Re: [CentOS] Slow login to system without internet connection

2012-11-20 Thread Stephen Harris
On Tue, Nov 20, 2012 at 07:48:40PM +0100, Ljubomir Ljubojevic wrote: But when I tried to login to my server, it was not instantenous, and I think it was 15+, maybe even 30+ seconds (I forgot to time it) from start of ssh command to password prompt. It is in-house connection, so there is

Re: [CentOS] How to configure sendmail

2012-12-02 Thread Stephen Harris
On Sun, Dec 02, 2012 at 05:54:06PM -0800, John R Pierce wrote: I once knew my way around the 'rules' in the .cf file. thats truly some evil arcane magic in there. My old SA interviews used to include a line of sendmail.cf to see if the applicant recognised it. At the time (SunOS 4,

[CentOS] Building a C5 chroot on a C6 machine

2012-12-14 Thread Stephen Harris
I'm trying to do something slightly silly; rather than having a C5 machine and a C6 machine around for compiling and testing, I want to create a C5 chroot area. Something similar to mock but using lvm snapshots and some local config specific stuff. (Potentially even using Linux Containers to

Re: [CentOS] Building a C5 chroot on a C6 machine

2012-12-14 Thread Stephen Harris
On Fri, Dec 14, 2012 at 12:38:18PM -0600, Les Mikesell wrote: On Fri, Dec 14, 2012 at 12:32 PM, Stephen Harris li...@spuddy.org wrote: I'm trying to do something slightly silly; rather than having a C5 machine and a C6 machine around for compiling and testing, I want to create a C5 chroot

Re: [CentOS] Building a C5 chroot on a C6 machine

2012-12-14 Thread Stephen Harris
On Fri, Dec 14, 2012 at 07:58:17PM +0100, Nicolas Thierry-Mieg wrote: Stephen Harris wrote: The rpm database is in the format of C6, so the C5 programs can't read it! perhaps if you kept the rpms that were installed by yum, you could rpm -i --justdb *.rpm within your chroot

Re: [CentOS] Filesystem Hierarchy Standard respecting CentOS

2012-12-27 Thread Stephen Harris
On Thu, Dec 27, 2012 at 04:14:18PM -0500, James B. Byrne wrote: However, I have not yet found any application packages for CentOS-6 that actually do this. I find some that go into /usr/package_name, some into /usr/lib/package_name, many that install into /usr/libexec I've seen a few. Not

Re: [CentOS] gdisk dependancy problem

2013-01-09 Thread Stephen Harris
On Wed, Jan 09, 2013 at 03:29:29PM -0500, Meyer, Bruce wrote: I followed the instructions here for enabling EHEL: http://www.thegeekstuff.com/2012/06/enable-epel-repository/ However, you enabled it for the wrong repository... --- Package gdisk.x86_64 0:0.8.4-1.el5 will be installed THis is a

[CentOS] dhclient in 5.9 having trouble with dhcpd in 6.3 ?

2013-01-23 Thread Stephen Harris
I have a KVM setup. Host is 6.3. I have a bridged client running 5.9 Since upgrading to 5.9 I noticed that ntpd is being restarted every 12 hours. Jan 20 08:00:25 mercury ntpd[16103]: ntpd exiting on signal 15 Jan 20 20:00:26 mercury ntpd[27462]: ntpd exiting on signal 15 Jan 21 08:00:27

Re: [CentOS] Performance issue

2013-02-09 Thread Stephen Harris
On Sat, Feb 09, 2013 at 04:24:19PM -0200, Carlos Henrique Reimer wrote: processors. vmstat r column run queue usually indicates values higher than 2 and less than 5 but Load Average values from top, sar -q and other commands show always values less than 1. Should not these values be higher

[CentOS] A workaround to dhclient problems

2013-02-12 Thread Stephen Harris
Summary: if you have C5 guests with dhclient bad udp checksum issues then this entry on the host will fix it: iptables -A POSTROUTING -t mangle -p udp --dport bootpc -j CHECKSUM --checksum-fill Detail: If anyone else is seeing this... Feb 11 19:22:11 mercury dhclient: DHCPREQUEST on eth0 to

Re: [CentOS] RHSA-2013:0223-1 - moderate kernel update

2013-02-12 Thread Stephen Harris
On Tue, Feb 12, 2013 at 11:02:58AM -0500, m.r...@5-cent.us wrote: CentOS team: has the CentOS kernel update come out yet that addresses what upstream sent out the email this morning RHSA-2013:0223-1, which mentions a bugfix for a deadlock when oom-killer's invoked? You mean

Re: [CentOS] OT: UPS battery vendor, cont'd

2013-02-12 Thread Stephen Harris
On Tue, Feb 12, 2013 at 01:28:32PM -0500, m.r...@5-cent.us wrote: Having checked with my manager, we'll try the open market quotes. I would like a third recommendation, so I can offer purchasing three quotes. Recommendations? Battery Mart? Looks like they're government CCR

Re: [CentOS] A question

2013-02-12 Thread Stephen Harris
On Tue, Feb 12, 2013 at 04:51:54PM -0800, Bassem Sossan wrote: I have found a good resource, it's a book called Beginning Red Hat Linux 9... the centos's version that I've installed centos 6... Is this book may be compatible with Centos 6 ? Define compatible. RH9 is very very *very* old.

