/srv/irclogs.ubuntu.com/2015/01/10/#ubuntu-server.txt

=== collizion is now known as Guest24740
=== collizio1 is now known as collizion
farawayhi i run ubuntu-server 12.04.5. I have installed ruby-2 using the „brightbox“ repos. Now I would like to use the dep of nginx to install the latest version on nginx.01:02
farawayThe problem I have now brigthbox also contains nginx and that that source is listed befor the one of nginx.org01:02
farawayAs far as i understand i could use Pinning to set the priority, but I’m not sure how I would do that correctly01:04
farawayIf i check the result with „apt-cache policy nginx“ it does not seem to work.01:04
sarnoldfaraway: apt_preferences(5) has the pinning documentation01:15
farawaynever mind  found the problem did use the wrong information for Pin: origin01:15
sarnoldaha :)01:19
=== markthomas is now known as markthomas|away
=== zz_DenBeiren is now known as DenBeiren
=== negronjl is now known as negronjl-afk
=== negronjl-afk is now known as negronjl
z1hazecan someone help me with finding a list of directories that begin with a certain name who's last modified date is longer than 2 days?05:42
z1hazei have come up with this so far: find . -type d -mtime +2 | egrep 'DIM_MYST*05:43
z1haze' but i dont want it to be recursive05:43
cryptodan -depth Process each directory's contents before the  directory  itself.05:44
cryptodan              The -delete action also implies -depth.05:44
z1hazeso like -maxdepth 1 ?05:45
cryptodan -maxdepth levels  Descend at most levels (a non-negative integer) levels of directories below the command line arguments.  -maxdepth 0 means only apply the tests and  actions  to  the  command  line arguments.05:45
z1hazeare you literally pasting definitions?05:46
cryptodanman find05:46
z1hazei didnt come here to read a manual i came for more intuitive help05:46
cryptodanthats how you get help in linux is using the man command05:46
cryptodanand if you cannot find it there use google then come to chat here05:47
z1hazei understand what the descriptions say, i just am having trouble with interpretting it correctly05:47
cryptodanso I am sorry if I didnt satify you wanting the actual work done for you05:47
z1hazei didnt ask you to do any work for me05:47
z1hazenever mind dude, thanks #ubuntu-server. always a pleasure05:48
Guest6251hi! I have a serious problem with 14.04 LTS.09:46
Guest6251Apache installed, no firewall. TCP port 80 is up and apache serves for 2-3 days (not large traffic)09:47
Guest6251after that all tcp connections stuck in 'SYN_RECV' state09:47
Guest6251and by all I mean all09:47
Guest6251no ping, no port80 afterwards09:48
Guest6251I have to reboot it, and it comes back working09:48
Guest6251what's worth checking?09:48
lordievaderGood morning.10:32
=== bilde2910|away is now known as bilde2910
=== liam_ is now known as Guest76709
xperiahi all i am trying to use ipset on my ubuntu server but keeps getting the error message "ipset v6.20.1: Kernel error received: set type not supported"13:52
xperiabefore it worked however. what did get wrong ?13:52
bekksxperia: Which Ubuntu are you on exactly? And which kernel are you on exactly?13:57
xperiabekks: Kernel is 3.13.0-35-generic and Ubuntu version is 14.0413:57
bekksMaybe you should try the current kernel, then. Just run sudo apt-get update and sudo apt-get dist-upgrade and try again.14:02
xperiabekks: i got the tip from the netfilter people to check the dmesg log file and look what is written ! Damn the Module was not Loaded anymore => "Request for unknown module key 'Magrathea: Glacier signing key: a28db5fd6e299cce4947dacaa66f459db4acce24' err -11 ip_set_hash_ip: disagrees about version of symbol module_layout"14:07
xperiawtf !14:07
bekksNo need to cuss :)14:08
