/srv/irclogs.ubuntu.com/2016/03/21/#ubuntu-server.txt

=== hiwhiteboy is now known as King
=== Piper-Off is now known as Monthrect
=== jiggalator is now known as netsin
=== King is now known as hiwhiteboy
=== hiwhiteboy is now known as hicuteboy
=== hicuteboy is now known as cuteboy
tarpmanlunaphyte: ah right! I found the place debconf priority is documented. https://www.debian.org/releases/jessie/amd64/ch05s03.html.en#installer-args :P04:50
=== cuteboy is now known as King
cooldharma06hi all05:35
cooldharma06i am trying to access pudb from my remote machine via ssh05:35
cooldharma06keys are not working05:35
=== King is now known as KiFam
=== KiFam is now known as King
trimasis SHA1 used in Ubuntu's default FDE setup less secure than using SHA256/512? SHA1 has been deemed insecure since 2005, or am I misinformed?07:46
jamespagemorning all08:34
RoyKmorning08:41
jamespagecoreycb, ddellav: SRU's mainly caught up with - Kilo is all in proposed and tested OK10:55
jamespagenova and keystone point releases in the sru team queue for wily10:56
Slashmanhello, I'm trying out lxd on ubuntu 15.10 and it works great but I have an issue when I start a container with debian jessie, I can't stop it: "lxc stop" get stuck and running "poweroff" inside the container get me "Failed to talk to init daemon.", with ubuntu container, there is no issue so my question is: how do you stop a debian container?11:13
Slashmanbtw the container is unprivileged11:14
coreycbjamespage, awesome, thanks11:38
jamespagecoreycb, np11:38
httperr418hi folks, I have an automount question11:59
httperr418I'm actually running ubuntu desktop but I wanted to do this via CLI so they suggested asking here12:00
httperr418I want to ensure that automounting is disabled for any device by default12:00
httperr418er, any external device12:00
httperr418I know it's possible because I've done it before, but I can't find the guide I located last time12:01
ddellavjamespage cool, ty12:41
mojtabaI can create proxy server using ssh -D locally and configure network manager manually to use it. Is there a way to select which addresses use this proxy? (By specifying something special in the URL, like http_proxy instead of http?) What is configuration URL for?13:09
jamespagecoreycb, added some bug management features to the tools that push stuff between uca pockets this morning as well:13:28
jamespagehttps://bugs.launchpad.net/cloud-archive/+bug/154644513:28
ubottuLaunchpad bug 1546445 in Ubuntu Cloud Archive kilo "support vhost user without specifying vhostforce" [Undecided,Fix committed]13:28
jamespagefor an example...13:29
coreycbjamespage, oh I like that, that last comment is automated then?13:30
jamespagecoreycb, yes13:30
jamespagecoreycb, also adopting the tag based verification approach that the sru team uses...13:30
coreycbjamespage, that's nice.  and does it auto-mark status as fix released?13:31
jamespagecoreycb, it should do - not tried that bit yet13:34
coreycbjamespage, ok.  thanks for all that!13:35
coreycbjamespage, I'm still debating if it makes sense to have a barbican-api init script or if directly using the apache2 init script makes more sense13:38
jamespagecoreycb, if you're running it under apache2, no init script required13:46
coreycbjamespage, ok, that is the case.  it's a change for users though since it used to run under uwsgi and had barbican-api init scripts. but we had to drop uwsgi to try and get it into main.13:48
jamespagecoreycb, can you take a read through this please - https://wiki.debian.org/Apache/PackagingFor2413:55
coreycbjamespage, yep13:55
jamespagecoreycb, you're doing alot of work in maintainer scripts you don't need to right now13:55
jamespagecoreycb, infact if you install the conf files directly to /etc/apache2/conf-avaliable and us dh_apache2 it will generate most of the required bits for you13:56
coreycbjamespage, ah that's nice. I'll revisit that after reading.13:57
jamespagecoreycb, actually its even nicer that that13:57