Re: [CentOS] recover lvm from pv

2013-03-07 Thread Stephen Harris
On Thu, Mar 07, 2013 at 09:54:59PM -0500, Harold Pritchett wrote: What other information do I need which may be available? What does 'vgscan' say? 'vgchange -a y' ? -- rgds Stephen ___ CentOS mailing list CentOS@centos.org

[CentOS] Question around updates and drpms directory

2013-03-09 Thread Stephen Harris
Looking at the nice new 6.4 tree (thanks!!!) I see there are already a few updates. eg Packages/firefox-17.0.3-1.el6.centos.i686.rpm Packages/firefox-17.0.3-1.el6.centos.x86_64.rpm So far, so normal. These occur because of timing. That's not a problem; it's expected. What confuses me,

Re: [CentOS] yum update gone wild? - new base?

2013-03-10 Thread Stephen Harris
On Sun, Mar 10, 2013 at 09:30:40PM -0400, Robert Moskowitz wrote: I don't recall ever seeing the base repo change; it is almost like it is picking up the the 6.4 base repo instead. That's exactly what it's doing. The /6 base and update repository always point to the latest version. 6.4 was

[CentOS] Newer version of ftdi_sio

2013-03-20 Thread Stephen Harris
I have just bought an FTDI USB UART New USB device found, idVendor=0403, idProduct=6015 New USB device strings: Mfr=1, Product=2, SerialNumber=3 Product: FT231X USB UART Manufacturer: FTDI However this appears to be slightly too new for the ftdi_sio driver in C6.4; it's not detected.

Re: [CentOS] nscd

2013-03-25 Thread Stephen Harris
On Mon, Mar 25, 2013 at 11:06:31PM +, Gary Greene wrote: NSCD is also necessary if you're running an LDAP or NIS environment, Not necessary in a NIS environment on a LAN 'cos NIS is UDP based and very very fast to respond. LDAP, however, pretty much needs nscd (or sssd) in order to be

Re: [CentOS] yum configuration

2013-03-29 Thread Stephen Harris
On Fri, Mar 29, 2013 at 02:54:58PM +0200, Andreas K. wrote: baseurl=ftp://yum.xx.xx.xx.xx/pub/linux/centos/$releasever/os/$basearch/ Is there a way to force a 6.3 machine to remain at 6.3 until a human being decides that is is time to do so? Change releasever to 6.3 for base and updates and

Re: [CentOS] [Possibly OT] - General question: state of internet traffic

2013-04-01 Thread Stephen Harris
the last month. Until today, I haven't experienced any. However, getting bank record data from chase.com here in NYC seems impossible. What do you mean by getting bank record data ? Every major US bank is under a constant DoS attack, which sometimes causes the sites to be slow. This is

Re: [CentOS] OpenVPN routing question

2013-04-14 Thread Stephen Harris
On Sun, Apr 14, 2013 at 09:00:16AM -0400, Boris Epstein wrote: Let's say I have an OpenVPN (v2) server sitting on a Linux machine with the IP address of, say, 192.168.10.1o. We are talking real address, assigned to a NIC on the machine. Now let us say the OpenVPN server hands out IP's in the

Re: [CentOS] OpenVPN routing question

2013-04-14 Thread Stephen Harris
On Sun, Apr 14, 2013 at 09:14:20AM -0400, Boris Epstein wrote: It works for every subnet except the one the OpenVPN server sits on ( 192.168.10.0/24 in our example). Yes, the VPN server has to be the default router - or else it just does not seem to work. This additional hop just kills

Re: [CentOS] Having difficulty exporting display

2013-04-18 Thread Stephen Harris
On Thu, Apr 18, 2013 at 04:42:18PM -0400, Yves S. Garret wrote: $ xhost + $ ssh -X someusern...@somehostname.net -p 49283 Remote: $ export DISPLAY=192.168.1.6:0.0 Why are you doing this? If ssh isn't setting the DISPLAY variable to something like localhost:10.0 then sshd isn't configured

Re: [CentOS] Missing printer driver

2013-05-11 Thread Stephen Harris
# ./lexmark-inkjet-08-driver-1.0-1.i386.rpm.sh CPU Arch: x86_64 Warning: No installer for x86_64 found, defaulting to x86... ./startupinstaller.sh: bin/linux/x86/libc.so.6/lzma-decode: /lib/ld-linux.so.2: bad ELF interpreter: No such file or directory Your system is pure 64bit; no 32bit

[CentOS] CentOS-Fasttrack readme and repo file is missing?

