/srv/irclogs.ubuntu.com/2021/04/27/#ubuntu-discuss.txt

lotuspsychje"good morning"01:55
ducassegood morning06:59
=== popey5 is now known as popey
=== ledeni__ is now known as ledeni
=== sarnold_ is now known as sarnold
[VMGuy23]Windows Sonic alternatve for ubuntu?19:20
sarnoldwhat's windows sonic?19:21
[VMGuy23]similar to dolby atmos for headphones19:24
[VMGuy23]Surrounds sound I think19:24
[VMGuy23]*surront19:24
Maik[VMGuy23]: ask that exact question on Google and it'll show you altenatives if any19:24
[VMGuy23]*surround19:24
[VMGuy23]Maik: sure thing19:24
daftykinsthat'll be some audio enhancement junk, by the looks - highly doubt there'll be anything of relevance19:24
sarnoldthere's a billion pulseaudio plugins, it feels pretty plausible there'd be something19:25
sarnoldwhether or not it would actually improve your experience is another question :)19:25
[VMGuy23]spatial sound19:26
=== TJ_Remix is now known as TJ-
cranberryHi, on SUSE there's a tool called "seccheck", which, along with regular basic security, audits, allows to set autologout timers for ssh and console sessions. Is there such a tool for Ubuntu, or does one need to script it themselves?22:02
sarnoldI haven't seen one myself, but I seem to remember seccheck fondly22:03
cranberryMainly looking for the autologout timers on shell sessions in order for users not to idle into infinity in forgotten terminals. :-)22:03
sarnoldthey also had some nice mtree or something similar integration to check file and directory permissions..22:03
cranberryOh yes it does that. If I had that in Ubuntu that'd be awesome too, but the autologout is more impotant22:03
cranberryHeh, just when speaking of it, a SUSE system just sent me an email via seccheck, https://pasta.lysergic.dev/?fc6eda3f7abc48e1#BsU6r3ZYArYYoEYjVCH9rDEtwonwaWhbaE5bxbiMNu8122:04
sarnoldthere's an autolog package in ubuntu, but it's probably 20-ish years since it was maintained in any way22:04
cranberryHmm, do you think it'd still work?22:05
cranberryI guess not that much changed to tty/ssh session handling?22:05
cranberryThis is what I find in the repo: autolog/focal 0.40+debian-3 amd64 - looks promising22:05
sarnoldit reads wtmp, and depending upon how it was written, it might work just fine no changes needed, or it might be helplessly broken.. I don't recall when 32 bit ids were introduced..22:05
cranberryGuess I'll try it out! Thank you for the tip! Have not found that in my online search22:06
sarnoldcranberry: that's a pretty cool seccheck output :)22:06
cranberryI know right :-) it's relatively simple in what it does but very useful22:07
cranberryI struggle finding documentation about autolog.. the config looks pretty simple and I commented out some of the example groups, but I cannot figure out how to have a line apply to ALL users? I assume I could set a line= for pts/* ? :^)22:11
cranberryhttps://pasta.lysergic.dev/?ec9614323b8b7ddc#6a64CQWGgGh8xXbtqfWFANMtyf273hnZVYY6GD2kPq8m22:11
sarnoldname=* group=* tty=* might do the trick; I don't know if a name=root idle=-1 line would still protect root in that case or not; I'd hope a specific match takes precedence over a RE-match22:14
sarnolderr22:14
sarnoldRE, right, name=.* group=.* tty=.* instead..22:14
sarnold*sigh* line= not tty= ... 'line', wow :)22:14
cranberryNice, thank you, I'll try that out! I commented out the root exempt as I don't need it.. a single global rule would be fine with me22:15
cranberryHeh, thank you! Will report back.. in a few minutes heh22:15
* sarnold waits for the 'connection closed by peer' quit22:17
cranberryHaha.. I'd be lying if I would say I did not disconnect while troubleshooting over Freenode before22:17
cranberryhm22:32
cranberryi got lost in chats and this other shell is still there22:32
sarnoldhrm :(22:32
cranberrydoes your example only apply to tty sessions?22:33
cranberrybecause mine are pts22:33
cranberryI put this:22:33
cranberryname=.* group=.* line=.* idle=3 grace=300 mail22:33
leftyfbcranberry: https://www.tecmint.com/increase-ssh-connection-timeout/22:34
cranberryleftyfb: Thanks, unfortunately I need it to apply to remote sessions which do not utilize OpenSSH22:35
