/srv/irclogs.ubuntu.com/2016/04/12/#ubuntu-server.txt

=== Assailant_ is now known as Assailant
hallynpmatulis: no, i should be able to, but it just doesn't seem to work.04:30
cpaelzerrbasak: you might still be asleep, but if I would thank you just once every 100 times I'm happy about uvt I'd still call you twice a week06:15
cpaelzerrbasak: big thanks for that tool06:15
=== athairus is now known as afkthairus
=== socketguru_ is now known as socketguru
rbasakcpaelzer: np. I need to find some time to polish it up :-(08:05
lordievaderGood morning.08:30
stemid25G     /var/log/lastlog on a server installed 3 months ago, one local user.12:20
stemidwtf12:20
stemidjust running last gives me 467 lines12:20
stemidit's an ubuntu 14.04 acting as a galera arbitrator.12:20
stemidand this has nothing to do with sparse files, it actually uses 25607496 kB on disk.12:23
pmatulishallyn: weird. i got one on my cloud but the thing eventually froze up12:32
pmatulisstemid: sounds like a party12:33
pmatulishallyn: lemme know if i can help debug12:34
smoserdmsimard, join #cloud-init and ping harlowja. he might be persuaded to do so. also spandhe might be able to.13:05
DammitJimfor the version of tomcat7 that installs from Ubuntu repos... what causes the catalina.out to be rolled over to catalina.out.1?13:10
dmsimardsmoser: thanks13:40
hallynpmatulis: smoser: i'm sort of wondering whether cloud-init+systemd+lxd-bridge are having a bad interaction14:27
hallynbut i've made no progress :(14:27
smoserhallyn, well, probably not wrt the no_seed that you foun14:28
hallynsmoser: no, those are mutually exclusive14:30
hallynbut both uvt-kvm and openstack are using xenial cloud images, but in one i get networking hang (nova) and the other boots fine (uvt-kvm) with a lxd container running14:31
SaltySolomonHi14:48
Bluekingany good with dual xeon configuration for home use, fileserver. vpn , multistream videos to 5-6 pc's in house +++15:43
patdk-wkthat sounds like you need a really really fast drive array, or ssd15:47
madwizardYou could try zfs mirrors with ssd as l2arc15:53
madwizardthe second level cache15:53
madwizardsince its xenial15:53
madwizardAlthough for 6 pcs l2arc may be an overkill15:53
qman__yeah, l2arc won't help much with streaming either unless they're streaming the same content15:54
qman__more, faster drives will do better15:55
sdeziell2arc doesn't use mirrored drives15:55
Bluekingpatdk-lap  I have hardware raid card15:55
madwizardsdeziel: uhm?15:55
madwizardsdeziel: Explain15:55
sdezielthe l2arc is made to sustain the loss of any drive without issue15:55
madwizardsdeziel: l2arc is a cache15:55
qman__he didn't say mirror the l2arc15:55
madwizardAlso15:55
qman__he said use drives in mirrored configuration and add l2arc15:55
madwizardYou *can* mirror l2arc15:55
madwizardDepends on usecase15:55
madwizardBut fast drives set up as mirror vdevs would do the trick15:56
qman__yeah15:57
Bluekingpeople talk about VM is it about virtual sumthin ?15:57
qman__my file server has 30 WD Red drives in mirrored ZFS configuration and has no trouble saturating gigabit reads15:57
madwizardBlueking: VM is usually a Virtual Machine15:57
qman__20*15:57
madwizardqman__: Nice15:57
sdezielmadwizard: yes I nkow that l2arc is a cache and that's exactly why mirroring it would be odd15:58
Bluekingpeople uses vm for homeuse ?15:58
madwizardsdeziel: I've seen such deployments15:58
qman__writes are slower, varies by compression but usually around 35MB/s15:58
qman__but I'm also using dm-crypt and old Opteron CPUs15:59
madwizardqman__: writes to zfs mirrors are slower. Visibility depends on hardware and workload, yes15:59
sdezielmadwizard: sounds like a waste of SSD/speed15:59
qman__without the encryption I'd expect it to go full speed16:00
jrwrenits pretty easy to saturate gigabit reads on sequential IO. :p16:00
qman__4 cores without AES accelleration definitely limits performance16:00
madwizardsdeziel: Some customers want to keep having hot cache despite ssd failure16:00
madwizardsdeziel: All depends on your business case16:00
sdezielmadwizard: true. I didn't know it was possible to set it up like that. Thanks16:01
madwizardnp16:01
madwizardI suspect it's a rare case16:01
sdezielmadwizard: man 8 zpool needs an update then. It clearly states that "cache" devices cannot be mirrored or part of raidz16:03