2013-05-30 Thread Stephen Harris
Just an FYI; hopefully someone who knows will be able to fix :-) http://wiki.centos.org/AdditionalResources/Repositories says CentOS-Fasttrack - This repository contains bugfix and enhancement updates, issued from time to time, between update sets that may be rolled into the next update

Re: [CentOS] Cannot get rtorrent to run

2013-06-21 Thread Stephen Harris
On Fri, Jun 21, 2013 at 09:47:22PM -0400, Yves S. Garret wrote: If I'm writing about this in the wrong place, please let me know. However, when I uninstalled rtorrent and then re-installed it, I kept getting this very same error: Where did you get rtorrent from? It's not part of the default

Re: [CentOS] Cannot get rtorrent to run

2013-06-21 Thread Stephen Harris
On Fri, Jun 21, 2013 at 10:02:47PM -0400, Yves S. Garret wrote: I got it from here: http://pkgs.repoforge.org/rtorrent/ Then you might want to join this list http://lists.repoforge.org/mailman/listinfo/users and ask there. -- rgds Stephen ___

[CentOS] CentOS 5.9 and google-authenticator

2013-06-27 Thread Stephen Harris
I'm playing with google-authenticator libpam https://code.google.com/p/google-authenticator/ It appears to be failing the make test on CentOS 5.9 32bit. ./pam_google_authenticator_unittest Testing base32 encoding Testing base32 decoding Testing HMAC_SHA1 Loading PAM module

Re: [CentOS] fstab, unusual behavior of missing UUID

2013-07-06 Thread Stephen Harris
(sorry for out-of-order post; I deleted the OP's before replying) On Sat, 2013-07-06 at 10:40 -0500, Joseph Hesse wrote: I have the following as the last line of my /etc/fstab file on a computer running CentOS6.4.. UUID=3b550884-8d05-41a5-a205-17b6d7269dd1 /mnt ext3

[CentOS] Kernel 3.10 and CentOS 5

2013-07-29 Thread Stephen Harris
I have a Centos 5 machine which I've just compiled the 3.10.4 kernel on (remembering to set CONFIG_SYSFS_DEPRECATED) because I needed new rtlwifi drivers for my rtl8192cu device. So far, so good. It seems to work. Except /proc/bus/usb doesn't exist anymore. USB_DEVICEFS has been removed. An

Re: [CentOS] How does such long term support work?

2013-07-30 Thread Stephen Harris
On Tue, Jul 30, 2013 at 10:42:46AM -0700, John R Pierce wrote: NetBSD), is a UNIX derived system, while Linux was derived from Minix, which was created from scratch as a Unix work-alike. Umm. No; Linux was not derived from Minix. Minix was a micro-kernel message-passing based system

Re: [CentOS] Kernel 3.10 and CentOS 5

2013-07-31 Thread Stephen Harris
On Tue, Jul 30, 2013 at 08:25:43PM +0200, Ljubomir Ljubojevic wrote: HAve you checked ElRepo third-party reposiroty? kmod packaged drivers for stock kernels. Just go to http://elrepo.org/tiki/DeviceIDs and check for vendor:device ID pairing that lspci command will show for your rtl8192cu

Re: [CentOS] run script on cron job only run on first Saturdat every month???

2013-07-31 Thread Stephen Harris
On Wed, Jul 31, 2013 at 08:52:02AM -0700, Bart Schaefer wrote: As Keith said, it's because the conditions are OR'd. A careful reading of crontab(5) shows that the algorithm is [minute AND hour AND (restricted day of week OR restricted day of month) AND month]. Day of week and day of month

Re: [CentOS] Openssl vulnerability - SSL/ TLS Renegotion Handshakes

2013-08-06 Thread Stephen Harris
On Tue, Aug 06, 2013 at 04:01:12PM +0530, Anumeha Prasad wrote: Hi, I'm currently at CentOS 5.8. I'm using openssl version openssl-0.9.8e-22.el5. The following vulnerability was reported by a Nessus security scan: Don't trust Nessus scans As per following link, Redhat has introduced

Re: [CentOS] 3TB External USB Drive isn't recognized

2013-08-12 Thread Stephen Harris
On Mon, Aug 12, 2013 at 02:56:59PM -0400, m.r...@5-cent.us wrote: I'll note right back at'cha that all of the 3TB drives we have appear to have firmware in them that will present the blocks as 512b. Many/most advanced format do 512e but not all do. The newer 1Tb disks I have do, as smartctl

Re: [CentOS] samba: check password with AD without joining domain?

2013-08-15 Thread Stephen Harris
On Thu, Aug 15, 2013 at 06:40:54PM -0700, Devin Reade wrote: Last time I checked a few years ago I don't think AD supported an LDAP anonymous bind, so you may need to bind as that user in order to validate the creds. AD is kerberos for authentication. If you just want to authenticate user

Re: [CentOS] Really Weird Question.....

2013-08-19 Thread Stephen Harris
On Mon, Aug 19, 2013 at 08:20:28PM -0400, Eddie G. O'Connor Jr. wrote: So I just got ahold of an old e-Machine (Model EL1600) with 1GB of Umm, this machine? http://www.newegg.com/Product/Product.aspx?Item=N82E16883114074 memory. I was going to install CEntOS on it and try to run VirtualBox

Re: [CentOS] Fastest way of removing very large number of files?