cranberryseccheck on use works universally, console session, openssh, teleport ssh, it sort of detects "everything"22:36
sarnoldleftyfb: I think that's a different thing, I think that's for spotting connections that have been torn down by NAT firewalls22:36
leftyfbWhat sort of remote session do you have that isn’t ssh?22:36
cranberryIt is SSH, but your article refers specifically to OpenSSH22:36
leftyfbWhat ssh do you have on Ubuntu that isn’t openssh?22:37
cranberryhttps://goteleport.com/22:37
leftyfbFunny you should mention that, I’m currently looking into that for my work22:37
cranberryLol what a coincidence22:37
cranberryIt employs a Go SSH server IIRC22:38
leftyfbI setup a test server and it seems to work. Next is getting one setup securely in AWS within a mesh VPN’d VPC and authenticating to maybe GitHub22:39
cranberryI only use local authentication, SSH and Web application access work nicely22:40
leftyfbDo you also have users logging in on the console through some sort of out of band BMC or serial console?22:40
cranberryNo22:41
leftyfbSo why not just set session timeout on openssh and teleport?22:41
cranberryTeleport has that?22:42
sarnoldoh wow this thing kinda looks like kerberos glued to go22:42
leftyfbcranberry: I know it does since when I was testing it I was getting booted from no activity22:42
cranberryI gess in terms of security comparable to Kerberos, in ease of setup and maintenance comparable to setting all your passwords to 000022:42
sarnoldlol22:43
cranberryleftyfb: Nice! I'll scan the docs22:43
leftyfbcranberry: they’ve got slack setup that you can join and talk to some of the devs directly22:43
cranberryhttps://goteleport.com/docs/config-reference/#teleportyaml22:43
cranberryfound it - will try that out. it'll only be for teleport, so not as nice as seccheck, but since 99% should be teleport and I don't need to install another package that's nice22:44
cranberryThank you!22:44
cranberryhm also it does not seem to have a grace option. but I'll see it positive and look into vim-autosaving as my next project22:47
leftyfbvim-autosaving?22:51
leftyfbI have session-agnostic history in vim, not sure if that’s helpful to you22:51
leftyfbI love editing a file I haven’t touched in years and going through the undo history :)22:52
cranberryOhh I need to look into that22:55
cranberryI'm someone who generally uses vim in its default configuration - lol22:55
leftyfbI’m ansiblizing the hell out of all my configs to make it easy to restore configs23:04
leftyfbAnd rebuilding my servers from scratch23:04
Ussatleftyfb, good move23:04
UssatI do that on all my servers23:05
UssatI manage all my *nix and AIX servers with ansible23:05
Ussatgood stuff23:05
leftyfbgot any tips on Apache vhosts other than just some nasty dicts?23:05
Ussatnasty dicts23:06
Ussatsorry23:06
Ussatsome things just dont ansible well23:06
leftyfbAlso torn on how/if I wan to do anything with certbot or just leave that manually at the end23:06
UssatI dont use certbot, so no advice there23:07
leftyfbno public domains or do you pay for certs like a caveman? :)23:07
Ussatpay for them like a major research hospital23:08
Ussatconnected to a majpor university23:08
leftyfbPssh :)23:09
leftyfbYou would think they would have made an Apache module for ansible by now23:14
* Ussat points to #ansible23:17
Ussathttps://docs.ansible.com/ansible/latest/collections/community/general/apache2_module_module.html23:17
Ussathttps://www.bogotobogo.com/DevOps/Ansible/Ansible_SettingUp_Webservers_Apache.php23:18
leftyfbyeah,  interested in community modules. Trying to keep it all stock23:18
leftyfbnot*23:18
UssatI agree23:19
Ussatbut the guys in #ansible might have some thoughts23:19
leftyfbI’ll ask at some point.23:19
leftyfbThey’ve helped me out with a lot23:20
leftyfbGot all fancy with my iptables and handlers23:20
UssatYa good folks there23:20
leftyfbeach role like ssh, Apache, postfix, etc has their own handlers to add their own things like iptables rules and Fail2Ban jails and such23:21

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!