/srv/irclogs.ubuntu.com/2018/04/10/#ubuntu-server.txt

Drag0nhunterhi all06:15
cpaelzerGood morning06:17
lordievaderGood morning06:18
=== led2 is now known as led1
Neo4Hi09:00
Neo4What is difference between trusted and untrusted certificate?09:01
Neo4Why validated certificate is secure and self signed not secure?09:01
Neo4who know scheme how PKI works?09:01
Neo4server has privet key, then it gives user public key and user encrypt data using this public key yes?09:02
Neo4guy who is sitting on the middle can get public key but he can't decrypt data encrypted by user, It can only do server who has privet key or other person with privet key09:03
Neo4I have many questions, Who know answers?09:04
mojtabaHello, do you know how can I encrypt my home directory and swap partition after installation of the ubuntu?09:04
Neo4mojtaba: no09:04
Neo4how does SSL/TLS work?09:05
mojtabaNeo4: Thanks for your participation.09:05
mojtabaAnyone else?09:05
Neo4we have server and user who speak with server,09:05
ducassemojtaba: there are scripts for that in the ecryptfs package09:06
Neo4server send public key for user, and how user can get encrypted server massage?09:06
mojtabaducasse: Even for swap partition?09:06
ducasseNeo4: this isn't an ubuntu question, look for an appropriate channel or ask in #freenode09:06
ducasse!alis | Neo409:06
ubottuNeo4: Alis is an IRC service to help you find channels. For help on using it, see "/msg Alis help list" or ask in #freenode. Example usage: "/msg Alis list http"09:06
ducassemojtaba: yes09:06
mojtabaducasse: thanks09:07
Neo4user send server encrypted messages by public key, but how can server encrypt messages for user understand them?09:07
Neo4ok09:07
Neo4ducasse: ok09:07
lordievaderNeo4: A self signed cert is untrusted because the chain of trust cannot be validated.09:31
Neo4lordievader: and I need full scheme PKI - public key infrustructure, Do you know how it works?09:33
lordievaderYou need a trusted CA (like LetsEncrypt or Verisign, etc) to sign your certificate. That way a browser can validate the chain of trust.09:34
Neo4lordievader: and I'm interesting in WHMCP web host manager control panel, We must use it? Can you give recomandation how to set up VPS on ubuntu and all needed applications09:35
lordievaderHow you set up your VPS is up to you, how you want it, what purpose it serves, etc.09:35
Neo4lordievader: yes, do you know Main in the middle attack?09:35
lordievaderYes? What about it?09:36
Neo4lordievader: I want to set up it using standard09:36
Neo4lordievader: and explain how valid certificate will protect you from tampered request?09:37
lordievaderYou lost me. Do you want to set up a web server?09:37
Neo4I want09:37
Neo4I did it but it difficult support and envision situation I find a client and offer him creat site on wordpress and what I must set up on VPS?09:38
Neo4it might have to be WHMCP at least?09:39
Neo4he won't use command line09:39
lordievaderI'm sorry I don't understand what you are saying.09:39
Neo4lordievader: can you give recommendation on this account?09:39
lordievaderWhat is your native language? Perhaps there is a native Ubuntu support channel for you. Might be easier.09:40
Neo4lordievader: no, I wholly understand you09:40
Neo4lordievader: what is your English level?09:40
Neo4I'm good in English enough for speak about, intermediate level it's very high09:41
lordievaderNeo4: I understand you want to setup a web server. What you want furthermore is unclear to me.09:42
Neo4lordievader: See let's I approach to you fro other side. What applications do you install on your VPS, For it should be some standard set of apps that so called 'must have always'09:42
Neo4lordievader: I want control panel09:43
Neo4Does exists some standard for VPS?09:43
lordievaderI don't run a control panel. But there are many available. Look for what you want and install that, I'd say.09:44
Neo4lordievader: it's like for hosting, What is for hosting necessary?09:44
lordievaderDepends on what you want to offer. If you want one-click installs of Wordpress, for example, the demands are quite different than if you only want to host static HTML pages.09:45
Neo4lordievader: compare usual shared hosting, and we need all of that put in ours, Do you see there always exists WHMCP? Always, User won't create it manualy or hire specialist for add subdoman, Obviously we need Control panel, I think about webmin09:45
lordievaderIn other words, read into the topic, setup a list of requirements, then install whatever is needed to meet those requirements.09:45
Neo4lordievader: I want to offers standard servise, creating sites on wordpress, Client pay me, I will buy domain, set up VPS, set up wp site and give users access to site, to control panel, I want something like this09:46
Neo4lordievader: plan?09:47
Neo4you are right09:47
lordievaderI believe cpanel does most (or all) of that.09:47
Neo4lordievader: Cpanel is paid, and client usually wants all for free09:47
Neo4they want pay for Cpanel, we can predict this variant as well, cPanel or ISPmanager only when we get rich client, for star will use some free like webmin, Do you agree?09:48
Neo4from free panels webmin is the best?09:49
lordievaderI have no idea. I rarely do anything  with web panels. Dislike them.09:49
Neo4it is said that webmail is the most popular for nodays09:49
Neo4lordievader: you are like me :)09:49
TJ-Has anyone prepared a bootable image for a PCEngines APU2 ?09:55