jamespageyou just have to have a .apache2 file in debian/ listing the conf files you want to enable...13:58
coreycbjamespage, very nice13:58
Slashmanto answer my own question from this morning, to stop a container that do not want to stop with "lxc stop", you must use the command "lxc stop <container> --force" which is undocumented14:12
jjrabbit543hello14:13
jjrabbit543ICMP protocol doesn't use a port?14:14
jjrabbit543how is that possible14:14
rbasakIP doesn't define ports. TCP and UDP do. ICMP is not TCP and UDP. It layers directly on IP.14:15
* patdk-wk kindof wishes we had 32bit ports14:18
jjrabbit543found the cisco guy14:20
jjrabbit543just joking. thanks man that makes more sense14:21
jjrabbit543can anyone tell me why  Your nick is owned by user [~user@104.131.1.159]14:22
jjrabbit543it says that?14:22
jjrabbit543woops sorry meant to send to different channel14:22
cyphermoxrharper: how is multipath-tools?14:49
rharpercyphermox: xnox was going to look at the FFE/merge and upload on Friday IIRC; I haven't looked yet15:07
rharpercyphermox: https://bugs.launchpad.net/ubuntu/+source/multipath-tools/+bug/155195215:08
ubottuLaunchpad bug 1551952 in multipath-tools (Ubuntu) "FFE: Please merge multipath-tools 0.5.0+git1.656f8865 from Debian unstable " [Undecided,Triaged]15:08
rharpercyphermox: stgraber said it was OK to upload, so it just needs a sponser15:08
cyphermoxyeah, stgraber acked it15:08
cyphermoxxnox: ?15:08
rharpercyphermox: I also pushed a fix upstream to debian re systemd.service file (the disable systemd for udeb broke linking against libsystemd for the non-udev, which broke notification via sd_notify);  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=81794015:09
ubottuDebian bug 817940 in multipath-tools "multipath-tools: multipathd is not linked to libsystemd, fails to notify systemd when ready" [Normal,Fixed]15:09
rharperneed to pull that fix in (instead of disabling systemd) in our package15:10
ndeeI'm looking for following tool: a user can create a payload in the browser and adds it to a queue. The queue payload gets executed by the root user, since some special privileges are needed. Does anyone know of some sort of queue tool?15:33
Slingsounds like a horrible idea15:34
Slingwhat problem are you trying to solve with this? or are you trying to create malware?15:34
ndeeSling: haha, no. What I'm trying to do is sync a staging environment of a CMS to a live environment. At the moment, I have an extension for that CMS which creates a file and a cronjob checks if that file exists and if it does, executes a task. That's the workflow I created 8 years ago and I'm wondering if there might be something "smarter" around the way.15:35
patdk-wkthere are hundreds of queue tools to use, pick one and use it15:36
patdk-wkthe issue is, the whole idea is flawed from the start15:36
ndeepatdk-wk: it is some sort of deployment and I'm not sure what a better way would be.15:36
patdk-wksomething that doesn't use a webserver :)15:36
patdk-wkit sounds like you already solved it15:37
patdk-wkcms creates a backup file, and cron job that checks if file exists and deploys it15:37
patdk-wkso sounds like the only thing you have to do is create another cron job15:37
patdk-wkif new backup file exists, copy it to the production server15:37
ndeepatdk-wk: so that's not a bad way to deploy something?15:37
patdk-wkonly if, anyone is allowed to make that file15:38
ndeeI sometimes get insecure with all those new flash tools and think that I also have to use it :D15:38
patdk-wkif a webuser can upload that file, and let it audodeploy, whatever they want :)15:38
patdk-wkmake sure that file location is well outside of what the webserver is allowed to touch15:38
patdk-wkand permissions are tight15:38
ndeepatdk-wk: the location of the file has to be writeable by the webserver, otherwise, the file can't be generated.15:39
patdk-wkno15:40
patdk-wkfrom your dev enviroment, sure15:40