gblfxt!! ubuntu server channel sullied w naughty language! how could you!14:15
ubottugblfxt: I am only a bot, please don't think I'm intelligent :)14:15
udit_how i install this certificate mydomainname_com.crt COMODORSADomainValidationSecureServerCA.crt COMODORSAAddTrustCA.crt AddTrustExternalCARoot.crt on nginx14:16
udit_i am using ubuntu 14.04 x6414:17
=== spinza_ is now known as spinza
udit_which command i use to install those certificate14:17
udit_i used comodo positive ssl14:17
lnxmenHi14:23
lnxmenWould anyone help me with postfix and receiving emails?14:23
lnxmenI set home_mailbox to "/var/mail/"14:24
lnxmenBut this folder is empty.14:24
gblfxt... postfix is a mta, not retriever...14:25
lnxmenSo, what should I install to receive mails?14:26
xperialnxmen: courier or dovecot14:30
lnxmenxperia: Okay, thank you.14:38
lnxmenDo you think I may use this tutorial? https://rtcamp.com/tutorials/mail/server/postfix-dovecot-ubuntu/14:38
lnxmen(Yes, I want to configure roundcube also)14:38
bekkslnxmen: I'd use this one: http://ubuntuguide.org/wiki/Mail_Server_setup14:40
lnxmenbekks: thanks, I will read both.14:41
lnxmen(firstly I am trying to understand what I am supposed to do.)14:41
gblfxtwhat is your purpose? you just trying to get mutt working and host a domain? :D14:43
lnxmenI am trying to set up fully working mail server with GUI.14:43
lnxmenBut I always read tutorials before executing commands.14:44
bekksWith GUI?14:45
bekksWhat do you need a GUI for on a mail server?14:45
gblfxtlike squirrelmail?14:45
bekksThats no "GUI" fpr a mailserver.14:46
bekksThats a webbased mail user agent.14:46
gblfxtyah, mta on squirrelmail is madness!14:46
gblfxtim not sure you want a mta at all14:46
lnxmenbekks: roundcube?14:57
bekkslnxmen: ?14:57
bekksA full sentence would be helpful when asking questions :)14:57
lnxmenYou asked "What do you need a GUI for on a mail server?"14:59
lnxmenI don't know if it's a GUI for mail server itself.14:59
bekksNo.15:00
lnxmenOkay. Is that hm... web based user agent?15:00
lnxmenGenerally, you know what I want.15:01
bekksBasically, yes.15:01
bekksNo, we dont know that.15:01
bekksDo you want a webbased mail user agent or do you want to administer your mailserver graphically?15:01
lnxmenthat first15:01
ubuntuaddictedtime appropriate greetings15:01
lnxmenSorry, for my mistake.15:02
bekkslnxmen: "that first" is an invalid answer to a question containing "or" :)15:02
lnxmenthis *15:02
bekksubuntuaddicted: time appropriate greetings back15:02
ubuntuaddictedi have a LAMP server running (Ubuntu) and I don't want mythweb to be the default web page. can anyone help me figure out why when I go to http://localhost that it takes me automagically to mythweb?15:02
lnxmenbekks: As you can see, English is not my native language. I need to polish it up.15:03
ubuntuaddictedi have multiple sites now, like owncloud and phpmyadmin so I think i just need to adjust some conf file but not sure which one15:04
bekksubuntuaddicted: What else do you want to be the start page? :)15:04
ubuntuaddictedbekks, i suppose just some dumb text file that says, welcome to ubu's server15:06
lnxmenCheck /etc/apache2/sites-available/000-default.conf15:06
bekksubuntuaddicted: And what is the actual goal behind that?15:06
ubuntuaddictedbekks, the goal would be because people "may" find out my IP, i don't want it to auto show them what i have running15:07
gblfxtno goal! https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&sqi=2&ved=0CB4QFjAA&url=http%3A%2F%2Fpatorjk.com%2Fsoftware%2Ftaag%2F&ei=PkCxVIvmE8nkoASx3ILwAQ&usg=AFQjCNGzACLjDY01jvntK_b3Sw2iXHqHQA&sig2=IJYf-mMEnsvovxM1V3R0LA15:08
bekksubuntuaddicted: are you running that on a server in the internet - or at home?15:08
gblfxtterrible link, patorjk.com/software/taag/15:08
