/srv/irclogs.ubuntu.com/2017/03/07/#ubuntu-server.txt

geigerCounterWhat does this mean?00:00
sarnoldgeigerCounter: yay :D00:00
geigerCounterYes, yay. Now how do I get roundcube to do that?00:00
naccgeigerCounter: it presumably means your exim4 configuration is fine00:01
nacchttps://github.com/roundcube/roundcubemail/wiki/Configuration ?00:01
nacctls:// for the smtp server00:01
sarnoldsmtp_user and smtp_pass perhaps?00:01
geigerCounterHmm00:02
geigerCounterIt's supposed to use the same user and pass that was used for logging into imap00:02
geigerCounterAnd yeah, lemme go take a looksee at the roundcube wiki.00:03
naccgeigerCounter: as in, you want to?00:03
geigerCounterThanks you guys.00:03
naccgeigerCounter: %u00:03
geigerCounternacc: I don't know if this affects anything but to authenticate successfully, I have to use <user>@<hostname>,<password>00:04
geigerCounterFor both imap and smtp00:04
geigerCounterIs that normal? That wouldn't confuse smtp applications, would it?00:04
naccgeigerCounter: that i don't know :/00:04
patdk-lapheh?00:05
patdk-lapit's it just username and password00:06
patdk-lapwhy would something matter if a username contained an @ in it or not00:06
geigerCounterpatdk-lap: Because that's the way my exim is configured, it's gotta match the hostname as part of the username.00:06
patdk-lap"That wouldn't confuse smtp applications", why would "smtp applications" care in the first place?00:07
geigerCounterI don't know.00:07
geigerCounterI wouldn't think it would.00:07
=== Tzunamii_ is now known as Tzunamii
geigerCounterHmm. Well roundcube still says authentication failed.00:18
geigerCounterHmm00:18
nacccpaelzer: would you be able to follow-up on LP: #1644530 ?00:20
ubottuLaunchpad bug 1644530 in keepalived (Ubuntu Xenial) "keepalived fails to restart cleanly due to the wrong systemd settings" [Medium,Confirmed] https://launchpad.net/bugs/164453000:20
geigerCounternacc: Suggestions on what else to try? I'm reading the wiki still00:37
sarnoldwhat do the postfix logs say?00:37
sarnoldmaybe they're more specific on the failure than the roundcube logs00:37
geigerCountersarnold: Not using postfix00:37
sarnoldsorry, force of habit, everyone else is.. hehe00:37
sarnoldso, what's the exim4 logs say? :)00:38
nacci assume you can get exim4 to be more verbose00:38
nacceither run it in the foreground, ro configure it to be noisy00:38
geigerCounterMm00:38
nacc*or00:39
geigerCounterWait wait.00:40
geigerCounterI just got roundcube to be noisier.00:40
geigerCounterI'm looking at the auth it's sending. It's not right.00:40
geigerCounterOH.00:41
geigerCounterI see now.00:41
geigerCounter...00:41
geigerCounterRoundcube isn't including the nulls.00:41
geigerCounterHow do I get it to do that?00:42
naccgeigerCounter: i believe they have an IRC channel :-P00:42
geigerCounterHeh yeah.00:42
geigerCounterOn freenode?00:42
geigerCounterThat's weird. Based on my debugging, Roundcube is only sending my username and not my password01:06
naccgeigerCounter: not sure, but i had to ask for some help when i was fixing it for php701:06
geigerCounterNo it's fine. I just got it.01:07
geigerCounterc:01:07
naccgeigerCounter: cool01:08
geigerCounterYep.01:08
geigerCounterI realized that it wasn't appending the password key to the auth string, so I just set the password to an empty string and added the password substitution token to the user name field, since that was actually being sent.01:09
geigerCounter"\0%u\0%p"01:09
geigerCounterAnd lo, it worked. :D01:09
geigerCounterIt feels kinda weird to do it this way, but it's no less secure I suppose.01:10
geigerCounterAnd it actually works now.01:10
* patdk-lap wonders why it's using login though at all01:12
* geigerCounter shrugs01:21
drabanybody knows if it's possible to force the veth hostname on the host for unprivileged containers?04:24
drabwtih a lot of containers and monitoring on the host it'd be pretty useful to be able to name those something sensible04:24
drablike veth_$hostname_#04:25
cpaelzernacc: I subscribed and will follow up later today07:57
