/srv/irclogs.ubuntu.com/2014/12/31/#ubuntu-server.txt

=== Lcawte is now known as Lcawte|Away
=== markthomas is now known as markthomas|away
=== zz_DenBeiren is now known as DenBeiren
rzekaI am about to set automatic backups on server but I'm wondering. Is it better to connect to target machine from source or to source from target. In 1st case, when I have 3 different sources, I cannot tell if previous backup is done so I might get 2 backups running at the same time. In 2nd method, if backup server is hacked anyone may get access to other servers with ease (login through ssh keys)07:33
=== Lcawte|Away is now known as Lcawte
=== bilde2910|away is now known as bilde2910
vidarnewith taskset you can set a specific running program to a  core as root/superuser but is there a way for a regular user to be allowed to set what core a program shall use ?  i have 3 game servers runing and i dont want them to use core/treds 1-3.11:49
vidarneis it visudo i have to use for that ?11:51
=== bilde2910 is now known as bilde2910|away
DonRichievidarne: You can give root permission for specific commands with sudo12:01
Kartagispostfix/smtp[8844]: connect to mail.example.com[xxx.xxx.xxx.xxx]:25: Connection refused how come?12:57
Kartagisguys, it seems that I can't receive any mail and I re13:08
Kartagisceive this in the log13:08
LartzaNot sure if I should ask this on php or apache so... Running Apache2 with php5-fpm and proxypassmatch, problem with aliases on webapps like phpmyadmin14:00
LartzaGetting a "primary script unknown" error but there's no better info anywhere14:00
LartzaI use ProxyPassMatch pointing to fcgi://127.0.0.1:9000/var/www/html/$1 and Alias /phpmyadmin /usr/share/phpmyadmin14:01
LartzaFixed I think :)14:09
=== bilde2910|away is now known as bilde2910
=== Lcawte is now known as Lcawte|Away
dav1dp0101Hey, does anyone know how to remove the X windowing system and any display manager and graphics manager I may have installed? I think I installed a few different types but I don't remember what.15:51
=== Lcawte|Away is now known as Lcawte
=== markthomas|away is now known as markthomas
jsonperlhiya, I have a fairly non-ubuntu related "disaster recovery" question, but you folks are sharp :)17:14
* patdk-wk goes around popping balloons17:14
jsonperlI want to host a backup web app, ready to failover if my "primary" app has issues17:15
patdk-wkand?17:15
jsonperlMy initial thought was to take care of it via a CNAME change when said issue occurs17:15
jsonperlAnd keep an A record already pointing to the "spare"17:15
patdk-wkdoesnt matter17:16
jsonperlThough now I'm thinking I'll still have the same issues with TTL as I would with just a straight A record17:16
patdk-wkso your question is ONLY related to dns failover?17:16
jsonperlfailover in general17:16
patdk-wknothing else in the scope? like failover disk data, the application itself, webservers, ....17:16
jsonperlYou would likely use a load balancer, and redirect?17:16
jsonperlJust the webserver17:16
patdk-wkthere are like 5 good ways to do it17:17
jsonperlDo you have a pref?17:17
patdk-wkbut every method has it's own time and scaling issues17:17
jsonperlI like the CNAME route, since it's drop dead simple17:17
jsonperlbut DNS prop may be a bit of an issue17:17
jsonperland it's obviously not automated17:17
jsonperlbut this is a disaster situation, so I'm somewhat unconcerned about that17:18
patdk-wkwhy is it not automated?17:18
jsonperlcname switching?17:18
patdk-wkya17:18
jsonperlI mean, it could be I spose17:18
patdk-wkit always was for me17:18
patdk-wkI had each dns server test reachability17:18
patdk-wkand only serve whatever one was usable17:18
jsonperlI'm not running my own dns17:18
jsonperlI'm on route 5317:18
patdk-wkif the dns servers can't test, then you just have to go *best* guess17:18
jsonperlperhaps they have some automation for that though17:19
patdk-wkand assume the dns servers have the same reachability as your testing location17:19
jsonperlbtw happy new year pat17:19
patdk-wkthey do17:19
patdk-wkbut I hadn't used it too much, so can't remember if it's good enough, think it is though17:19
jsonperlthat may be the best solution17:19
jsonperlleast moving parts17:19
=== martinst is now known as martins-afk
Novice201yHi. How can I limit TLS version to ingore SSL3 on my Ubuntu 12.04 Server?18:58
Novice201yHi. I run OpenVPN Access Server on VPS's Ubuntu 12.04 and want to limit TLS version that accessing /admin via https will try something higher that SSL3.19:22
qmanYou will need to adjust the web server's SSL configuration19:25
=== duxklr| is now known as duxklr
