[qubes-users] ANN: Qubes-VM-hardening v0.8.4 released

2019-07-18 Thread Chris Laprise
template-based AppVMs, sys-net and sys-vpn Version 0.8.4 expands protection to the /home/user systemd directory, and now hides its vms config directory on all VM startups (not just when its enabled). Upgrading is recommended. Github link - https://github.com/tasket/Qubes-VM-hardening -- Chris

Re: [qubes-users] The PGP Encryption Problem

2019-07-17 Thread Chris Laprise
have a proper replacement. Otherwise, I fear that information security as a field will have failed. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you ar

Re: [qubes-users] Debian 10 Buster upgrade

2019-07-15 Thread Chris Laprise
ting' or 'sid' you may have to also comment those out for the upgrade procedure. Then do the following: apt-get update apt-get upgrade apt-get dist-upgrade apt-get autoremove This process worked for me. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com

Re: [qubes-users] Qubes OS 4.0.2-rc1 has been released!

2019-07-11 Thread Chris Laprise
n't obvious, as release candidates can become the actual release. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups

Re: [qubes-users] are system hangs normal?

2019-07-10 Thread Chris Laprise
On 7/10/19 1:19 PM, acunal.hamad...@gmail.com wrote: Chris: Thank you for your thoughts It just happened again less than an hour of up time while editing a plain text file. while trying to open a dom0 terminal "Failed to execute command "exp-open --launch TerminalEmulator" Fa

Re: [qubes-users] Qubes OS 4.0.2-rc1 has been released!

2019-07-10 Thread Chris Laprise
ssues/5149 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this

Re: [qubes-users] are system hangs normal?

2019-07-09 Thread Chris Laprise
at came to mind when I read your post. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To u

Re: [qubes-users] VPN before sys-firewall ?

2019-07-09 Thread Chris Laprise
sys-vpn. As a result, sys-vpn can perform both vpn and firewall functions. If you consider sys-vpn's role to be trusted and low-risk, then the third example can accomplish the same thing as the first two while consuming less memory and CPU. -- Chris Laprise, tas...@posteo.net https

Re: [qubes-users] Exciting day for Debian! Watching the twitter feed

2019-07-08 Thread Chris Laprise
Heads up on the debian-10 update error (with workaround): https://forums.whonix.org/t/apt-get-error-e-repository-tor-https-cdn-aws-deb-debian-org-debian-security-buster-updates-inrelease-changed-its-suite-value-from-testing-to-stable/7704 -- Chris Laprise, tas...@posteo.net https://github.com

Re: [qubes-users] how to reinstall whonix-14 templates

2019-07-08 Thread Chris Laprise
ork use '--action=upgrade'. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscr

Re: [qubes-users] Installing qubes, new machine.

2019-07-06 Thread Chris Laprise
vidia-driver/ Since nvidia is generally a source a problems, I'd check to see if you can change the BIOS/UEFI settings to turn off the Nvidia GPU and switch to integrated Intel graphics (if available). That should raise the compatibility profile substantially. -- Chris Laprise, tas...@post

Re: [qubes-users] Exciting day for Debian! Watching the twitter feed

2019-07-06 Thread Chris Laprise
On 7/6/19 4:14 PM, drok...@gmail.com wrote: https://twitter.com/debian Buster has arrived! Yay! :D I have to admit, I moved the rest of my VMs over to it a day early (had already been using debian-10 for a while on a few misc things). Thanks to unman for keeping us up to date! -- Chris

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-06 Thread Chris Laprise
em startup script (that's because you chose not to add it to the OS template). So it won't be registered or active right after installation; a restart is necessary. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB

Re: [qubes-users] strange experince with Qube

2019-07-05 Thread Chris Laprise
or users. So a Tor list or forum is probably a better place to discuss this issue. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Goo

Re: [qubes-users] TemplateVM updates almost instantly fail when target is VPN qube but dom0 updates run just fine

2019-07-05 Thread Chris Laprise
this @Chris I think you may be right about the fact that this is a bug and I guess it's time to escalate it into an issue in github. I'm willing to lend a helping hand in making the issue as needed. My setup is all fully dependent on variations of fedora-30-minimal template that

Re: [qubes-users] Re: ANN: Qubes-vpn-support v1.4.1 released!

