Grokbase
Topics Posts Groups | in
x
[ help ]

David Mackintosh (david.macki...@xdroop.com)

Profile | Posts (25)Page 1 of 2: 1 2 > >>
1) David Mackintosh Re: [CentOS] OT: is parted reliable?
| +1 vote
How off-topic is it to ask precisely what is on-topic for this list if questions and discussions of...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Tue, Oct 14, 2008 at 11:13:18PM +0100, Karanbir Singh wrote:

> And Just to remind everyone that no, this is still not a general
> conversation about stuff list.

How off-topic is it to ask precisely what is on-topic for this list
if questions and discussions of the included components belong on the
support mechanisms for those individual parts, and the rest (ie anaconda
and friends) probably belongs in the upstream vendor's forums?

What does that leave?  The color of the logo?

(I like the blue.)

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFI9VA1cwUBd0wDJQQRAnpnAJ4/0jdjWx8xvZzM/tbzXJZU6/leXACdECZl
KPBwtUWzBWJpjLqjXNOWG60=
=0yWc
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
2) David Mackintosh Re: [CentOS] Securing SSH
| +1 vote
Strictly speaking, yes; however in practice, the number of bots (or, indeed, external users who are...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Tue, Mar 25, 2008 at 11:28:45AM -0700, Tim Alberts wrote:
> >http://wiki.xdroop.com/space/Linux/Limited+SSH+Access
> >  
> That sounds great for getting around a remote dynamic IP address, but
> some more authentication/security on that web page is necessary,
> otherwise, anyone who finds that web page is given access?

Strictly speaking, yes; however in practice, the number of bots (or,
indeed, external users who are not me) who the magic web page to hit
(my actual page is not named as the example on the web page is!)
before attacking the ssh connection is zero; therefore since the goal
was to prevent stupid robots from brute-forcing my ssh and filling my
logs, it isn't necessary.  

I mean, strictly speaking you'd next have to insist on a proper SSL
connection to the web server, otherwise you are at risk of someone
sniffing the username and password used in the .htaccess process.
And then after that, you'd have to insist on some kind of security on
the remote system to ensure that your passwords are not being
captured.  Etc, etc.  

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFH6UuvcwUBd0wDJQQRAhR0AJ4wMZZk/r+kAyefHl6vRrqFBIE/vgCff6UW
M6fryQZRwVVPHbbt3om9Nac=
=6n5J
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
3) David Mackintosh Re: [CentOS] Securing SSH
| +1 vote
This is what I do. http://wiki.xdroop.com/space/Linux/Limited+SSH+Access
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Tue, Mar 25, 2008 at 09:48:17AM -0700, Tim Alberts wrote:
> So I setup ssh on a server so I could do some work from home and I think
> the second I opened it every sorry monkey from around the world has been
> trying every account name imaginable to get into the system.
>
> What's a good way to deal with this?

This is what I do.

http://wiki.xdroop.com/space/Linux/Limited+SSH+Access

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFH6UJ2cwUBd0wDJQQRArJZAJ9Gf/6YhEgjMFUi3di6Tv5agwf7LwCeMrWL
jmLCnMATCxN8NKfBQjbuagg=
=v3Pm
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
4) David Mackintosh Re: [CentOS] Xen or VMWARE on CentOS 5
| +1 vote
This is pretty much what I do. I also keep stock "reference" images for each OS I support and copy...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Wed, Feb 27, 2008 at 08:03:09AM -0600, Les Mikesell wrote:
> Ern jura wrote:
> >Does anyone out there have a comprehensive tutorial on installing VMware
> >and
> >successfully managing virtual machines with either xen or vmware?
>
> VMware is pretty simple: download the server rpm, install it, run the
> vmware-config.pl setup script to set the options and install your (free)
> license key. Then run vmware locally or from some other machine to
> access the console where you can create and start the virtual machines.
> Once created, you can treat the virtual machines like they were
> separate physical boxes except that they contend for host resources (and
> once they are up on the network I prefer to connect directly to them
> with ssh, X, freenx, or vnc instead of using the VMware console. You'll
> want plenty of RAM on the host machine and if you run several VM's they
> will perform better if you can spread them over different disk drives.
>
> With VMware you can copy your disk images over to a Windows or Mac host
> and run them with no changes (Mac version isn't free, though).

