/srv/irclogs.ubuntu.com/2017/02/15/#ubuntu-server.txt

tewardrbasak: uhm, who looks after the perl autopkgtests00:18
tewardbecause there's some nasties in there holding up Perl, and we need that to get out of proposed, or forcibly bypass that, before we can actually test the merge, etc.00:18
tewardbecause i need to rebuild if we've bumped Perl at all00:18
=== Guest3904 is now known as medberry
=== medberry is now known as med_
=== tgm4883_ is now known as tgm4883
=== zwamkat_ is now known as zwamkat
=== mihalis68_ is now known as mihalis68
=== lukasa_ is now known as lukasa
=== TodPunk_ is now known as TodPunk
=== petevg_ is now known as petevg
=== arosales_ is now known as arosales
=== robher_ is now known as robher
=== lordievader is now known as Guest65702
=== zeestrat_ is now known as zeestrat
=== ulkesh_ is now known as ulkesh
=== bradm_ is now known as bradm
=== alkisg1 is now known as alkisg
b3h3m0thHow do I: Lock user for X seconds after Y consecutive failed login attempts within a time windows of Z seconds.07:27
b3h3m0thUsing PAM ?07:27
sarnoldb3h3m0th: I think pam_tally2 is probably the way to get there07:30
b3h3m0thI tried tally but could not figure out a way to specify the Z param07:30
b3h3m0th*tally207:30
b3h3m0thpam_faillock,  a redhat patch does support this using a fail_interval param. But  unfortunately for me ubuntu does not ship it :(07:31
b3h3m0thfail_interval=n: The length of the interval during which the consecutive authentication failures must happen for the user account lock out is n seconds. The default is 900 (15 minutes).07:41
b3h3m0th^ This is what I'm actually looking for. [source: https://linux.die.net/man/8/pam_faillock]07:41
b3h3m0thI want a user to be able to try to login (Y-1) times every Z seconds indefinitely without lockout.07:42
=== madwizar1 is now known as madwizard
zioprotohello all. Just starting a trusty to xenial do-release-upgrade on a server running glance-api and glance-registry. Openstack version MItaka. Any specific Openstack advice ? It is a staging system so relax :)08:56
aaranHi, what is the name of the service that lets you book out time slots on a server for computation? I thought it was time sharing but thats from the olden days of mainframes09:47
aaranany ideas?09:49
aaranhmm think I found it job scheduling09:54
rbasakaaran: are you thinking about stuff like https://en.wikipedia.org/wiki/TORQUE_Resource_Manager ?09:54
rbasakIt's more of an HPC thing.09:55
rbasakAlso Slurm09:56
aaranbasically we have a gpu server that a bunch of staff would like to run jobs on and its a system to book time to use the machine09:57
aaranits a single server so I dont think that slrum would be needed as that seems to be for clusters?09:59
rbasakFor a single server, why not just use a shared calendar and trust?10:07
aaranbecause of students and their inability to stick to a schedule10:08
aaranBut its an idea, thanks I will pitch the idea and wait to see what comes of it10:08
caribou_rbasak: jgrimm: FYI I have just synced clamav. The only remaining part will be to get the MIRed tomsfastmath in10:10
cpaelzeraaran: from my experience with similar - unfortunately not FOSS - solutions after the initial setup of getting hard schedules everybody complains about wasting so much time10:10
cpaelzeraaran: if you go for calendar+trust doe it as calendar+trust+communication; nothing is as bad as killing a 8 hour job 5 minutes before it completes :-)10:11
cpaelzeraaran: if you go for any sort of automation, make it a prio or credit based system with seme tolerance before killing runnign jobs10:11
=== caribou_ is now known as caribou
