/srv/irclogs.ubuntu.com/2014/09/18/#ubuntu-server.txt

=== markthomas is now known as markthomas|away
=== TDog_ is now known as TDog
lordievaderGood morning.06:28
=== esde is now known as Guest67997
=== hachre_ is now known as hachre
=== SPQN is now known as AndreiCurelaru
jamespagecoreycb, zul: bumped new versions of oslo.db and vmware into utopic for ceilometer09:28
kubblaihi i have W: Failed to fetch http://gb.archive.ubuntu.com/ubuntu/dists/precise/Release.gpg  Connection failed [IP: 91.189.92.200 80] error on 12.04.5 server. I have tried rm -rf /var/lib/apt/lists/* with a clean but no luck09:30
kubblaiI have also tried removing the gb. from apt/sources.list09:31
jpdskubblai: It says Connection failed.09:31
jpdskubblai: Tried checking the connection between you and that IP?09:32
skatariaI need help, i have ubuntu 12.04 and openssl 1.0.1 but it's not support for TLSv 1.2 how i can i enable it with my server so i can enable with apache09:33
kubblaijpds if i try with de or fr or gb it fails09:45
jpdskubblai: Works for me.09:46
jpdsskataria: https://serverfault.com/questions/372943/ssl-tls-1-2-on-apache-with-openssl-1-0-109:50
kubblaijpds: i can wget the file but it retries 5 times with HTTP request sent, awaiting response... Read error (Connection reset by peer) in headers.09:52
kubblaijpds: mtr shows no packetloss between my host and the ip 91.189.91.1509:53
skatariathanks jpds let me check for that09:55
=== a1berto_ is now known as a1berto
skatariajpds: i don't understand that link as i checked supported version of my ssl server and it's showing Supported versions: SSLv3 TLSv1.0 TLSv1.110:06
skatariait's not showing TLSV1.2 then how can i add it10:06
kubblaiah jpds there is an issue with my wireless i believe, I'm getting loads of DUP!'s when pinging that host10:14
jpdsskataria: Change the config as the link suggests?10:26
jamespagezul, also fixed tooz - the problem was the git generated orig.tar.gz10:37
jamespageswitching to the actual upstream release tarball makes everything just work10:37
jamespagezul, working on re-enabling the neutron test suite10:58
Vladimir_I have set a script that execute a timestamp script every 10 minutes, it adds a time/date for all the files that has changed during the past 10 minutes, the problem is it adds timestamps to files that has already got its timestamp, so it just adds over and over again :/11:16
zuljamespage: im going to update oslo depdenencies this morning11:24
=== ws2k3 is now known as ws2k3__
coreycbjamespage, zul: I'm looking at the python-glance-store test failures11:42
coreycbjamespage, zul: looks like several of the python-xstatic syncs haven't happened yet11:43
=== psivaa_ is now known as psivaa
jamespagecoreycb, re xstatic yes that is the case12:06
jamespagezul, did you see I updated db and vmware?12:06
jamespageand fixed up tooz12:06
jamespagezul, we also need a MIR for oslo.serialization12:07
=== ws2k3__ is now known as ws2k3
zuljamespage: yep going to do that today12:27
jamespagezul, three neutron failures - something is racey12:28
* jamespage digs some more12:28
zuljamespage: surprised?12:28
jamespagezul, no12:28
jamespagethey pass individually12:28
rrittenhouseIf I dd a drive from an ubuntu server (with one nic, eth0) why does it register as eth1 or eth2 in some cases? Is there a quick fix or script to run to have it re-detect the drives like it does on a normal install? Thanks.12:29
=== Guest67997 is now known as esde
smbhallyn, I got the patches I care about back on top of libvirt 1.2.8. Do you want to peek at things or shall I just push the upload?12:30
zuljamespage: yeah i did see you did the updates as well12:32
jamespagezul, awesome12:32
zuljamespage: im going to update oslo.messaging12:32
jamespagezul, having a distro day today - charms tomorrow12:32
jamespagezul, +112:32
zuljamespage: i usually do 50/50...most days12:33
jamespagezul, I didn't bump to the very latest of things12:33
jamespagejust to the minimum requirement12:33
zulok12:33
jamespagezul, oh - we might need to bump eventlet as well - I've avoided it so far12:33
zuljamespage: ok ill do that this morning12:33
jamespagezul, lets check first12:33
jamespagezul, zigo has a new version in experimental - the very latest oslo.vmware wanted it but the previous release was OK12:34
zuljamespage: ok12:34
zuljamespage: dhellman is also cutting the final oslo libraries today, mostly just version bumps though12:35
jamespagezul, ack - eventlet bug - https://bugs.launchpad.net/ironic/+bug/132178712:35
uvirtbotLaunchpad bug 1321787 in python-eventlet "Paramiko does not properly work with eventlet concurrency" [Undecided,Confirmed]12:35
jamespagezul, awesome12:35
jamespagezul, let me know if you need to pickup anything12:36
jamespagezul, fyi I've been reviewing minimum requirements and updating d/controls'12:36
zuljamespage: sure12:36
jamespageceilometer done and uploaded, neutron still working on tests12:36
