=== Lcawte is now known as Lcawte|Away === markthomas is now known as markthomas|away === zz_DenBeiren is now known as DenBeiren [07:33] I am about to set automatic backups on server but I'm wondering. Is it better to connect to target machine from source or to source from target. In 1st case, when I have 3 different sources, I cannot tell if previous backup is done so I might get 2 backups running at the same time. In 2nd method, if backup server is hacked anyone may get access to other servers with ease (login through ssh keys) === Lcawte|Away is now known as Lcawte === bilde2910|away is now known as bilde2910 [11:49] with taskset you can set a specific running program to a core as root/superuser but is there a way for a regular user to be allowed to set what core a program shall use ? i have 3 game servers runing and i dont want them to use core/treds 1-3. [11:51] is it visudo i have to use for that ? === bilde2910 is now known as bilde2910|away [12:01] vidarne: You can give root permission for specific commands with sudo [12:57] postfix/smtp[8844]: connect to mail.example.com[xxx.xxx.xxx.xxx]:25: Connection refused how come? [13:08] guys, it seems that I can't receive any mail and I re [13:08] ceive this in the log [14:00] Not sure if I should ask this on php or apache so... Running Apache2 with php5-fpm and proxypassmatch, problem with aliases on webapps like phpmyadmin [14:00] Getting a "primary script unknown" error but there's no better info anywhere [14:01] I use ProxyPassMatch pointing to fcgi://127.0.0.1:9000/var/www/html/$1 and Alias /phpmyadmin /usr/share/phpmyadmin [14:09] Fixed I think :) === bilde2910|away is now known as bilde2910 === Lcawte is now known as Lcawte|Away [15:51] Hey, does anyone know how to remove the X windowing system and any display manager and graphics manager I may have installed? I think I installed a few different types but I don't remember what. === Lcawte|Away is now known as Lcawte === markthomas|away is now known as markthomas [17:14] hiya, I have a fairly non-ubuntu related "disaster recovery" question, but you folks are sharp :) [17:14] * patdk-wk goes around popping balloons [17:15] I want to host a backup web app, ready to failover if my "primary" app has issues [17:15] and? [17:15] My initial thought was to take care of it via a CNAME change when said issue occurs [17:15] And keep an A record already pointing to the "spare" [17:16] doesnt matter [17:16] Though now I'm thinking I'll still have the same issues with TTL as I would with just a straight A record [17:16] so your question is ONLY related to dns failover? [17:16] failover in general [17:16] nothing else in the scope? like failover disk data, the application itself, webservers, .... [17:16] You would likely use a load balancer, and redirect? [17:16] Just the webserver [17:17] there are like 5 good ways to do it [17:17] Do you have a pref? [17:17] but every method has it's own time and scaling issues [17:17] I like the CNAME route, since it's drop dead simple [17:17] but DNS prop may be a bit of an issue [17:17] and it's obviously not automated [17:18] but this is a disaster situation, so I'm somewhat unconcerned about that [17:18] why is it not automated? [17:18] cname switching? [17:18] ya [17:18] I mean, it could be I spose [17:18] it always was for me [17:18] I had each dns server test reachability [17:18] and only serve whatever one was usable [17:18] I'm not running my own dns [17:18] I'm on route 53 [17:18] if the dns servers can't test, then you just have to go *best* guess [17:19] perhaps they have some automation for that though [17:19] and assume the dns servers have the same reachability as your testing location [17:19] btw happy new year pat [17:19] they do [17:19] but I hadn't used it too much, so can't remember if it's good enough, think it is though [17:19] that may be the best solution [17:19] least moving parts === martinst is now known as martins-afk [18:58] Hi. How can I limit TLS version to ingore SSL3 on my Ubuntu 12.04 Server? [19:22] Hi. I run OpenVPN Access Server on VPS's Ubuntu 12.04 and want to limit TLS version that accessing /admin via https will try something higher that SSL3. [19:25] You will