2019-07-05 Thread Chris Laprise
On 7/4/19 1:51 PM, Jon deps wrote: On 6/20/19 8:00 PM, Chris Laprise wrote: Version 1.4.1 of Qubes-vpn-support has been released. It includes tweaks for smoother operation, greater control over the firewall, and revised docs in the Readme: https://github.com/tasket/Qubes-vpn-support

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-05 Thread Chris Laprise
use firewall please enable networking”. The sys-net VM should always have its netvm set to (none), because its the one VM that communicates through the hardware and not through another VM. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 7

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-04 Thread Chris Laprise
On 7/4/19 4:16 AM, l1am9...@gmail.com wrote: On Thursday, July 4, 2019 at 6:32:55 AM UTC, Philip Pians wrote: On Thursday, July 4, 2019 at 3:49:42 AM UTC, Chris Laprise wrote: On 7/3/19 5:34 PM, Philip Pians wrote: Must be doing something wrong? Wanted to do the test stage and discovered no

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-03 Thread Chris Laprise
vpn-client.conf ...the 'US_East.ovpn' is just an example. So you would do this instead: sudo cp Openvpn.ovpn vpn-client.conf -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You rec

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-02 Thread Chris Laprise
On 7/2/19 3:24 AM, Sphere wrote: On Tuesday, July 2, 2019 at 5:37:58 AM UTC, Philip Pians wrote: On Tuesday, July 2, 2019 at 4:36:22 AM UTC, Chris Laprise wrote: On 7/1/19 11:18 PM, Philip Pians wrote: On Tuesday, July 2, 2019 at 3:13:56 AM UTC, Philip Pians wrote: Using instructions to

Re: [qubes-users] Re: No vpn-handler-openvpn in service tab

2019-07-01 Thread Chris Laprise
it on the line and click the plus sign. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users"

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-07-01 Thread Chris Laprise
or DoH. Thanks a lot for your attention, interest and help. Again, very much appreciated. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to th

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
On 6/30/19 4:10 PM, Chris Laprise wrote: A shortcut you can take to setting up iptables for DNS is to populate /etc/resolv.conf and then run '/usr/lib/qubes/qubes-setup-dnat-to-ns'. This should configure the nat/PR-QBS chain with the DNS addresses you set. So check that your Do

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
hain with the DNS addresses you set. So check that your DoT setup is updating /etc/resolv.conf, then run '/usr/lib/qubes/qubes-setup-dnat-to-ns'. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F0

Re: [qubes-users] Dns-over-TLS in sys-vpn. Is it possible? How?

2019-06-30 Thread Chris Laprise
mething like DoT becomes useful only when your link is generally insecure or you need to use a third-party DNS for some other reason (i.e. you set up your own VPN server but not a DNS server to go with it). -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett

[qubes-users] Re: Sorry, we cannot find your kernels...

2019-06-29 Thread Chris
There are mirrors btw. https://www.qubes-os.org/downloads/#mirrors -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To po

[qubes-users] Re: Sorry, we cannot find your kernels...

2019-06-29 Thread Chris
Yup. Down for me too. The update servers were down earlier today. Not sure if related. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@goo

Re: [qubes-users] Re: Unable to get network adapter working

2019-06-28 Thread Chris
> Do remember to run backups, though. EXT3 on thin LVM is not > as resilient as NTFS, for example. Thanks for the reminder! > For a canonical answer, you might try the qubes-devel mailing list since > they get more in-depth. Will try to ask over there. Thanks much! Case closed -- You received

[qubes-users] HCL - Fitlet2

2019-06-28 Thread Chris
1. Installation was smooth except for the following error: > The following error occurred while installing the boot loader. The system will > not be bootable. Would you like to ignore this and continue with installation? > > failed to set new efi boot target Issue solved by manually creating bo

[qubes-users] Re: Unable to get network adapter working

2019-06-27 Thread Chris
> I will do a fresh install and confirm again that disabling msi does the trick. Confirmed. I tweaked the command a bit because it removed the default kernel options. > qvm-prefs sys-net kernelopts "nopat iommu=soft swiotlb=8192 pci=nomsi" Any idea if this would introduce any security vulnerabi

