/srv/irclogs.ubuntu.com/2015/02/06/#ubuntu-server.txt

=== Lcawte is now known as Lcawte|Away
jorenHey, I'm trying debug my tftpd server but it seems to have stopped logging to syslog. I verified that the --verbose flag is set but I just can't figure out where it's logging to. anyone have any reccomendations?00:33
sarnoldjoren: check old rotated log files00:37
jorenI just tried running it with -L to stay in the foreground and still no output, I'm thinking my tftp requests might not be making it to the server which is why I'm not seeing any logs00:38
sarnoldtcpdump? :)00:39
joreneh, yeah, might come to that :P00:40
jorenI think the wrong darn dhcp server was running... ugh -_-00:45
PatrickdkI had a rather useless tcpdump today :(00:46
Patrickdktcpdump on client machine00:46
Patrickdkcan access one ip fine, but not another a few ip addresses away00:46
Patrickdkconnection starts, ssl kindof gets setup, then server keeps sending dup packets, cause it doesn't get an ack00:46
Patrickdksince tcpdump was running on the client, it is not an issue of the client ack getting lost, they didn't exist in the tcp dump00:47
Patrickdkthen like 50seconds later, some acks go out00:47
Patrickdkthen another 50seconds, it figured it all out, and fixed the mtu scaleback00:47
Patrickdkinsane, odd issue00:47
sarnold"50 seconds" sounds like spanning tree protocol pain00:48
Patrickdkwant to look at the dump?00:48
sarnoldnothanks :)00:48
Patrickdk:)00:48
Patrickdkit's not big :) thankfully00:48
* X123 specializes in odd issues00:49
Patrickdkspanning tree running on the clients win 8.1 desktop? :)00:49
sarnoldPatrickdk: ugh00:49
Patrickdkreally odd, and I doubt that dump is a proper sample of our real issue00:49
Patrickdkthat seems to be, likely, one of our clients got their domain *improperly* listed on virgins blacklist again00:50
Patrickdkthey keep thinking it's some porn site, no idea why00:50
sarnold.uk? :)00:51
Patrickdkuk, plus other random parts of eu too00:51
Patrickdkbut it seems virgin is the most *sensitive*00:51
pmatulisi think there's a joke in there somewhere00:56
joren"who-has es-pxe0" well that's not right, missing a dash :)00:59
=== teward is now known as teward_
=== teward_ is now known as teward
=== zz_DenBeiren is now known as DenBeiren
dtscodehey guys... i followed this to a T, https://www.digitalocean.com/community/tutorials/how-to-set-up-apache-virtual-hosts-on-ubuntu-12-04-lts and it worked before, but now its not working. any ideas why?03:10
sarnolddtscode: iirc, the apache initscript has a 'configuration check' option; it's worth running that to make sure the config file parses properly, no errors, etc..03:11
sarnolddtscode: if that doesn't report anything, check the logs, both for the specific virtualhost and generic error logs..03:12
dtscodeok03:12
dtscodeand whats the init script again?03:12
sarnold/etc/init.d/apache or apache2 or similar.03:12
dtscodethanks03:13
tdelamI need openssl 1.0.2 due to pci scan, I installed openssl via apt-get, I noticed apt only has 1.0.1, how can I install 1.0.2? Do I revert to installing from source?03:13
sarnoldtdelam: ugh. hate.03:14
tdelamsarnold: ?03:14
sarnoldtdelam: I don't know why they always assume everyone builds their servers themselves...03:14
tdelamyea :(03:15
dtscodesarnold, im not seeing any help option. just {start|stop|graceful-stop|restart|reload|force-reload|start-htcacheclean|stop-htcacheclean}03:15
sarnoldtdelam: completely ignoring that nearly everyone runs something like ubuntu or debian or rhel or sles and uses packages with backported security fixes....03:15
sarnoldtdelam: maybe aim the auditor at this? http://people.canonical.com/~ubuntu-security/cve/pkg/openssl.html03:15
sarnolddtscode: dang. maybe it's an apachectl command line option? I could have sworn it was offered by the initscript though :/03:16
dtscodemaybe it just always does a sanity check?03:16
sarnolddtscode: but there should be a way t oget the sanity check without stopping a running server03:16
dtscodehmmm... ill have to google03:17
sarnold... and get the messages to your terminal, rather than a log file ;)03:17
tdelamsarnold: I've tried to argue with this but given the size of the company they only live on version number consistency. Sadly, we got bought out and now we're stuck trying to satisfy bigwigs.03:17
tdelamI don't do IT, I just have access and know my way around Ubuntu from using it at home. Tthis is a bandaid solution until migration is complete.03:17