ndeeah15:40
patdk-wkthat dev enviroment shouldn't be accessable to the outside15:40
patdk-wkbut on the live/production one, you should take care that file is protected15:40
ndeeof course15:40
patdk-wkor rather, firewall rules should be protecting the dev one15:41
patdk-wkso file level access, isn't strictly required, nice, but15:41
jamespagerbasak, kickinz1: hey - just reviewing the pacemaker merge from debian - I've tested the upgrade as I wanted to ensure that the package splits upgraded ok - works fine15:48
jamespageare you both happy we want todo that this cycle?15:48
=== roaksoax-afk is now known as roaksoax
kickinz1jamespage, rbasak thanks jamespage for having taken the time to look after it, I think that we want it this cycle yes.15:56
jamespagekickinz1, rbasak: ok uploaded16:01
kickinz1jamespage: thanks!16:02
daften_hi, i have a problem on a server with sudo, it won't use the users password16:07
daften_the users password is correct, i've checked this by issuing passwd and entering the current password, which is accepted16:07
daften_the sudo config is also correct. i've changed the file in /etc/sudoers.d/ that gives sudo rights to the group so it gives sudo rights without password entry, and then i can issue sudo commands16:08
daften_so there's something very strange going on, and i have no clue. can somebody help me?16:08
=== InfoTest1 is now known as InfoTest
=== InfoTest1 is now known as InfoTest
=== InfoTest1 is now known as InfoTest
jeeves_mosswhat is the best cliserable VPN server that uses an HTTP client that is free?  We have a bunch of IoT devices that we would like to connect to the network (to a NATed system), and not to have to worry about a bunch of open devices floating around18:04
patdk-wknone?18:11
patdk-wkhttp is not secure, so don't use it for a vpn18:11
jeeves_mosspatdk-wk: I meant https.  missed a letter.  we're looking for something that will punch through a NAT router18:13
patdk-wksounds like openvpn18:13
patdk-wkunless you need to be http proxy aware18:13
jjrabbit543hello18:16
jjrabbit543anyone know if there is a more recent project of this tool?18:16
jjrabbit543https://sourceforge.net/projects/ldaptool/18:16
sarnoldjjrabbit543: that sounds kind of like https://directory.apache.org/studio/18:18
sarnoldjjrabbit543: i'm normally hesistant to recommend anything from the apache project but .. i'm not sure where else you'll find this sort of thing.18:19
tewardrbasak: ping - who do i bother when i see something that prevents testcases from being completed in the server dailies?18:20
tewardis that matsubara still, or someone else?18:20
matsubarateward, Hi, I can take a look. What's up?18:21
tewardmatsubara: refer to today's server testcase, i filed a failed testcase, can't select keyboard layout per the testcase, possibly bug 155950718:22
ubottubug 1559507 in debian-installer (Ubuntu) "Keyboard selection is missed" [Undecided,Confirmed] https://launchpad.net/bugs/155950718:22
teward(initially observed 20160318 Lubuntu alt, then 20160319 Server, by phillw, poked to me in another channel to test/confirm)18:22
tewardconfirmed today by myself, both Lubuntu alt and Server18:23
tewardmatsubara: i'd poke the release team, but i'd like more eyes on it first :)18:23
tewardnote this is on the iso tracker18:24
tewardnot on our autotests (if we do them)18:24
tewardmatsubara: i'd set the bug as "high" because we may have cases where people have foreign keyboard layouts that need selected (or can't be autodetected), but again, i wanted some extra opinions18:26
tewardmatsubara: note that installation progresses as it should, apparently, but that means that either we're deprecating and removing keyboard layout selection, or our testcase is bugged, or the bug is actually something missing18:28
tewardi'm not qualified, I think, to make that determination18:28
matsubarateward, thanks for raising that. I think you're right. It should be high or if this is an intentional change the testcase needs update18:29
