[01:10] having issues using VPN. it says it is connected but pages dont load and i cant ping past router unless i DC from vpn [01:10] i can connect to VPN from windows 10 with no problem [01:10] check error logs on both the vpn client and the vpn server === JanC_ is now known as JanC [07:36] Hi all, I am having problems with lio/targetcli restoring config on boot, is anyone else using it? === JanC is now known as Guest38106 === JanC_ is now known as JanC [08:27] Good morning. === disposable3 is now known as disposable2 [10:22] I'm having difficulty installing ubuntu-server 16.04.2. When it detects the disc is gives, "Enter an IP address to scan for iSCSI targets". I don't know what this is about. I want to just partition my local disk. Any help appreciated. [10:24] If you don't want to use iSCSI can you not cancel the window? [10:28] thanks for replying lordievader. It's the only option it gave me. I fiddled about with BIOS settings but it only seemed to give me the option to set up iSCSI. Don't know why. However, the power supply in the back of the PC just made a noise like an arc welder. Proble Solved! [10:29] Err, okay? [10:29] Computer not working so I'll have to do somthing else. [10:30] I'm being silly. I won't be able to progress for the moment. I'll have to either dig out a power supply from another PC or use VM. [10:31] It's unusual though. Previously when I've installed ubuntu, it opens the partitioner and I can choose between manual partition or just accept defaults. Didn't give me the chance for some reason. [10:35] Are you using some kind of raid controller? [10:37] no [10:38] I seem to recall having a simila difficulty with an old Dell before. As it appears to have turned into an arc welder, I'll defer that for the momoent. I'll use another old PC for the moment. [10:38] I'm going to have to muck about with hardware for a while. Thanks === ggherdov`____ is now known as ggherdov` [13:00] +1 on zfs it is really REALLY nice [13:00] sorry wrong window [13:15] The same thing was said here a few days ago ;) [13:27] zul, i'm starting on cinder and horizon rc2 [13:30] ok [13:31] coreycb: i got nova and manila [13:31] ok [13:42] zul, i'll get the neutrons [13:42] ok [13:49] zul, i'll get trove [13:50] coreycb: i got mistral* after.. [13:54] i got magnum as well [13:57] Hi all, how can I get ubuntu server to auto import zpools on boot? [14:25] coreycb, zul: we need to sortout qemu for ppc64el in proposed [14:25] I'll do that now [14:25] I need to disable the seccomp support on that arch [14:25] jamespage: ack [14:27] jamespage, ok thanks [14:35] lordievader: exactly :D the error was "Up arrow, Enter" :D [14:36] coreycb, zul: qemu re-backporting now [14:36] jamespage: k === kirkland` is now known as kirkland [14:53] mwhahaha, hey around? [14:54] jamespage: what's up? [14:54] mwhahaha, are you around at the PTG next week? [14:55] jamespage: I will not be [14:56] mwhahaha, hmm no openstack-puppet slots mon/tues [14:56] mwhahaha, OK [14:56] jamespage: yea we had 0 response when asked about the ptg so nothing for Puppet [14:57] jamespage: EmilienM will be there if you had specific questions [14:57] I had a schedule conflict [14:57] mwhahaha, np - I've been working to get topics scheduled to discuss what we're planing with snaps [15:00] jamespage: yes, feel free to reach me [15:01] EmilienM, awesome I will do [16:21] this is a general server question... does a single drive in a RAID array have data that can be read? [16:25] DammitJim: depends on what raid, depends what you mean read, in raid1, yes, in raid6 it depends and you'd have to read at low level [16:26] right, but I mean, you can't just grab this drive and plug it into some cable to your computer and just read data [16:30] from a raid1 sure, but probably not from other raid levels [16:30] can I add a md/raid device as a member in annother md/raid ? [16:32] thanks [16:38] do you guys know if there is a way to control what range of ID number to use for when one creates a new user? [16:38] for some reason on a server I have that is joined to a domain, it sets the ID to the 10,000 range [16:38] instead of just 1,000 [16:44] nacc, thoughts? https://bugs.launchpad.net/usd-importer/+bug/1665703 [16:44] Launchpad bug 1665703 in usd-importer "add subcommand for 'import-dsc'" [Undecided,New] [16:47] smoser: certainly reasonable