lordievaderGood morning.08:10
zioprotozul: just wanted to report that I tested again nova upgrade from Mitaka to Newton, and with the new packages everything works just fine. We are just waiting for release of the packages in SRU at this point. Thank you08:39
=== mwsb is now known as chu
jamespagebug 166703310:57
ubottubug 1667033 in qemu (Ubuntu) "nova instance console log empty" [High,Fix released] https://launchpad.net/bugs/166703310:57
cpaelzerjamespage: oO not working for you ?10:57
jamespagecpaelzer: just needed the link10:58
jamespage:-)10:58
cpaelzerpuh10:58
ztaneis there a specific day for 1204 LTS support dropping?11:54
hateballztane: https://www.ubuntu.com/info/release-end-of-life11:57
hateballoh specific *day*11:58
ztaneyes12:01
patdk-wkearly april13:24
fricklerzul: coreycb: I'm seeing https://bugs.launchpad.net/horizon/+bug/1643964 reappear with 3:10.0.2-0ubuntu1 proposed for yakkety/newton: http://paste.ubuntu.com/24130835/ . The bug only mentions Ocata, can you check this, please?13:33
ubottuLaunchpad bug 1643964 in horizon (Ubuntu) "compressing static assets fails with xstatic-bootswatch 3.3.7.0" [Undecided,Fix released]13:33
zulfrickler: yep will have a look today13:39
coreycbzul, frickler: 10.0.2 isn't in proposed yet13:40
fricklercoreycb: zul: it is queued for yakkety13:41
coreycbzul, frickler: if you refreshed static assets for that version, i'd recommend trying without the static assets refreshed13:41
zulcoreycb: yeah frickler is using a ppa version that i uploaded  for him to a ppa13:41
coreycbfrickler, thanks for testing that :)13:41
fricklerseems like 3:10.0.0-0ubuntu1~cloud0 is fine, while 3:10.0.1-0ubuntu1~cloud0 shows the same issue, but I need to retry the latter on a fresh machine13:42
frickleror it may be some python dependency that got updated in the last three weeks13:43
coreycbzul, s/static assets / xstatic deps/13:44
coreycbfrickler, ok if you see this with 10.0.1 too, let us know please13:44
zioprotohello. I am trying a Trusty to Xenial upgrade for my nova compute nodes (Mitaka). My neutron agent are broken with this stacktrace: http://paste.openstack.org/show/601784/15:16
zioprotodoes this 'sudo: policy plugin failed session initialization' ring a bell to anyone ?15:16
wimpogHello, I've got PCI compliance scan failure for CVE-2016-2183. Here is the version of my system: http://pastebin.com/DkReaJe1 What can I do to resolve this reported failure?15:27
=== joedborg_ is now known as joedborg
rbasakwimpog: see https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2183.html15:38
rbasakwimpog: follow the usn links for instructions.15:39
nacccpaelzer: thanks!15:40
wimpogrbasak: thank you. I have looked at it. Does that mean it is fixed? I have OpenSSL 1.0.1f 6 Jan 201415:40
rbasakwimpog: fixed in which package?15:42
wimpogrbasak: openssl15:42
rbasakwimpog: the upstream version is not relevant for security fixes in distribution packages. You need to report the package version.15:42
wimpogrbasak: the openssl version?15:43
wimpogrbasak: openssl version: OpenSSL 1.0.1f 6 Jan 201415:43
rbasakThe version string of the openssl package.15:43
rbasakYou are reporting the upstream version, not the package version.15:43
wimpogrbasak: how do I get it?15:44
wimpogdpkg-query -l | grep openssl15:44
wimpogii  libgnutls-openssl27:amd64            2.12.23-12ubuntu2.6                  amd64        GNU TLS library - OpenSSL wrapper15:44
wimpogii  openssl                              1.0.1f-1ubuntu2.22                   amd64        Secure Sockets Layer toolkit - cryptographic utility15:44
rbasakRight, so 1.0.1f-1ubuntu2.2215:44
rbasakAccording to the page I linked, CVE-2016-2183 was fixed in 1.0.1f-1ubuntu2.20.15:45
rbasakIf you have 1.0.1f-1ubuntu2.22 installed then you are not affected by CVE-2016-2183 according to the data.15:45
rbasakFor the openssl package.15:45
patdk-wkassuming the services that use it, where restarted15:46
wimpogrbasak: thank you! That's what I thought, but still don't why why this PCI scan is failing15:46
patdk-wkbecause, PCI scanners are idiots15:46