tdelamI build software, not mess with this stuff :(03:18
sarnoldtdelam: this one feels worth pushing back on -- you'd have to rebuild all your services that use openssl to use your own from-source openssl03:18
sarnoldtdelam: .. and then you'd have to keep up on the security updates for openssl and all your other services yourself. That's what we're here for. :)03:18
tdelamsarnold: well, happily this server is only a proxy server that onnly forwards requests to one web site. SSL is not even being used03:18
sarnoldtdelam: ha! sigh.03:18
dtscodedtscode@dtscode:~/ackbot$ apache2ctl configtest03:19
dtscodeSyntax OK03:19
tdelamyea, sarnold... I know.03:19
sarnolddtscode: nice :)03:19
dtscode:/03:19
sarnolddtscode: so, time to go hunting through log files...03:19
tdelamcouldn't I just remove it?03:19
dtscodesarnold, meh. i was hoping it was the issue. easy fix. yep. log file time03:19
sarnoldtdelam: maybe. worth a shot...03:19
sarnoldtdelam: d'oh. that'd remove openssh-server. that's not going to be a good solution.03:20
tdelamsarnold: that's what I will do. Not a single thing OpenSSL is being used on this server, this server is nothing but a bandaid.03:20
tdelamoh ssh has to be turned off03:20
sarnoldo_O03:21
tdelamit's not even running, hasn't been in a few months. I do this all through some ugly java console.03:21
sarnoldwhat a wacky auditor..03:21
tdelamI hate it.03:21
sarnold*ahem* how's the resume?03:21
sarnoldsounds like a silly place to work03:21
sarnoldsorry :)03:22
tdelamsarnold: I turned it off. I will ask him to do a dryrun before our official PCI scan in a few days.03:22
tdelamsarnold: I don't work there anymore, I do some contract still at a VERY high rate.03:22
sarnoldtdelam: sweet. :)03:22
tdelamYep, thanks sarnold. All else fails; delete.03:23
dtscodehow can i tell what {APACHE_LOG_DIR} is?03:31
sarnolddtscode: it's probably /var/log/apache*03:34
sarnoldhehe03:34
dtscodeah thanks03:41
dtscodenothing helpful in the logs :/03:44
sarnoldwhat helps me debug webservers is to have a tail -F *  in the log directory, then start hitting it with requests -- watch them as they happen..03:45
edenisthey05:58
Anteacanyone experienced with ispconfig autoinstaller?06:00
=== HWET is now known as MycoFox
bigbrovarhello guys.. am kinda new to quotas especially warnquotas.. I have setup quota for users in an nfs home dir.. that is working fine..  i read warnquota can mail any user who has gone past its soft limit.. my questions is... how can I indicate to warnquota the user email address. how does it determine the user email address.. I can't seem to find this information anywhere and this don't seem to be anywhere in the config where this info can be stat07:10
bigbrovared07:10
=== kickinz1|afk is now known as kickinz1
arcskysarnold: thanks07:48
arcskymorning, which ones do you guys recommend  landscape, ansible, puppet, chef, cfengine (ancient) ?07:49
Slingfor doing what, in what environment, scale, etc07:54
erenhello07:55
erenwhere are the source packages for openstack juno release? I can get the sources with "apt-get source" but I would like to see the source packages in some kind of a git tree07:56
erenis it how it's developed?07:56
Slingeren: probably better to ask in #openstack07:56
Slingunless you specifically mean the ubuntu openstack package development07:56
erenSling: I'm asking for ubuntu openstack package development07:57
arcskyi just have few (5-10) ubuntu servers i our company. and has not scale that good lets say 10 more. in next few years. running DNS,NTP,FTP,HTTP. Finance industry so has to be high focus on security07:57
erenkernel team maintains git repository so that I can checkout and create debian packages07:57
erenI would like to, if possible, do the same with openstack packages07:57
Slingeren: can't seem to find it, weird launchpad stuff08:03
SlingI ended up at https://jenkins.qa.ubuntu.com/view/Openstack_Testing/view/Juno/08:03
Slingperhaps that gives some lead to where the actual repositories are with src :)08:04
erenSling: thanks! :) I guess I need to ask the actual maintainers. I hope it's in git repository08:14
erenbzr stuff is really a pain08:14
=== Lcawte|Away is now known as Lcawte
Slingindeed08:15
Slingsemi-opensource08:15
MaamuThi all \o08:29
MaamuTsorry for my funny english, i'm french ;)08:30
MaamuT2 server with ubuntu 14.04 TLS08:31
MaamuTin both : apt update08:31