rbasakFor hard (no trust needed) schedules, I wonder if MAAS could help. It has an API, so you could automatically redeploy and give access to a scheduled user every time the scheduled user changes.10:12
rbasakNot too much scripting.10:12
rbasakPerhaps way overkill though (over using trust).10:12
aaranhhmm10:12
cpaelzeralso chargeback (no matter how small) helps tremendously to get the people to keep their work fast and efficient10:12
aarannot sure if chargeback would be feasible10:14
cpaelzerdoesn't have to be money10:14
cpaelzerif you implement something time credit based just lower that in case one overruns10:15
cpaelzermakes things much more self regulating10:15
cpaelzerbut well over-engineering s at stake - start with calendar+trust and see where you get10:15
=== Guest65702 is now known as lordievader
joelioany idea how https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-8743.html is getting on, appreciate it's medium risk11:10
rbasakjoelio: try asking in #ubuntu-hardened.11:15
rbasak(it's also quite early for the Americas so you might not get an answer straight away)11:16
joeliorbasak: no worries, it's just on my list of things to keep an eye on, no biggie :)11:17
cpaelzernacc: I think I debugged and understood the pg-repack issue, if you could trigger to re-run the postgres dep8s that would be nice11:48
cpaelzernacc: from https://bileto.ubuntu.com/excuses/2470/yakkety.html that would be11:48
cpaelzernacc: and actually the postfix tests and not the postgres ones11:49
cpaelzerpitti confirmed in the bug that these might just be flaky and worth a re-trigger11:49
=== coreycb` is now known as coreycb
zioprotoregarding openstack packaging for glance the trusty to xenial upgrade was painless12:57
zioprotoI am using the standard xenial mitaka packages12:57
=== freyes__ is now known as freyes
zioprotoFinally some interesting problem. I guess all puppet+openstack people will run soon into this https://bugs.launchpad.net/ubuntu/+source/puppet/+bug/157047213:16
ubottuLaunchpad bug 1570472 in puppet (Ubuntu) "Set systemd as default service provider" [Medium,In progress]13:16
zioprotojamespag`, coreycb this bug is not assigned on Xenial, there is PPA that fixes the problem. Before we have a bunch of Openstack people having this problem, how can we make sure this gets assigned for review and merge in Xenial ??? thanks https://bugs.launchpad.net/ubuntu/+source/puppet/+bug/157047213:24
ubottuLaunchpad bug 1570472 in puppet (Ubuntu) "Set systemd as default service provider" [Medium,In progress]13:24
=== miczac_ is now known as miczac
=== alai` is now known as alai
cpaelzercoreycb: FYI the machine type fixes just passed the unapproved queue14:39
cpaelzercoreycb: I'll ping again when they built, tested and I'mabout to mark as verification done14:40
coreycbcpaelzer, ok thanks14:41
lucidguyLooks like if you want Nagios4 on Ubuntu 16.04 you have to build from source.. not on any reputable repo?14:59
=== ashleyd is now known as ashd
rbasaklucidguy: yeah I don't think Nagios 4 is packaged in Debian or Ubuntu.15:16
lucidguyrbasak: I'm trying to decide if I should stick with v3 from repo or go and build v415:19
rbasakI don't know enough to answer that question, sorry.15:21
tewardcpaelzer: thanks for your testing, I appreciate the rapidity of your getting those tests done :)15:56
tewardcpaelzer: thanks for your testing, I appreciate the rapidity of your getting those tests done :)15:56
tewardcpaelzer: did you see anything that would otherwise be considered "bad" in the package?  (My brain isn't fully awake, I need another 3 coffees lol)15:56
cpaelzerteward: I did not do packaging review yet16:00
cpaelzerteward: didn't realize I should16:00
tewardcpaelzer: nah, it's all good, i meant as "Anything odd introduced in the logs"16:00