zuljamespage: i have a charm question for n-c-f later though12:36
zuljamespage: im going to make sure we have the latest clients as well12:37
zuljamespage: i dont know if you saw this but rather than patching out requirements.txt i been adding depdencies to pydist-overrides so that they dont get installed so we carry less packages12:41
zulpatches12:41
jamespagezul, that does not always work depending on how things are loaded12:42
jamespagestevedore can error with that12:42
jamespageit parses requirements and explodes....12:42
zuldoh12:42
zuljamespage: well it was websockify and rtlsib i think12:43
=== henkjan_ is now known as henkjan
hallynsmb: are they just re-writes of xen patches whcich were ther epreviously?13:31
hallynsmb: if so, then just push.  if new, then i'll take a look13:31
smbhallyn, no, just rewrite/adds13:31
smbok, I will push them13:32
hallynsmb: thx13:51
zuljamespage/coreycb: just updated python-novaclient, python-glanceclient, python-swiftclient, python-cinderclient, python-keystoneclient, python-neutronclient, if there is no major bugs between now and release these are the versions we are gonig with13:59
jamespagezul, so we probably need keepalived dependency for the neutron l3 agent13:59
* koolhead17 looks around14:00
zulin neutron or neutronclient?14:00
jamespagezul, neutron - but the feature is not inb314:01
jamespagegrrr14:02
jamespageanyway - I'll leave that for now14:02
zuljamespage: lovely14:02
zuljamespage: saw this as well https://review.openstack.org/#/c/121509/14:03
jamespagezul, meh - thats a bugfix - no objection to that.14:04
zuljamespage: apparently you have to wait for 1.0.414:04
zuljamespage: final oslo.messaging uploaded, oslo.serialiazation MIR is (#1371163)14:55
jamespagezul, awesome15:05
jamespagezul, cinder/barbicanclient?15:06
jamespagejust revising versioned depends and noticed that one15:06
zuljamespage: right15:06
zuljamespage: 1371171 for barbicanclient15:08
jamespagebug 137117115:09
uvirtbotLaunchpad bug 1371171 in python-barbicanclient "[MIR] python-barbicanclient" [High,New] https://launchpad.net/bugs/137117115:09
=== wedgwood1 is now known as wedgwood
jamespagezul, tidying cinder right now btw15:44
jamespageversioning checking etc...15:45
zuljamespage: cool just doing the final oslo namespace stuff15:45
zuljamespage: olso.config, oslo.db, olso.messaging have been updated so far15:46
zuljamespage,: a newer oslo.db might fix the database races in neutron tests15:47
jamespagezul, might do - lets see15:47
zuljamespage: yep15:47
=== Ursinha is now known as Ursinha-afk
jamespagezul, I hit the button of despair a few times to get it to go through15:48
zuljamespage: lol15:48
zulcoreycb,done15:50
=== markthomas|away is now known as markthomas
=== Lcawte|Away is now known as Lcawte
zuljamespage/coreycb: we should be good for oslo dependencies for juno now17:29
coreycbzul, nice17:29
jamespagezul, awesome17:31
jdstrandhallyn: hey, what do you use to create a container for use with libvirt-lxc?19:23
hallynjdstrand: https://wiki.ubuntu.com/SergeHallyn_libvirtlxc19:23
hallynsubstitute utopic for oneiric :)  but still works19:23
jdstrandrocking19:24
jdstrandthanks19:24
jdstrandhallyn: I'm not seeing that the container started under apparmor. is that enabled in 1.2.8-0ubuntu2?19:46
hallynjdstrand: should be.  did /etc/libvirt/lxc.conf get installed for you from the new package ?19:47
hallynshould have security_driver = "apparmor"19:47
jdstrandyes19:47
jdstrandI wonder if I need to restart libvirtd19:48
hallynhuh.  definately was working in my test vms.  I assume you have /etc/apparmor.d/libvirt/TEMPLATE.lcx19:48
jdstrandcause I installed it, then installed lxc19:48
jdstrandwell, no19:48
jdstrandI started a container19:48
hallynno that shouldn't need that19:48
jdstrandI do19:48
jdstrandwow, that is a pretty open rofile19:49
hallyn?19:50
jdstrand"file,"19:51
jdstrand/etc/apparmor.d/libvirt/TEMPLATE.lxc19:51
hallynhm, yeah.  that came from upstream.  might wanna tighten that down at some point19:51
hallynbut still, that will at least prevent cases where containers change your root disk to ro :)19:51
jdstrandthat, lxc and docker.io should really have very similar profiles19:52
jdstrandanyhoo19:52
jdstrandvirsh -c lxc:// capabilities|grep -C1 secmodel19:53
jdstrand    <secmodel>19:53
jdstrand      <model>none</model>19:53
jdstrand      <doi>0</doi>19:53
jdstrand    </secmodel>19:53
hallynyeah, and both it and docker.io have ripped parts out of the lxc one :)  then opened it up19:53
hallynserge@sl:~$ virsh -c lxc:/// capabilities | grep -C1 secmodel19:54
hallyn    </topology>19:54
hallyn    <secmodel>19:54
hallyn      <model>apparmor</model>19:54
hallyn      <doi>0</doi>19:54
hallyn    </secmodel>19:54
hallyn  </host>19:54
hallynyou've got /etc/apparmor.d/abstractions/libvirt/libvirt-lxc ?19:54
hallynI don't know why you're getting htat.  weird.19:54
