/srv/irclogs.ubuntu.com/2015/01/14/#ubuntu-server.txt

=== martins-afk is now known as martinst
=== martinst is now known as martins-afk
=== Guest85585 is now known as mfisch
=== zz_DenBeiren is now known as DenBeiren
=== _thumper_ is now known as thumper
=== markthomas|away is now known as markthomas
=== markthomas is now known as markthomas|away
cyclobshi all, I'm trying to do something which i'm not sure is entirely possible with pam authing against an mysql database. Is it possible to have pam run the plain text passwords into a hashing script that i made before it gets checked against the mysql database?06:38
sarnoldcyclobs: you may be able to get pam_exec to do it, but I'd be scared about doing it myself06:48
sarnoldcyclobs: I'd be more inclined to take pam_userdb or a similar module and see if you can slightly modify it06:49
cyclobsah pam_exec might do what i'm looking for. the next option really is to edit the source and add my own crypt function06:50
=== kickinz1|afk is now known as kickinz1
=== Lcawte|Away is now known as Lcawte
=== Lcawte is now known as Lcawte|Away
=== kickinz1 is now known as kickinz1|afk
=== kickinz1|afk is now known as kickinz1
lordievaderGood morning.08:58
stemidI patched a precise server last monday, january 5th, and for some reason the patching left me without the directory /opt/tivoli. this dir completely vanished and of course all TSM related services stopped working.09:00
stemiddiscovered it now.09:00
stemiddid anyone else notice this?09:00
=== Lcawte|Away is now known as Lcawte
=== Lcawte is now known as Lcawte|Away
=== Lcawte|Away is now known as Lcawte
=== Lcawte is now known as Lcawte|Away
^^rcaskeyhey all, the interactive menus on -server are just too tough for me to figure out, can I instead download the configuration options via http via some kind of argument passed by dhcp?13:30
tehgoochSo I've got a client with Ubuntu Server 12.04 that hangs on boot. Last think on console is the e1000 NIC showing up. There is an error about remounting / earlier in the boot, but it continues to boot. Initially there wad an error about the encrypted swap so I commented it out in rescue mode and formatted it as regular swap. I'm sure I left details out feel free to ask. I'm on my phone at the console.13:33
tehgoochLast thing in dmesg is saying eth0 link not ready13:36
=== schrodinger_ is now known as schrodinger
=== Lcawte|Away is now known as Lcawte
AdventureTimeHello everyone14:06
=== jdstrand_ is now known as jdstrand
AdventureTimeI badly need help.14:06
collizionAdventureTime: What's up?14:12
AdventureTimeOh thanks. Well, I was just wondering what happened with this server. Why the php5-cgi has a high usage. Is it because of the 15,000+ visitors everyday? Here are the screenshots http://imgur.com/a/FSnGc and the specs of the server: http://www.serverloft.eu/rootservers/rootservers-compare.php?server=RootServer-L14:13
collizionAdventureTime: Depends on how PHP-heavy your application is.14:16
AdventureTimeIt uses Wordpress with MySQL.14:17
AdventureTimeI’m thinking of upgrading to a newer distro but people from reddit said I better not upgrade to a newer distro, instead do a fresh install.14:17
jamespagecoreycb, zul: we'll need todo a no-change rebuild on most openstack packages - I just fixed a problem with the upstart configuration generation14:17
collizionAdventureTime: What distro are you running at the moment? And "nuke and pave" is not always the best solution.14:19
AdventureTimeI don’t understand what “nuke and pave” is.14:19
AdventureTimeI think it is the LTS Ubuntu v1014:19
collizionAdventureTime: It's an Americanism for completely wiping out what's there and reinstalling a fresh system.14:25
collizionAdventureTime: Ubuntu 10.04 LTS?14:25
AdventureTimeYes, that is correct. Oh thanks for the FYI :)14:25