[qubes-users] Re: Unable to get network adapter working

2019-06-27 Thread Chris
> You fooled me with the cogent problem description and troubleshooting > approach. (~_^) I am a professional Googler and I might have found a solution. Rmb the dmesg logs above where qubes show [ 4.742826] igb :00:06.0: Using MSI interrupts. 1 rx queue(s), 1 tx queue(s) while Ubuntu show [1

[qubes-users] Re: Unable to get network adapter working

2019-06-26 Thread Chris
> I don't think you said which template you are using for sys-net did you? The default was Fedora-29. And some observations.. When I shutdown sys-net, the physical LED of the network adapter is still going through the blinking and off cycle. This probably means that it has nothing to do with

Re: [qubes-users] Unable to get network adapter working

2019-06-26 Thread Chris
> Quickest thing to try is to switch sys-net's template to Debian. Also, > experiment with I tried the Debian template but it still doesn't work. Same symptoms > https://www.qubes-os.org/doc/pci-devices/#pci-passthrough-issues attach > options. I need some help here. Couldn't find the configur

Re: [qubes-users] TemplateVM updates almost instantly fail when target is VPN qube but dom0 updates run just fine

2019-06-26 Thread Chris Laprise
. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiv

Re: [qubes-users] TemplateVM updates almost instantly fail when target is VPN qube but dom0 updates run just fine

2019-06-26 Thread Chris Laprise
s-proxy-forwarder@13-127.0.0.1:8082-127.0.0.1:45048 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jun 26 09:47:18 fedora-30 systemd[1]: qubes-updates-proxy-forwarder@13-127.0.0.1:8082-127.0.0.1:45048.service: Succeeded. I wonder

Re: [qubes-users] Unable to get network adapter working

2019-06-26 Thread Chris Laprise
On 6/26/19 7:56 AM, 'awokd' via qubes-users wrote: Chris: Hi all! Welcome! Successfully booted into Qubes but couldn't get network working. 1. Physically, port LEDs go off and start blinking after awhile. Keeps repeating. 2. Network icon on top right is red and shows &#x

[qubes-users] Unable to get network adapter working

2019-06-26 Thread Chris
Hi all! It's my first time installing Qubes and I need some help with my network adapters. I am using Qubes 4.0.1 The hardware is Fitlet2 with Intel Celeron J3455 (supports both VT-x and VT-d). It comes with 4 Gigabit Ethernet ports using Intel i211. Installation was successful but EFI boot entr

Re: [qubes-users] TemplateVM updates almost instantly fail when target is VPN qube but dom0 updates run just fine

2019-06-24 Thread Chris Laprise
ier versions of Fedora would wait instead of timing-out immediately. So this looks like a bug that should have an issue opened for it. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You recei

Re: [qubes-users] Re: ANN: Qubes-vpn-support v1.4.1 released!

2019-06-21 Thread Chris Laprise
u can see Tor is carried inside the VPN tunnel (no Tor packets visible to your ISP). -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to t

[qubes-users] ANN: Qubes-vpn-support v1.4.1 released!

2019-06-20 Thread Chris Laprise
win vpn project), an equivalent update is forthcoming in the next week. However, if you wish to switch to Qubes-vpn-support now, you can install it without issues for a new VPN VM. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] Convenient untrusted storage for Qubes OS: qcrypt & qcryptd

2019-06-20 Thread Chris Laprise
e experienced this a number of times with my own setups. It would be nice to have the unmounting and closing handled automatically, perhaps with this: https://dev.qubes-os.org/projects/core-admin/en/latest/qubes-events.html#qubes.events.handler -- Chris Laprise, tas...@posteo.net https://githu

Re: [qubes-users] Trim/discard unallocated thin pool space

2019-06-17 Thread Chris Laprise
On 6/17/19 11:38 AM, brendan.h...@gmail.com wrote: Chris - thanks for jumping on this. :) On Monday, June 17, 2019 at 11:16:05 AM UTC-4, Chris Laprise wrote: I would fully expect lvremove to issue discards, if lvm is configured for it. Did you try changing /etc/lvm/lvm.conf so that

Re: [qubes-users] Trim/discard unallocated thin pool space

2019-06-17 Thread Chris Laprise
oving to btrfs. Its unified approach is more likely to process discards completely. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the G

Re: [qubes-users] Trim/discard unallocated thin pool space

2019-06-17 Thread Chris Laprise
lesystem, you would zero-fill an fs by creating a file. Just don't max out the pool completely, or you may end up with an un-bootable system. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 188

Re: [qubes-users] Re: Does Qubes-OS 4.0.1 have support for KDE or GNOME desktop environment?