This is pretty much what I do.  I also keep stock "reference" images
for each OS I support and copy from the reference image every time I
need to deploy a new VM.

I like the idea of Xen, but the documentation is a little thin
especially when it comes to installing useful things like Windows
VMs; I don't have the time to solve the problem properly, and I hope
that in a year or two I can change this.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHxZ9XcwUBd0wDJQQRAmj0AJ96DVWpglCksCg2rUiZ3dgKwhq0MwCeN3Lo
05/MNwA1A4JeY05haCOYv2E=
=Xm0z
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
5) David Mackintosh Re: [CentOS] Making FORWARD_IPV4=YES permanent / DHCP multiple routers
| +1 vote
edit /etc/sysctl.conf Not as far as I know....
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Tue, Feb 12, 2008 at 10:26:54AM -0800, Tim Alberts wrote:
> So how do I do this?

edit /etc/sysctl.conf

> option routers 10.0.0.1 10.0.0.2;

Not as far as I know.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHsedCcwUBd0wDJQQRAj5/AJ0fDki5C0zUo+RP33OGg4wyKe4r3wCfSisZ
utL6xrX0BddZCPzNdK/Msb8=
=Nh72
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
6) David Mackintosh Re: [CentOS] One approach to dealing with SSH brute force attacks.
| +1 vote
This is how I deal with them: deny by default unless you know the "secret handshake"....
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Wed, Jan 30, 2008 at 12:17:22PM -0500, Ed Donahue wrote:
> I use this one, works great and easy to setup
> http://rfxnetworks.com/bfd.php

This is how I deal with them: deny by default unless you know the
"secret handshake".

http://wiki.xdroop.com/space/Linux/Limited+SSH+Access

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHoUvkcwUBd0wDJQQRAudKAJ99OyG/g71oKfD8X4bz13PQlAVGRwCfcYGV
NdXJ8w/4hbCwtFYNtPx7hDg=
=OVMk
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
7) David Mackintosh Re: [CentOS] Bugzilla Install problems - need last mile help
| +1 vote
I've seen this problem before, but I can't find my notes on it. Try creating a user...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Fri, Nov 23, 2007 at 08:59:43AM -0500, Scott Ehrlich wrote:
> Creating database bugs...
> The 'bugs' database could not be created. The error returned was:
>
> Access denied for user ''@'localhost' to database 'bugs'

I've seen this problem before, but I can't find my notes on it.

Try creating a user "bugs@localhost" instead just creating a user
"bugs" -- to mysql, they are different.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHRwUccwUBd0wDJQQRAn1YAJ9dFxCTwf679Ys3m8e/m/hpN2FzqACbBUxt
1vp/L8HnyNSt3++nEQa6STs=
=7vAw
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
8) David Mackintosh Re: [CentOS] fetchmail log messages I don't understand
| +1 vote
I get messages like this with my fetchmail -- the cause has been either the mail provider on the...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Wed, Oct 24, 2007 at 11:46:34AM -0500, Chuck Campbell wrote:
> I see these messages every time fetchmail pops my mail. I don't understand
> what certificates it is talking about, or how to straighten this out.
>
> fetchmail: Server CommonName mismatch: localhost != mail.mydomain.com
> fetchmail: Server certificate verification error: self signed certificate
> fetchmail: Server certificate verification error: certificate has expired
>
> What do I need to read up on to understand this and find a fix?

I get messages like this with my fetchmail -- the cause has been either
the mail provider on the remote end is using a default, self-signed and unmaintained
certificate (ie when you install Sendmail, you get some self-signed certs
generated that are useless beyond the scope of your own private use); in
other cases I have been referring to the computer by a name which differs from
that which the certificate was created with.

In this case I suspect a combination of the two.  It looks like the
service provider got a default cert set up with the system referring to
itself as 'localhost', which is naturally different form the name
'mail.mydomain.com' which is how you are referring to it.

