/srv/irclogs.ubuntu.com/2015/10/27/#ubuntu-server.txt

tewardpmatulis: again, no rush, not a huge issue :)00:01
=== markthomas is now known as markthomas|away
=== Lcawte is now known as Lcawte|Away
=== cmoneylu_ is now known as cmoney
=== markthomas|away is now known as markthomas
=== markthomas is now known as markthomas|away
=== krsna- is now known as krnsa
=== krnsa is now known as Lord_Govindam
lordievaderGood morning.08:07
th3s3_3y3smorning lordievader08:18
soulissonHi, does Ubuntu has a repo for security updates?11:11
ogra_soulisson, yes, it is enabled by default in your reposoitory list in /etc/apt/sources.list11:14
=== Lcawte|Away is now known as Lcawte
soulissonogra_, trusty-security?11:17
ogra_on a trusty install, yes (and with the correct server name)11:18
soulissonogra_, do the security packages contain the version provided by the editor or is this is the work of the ubuntu team?11:22
rbasaksoulisson: the Ubuntu security team cherry-pick security fixes11:26
andolWell, at least that's the general rule.11:27
soulissonrbasak, sorry english is not my first language what does it mean?11:28
rbasaksoulisson: the Ubuntu security team take the security fix patch from upstream and apply it to the package version that is in the stable release.11:28
rbasaksoulisson: as andol says this is the general case - there are occasional exceptions11:28
soulissonrbasak, ok, thanks11:29
enleetenah a little chmoding never hurt anybody12:39
=== marlinc_ is now known as marlinc
=== markthomas|away is now known as markthomas
ztyuiohi16:01
ztyuioi need your help to setup nomachine 4.3.3 on windows 10 with ubuntu trusty16:01
ztyuioanyone using nomachine here ?16:02
ztyuioseems not working with port 2216:02
ztyuioi can able to join my machine over putty a putty session16:02
ztyuiobut not with nomachine16:02
=== Lcawte is now known as Lcawte|Away
roaksoaxsmoser: have you seen this before? http://pastebin.ubuntu.com/12980715/16:33
smosernot enough context, but it would seem something is pretty wrong.16:35
smoserit is always helpful to post entire logs.16:35
smoserprobably there is a WARN somewhere.16:35
roaksoaxsmoser: yeah, the person doesn't seem to have the full set of logs16:35
roaksoaxsmoser: http://paste.ubuntu.com/12980737/16:38
smoserstill not much context, but it really seems like package is not installed, or cloud-init is foobarred badkly somewhere.16:40
roaksoaxsmoser: http://paste.ubuntu.com/12980749/16:41
roaksoaxsmoser: it seems so16:41
hallyndannf: hey - so no problems using the qemu from ppa from a few weeks ago?17:51
th3s3_3y3sIs single user mode no longer supported or runlevels at all?17:51
hallyndannf: if not i'll push that with changelog tweak to xenial17:52
dannfhallyn: no, it worked fine. most of the problems i had were backporting it to trusty. i worked through those, but there's probably some changes you'd want to bring in17:52
dannfthat i need to clean up17:52
dannfhallyn: def good enough for the initial xenial upload imo :)17:52
hallyncool, thx.17:52
hallynhm, but why does x have a newer version than nw17:53
hallynoh, rharper17:53
hallynwell that complicates the merge :(17:53
hallynscrew it i'll fake it in git17:54
dannfhallyn: here's one patch you might want to bring in: http://lists.nongnu.org/archive/html/qemu-devel/2015-10/msg04627.html17:55
dannfhallyn: it'll land upstream differently because they're doing some other configure changes17:55
hallyndannf: but it's ok/safe as is?17:55
dannfyeah17:56
hallynhm,17:56
dannfnot needed for xenial, but is for trusty - i just assume that i won't be the only one that needs to backport it (e.g. cloud archive)17:56
hallynright, i see17:56
hallynhad to check rmadison then groked17:56
hallynall right, i'll try to get something into x today - thx17:57
hallynwow no zul17:57
hallynlife is meaningless.  alea jacta est17:58
hallyni really need to set something up to notify me on all new devel-release qemu uploads18:01
=== Lcawte|Away is now known as Lcawte
th3s3_3y3sDoes the instal cd come with a pxe bootable kernel?18:32
bekksEvery Ubuntu kernel can be booted using PXE.18:32
th3s3_3y3slooking at this command to copy from the ubuntu server install cd : sudo cp -fr install/netboot/* /var/lib/tftpboot/18:33
gzooI'm trying to setup a mail server. I installed the mail-stack-delivery package, but I want to use virtual users.18:35
gzooI set up dovecot so it recognizes users with `doveadm user <user>`18:35
gzoobut I'm not sure on the postfix part... I got up to the point where the mail is delivered to my server, but "user" is getting the mail instead of "user@nicedomain", so the postfix thinks theres no such user18:36