tewardmatsubara: thank phillw (the one who brought up the 'no 32bit qa iso manual test cases' problem a while ago) for pinging me randomly on it18:29
* teward usually avoids testing unless he has to18:29
tewardmatsubara: I'll set it to High for now, but can you poke around to see if this is an intentional change?18:30
matsubarateward, yep, I'll check it out. In any case I'll add a topic for discussion in tomorrow's meeitng18:30
tewardmatsubara: thanks!  i'm making a comment that i'm setting high after discussing with you :)18:31
matsubarathanks teward18:31
tewardyou're welcome18:31
tewardmatsubara: and thanks for replying promptly :)18:33
=== devil is now known as Guest3520
=== Guest3520 is now known as devil__
=== devil__ is now known as devil_
tewardmatsubara: confirmed that the install is otherwise unaffected, though, with regards to the test case - the testcase in its current form just can't be completed, but installations apparently can18:44
tewardthough i wouldn't put faith in that18:49
=== Monthrect is now known as Piper-Off
j^2Hi!19:06
j^2I was just convinced to come here per dobey from #ubuntu-quality19:06
j^2I work for Chef software, (what used to be opscode) and I wanted to talk about the version of chef that comes in when you do an apt-get install -y chef19:07
j^2it seem in 16.04 chef_12.3.1-1_i386.deb comes in, which is great19:07
j^2but that’s not the must up-to-date19:07
j^2we are at chef_12.8.1-1_i386.deb now19:07
j^2not to mention we have another SDK called the chefdk that we would like to add as an option19:08
j^2who can i talk to about who owns these, and work with them?19:08
tewardj^2: we're past feature-freeze, so any updates and feature additions would need individual exceptions.19:08
sarnoldj^2: https://wiki.ubuntu.com/FreezeExceptionProcess#FeatureFreeze_Exceptions19:08
tewardand testing19:08
tewardand review by the release team for inclusion19:08
tewardthe link sarnold provided gives details19:08
j^2awesome, thanks! I’ll start reading through this :D19:09
tewardj^2: obvious question: is this in Debian yet19:09
tewardaaaand rmadison answered my question19:09
tewardit is not19:09
j^2so that’s the problem, i’m not sure because i don’t know how it’s getting there. No one seems to know19:09
tewardi assume we're talking about the 'chef' package19:10
j^2somebody has to own this19:10
j^2yep19:10
sarnoldit seems like there's a reasonable chance, chef is in universe and it looks like a 'leaf' package19:10
tewardsarnold: no Debian updates, though, so it'd need more testing19:10
j^2ok19:10
sarnoldbummer though, logan did a merge just five days ago..19:10
j^2yeah it seems that isn’t the official chef package either from debian19:11
j^2it’s not ours, it was created by someone else19:11
j^2we have our packages posted: https://downloads.chef.io/chef-client/ubuntu/19:11
j^2so does that mean i should go to debian to get this fixed or through y’all?19:12
sarnoldprobably both19:12
j^2lovely19:12
sarnolda month ago maybe justdebian would have sufficed19:12
sarnoldbut, feature freeze and all19:12
j^2grrrr19:12
j^2ok, well this is my task, i’ll make it happen19:12
j^2lets start with y’all, i’m assuming i should go through the exception docs to get myself informed here?19:13
sarnoldyeah, that's a good starting point19:13
j^2start that process, then who/where should i go for the debian group?19:13
sarnoldI -think- this is the most recent chef changelog from debian http://metadata.ftp-master.debian.org/changelogs/main/c/chef/chef_11.12.8-2_changelog19:14
jcastrohttps://qa.debian.org/developer.php?email=pkg-ruby-extras-maintainers%40lists.alioth.debian.org19:14
sarnoldI -think- you won't go too far wrong if you email the three or four most recent uploaders; maybe filing a bug?19:14
jcastrothat's what the PTS lists as the chef maintainers19:14
jcastrohttps://tracker.debian.org/pkg/chef19:14
sarnoldah, go with jcastro's link instead :)19:14
