/srv/irclogs.ubuntu.com/2014/11/25/#ubuntu-server.txt

=== Lcawte is now known as Lcawte|Away
=== johnlage_partyha is now known as johnlage
aurorauseranyone have experience with mdadm arrays?01:57
aurorausermdadm, anyone?01:59
=== aurorauser is now known as DanaM
=== markthomas is now known as markthomas|away
=== _thumper_ is now known as thumper
neurotusis there a package for cgi:irc in 14.04 ?04:39
neurotusthere is one in 10.04 but in 14.04 ?04:40
neurotusor an alternative ?04:40
sheptardI approve07:00
sorenYeah, that was getting old.07:01
jonascjHi all. I have rented a server with hetzner.de and after installation of Ubuntu Server 14.04 the system have a single user 'root' which I can log into. What would the recommended action be at this point, to get to a system where I don't use the root account?07:18
jonascjShould I just add another user and setup sudo (maybe it already is), and disable the root account?07:19
jonascjAnd how should I disable the root-account, remove the password or "PermitRootLogin no" in the ssh-config?07:25
lordievaderGood morning.08:05
=== zz_DenBeiren is now known as DenBeiren
=== MeltedDed is now known as MeltedLux
=== psivaa-holiday is now known as psivaa
RoyKDanaM: probably quite a few here that knows mdadm ;)09:44
=== EXIXT is now known as exixt
peetaur2Hi. Why do I have these strange ntp servers that don't appear in my ntp.conf? https://bpaste.net/show/6f9ef78b661611:01
ihreHello, what happens when an application sends a a line bigger than 1024 characters syslog?11:01
peetaur2and missing the 2nd and 3rd ntp server I have from conf. the list there should be ntp, ntp3, localhost11:01
peetaur2oh nevermind...found it. there was some file here:  /var/lib/ntp/ntp.conf.dhcp11:03
=== Lcawte|Away is now known as Lcawte
=== zz_DenBeiren is now known as DenBeiren
=== Lcawte is now known as Lcawte|Away
peetaur2how do I tell it to install without removing the other stuff? https://bpaste.net/show/f04a392fc245  (like with rpm --force --nodeps)13:06
peetaur2I guess this worked:    apt-get -d install rsyslog ; dpkg --force-depends-version -i /var/cache/apt/archives/rsyslog_7.4.4-1ubuntu2.3_amd64.deb13:10
peetaur2but not sure if it will survive updates ;)13:10
=== exixt is now known as EXIXT
=== EXIXT is now known as exixt
=== hackeron_ is now known as hackeron
zuljamespage:  any objections to update alembic?13:40
MacroManI have read advice saying it's best to turn off DNS recursion in Bind9.14:39
MacroManI only use Bind9 for locally hosted websites. Is it safe to turn off recursion?14:40
maswanMacroMan: It is best to separate authorative and recursive nameservers, so that the same bind/whatever doesn't do both.14:47
MacroManI'll be honest, that's gone over my head14:48
maswanusing it "for locally hosted websites" doesn't say which kind of use14:48
MacroManI use my servers IP addresses in my nameserver settings on my domains, so I think I use it authoritively14:49
maswanThe IPs in /etc/resolv.conf or equivalent is "recursive"/"resolving" use14:50
maswanAuthorative is when you configure it to answer questions to the whole world for a particular dns zone/domain14:50
MacroManThen I use it Authoritvely14:55
jamespagezul, nope14:56
peetaur2sigh.... my solution before to the rsyslog issue wasn't so good. Unlike what I said with zypper/rpm, it results in stupid errors so you can't install anything else normally afterwards: https://bpaste.net/show/7ea74828b41e15:42
=== bilde2910|away is now known as bilde2910
ogra_well, package maintainers dont add versioned dependencies just for fun (they are not fun to maintain at all)15:50
dpeshi all15:51
dpeshow to disable apparmor15:51
dpes?15:52
dpesi'm still getting apparmor module is loaded. after stop15:52
ogra_you edit your kernel cmdline15:52
dpeson 14.0415:52
dpeswithout restart...15:52
jdstranddpes: boot with apparmor=0. that said if you are trying to workaround policy bugs with Ubuntu-shipped policy, I would advise reporting the bugs at: https://bugs.launchpad.net/ubuntu/+source/apparmor/+filebug15:56
dpesjdstrand: could You confirm that then there is no >ZERO< loaded profiles in apparmor15:58
dpesthen it don't interfer in os?15:58
dpesafter teardown15:58
jdstranddpes: if you boot with apparmor=0, apparmor will be disabled15:58
dpesi cannot boot this machine15:58
jdstranddpes: with teardown, you can see if anything is loaded with 'sudo aa-status'15:59
dpesapparmor module is loaded15:59
jdstranddbck: you will always get that the apparmor module is loaded if you aren't booting with apparmor=015:59
dpesand everywhare 015:59
dpes0 profiles *15:59
jdstrandthe module is loaded in the kernel15:59
jdstrandbut if no profiles are loaded in the kernel, the module will not do anything16:00
dpesok i get it16:00
dpesso it won't be apparmor issue16:00
jdstrandyou can also watch /var/log/syslog for apparmor DENIALs16:00
jdstranderr16:01
jdstrandDENIED messages16:01
jdstrandI use this when try to see if apparmor needs to be adjusted: tail -f /var/log/syslog | grep DEN16:01
dpesthx16:02
jdstrandnp16:02
=== Lcawte|Away is now known as Lcawte
=== markthomas|away is now known as markthomas
jamespagejdstrand, do you have a revised set of apparmor patches for docker/libcontainer?  just looking at the merge for vivid - the current patch applies OK - but I see some chat upstream :-)17:15
Davieyjamespage / jdstrand: Are you tracking CVE-2014-6407 ?17:20
uvirtbotDaviey: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6407)17:20
jdstrandjamespage: not yet, on my todo17:21
DavieyAh, doesn't look like it impacts the ubuntu version.17:21
jdstrandwe also have hardlink and symlink protections via yama17:22
jamespageDaviey, yes I am17:22
TechIsCoolGot a question about services. In windows a service can be assigned a user account. How can I check if services are attached to a user account in ubuntu? I am trying to remove a old user account but want to confirm I will not break anything by removing the account17:59
jamespagejdstrand, 1.3.2 is testing OK with the current patch from 1.2.0; I'll upload that as a merge and we can take if from there18:00
jdstrandjamespage: yeah, that should work fine. the upstream stuff is for running a new docker with old apparmor userspace18:05
jamespagejdstrand, ack18:05
=== rcj is now known as Guest93149
=== err-or_ is now known as err-or
=== zz_DenBeiren is now known as DenBeiren
=== markthomas is now known as markthomas|away
=== TDog_ is now known as TDog
=== rcj is now known as Guest31019
=== markthomas|away is now known as markthomas
=== MeltedLux is now known as MeltedDed
=== Guest71825 is now known as zsoc
=== MeltedDed is now known as MeltedLux
=== bilde2910 is now known as bilde2910|away
=== MeltedDed is now known as MeltedLux
=== MeltedLux is now known as MeltedDed
=== Lcawte is now known as Lcawte|Away
=== Guest31019 is now known as rcj
=== rcj is now known as Guest68049

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!