MaamuTin first : Hit http://mirrors.gandi.net trusty/main amd64 Packages08:31
MaamuTin second : Hit http://mirrors.gandi.net trusty/main amd64 Packages 404 Not Found08:32
MaamuToops08:32
MaamuTin second : Err http://mirrors.gandi.net trusty/main amd64 Packages08:32
MaamuTarg, sorry08:32
MaamuTin first : Hit http://mirrors.gandi.net trusty/main amd64 Packages08:32
MaamuTin second : Err http://mirrors.gandi.net trusty/main amd64 Packages 404 Not Found08:33
MaamuTsame sources.list on both08:33
MaamuTsame provider08:33
erenSling: just got an email from maintainer, apperantly it's developed in bzr and lp, not git09:23
erenneed to learn bzr workflw09:23
lordievaderGood morning.09:24
=== Lcawte is now known as Lcawte|Away
YamakasYhu guys!10:16
YamakasYdoes someone have a good example for the sources.list without the i386 issues ?10:17
=== Lcawte|Away is now known as Lcawte
=== kickinz1 is now known as kickinz1|away
pruttelShould sudo be a primary group for a sudo user or does this user only need to be member (what's the difference?)10:59
pruttelFrom what I read now, I think, it does not need to be a primary group.11:01
=== kickinz1|away is now known as kickinz1
=== mlocher_ is now known as mlocher
=== Lcawte is now known as Lcawte|Away
rbasakjpds: any opinion on bug 1418287 please? Do you have time to look it it before feature freeze?12:11
rbasakhttps://bugs.launchpad.net/ubuntu/+source/unbound/+bug/141828712:11
jpdsrbasak: Surely we can just sync from Debianfor unbound?12:14
=== Locke2002 is now known as Guest26302
jpdsrbasak: All we did in the Ubuntu package was enable the testsuite for main inclusion.12:15
rbasakjpds: I see a fair few more changes than that: https://launchpad.net/ubuntu/+source/unbound/+changelog12:17
rbasakjpds: a sync would be fine if the delta can be dropped, but I'm not familiar with the changes and so am not sure without further investigation.12:17
jpdsrbasak: I'll have to look at things once I'm back from the sprint.12:19
jpdsLooking at the build logs, Debian still hasn't enabled the testsuite... :(12:19
rbasakjpds: thanks!12:20
=== Sling_ is now known as Sling
bigbrovarhello guys.. am kinda new to quotas especially warnquotas.. I have setup quota for users in an nfs home dir.. that is working fine..  i read warnquota can mail any user who has gone past its soft limit.. my questions is... how can I indicate to warnquota the user email address. how does it determine the user email address.. I can't seem to find this information anywhere and this don't seem to be anywhere in the config where this info can be stat12:30
bigbrovared12:30
arcskywhat ubuntu mangment tool do you guys use for maintain your ubuntu servers?12:44
henkjanarcsky: mostly apt and vim :)12:50
YamakasYdoes someone have a good example for the sources.list without the i386 issues ?12:52
arcskyhenkjan: i mean system for mangement like apt-get update on all. GUI wise12:54
=== Jare_ is now known as Jare
nivvHey guys! I have a group called www-data. This group is the owner of the folder /var/www/site14:00
nivvI then have a user called mongo14:00
nivvmongo can create files fine because he's in the www-data group.14:00
nivvThen comes the user foobar and wants to edit the file mongo created, but he cant. Permission denied.14:00
nivvThis is because the file that mongo created didn't inherit the permission of the folder14:01
nivvWhy is that?14:01
ikoniawhat groups is the usuer foo in ?14:01
nivvwww-data14:01
ikoniawhat is the permissions on the file14:01
nivv64414:01
ikoniaso there you go14:02
ikoniano write permission14:02
nivvyes14:02
tewardnivv: 644 is too restrictive - that's -rw-r--r--14:02
nivvI want user created files to be 66414:02
nivv-rw-rw-r--14:02
nivvbut when Mongo creates a file it becomes 644 automatically14:03
ikoniathen set the umask14:03
=== suigeneris is now known as Kartagis
nivvYes, ikonia , I've read some about it and ppl are saying it's a bad idea14:03
nivvcan you set umask on folder level?14:03
ikoniaif it's a bad idea, why do you want to do it ?14:03
jrwrensetfacl should let you, yes.14:04
nivvNevermind, I don't know14:04
nivvbasically I want all users in the www-group to be able to edit files in /var/www14:04
nivvand it shouldn't matter who created them14:04
nivvas long as they are in the www-data group of course14:04
ikoniayou'll need to set either ACL's or the umask14:06
nivvhm okay14:06