2013-08-23 Thread Stephen Harris
On Fri, Aug 23, 2013 at 12:40:51PM +0200, Dennis Jacobfeuerborn wrote: I doubt saving functions calls is going to gain you anything in this case as 99.9% of the time the rm takes is on disk I/O. If you want to reduce the rm time you have to find a way to reduce the disk I/O it requires.

[CentOS] Adding new root suffix to 389 server

2013-08-30 Thread Stephen Harris
My apologies if this is off-topic... On a centos6.4 system I installed 389 server from EPEL. It seems to work well enough. However I'm trying to script things, rather than do it via the GUI. So, for example, I want to add a new suffix: #!/bin/ksh -p pswd=$(cat ~/passwd) add() {

Re: [CentOS] Shell Script Help

2013-09-05 Thread Stephen Harris
On Thu, Sep 05, 2013 at 10:24:55AM -0500, Matt wrote: I have a script file in my cron.hourly that contains a good number of scripts I must call. #!/bin/sh sleep 15 perl /scripts/create_graph.pl sleep 15 perl /scripts/create_graph_out.pl many more lines. etc. Don't background

Re: [CentOS] Enterprise Class Hard Drive - Scam Warning

2013-10-02 Thread Stephen Harris
On Wed, Oct 02, 2013 at 05:24:54PM +0100, Steve Brooks wrote: 9 Power_On_Hours 0x0032 098 097 000Old_age - 2106 12 Power_Cycle_Count 0x0032 100 100 000Old_age - 80 replaced with new drives. Wow... I was also told by the online retailer this

Re: [CentOS] rsyslog not loading relp

2013-10-31 Thread Stephen Harris
On Thu, Oct 31, 2013 at 05:25:50PM -0400, Mauricio Tavares wrote: Oct 31 17:23:43 scan rsyslogd: the last error occured in /etc/rsyslog.conf, line 24:module(load=imrelp) # needs to be done just once Do 'rsyslogd -n -N1 -d' and you might get a better diagnostic (eg missing libraries or

Re: [CentOS] rsyslog not loading relp

2013-10-31 Thread Stephen Harris
On Thu, Oct 31, 2013 at 05:43:28PM -0400, m.r...@5-cent.us wrote: Stephen Harris wrote: Do 'rsyslogd -n -N1 -d' and you might get a better diagnostic (eg missing libraries or incompatible libraries) Or ldd /sbin/rsyslogd. No, that's not good enough. rsyslogd loads modules dynamically

Re: [CentOS] rsyslog not loading relp

2013-11-01 Thread Stephen Harris
On Fri, Nov 01, 2013 at 05:32:53PM -0400, Mauricio Tavares wrote: 1968.101297470:7f2b4eda1700: Requested to load module 'imuxsock' 1968.101300039:7f2b4eda1700: Module 'imuxsock' already loaded Well the good news is that the libraries are all good. There's no failure there. I think it's a

Re: [CentOS] Postfix vs Sendmail

2013-11-02 Thread Stephen Harris
On Sat, Nov 02, 2013 at 01:58:33PM -0400, Fred Smith wrote: I've accumulated a set of rules for the sendmail.mc file that do what sendmail.mc ? Back in the day all we had (SunOS 4) was the cf files that we had to mangle by hand :-) -- rgds Stephen

Re: [CentOS] rsyslog not loading relp

2013-11-04 Thread Stephen Harris
On Mon, Nov 04, 2013 at 09:49:37AM -0500, Mauricio Tavares wrote: I really have nobody else but rsyslog.conf here: [root@scan log]# ls -ld /etc/rsyslog.* Don't use the d flag to ls; that'll stop it looking inside directories. The debug output showed it reading a file from

Re: [CentOS] Machine check events

2013-11-26 Thread Stephen Harris
On Tue, Nov 26, 2013 at 09:25:55AM -0300, Glenn Eychaner wrote: Further investigation seems to indicate that these events should be handled by mcelog or mced. However, there is no /var/log/mcelog, nor do I have a mcelog or mced binary, nor does yum seem to contain anything related (based on

Re: [CentOS] Story of an email

2013-11-30 Thread Stephen Harris
On Sat, Nov 30, 2013 at 07:43:36AM -0500, Scott Robbins wrote: Fetchmail (and getmail) don't make use of smtp. As their name suggests, Yes it does. From man fetchmail As each message is retrieved, fetchmail normally delivers it via SMTP to port 25 on the machine it is running

[CentOS] Error in 6.5 release notes?

2013-12-01 Thread Stephen Harris
http://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.5 Here it says In addition to the samba4 RPM mentioned above but, except for that line, samba isn't mentioned at all. Is this a legacy comment, or is information missing? -- rgds Stephen ___

Re: [CentOS] What is eating up Swap

2013-12-14 Thread Stephen Harris
# free -m total used free sharedbuffers cached Mem: 32081 31784296 0206 2635 -/+ buffers/cache: 28943 3137 Swap:16111 3220 12891 free memory without need of swapping? Not really.