patdk-wkthey only bother to check what version they detect, they do not CHECK to see if you are actually vaunerable15:47
patdk-wkto them, you are vaunerable until proven not to be15:47
wimpogrbasak, patdk-wk: thank you!15:47
wimpogrbasak: patdk-wk I'll probably submit a dispute with them15:47
patdk-wkyes, you will always have to15:48
patdk-wkand include the version installed and a link to the USN above15:48
wimpogpatdk-wk: the link that rbasak has posted? https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2183.html ?15:48
patdk-wkyes15:49
jbichahi, I'm pinging about bug 166719515:49
ubottubug 1667195 in mdbtools (Ubuntu) "Drop mdbtools-gmdb from main" [Undecided,New] https://launchpad.net/bugs/166719515:49
rbasakjbicha: looks reasonable. jgrimm: ^?15:51
rbasakI'm not sure I follow why we want it in supported-misc-servers at all.15:51
rbasakIs it a leaf package that server users even expect?15:51
rbasakjbicha: so I have no objection, but OOI, what creates your interest in this?15:51
rbasakemacs25?15:52
jbicharbasak: my interest is I don't think gconf and old obsolete gnome2 libraries should be in main any more15:53
rbasakFair enough :)15:53
rbasakkirkland: ^ opinion on unseeding mdbtools from supported-misc-servers please?15:54
rbasakWe're seeding mdbtools. I'm not sure why.15:54
jgrimmrbasak, why was it in main to begin with?15:55
jgrimmi just did a quick look for MIR bug, but didn't see anything15:55
rbasakLooking15:55
jgrimmbut if it was just pulled in as a dependency seems that no longer exists, +115:56
rbasakIt was seeded directly15:56
rbasakI'm failing at bzr here.15:59
rbasakThe seeds were restructured in r1171 in 2008; the seeding of mdbtools predates this.15:59
rbasakHere we are: http://bazaar.launchpad.net/~ubuntu-core-dev/ubuntu-seeds/platform.zesty/revision/40016:01
rbasakDate: 2005-09-15 07:29:51 UTC16:01
jgrimmrharper, smoser, caribou, rbasak: server irc mtg16:02
rbasak"add mdbtools, mdbtools-gmdb. JET format supported by OOo2."16:02
rbasakjgrimm: it was added to "supported", then moved to "supported-misc-servers" later. Since it mentions OOo2, I think maybe the intention is a desktop thing.16:02
jgrimmrbasak, indeed, thinking the same16:02
rbasakjgrimm, jbicha: we should move it to the desktop seed, or drop if they don't want it.16:03
fricklerzul: coreycb: o.k., so the 10.0.1 package by itself is fine. upgrading to 10.0.2 or installing 10.0.2 directly fails. after upgrading also downgrading again is broken: http://paste.ubuntu.com/24131501/ so I guess the xstatic refresh within the ppa build broke things16:03
jbichasome sort of support for using LO Base to work with Microsoft Access files or something but I don't know anyone that does that16:03
rbasakYeah16:03
jbichamdbtools isn't installed by desktop either16:03
rbasakI think it doesn't make sense for Ubuntu to be seeding it now, but that's a question for ~ubuntu-desktop.16:03
rbasakmdbtools-gmdb is also seeded in supported-sysadmin-desktop16:04
jgrimmagreed, agruably it is a servery thing, but doesn't seem to really need to be seeded for its original reason, but yes, please check16:04
jbicharbasak: could you or someone comment from server's side on the bug then?16:05
rbasakSure I'll comment.16:05
jbichaand I'll try to get desktop to comment then we just need to someone to adjust the seeds based on that16:05
jgrimmrbasak, jbicha: thank you16:07
rbasakjbicha: if ~ubuntu-desktop agree I'd be happy to unseed it.16:10
coreycbfrickler, ok that's good that 10.0.1 works.  I think zul is uploading a new 10.0.2 without refreshing xstatic files.16:14
naccrbasak: are you seeing a git-commit-tree failure with tftp-hpa?16:38
rbasaknacc: yes16:41
rbasak03/07/2017 16:24:31 - DEBUG:stderr: fatal: invalid date format: None16:41
naccbah16:42
rbasaknacc: is this due to the refactoring for the devel pointers?16:43
naccrbasak: possibly, let me debug locally16:44
naccrbasak: could you undo that change locally and --no-push --no-clean to see?16:45
rbasakYeah16:45
nacci'm adding some debugging locally to see if i can figure it out16:45