ubuntuaddictedbekks, um, both.15:09
ubuntuaddictedbekks, i have a linode server and i have a home server15:09
bekksubuntuaddicted: And both are running mythtv?15:09
bekksWhich server are you talking about, actually?15:09
ubuntuaddictedbekks, no sorry, only the home one is15:09
ubuntuaddictedim talking about my home server15:09
lnxmena2dissite 000-default.conf?15:10
bekksSo unless you deliberately enable port forwarding in your router, your home network will not be exposed to the outside world. No need to worry.15:10
ubuntuaddictedi found 000-default-mythbuntu.conf. thanks guys15:10
ubuntuaddictedbekks, i am forwarding port 80 for my owncloud server15:10
bekksYou arent.15:10
bekksI just tried ;)15:10
ubuntuaddictedbekks, not yet. lol15:11
bekksYou dont expose anything to the internet at all - no need to worry.15:11
ubuntuaddictedbekks, understood but i am exposing owncloud to the internet.15:12
ubuntuaddictedbekks, try again15:12
ubuntuaddictedif you want15:12
bekks"Internal Server Error".15:12
ubuntuaddictednot sure what you mean. im in my lan and mythweb works. what are you attempting to access may i ask?15:13
ubuntuaddictedthere may be a DNS entabglement because i'm in the process of doing a lot of things15:14
ubuntuaddicted*dns conflict15:14
ubuntuaddictedownloud doesn't work and i know that. but mythweb "should" be working15:14
bekksubuntuaddicted: I am just trying to access port 80 of the IP I can see for you.15:14
ubuntuaddictedcan you PM me the IP you think i am please15:15
bekksubuntuaddicted: I am just using the address shown by "/whois ubuntuaddicted"15:17
ubuntuaddictedbekks, nmap -P0 to my home IP shows port 80 open15:17
bekksBut either you misconfigured your portforwarding or you broke your webserver setup.15:18
ubuntuaddictedwhat's the ubuntu package for apache2 and mod_auth_host?15:22
bekksubuntuaddicted: No package needed, but some more configuration needed: http://httpd.apache.org/docs/2.4/howto/access.html15:23
=== unreal_ is now known as unreal
ubuntuaddictedbekks, ok, i'm using Allow from localhost for mythweb15:24
bekksAnd you have to deny all the rest :)15:24
ubuntuaddictedbekks, i guess i'm a little confused by apache2 and virtual websesrvers15:25
ubuntuaddictedbekks, i have Order allow,deny first15:25
bekksThen you should not expose anything to the internet before you get all that working.15:25
ubuntuaddictedbekks, agreed. thanks for the top15:26
ubuntuaddicted*tip15:26
ubuntuaddictedbekks, as you found out, i wasn't forwarding port 80. :)15:26
bekks:P15:26
ubuntuaddictedthanks for the help15:27
ubuntuaddictedim in the process of switching from .htaccess to htdigest and it's fun.15:27
ubuntuaddicted*ssarcasm15:27
ubuntuaddictedbekks, i thought ubuntu had some file for default It Works. that's what i remember years ago when I setup my first LAMP server15:28
streulmaUbuntu Server hangs in boot15:32
streulmamaybe root-device not found?15:32
streulmahangs after Freeing Initrd memory15:33
=== ValicekB_ is now known as ValicekB
bekksubuntuaddicted: And what are you trying to achieve, actually?15:42
bekksstreulma: Try booting without "quiet splash" kernel options.15:43
streulmabekks, that he does15:43
streulmabut gangs15:43
streulmahangs15:44
streulmaI did an fsck15:44
streulmaand tons off Illegal blocks15:44
streulmaand inodes setting to 015:44
streulmathere was a power cut15:44
streulmaon vps15:44
streulmathe data is on storage server15:44
ubuntuaddictedbekks, host owncloud for collaborating with the my global clients, host a jitsi videobridge for global HD video conferencing, and be able to access my mythtv server from the WAN. for now.15:46
udit_how to create empty .crt file in ubuntu 14.04 x6415:51