coreycbjamespage, ok14:29
collizionAdventureTime: If you're running a version THAT old, then a full reinstall might be a good idea.14:30
coreycbjamespage, want me to handle them?14:30
jamespagecoreycb, sure - I'm working on neutron so stay clear of that one - but all others +1 that would be great14:30
AdventureTimeOh, sorry. They can’t afford a downtime. The site is fully functional.14:30
coreycbjamespage, ok will do.14:30
AdventureTimeThey are just concerned with the memory usage/processor usage.14:31
collizionAdventureTime: I'd look at optimizing the application itself. What are you running? Wordpress, Drupal, etc?14:35
AdventureTimejust wordpress14:36
AdventureTimeso this is not a server issue?14:36
AdventureTimedid you see the screenshots14:36
collizionAdventureTime: It may not be. Just because you see high CPU usage in php doesn't mean it's a server problem. There could be something in the actual application itself generating that activity.14:37
AdventureTimebut disabling the plugins in a production server will procude a  downtime. the owner of the site does not want that :(14:37
collizionAdventureTime: I hate to be blunt about this, but... tough? You've got a problem. That requires maintenance.14:38
collizionAdventureTime: You've also got the problem that 10.04 goes EOL in three months. You won't receive security updates after that, which is a Bad Thing for a web server.14:38
collizion(Someone else please back me up on that. EOL means no more security updates, right?)14:39
maswanyeah14:39
collizionThanks.14:39
AdventureTimeholy crap14:40
AdventureTimeso downtime is needed?14:40
maswanor install a new server, and then move over the laod14:40
AdventureTimeyeah but they use Plesk.14:55
=== rcj is now known as Guest58400
coreycbjamespage, can I get a +1 on this before moving on to the rest?  https://code.launchpad.net/~corey.bryant/ceilometer/2015.1-b1-0ubuntu4/+merge/24643715:18
jamespagecoreycb, I'd be tempted to bump the version dependency on openstack-pkg-tools  to 21ubuntu6~15:18
jamespagethat will make sure you get the fix irrespective of the order in which things are built15:18
coreycbjamespage, good point, will do15:19
coreycbjamespage, I'm seeing 21ubuntu5~ as the latest15:22
jamespagecoreycb, yep that's the one15:24
coreycbjamespage, k15:24
=== Lcawte is now known as Lcawte|Away
=== marrusl_ is now known as marrusl_really
AdventureTimedo i have to install centos now?15:32
AdventureTimeor debian maybe?15:32
collizionAdventureTime: If you like Ubuntu, use Ubuntu.15:32
collizionJust use a current version.15:33
=== bilde2910|away is now known as bilde2910
=== Guest58400 is now known as rcj
coreycbjamespage, mp's for upstart generation rebuilds - http://pastebin.ubuntu.com/9749470/16:12
jamespagecoreycb, ok most of those done16:30
jamespagesahara we can skip as its not built yet...16:30
coreycbjamespage, ok thanks16:32
jamespagecoreycb, btw the cinder disabling of SSL based tests patch could be reworked to make them pass as I did for neutron16:33
coreycbjamespage, ok I can do that16:34
jamespagecoreycb, https://review.openstack.org/#/c/145208/16:34
jcastrojamespage, this seem right? http://askubuntu.com/questions/573761/error-instaling-openstack-with-juju-due-to-kvm-ok-not-being-installed/57376616:46
rbasakjcastro: good shout that KVM will need to work inside there. But I don't think that failure would cause that error message. He should have kvm-ok installed OK and then see kvm-ok fail if that were the case.16:49
rbasakjcastro: sounds like a bug or at least a use case that should be investigated.16:49
justus_Hello everybody, I have a question concerning networking and routing. I have a vpn connection running on one machine. Now i want to connect 3 other machines to route all their traffic through the machine with the vpn running...16:50