patdk-wkodd18:38
patdk-wkyou are using lmtp right? to deliever it to dovecot?18:38
gzoopatdk-wk, yes, I use dovecot-lmtp. But I think I'm confusing many, many things.18:42
gzoocan postfix check whether a user exists when talking to dovecot by lmtp?18:43
patdk-wkyes, but you really shouldn't bother doing that19:00
tewardsarnold: around?19:06
th3s3_3y3sno?19:06
sarnoldhey teward :)19:06
tewardsarnold: incoming PM :)19:06
th3s3_3y3spatdk-lap, specifiy that19:06
patdk-wkheh?19:11
patdk-wkspecify what?19:11
th3s3_3y3swhat you shouldn't nother with19:16
th3s3_3y3sspecify19:16
tewardsarnold: can I pick your brain with a packaging question in the interim?19:49
sarnoldteward: you can try but if it's about the conflicts: thing from the other channel, I've got no idea :)19:50
sarnoldteward: learning packaging on the security team I really only deal with the easy cases where we just do tiny bumps of version numbers and make sure that version numbers are monotonically increasing..19:50
sarnoldI really am clueluess about the finer points of long-term packaging19:51
gzoopatdk-wk, (sorry for reviving an old comment), how do I tell postfix to use dovecot properly? after that all should be set? no virtual user maps on the postfix side?20:08
patdk-wkwhy is there no virtual user mapings?20:09
patdk-wkyou just said you didn't want system user accounts20:10
patdk-wkbut full email address accounts20:10
gzoopatdk-wk, yes, I have virtual users on the dovecot side20:10
gzoono system users20:10
patdk-wknormally, one sets up virtual users in postfix20:10
patdk-wkpostfix at a min, will need to know all the virtual domains20:11
patdk-wkbut you generally need 2 tables to do all the mapping20:11
patdk-wkdovecot users20:11
patdk-wkmap this to postfix mailboxes20:11
patdk-wkor you could let postfix figure them out by asking dovecot via lmtp, but seems kindof overkill20:12
patdk-wkand a alias map table, for email addresses to mailboxes, for postfix20:12
patdk-wkbut this is way too much for an irc channel20:12
patdk-wklots of people in #postfix will help with the postfix part though20:12
gzoowell, I didn't like the idea of having the same data about users in both dovecot and postfix20:13
gzooI guess I'll head off to #postfix for more in-depth help20:13
patdk-wkwhy not?20:13
patdk-wkif they use the *same source data*, why not let many programs use the same data directly?20:13
patdk-wkless points of failure and other things to go wrong20:14
patdk-wkor, less castcading failures20:14
gzoohow come having a table on the postfix side, and another one on the dovecot side is the 'same source data'?20:15
gzooit's the same data duplicated20:15
patdk-wkheh?20:15
patdk-wkit's one table20:15
gzooerr, ok i'm missing something20:15
patdk-wkyour using static hash-key files?20:15
patdk-wknot sql/ldap/....20:16
patdk-wkI would highly recommend using sqlite instead if your doing that20:16
patdk-wkbut yes, doing it that way would be a royal pain20:17
patdk-wkcause you have too many different pieces of info about one user all over the place20:17
patdk-wkif you really must do it that way, no idea why you would, make one file to hold it, and use a make file to create the seperate parts20:17
gzoocan't I just have a passwd-like file like they show on the dovecot docs, instead of sqlite. I only need to have 1-few users on the server, and using sql on this would be the overkill opposed to simple files20:19
patdk-wkthat won't handle your aliases and mappings for postfix20:19
gzoowhich creates the duplication problem.20:19
patdk-wkif you want something simple like that, it sounds like you want to use system users20:19
gzooif I go sqlite, I can have postfix play with sqlite as well?20:19
patdk-wknot virtual20:19
gzooI prefer it be virtual users actually20:21
patdk-wkyou can perfer it all you want20:21
patdk-wkbut by definition, you have to duplicate all the work, local/system users does automatically for you20:21
patdk-wkmaking it *not as simple*20:21
patdk-wkyou can't have everything20:22
sarnoldthough you do then have to worry about those users trying to ssh in to the system, heh20:22
gzooI have to note that this is a hobby exercise, so even if I'm scratching my right ear with my left hand I'd rather have it scratched20:23
gzooSome googling seems to show postfix+sqlite hopes20:23
patdk-wksarnold, no20:23
patdk-wkyou just set it to /bin/false, done20:23
gzoopatdk-wk, set the system user's shell to /bin/false?20:24
patdk-wkyes20:24
gzoowell, thanks for clarifying some things. I will try going the SQLite way.20:35