In practice this is probably nothing to worry unduly about unless you
are paying extra for verified TLS-secured mail transmission.  The expired,
mismatched-name cert will be used to encrypt the mail transmission just as
well as a "proper" cert will.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHH5j6cwUBd0wDJQQRAnNGAJ9nX+ajAw615AM936gFYeHV/K/wjQCeM0lu
1kFF2HV+rlEYziKQeFCUqTo=
=h4g8
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
9) David Mackintosh Re: [CentOS] Large scale Postfix/Cyrus email system for 100, 000+ users
| +1 vote
Last I checked, cyrus-imapd could not provide reliable service when the datastore was on NFS.
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Wed, Oct 24, 2007 at 10:38:41AM -0700, Craig White wrote:
> On Wed, 2007-10-24 at 21:21 +0800, Christopher Chan wrote:
> > > I thought the usual ways of doing this were to either use a
> > > high-performance NFS server (netapp filer...) and maildir format so you
> > > can run imap from any client facing server, or to keep the delivery host
> > > information in an LDAP attribute that you find when validating the address.
> > This is the 'I have the money' way of doing this ;-)
> ----
> last I checked, openldap, postfix and cyrus-imapd were free. What is the
> money reference?

Last I checked, cyrus-imapd could not provide reliable service when the datastore
was on NFS.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHH5Z9cwUBd0wDJQQRAs6RAJ9eQlLEmxSVwIFqChvagJafjbau1QCdFJhr
WSElKDGNtNdRqvFobRszvVI=
=KAgU
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
10) David Mackintosh Re: [CentOS] Asus P5B-VM DO board?
| +1 vote
No, unfortunately this is an engineering environment where 4.x is required for compatibility with...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Fri, Oct 12, 2007 at 06:38:51PM +0200, Frank Büttner wrote:
> David Mackintosh schrieb:
> > Anyone had any success with or hints for a system based on the Asus
> > P5B-VM DO board, or the Intel Q965 (with its associated Intel GMA
> > 3000 VGA chip) in general?  
> Have you try it with CentOS 5?

No, unfortunately this is an engineering environment where 4.x is required
for compatibility with their toolset.  I'm sure 5.x is in their future
in the next year, but for today we need 4.x.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHD65ScwUBd0wDJQQRAi3JAKCHkyFY97YPPX7S/A+Cgts/yjURWgCeP2TA
PUWsvbhzyBV2kwLlDzny414=
=eY8o
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
11) David Mackintosh [CentOS] Asus P5B-VM DO board?
| +1 vote
Anyone had any success with or hints for a system based on the Asus P5B-VM DO board, or the Intel...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
Anyone had any success with or hints for a system based on the Asus
P5B-VM DO board, or the Intel Q965 (with its associated Intel GMA
3000 VGA chip) in general?  

I had to put pci=nommconf in order to get the installer (CentOS 4.5)
and the installed system to boot, but I can't get the graphics to work.

Following the instructions at the Intel website
http://www.intellinuxgraphics.org/install.html ends with a compilation error:

# cd drm/linux-core/
# make
make -C /lib/modules/2.6.9-55.0.9.ELsmp/source SUBDIRS=`pwd` DRMSRCDIR=`pwd` modules
make[1]: Entering directory `/usr/src/kernels/2.6.9-55.0.9.EL-smp-x86_64'
  CC [M]  /root/intel/drm/linux-core/drm_agpsupport.o
In file included from /root/intel/drm/linux-core/drmP.h:168,
                 from /root/intel/drm/linux-core/drm_agpsupport.c:34:
/root/intel/drm/linux-core/drm_compat.h:114: warning: static declaration of 'kcalloc' follows non-static declaration
include/linux/slab.h:103: warning: previous declaration of 'kcalloc' was here
/root/intel/drm/linux-core/drm_agpsupport.c: In function `drm_agp_populate':
/root/intel/drm/linux-core/drm_agpsupport.c:531: warning: implicit declaration of function `phys_to_gart'
/root/intel/drm/linux-core/drm_agpsupport.c: In function `drm_agp_init_ttm':
/root/intel/drm/linux-core/drm_agpsupport.c:643: error: structure has no member named `bridge'
make[2]: *** [/root/intel/drm/linux-core/drm_agpsupport.o] Error 1
make[1]: *** [_module_/root/intel/drm/linux-core] Error 2
make[1]: Leaving directory `/usr/src/kernels/2.6.9-55.0.9.EL-smp-x86_64'
make: *** [modules] Error 2