madwizardsdeziel: Hm. Or the functionality was removed.16:04
madwizardsdeziel: I wonder if I still have a vm where I can test16:04
sdezielmadwizard: my SSD buget doesn't even allow me to consider such setup anyways ;)16:04
madwizardOooorrrr16:05
madwizardI might be mistaken after all16:05
madwizardsdeziel: I would try it on files :)16:05
madwizardsdeziel: You don't need ssds to test a command16:05
sdezielmadwizard: I know but I was saying I won't even need to have redundant SSD backed caches16:06
qman__it really wouldn't make sense with SSDs, since they fail after a certain amount of writes16:06
patdk-wkl2arc won't help at all for streaming workloads16:06
qman__they're more likely than HDDs to fail simultaneously given the same load16:06
patdk-wkit's unlikely that data will even move from arc to l2arc16:06
madwizardpatdk-wk: Yeah, come to think of it16:07
patdk-wkit will be very hit and miss16:07
patdk-wkbut the issue with multible streaming workloads is, it becomes really really random16:07
patdk-wkcause it constantly has to keep seeking16:07
madwizardPoor, poor read thread :(16:08
qman__yeah, the best solution for that is just a bigger raid 10 / zfs mirror setup16:08
madwizardCan't find what it's looking for, constantly seeking16:08
patdk-wkand raidz will NOT help16:08
qman__or going all SSD16:08
patdk-wkraid5/6 can somewhat help16:08
madwizardpatdk-wk: What is the difference?16:10
patdk-wkraidz has to read from ALL disks for each read16:10
patdk-wkraid5/6 only read the disk needed, assuming stripe size is large enough16:11
madwizardokay16:11
madwizardthnx16:11
qman__to see any advantage from that though, you generally need an expensive RAID card16:12
qman__on cheap cards and software RAID the gains are slim16:12
qman__and the problems with raid 5/6 far outweigh that benefit in my opinion16:13
patdk-wkno, you can easily see an advantage without an expensive raid card16:15
patdk-wkthe expensive raid card causes the advantage only when doing writes, when you have bbwc16:16
patdk-wkfor reads the advantage will be there, anyway you look at it16:16
patdk-wkjust you get no protection on reads, like you would have using zfs16:16
tewardjgrimm: you asked for an update?16:51
tewardi apologize for not speaking up earlier - internet evils are evil16:51
jgrimmteward, i was just giving you an opportunity since I saw you had joined the meeting.16:53
tewardjgrimm: not for lack of trying, Internet came back but died again16:54
tewardjgrimm: nothing other than 1.9.14 landing finally16:54
tewardwith HTTP/2 enabled16:54
jgrimmno worries. thanks!!16:54
tewardyep16:55
=== nodoubleg is now known as nodoubleg-afk
=== afkthairus is now known as athairus
=== nodoubleg-afk is now known as nodoubleg
max3can someone help me out? no matter what i do i cannot get ldap to start. it keeps throwing 570d37b7 main: TLS init def ctx failed: -118:00
max3i've tried all sorts of permissions schemes on the ssl certs18:00
sarnoldmax3: is there anything else more informative in the logs?18:09
max3nope18:09
max3just the memory address of the call18:09
max3570d37b7 main: TLS init def ctx failed: -118:09
max3from googling around it's apparent this is because of permissions on the certs18:09
tarpmanmax3: that is one possible cause, not the only one18:10
tarpmanmax3: you could confirm with strace whether it's actually trying to open the cert file you expect, and what the return code from that is18:10
pmatulismax3: you can also temporarily remove TLS and see18:10
max3well when i comment out olcTLS*CertificateFile in cn\=config.ldif it starts18:11
max3so smoking gun i think18:11
max3although strace is a good idea18:11
tarpmanmax3: as far as permissions, don't forget to consider the directories containing the certs, as well as the files themselves18:12
max3i have18:13
max3in fact it shouldn't be an issue because the error occurs even when i try to start slapd as root18:13
tarpmanright. likely not permissions, then18:13
tarpmana couple of other stabs in the dark:18:14
tarpmanthe private key needs to not be encrypted - i.e. no passphrase on it18:14
max3as far as i can tell it's not18:14
tarpmanif you have an olcTLSCipherSuite setting, check that it's a valid gnutls priority string - and not e.g. an openssl ciphers string18:14
max3no ciphersuite18:15