jdstrandoh, libvirt doesn't have its profile loaded19:54
jdstrandok, that fixed it19:55
jdstrandhallyn: ^19:55
jdstrandthat was almost certainly my fault19:55
hallynhow could that happen?19:56
jdstrandunloading it manually19:56
jdstrandI was playing around with the profile19:56
jdstrandI clearly made a mistake :)19:56
jdstrandhallyn: oh, I bet it was qrt that unloaded it19:57
jdstrandanyhoo, it is working19:58
hallynhm, that reminds me, did i ever send the patch to the m-l to allow the apparmor security driver to be missing?  Probably not...19:59
jdstrandidr19:59
jdstrandhallyn: fyi, I'll be uploading ubuntu4 for a small apparmor change20:10
hallynmake that 520:10
hallynjdstrand: ^20:10
hallyni've got a feeling this is gonna be touch-n-go for the next week :(20:11
jdstrandhallyn: launchpad is only showing ubuntu320:11
hallyn oh, right you are!20:12
hallynthat was qemu.  nm20:12
jdstrandok, so I am free to upload ubuntu4?20:12
jdstrandhallyn: ^20:13
hallynjdstrand: yes  :)  thx20:13
hallynwhat are you changing?20:13
jdstrandadd 'network netlink,' to usr.sin.libvirtd20:13
jdstrandsbin*20:13
jdstrandit is needed for the kernel pull request that will be hitting the kt list later today20:14
jdstrandit was supposed to by in my ubuntu6 upload from before, but I missed it20:14
=== markthomas is now known as markthomas|away
=== markthomas|away is now known as markthomas
fridaynextif i'm sending mail from domain1.com's website, but the 'from' address is from domain2.com, do I need dkim for domain2 in domain1's dns records?22:14
shaunofridaynext: no; if domain1 could do that, so could randomspammer.ru.  the from address is canonical - only domain2 needs the record22:16
fridaynextshauno: it's just weird, b/c I have dkim set properly for domain2.com - which is where the mail's being sent from - but the test show dkim is not working properly when sent from domain1.com's wordpress site.22:18
shaunois domain1 signing anything?22:19
fridaynextI have it set up in my keytable, but i'm not sending anything from that domain.22:19
fridaynextlike, nothing from example@domain1.com is being sent - but i do have an opendkim keytable entry for that domain22:20
shaunoI mean is it signing stuff on behalf of domain222:21
fridaynextIt appears to not be.22:21
fridaynextwhen i send an email to brandonchecketts test DIRECTLY from domain2, it shows the dkim sig22:22
fridaynextbut when i send 'from' that same email address, but via the domain2.com wordpress site's mailpoet plugin, the dkim sig does NOT show.22:22
fridaynextdomain1 is using google apps for email22:23
shaunoso that'll be where it's failing; not that it can't find the pubkey (so dns isn't an issue yet), but that there's no signature to even check22:24
fridaynextshauno: how do I fix that?22:24
=== Lcawte is now known as Lcawte|Away
shaunoI'd assume you'll need the wordpress install to use domain2 as a mail relay (since the chances of getting google to install your dkim key is .. low)22:25
fridaynextI'm using google's dkim on domain122:26
fridaynextwell, there's this: https://wordpress.org/plugins/easy-wp-smtp/22:27
fridaynextI think Google limits the number of emails you can send at a time, but this site is not super highly trafficked, so I'm guessing that won't be an issue22:27
fridaynextonly about 40 regular customers22:27
fridaynextShould I remove domain1's domainkey generated on my server, since I'm now using Google's?22:28
shaunoI'm re-reading trying to keep track of what's sending from where  heh22:29
fridaynextso friday-next.com is where email comes from22:29
fridaynexti have that set up with google apps22:29
fridaynextand i have added google's dkim as a TXT record for friday-next in my DNS settings22:30
fridaynextbefore I switched to google apps, i generated my own domainkey for my postfix/dovecot server, and put that domainkey as a TXT record22:30
fridaynextshould I delete that home-grown domainkey from my TXT records, since I don't really need it any more?22:30
shaunoI'm actually not sure what the result of having two conflicting pubkeys would be22:31
fridaynextit doesn't seem to be using the old one, so i'm guessing it's not a problem, but i'm pretty sure i don't need it any more22:32
shaunobut I think the first thing would be to figure out why the signature isn't present in the mail wp sends?22:32
fridaynextwell with that "Easy WP SMTP" plugin, it'll just send via smtp, which will add the dkim sig.22:32
shaunoah, okay.  so without it's just sending straight from that box rather than from google's mailservers (so no key)22:33
fridaynextright. but it would still be nice to know why it's not signing, for my other clients with sites on my box22:34
shaunothen yes, I'd assume from there you just need the right pubkey published in the domain that matches the sender's address22:34
roaksoax.1/win 823:06

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!