j^2woah, that’s not great, that’s not us at all19:15
sarnoldthat's usual19:15
j^2:-/19:15
jcastromost packaged software is not done by the people who write it19:15
teward^ that19:16
j^2jcastro: i guess that makes sense19:16
teward(nginx as a prime example)19:16
jcastrothough IME most packagers prefer to have a good relationship with their respective upstream and just teamwork it all19:16
teward^19:16
j^2but we have packages that are packaged by us… it’s odd y’all don’t just take them right?19:16
tewardj^2: we inherit our packages for the most part from Debian, I believe.  Nginx is in your type of case as well - they provide official packages on their own "official" repository, but many people use what's just in Ubuntu19:17
jcastroideally, the upstream and the distro would share the same source packaging19:17
teward^ that19:17
j^2ah interesting19:17
tewardand yes i'm referring to nginx a lot because I work in that package :)19:17
jcastrobut not, we need to be able to rebuild the entire archive from source so we don't just copy binaries into the archive19:17
j^2;)19:17
j^2hmm, ok so there are a handful of things/conversations i need to have no it seems19:18
j^2now*19:18
jcastroyeah, but there's no reason it can't happen all at once19:18
j^2jcastro: sorry i’m not following19:18
jcastroif you fix it in debian then for us it's just a sync19:18
j^2ah!19:18
jcastroit's not "debian fix problem A, ubuntu fix problem A" It's "Debian let's fix problem A, ubuntu grab that."19:19
jcastrothough, one thing worth investigating right off19:19
sarnold.. but at this point in the 16.04 LTS release cycle, you'll still need the paperwork finsihed even if it is just a sync from debian :)19:19
jcastrois find the difference between your packages and the debian packages19:19
jcastrolike, are they carrying patches?19:19
j^2yeah there are a ton of updates iirc19:20
jcastrohttps://sources.debian.net/src/chef/12.3.0-3/debian/patches/19:20
jcastrofor example19:20
j^2I’ll have to figure it out19:20
sarnold.. and figure out what to do with ubuntu's difference from debian, too https://patches.ubuntu.com/c/chef/19:21
jcastroideally someone says "ok let's just take all these changes and fix them in one place"19:21
jcastrothat one place probably being upstream19:21
jcastroj^2: well, you haven't quit the channel yet so I guess that's a good sign, heh.19:23
j^2heh19:23
j^2yeah i’m trying to figure out the diff19:23
j^2;)19:23
sarnoldhehehe19:23
j^2maaayybeee this is it?19:24
j^2https://github.com/chef/chef/compare/master...12.3-stable19:24
j^2wait19:24
j^2shit19:24
j^2there we go19:24
j^2https://github.com/chef/chef/compare/12.3-stable...master19:24
j^24k commits19:24
j^2between the version on debian and our newest19:25
j^2stable19:25
j^2so for that, i’m betting yall want me to go to debian eh?19:26
j^2let them build the pkg from us, then sync down (after the paperwork)19:26
* jcastro nods19:27
j^2yeah i have a feeling i’m going to have to keep an eye on this for a while to make sure everyone is getting the correct software :-/19:27
jcastroj^2: also, there are ways to get newer versions into the LTS down the road19:27
j^2this type of oversight is probably due to everyone was assuming someone else was watching this stuff19:28
jcastrovia backports and whatnot, so I wouldn't sweat about the deadline. I would of course try to get everything in as quick as you can but I wouldn't panic.19:28
j^2jcastro: awesome, thanks for that. I’ll start the conversation with debian, and i’ll be around here to ask questions? cool?19:28
jcastroI'm always around19:29
j^2\o/19:29
jcastroor you can mail me at jorge@ubuntu.com19:29
j^2rock on thanks!19:29
jcastroI owe you guys since we broke the maas<->chef integration, heh19:29
j^2ha!19:29
j^2yeah that was going to be the next task after me getting this done ;)19:29
j^2hey it worked i tested maas 1.8? it worked swimmingly19:30
jcastrothough, posting to the debian list quickly will get eyeballs on it quick19:30
