/srv/irclogs.ubuntu.com/2019/11/12/#ubuntu-server.txt

=== Wryhder is now known as Lucas_Gray
=== cpaelzer_ is now known as cpaelzer
lordievaderGood morning07:19
V7Mornin o/07:53
mgedminanyone have problems with docker in 19.10?  I've a container with four uwsgi processes all blocked trying to write to stderr09:27
mgedminthe containerd-shim that's supposed to be reading from the pipe isn't doing anything09:28
mgedmin(well it has a lot of threads that do various things, but they're not reading from the right pipes)09:28
im0ndeCan someone help me install ubuntu server on a nvme drive? I get an error in the installation with the drive.  This is the full error https://imgur.com/a/ijNDCDM11:26
weedmicim0nde: I have not done what you want to do, but... it appears that the machine does not see the drive.  did you setup the cmos to boot the nvme drive first?  this is not possible on many older machines.11:28
im0ndeweedmic: The thing is, I can partition it in the installer. So it seems to be there?11:30
im0ndeAlso the machine is very new and came with a linux distro prenstalled11:30
im0ndeI deleted it though, because I wanted a server OS11:30
weedmicyes, it is there - but if it is not a bootable drive, then you need to setup the install differently and put the bootloader on a disc that can be read, then access the nvme one.  but... u sh'd check the cmos, it might be an option to boot to that drive11:31
weedmicjust one click/boot away...11:32
badv991Im0nde: I can't really see the text in the pic you posted, but you might want to try the "alternative installer"11:32
im0ndeweedmic: Sorry, I don't fully understand what to select in the bios. I have pressed f12 to boot from the drive, isn't that correct?11:34
im0ndealso there was a linux distro installed (which worked) in exactly that hardware configuratioooooooooooooooooo11:34
im0nde*configuration11:34
im0ndebadv991: I have only the option of "safe graphics"11:35
mgedminweedmic: that looks like a bug in the installer to me11:35
badv991Yeah then definitely try alternative installer since it's basically Debian11:35
im0ndemgedmin: Yeah to me too11:35
mgedminweedmic: report it11:35
mgedminand try an alternative installer11:35
badv991Yes it's a different ISO you need to download that uses Debian curses installer11:35
im0ndemgedmin: badv991 Where do I select the alternate installer?11:35
im0ndeah ok11:36
weedmici think u need to go into the cmos, setup the boot order so that the nvme drive is 1st likely, this might be a good way to tell, if your "boot order" setup does not contain the nvme drive/slot - then it is not an option.11:36
im0ndesorry, thougth that was an option11:36
mgedminI think http://cdimages.ubuntu.com/releases/18.04/release/ is the debian-installer based image11:37
mgedminthe subiquity one is called *-live-server-*.iso11:37
mgedmindebian-installer is called *-server-*.iso11:37
mgedminthey're split between cdimages.ubuntu.com and releases.ubuntu.com using some moon logic I don't follow11:37
mgedmin(an neither links to the other one afaics)11:38
im0nde:D11:38
im0ndeok, I'll download an alternate server install then, brb11:38
tomreynim0nde: could you please report a bug on this, it doesn't seem like there is a bug report for it, yet (from what i can find)12:26
tomreyn!bug12:27
ubottuIf you find a bug in Ubuntu or any of its official !flavors, please report it using the command « ubuntu-bug <package> » - See https://help.ubuntu.com/community/ReportingBugs for other ways to report bugs.12:27
tomreynyou can do so from a different tty:12:27
im0ndetomreyn: I will. Just updated the bios to see if that makes a difference12:27
tomreynok12:27
im0ndetomreyn: yes?12:28
tomreyn!tty12:28
ubottuTo get to the TTY terminals 3-6, use the keystroke Ctrl + Alt + F3-F6 respectively. Ctrl-Alt-F2 or Ctrl-Alt-F1 will get you back to your graphical login (Ctrl-Alt-F7 on 16.04). To change TTY resolution, see https://help.ubuntu.com/community/ChangeTTYResolution12:28
tomreyni assume you know so much ;)12:28
tomreynand this is more targetted at desktops12:28
im0ndetomreyn: yes, i know. Thing is, i can't copy paste12:28
tomreynyou can pipe output into   | nc termbin.com 999912:29
im0ndeI'll try my best. At least I have a photo and can provide the hardware12:29