jcastrorbasak, indeed16:52
jcastrorbasak, any idea which package I should file that bug in?16:53
justus_has anyone experience with routing or ip-forwarding?16:53
rbasakjcastro: I'm not sure. Is that the cloud-installer package he's using? I'd start there if so. It might need to be punted to Juju, but I'm not sure how it's setting up the local environment and that looks like the faulty bit.16:54
rbasaktych0: ^^ can you help?16:55
jrwrenjustus_: if the vpn connected machine is not the default route for the lan, you don't have many options. You might get away with proxy arp, but typically you'd need your VPN endpoint to be default route or a route along the way.16:59
justus_jwren: thank you for the answer. Im not sure if I understood it correct. the target machine itself is running a vpn (it is not an endpoint), but it is still reachable by other machines from the same network. I just want the other machines from the same network to use this machine to connect to the internet so to say...17:01
jrwrenjustus_: you would need to change the default route on all those machines to be that vpn machine. It gets tricky, because that machine would then need to know to route for that subnet. Basically, this is not how ip routing works ;(17:06
jrwrenjustus_: it becomes easy if your node that is already your default route is the same node which does the VPN connection.17:07
justus_jrwren: it is not possible to run the vpn on the already configure default route. Do you think an ssh tunnel would be an easier solution? I thought it would be easy to setup a machine, to just channel all incoming and outgoing traffic :/17:11
jrwrenjustus_: maybe we think different things are easy :)17:11
jrwrenjustus_: if you have limited services you are accessing, ssh tunnels might be easier, yes.17:12
justus_jrwren: hehe ^^ I actually have no clue about ip routing, but I am here to learn :)17:12
justus_jrwren: ok, the only problem i was having with an ssh tunnel was that it was not as stable as i might have wished. And as I do not need the traffic to be encrypted I thought there might be a better solution...17:13
jrwrenjustus_: no need for encryption? In that case, can you use ipv6 at both sides? :)17:14
=== markthomas|away is now known as markthomas
justus_yes17:15
justus_jwren: yes17:15
justus_jrwren: yes (now i got it right...)17:16
jrwrenjustus_: then do that and you are done. :)17:16
justus_jrwren: do what? ^^17:16
jrwrenjustus_: use ipv6.17:16
justus_jrwren: how can i use ipv6 to route traffic from one machine to another?17:18
jrwrenjustus_: public ipv6. They should already have routes. That is the luxury of ipv6, there is no nat.17:19
jrwrenjustus_: I should have asked, do you have public ipv6.17:19
justus_I actually have public ipv4 addresses17:20
jrwrenjustus_: ah, ok, nevermind.17:20
jrwrenjustus_: do you control LAN at both sides of the connection?17:20
justus_jrwren: i only control the machines17:20
jrwrenjustus_: in that case, maybe each machine could connect to VPN?17:21
justus_jrwren: yes that is the actual problem :/ only one machine can connect to the vpn. that is the only reason why i want the other machines to use this machine to connect to the internet17:22
jrwrenjustus_: I see. I think it is possible with some tricks.17:22
jrwrenjustus_: you want all traffic to go through VPN, or only to certain subnet?17:22
justus_jrwren: I still need to be able to log into the machine via ssh. but that is already configured in the routes if that is sufficient17:23
X123Greetings17:25
X123I'm trying to track down some weird tcp stalling on initial connections.17:26
X123Has anyone seen an issue with that and 3.13+ kernel?17:26
X123(example ssh to 127.0.0.1 and put in password, and then it hangs for a minute and sometimes goes through and sometimes resets)17:27