rbasaknacc: yeah it works with 1aa0f4616:47
naccrbasak: ok, i'll work on a fix, if you want to just import with that version for now16:47
rbasaknacc: thanks. Happy for me to push that to lpusdi?16:47
rbasakOr I can keep it local if you prefer.16:47
naccrbasak: yeah that's fine16:48
rbasakack16:48
rbasakPushed.17:01
naccrbasak: thanks -- i think i have the fix as well17:04
=== drab_ is now known as drab
hheeafter update from 14 to 16, apt-get update, got " Ignoring file '50unattended-upgrades.ucf-dist' in directory '/etc/apt/apt.conf.d/' as it has an invalid filename extension"17:33
hheewhat is going wrong?17:33
patdk-wknothing17:33
hheehow to fix it?17:33
patdk-wkyou don't17:33
patdk-wkwhen you upgraded, it asked if you wanted to update that file, and you said no17:34
patdk-wkso it created that file with the new changes in it17:34
patdk-wkyou either merge those changes into your existing file, don't merge those changes17:34
patdk-wkthen when you happy, delete that file17:34
hheepatdk-wk, got it. thx!17:35
zulcoreycb: cloud-archive should be good again18:07
coreycbzul, ack18:08
quadHelixUbuntu 14.04LTS Server.  I am trying to disable the arcfour cipher in ssh for PCI Compliance.  I have googled and gone through many articles, both ssh_config and sshd_config do not reference "arcfour".  Could anybody point me in the right direction?  Do I have to compile from source or something?18:11
patdk-wkhttps://wiki.mozilla.org/Security/Guidelines/OpenSSH18:16
quadHelixthank you sir, I will read this article forth-with ;)18:20
quadHelixActually, I had been through that article once.  When I run ssh -Q cipher <ip addr> it was still showing me arcfour18:21
patdk-wkyes18:22
patdk-wkand why would you expect it not to?18:23
quadHelixignorance perhaps?  I am new to this realm.  I didnt even know that arcfour is RC4 ;)18:23
patdk-wk"The various algorithms supported by a particular OpenSSH version can be listed with the following commands: "18:23
patdk-wksupported!=enabled18:23
quadHelixunderstood.  thank you.18:24
sarnoldquadHelix: it's a bit of a joke. RSA didn't patent RC4; when other people started using it, they tried to claim it as a 'trade secret' in court to stifle people from using it; so some people took to calling it 'arcfour' as in, "apparently rc4", so they could say it's apparently rc4 but not necessarily the thing rsa was using.18:36
drablol, didn't know that one, thanks for sharing :)18:37
quadHelixty sarnold, I like to know the back story.19:06
jancoowHi. My ubuntu server installation hangs on a purple screen everytime20:02
jancoowIt says detection hardware.. or something20:03
jancoowand then something with copying cdrom20:03
jancoowand then only purple screen with white bar underneath20:03
patdk-wkis it a dell?20:10
patdk-wkoh he left20:10
DoowWhat is it that's supposed to trigger starting apache on boot? Since yesterday it20:39
Doow's not starting anymore for me, no errors in logs or anything, and starting the service manually works fine20:39
sarnoldwhat release?20:39
Doow16.1020:40
Doowsudo systemctl enable apache2.service just says that it's not configured to be enabled/disabled but started some other way20:40
DoowI added a service of my own making yesterday and I wonder if that might have blocked it somehow?20:41
DoowI looked in apaches own logs, syslog and journalctl20:41
sarnoldsystemd requires a service to be wanted by multiuser.boot or something like that20:44
DoowI'm still trying to figure out if apache is even trying to start at boot, I can't find anything in the logs, but it's enabled in /etc/rc2-5.d22:22
Doowany ideas?22:22
DoowI haven't done anything to try and turn it off, but it's just not starting anymore22:23
DoowI'm suspecting a collision with mysql (i.e. maybe mysql hasn't started before apache) but that's just a guess22:24
Doowthis is what systemctl tells me http://pasteall.org/284600/text22:24
quadHelixDoow have you tried netstat -tnlp and looked for your listening port?22:55

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!