2019-06-15 Thread Chris Laprise
On 6/15/19 4:44 PM, john s. wrote: On 6/15/19 12:50 AM, Chris Laprise wrote: On 6/14/19 6:00 PM, Jon deps wrote: On 6/5/19 8:00 PM, Chris Laprise wrote: On 6/2/19 3:41 AM, Finn wrote: I've installed Qubes-OS 4.0.1 and it's XFCE desktop environment but I would rather prefer eit

Re: [qubes-users] Re: Does Qubes-OS 4.0.1 have support for KDE or GNOME desktop environment?

2019-06-14 Thread Chris Laprise
On 6/14/19 6:00 PM, Jon deps wrote: On 6/5/19 8:00 PM, Chris Laprise wrote: On 6/2/19 3:41 AM, Finn wrote: I've installed Qubes-OS 4.0.1 and it's XFCE desktop environment but I would rather prefer either KDE or GNOME desktop environment. I found this document[1] where mentioned tha

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-14 Thread Chris Laprise
e the root-autosnap to something else as a way to set aside the most recent good configuration before making dom0 changes or before rebooting after making changes. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-12 Thread Chris Laprise
On 6/12/19 3:04 PM, Mike Keehan wrote: On Wed, 12 Jun 2019 10:29:54 -0400 Chris Laprise wrote: On 6/11/19 6:50 PM, Chris Laprise wrote: I think the best solution for a safe and comprehensive dom0 backup is to have Qubes simply snapshot the root lv at boot time, before its mounted as read

Re: [qubes-users] Qubes: Unable to connect to VPN

2019-06-12 Thread Chris Laprise
.e. only downstream VMs get to access the tunnel). What IS necessary is populating the DNAT rules in the firewall. Check the PR-QBS chain to see if your DNS server IPs were added: iptables -L -v -t nat PR-QBS -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/tt

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-12 Thread Chris Laprise
On 6/11/19 6:50 PM, Chris Laprise wrote: I think the best solution for a safe and comprehensive dom0 backup is to have Qubes simply snapshot the root lv at boot time, before its mounted as read-write. It shouldn't take more than a few script lines in the dom0 startup. Then dom0 can be b

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-11 Thread Chris Laprise
forgot to plan. I think the best solution for a safe and comprehensive dom0 backup is to have Qubes simply snapshot the root lv at boot time, before its mounted as read-write. It shouldn't take more than a few script lines in the dom0 startup. Then dom0 can be backed up like any other vm. --

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-11 Thread Chris
I have the BootIt collection which is great and have used it for years - highly recommended. Regards, Chris - Chris Willard ch...@meliser.co.uk Sent with ProtonMail Secure Email. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To

Re: [qubes-users] Full proper backup of Dom0 possible?

2019-06-10 Thread Chris Laprise
ated in just seconds. With this tool, snapshots are automatically created and it can be used on any regular Qubes lvm volume (but isn't limited to Qubes). -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4

Re: [qubes-users] Can I run a "full" OS within qubes?

2019-06-09 Thread Chris Laprise
On 6/9/19 4:50 PM, kht-lists wrote: Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Sunday, June 9, 2019 2:52 PM, Chris Laprise wrote: On 6/9/19 2:43 PM, Chris Laprise wrote: On 6/9/19 2:01 PM, 'kht-lists' via qubes-users wrote: After watching Matthe

Re: [qubes-users] Can I run a "full" OS within qubes?

2019-06-09 Thread Chris Laprise
On 6/9/19 2:43 PM, Chris Laprise wrote: On 6/9/19 2:01 PM, 'kht-lists' via qubes-users wrote: After watching Matthew Wilson's excellent video and reviewing various FAQs and documents on the qubes-os web site I find myself with a basic philosophical question.  Currently I ru

Re: [qubes-users] Can I run a "full" OS within qubes?

2019-06-09 Thread Chris Laprise
configuring their appVMs in this way. Perhaps someone else can chime in about this possibility. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscr

Re: [qubes-users] AppVm.... ProxyVM not listed?