bekksubuntuaddicted: So whats your downstream/upstream bandwidth, just for my curiousity?15:54
bekksudit_: An empty certificate?15:55
ubuntuaddictedbekks, 30Mbps/5Mbps for livestreaming to youtube and hitbox (undefined for when i move my nginx server to a datacenter) and another line that's 2Mbps/5Mbps for ubucraft15:56
udit_yes after creating file i enter the code15:56
udit_using nano15:57
udit_please help me15:57
bekksudit_: I am not interested in your internet server's bandwidth :)15:57
ubuntuaddictedbekks, i have a lot going on so the answer isn't so straight forward15:57
bekksudit_: But 5MBit/s only for "global clients" and "video conferencing" is pretty low.15:57
bekksubuntuaddicted: You have only one interbnet access at home, do you? So that question is answered very easily.15:58
streulmabekks 60/6 !15:58
ubuntuaddictedbekks, it's enough for plenty of people where they send a 640x360 h264 stream to me15:58
streulmabekks: the most I must can from provider is 30 :D15:58
ubuntuaddictedbekks, i have 2 internet lines15:58
udit_please anybody tell me how to create empty .crt file in ubuntu 14.04 x6415:58
bekksudit_: "touch filename.crt"15:59
ubuntuaddictedudit_, touch foo.crt15:59
bekksudit_: What are you actually trying to achieve?15:59
ubuntuaddictedudit_, it's probably best if you link us to the tutorial you're following so we have some context and can better help15:59
udit_i am try to setup ssl16:00
udit_comodo ssl16:00
bekksudit_: Then you dont need an empty certificate, but a valid one.16:00
udit_after creating empty certificate i add the code that given by comodo16:01
bekksWhich sounds broken.16:01
bekksA valid certificate doesnt contain "code".16:01
udit_-----BEGIN CERTIFICATE----- +Q8FADiZNjui9DdjeHmWAeSIRGa0lGMw35VPqPUznBQYFf0wuLFTGD4XLzubTuq yITyO4WKdYenOvj5mRfLoca5ZGKtetmwfij1g+fsJAvdatViSuLdc/ZaQcgIyN0h 3WzFl9vVztDXoKKScjvJH3dy6AA22+zsApT3rnRBAjHzsbW0Vw+/HIIXYUxUohSJ wnG9IHhUrsYWUXbdbrDhKS+FTn/z31UaWyLqhGkXj42pQhvyeMvfGag6FgRYe52M howCzdiK6HnItuCI3inB8qV1zVkaJLsCAwEAAaOCAeEwggHdMB8GA1UdIwQYMBaA FJCvajqUWgvYkOoSVnPfQ7Q6KNrnMB0GA1UdDgQWBBROlpwFyEog46GdOrB370Q3 G3ZhVzAOBgNVHQ816:03
udit_code is look like this16:03
ubuntuaddictedudit_, just my opinion, but posting your certificate on irc isn't a good idea16:04
udit_how i create mydomain_com.crt file and add this code inside it ? and the file should be in this /etc/nginx/ssl/16:06
udit_thanks but i don't add the full code16:06
udit_this is the small part of code16:07
udit_please tell me how i do it that16:09
bekksOpen an editor, insert that certificate, and save it as your desired file.16:11
bekksNo need to create an "empty .crt" before.16:11
mucusbam, here i am!18:15
mucusmy server was hacked early this morning! :(  so i nuked it and am starting fresh! :)18:15
mucuswhat can i do to make sure my new install is real securelike?18:15
Patrickdkdon't turn it on18:16
mucusi didn't18:16
PatrickdkI mean, the new one18:16
mucus-_-18:16
Patrickdkthe moment you power on a system, it's insecure18:17
mucusbarring that18:17
Patrickdkthe moment you plug in a network cable, it's less secure18:17
Patrickdkdon't run a webserver or any other service on it?18:17
Patrickdkthe more stuff you open, the more insecure it is18:17
Patrickdkthe more software you have to check and lock down18:17
mucusnow let's suppose i /do/ want to host some servers on it.18:17
Patrickdklike what?18:18
Patrickdkwe could spend the next 3 years securing your server18:18
mucusi want to run a mc server, forum/website software currently18:19
Patrickdkisn't mc closed source? no way to secure that18:19
Patrickdkthe best you can do is chroot it, apparmor it, and anything else you can do18:20
Patrickdksame really for a forum/website18:20
Patrickdkit won't stop any of those from being hacked18:20
