[02:26] Hello! [02:26] hi set_ [02:26] Where should I look to view tutorials on making my server run outside of my servers? [02:27] I have ubuntu server. [02:27] For instance, should I use Bind9? [02:27] what problem are you trying to solve? [02:27] Oh. [02:28] I can only view my web page online on my network for some reason. [02:28] I want to view it outside of the network. [02:28] alright .. there's a lot of moving parts to that one :) [02:28] Yea! [02:29] I am using apache2 for now. [02:29] I plan on using nginx later but for now, I would like to stick w/ apache2. [02:29] so .. is your network NATted? (probably yes) [02:29] No. [02:29] ohho [02:29] alright then :) [02:30] Yep! [02:30] what IP addresses is apache bound to? [02:30] an ip address w/ :443 only. [02:30] you need to make sure that it's bound on a routable address, not just a lan-local address or localhost [02:31] Oh. [02:31] you need to make sure any firewall in place on the network or the machine allow network connections from the world [02:31] Right. I got that idea. [02:32] The routable address needs to be from a service or can I use free addresses? [02:32] See. I own this website and I am thinking of getting dynamic dns services for a static ip. [02:33] whatever IP addresses you've been allocated by your ISP ought to work [02:34] I learned how to use netplan but the Ubuntu server is/or netplan is complaining. So, I went w/ another idea = apache2. [02:34] Okay. [02:34] I have 18.04 and netplan loves to complain. Are you having trouble w/ this issue or netplan in general? [02:36] netplan has worked well for me so far [02:36] sarnold: Oh. [02:36] Okay. [02:36] No issue. [02:37] but I've got a really simple network: the laptop is just using network manager, the big machine in the basement is just doing one IP behind a nat firewall.. [02:37] Oh. [02:37] See. I was going to host a website from my own server but the ideas are vast and I am only one person. It takes an age to get things done. [02:37] ... [02:38] This is why I thought a service might help out. [02:38] Anyway...I appreciate your help. [02:38] I guess I do not know the correct way to ask just yet. I will have to read more. [02:40] I read this book, "Mastering Ubuntu Server, (LaCroix 2018)," and the ideas are beating my brain senseless. [02:40] I have not been able to reproduce the steps this person took w/ Ubuntu Server. [02:40] sarnold: Have you read this book? [02:41] set_: sorry, no. but that's not too much of a surprise .. [02:41] set_: so, where are you currently stuck? [02:41] set_: like, is your apache bound to a routable IP? [02:41] Okay. [02:41] Yes. [02:42] The website comes up and it is live, I have https for my site, and the site is not live outside of the network. [02:42] I tried to view it elsewhere and it just keeps circling. [02:42] No reponse. [02:42] reponse = response [02:43] My apache2 server works. Ubuntu Server works. I am missing something. [02:44] set_: so, from a host off your network, what do you get when you run openssl s_client -connect ipadress:443 ? [02:44] try it against google if you want to see what success looks like, openssl s_client -connect www.google.com:443 [02:45] I would have to look tomorrow when I travel. [02:46] If I am not using openssl, does that command still work? [02:46] if you don't have an aws instance or similar to use for testing, you could also try the qualys checker, https://www.ssllabs.com/ssltest/analyze.html?viaform=on&d= [02:46] this is just using openssl's s_client interface to talk tls to a service and then do nothing else [02:47] Okay. [02:47] it's great for testing web servers, mail servers, irc servers etc [02:47] Aw. [02:47] it's a lot like a netcat that understands TLS [02:48] Yea. sarnold: You are talking out of my league still. I am a fresh-off-the-boat user for ubuntu server. [02:48] I used openssl but stopped b/c I did not self-signed certs. [02:49] okay, a quick intro to netcat then :) try "echo hi | nc localhost 22" to see your openssh login banner [02:50] Anyway sarnold: I have a lot to learn and tonight might not be the night. I need to learn more to discuss things w/ this crowd (obviously). [02:50] Thank you, anyway. Maybe another time, sorry. [02:51] alright, have fun :) [02:51] I appreciate the effort and help. [06:18] hello all [06:19] I'm having trouble with mod_ruid2 mod for apache on 14.04. The user group I set in vhost configs, apache is not writing new files with its ownership. Also, is this issue resolved in 16.x, 18.x? this is an amazon aws instance, running from the freely available images on amazon [10:13] Haris: 14.04 is almost end of life, upgrade now! [10:14] yes, I know. but still need a way to keep things running meanwhile [10:15] Haris: what do you use / need mod_ruid2 for? [10:15] for anything uploaded or any file/folder created by web scripts to be with ownership, permissions of the configured u/g [10:16] processes apache runs for that specific vhost run with perms/ownership of that u/g [10:16] which languages are those web scripts in? [10:16] php [10:16] why don't you use php-fpm? [10:17] don't want to use php plugin independent of web server [10:18] no significant benefit from it [10:18] have you ever used it? [10:18] yes [10:19] then i'm surprised you see no benefit [10:19] i never used mod_ruid2, though. but if it's anything like suexec... [10:19] it