X123same with http requests17:28
jrwrenX123: is dns resolving quickly? is localhost in /etc/hosts and getting used?17:29
X123yeah17:29
X123that wouldn't stall curls to 127.0.0.1 though17:30
jrwrenX123: you'd be surprised :)17:30
X123it only does it on 3.13+ kernel though lol17:30
X123hrm17:33
X123I'm also noticing that i can't open a listen socket17:34
X123basically rebooting the machine, there's no problem at all for 5-10 mins17:34
X123then the problem happens, and i can't even start a new service listening on a port17:35
X123and almost all connections hang forever before connecting, or they get reset after a while17:35
X123(Broken pipe, reset by peer)17:35
X123if i kill a bunch of processes that are listening on ports, i can then start the process that i was trying to start before and it listens17:35
X123but the delay /reset is still there17:36
tych0rbasak: jcastro: stokachu: just saw this; stokatchu is probably the right guy to help17:36
X123something is whacked with 3.13+ :)17:36
X123anyone else seeing this?17:38
X1231:~# ssh ::1 root@::1's password: Write failed: Broken pipe17:40
rbasakThanks tych0. I wasn't sure.17:40
tych0rbasak: sure, np17:45
X123sure is quiet in here :>17:59
ertyihello there18:13
ertyianyone tested with iscsi features ?18:13
k2gremlinAnyone around that runs a squid3 proxy transparent on ubuntu server?18:21
numkemwhat is the proper way of reload /etc/sysctl.conf and /etc/sysctl.d/ ?18:26
numkemthere is a file in /etc/sysctl.d/ that talks about using the procps service. But the service doesn't start, just says stopped18:27
lnxmenHello.18:28
lnxmenCould anyone help me with mail server configuration?18:28
lnxmenI can't send email to my domain from GMail.18:28
lnxmenrelay=local, delay=0.08, delays=0.05/0/0/0.03, dsn=5.1.1, status=bounced (unknown user: "admin")18:28
numkemlnxmen: do you have a user with that name or with that alias?18:29
lnxmenI created admin@domain.com in ispconfig18:29
lnxmennumkem: So I have an alias.18:29
numkemcan you send it locally?18:29
lnxmenI will check.18:30
lnxmennumkem: No, I can't18:31
lnxmenThe same error.18:31
numkemlnxmen: have you tried doing a newaliases or something along that? I think you problem is the aliases aren't fresh18:33
numkemispconfig is some kind of webmin correct?18:34
lnxmenYes, something like that.18:34
lnxmenI tried doing new ones.18:34
lnxmenBut I want to create mailboxes rather than store everything on one account.18:35
lnxmenA z tym na razie ciężko. ;<18:35
lnxmenUops, sorry.18:35
numkemI really don't know how your setup is like mta and such or it's configuration if you did it with ispconfig18:38
numkemsomething that is rather standard is to have unix accounts as mailbox users too18:39
k2gremlinSquid3 transparent on Ubuntu 14 anyone?18:39
lnxmennumkem: It's mail server for site support.18:40
numkembut there is a millions way of configurating the mta18:40
jrwrenk2gremlin: i've used squid. Do you have a specific question?18:41
lnxmennumkem: Is there any file I can paste to let you know how mta is configured?18:43
numkemlnxmen: a list of your processes would be a good start18:45
lnxmenI'll find postfix, dovecot...18:45
k2gremlinjrwren, Im trying to setup a transparent squid. Right now I have a VM with squid running in non transparent.18:45
k2gremlinIm making another VM using 2 OTHER vswitches connected to 2 other physical ports.18:46
k2gremlin1 of those ports is connected to a test laptop. the other port is connected on my normal router18:46
k2gremlinThe part I can't for the life of me figure out is the iptables crap18:47
k2gremlinjrwren, I tried following this... http://ubuntuserverguide.com/2012/06/how-to-setup-squid3-as-transparent-proxy-on-ubuntu-server-12-04.html18:47