tewardpackaging review I'm confident is fine, base Debian + our delta16:00
cpaelzerteward: from the "package user side" it appeared good to me16:00
tewardand we were able to drop a few things.16:00
tewardcpaelzer: yeah that's the primary tests I was after16:00
tewardpackage review, I'm confident it's fine, because it's pretty much base Debian package + nginx-core specific things + build compat. fix for fPIE/fPIC that seems to be ubuntu specific + apport hooks16:01
tewardnginx in Debian just uploaded 1.10.3-1 recently so it's not able to be pulled yet for merging, but it shouldn't be more than packaging changes.16:02
tewardi'll check that tomorrow, until then I'm going to push this up because I'd *love* to get this in before FeatureFreeze16:02
tewardwe can FFe request for any packaging-specific changes that aren't 'new features'16:02
tewardfirst, food, 'cause I haven't eaten all morning16:03
joeliolucidguy: considered Icinga2 ?16:10
cpaelzerrbasak: can you hit the importer on exim4 and logwatch for me - I'd like to consider feasibility of a re-merge before FF16:25
jgrimmcpaelzer, thanks!  cpaelzer btw, i suggested that you be added to the importer team16:27
cpaelzerjgrimm: I had hoped to annoy rbasak often enough that he does so on his own at some point :-)16:28
jgrimmheheh16:28
rbasakRunning16:28
cpaelzerthanks16:28
cpaelzerjgrimm: btw I escaped the libvirt abstraction hell, libvirt-python binding to the rescue16:29
jgrimmrbasak, since you are at it.  autofs and libqb would be handy to import too.16:29
lucidguyjoelio: no, boss asked for Nagios16:29
jgrimmcpaelzer, \o/16:29
rbasakcpaelzer: done. I think they were no-ops. The automatic importer is working maybe?16:30
rbasaknacc: OK to push obviously-correct minor usd bugfixes straight to master?16:40
tewardrbasak, cpaelzer, jgrimm, powersj: NGINX merge uploaded to proposed.  Faster than my initial timeline was yesterday.  :)16:41
rbasakteward: \o/16:41
rbasakThank you!16:41
jgrimmteward, \o/16:41
tewardmight need another one as an FFe for 1.10.3-1 from Debian (additional packaging changes)16:41
tewardbut hey *that* merge we get to drop a delta xD16:41
rbasaknacc: never mind. It's a bug in my pending branch. Not even in master!16:42
tewardrbasak: those local branch/tree bugs are pesky and annoying, aren't they :P16:43
rbasak:-)16:43
rbasakNice to get the bugs ironed out before I propose a merge :)16:43
naccrbasak: ack on bugs16:45
nacccpaelzer: i think pitti got those retriggered?16:45
rbasakjgrimm: autofs done (no-op?)16:46
rbasakjgrimm: libqb running (looks like an import from the beginning)16:46
tewardrbasak: eheh, look at all the "NEW" in the queue xD  https://launchpad.net/ubuntu/zesty/+queue16:49
teward(for nginx)16:49
teward(translations)16:50
jgrimmrbasak, thanks! and thanks!16:56
naccjgrimm: fyi, new dogtag-pki is being synced over and built now, then various tests should rekick or i will manually as neccessary16:56
jgrimmnacc, thanks16:56
naccjgrimm: re: openvpn, can i reject the old merge request?16:57
naccjgrimm: MP: #31633716:58
jgrimmnacc, yep i only left it around for you to refer back to16:58
naccjgrimm: ack, will close once i merge the new one16:58
jgrimmsince i'd uploaded a new branch. thanks sir16:58
naccjgrimm: 317004 is current?16:58
jgrimmnacc, yes16:59
coreycbzul, i'm working on testing a cherry-pick of this to nova: https://review.openstack.org/#/c/431582/17:02
=== JanC_ is now known as JanC
GPenguinhello, i am interested in the wordpress package on ubuntu 16.04. server edition17:04
GPenguinthe readme in /usr/share/doc/wordpress is ... uhm... well, a bit rusty?17:05
GPenguini see the mysql server itself is not installed. and the doc speaks about a password which i never set17:05