qmanHow precisely you do that depends on which web server you're running19:25
Novice201yqman: I don't think so - I installed only OpenVPN Access Server on this Ubuntu, changes options under SSL tab, but still ask for SSL3 on conection.19:27
qmanA pretty decent guide for securing SSL on some common softwares: https://wiki.mozilla.org/Security/Server_Side_TLS19:27
qmanIf the OpenVPN Access Server runs its own web server, you will have to check with their documentation on how to configure it19:28
=== Lcawte is now known as Lcawte|Away
qmanThe algorithm selection is handled by the service, it's not a systemwide setting19:30
Novice201yqman: Thanks19:32
Aisonhello19:54
AisonI would like to setup several vlans19:54
Aisonwith network/interfaces it works19:55
Aisonand I guess with network/interfaces vconfig is used19:55
Aisonbut now I would like to use GVRP to announce the VLAN19:55
Aisonthis can be done eg. with19:55
Aisonip link add link eth0 eth0.260 type vlan id 260 gvrp on loose_binding on19:56
Aisoncan I somehow define a VLAN device inside network/interfaces so that GVRP is used?19:56
Aisonor maybe I need to define a inet manual device?!?20:00
=== markthomas is now known as markthomas|away
jvwjgamesHi21:35
jvwjgamesI need emergency help with my website21:35
jvwjgamesmy website is sufering sever probems21:43
jvwjgamesi need help can someone please help me21:44
cryptodanwhat kind21:44
jvwjgameslet me explain21:44
jvwjgameshere is my website21:44
jvwjgamestry to goto it21:45
jvwjgameshttp://jvwjgames.net21:45
cryptodanwhats the issue21:45
jvwjgamesmy customers recive an http error 504 gateway timeout error21:46
cryptodanI can get to it21:46
jvwjgamesreally21:46
cryptodanhttp://i.imgur.com/YmI2sPF.png21:47
jvwjgameshmmm21:47
jvwjgamesmy phone i use mobile data and get an http error 50421:48
jvwjgamesbut interal network can get to it21:48
cryptodanwhen i use www.jvwjgames.net I get a not found21:48
jvwjgamesya that expected cause i don't have an A record for www.jvwjgames.net only jvwgjames.net21:49
cryptodanbut without the www's I get to it21:49
jvwjgames*jvwjgames.net21:49
jvwjgamesya21:49
jvwjgamesbut for some odd reason my phone can't from out side my network21:50
jvwjgamesis it my server issue or is it tmobile issue21:50
cryptodantmobile21:51
jvwjgamesyes tombile21:51
cryptodanyou can check via www.network-tools.com or another site like it21:51
jvwjgamesok this is strange21:56
jvwjgamesit says it is ok on a website tester i used but my phone it has an http error 50421:57
jvwjgameshmmm21:57
cryptodanthen its a tmobile issue21:57
jvwjgameshmm i just don't get it22:00
jvwjgamescause all other websites work22:00
jvwjgameson tmobile22:02
jemejonesdoes anyone know of a tool that can see if any packages that i have installed have a known vulnerability (by pulling a feed from a cve database)?22:03
jemejonesi think maybe nessus can do it22:03
cryptodanyes nessus can22:03
jemejonesi'm trying to figure out if openvas (a fork of nessus from way-back-when) can do it22:04
jemejonesok - awesome22:04
cryptodanjvwjgames: could be an issue between tmobile and comcast22:04
jvwjgamescomcast?22:05
jvwjgamesdid you do an ip lookup22:05
jvwjgameslol22:05
cryptodanjvwjgames: yup22:05
jvwjgamesnice22:05
cryptodanbut it works for me so its an issue with tmobile22:06
jvwjgamesi have a tracert program on my android phone and it can do a tracrt just fine22:07
jvwjgamesfrom mobile data22:07
cryptodantraceroute is performed via ICMP or UDP it doesnt care about port 8022:07
=== markthomas|away is now known as markthomas
jvwjgamesthis is really strange22:14
jvwjgamesi can get to the site via mobile data if i use https but can't if i use http22:15
jvwjgamesok22:17
jvwjgamesi found the problem22:17
jvwjgamesThis is a known problem with US T-mobile - they fail to route to certain web services, including to Memsource. However, there is a workaround: Always use https for all communication, including using https from Memsource Editor. That should get you connected.22:17
jvwjgamesYou should report this issue to T-Mobile, so that they fix this. Their users seem to have similar problems connecting not just to Memsource:22:17
jvwjgamesso this is a know issue on T-Mobile apperantly22:18
cryptodannow I know another reason not to use tmobile22:23
=== TheRealCrell is now known as Crell
=== akaWolf1 is now known as akaWolf
=== dw2 is now known as dw1
=== rcj is now known as Guest87135
=== thesheff17_ is now known as thesheff17
=== bilde2910 is now known as bilde2910|away

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!