Re: [CentOS] New company name

2014-01-04 Thread Stephen Harris
On Sat, Jan 04, 2014 at 06:36:34AM -0600, John R. Dennison wrote: How can this even be remotely construed to be on-topic for this list? It's not; it's spam. -- rgds Stephen ___ CentOS mailing list CentOS@centos.org

Re: [CentOS] I want to ask about some Kernel level operations.

2014-01-05 Thread Stephen Harris
On Sun, Jan 05, 2014 at 11:54:12PM +0200, Eliezer Croitoru wrote: Well I am building as root when I understand it is safe to do so. This is the point; unless you wrote every line of code then you _don't_ know it's safe. If I sent you a random script, would you run it as root without checking

Re: [CentOS] [CentOS-announce] CentOS Project joins forces with Red Hat

2014-01-07 Thread Stephen Harris
On Wed, Jan 08, 2014 at 01:04:29AM +, Always Learning wrote: The compulsory imposition of USA law on all Centos downloaders creates the possibility of being arrested in one's home country and sent to the [...] Can anyone remember seeing this on the old Centos ? By downloading CentOS

Re: [CentOS] [CentOS-announce] CentOS Project joins forces with Red Hat

2014-01-07 Thread Stephen Harris
On Wed, Jan 08, 2014 at 01:27:49AM +, Always Learning wrote: On Tue, 2014-01-07 at 20:14 -0500, Stephen Harris wrote: If the software was subject to EAR then it was subject to it regardless of a web page stating it. [EAR = USA's Export Administration Regulations] How would

Re: [CentOS] CentOS Project joins forces with Red Hat

2014-01-09 Thread Stephen Harris
On Thu, Jan 09, 2014 at 03:18:10PM -0500, m.r...@5-cent.us wrote: Tell them you can try it out, and if they like the results, they can pay for a license and support for RHEL, the real thing, and that's a *lot* easier sell. Especially if there's a migration script to convert existing CentOS

Re: [CentOS] A question about 7

2014-01-14 Thread Stephen Harris
On Tue, Jan 14, 2014 at 08:35:06PM -0600, Les Mikesell wrote: Let anaconda figure it out. I don't care what it is, just that it is repeatable. Awooga! Awoooga! Awooga! Here's the fun part; devices discovered by Anaconda may not match the devices disovered during the production boot. Device

Re: [CentOS] A question about 7

2014-01-14 Thread Stephen Harris
On Tue, Jan 14, 2014 at 08:54:33PM -0600, Les Mikesell wrote: On Tue, Jan 14, 2014 at 8:43 PM, Stephen Harris li...@spuddy.org wrote: Ultimately what we have is a situation similar to hard disks. We've got used to sd devices changing depending on the order disks are discovered in, which

Re: [CentOS] [CentOS-announce] CentOS Project joins forces with Red Hat

2014-01-16 Thread Stephen Harris
On Thu, Jan 16, 2014 at 10:00:39PM -0500, Joseph Godino wrote: If I recall this was about a CentOS mirror in Iran and the new export restrictions prohibit that. There are no *new* export restrictions. You're just now aware of them. It's the US gubmint that puts those restrictions, not RedHat,

Re: [CentOS] [CentOS-announce] CentOS Project joins forces with Red Hat

2014-01-16 Thread Stephen Harris
On Thu, Jan 16, 2014 at 10:29:09PM -0500, Joseph Godino wrote: stating and what it was referring to. Please retract the word new. That's the point though. If you (for generic values of you) export code under US legal restriction from the US then you're in breach of US regulations. Whether you

Re: [CentOS] Problem with cron

2014-02-23 Thread Stephen Harris
On Sun, Feb 23, 2014 at 08:20:06AM -0600, Joseph Hesse wrote: I have a root cron job that powers down my server every day at 1am and 6pm. The output of '# crontab -l' is shown below. * 1,18 * * * poweroff Nope. That says every minute of hours 1 and 18. So 0100, 0101, 0102, 0103 etc etc

Re: [CentOS] gnutls bug

2014-03-05 Thread Stephen Harris
On Wed, Mar 05, 2014 at 06:12:49PM -0600, Les Mikesell wrote: On Wed, Mar 5, 2014 at 6:00 PM, Michael Coffman updated. I did not realize that once the OS was vaulted, there were no more updates. Now I know so thanks... No, what everyone has said is that there _are_ updates, and yum

Re: [CentOS] Removing a file that starts with dashes

2014-04-02 Thread Stephen Harris
On Wed, Apr 02, 2014 at 09:51:41AM -0500, Frank M. Ramaekers wrote: rm: unrecognized option `--backup=numbered' Try `rm ./'--backup=numbered'' to remove the file `--backup=numbered'. Try `rm --help' for more information. This is one of the oldest of oldest of Unix FAQs eg

Re: [CentOS] CVE-2014-0160 CentOS 6 openssl heartbleed workaround

2014-04-09 Thread Stephen Harris
On Wed, Apr 09, 2014 at 09:36:25AM -0400, James B. Byrne wrote: However, if one was running an affected service, say httpd/ mod_ssl, on a host that had sftp sessions connected to it then would not the ssh private keys of the host and local users be in memory and therefore readable by the