patdk-wktables makes it much easier20:38
patdk-wkbasically a mailbox table, a alias table, and a domain table20:38
patdk-wkshould solve all your needs, or you can make it more complex20:38
patdk-wkshould be tons of examples on google20:39
patdk-wkthe bad thing, almost all the examples have issues too :(20:39
ponyofdeathanyone know if its possible to write a app armor policy to only allow a process to append to files and not be able to erase or clear them?22:22
sarnoldponyofdeath: the 'a' permission should do exactly that23:10
ponyofdeathsarnold: thanks! i was just reading that in the man page :)23:10
lamontthe whole "don't boot with incomplete swraid" option... what package is that in>?23:16
TJ-lamont: do you mean the old requirement for bootdegraded=true thing?23:18
ElionHi, i have an ubuntu server and i want to install multiple services on it like gitlab, owncloud, mumble, web server, monitoring system, .... What do you advise me to use to get services in boxes : docker, vm, whatever... and should i use something like chef to manage it ?23:19
BrianBlaze420hello beautifuls23:20
BrianBlaze420I seem to have openvpn server running23:20
BrianBlaze420as the service says it is and syslog looks good23:20
BrianBlaze420but netstat -lntp shows only ssh is there I don't see my vpn port23:21
BrianBlaze420anyone know where I messed up?23:21
sarnoldBrianBlaze420: remove the 't'23:21
BrianBlaze420lol23:21
sarnoldBrianBlaze420: that shows tcp but openvpn probably runs on udp23:21
BrianBlaze420true it does23:21
BrianBlaze420okay so I use u instead23:22
BrianBlaze420and see it lol23:22
BrianBlaze420thanks23:22
sarnoldyay :)23:22
BrianBlaze420so now I gotta figure out whats blocking me out of thurrr23:22
BrianBlaze420thanks a lot tho23:22
BrianBlaze420:)23:22
lamontTJ-: yeah that23:23
lamont(trusty system)23:23
TJ-lamont: as I recall, in trusty, either on release, or very soon thereafter, there was an update that stripped that out - I remember because it caught me out!23:23
sarnoldBrianBlaze420: do you get any error messages from either peer? check service logs, syslog, dmesg on both23:23
lamontTJ-: I know that I have a machine that doesn't boot when I have a one-device raid123:24
lamontTJ-: that when I force my way into busybox and mdadm --add the second partitoin, and then reboot, it comes up just fine23:24
TJ-lamont: 3.2.5-5ubuntu3 : http://changelogs.ubuntu.com/changelogs/pool/main/m/mdadm/mdadm_3.2.5-5ubuntu4/changelog23:24
BrianBlaze420nah I am actually using amazon aws and it's funny when I open ports it's like they don't open but I wanted to really make sure it wasn't my server23:24
BrianBlaze420because everything looks grand server side23:24
TJ-lamont bug 127974123:25
ubottubug 1279741 in mdadm (Ubuntu) "Degraded array check, may not do what it says it's doing" [Undecided,Fix released] https://launchpad.net/bugs/127974123:25
sarnoldBrianBlaze420: ah, yes, the security groups also need to be managed :)23:25
BrianBlaze420I have done that23:26
lamontTJ-: oh hell.  that reads like exatly what I most donot want23:26
BrianBlaze420but I swear they don't open23:26
TJ-lamont: I recall I was hit in a similar way as you seem to be, and I did some debugging and decided the patch xnox added wasn't working for all circumstances, but I can't recall where that led23:26
lamontmy issue is that I want the machine UP and I'll deal with recovering the RAID at that point.  Given the size of the drives, a 2 day reboot is unacceptable.23:27
TJ-lamont: yeah, that was my scenario too23:28
lamontesp when, since the second drive wound up not being in the array at all, it's not a 2 day outage, it's a drive there and hookup the keyboard and monitor and manually intervene23:29
* lamont has to run23:30
TJ-lamont: I had the advantage of network KVM, but yes, it isn't good23:30
BrianBlaze420you don't know of a way to kick in an updated security group do you>23:33
BrianBlaze420I heard it was right away... I have yet to see it right away lol23:33
sarnoldBrianBlaze420: if you've had time to type about it on irc then perhaps there's something else wrong.. it seems most likely to me that perhaps the one you added might not be sufficient for the job..23:35
BrianBlaze420I went this through my other server with opening port 80 too23:36
BrianBlaze420and magically it just started working23:36
BrianBlaze420so I guess I wait lol23:36
BrianBlaze420well i stand corrected other ports opened so its all on me this time23:51
BrianBlaze420and it works :)23:54

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!