to do. Would it just be `git-dsc-commit`? I'm not sure we can support parenting it correctly for the first version imported (it'd be an orphan), but as lng as 1.4, 1.5 mention 1.3 in the changelog, i think we'd find it [16:47] rbasak: um, i'm not sure why it's saying 'unsatisfiable dependencies' on nginx on update_excuses, can you peek? [16:47] smoser: that is, wrapping git-dsc-commit as we do now with usd [16:47] the package versions it's after are *listed* in Zesty right now, per rmadison... [16:47] also Perl still hanging the migration out of proposed [16:48] teward: new build hasn't been copied to the archive(s) yet? [16:48] teward: there's latency there between when the build finishes and when excuses sees it, iirc [16:48] nacc: new build of the dependencies you mean [16:49] *brain is not fully online* [16:49] teward: oh sorry, i was looking at the nginx lines, my fault [16:49] nacc: two issues: (1) "Dependency not satisfiable" when those packages exist in those archs. (2) Perl version is holding up migration, but I don't know why. [16:50] teward: let's focus on 1), trying to reproduce in my chdist, one sec [16:51] nacc: mmkay. My brain is offline today so blah. :) [16:51] ah, but you're probably right -1ubuntu2 probably isn't uploaded when it was created [16:51] though it should've been since it was uploaded yesterday heh [16:53] teward: component mismatch. [16:53] libnginx-mod-http-lua is in main. libluajit-5.1-2 is in universe. [16:53] teward: yeah, main/universe [16:53] teward: as is liblua5.1-0 [16:54] rbasak: http-lua should go to universe then [16:54] teward: is there any reason those two can't live in universe? [16:54] nacc: i'm five steps ahead of you [16:54] Yeah you can do that. An archive admin can move it. [16:54] rbasak: the bug for the merge has what should be in main [16:54] If you can't find one on IRC, file a bug against nginx and subscribe ~ubuntu-archive please. [16:54] http://people.canonical.com/~ubuntu-archive/component-mismatches-proposed [16:54] in terms of libnginx-mod [16:54] teward: --^ :) [16:55] Or just subscribe ~ubuntu-archive to that bug I guess, if it's still open. [16:55] it's a binary only movement, so it's easy, just needs the AA as rbasak said [16:55] rbasak: we do have a few of those for server, it seems [16:55] rbasak: it's the merge bug until it moves out of proposed... [17:07] rbasak: nacc: do we know why nginx-core-dbg, a debug symbols package, is being caught? [17:07] is it because it's new? [17:08] WOW i'm an idito nevermind [17:08] actually, wait i still don't knwo why that's listed [17:09] teward: as i read it, ubuntu1 produced that binary, but ubuntu2 did not [17:09] (it produced -dbgsym instead) [17:09] https://launchpad.net/ubuntu/+source/nginx/1.10.3-0ubuntu1/ vs https://launchpad.net/ubuntu/+source/nginx/1.10.3-1ubuntu2/ [17:10] (or only -dbgsym rather) [17:11] teward: and excuses/proposed-migration doesn't like binaries going away [17:13] ah, right [17:13] nacc: that's a result of the evil packaging changes [17:13] i'll make a note of that too [17:14] teward: I *think* you need AA intervention for that too [17:14] well the AAs are going to be busy either way [17:14] :) [17:18] rbasak: i'mma subscribe ubuntu-archive and add this massive list of things heh [17:21] rbasak: added to the bug, and ubuntu-archive subbed. I hope I dont get shot for any of these things heh. [17:21] but that should be able to fix the mismatches. [17:22] Perl is just hanging the migration currently from proposed to nonproposed :/ [17:23] teward: thanks! [17:24] I wouldn't worry too much about Perl. I'm sure the Foundations team will take care of it :-) [18:44] Hello! [18:44] I upgraded linux-image of Ubuntu 16.04 LTS. But the post installation process doesn't succeed. [18:44] Someone can help me? [18:45] It generates too much initramfs to occupy whole /boot [18:56] is there a way to disable these ssl warnings on mysql server 5.7? [18:58] I'm trying to create an image for Openstack manually and I am using the minimal ubuntu installer and without selecting anything during installation its 1.9GB for me. I'm using QCOW2 and I have no idea how to make the installation smaller. Any suggestions? [18:59] http://cloud-images.ubuntu.com/xenial/current/xenial-server-cloudimg-amd64-disk1.img this image from Ubuntu is ~300MB [19:00] Emmanuel_Chanel: btw irc works best if you stick around for a while :) [19:00] Emmanuel_Chanel: how large is your /boot? do you even need a /boot? [19:03] sarnold: /boot = 113MB and yes, I need /boot . [19:03] My HP server is not with UEFI but with BIOS. [19:04] But the HDD RAID1 pair is about 6TB. [19:04] sarnold: Can you help me? [19:06] Emmanuel_Chanel: ouch. that's -really- tiny. I think 500 MB or so would be far safer [19:07] /boot on my laptop is 256M, /boot on a serverish-machine is 280. definitely you need bigger.. [19:08] ok. [19:08] Emmanuel_Chanel: my guess is you have old kernels around [19:08] Do you know why it generates unneeded initrd images? [19:08] Emmanuel_Chanel: that size /boot is only really going to be able to store 1 or 2 kernels it feels like [19:09] greetings had to "unset DISPLAY" on ubuntu server, how do i get display back? [19:09] Emmanuel_Chanel: define 'unneeded' [19:09] nacc: How can I do? [19:09] Emmanuel_Chanel: `apt autoremove` typically [19:09] Emmanuel_Chanel: but it depends on what all is installed [19:10] Emmanuel_Chanel: what version of ubuntu and please pastebin `ls -ahl /boot` [19:18] nacc and sarnold http://pastebin.com/AZNc4yD4 [19:19] do you guys know what I can add to my mysql config so that I don't get SSL warnings? [19:19] DammitJim: what warning are you getting? [19:20] Emmanuel_Chanel: ls -ahl /var/lib/initramfs-tools [19:20] Emmanuel_Chanel: excellent; what kernel does uname -r report that you're running now? [19:20] WARN: Establishing SSL connection without server's identity verification is not recommended. [19:20] I understand I can provide a useSSL=false on the client connecting to the server [19:20] but can I set something up on the server so it doesn't check for this? [19:21] DammitJim: ehhhh... using ssl without verification is better than using no ssl at all. [19:21] sarnold: uname -r = 4.4.0-62-generic [19:21] DammitJim: and enabling verification is going to be some work. I'd leave it alone. [19:21] sarnold, maybe you can help me understand what that means [19:21] nacc: I'm trying it now. [19:21] that's probably what I'm missing [19:22] you mean leave the warnings alone? [19:22] this is for local connections [19:22] DammitJim: this means that the certificate from the other side can't be verified -- it isn't signed by a trusted certificate authority [19:22] oh gosh [19:22] but I don't want to use certificates [19:22] http://pastebin.com/RURU7bLU [19:22] nacc: Done. [19:23] Emmanuel_Chanel: ok, that is why extra initrds are being generated [19:23] DammitJim: you don't want to go to the hassle of using _real_ certificates... but self-signed is fine enough for many uses, and this is probably one of them. [19:23] *normally*, i beleive that directory only contains kernels that are actually installed [19:23] oh man [19:23] Emmanuel_Chanel: did you manually delete some kernels (rather than using apt)? [19:23] nacc: So all I need to is delete them except 4.4.0-62-generic [19:23] so, a solution would be to use self signed certificates, huh? [19:24] Emmanuel_Chanel: yes, i believe so [19:24] do I have to then import them for the server and then import them for the client? (even though the server and client are on the same server) [19:24] nacc: No... I deleted /var/tmp/mkinitramfs* , though. [19:24] nacc: ok. I do. [19:24] Emmanuel_Chanel: be sure to keep a fall-back as well; in general, keep the kernel you're running, keep the newest, and if those are the same, keep the next newest :) [19:24] sarnold: no fallback in /boot (taht i can see) [19:24] DammitJim: yeah; I suspect you're already using self-signed certs [19:24] which is why i think something manually was done [19:25] I am, but not for mysql [19:25] so, would I need to change my client connections to use a client certificate? [19:25] or where do I tell mysql client that the server cert is good? [19:26] sarnold and nacc: Thanks for your help! Looks my problem is solved. [19:26] oh man, I loose either way because I have to get the developers to change their connection code [19:26] is that right? [19:28] DammitJim: I don't know how to fix that -- I really don't know mysql -- but if you put the self-signed cert in your /etc/ssl/certs/ directory and run update-ca-certficates I think that will do the trick -- read the update-ca-certificates manpage first and make sure it sounds right [19:29] sarnold, so if I add the certs, then I won't need to update connection code? === JanC is now known as Guest50386 === JanC_ is now known as JanC [19:33] DammitJim: I don't know about that; all the clients may need to have their cert stores updated if they're on different hosts.. [19:34] something tells me one can disable ssl on the server as an option [19:34] yeah you probably can but I really don't like that idea :) [19:34] why use telnet when you can use ssh? [19:35] because this will involve a couple dozen apps to be updated [19:35] why? for one warning?? [19:36] yeah, this happens in multiple servers [19:36] but it's a warning; what's wrong with ignoring it? :) [19:36] it clutters the log files [19:36] true enough [19:37] but if you don't care about the tls certificate validation then you might as well work on something that you do care about ;) === madsa_ is now known as madsa [19:39] Hello! [19:41] Hi, I recently did a fresh install of an ubuntu server (16.10). When taking a look at the open ports I noticed that it was listening on three ports. 22, 80 and 5355. 22 and 80 I knew about and it's intentional, but what is 5355? /etc/services lists it as 'hostmon', but hostmon doesn't have a manpage and I haven't found anything really relevant when googling either. Only airport-hostmon which seems to be some old apple standard. [19:42] tldr: what is hostmon running on port 5355? [19:42] Doow: what program is listening on it? [19:42] run netstat -lntp or something similar to find out [19:42] I'm running Ubuntu 14.04 LTS server edition and trying to configure exim4 to use tls. Here's my config: http://paste.ubuntu.com/24015110/ [19:43] The connection times out when connecting remotely with telnet or thunderbird. Connecting locally with telnet, I'm able to access smtp and after running ehlo, I'm able to try "starttls", but it gives me an error message that tls is unavailable. What should I do? [19:44] sarnold: 810/systemd-resolve [19:45] Doow: hopefully useful https://lists.ubuntu.com/archives/ubuntu-devel/2016-May/039350.html [19:45] geigerCounter: connection timing out sounds like firewall settings [19:46] sarnold: I wasn't running netstat as root at first =) [19:46] sarnold: thanks, I'll take a look [19:46] sarnold: On the server or the client? [19:47] sarnold: That also doesn't explain why starttls fails. [19:48] geigerCounter: indeed, but one problem at a time is the way to preserve sanity :) [19:48] Doow: aha :D [19:51] sarnold: That explained everything, thanks for the quick help [19:51] great :) [19:53] I don't think it's a firewall issue though, as before I started trying to config exim4 to use tls, I was able to access SMTP fine remotely as well. But just to be sure, I've made sure to add an exception for port 25 in Windows firewall. I know that server-side there's no firewall whatsoever and there's activity to my SMTP server just fine. GoDaddy's MX Toolbox reports when SMTP goes down and when it [19:53] comes back up and right now... it says it's down... [19:54] I just restarted exim4 [19:56] I just connected locally via telnet and was able to log in. [19:56] Well I was able to connect and ehlo, haven't actually tried to auth. [19:57] Hang on... === madsa_ is now known as madsa === jelly-home is now known as jelly === madsa_ is now known as madsa [21:33] how do I install a particular version of a package? [21:34] axisys: apt install package=version [21:34] sudo apt-get install zabbix-agent=1.8.22 says not found [21:34] how do I get a older version? [21:34] trusty latest is 2.2.2 [21:34] axisys: 'apt-cache policy zabbix-agent' will show you the available versions [21:35] on 2.2.2 [21:35] only* [21:35] axisys: according to http://packages.ubuntu.com/zabbix-agent you probably have to go back to 12.04 if you want zabbix 1.8 [21:35] so is it possible to install 1.8.x on 14.04 ? [21:36] I don't know, sorry [23:16] axisys: no, you'd need to use 12.04 for that, presumably [23:26] Okay, I think I finally found something out in regards to my exim situation. It appears that the self-signed certs I rolled for testing exim with are not valid and/or cannot be accessed by exim. [23:27] geigerCounter: ugh :/ while I wouldn't necessarily expect all clients to work with that, I sort ofhope the server itself wouldn't care [23:27] No, I mean, it literally couldn't read the cert. And