jrwrenk2gremlin: you need to run the iptables rules on your default gateway for it to be transparent.18:49
k2gremlinCan't this server be the gateway for the lan?18:50
jrwrenk2gremlin: maybe it could. you'd need to configure it correctly.18:50
k2gremlinjrwren, and therein lies the problem... me and iptables have never worked lol18:50
jrwrenk2gremlin: :)  because packets are never getting to that VM running squid.18:51
k2gremlinjrwren, well they are.18:51
jrwrenk2gremlin: how?18:51
k2gremlinMy outside is 192.168.1.0   and the LAN side is 192.168.2.018:52
k2gremlinsec ill pastebin my network/infaces file18:52
k2gremlinjrwren, http://pastebin.com/bTkXECSD18:53
k2gremlinso the laptop is connected to eth0 directly.18:54
jrwrenk2gremlin: and you want trasparent to work only for the laptop?18:54
k2gremlinwell this is just a test enviorment. Once I get it working... my router with all clients will be moved to that port18:55
k2gremlinand the eth1 port will plug into my cable modem18:55
k2gremlinif that makes sense18:55
jrwrenk2gremlin: sure. these are test nets.18:55
k2gremlincorrect. Ill probably leave the client net on 192.168.2.0, but the outside net will change to match my ISP18:56
k2gremlinEth1 will probably need to change to dhcp as I don't own a static IP18:56
k2gremlin(home network) lol18:56
jrwrenk2gremlin: lets say your laptop is 192.168.1.31. How is a connect request to 192.0.2.0:80 going to get to this VM running squid?18:56
k2gremlinthe laptop is 192.168.2.218:57
k2gremlinerr 2.1018:57
k2gremlinbut still18:57
jrwrenok, same question :)18:57
k2gremlinit is directly connected to the Eth0 interface on the server18:57
jrwrenk2gremlin: can it talk to anything? because it really shouldn't be able to.18:57
k2gremlinEth0 is on the VM running squid18:57
k2gremlinOk right now, all I have configured on the VM is...18:58
k2gremlinthose 2 interfaces...18:58
jrwrenk2gremlin: how does DNS even work on laptop then?18:58
k2gremlinidk yet.. lol18:58
jrwrenk2gremlin: I see.18:58
k2gremlinBut basic install atm18:58
k2gremlinnics are setup and squid3 is in with initial install18:59
k2gremlinWhen I try to goto google.com, I get the squid3 block page18:59
jrwrenk2gremlin: transparent squid doesn't substitute the need for working inet. Still need basic ipv4 for DNS and connectivity to that squid host.18:59
k2gremlinwhich is expected18:59
jrwrenI'd not expect that give the config you have described as I understand it.18:59
k2gremlinill draw a visio up... maybe that will help18:59
jrwrenk2gremlin: it may help to describe everything and maybe ask on askubuntu.com18:59
k2gremlinok18:59
RoyKk2gremlin: look at the acl entries in /etc/squid3/squid.conf19:00
jrwrenk2gremlin: also, a lot of us don't have access to visio, so maybe draw it in text :)19:01
k2gremlinRoyK, I know squid really well. I tried a VM 2 days ago and setup the ACL's and such in squid. once it's past the rules in squid the http requests die lol19:01
k2gremlinjrwren, I screen shot the visio :)19:01
k2gremlin1 sec19:01
sarnoldRoyK: jeeze the other day I wasted twenty minutes trying to figure out why my sed -i -e 's/anl.gov/pnl.gov/ for my apt sources failed19:02
sarnoldRoyK: it culminated in finding that I had previously set acls on squid for the hosts it would cache :)19:02
RoyKsarnold: hehehe19:03
k2gremlinjrwren, Ok the top is what I have right now for testing. The bottom is the end result I eventually want. http://puu.sh/ew2LH/59f97f043e.png19:07
jrwrenk2gremlin: I don't think it is possible the way you have documented it.19:08
k2gremlinWHOA...19:09
k2gremlinI set the acl for src 192.168.2.0/2419:09
k2gremlinand allow http_access for that acl19:09
k2gremlinit worked..19:09
k2gremlinNOTHING is configured for IP tables19:09
k2gremlinlet me make sure the laptop isnt directed at squid for a proxy19:10