Patrickdkbut should contain it, assuming you do update your server, and don't leave an exposed local priv escelation vaunerability unpatched.18:21
mucushm18:22
mucuscan't i create a virtual machine on the server and host my mc server there?18:23
mucusso even if someone gets in through it there's little they can do to truly muck me up?18:23
Patrickdkassuming your server supports it18:23
Patrickdkand that still doesn't close or stop soemthing inside the vm hacking into the host still18:23
Patrickdkjust changes the paths of vaunerability to do it18:23
mucusi'm rather dense, and very green to all linux.18:23
mucushow's the lightest way to create a vm instance?18:24
mucuslightest/best/more secure18:24
mucusone or more of those options18:24
=== radius is now known as rafk
=== unreal_ is now known as unreal
pmatulismucus: maybe start with LXC containers18:59
mucusthanks!19:00
ubuntuaddictedPatrickdk, i just noticed your comment about not turning on a server if they want it secure. that's funny as hell and made my day19:01
mucusi also thought it was clever19:02
ubuntuaddictedmucus, im familiar with hosting mc. i'm the owner of ubucraft19:02
ubuntuaddictedowner, creator, the man. ;)19:02
mucusi'm starting a small roleplay server19:02
ubuntuaddictedmucus, ah cool19:03
mucusand setting it up to be unlike vanilla minecraft19:03
mucuswhat with dirt taking 7 minutes to break by hand19:03
mucusand swimming not getting you across large bodies of water19:03
mucusand other stuff19:03
ubuntuaddictedwant to hop into my murmur server or teamspeak server to chat about it?19:03
mucusi dislike voice chat very much19:03
ubuntuaddictedtext chat is so archaic but ok19:03
mucustext chat is newer than voice chat.19:04
ubuntuaddictedsince it's very specific, maybe we should go into a private room?19:04
ubuntuaddictedno19:04
ubuntuaddictedwe've been writing on walls since before caveman. lol19:04
mucuswe've been grunting since before writing19:05
ubuntuaddictedxD19:05
Patrickdknot sure about that19:05
ubuntuaddictedim a realist. sometime too much so19:05
bekksSome people still grunt :P19:05
mucusi still grunt19:05
bekks^19:05
ubuntuaddictedsadly that's true.19:05
ubuntuaddicted"some people still grunt" i was referring too.19:06
ubuntuaddictedmucus, anyway, so you want to host a spigot server on ubutnu 14.04.1?19:06
mucusi was already hosting spigot on 14.1019:07
ubuntuaddictedi would already suggest against that because 14.10 isn't an LTS release but that's just my opinion19:08
mucusah19:08
ubuntuaddictednot to mention, depends what settings you have for apt on whether you break your server19:09
RoyKmucus: kvm vm's aren't very heavy19:10
bekksDepends on the config.19:11
mucusRoyK i'm liking the concept of these lxc containers19:11
RoyKmucus: you do until you try to make something like an nfs server19:11
mucusi don't even know what an nfs server is19:11
RoyKthen that's not a problem ;)19:12
RoyKsince the kernel is shared on lxc, not all things work as planned19:12
RoyKI just use KVM19:12
RoyKor vmware at work19:12
RoyKit's a little more overhead for real virtualisation, but IMHO it's worth it, the isolation is total19:13
ubuntuaddictedRoyK, lxc, where is this? i need this in my life. :)19:39
Patrickdklike on every linux kernel for awhile now :)19:41
=== rafk is now known as radius
thor77hi, i want to use this (https://github.com/munin-monitoring/contrib/blob/master/plugins/nginx/nginx_vhost_traffic) munin-plugin, but for this to work, the munin-user needs to read this files, what's the easiest way to achieve that? current file-permissions: http://paste.ubuntu.com/9707429/20:31
thor77*the munin-user needs to read the nginx-log-files20:32
Patrickdkmunin-user should NEVER had to read that20:39
