, anyone using Ubuntu 10.04 LTS with openssl/postfix, having this error in log: "ccs received early"? seems to be related with CVE-2014-022410:00
uvirtbotirgendwer4711: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability. (http://cve.mitre.org/cgi-bin10:00
irgendwer4711TLS encrytion could be worthless!10:05
cfhowlettirgendwer4711, might ##linux know more?10:08
irgendwer4711this is an ubuntu problem10:08
cfhowlettirgendwer4711, it's a LINUX problem.10:08
irgendwer4711old debian squeeze hasnt this problem, this use 0.9.8o10:09
irgendwer4711openssl10:09
cfhowlett!openssl10:09
cfhowlett!ssl10:09
irgendwer4711what are you doing10:12
irgendwer4711maybe youre right, should write it to #linux10:14
cfhowlettirgendwer4711, this helps???  http://askubuntu.com/questions/478042/how-to-patch-the-vulnerability-cve-2014-0224-in-openssl10:14
uvirtbotcfhowlett: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability. (http://cve.mitre.org/cgi-bin/cve10:14
irgendwer4711ubuntu fixed that, but wrong10:15
irgendwer4711cfhowlett: https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.1810:21
irgendwer4711there they tried to fix this10:21
cfhowlettirgendwer4711, I don't have enough knowledge to advise in meaningful fashion.  sorry.10:22
irgendwer4711mdeslaur: maybe we asked him :-)10:24
rbasakjamespage: ping10:33
rbasakirgendwer4711: are you sure your log message is a real problem?10:34
irgendwer4711yes10:34
rbasakWhy?10:34
irgendwer4711rbasak: TLS got  useless10:35
rbasakSo you're saying that TLS doesn't work at all?10:35
irgendwer4711rbasak: in this case, I think so. postfix is sending this mail without TLS10:35
irgendwer4711rbasak: maybe NSA wrote this crappy bugfix ;-)10:37
rbasakirgendwer4711: can you confirm that downgrading to the package version prior to the security update makes TLS work again? In that case you may have a security regression.10:37
rbasakIf so, then please file a bug detailing steps to reproduce, and the security team will take a look at it.10:37
irgendwer4711rbasak: noone of them online now?10:38
rbasakMy only reservation is that it may be that the TLS configuration you have is incompatible with current best-practice (because I haven't seen it).10:38
rbasakSometimes the security team have to make hard choices when issuing security updates.10:38
irgendwer4711rbasak: my config worked well until openssl-0.9.8k-update10:38
rbasakSo I think it's best to first detail steps to reproduce, and then the security team can take a look.10:38
irgendwer4711wrote a mail :-D10:38
rbasakYou can find the security team in #ubuntu-hardened, but really I think they'll want steps to reproduce to be able to look into it.10:39
irgendwer4711they just need a ubuntu 10.4.4 tls with running postfix10:39
rbasakAlso, they have a process for triaging bugs to make sure these things don't get missed. Emails and IRC messages don't end up in a queue to look at.10:39
rbasakPlease provide steps to reproduce. Really. See http://www.chiark.greenend.org.uk/~sgtatham/bugs.html for reasons why.10:40
irgendwer4711first I try at #ubuntu-bugs10:40
rbasak#ubuntu-bugs is for triaging bugs, not for reporting them. See the channel topic there.10:40
irgendwer4711hm no #ubuntu-hardend10:40
pmatulismorning11:20
=== _ruben_ is now known as _ruben
bentech4youhi, anyone please help me to get it work. i am always getting invalid user12:52
bentech4youi have followd http://www.linuxintro.org/wiki/Guacamole12:52
bentech4youany help please12:54
ikoniabentech4you: that sounds like you need to talk to the guacamole people as the auth looks like it's internal tot he app13:05
ikoniawhich is the war file you deployed in tomcat13:06
ikoniabentech4you: I assume you read the part that says "it is not possible to login yet" and you have to go down approx 10 steps to configure the users13:06
bentech4youguacamole.war file.13:16
bentech4youi renamed to that . i am getting login page from this. but user is not able to login to that13:16
bentech4youyea , i have created all config files too https://sourceforge.net/p/guacamole/discussion/1110834/thread/83f6d29c/13:18
ikoniabentech4you: that's not what I said13:24
bentech4youyea i configured user also13:32
bentech4youi have pasted my user conf file on that link13:32
ikoniaso then it's an application problem13:34
ikoniaan application that's not part of ubuntu13:34
ikoniaso take it to the guys who support it13:34
ikoniamore so as you've changed the names of the war files and made changes to the process in that document13:34
=== kickinz1 is now known as kickinz1|bbs
=== kickinz1|bbs is now known as kickinz1
=== lamont` is now known as lamont
=== niemeyer_ is now known as niemeyer
=== sync0new is now known as sync0pate
lordievaderGood afternoon.15:51
fridaynextI've got my Hackintosh plugged into an APC UPS.  Is there a way to share that signal with my Ubuntu 14.04 box running NUT?16:57
RoyKfridaynext: should be quite possible, but then, NUT isn't my strongest side :P17:02
fridaynextRoyK: I just found a tutorial online that should help me figure it out.17:02
fridaynextRoyK: thanks though.17:02
=== FreezingAlt is now known as FreezingCold
FishsceneAre there any known issues with isc-dhcp-server on Ubuntu Server 14.04 and Virtualbox17:33
Fishsceneerr… narrowing that down a bit… The other day, I tried setting up an LTSP server standalone and configured virtualbox with an Internal network. But for the life of me, I could not get it to hand out DHCP addresses.17:34
jhobbs_use wireshark or tcpdump to debug how far traffic is making it17:35