GPenguinis there a more detailed and more up to date version of the documentation out there?17:06
naccGPenguin: yes, wordpress only depends on a client17:07
naccGPenguin: you need to setup a server potentially17:07
GPenguinah, hmmm17:07
naccGPenguin: if you insatll suggests, it will pick up mysql-server as well17:08
rbasakjgrimm: libqb done17:08
GPenguinnacc: i am also missing the wp-config.php17:11
jgrimmrbasak, thanks17:12
GPenguinuhh, that is in /usr/share/wordpress17:13
naccGPenguin: looking to see if i can reproduce; iirc, when i did the update, i got it installed and setup fine17:17
naccGPenguin: and the apache config uses /usr/share/wordpress17:26
naccGPenguin: the example one17:26
naccGPenguin: yeah, so that basically works, your choice of apache configuration, enable it, run setup-mysql and then navigate in a browser to finsih the wordpress install like normal17:37
GPenguinhmmm17:38
zulcoreycb: okie dokie18:04
BrianBlaze420oh man going from 8 to 16 is fun lol18:27
compdoc16 girlfriends?18:37
OerHeks16 bit?18:42
nacc8.04 to 16.04 based upon yesterday's context18:44
naccBrianBlaze420: honestly, it's probably easiest to backup data and install from scratcch18:44
BrianBlaze420yeah that's what is happening18:44
BrianBlaze420so sad lol18:44
BrianBlaze420i am more sad that the guy who set this up walked away from it for so long18:45
BrianBlaze420anyways I am just venting :)18:45
=== jdstrand_ is now known as jdstrand
tewardBrianBlaze420: sounds like an evil system I had to work with in the past, at my one workplace.  8.04 running evil Python18:55
teward16.04 wasn't out yet so we had to -> 14.0418:55
teward14.04 -> 16.04 will be easy heh18:55
tewardpython, dovecot, etc. all configured on 14.04 works pretty well on 16.04 too :P18:55
BrianBlaze420lol yeah I am looking forward to getting there18:55
BrianBlaze420where I am not horrified of updating lol18:55
tewardtook a year to migrate everything off 8.0418:56
tewardbecause of python lol18:56
tewarddovecot and postfix were easy18:56
tewardpython, not so much18:56
teward(3rd party library updates, etc. caused problems018:56
tewards/library/module/18:56
tewardanyways i digress :)18:56
BrianBlaze420:)18:57
BrianBlaze420at least I feel less alone, so I appreciate lol18:57
tewardsarnold: ohai, you!  nginx merge uploaded to -proposed.  Lotsa new binaries lol18:57
sarnoldteward: \o/ nice, how'd it go?18:58
tewardsarnold: painfully.  'cause it's a ***horrible*** evil process.18:58
sarnoldteward: aye :/18:58
tewardbaseDebian + PackagingDeltaChanges + (fixMistake x 4)18:58
tewardfinally got it to a PPA last night, and cpaelzer was kind enough to run install/upgrade tests18:59
tewardi'm just waiting for the mismatched components report :P18:59
teward'cause there'll be some18:59
teward(some of the dynamic module packages)19:00
JoseLuis_Good afternoon all.19:13
tewardgreetings19:14
JoseLuis_I have a lot of mail in my server about Cron <root@localhost> /etc/cron.hourly/kill.sh  and Cron <root@localhost> /etc/cron.hourly/cron.sh19:16
JoseLuis_SIOCSIFFLAGS: Cannot assign requested address     SIOCSIFFLAGS: Protocol driver not attached19:18
sarnoldwhat do those scripts do?19:20
JoseLuis_cat /etc/cron.hourly/kill.sh  http://termbin.com/vgz819:22
JoseLuis_cat /etc/cron.hourly/cron.sh http://termbin.com/cfb419:22
sarnoldoh crap19:23
sarnoldnow I remember why your name is familiar19:23
sarnoldJoseLuis_: https://www.linode.com/docs/security/recovering-from-a-system-compromise19:23
JoseLuis_sarnold: I am going to read19:25
JoseLuis_sarnold: Definitely, we will to create a new server in linode, but we should need to install security first before to install program and database.19:34