upon checking I know see why. [23:27] I had MAIN_TLS_PRIVKEY as the macro instead of MAIN_TLS_PRIVATEKEY [23:27] * geigerCounter facepalms [23:28] oh man [23:29] So pedantic. [23:29] 'unknown macro' would have been kind.. [23:29] might be nice for it to complain about unknown keys in the cof? [23:29] *conf [23:29] Yeahh... [23:29] Yeah. [23:30] But it didn't do that until I tried to send stuff to/from Gmail. [23:31] That still doesn't seem to have fixed it though... [23:31] starttls still isn't working. [23:31] Wait. [23:32] -rw-r--r-- means globably readable by all users right? [23:32] yes [23:32] yes [23:33] That's what I thought. exim's now pointing to the correct cert and key, but it can't read them. [23:33] directory permissions above it may prevent the world from getting to the file, thuogh [23:33] It won't say how and why. [23:33] Ah [23:33] Well can I symlink it to another directory then? [23:33] and apparmor permissions could prevent it too (check dmesg | grep DENIED if you think this might be the case) [23:33] I don't think I have apparmor installed yet. [23:34] Mmm... yeah, the certs directory ( /etc/ssl/certs ) is readable, the key directory ( /etc/ssl/private ) is not. [23:35] I assume this is by design. [23:35] Would that prevent exim from being able to read /etc/ssl/private/exim.key ? [23:36] it could; maybe you need to add the supplementary group ssl-cert to exim's startup scripts? [23:37] I may yes, but for whatever reason my /etc/ssl/private directory is user read only. It's group executable tho... [23:37] Not sure if that makes a difference in this case. [23:38] interesting, mine is: drwx--x--- 2 root ssl-cert [23:38] So is mine. [23:38] oh ok, good [23:38] And idk. [23:38] I've got another key in here that dovecot uses and is able to read just fine. [23:38] So mm. [23:39] I'm not sure if that means dovecot spawns with different permissions or what? [23:39] dovecot probably reads it as root at startup or also has the ssl-cert supplemtnary group [23:39] Mm. Makes sense. [23:40] To add a user to a group, you run "adduser " right? [23:40] worth a try [23:41] funny, I jumped right to 'edit the startup' but it might be easier than I was making it :) [23:41] Hm? [23:41] I generally use sudo usermod -Ga newgroup username [23:42] Woo! No error when accepting mail from gmail! :D [23:43] tls starts! [23:43] geigerCounter: great :D [23:44] Yeah, that's one issue down, one to go. [23:45] Or maybe not...? [23:46] hello, know when you cp a file and use -R -v ,i whish it showed a bar of the current file size that im copyig like when you use wget [23:46] TLS error on connection from [my.ip] (gnutls_handshake): An unexpected TLS packet was received. [23:47] maybe i should use mc ,, lol [23:48] Henster: Midnight Commander? I have it, I like it, I don't use it much tho. ;p [23:49] i found this chem today tmux .. man making my life allot easer ,, screen did not work well with mc [23:49] sarnold: Okay, now after getting the 220 TLS go ahead, any additional input crashes the connection and gives me the above error. :Y What am I doing wrong now? [23:50] so i hosted my 1st wordpress website on Ubuntu server ,, man im nervious but so far so good [23:50] Henster: Hey man, congrats! It's probably way smarter than what I'm doing trying to build a custom content system. x-x [23:51] My everything is broken... [23:52] geigerCounter: yikes. that doesn't make sense :/ [23:54] sarnold: Nope. But then again, configuring email seems to be an eldritch task, so... [23:54] Lol. [23:54] @geigerCounter im learing early to make backups ,,not so sure how im going to secure remorte archive files [23:54] geigerCounter: yeah. it's miserable these days. [23:54] * geigerCounter sighs [23:54] I'm making progress at least! [23:55] Henster: Can you try that sentence again, I don't quite get what you mean... [23:56] sever 1 ,, webserver and server 2 has files server 1 uses ,, eg. some files of Apache document root .. want to encrypt the data inetween the 2 servers [23:57] inbetween* sorry my spelling [23:57] Let me see if I've got this right: You have two servers, a file server and a webserver, and you want to secure the data transfer between them with encryption? [23:59] Henster: Is there a special reason why you can't just have both on the same server? [23:59] @geigerCounter correct [23:59] Okay.