Re: [CentOS] [CentOS-announce] CVE-2014-0160 CentOS 6 openssl heartbleed workaround

2014-04-10 Thread Stephen Harris
On Thu, Apr 10, 2014 at 03:10:31PM +0200, David Hrbá?? wrote: are going to regenerate the user passwords and ssh keys. What more we SSH keys were not compromised by heartbleed (unless you had a management tool that was vulnerable or an alternative ssh daemon that used libssl). Nothing in the

Re: [CentOS] Death of dyndns

2014-04-13 Thread Stephen Harris
On Sun, Apr 13, 2014 at 02:06:42PM +, David G. Miller wrote: Be aware that the actual owner of the dynamic IP address is still authoritative for reverse look ups. This means that some uses of a system with a dynamic IP address are problematic (e.g., mail server) since the reverse look up

Re: [CentOS] Death of dyndns

2014-04-14 Thread Stephen Harris
On Mon, Apr 14, 2014 at 01:42:07PM +, David G. Miller wrote: Interesting. I had to have my ISP add a C record to their DNS for my fixed IP address before most of my e-mails were accepted. I recently also had to add an SPF (sender policy framework) record on my DNS to get my e-mails

[CentOS] Some basic SELinux questions

2014-04-25 Thread Stephen Harris
At my place we don't use SELinux because we have a gazillion tonnes of legacy software that just are not compatible with the default policies. No one wants to go to the effort of working out everything that needs changing. We also use cfengine for central management. Which somestimes causes a

Re: [CentOS] Some basic SELinux questions

2014-04-25 Thread Stephen Harris
On Fri, Apr 25, 2014 at 02:51:40PM -0400, m.r...@5-cent.us wrote: Stephen Harris wrote: a problem when CFe modifies a file that I don't want modified on my machine. Doesn't cfengine allow for logging changes on a per-system basis? I don't control the cfengine configuration, so I don't get

Re: [CentOS] Some basic SELinux questions

2014-04-25 Thread Stephen Harris
Sorry, I got trigger happy with the delete key... so this message is a little out of order... Eero Volotinen wrote: how about using auditd or ossec ? And it looks like auditd may be exactly what I need. Thanks! -- rgds Stephen ___ CentOS mailing

Re: [CentOS] Ulimit problem - CentOS 5.10

2014-04-28 Thread Stephen Harris
On Mon, Apr 28, 2014 at 04:20:25PM -0600, Nathan Duehr wrote: Seems like the brokenness is the behavior of init ignoring /etc/security/limits.conf, to my way of thinking anyway. Umm, no. That's you not understanding what limits.conf is. Limits are hard to grok. I had to write a massive

Re: [CentOS] Disappearing Network Manager config scripts

2014-05-01 Thread Stephen Harris
On Thu, May 01, 2014 at 08:59:54AM -0400, James B. Byrne wrote: On Wed, April 30, 2014 14:11, Les Mikesell wrote: Makes me wonder why we have cars that are all approximately the correct widths to fit on a road and brake and accelerator pedals in the same relative positions.

Re: [CentOS] Ulimit problem - CentOS 5.10

2014-05-05 Thread Stephen Harris
On Mon, May 05, 2014 at 12:44:01PM -0600, Nathan Duehr wrote: Not processes started that change to a non-root user from a root/init/rc script. No session. At least not from what I was seeing in 5.10. Intended or not, it wasn't behaving like PAM was ever involved. :-) If you're doing it as su

Re: [CentOS] Processes launched from rc*.d and ulimit -n

2014-05-08 Thread Stephen Harris
On Fri, May 09, 2014 at 12:06:15AM +, Mitch Patenaude wrote: I figured out part of this: limits.conf is read by pam_limits.so, so until you log in, it isn't effective. I don't have an elegant solution, but my hackish solution so far is just to put a ulimit -n 65536 into the init script.

Re: [CentOS] CentOS 6.5 fresh install, public ssh keys cannot authenticate

2014-05-09 Thread Stephen Harris
On Fri, May 09, 2014 at 03:42:52PM -0700, Greg Bailey wrote: I think you're missing: chmod 600 ~dan/.ssh/authorized_keys Without it, sshd won't use the authorized_keys file if it's readable by other users. (I think that's related to StrictMode; consult sshd man page) No. Public keys

Re: [CentOS] find with exclude directory

2014-05-11 Thread Stephen Harris
On Sun, May 11, 2014 at 12:33:47PM -0400, Tim Dunphy wrote: find / -path '/usr/local/digitalplatform/*' -prune -o -name *varnish* Try find / -path /usr/local/digitalplatform -prune -o name '*varnish*' -print Without the explicit -print, find will implicitly add one e.g find / \( -path

Re: [CentOS] Sorry

2014-05-17 Thread Stephen Harris
On Sat, May 17, 2014 at 03:36:16PM -0700, Russell Miller wrote: One of the adages that drove the creation of the Internet is thus: Be conservative in what you send, and liberal in what you accept. ... says the person sending 100 character width emails :-) -- rgds Stephen

Re: [CentOS] Is it legal ?

