=== poster is now known as Poster === JanC_ is now known as JanC [01:41] oooookay, so apparently etherpad-lite is NOT friends with mod_evasive or fail2ban:apache-auth [01:42] It just banned my entire staff from the prod server. [01:42] I had to fix that, so............. [01:42] ouch ;) [01:42] According to access logs, etherpad-lite has an average of, I dunno, around 12 pings a minute? [01:42] Way above evasive's threshold of 5 [01:43] So...I need some advice. [01:44] Can I (a) adjust fail2ban:apache-auth and mod_evasive to NOT freak out with etherpad-lite being used? [01:44] or (b) turn OFF those mods for only the etherpad subdomain (not ideal, of course) [01:44] or, (c) are they just practically incompatible and I need to kick etherpad to the curve if I want to keep a secure server in any capacity? [01:45] I mean, is 15 a REASONABLE threshold for mod_evasive? [01:46] CodeMouse92__: this page looks like you can also whitelist ips in mod_evasive https://www.digitalocean.com/community/tutorials/how-to-protect-against-dos-and-ddos-with-mod_evasive-for-apache-on-centos-7 [01:50] sarnold: Well, the trouble is, my staff is all remote. [01:50] Changing IPs. [01:51] sarnold: I think I'll raise the threshold on mod_evasive to 15 hits per page [01:51] per minute [01:53] And, actually, since nothing's authenticating on etherpad-lite, I think fail2ban:apache-auth may have been reacting to the error logs filled up by mod evasive [01:54] CodeMouse92__: what happens with etherpad when people type? does it send every keystroke in a new packet? or does it wait a full five seconds before sending the new text? [01:54] sarnold: I'm not honestly sure. [01:54] It seems to send in packets, based on how it updates [01:54] large packets, that is [01:55] I'd aim for something more like 120 requests per minute for etherpad things; most devs can touch-type quickly [01:55] sarnold: It's an open thing. Would you mind spam-typing on mine, just to see if you get locked out? [01:55] I've whitelisted local network (me) [01:56] sarnold: https://pad.mousepawmedia.net/p/test2 [02:01] sarnold: Must be working now. I've got someone trying it, no bans [02:02] good evening everyone. not really a server related issue but I dont know where else to ask [02:02] can a ecryptfs folder / volume be mounted without passphrase but with the only signature? [02:03] the situation is the following, I have home fully encrypted, while the rest of the rootfs is not encrypted. passphrase key file is store in home, while signature of this mount is stored in /root/. (not crypted) [02:04] the crypted folder in this case is found in /usr/local/ [02:04] thanks [02:10] Latrina: If you *don't* get an answer here, you can try ##linux [02:13] CodeMouse92__, thank you man [02:14] "signature"? [02:23] the passphrase signature? [02:41] i try to install "$ sudo apt search linux-generic-lts-trusty", but i couldn't find the kernel 3.13.0.117.127 listed on the menu.lst http://vpaste.net/kKRu9 [05:06] good morning [06:28] Good morning [09:31] nacc: I added usd build-source to the workflow on the wiki [09:31] nacc: working fine after the fix you added yesterday === fnordahl_ is now known as fnordahl [10:50] jamespage: any news about the refresh for nova 14.0.5 ? === tinwood is now known as tinwood_lunch === tinwood_lunch is now known as tinwood === freyes__ is now known as freyes === jgrimm is now known as jgrimm-away [14:53] I have a server with a bad mdadm drive that rebooted this morning. now its resyncing, but I assume the bad drive is syncing to the good drive, and copying any damaged data to the good drive. [14:53] bad, meaning it has reallocated sectors [15:06] I was reading about apr-proxy, yet not sure if there is a newer solution? [15:21] cpaelzer: great, thanks! [15:58] rbasak: re: LP: #1686859, my reading is that should be ok to sponsor? [15:58] Launchpad bug 1686859 in ruby-riddle (Ubuntu) "ruby-riddle tests start mysql server with unknown option --force" [Undecided,New] https://launchpad.net/bugs/1686859 [15:59] rbasak: as delta for us? since our default is still mysql 5.7? [16:00] nacc: I believe so, though I think Lars might be working on an improvement. Would you want to wait for that? If so I can confirm with him in the bug. [16:03] rbasak: that's fine, i'm just trying to push through the php7.0 removal and that's the last build-dep to get rid of :) [16:03] hey all, got a problem here. I ran some install script that installed MariaDB but it failed, now every time I install anything I get the MariaDB configuration script pop up asking me to set a root db password [16:04] if I do a apt-get purge mariadb-server it looks like I don't have it installed [16:05] but maria's package config keeps popping up when I install or remove anything on the box [16:06] jge: there are other related packages, like mariadb-common and mariadb-server-10.0 (or 10.1), etc. [16:07] jge: try "dpkg -l|grep mariadb" [16:07] Also "dpkg -l|grep mysql" [16:07] Note that some libraries are needed by the base system, so you can't remove everything. dpkg will stop you with an explanation if you try. [16:08] ok, yeah I see them now.. let me try to remove one by one [16:08] I'd do them all at once to avoid dependency issues between them. [16:08] ok let me try [16:08] rbasak: and anyone who cares, thanks to Debian and some googling I've got patches from upstream sources to patch the fail to builds i'm seeing for nginx 1.12.0, an upload is 'soon' if it builds alright in the PPA. [16:09] teward: thanks! [16:12] rbasak: that did it, thank you :) [16:33] yay it built, uploading shortly lol [16:33] (it also works from what I can tell in this container...) [16:44] rbasak: nginx 1.12.0-0ubuntu1 uploaded to artful proposed :) [16:56] teward: \o/ thank you! === poster is now known as Poster [20:04] odd mount issue. Have a tmpfs mounted directory that has run out of space. Need to remount with new space. But this is on a busy website and there is a good chance of a file/directory being created in the time between the umount command and the mount -a command. [20:05] The mount was NOT in /etc/fstab (I've slapped the fingers already), but is now, so the remount should be done via a mount -a. Would a "mount -a -o remount" do the trick? We really need to make sure the fstab entry is working properly as well... [20:06] Guys, how to enable libosinfo in Ocata (Ubuntu 16.04)? Under [libvirt] at the docs, there are no such "hardware_config=libosinfo" option... I have installed libosinfo-bin, but I'm still seeing: "Cannot load Libosinfo: (No module named Libosinfo)" at nova-compute.log. Any idea? [20:18] hmm strange, I'm trying to use SNI to host two apache SSL sites (same IP/Port) but when I split my VirtualHost in two files I get some ProtocolERROR and when I put them on a single file it works.. anyone know why this is? [20:47] has anyone here ever added spice drivers to existing windes kvm guest? [20:48] sorry ... has anyone here ever added spice drivers to existing windows 7 kvm guest? [20:54] whats the real question [20:54] and please don't cross-post === JanC_ is now known as JanC [23:36] sup [23:36] https://hastebin.com/owujucazoq.erl what do these mean in dmesg? [23:41] bindi: probably something like grub-install probing disks to find out what filesystem types need to be supported..