tewardnivv: I question the need to put users into www-data anyways, because if it's a standard user without admin rights they could easily get db auth data and hijack the site and the db14:06
tewardbut that's just my security paranoia at work14:07
nivvteward, that's true I suppose14:07
nivvdoesn't really fix my problem though14:07
nivv:)14:07
tewardnivv: no, it doesn't, i'm just making that security concern of mine known - you'll either need to set ACLs or the umask to do what you want to14:08
nivvYup, trying to find some good resources on how to do that14:09
nivvteward, ik14:10
jrwrennivv: setfacl -m d:g:www-data:rw /var/www/14:10
nivvah yiss14:10
jrwrennivv: if you are publishing web content from multiple editors, there are likely many other better ways to do it.14:11
jrwrennivv: keep your web content in source control and use a post commit hook to publish to the server for example.14:11
nivvjrwren how so? The other guys are using sftp, the don't even know what git is14:11
nivvthey*14:11
nivvjrwren yea, that would be ideal, but we have many small projects using the same cms, that is source controlled. can't really update all of them if I push a commit14:12
jrwrennivv: I'm idealizing the world. Now is a great time for them to learn :)14:12
nivvjrwren they're still using asp classic -.-14:12
jrwrennivv: good times that was.14:13
nivvjrwren what does the "d" and "g" mean in d:g:www-data:rw /var/www/14:19
jrwrennivv: default. it sets the default for new files.14:19
nivvjrwren okay, it didn't work :)14:21
nivvIt seems that if I create a folder it sets the permissions correctly, but not new files14:22
nivvor scratch that, it doesnt14:22
jrwrennivv: filesystem mounted with acl support?14:23
nivvhuh nope14:23
nivvshieet14:23
nivvthat's sounds like a big thing to change?14:24
jrwrennivv: no. update /etc/fstab and mount /PATH -o remount,acl14:24
nivvis that all? I'm on a hosted vps, and that sounds scary :D14:25
nivvisn't there any other way? ;)14:25
nivvjrwren what does the PATH refer to?14:25
jrwrennivv: whatever the mount point is. probably /, but you might have /var/www elsewhere.14:26
nivvjrwren seems like standard /var/www ? https://www.dropbox.com/s/6xapm303nwi41f5/Sk%C3%A4rmklipp%202015-02-06%2015.27.28.png?dl=014:27
jrwrennivv: mount will show you which filesystems are mounted at which points.14:28
nivvhttps://www.dropbox.com/s/193k1ce1ges3as7/Sk%C3%A4rmklipp%202015-02-06%2015.29.06.png?dl=014:29
jrwrennivv: yeah, go for it with / then.14:29
jrwrennivv: a bit strange that you don't have devfs, sysfs, procfs and tmpfs mount points showing.14:30
nivvDo I have to reboot or how do I remount?14:30
nivvjrwren like this? https://www.dropbox.com/s/3wfrlhse5t0kjpx/Sk%C3%A4rmklipp%202015-02-06%2015.32.07.png?dl=014:32
jrwrennivv: no no no14:33
jrwrennivv: undo all that.14:33
jrwrennivv: lets not touch fstab for now, K?14:33
nivvhah, sure!14:33
jrwrennivv: sudo mount -o remount,acl /14:33
jrwrennivv: just that.14:33
jrwrennivv: then try that setfacl again.14:33
jrwrennivv: use getfacl to confirm that the setfacl worked.14:34
nivvhm, this seems somehow safer http://superuser.com/questions/612771/how-to-set-umask-for-a-folder-and-its-subfolder14:34
jrwrennivv: if you can get that to work, go for it! :)14:34
nivvI mean safer in a "at least I didnt bring down the server kind of way"14:34
jrwrenwe have different definitions of safety in that regard :)14:35
jsmith-argotecivoks: you around?  still working on that pacemaker problem if you have a few minutes to help troubleshoot14:38
nivvjrwren hm, I guess14:38
zzxcHey how do I change the mailserver from mailx to mailutils in ubuntu 14.04?14:39
zzxcor more accurately the "mail" command.14:40
nivvjrwren what should happen when I run sudo mount -o remount,acl / ?14:40
nivvshould I do the setfacl after that?14:40
nivvI've already did it once14:40
jrwrennivv: use getfacl to read the acls and see if you need to do it again.14:41
nivvjr14:41
nivvjrwren now or after? https://www.dropbox.com/s/rg9pi05lfbh3s5u/Sk%C3%A4rmklipp%202015-02-06%2015.42.37.png?dl=014:42
jrwrennivv: looks like the setfacl did not work because the fs was not mounted with acl support.14:43
nivvWhen I did "sudo mount -o remount,acl /" I got bad option14:43
nivvokay good14:43
nivv"mount: / not mounted or bad option"14:43
jrwrennivv: works for me. Sorry. I don't know why that would fail.14:45
nivvjrwren alright!14:46
nivvjrwren, it's strange that this little task i so complicated14:48