Patrickdkjust fix your plugins20:39
Patrickdkyou DO know how to USE munin right?20:39
thor77no20:40
thor77its not my plugin20:40
thor77this plugin cant work without the nginx-logfiles20:40
thor77what do you mean with "use munin right"?20:41
pmatulisa toast to those who grunt21:43
mucusgrng21:43
am11hello, is there a list which tells which version of Ubuntu (or any linux distro) corresponds to which *default* version of toolchain (gcc, g++,gcc-c++, glibc)?21:54
RoyKam11: guess not22:02
RoyKam11: most distros update their gcc* things regularly22:02
am11RoyK: I am particualy looking for Ubuntu which is bind to gcc v4.5.x.22:03
RoyKhm... debian wheezy is at gcc 4.722:03
am11The requirement is v4.5.x. Our code does not compile below it.22:04
RoyKubuntu 14.04 is at 4.822:04
am11Yes! which will defeat the purpose. The binary wouldn't run with old glibcs.22:05
RoyKseems ubuntu 12.04 is at gcc 4.622:05
mucuswhat is gcc?22:05
RoyKmucus: the compiler22:05
bekksmucus: GNU compiler collection22:05
mucusthank you22:05
RoyKam11: guess 4.5 should be quite safe with most distros22:06
RoyKunless you're in redhat/centos land where rhel6 uses 4.422:06
am11RoyK: we need to compile with minimum possible version, which is 4.5. And changing the gcc version is a real PITA. (except for if you are using fedora mock: http://fedoraproject.org/wiki/Using_Mock_to_test_package_builds  which doesn't have 4.5 either)22:07
RoyKbut then, i guess rhel7 etc uses newer stuff22:07
RoyKI use RHEL/CentOS a lot at work22:08
RoyKbut I don't like it :P22:08
am11RoyK: we have a nodejs parckage, which has C++ addon. so before publishing our npm we compile the binaries. For windows, VS2013 just do fine. For Mac, the univeral binaries. On linux however, if we build with glibc/gcc/g++/gcc-c++ later versions, it doesn't provide backward compat. So we need to compile with minimum version of glibc, which doesn't have problem with C++11 code we are22:11
am11using as well as provide massive coverage (especially servers running old CentOS 5.5, 6 etc.)22:11
am11last time we had to make alot of changes in the code to compile with gcc 4.4.7. Now we are confirmed that the minimum compiler requirement is v4.5, so i cannot find any distributn which has 4.5. It is either 4.4.7 or 4.6+. :)22:13
am11That is the entirety of my sad story.22:13
RoyK5<6, so 4.6 should do22:13
RoyKwhat sort of software is this?22:14
am114.8 can also do it! but that wont work on older OSes22:14
RoyK4.6 is rather old22:15
RoyKso it should work with most distros22:15
am11which means, there is no linux distribution which has gcc 4.5 without going to lengths of trouble to downgrade or upgrade or mock gcc.22:16
RoyKredhat/centos 6 has gcc 4.422:17
RoyKand there's a lot of installed machines on those OSes22:18
RoyKsupporting RHEL/CentOS 5 shouldn't be primary22:19
RoyKrhel5 will last another year before support ends22:19
RoyKomg, we've been infected by Stuxnet!22:20
bekksRHEL5 supports ends in 2017 :)22:21
StuxnetThis is not really a server specific question but if I've uninstalled a package why would the service still be listed in /etc/init.d? (albeit with a22:27
Stuxnet[?] status22:27
StuxnetDo i need to purge it?22:27
Stuxnetnvm just answered my own question.22:28
=== guampa_ is now known as guampa
xperiahi all. i have this iptables line => iptables -I INPUT -p tcp -m multiport --dports all -j myipchan that gives me this error message iptables v1.4.21: invalid port/service `all' specified23:44
xperiahow can i fix that so i am still able to block all traffic from a ip adress on all ports with iptables ?23:44
=== bilde2910 is now known as bilde2910|away
bekksBlock the IP.23:53
bekksYou dont have to specify any ports.23:53

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!