=== strigazi_ is now known as strigazi
_rubenTJ-: i installed mine using the netinstaller from an usb stick10:38
TJ-_ruben: I'm trying to pre-build a bootable image, don't want to use an installer on the device, was trying to figure out the layout10:45
=== strigazi is now known as strigaz_
=== strigaz_ is now known as strigazi_
=== strigazi_ is now known as strigazi
=== beatzz_ is now known as beatzz
=== uptime is now known as downtime
RattleBattle79is ubuntu 18.04 supposed to ship with that live thing?12:20
_rubenTJ-: layout of what?12:55
TJ-_ruben: sorted it, the USB boot device I was using had too old a kernel on it12:56
_rubenah :)12:56
TJ-I'm trying not to disturb pfsense so I can archive it, then replace with 18.04, and want to explore first12:56
TJ-_ruben: also was in an embedded ARM mindset forgetting this thing is x86 :)12:57
ddstreetsmoser hi, re: lp #1686437 it looks like your merge request has to be actually merged by someone from the server team... freyes has acked it, so should be ready to merge and then upload i think14:33
ubottuLaunchpad bug 1686437 in simplestreams (Ubuntu Xenial) "[SRU] glance sync: need keystone v3 auth support" [Medium,Confirmed] https://launchpad.net/bugs/168643714:33
ddstreetwe can upload to xenial if you don't have time, but i don't think we can merge into simplestreams:ubuntu/xenial-devel repo14:34
smoserddstreet: if you want to ACK that merge proposal i'm ok to upload. but really i just put the merge proposal to provide something to easily test.15:03
ddstreetsmoser ok cool, thanks, will do15:22
naccddstreet: smoser: it's not a 'real' merge15:23
naccddstreet: smoser: someone just needs to upload tag it in the repo (for now) and then dput can be done15:23
naccsmoser has such permissions15:23
ddstreetok yep...i'm not familiar with where simplestreams upstream is, so i assumed it was proposing upstream merge15:23
ddstreeti'll do review of diff in MR and ack it, and let smoser do the uploading15:24
naccddstreet: we have recently started toggling the 'default' Git repository in Launchpad for source packages we imported to our repository15:24
naccddstreet: so the URLs have changed15:24
ddstreetnacc is there documentation yet around how to use git-ubuntu to 'commit', i.e. upload?15:24
ddstreeti don't remember there being any docs on how to do that15:25
naccddstreet: not really, as it's going to change anyways15:25
naccddstreet: the eventual goal is to have `git ubunt build` write the hash of the commit being built into the source pacakge15:25
naccddstreet: then the importer can look for that special field in the source package publication downloaded and use that to search Launchpad (via an API)15:26
ddstreetok, so for now i should stay with the legacy sponsor/upload mechanism and wait before i get into using git-ubuntu for actual sponsoring/uploading...?15:26
naccddstreet: right, the issue is that there is a limited permission set that can create tags (current method for giving 'rich history')15:27
naccddstreet: we don't necessarily want to broaden that, because those users can also fubar the repositories, if they aren't careful15:27
naccddstreet: you can always still dput like normal, after just using the MPs for reviews15:28
naccddstreet: you just won't get 'rich' history in the imported commit15:28
smosereven without the process or the tag in place, the merge proposal provides a very good way to review and share code15:32
smoserthe tag and push on top of that is useful, but for many things (such as this) its only a bit of icing15:32
naccright, that's my point just now15:32
smoserin my opinion.15:32
naccyeah, especially for single changes15:33
smoserwhere the merge process and code sharing is the big thing.15:33
naccbecause the git diff you get after import is almost the same15:33
smosersigned tag and push with magic launchpad upload, that would seal it all up.15:33
naccsmoser: right, we're going to (avoid) the signed tag bit, by the fact that you sign the upload15:34
naccat least, that's my understanding, for now15:34
smosernacc: right. i was saying in future world where launchpad signed the upload15:40
smoserbased on me signing the tag15:40
smoseri thoguht that was a goal.... getting rid of the upload stage.15:41
smoserbut anyway.15:41
naccsmoser: yeah, we may or may not ever get to that15:41
naccsmoser: but yeah, that's future+2 :)15:41
smoserddstreet or freyes please ACK https://code.launchpad.net/~smoser/ubuntu/+source/simplestreams/+git/simplestreams/+merge/341215 also15:43
freyessmoser, ack, will review for artful as well15:45
ddstreetsmoser i'll let freyes ack it, and i asked wolsen (more familiar with cloudy stuff than me) to review/ack them too15:45
GumaI was wondering if any one can share some good documents how to strengthen openssh server? How to disable various old cyphers and best practices21:35
GumaI do not care about compatibility ... Just most secure and up to date21:35
dpb1Guma: I'd suggest: https://askubuntu.com/questions/2271/how-to-harden-an-ssh-server?answertab=votes#tab-top21:40
tomreynhttps://cipherli.st/ -> OpenSSH Server21:45
JanCrate limiting connection attempts to the server is probably useful too21:48
lucas_aiAnyone know how to make realtime video streaming that can be embedded in HTML or Iframes? Real time meaning less than 200ms delay. Similar to video conferencing found in facebook, skype, hangouts, etc.23:50

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!