sarnoldJoseLuis_: it'd be worth trying to figure out how this instance was compromised while you're at it -- full forensics are extremely difficult, but it'd be best to know if the machine was hacked via ssh password brute-force searches, or a web-based management console, or something else..19:36
JoseLuis_yeah, but I do not know how to do this.19:40
tewardsarnold: compromised systems are compromised!19:41
tewardJoseLuis_: you'd either hire someone19:41
tewardor just not bother finding how to ID the compromise.  Either case, nuke with fire19:41
JoseLuis_I was hired in august for manage mongodb and to make some scripts in linux to monitoring some server in linode and windows.19:46
sarnoldI wonder if this was involved http://thehackernews.com/2017/01/secure-mongodb-database.html19:48
JoseLuis_the security in linux servers and windows server is almost null, (pass with 12345678, qwerty, etc..)19:49
tewardJoseLuis_: well, "the security in linux servers" is a matter of configuration19:50
teward99% of the time, people who set up the servers19:50
tewarddon't follow common sense practices19:50
JoseLuis_sarnold: thanks for the information.19:50
sarnoldteward: I'm afraid that's what he was reporting on :)19:51
sarnoldJoseLuis_: good luck19:51
tewardheh19:51
tewardsarnold: CrapSecurity is about equal to ZeroSecurity19:51
tewardand then there's my network, locked up tight, every system has a firewall, different passwords for each, service and priv. separation across multiple systems...19:52
tewardVLANed out the wazoo to protect other subnets...19:52
tewardIDS/IPS on the border...19:52
tewardredundant firewalls...19:52
teward... is my network overkill yet?  :P19:52
sarnoldayup. :)19:53
=== Gorian- is now known as Gorian
=== manjo` is now known as manjo
pmatulisa rift in the fabric of time21:09
=== skeezix-hf is now known as Ofir
=== Ofir is now known as skeezix-hf
Dmitrii-Shcpaelzer: hi, is there a reason why libvirt is missing from https://code.launchpad.net/~usd-import-team/+git ? I'm not too familiar with usd-importer yet but 'git grep -i libvirt' in its repo shows that it is commented out in the usd-cron-packages.txt:#libvirt21:39
Dmitrii-Shcpaelzer: in general, I am looking for a good way to do quick git merge-base --is-ancestor <hash1> <hash2> type of checks for upstream patches and it is much easier to have an up-to-date git repo at hand to do it21:42
naccDmitrii-Sh: there is a distinct git repository being used21:43
naccDmitrii-Sh: for libvirt they use the debian repo, iirc21:44
naccDmitrii-Sh: there is an ubuntu branch (or branches)21:44
naccDmitrii-Sh: i might be wrong, smb may also know21:44
Dmitrii-Shnacc: hmm, I saw the Debian repo https://anonscm.debian.org/cgit/pkg-libvirt/libvirt.git/refs/ but there is only a single ubuntu branch there (from 2007)21:46
naccDmitrii-Sh: oh sorry, there is a lp repo, i guess (found it from the ubuntu package search SCM link)21:47
nacchttps://git.launchpad.net/~libvirt-maintainers/ubuntu/+source/libvirt21:47
naccDmitrii-Sh: that looks current, i think21:48
naccDmitrii-Sh: also, should be the Vcs-Git value in the control file in the source pacakge, iirc21:48
Dmitrii-Shnacc: this one seems right21:51
Dmitrii-Shnacc: http://packages.ubuntu.com/source/xenial-updates/libvirt the repo mentioned here too21:51
naccDmitrii-Sh: cool :)21:51
Dmitrii-Shnacc: wasn't the case with qemu AFAIR but this one is good )21:52
Dmitrii-Shnacc: thx21:52
powersjrbasak: thanks for the review of etckeeper, updates made!22:35
=== miczac is now known as miczac\away
=== mwhudson_ is now known as mwhudson
=== mwhudson is now known as Guest32650
=== mwhudson_ is now known as mwhudson

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!