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHD5+NcwUBd0wDJQQRAiHXAJ97B0ZBUmZm+yuppd/2oJcgScqTDgCdGgdP
1BZXAmTJ0DbnM87X0NKToj0=
=Z3CX
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
12) David Mackintosh Re: [CentOS] PHP5/CentosPlus big mess.
| +1 vote
For those who end up here as the result of an internet search: my problem in this case was that I...
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Fri, Sep 28, 2007 at 11:15:44AM -0400, David Mackintosh wrote:
> Ok, so if you tuned in last time, I couldn't make the installation/upgrade of
> PHP5 from the Centos4 CentOS Plus repository work. Not one to be easilly
> dissuaded, I shapened my shovel and dug myself a hole.

[...]

> Now, my users are complaining about errors like:
>
> [28-Sep-2007 10:32:29] PHP Warning: PHP Startup: Unable to load dynamic library '/usr/lib/php/modules/fileinfo.so' - /usr/lib/php/modules/fileinfo.so: cannot open shared object file: No such file or directory in Unknown on line 0
> [28-Sep-2007 10:32:29] PHP Warning: PHP Startup: Unable to load dynamic library '/usr/lib/php/modules/apc.so' - /usr/lib/php/modules/apc.so: cannot open shared object file: No such file or directory in Unknown on line 0
> [...repeat for each file in /usr/lib/php/modules/...]
>
> However, those "files" are there:
>
> # ls -l /usr/lib/php/modules/fileinfo.so /usr/lib/php/modules/apc.so
> -rwxr-xr-x 1 root root 75652 Nov 24 2006 /usr/lib/php/modules/apc.so
> -rwxr-xr-x 1 root root 10580 Nov 24 2006 /usr/lib/php/modules/fileinfo.so
>
> I don't know anything about how to get php to show these errors, since
> the simple phpinfo.php file works (but admittedly it doesn't really do anything).
>
> Can anyone point me in the right direction, or perhaps offer me other
> directions in which to dig?

For those who end up here as the result of an internet search: my
problem in this case was that I installed i386 rpms on a x86_64
system, which explains why php couldn't load the modules even though
they were there.  

Two long hours with yum and rpm, removing and re-installing various
parts, and I have a happy user community.

So honestly this problem was of my own making.  Nothing to see here.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFHAtjkcwUBd0wDJQQRAjYoAJ9pmrYe+KMX6LHw1LDfC01XNx2XXgCeNBVi
HjHCQJNmm6RuxyhwWWeGvLY=
=gDAA
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
13) David Mackintosh Re: [CentOS] PHP5/CentosPlus big mess.
| +1 vote
Yes, I did.
CentOS
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
On Fri, Sep 28, 2007 at 12:48:23PM -0400, Ignacio Vazquez-Abrams wrote:
> On Fri, 2007-09-28 at 12:24 -0400, David Mackintosh wrote:
> > Ahh, I didn't know you could ldd modules. But I still cannot see a problem:
>
> Did you run it on a system exhibiting the problem?

Yes, I did.

--
/\oo/\
/ /()\ \ David Mackintosh |
[email protected: d...@xdroop.com] | http://www.xdroop.com -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFG/UFGcwUBd0wDJQQRAj6dAJ9164Miy9BCnlkk5mgOkE8oZcDwrACeMqTj
twYKu4Pzz+dof3XWhZcmP/0=
=bbE7
-----END PGP SIGNATURE-----

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos
14) David Mackintosh Re: [CentOS] PHP5/CentosPlus big mess.
| +1 vote
Ahh, I didn't know you could ldd modules. But I still cannot see a problem: # ldd...
CentOS