/srv/irclogs.ubuntu.com/2019/05/14/#ubuntu-server.txt

chl_has anyone switched from isc-dhcp to kea-dhcp recently? any difficulties?11:39
Odd_Blokechl_: I haven't, so I can't offer any advice; one thing to note is that isc-kea is not in the set of packages that the Ubuntu Security team maintain, so you won't receive security updates for it.11:43
chl_Should be able to work around that, but thanks for the heads up Odd_Bloke11:44
tomreynmore precisely: there's no guarantee that you'll receive timely security patches for it.11:44
chl_any recommendations for another dhcp server? pref. with some kind of db support11:45
Odd_BlokeYes, thanks tomreyn, that's more accurate.11:46
tomreynthanks11:47
supamanso, a bit of advice would be welcome here. I have several VM's running ubuntu-server. One of them is an NFS that others have to mount from. I am having a bit of a difficulty with getting permissions right for normal users to write to the NFS from other servers. Should I debug it further or just get LDAP up and running?12:10
supamanon the nfs server I have set the permissions so that group 33 (www-data) can write to the directories that are shared12:11
supamanon the nfs-client the user that is supposed to write is a member of the same group on the nfs-client machine (id=33, www-data)12:12
supamanstill if I do a 'touch filename' on the nfs-client machine in the nfs mounted directories I get permission denied12:13
supamanbut if I go up a directory into a local directory on the nfs-client machine that has ownership www-data:www-data and permissions 775 then I can write to that directory12:13
supamanhmmm, the writing works if I am using NFSv312:21
supamanargh! ... now it works fine12:23
supamanwhich is good, but still frustrating when it only needs time for things to work :-)12:23
supamanahh, it needed one more thing then just time, the corresponding user on nfs-server had to be added to www-data group for the write to work, thats what fixed it12:25
rbasakahasenack: bug 1789527 is on the 180 not touched list. Please could you take a look?15:59
ubottubug 1789527 in resource-agents (Ubuntu) "Galera agent doesn't work when grastate.dat contains safe_to_bootstrap" [High,In progress] https://launchpad.net/bugs/178952715:59
rbasakIt is server-next but maybe that isn't pertinent any more due to the time delay16:00
ahasenackright, server-next can be dropped16:08
ahasenackback then I thought it was an escalation, but that wasn't the case16:08
ahasenackrbasak: ^16:08
rbasakahasenack: thanks, I dropped the tag. Is Importance: High still accurate? Should we restore to Triaged and unassign you?16:30
ahasenackrbasak: yes please16:45
ahasenackI'd mark it medium16:46
ahasenackthere is a workaround16:46
UssatIs there an upgrade path from 17.X --> 18.x ?16:48
tewardUssat: 17.04 -> 17.10 -> 18.0416:48
UssatOK, thankyas16:48
tewardor 17.10 -> 18.04 direct16:48
UssatYa its at 17.10 now16:49
rbasakUssat: importantly, 17.04 to 17.10 is a major upgrade. Saying 17.X --> 18.x suggests to me that you have a dangerous misunderstanding of how Ubuntu release versions work.16:50
teward^ this though16:50
UssatNo I understand, I just was not on the box to get the exact release when I typed that16:51
Ussatand I did not remember16:51
rbasakOK16:51
UssatI have a few hundread and dont remember exactly detail about each one16:51
AvidWolf43hey whats up guys17:03
AvidWolf43how can I force my end users to only have access to install things from ubuntu repo17:03
tewardprobably shouldn't give end-users that kind of access, sounds like a security risk.17:17
UssatHow about not letting users install things17:19
AvidWolf43ok so i have a tall order and im just trying to figure out how to make it work17:20
AvidWolf43as a POC we are looking at giving developers ubuntu workstations (laptops) that are managed with landscape17:20
tewardAvidWolf43: so setup the systems, and drop the 'users' to non-sudo users?17:21
AvidWolf43right, but they are developers who will need sudo acces for some things17:21
AvidWolf43just not all17:21
AvidWolf43the directive was "use your best judgement"17:21
AvidWolf43I'm just not sure what I want to allow / disallow them sudo for17:22
rbasakWhat type of scenario are you looking to prevent by disallowing certain sudo access?17:22
AvidWolf43data exfiltration mainly17:23
rbasakWhat - from elsewhere on the network?17:23
AvidWolf43installing unapproved applications that havent passed legal review17:23
rbasakAre you going to prevent developers from creating VMs and/or containers?17:23
AvidWolf43no, we are trying to be as least restrictive as possible17:23
rbasakThen a developer could just create a VM and install whatever software they like into that.17:24
rbasakSo what is achieved by blocking the developer from installing software on the host machine?17:24
AvidWolf43but at least we can log all the things? and hopefully have appropriate flags setup to alert in real time17:24
rbasakYou won't get a log of what happened in a VM.17:24
rbasakYou'd effectively be pushing developers from doing things in places that you _can_ log (eg. host machine package list via Landscape) to doing things in places that you can't see (inside a VM).17:25
AvidWolf43we can't see what is in the vm, but we can see if there are vm's installed. So we can have a policy that you can have vm's but you have to pipe logs to us for visibility? would that be acceptable?17:26
AvidWolf43I'm just brainstorming17:26
masonAre packages for https://blog.ubuntu.com/2019/05/14/ubuntu-updates-to-mitigate-new-microarchitectural-data-sampling-mds-vulnerabilities not out the door just yet?17:30
masonNot seeing them here.17:31
sdezielmason: https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/MDS shows that packages were built already17:33
rbasakparide, cpaelzer, ahasenack: FYI https://github.com/powersj/ubuntu-server-triage/pull/2017:34
masonsdeziel: Ah, maybe they're making their way out.17:34
sdezielmason: looks that way17:34
masonty for the link, though - I'll bookmark it17:35
UssatI have a question regarding landscape, can I centerally managet encryption keys, something like the way an orginization can centerally manage TPM keys on windows ?17:38
Ussatmanage17:38
UssatAvidWolf43, its a trust thing more than a tech issue17:55
UssatAll the polocies in the world are pointless if you dont trust your devs etc17:56

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!