2014-05-18 Thread Stephen Harris
On Sun, May 18, 2014 at 02:00:32PM -0700, ngeorgop wrote: Please tell me your opinion. How legal is to use, redistribute, include in installation cds, repos etc, This is not a legal mailing list. Any opinion represented is not worth the electrons used to transmit it. If you are concerned

Re: [CentOS] parsing out adjacent text

2014-06-03 Thread Stephen Harris
On Tue, Jun 03, 2014 at 11:55:55AM -0400, Tim Dunphy wrote: while true do echo Time and date: $(/bin/date +%D %H:%M:%S) /tmp/apache_request_log /tmp/apache_request_log echo ???hostname: $(/bin/hostname -f)\n???/tmp/apache_request_log echo ???host ip: $(/bin/hostname -i)???

Re: [CentOS] [OT] OSX-10.9.3 cd ~'/ problem with spaces'

2014-06-03 Thread Stephen Harris
On Tue, Jun 03, 2014 at 09:34:29AM -0700, Bill Campbell wrote: On Tue, Jun 03, 2014, James B. Byrne wrote: Apologies for this OT post. I need some help debugging a bash script. It just happens to be provided by Apple Inc. In a terminal session under OSX-10.9.3 I want do do this: cd

Re: [CentOS] [OT] OSX-10.9.3 cd ~'/ problem with spaces'

2014-06-04 Thread Stephen Harris
On Wed, Jun 04, 2014 at 02:42:23PM -0400, James B. Byrne wrote: On Tue, June 3, 2014 12:37, Stephen Harris wrote: The OP likely has a function called cd which does other stuff (sets hll-m22:~ byrnejb$ alias A function is not an alias. -- rgds Stephen

Re: [CentOS] dumb developer explodes yum

2014-06-14 Thread Stephen Harris
On Sat, Jun 14, 2014 at 08:14:43PM -0400, Tim Dunphy wrote: rpm-libs-4.4.2-37.el5.i386.rpm Asks for a bunch of libraries. This is what I see when I try: [root@uszmpaplp005lc i386]# rpm -Uvh rpm-libs-4.4.2-37.el5.i386.rpm warning: rpm-libs-4.4.2-37.el5.i386.rpm: Header V3 DSA signature:

Re: [CentOS] block level changes at the file system level?

2014-07-03 Thread Stephen Harris
On Thu, Jul 03, 2014 at 12:48:34PM -0700, Lists wrote: Whatever we do, we need the ability to create a point-in-time history. We commonly use our archival dumps for audit, testing, and debugging purposes. I don't think PG + WAL provides this type of capability. So at the moment we're down

Re: [CentOS] C6.5 - combine two DVD isos into one tree?

2014-07-15 Thread Stephen Harris
On Tue, Jul 15, 2014 at 04:15:44PM +, Tony Mountifield wrote: Or any other ideas? I'm sure I can't be the first to stumble over this! Make a symlink tree from a third location that just points to all the files, and point your boot infrastructure at that. (assuming you're doing a http based

Re: [CentOS] CentOS-7 amavisd-new

2014-07-18 Thread Stephen Harris
On Fri, Jul 18, 2014 at 06:07:08PM +0200, Timothy Murphy wrote: What is the point of putting an rpm in the epel repo if it cannot be installed? Why don't you ask on the EPEL list where it is on-topic and not here, where it is not. -- rgds Stephen

[CentOS] Shrinking a RAID array

2014-07-29 Thread Stephen Harris
My google-fu appears to be weak today... I currently have 8*4Tb in a RAID6. So far I'm only using 6Tb PV VGFmt Attr PSize PFree Used /dev/md6 Large lvm2 a-- 21.83t 15.37t 6.46t Let's say I wanted to remove 2 of these disks from the array and shrink it down to a 6*4Tb How

Re: [CentOS] sssd and authconfig and ldap database lookups

2014-08-06 Thread Stephen Harris
On Wed, Aug 06, 2014 at 05:05:36PM -0400, Mauricio Tavares wrote: [root@testcentos ~]# yum install sssd [...] Package sssd-1.9.2-129.el6_5.4.x86_64 already installed and latest version Nothing to do It didn't re-install any files because the package is already installed. -- rgds Stephen

Re: [CentOS] Centos 7 - iptables service failed to start

2014-08-10 Thread Stephen Harris
On Sat, Aug 09, 2014 at 10:21:33PM -0500, Neil Aggarwal wrote: Hello all: I did a fresh install of CentOS 7 on a new machine. I wrote /usr/local/bin/firewall.stop to remove all the firewall rules. It contains this code: # Flush the rules /usr/sbin/iptables -F You are missing a first

Re: [CentOS] Bare drive RAID question, was RE: *very* ugly mdadm issue [Solved, badly]

2014-09-05 Thread Stephen Harris
On Fri, Sep 05, 2014 at 08:01:05AM -0600, Warren Young wrote: So the real question is, why do you believe you need to make each RAID member a *partition* on a disk, instead of just take over the entire disk? Unless you're going to do something insane like: For me I have things like sda1

Re: [CentOS] CentOS 5.11 / Firefox 31 -- totally borked...