k2gremlinshit it is19:10
k2gremlinlemme uncheck lol19:10
k2gremlinand connection fails lol19:10
k2gremlinSo I need IPtables to pull traffic from eth1 and force it to squid... then squid to redirect the traffic to eth 019:11
k2gremlinbut this is sort of working. Clients cant access the internet without having the proxy setup.19:11
jrwrenk2gremlin: sounds like you are almost there.19:11
k2gremlinMy current home setup, if the proxy isnt configre they go straight out to the net19:11
k2gremlinwhich I don't want them to be able to do.19:12
k2gremlinUltimatly, I want them to go through the proxy without having to configure the client19:12
=== martins-afk is now known as martinst
=== martinst is now known as martins-afk
lnxmen1numkem: https://www.linode.com/docs/email/postfix/email-with-postfix-dovecot-and-mysql20:09
lnxmen1I configured this server with this tutorial20:09
sarnoldutlemming: why do you attach your gpg key to every email message?20:26
dasjoeWhy should one trust a GPG key received in that way?20:28
sarnolddasjoe: well, in some sense, it's better than just requesting a key from the servers with a 32 bit keyid -- you can inspect the headers of the email and make sure that they look similar to previous emails from the sender, the purported sender can complain if seeing the mails on a public list..20:29
rbasakSign every email. Then the recipient doesn't need to inspect the headers - he can just verify that all previous emails were signed by the same key.20:30
rbasakThat pushes any possible MITM attack back to before the first email.20:31
sarnoldrbasak: hehe, yeah, I sometimes download a key from the servers with the 32 bit key id, filter mutt to show only messages from that person, and go verify a few dozen emails with it -- then lsign the thing :)20:33
sarnoldI wish mutt had some kind of interface to let me know when keys change or someone who always signs neglects to sign... but it's a start.20:33
keithzgHmm, I think I'm out of my depth in trying to limit the CPU usage of a libvirtd-run VM. I had assumed I could set a percentage or such, but in <cputune> one needs to set the <quota> in microseconds. I can't claim to have any idea of what a reasonable value would be!20:45
RoyKkeithzg: perhaps playing with cgroups could help?20:45
sarnoldkeithzg: you could set it to something like 750000 -- if it is measured per-second, as I expected, that'd be a 75% quota..20:46
keithzgRoyK: Probably, I guess I just assumed via the KVM settings would be the easier way to go.20:49
keithzgsarnold: Thanks, I'll give that a shot.20:49
keithzg(this is a VM that still runs a CVSNT server for people to go back and check from time to time, because nobody can be bothered to just find the equivalent commits in SVN I guess :P And CVSNT being CVSNT, it sometimes chews inexplicably high CPU time, making all the other VMs on the same host intermittently slow)20:50
sarnoldand it's not disk bandwidth?20:51
keithzgnaw, it's cvslockd jumping up to 100% CPU usage.20:54
keithzgAnd then it just sticks there until I retart either the lock daemon or, if I'm feeling lazy, the entire VM.20:54
sarnold*nod*20:56
sarnoldit probably needs the restart from time to time anyhow :)20:56
keithzgThat's what I tell myself at least ;)21:01
=== bilde2910 is now known as bilde2910|away
k2gremlinis there any reason an iptable command does not show up when I do iptables -L21:21
k2gremlinthe command I entered was "sudo iptables -t mangle -A PREROUTING -p tcp --dport 3128 -j DROP"21:21
tewardk2gremlin: different tables set21:23
k2gremlinYea I see now, iptables -L -t nat21:23
k2gremlinbut my proxy still not working lol21:23
k2gremlintrying to accept packets on one port... bring through the proxy, then forward to another port21:24
=== Lcawte|Away is now known as Lcawte