tarpmansigh. pin-the-tail-on-the-tls-config-issue is no fun :|18:16
max3yes18:16
sdezielmax3: I'd check if the key matches the cert. I compare the modulus to be sure18:16
tarpmanyeah, worth checking that you can run gnutls-serv with the same cert and key and connect to it18:16
max3i'm looking at strace output18:17
max3just to test i put the ca cert in /tmp/18:18
max3yet i get open("/tmp/cacert.pem", O_RDONLY)       = -1 ENOENT (No such file or directory)18:19
max3but i also get open("/etc/pkcs11/pkcs11.conf", O_RDONLY|O_CLOEXEC) = -1 ENOENT (No such file or directory) which i guess is from a package i have not installed18:19
patdk-wkapparmor?18:19
max3god damn it18:20
max3indeed18:20
max3i don't know how i missed that18:20
max3in dmesg18:20
max3lol it's clear as day18:20
max3apparmor="DENIED" operation="open" profile="/usr/sbin/slapd" name="/tmp/gw-01-private.key"18:21
max3lol18:21
max3thanks patdk-lap18:22
max3thanks patdk-wk18:22
sarnoldapaprmor shouldn't cause ENOENT errors18:22
max3well18:23
max3actually sarnold you're right. i'm still getting the same error in strace18:25
max3i am le dumb18:29
=== strigazi is now known as strigazi_AFK
fullstopHi all.  Where would be the right place to ask about the inclusion of a root certificate?  Does that fall more into debian-land?20:02
sarnoldfullstop: what's the goal?20:02
sarnoldfullstop: talking with mozilla may be quickest, iirc their certificate store is The Source for the ca-certificates package20:03
fullstopsarnold: the certificate bundle does not contain StartSSL's extended validation root.20:03
fullstopsarnold: it actually looks like mozilla's cert store does contain it.20:04
fullstopin short, chrome/chromium on linux will never show a "green bar" for any startssl ev cert.20:04
fullstopmaybe I'm completely wrong here, but that's where I got after talking to chromium people.20:06
sarnoldfullstop: if you would, please https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+filebug  -- that'll get it to the right people20:08
sarnoldfullstop: bonus points if you can show it in the mozilla bundle :)20:08
fullstopI'll try to dig that up.20:08
sarnoldfullstop: thanks!20:09
=== dzragon is now known as dzragon^afk
=== dzragon^afk is now known as dzragon
=== dzragon is now known as dzragon^afk
=== dzragon^afk is now known as dzragon
=== dzragon is now known as dzragon^afk
=== dzragon^afk is now known as dzragon
geniiIs there any way for a PXE server to know the architecture of a client machine so it can feed the correct binary for that platform?21:57
naccgenii: yes, iirc, well, over dhcp there is21:58
geniiDocumentation on the subject seems sparse21:59
naccpxe-system-type, iirc?21:59
naccgenii: option pxe-system-type code 93 = unsigned integer 16;22:00
naccthen, you can do, .e.g22:00
naccif option pxe-system-type = 00:06  for x86, 00:07 for x86_6422:00
naccgenii: https://tools.ietf.org/html/rfc4578#section-2.122:02
geniiApologies on lag, work required me for a bit...22:05
naccgenii: that only seems to cover the x86 family, though, do you need to do more architectures than that? not sure if, e.g., powerpc provides a differn value (should be debuggable)22:05
geniiPXE system is currently based on dnsmasq22:05
geniinacc: Ideally one server for x86,x86-64, PPC, ARM, and MIPS22:07
* genii gets back to reading22:07
naccgenii: ok, dnsmasq should be able to see the same option, i think22:08
naccgenii: not sure if those other archs have appended to the above list in their pxe env, unofficially22:09
naccgenii: iirc, power does something specific, but i can't reacall22:09
geniiYeah, also PPC has little-endian and big-endian types22:10
* genii makes more coffee22:10
geniiInteresting, there seems to be an #isc-dhcp channel on Freenode22:14
naccgenii: right, that's a good point22:15
naccgenii: i don't believe the BE implementations support PXE, fwiw22:15
drabhi, trying to install 1604 from pxe and getting an error about "kernel modules not found on mirror"22:31
drabexactly the same as this guy: http://askubuntu.com/questions/754947/how-to-fix-no-kernel-modules-were-found22:31
drabunfortunately no answer there, someone else is saying to be having the same problem installing from USB22:32
drabso this doesn't seem to be pxe related, which indeed it shouldn't, the installation is well in progress22:32