=== jhobbs_ is now known as jhobbs
jhobbswatch for dhcp requests on your server, if you don't see them there, figure out why it's not seeing them17:36
jhobbsif you do, figure out why it's not responding17:36
Fishscenehmm.. I hadn't thought of that. I'll try that out if my VM rebuild yields the same issue.17:36
streulmahello, in my VPS template, the /var/cache directory is deleted. How can I restore this?17:40
sarnoldFishscene: check dmesg for apparmor DEN lines, dhcp is .. funny17:40
sarnoldstreulma: on my system /var/cache is root:root 75517:41
streulmasarnold: the WHOLE directory is away17:41
sarnoldstreulma: I hoped whatever needed it would re-create their own dirs within when needed..17:42
streulmano sarnold :( apt-get update fails and dpkg also17:42
sarnoldstreulma: if not, here's the rest of the dirs in mine: http://paste.ubuntu.com/8047132/17:42
=== lazyPower_ is now known as lazyPower
streulmasarnold, only apt directory is for the moment important17:46
sarnoldstreulma: if it needs more still: http://paste.ubuntu.com/8047158/17:47
streulmasarnold and debconf because dpkg is also broken :)17:48
streulmaI don't know why they remove cache dir in Debian and Ubuntu template17:48
streulmaCentOS has the fault that yum is broken, more, python is broken...17:49
streulmaI repaired, and after a while it was the same, again broken17:49
sarnoldstreulma: /var/cache/debconf/ http://paste.ubuntu.com/8047175/17:49
=== Lcawte|Away is now known as Lcawte
=== Mogwai is now known as Guest82958
mdeslaurQEMU security update call for testing: https://lists.ubuntu.com/archives/ubuntu-server/2014-August/006955.html18:35
sarkishow can i see what version of the kernel will be installed with apt-get? i tried apt-cache policy linux-general19:09
RoyKsarkis: it'll normally just upgrade the current kernel to a newer subversion (unless something has changed recently)19:15
rberg'aptitude show linux-image' will show what versions are available19:25
rbergor sometimes I use 'apt-get upgrade -d' just to see whats being downloaded19:28
=== keithzg_ is now known as keithzg
* keithzg totally forgot about the /var/www/ -> /var/www/html/ switch in Debian, was super confused when a bunch of internal websites ceased working after upgrading from 12.04 -> 14.04 today, haha19:57
Lord255hi all, i have insalled firefox to my server, i have a win client, i use putty to connect. xming installed on my pc and x11 fwd is enabled in putty. when i try to run firefox it goes to defunct. do you have any advices whats wrong or something?20:05
sarkishmmm how can i upgrade the version of the kernel?20:07
sarkissomehow one of my machines has 3.5.x and others are on 3.2.x20:07
Lord255apt-get dist-upgrade20:08
sarkismaybe this is an issue with --dry-run20:08
sarkisbut i do apt-get dist-upgrade --dry-run20:08
sarkisi don't see it trying to grab 3.5x20:08
dasjoesarkis: your machines are on different kernels because one of them is using a different HWE stack, see https://wiki.ubuntu.com/Kernel/LTSEnablementStack20:09
sarkishow the hell20:09
dasjoeLord255: I'd try connecting with http://mobaxterm.mobatek.net/ as I've had more success with MobaXterm than a manual setup20:11
dasjoeLord255: also make sure your /etc/ssh/sshd_config contains "X11Forwarding yes"20:12
Lord255fwd in sshd conf is ok. i will try the one which you have sent.20:15
Lord255dasjoe: it goes to deunct as well20:38
keithzgLord255: Have you tried anything lighter than Firefox?20:38
=== _monokrome is now known as monokrome
sarkisdasjoe: thanks, that was it, not sure how the hell it happened though20:39
sarkisdasjoe: i mean both are still reporting it as 12.04.4 yet that 1 box does have -quantal20:39
Lord255however it opened the window now20:40
Lord255if that prog works why xming doesnt?:o20:40
Lord255and idk why a defunct irefox appears20:40
keithzgX11 on Windows == a nightmare hell ride ;)20:41
Lord255lol :D20:41
IcabashHello, I'm having trouble installing Ubuntu Server x86 on one of my machines - The install hangs and does not continue when it reaches "load debconf preconfiguration file". Any advice on how to get this working?20:53
IcabashI've got the install screen up right now, so I'm happy to give any information required to solve this problem :)20:53
IcabashAh, I just tried the installation again. Now it's stopping with the message: "Your installation CD-ROM couldn't be mounted. This probably means that the CD-ROM was not in the drive. If so you can insert it and try again.21:06
=== sarkis_ is now known as sarkis
=== Lcawte is now known as Lcawte|Away
=== Ursinha is now known as Ursinha-afk
=== Ursinha-afk is now known as Ursinha
Matt3o12Hello.23:52
Matt3o12Is it save to remove the root password (`passwd -d root`) on my Ubuntu server? When I installed the server, I was given a root password but I wonder whether it is necessary to use root since I still can use sudo.23:53
sarnoldMatt3o12: should be be safe; my /etc/shadow has root:!:..23:54
sarnoldMatt3o12: and if things ever go really wrong you can always boot into init=/bin/sh and fix whatever needs fixing23:54
Matt3o12And what about user mod -s /usr/sbin/nologin ?23:55
sarnoldhrm, I wouldn't, I'd worry about a program running as root deciding what shell to use with getpwent or similar23:57
Matt3o12And is it save to allow ssh connections without a valid public (and just with a password)? I'm worry about losing all data on my computer...23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!