need to adjust the web server's SSL configuration === duxklr| is now known as duxklr [19:25] How precisely you do that depends on which web server you're running [19:27] qman: I don't think so - I installed only OpenVPN Access Server on this Ubuntu, changes options under SSL tab, but still ask for SSL3 on conection. [19:27] A pretty decent guide for securing SSL on some common softwares: https://wiki.mozilla.org/Security/Server_Side_TLS [19:28] If the OpenVPN Access Server runs its own web server, you will have to check with their documentation on how to configure it === Lcawte is now known as Lcawte|Away [19:30] The algorithm selection is handled by the service, it's not a systemwide setting [19:32] qman: Thanks [19:54] hello [19:54] I would like to setup several vlans [19:55] with network/interfaces it works [19:55] and I guess with network/interfaces vconfig is used [19:55] but now I would like to use GVRP to announce the VLAN [19:55] this can be done eg. with [19:56] ip link add link eth0 eth0.260 type vlan id 260 gvrp on loose_binding on [19:56] can I somehow define a VLAN device inside network/interfaces so that GVRP is used? [20:00] or maybe I need to define a inet manual device?!? === markthomas is now known as markthomas|away [21:35] Hi [21:35] I need emergency help with my website [21:43] my website is sufering sever probems [21:44] i need help can someone please help me [21:44] what kind [21:44] let me explain [21:44] here is my website [21:45] try to goto it [21:45] http://jvwjgames.net [21:45] whats the issue [21:46] my customers recive an http error 504 gateway timeout error [21:46] I can get to it [21:46] really [21:47] http://i.imgur.com/YmI2sPF.png [21:47] hmmm [21:48] my phone i use mobile data and get an http error 504 [21:48] but interal network can get to it [21:48] when i use www.jvwjgames.net I get a not found [21:49] ya that expected cause i don't have an A record for www.jvwjgames.net only jvwgjames.net [21:49] but without the www's I get to it [21:49] *jvwjgames.net [21:49] ya [21:50] but for some odd reason my phone can't from out side my network [21:50] is it my server issue or is it tmobile issue [21:51] tmobile [21:51] yes tombile [21:51] you can check via www.network-tools.com or another site like it [21:56] ok this is strange [21:57] it says it is ok on a website tester i used but my phone it has an http error 504 [21:57] hmmm [21:57] then its a tmobile issue [22:00] hmm i just don't get it [22:00] cause all other websites work [22:02] on tmobile [22:03] does anyone know of a tool that can see if any packages that i have installed have a known vulnerability (by pulling a feed from a cve database)? [22:03] i think maybe nessus can do it [22:03] yes nessus can [22:04] i'm trying to figure out if openvas (a fork of nessus from way-back-when) can do it [22:04] ok - awesome [22:04] jvwjgames: could be an issue between tmobile and comcast [22:05] comcast? [22:05] did you do an ip lookup [22:05] lol [22:05] jvwjgames: yup [22:05] nice [22:06] but it works for me so its an issue with tmobile [22:07] i have a tracert program on my android phone and it can do a tracrt just fine [22:07] from mobile data [22:07] traceroute is performed via ICMP or UDP it doesnt care about port 80 === markthomas|away is now known as markthomas [22:14] this is really strange [22:15] i can get to the site via mobile data if i use https but can't if i use http [22:17] ok [22:17] i found the problem [22:17] This is a known problem with US T-mobile - they fail to route to certain web services, including to Memsource. However, there is a workaround: Always use https for all communication, including using https from Memsource Editor. That should get you connected. [22:17] You should report this issue to T-Mobile, so that they fix this. Their users seem to have similar problems connecting not just to Memsource: [22:18] so this is a know issue on T-Mobile apperantly [22:23] now I know another reason not to use tmobile === TheRealCrell is now known as Crell === akaWolf1 is now known as akaWolf === dw2 is now known as dw1 === rcj is now known as Guest87135 === thesheff17_ is now known as thesheff17 === bilde2910 is now known as bilde2910|away