drabany thoughts?22:32
sarnolddrab: try hitting control+alt+ f2..f7 to see if there are more explanatory error messages on another terminal22:35
sarnolddrab: check also the logs, there may be more debugging info there22:36
ShaRoseTrying to get ulimit -n to work for all users, edited /etc/security/limits.conf to have * soft/hard nofile 200000 and /etc/pam.d/* to have session required pam_limits.so. Default is still 1024 soft and 4096 hard, UNLESS I go su $USER, after which it works.22:38
ShaRoseTrying to avoid adding su $USER to every script because I really, really shouldn't have to use that kind of a hack.22:38
* ShaRose is debating whether he should just shrug and add su $USER into /etc/profile :P22:39
ShaRosewell that at the whole 'enter your password' deal22:40
randymarsh9ShaRose: if it's stupid and it works it ain't stupid22:41
randymarsh9;)22:41
ShaRoseit don't if the user has a password and it's in a script :P22:41
ratraceShaRose: not sure I understand your problem. If you log in as a user, do you see the limits you've set in limits.conf?22:41
ShaRoseno, I see the defaults: soft 1024, hard 4096.22:42
ratracehow did you set up the limits.conf?22:43
ShaRosesudo nano /etc/security/limits.conf, add the 2 lines at the end22:43
ratraceyeah what two lines?22:43
ShaRose(there aren't any files in /etc/security/limits.d)22:43
ShaRose* soft nofile 200000 and * hard nofile 20000022:43
ShaRoseI've even spun up a ubuntu server install in a VM so that I didn't have to reboot my main server a bunch of times trying stuff, but it's not even working there22:44
ratracebummer.22:45
drabsarnold: not much, syslog shows the same error22:45
drabsaying it can't find a suitable module for kernel 4.4.0-1522:45
drabthis has probably something to do with the fact it's a beta2, but I can't figure out what, after all it should still be valid22:46
ShaRoseyeah, kind of sucks to have a webserver that keels over with ~500 clients because it's hitting ulimit issues22:46
drabsince a final release hasn't happened yet22:46
ShaRose(to be fair, it's only personal image hosting, but...)22:46
=== Piper-Off is now known as Monthrect
ratraceShaRose: which service?22:46
ShaRoseservice?22:46
ratracenginx?22:46
ShaRoseoh, caddy22:46
ShaRosetesting it out22:46
ShaRosenginx would have the same problems sadly22:47
sarnolddoes the caddy initscript set ulimits? e.g. /etc/init.d/nginx has explicit ulimit support..22:47
ShaRoseright now I'm mitigating it by just having cloudflare turned on22:47
sarnold.. and since it never uses authenication it'll never go through the PAM stack.22:47
ShaRoseactually, atm I'm using monit for it: testing server, so22:48
sarnolddoes the monit initscript / upstart config / systemd unit file set ulimits?22:48
ShaRose(I'm only REALLY avoiding shutting it down for znc tbh, I'm planning on wiping and restarting the entire thing when I get this last thing solved)22:48
ShaRoseno, but it's not just monit that's having the problem, I can log in as a non-root user over ssh and do ulimit -n and get back 102422:49
ShaRosein fact even logging in as root doesn't do it, but w/e22:49
ShaRoseproblem SEEMS to be that logging in isn't going through pam, so it's not setting limits22:49
sarnoldit depends, sshd can be configured to use pam or to skip pam; by default on debian/ubuntu it's set to use pam22:50
ShaRoseyeah, checked that too, but even then a screen should go around that afaik22:51
ShaRoseok so I looked through every single control file in pam.d, and unless it was obvious it isn't a user (common-password for example) I added or made sure that session required pam_limits.so was there22:59
ShaRoseand it SEEMS to have worked on my test machine22:59
ShaRoseI suppose let's test on the main one...23:01
=== alexisb is now known as alexisb-afk
ShaRoseOk, so that's annoying. It seems it still doesn't work, even su.23:06
keithzgIs it known that the daily builds for Xenial fail on the installation step? I've gotten it reliably a few daily builds in a row now. I see on the QA site that someone tested and had success with Beta 2 apparently, although that ISO isn't even available to download anymore23:50
keithzgNote that I'm installing trying to use UEFI; gonna test legacy now.23:51

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!