hoogeveeni'm trying to use a working OEL/redhat kickstart process, which uses NFS based ISO install tree for ubuntu and the ubuntu installer keeps barfing on a missing CD.21:30
hoogeveenis there a way of telling ubuntu to get its files from an NFS location instead of a local cd?21:31
hoogeveenthe doc for auto-install states that this is not supported: "Installation from an archive on a local hard disk or from an NFS archive. "21:31
hoogeveenbut this doc may be old.21:31
=== WilliamDotAT is now known as WilliamDotSI
hoogeveenthe installer has created a dir /var/spool/kickseed/fetch/nfs/A.B.C.D/export/linux/ks/hosts21:35
hoogeveenwhich sort of implies that it is attempting to do something, NFS-wise, since A.B.C.D is the IP of my kickstart server21:36
hoogeveenahhh, kickseed appears to be only the ks config file21:37
=== martins-afk is now known as martinst
=== martinst is now known as martins-afk
bekkshoogeveen: How does your kickstart file looks like? And how does your boot entry for booting off that kickstart file looks like?22:44
hoogeveenthe kickstart file contains an nfs line22:45
bekksPlease show us both files :)22:45
hoogeveenthe nfs line looks like this:22:46
hoogeveennfs --server=ni1central-228.us.oracle.com --dir=/export/linux/ubuntu/ubu14.04.1.tls22:46
hoogeveenthat is in the kickstart file22:46
AdventureTimethanks to the guy who helped me out! who ever you are, send me a pm so that i can talk you.22:46
hoogeveeni think you mean the command line for the kernel and that looks like:22:46
sarnoldare you confident that DNS works at that stage of boot?22:46
hoogeveenksdevice=eth0 ip=10.80.228.174 netmask=255.255.255.0 gateway=10.80.228.1 dns=192.135.82.132,130.35.249.41,130.35.249.52 ks=nfs:10.80.228.15:/export/linux/ks/hosts/tbrm-x86 load_ramdisk=1 initrd=pxelinux.cfg/ubu14.04.1.tls/initrd.gz network console=ttyS0,9600 BOOT_IMAGE=pxelinux.cfg/ubu14.04.1.tls/vmlinuz22:46
hoogeveenno, not with ubuntu, since it isn't working.  it works with redhat/oel22:47
hoogeveenhowever, i'm not getting dns errors, i'm getting "nothing loaded in cdrom" errors.22:47
sarnoldah, right22:47
hoogeveentwo different auto-install docs mention that nfs doesn't work for the pkgs and peole should use http instead.22:47
hoogeveenso, i wanted to verify that before i go down that road.22:47
hoogeveeni'm fairly sure that it is probably getting the kickstart file22:48
hoogeveenin that the log file mentions it.22:49
hoogeveenit is a little odd that the installer can nfs mount and fetch the ks.cfg file, but can't nfs mount and fetch a package.22:49
hoogeveeni'm not sure what the difference would be, unless it is just the front-end processing that is missing.22:50
hoogeveenthe nfs support *appears* to be there...22:50
hoogeveenbut, this is my first foray into network installs with nfs on ubuntu22:50
hoogeveenso i am quite unfamiliar with any restrictions that may be in place.22:50
hoogeveenother than the afore mentioned two documents on auto-install which counter indicate nfs & archives22:51
hoogeveendo you still want the contents of the ks.cfg file?22:51
=== optrusty is now known as optrusty|PING
bekkshoogeveen: That would be helpful too, yes.22:53
hoogeveenshould i paste it somewhere or splatter it here, getting bits of crap all over everyone?22:54
* hoogeveen is unfamiliar with this channle.22:54
hoogeveenor channel even22:54
sarnoldhoogeveen: generally pastebins are preferred if it's more than two or three lines22:54
hoogeveenok, i thought so.   wait a bit and i'll whip it up22:55
sarnoldpastebinit or wgetpaste can make it easier22:55
hoogeveennot familiar with those tools on solaris.22:55
hoogeveeni'm guessing that is either windows or linux22:55
hoogeveen269 lines22:55