works ok on centos [10:19] doesn't work on ubuntu's implementation [10:19] not like suexec [10:20] its inline, included plugin in apache [10:20] doesn't run separate [10:22] sure, it's a module, this can probably improve handling. on the other hand it means it needs to have authority to change ownership of files to any users, i guess, which effectively means root. [10:22] but i'll need to read up more [10:23] its good because it works as an inline, included plugin. removes all headaches like suexec [10:28] i'm assumign you're doing shared hosting there, in which case per customer / user process control and isolation is important. does it do this well? [10:41] im encountering issues with the 18.04.2 live cd. when installing using lvm and a custom partition layout, the fstab mountpoints use UUIDs only, and during first boot, /usr cannot be mounted. same for root, more or less. lvm vgchange -a y fixes it. [10:44] xedniv: can you show the custom partition layout? [10:44] by "18.04.2 live cd" you mean the 18.04.2 live-server installer, right? [10:45] pabed: ask your issue here mate, volunteers might help think along with you [10:47] lotuspsychje: in this path "/etc/network/if-pre-up.d/ i see https://termbin.com/0f0g not iptables [10:49] I followe this https://paste.ubuntu.com/p/sjpxf9FdGD/ for persistent iptables , but there is no such file there [10:50] pabed: iptables-persistent, perhaps? [10:51] RoyK: how should I use this command? [10:51] apt install iptables-persistent [10:51] then read the manual [10:54] tomreyn, yes [10:57] RoyK: I installed but it is not found [10:57] tomreyn, https://pastebin.com/K9sqi7qg [10:57] the fstab [10:58] tomreyn, the ubuntu-vg mapper entries: https://pastebin.com/KyjXCM3i [10:59] pabed: it was just a suggestion - personally, I just use ufw [11:00] xedniv: thanks. i'll try to reproduce this. have you filed a bug report, yet? [11:01] not yet, i havent got my launchpad account in order in ages [11:01] :( [11:01] (but will do) [11:01] xedniv: would you post it here when you did, please? [11:02] tomreyn, in a couple hours, yes [11:02] are you trying to repro it now? [11:03] the dirty workaround I used in one guest was to add a initramfs script [11:03] that just calls lvm vgchange -a y [11:03] but thats tricky, it could definitely mess things up in other installations [11:03] by activating groups not needed at boot [11:16] tomreyn, https://bugs.launchpad.net/bugs/1573982 [11:16] Launchpad bug 1573982 in lvm2 (Ubuntu) "LVM boot problem - volumes not activated after upgrade to Xenial" [Undecided,Confirmed] [11:16] tomreyn, https://askubuntu.com/questions/551446/cant-find-lvm-root-dropped-back-to-initramfs [11:17] seems im not alone [11:26] xedniv: i'd say file a new bug against subiquity (server live-installer) and curtin. unless you did btrfs? [11:26] ext4 [11:26] this bug report is old, centers on unsupported versions [11:27] that's unless oyu know it's axctly your bug [11:28] i.e. this commit makes a difference for your use case. [11:28] not so old if it applies to current [11:29] hmm yes maybe you're right [11:29] i think this Tag fginther added is actually a reference to a cnonical internal ticket, suggesting there may be someone planning to work on this. [11:30] (after comment 25) [11:35] xedniv: the issue i take there is that the bug title describes an upgrade, whereas your issue is a fresh installation (different, and more serious). [11:37] rewriting the first title (and maybe the first post, too) may be an option, if it doesn't break context. [11:37] i won't try to reproduce it then, though. [11:38] yup [11:38] you might eb able to repro faster than i can file the bug though [11:38] swamped atm [11:39] i already had the issue with two separate installs fyi [11:40] if you're looking for a solution, use the alternative server installer, it may work better. [11:44] what are the main differences? [11:44] (lazy question, i know!) [11:49] the alternative server installer is the old "debian-installer" (also still in use for mini.iso). is both enables and forces you to configure a lot more, whereas the new server-live installer comes not only with a nicer GUI, but also asks a lot less questions, and installs as soon as it can. the live-server (subiquity) installer is also an image-based installation just like the (ubiquity) desktop installer, i.e. a tarball of the completed [11:49] installation is produced when building the installer and shipped with it, and just pushed to the disk during the installation, which is a lot faster than actually installing all those debian packages one by one. [11:50] xedniv: ^ [11:51] this said, the server installer still has several relevant bugs (from the perspective of this non cannoical affiliated volunteer) [12:05] What do ya'll know about the funky version of Ubuntu 16.04 every VPS provider seems to use [12:06] *VPS providers seem === Wryhder is now known as Lucas_Gray [13:46] Define "funky"? [13:46] Oh, he's gone. Oops. [17:08] whislock: they probably meant the preinstalled 'images' :P [17:57] Oh, yeah. A lot of them are terribad. [17:57] Linode: "Here, you need wifi support." What?! [19:07] seems like the main thing my VPS provider's new cloud infrastructure adds (in addition to adding their own APT mirrors & optionally injecting your SSH keys) is Qemu guest agent === gislaved40 is now known as gislaved