nivvI mean, why even have group if the group doesn't allow the group to edit the files :)14:49
jrwrennivv: it does of course. group has rwx, just like user and everyone14:51
nivvYeah but if a new file is created then it should be applied to the new file as well14:52
jrwrennivv: should it? there is strong argument for both.14:54
nivvjrwren, the only solution for us is to either to use ACL. Which seems to be a pain to setup, or we both have to use the same account :/14:55
jrwrennivv: many other possible solutions when you take a step back and try to solve the bigger problem.14:56
nivvjrwren I knowm I know14:56
jrwrennivv: did you try http://superuser.com/questions/612771/how-to-set-umask-for-a-folder-and-its-subfolder yet?14:56
nivvyes, But then you said something concerning security so I passed on that one :)14:57
nivvyou see, I'm like a 5 yr old child, if someone tells me something, it's the absolute truth14:57
nivv:D14:57
nivvit  did work, I tried it, but I don't know what consequences it might have on security.14:58
jrwrennivv: it wasn't me. someone else said something about security :)15:02
nivvHah, alright15:02
nivvI mean, if I set the umask to 002 then only users in the www-group can edit the files right?15:02
jrwrennivv: no. you should probably read and fully understand modes and masks15:08
nivvjrwren really a shame that I have to go. I need to get better at his. I15:10
nivvThe folder I'm talking about is owned by the group www-data, then that would only allow users in the www-group to edit the files?15:11
nivvjrwren thanks for the help though!15:14
=== Guest50107 is now known as HackeMate
=== matsubara is now known as matsubara-lunch
=== kickinz1 is now known as kickinz1|afk
=== Lcawte|Away is now known as Lcawte
coreycbzul, also need python-oslo.context in vivid16:20
coreycbin adition to the oslo bumps16:20
zulcoreycb: it should be there16:21
zulcoreycb:  bah16:21
coreycbyeah not seeing it unless I spelled it wrong16:21
coreycbzul, test-requirements.txt for ceilometer needs gabbi(?) and pyhon-elasticsearch (in universe)16:35
zulwtf is gabbi?16:35
coreycbzul, https://pypi.python.org/pypi/gabbi/0.1.116:36
zulseriously16:37
=== teward is now known as teward_
=== PaulW2U_ is now known as PaulW2U
=== collizion is now known as Guest33144
=== collizio1 is now known as collizion
=== martins-afk is now known as martinst
=== matsubara-lunch is now known as matsubara
lucidguyJust enabled/configed eth1, it is responding to the network but iftop and iptraf does not seem to log any traffic, thoughts?18:20
sarnoldlucidguy: perhaps they enumerated the interfaces at start and don't periodically re-enumerate interfaces? check the docs, sometimes you can send daemons a signal to force them to re-initialize themselves18:46
=== martinst is now known as martins-afk
adebayohi, pls i need help concerning openvswitch20:00
adebayothere is a problem with the latest kernel and i need to remove it to install another one20:01
lucidguyhmm, I have an ubuntu server that traffic packets were custom/changed to go out certain devices depending on source nic, where does one set that?20:01
sarnoldadebayo: run this to see what kernel versions you have installed: dpkg -l 'linux-image*' | awk '/^ii/ {print $1, $2, $3}'20:06
sarnoldadebayo: if one of those will suffice, you ought to be able to select a new kernel at the grub prompt when you reboot, if you have console access20:07
=== matsubara is now known as matsubara-afk
adebayoI was told the one i install is  Package: openvswitch-datapath-dkms 2.0.2-0ubuntu0.14.04.1 which is causing the problem and i need to install another one without the datapath which i dont know how to20:11
adebayosarnord: can you pls help me out with that20:12
sarnoldadebayo: ah, so you need a different version of the module?20:13
adebayoyes20:17
sarnoldadebayo: apt-get install openvswitch-datapath-dkms=..... -- where the ... are the version that you need; apt-cache show openvswitch-datapath-dkms  ought to show you the versions that are available20:17
adebayoi have run the command you gave me the kernel is 3.13.0.45.52 amd6420:18
adebayohi sarnold20:27
=== CiPi is now known as cipi
=== cipi is now known as CiPi
Aisonis there some ppa with bacula version 7 packages for ubuntu22:35
Aisonubuntu bacula packages are quite old22:36
=== Lcawte is now known as Lcawte|Away
=== markthomas|away is now known as markthomas

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!