sarnoldpastebinit requires python3, so it should be portable to solaris -- though if you don't already have python3 installed, it might be too much work22:57
hoogeveeni'll look for it later - thanks for the tip22:57
bekksYou can just upload it to a pastebin with your browser, too.22:58
cyclob|workHi all, can anyone point me into the direction of getting pam_mysql to use hsa512 passwords. Apparently it's supported but i can't find out where i can set it to use it22:58
hoogeveenare you ok with me eliding the post-install script?  that isn't really germane to this problem.22:58
cyclob|worksha512*22:58
sarnoldbekks: yeah but copy-paste is such a pain in the ass when it doesn't fit on one terminal window :)22:58
bekkssarnold: The even have a file selection button :P22:58
bekks*They22:59
sarnoldbekks: they do? hunh :)22:59
bekks:D22:59
hoogeveenhttp://pastebin.com/ab8kKNV223:02
hoogeveenthat is the kickstart minus the %post23:02
hoogeveenthis is the pxe file   http://pastebin.com/eHm5u18J23:05
hoogeveenhere they are, sarnold bekks23:07
sarnoldhoogeveen: sorry, I"ve never done kickstart myself :/23:09
sarnoldhoogeveen: nothing else stands out to me23:10
hoogeveenok.   i suspect that it isn't supported and that i should stand up a web server, but didn't really want to do that if i already had a full NFS install structure set up.23:10
sarnoldno kidding23:10
sarnoldNFS is just so easy by comparison23:10
hoogeveeni could unroll the initrd and putz around in there with getting the nfs mount point set up, but that seems like a bit more work than it may be worth23:11
* hoogeveen is unsure if sarnold has the sarcasm flag enabled....23:11
sarnoldhoogeveen: hehe, no, I don't much like how complicated webservers are23:11
bekksI just compared your settings against mine - and the only difference is that I'm actually using a http server for serving all files, instead of a NFS server.23:11
sarnoldhoogeveen: especially if yo'ure using zfs on a dataset, you probably just get to zfs export dataset ... and the damn thing just works :)23:12
bekksAnd setting up a webserver just for serving that stuff is pretty easy :)23:12
hoogeveenok, i think that you two, plus the people in #ubuntu who didn't know what i was talking about, plus the two docs, plus a couple of other people are enough of a quorum on this23:12
hoogeveenyup.23:12
hoogeveenzfs is nice23:12
hoogeveenwell, i live in a big corp, so there are sometimes.... let me say, complications to things like that.23:13
sarnoldoh, it'd be zfs share, not export, that's something else entirely. :) anyway, I wish there was a similarly easy way to do httpd. hehe.23:13
hoogeveenhopefully, i'll just be able to do the simple standup to share these out and be done with it.23:13
hoogeveenthanks for the eyeballs on this.23:13
sarnoldgood luck :)23:13
hoogeveenoh, one more question.  it looked like it was just http and not https23:13
hoogeveenis that correct?23:13
hoogeveenor was it just that the examples were http and https was implied?23:14
cyclob|workanyone know how how to get pam_mysql hashing with sha512?23:14
hoogeveenwe've been moving to all htpps internally lately23:14
sarnoldno idea, sorry; I suspect http, since the 's' part might be difficult to do correctly (trusted CAs, trusted date/time for boot, etc..)23:14
hoogeveenyeah, that can be a *big* can of worms.23:14
hoogeveenagain, thanks for taking the time to indulge me and talk to you later.23:14
sarnoldthe installer verifies signatures with gpg, so https has never been a big priority for anyone23:15
sarnolda pleasure hoogeveen :)23:15
bekks:)23:16
cyclob|workgrr. why am i getting permission denied when my user is in an webdev group with rwx permissions23:49
=== kickinz1 is now known as kickinz1|afk
cyclob|workoh right have to re-log to make the group take effect.23:52

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!