2014-10-20 Thread Stephen Harris
On Mon, Oct 20, 2014 at 12:49:38PM +0100, Lars Hecking wrote: http://people.centos.org/tru/firefox-31.2.0-3.el5.centos.bz1150082-32/ Sweet. Thanks Tru and Johnny! Yay, also fixed my read RH5 32bit desktop at work :-) Thanks! -- rgds Stephen ___

Re: [CentOS] Testing dark SSL sites

2014-10-21 Thread Stephen Harris
On Tue, Oct 21, 2014 at 02:57:42PM -0700, li...@benjamindsmith.com wrote: So we have a set of unit tests written using PHPUnit, having trouble validating certificates. How do you test/validate an SSL cert for a prototype foo.com server if it's not actually active at the IP address that

Re: [CentOS] Testing dark SSL sites

2014-10-21 Thread Stephen Harris
On Tue, Oct 21, 2014 at 04:17:25PM -0700, li...@benjamindsmith.com wrote: I've already confirmed for example, that using openssl s_client as you mention above doesn't actually check the certs, just lists them. Actually it does check them as well. e.g. openssl s_client -connect localhost:443

Re: [CentOS] Centos7 Annoyances

2014-10-30 Thread Stephen Harris
On Thu, Oct 30, 2014 at 05:45:58PM -0700, david wrote: 1: Firewall changes Remove firewalld; install iptables. Problem solved. This has been discussed ad nauseum on this list recently. 2: Apache changes Not RedHat specific issues; that's just progress from upstream. 3: Service - systemd

Re: [CentOS] [OT] mail address - centos mail list

2014-11-08 Thread Stephen Harris
On Sat, Nov 08, 2014 at 05:58:53PM -0800, Keith Keller wrote: The fundamental reason is because Mailman is rewriting the headers in an incompatible way. It is not his site's usage of DKIM. This is a known issue with Mailman. (I used to have a good link explaining the issue, but can't find

Re: [CentOS] Error: libusb-1.0.so.0 is needed....

2014-12-14 Thread Stephen Harris
On Sun, Dec 14, 2014 at 07:22:01PM -0500, Mark LaPierre wrote: On 12/14/14 07:29, ken wrote: uname -r; rpm -q libusb CentOS 6.6 says: [mlapier@mushroom ~]$ uname -r; rpm -q libusb 2.6.32-504.1.3.el6.i686 libusb-0.1.12-23.el6.i686 CentOS 5 has: libusb-0.1.12 CentOS 6 has:

Re: [CentOS] Asymmetric encryption for very large tar file

2014-12-17 Thread Stephen Harris
On Wed, Dec 17, 2014 at 05:14:21PM +, Xinhuan Zheng wrote: used is openssl smime -encrypt -aes256 -in backup.tar -binary -outform DEM -out backup.tar.ssl public.pem². The resulting backup.tar.ssl file is only 2G then encryption process stops there and refuse to do more. Cannot get around

Re: [CentOS] Changing LANG from de_DE to en_US in CentOS 6

2014-12-21 Thread Stephen Harris
On Sun, Dec 21, 2014 at 11:04:30AM +0100, Alexander Farber wrote: on a Macbook with OSX Yosemite (which prints de_DE.UTF-8 as value of $LANG in Terminal) and VmWare Fusion 7 I have installed CentOS 6.6 minimal. When I ssh to my new VM as root, the $LANG is de_DE.UTF-8 too. So where does

Re: [CentOS] can i skip this in backups

2015-01-26 Thread Stephen Harris
On Mon, Jan 26, 2015 at 05:31:54PM +, Jake Shipton wrote: On 26/01/15 17:27, John R Pierce wrote: On 1/26/2015 6:54 AM, kqt4a...@gmail.com wrote: Is it ok to skip /run/log/journal/ in backups there is no directory /run/ on a stock centos system. I think he means

[CentOS] How to prevent root from managing/disabling SELinux

2015-01-23 Thread Stephen Harris
At work I'm used to tools like eTrust Access Control (aka SEOS). eTrust takes away the ability to manage the eTrust config from root and puts it in the hands of security admin. So there's a good separation of duties; security admin control the security ruleset, but are limited by the OS

Re: [CentOS] OT: Extracting Subject Lines from IMAP Mailbox

2015-02-16 Thread Stephen Harris
On Mon, Feb 16, 2015 at 01:50:31PM -0500, Tim Evans wrote: Looking for a command-line way to extract only the Subject lines from my mailbox on my ISP's IMAP server, without actually downloading/modifying the contents of the mailbox. Sort of the remote equivalent of locally doing: telnet

Re: [CentOS] How to prevent root from managing/disabling SELinux

2015-01-26 Thread Stephen Harris
On Mon, Jan 26, 2015 at 03:29:23PM -0500, Daniel J Walsh wrote: You could also set the secure_ booleans Is this in addition to or instead of removing unconfined users? getsebool -a | grep secure_* secure_mode -- off secure_mode_insmod -- off secure_mode_policyload -- off Without removing

<    1   2   3   4   5   6   7   >