j^2is there a package ml?19:30
j^2<— the guy that wrote the maas integration :D19:30
jcastroI can't speak for those maintainers but most packagers I know love to work with their upstream19:30
j^2awesome19:30
jcastrohttps://qa.debian.org/developer.php?email=pkg-ruby-extras-maintainers%40lists.alioth.debian.org19:31
jcastrolooks to be the list19:31
j^2awesome19:31
j^2already making progress :D19:31
jcastroubuntu-devel-discuss@lists.ubuntu.com is listed as the maintainer list for the ubuntu version of the package19:32
j^2awesome19:34
nacchallyn: stgraber: there is some discusion on #ubuntu-devel about this just now, but having lxc-dns's dnsmasq installed by default (in cloud/server, as lxc is installed by default) means that many (all?) dns-server packages will fail to install20:20
mahmohj^2: so you're pretty good then?  need to also ask about a firefox-like package that pulls the latest chef for the LTS releases and beyond20:28
j^2mahmoh: awesome yeah that would be perfect20:28
j^2but i need to get debian updated first20:28
j^2which is the next step if i understand everything20:28
mahmohj^2: start an exception for that too then, might be too late though but maybe not20:29
j^2per the email earlier ;)20:29
mahmohgr820:29
j^2mahmoh: hey man you know you love me ;)20:29
mahmohj^2: let me know if you need anything20:29
j^2:D20:29
stgrabernacc: that won't be a problem by the time we release 16.0420:41
naccstgraber: thanks, and thanks hallyn for clarifying20:53
=== King is now known as hiwhiteboy
=== r0ry is now known as Guest26199
=== hiwhiteboy is now known as King
unomieOne of my sites is now pointing to my Docroot directory. The .conf file looks fine. Enabled/Disabled & restarted apache to make sure it wasn't using an outdated .conf - https://bpaste.net/show/caf1b10096f6 -  Any ideas?23:20
unomieother sites are working fine & so was this one up until a few days ago,23:20
unomiecan't find anything in the logs other than it loading the favicon. No errors...23:20
sarnoldtry removing the trailing / on DocumentRoot /var/www/html/pagenation.co.uk/23:20
sarnoldapache is quite picky about that trailing / and it always feels like it gets it exactly wrong23:21
unomiesarnold: Same result23:22
sarnoldunomie: dang. how about the logs? anything in the site-specific error or access logs, or the generic error or access logs?23:23
unomiechecked the syslog in /var/log, and other_vhosts_access.log error.log in /var/log/apache223:24
unomiesite-specific error log hasnt been updated in a month. Trying to the site-specific error log now but that hasn't been updated in an hour and I've been refreshing the site23:25
unomie*access.log for the second one23:26
unomiejust spiders crawling the site....23:27
shaunois there any sign that file's being loaded at all?  I noticed at some point apache started including sites-enabled/*conf instead of sites-enabled/*23:32
shauno(eg, 'a2query -s')23:33
unomieshauno: Not sure - where would I check? Yeah I switched over all my sites to .conf a year or so ago (whenever the switch happened)23:33
unomieshauno: Ta, yeah it's there - pagenation.co.uk (enabled by site administrator)23:35
shaunofair enough.  just thought I'd ask since that one made things mysteriously disappear for me23:35
unomieThink it might have something to do with the FQDN. I was messing about with that a month ago as it's set to pagenation.pagenation.co.uk (duplication - I was never able to sort it but the site that wasn't sending out mail started working so I abandoned it)23:36
Pinkamena_DHas anyone ever tried to join ubuntu to windows active directory with PBIS? I have had success with it, but now I am trying to add a network printer as well. How can I let users use their active directory credentials for the network printer?23:56
bekksWhats "PBIS"?23:57
tarpmanbekks: http://www.powerbrokeropen.org/23:58
bekksNever heard of it.23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!