im0ndeOh nice12:29
im0ndedidn't know that one12:29
im0ndeI'm trying out the alternate installer too12:29
tomreynor you can just run    DISPLAY=:1 ubuntu-bug subiquity12:29
tomreynthis should print a URL which you can access form a desktop computer to continue your bug report (aftzer it collected and posted the relevant logs)12:30
im0ndetomreyn: mgedmin the alternate installer worked perfectly!12:41
mgedminim0nde: have you filed a subiquity bug?12:41
im0ndeThanks for the help, I would have trying for ages12:41
im0ndemgedmin: I'm doing that right now12:41
im0ndemgedmin: here, right? https://bugs.launchpad.net/subiquity12:42
mgedminhm, ubuntu desktop doesn't have problems installing into nvme disks -- I've just checked and my laptop has the same kind of /dev/disk/by-id/nvme-eui.XXXXXX structure12:43
=== jelly is now known as xj9
=== xj9 is now known as jelly
weedmichow does one do "systemctl snapshot test" in ubuntu?  says "snapshot is unknown command"?13:29
weedmicactual error was - Unknown operation snapshot.13:31
lordievader(if your display hangs out there, /me might miss backlog but typically the first display hangs out at :0 )13:38
RoyKweedmic: I guess you'll need a rather new version of systemd to support that14:10
weedmicit was depricated between 2015 and now - unsure how to tell I seldom use github and was not about to make an account just to say, well I was that one bloke - there was a comment no one uses it :D14:12
RoyKah14:15
weedmicno problems, if the files are similar each go (around), I'll have python do it for me and create some colour highlighted report with changes, then manually change them.14:15
weedmicbut, it was exactly the command I wanted (already done)14:16
weedmicI mean it had a bow on it and everything14:16
=== JanC is now known as Guest71930
albechanyone have experience with fail2ban and RBLs? I am getting thousands of brute force attempts on my mail server and fail2ban is doing a great job banning offenders after 5 tries, but eventually someone will get in and I was wondering about tightening the security with a RBL. Suggestions/comments?20:47
lordcirth_albech, If you are worried about your password being brute-forced, ban passwords and only allow keys20:51
lordcirth_Oh wait, mail, not ssh. nvrm20:51
tomreynfail2ban usually does banning via iptables, which is not the right place to apply RBLs, those can be used by your mail server, though20:54
sdezielalbech: RBL should be used on SMTP port (TCP/25) only where no auth should be permitted as that's normally on smtps/submission/submissions (TCP/465 or TCP/587)20:54
tomreynwhat you can use with iptables / at the network layer are drop lists / ipsets20:55
sdezielalbech: that said, to protect your SMTP port, I would recommend postscreen (builtin with postfix) as it has a good DNSBL/DNSWL integration among other nice features to weed off spammers20:56
albechthanks for the input guys.. highly appreciated.. ill have a look at postscreen as its already postfix im running20:57
albechthat doesnt strengthen security on dovecot however. switching to keys isnt really an option unfortunately.20:59
sdezielalbech: SASL should NOT be offered on TCP/25. Removing this should already mitigate the problem to some extent21:01
albechsdeziel: it already is disabled21:05
sdezielalbech: I also noticed that requiring recent TLS versions (1.2+) on the TCP/465 and TCP/587 services prevent some dummy bots to be able to pass the StartTLS while being compatible with every legitimate users' MSA21:05
sdezielalbech: you can also try those http://www.postfix.org/TUNING_README.html#conn_limit21:07
albechsdeziel: cheers21:07
tomreynif you want something to firewall against (and thus keep traffic out of your mail server and tcp sessions already): https://www.spamhaus.org/drop/21:09
sdezielalbech: I don't know if it applies in your case but here I'm adding IP ACLs (allow_nets) to some accounts in dovecot's password file21:09
albechsdeziel: that is one option i have thought about. i will look at postscreen and some limit thresholds first and see how it works out21:13
albechthanks again21:13
sdezielalbech: postscreen is designed to protect TCP/25 only though21:13

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!