2019-06-08 Thread Chris Laprise
e in username/password (if any): https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to th

Re: [qubes-users] Re: Wireguard randomly hangs when the request is originated from a different AppVM

2019-06-08 Thread Chris Laprise
ected to the proxy vm. Finding a similar hook in R4 would allow you to set the MTU automatically. Given that wireguard is becoming popular on routers, and Qubes proxy vms are basically routers, you might find some good tips for dealing with this around the web. -- Chris Laprise, tas...@poste

Re: [qubes-users] Re: Wireguard randomly hangs when the request is originated from a different AppVM

2019-06-08 Thread Chris Laprise
openvpn probing the MTU and handling packet fragmentation. I wonder if this is a case of Wireguard requiring manual configuration where openvpn does not. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F0

Re: [qubes-users] Wireguard not working on fedora-29

2019-06-08 Thread Chris Laprise
On 6/8/19 6:11 PM, mmo...@disroot.org wrote: Thanks Chris. I've solved this differently. I'm using the PostUp/PostDown script to set the DNAT rules through a script that I've made, which also sets the resolv.conf properly since the resolvconf daemon is not working as it sho

Re: [qubes-users] Wireguard not working on fedora-29

2019-06-08 Thread Chris Laprise
On 6/8/19 3:20 PM, Chris Laprise wrote: On 6/8/19 8:22 AM, mmo...@disroot.org wrote: I saw this issue. But unfortunately the latest-kernel-vm (5.1.2-1) doesn't contain the modules for wireguard. So the problem still remains. When I use the debian-9 template on the sys-vpn the other appvm

Re: [qubes-users] Wireguard not working on fedora-29

2019-06-08 Thread Chris Laprise
e the '10_wg.conf.example' file to '10_wg.conf'. https://github.com/tasket/Qubes-vpn-support/ -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are

Re: [qubes-users] future dom0 to run fedora-30 or debian-10 ?

2019-06-05 Thread Chris Laprise
That dom0 Debian target dropped some time ago. This is news to me. Are you saying that Debian installs can't be cut down to suit a GUI domain or small dom0? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D1

Re: [qubes-users] Does Qubes-OS 4.0.1 have support for KDE or GNOME desktop environment?

2019-06-05 Thread Chris Laprise
h UI, melded WM/app widgets) doesn't seem compatible with Qubes' concept. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google G

Re: [qubes-users] ## PLEASE ... only 1 more invite urgently needed (Riseup email) PLEASE ##

2019-06-04 Thread Chris Laprise
itively to such requests... I think the poster is a 'WHATEVER YOU MIGHT THINK'. Think about it. :) -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are

Re: [qubes-users] halfway to a certified hardware list

2019-06-03 Thread Chris Laprise
supplied a date. The ordering (year first) allows sorting without having to parse the input as an actual date. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-users] upgrading to fed 30 min for vpn proxy?

2019-06-01 Thread Chris Laprise
es the vpn scripts to hang for the same period. Current workaround is to run it with debian-9. Issue: https://github.com/tasket/Qubes-vpn-support/issues/39 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106

Re: [qubes-users] Fedora 28 has reached EOL

2019-05-30 Thread Chris Laprise
f update again and there are 219 packages to update. 2. Trying to remove thunderbird, dnf wants to remove 67 packages incl. most of qubes*, nftables, salt, tinyproxy. It would be good to be able to remove thunderbird or other large apps without the OS crumbling to pieces. -- Chris Laprise

Re: [qubes-users] qubes-tunnel service fails in VPN ProxyVM

2019-05-28 Thread Chris Laprise
nd is missing in the templatevm. I recommend not using minimal templates, and for now avoid fedora-29 (fedora-28 and debian are OK). -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this

Re: [qubes-users] Re: real and virtual storage usage by qubes

2019-05-28 Thread Chris Laprise
ich point the storage pool becomes unusable). Thread https://groups.google.com/d/msgid/qubes-users/44f1ae64-2da1-480f-aa30-98c5f22653ba%40googlegroups.com -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F

Re: [qubes-users] Backup while VMs are running??

2019-05-28 Thread Chris Laprise
there might be a problem in that case. The disk usage widget in the system tray will tell you what kind of storage system your Qubes is using; if you used the default LVM it will say "lvm" with the usage stats to the right. -- Chris Laprise, tas...@posteo.net https://github.c

Re: [qubes-users] Q4.0 - LVM Thin Pool volumes - lsblk returns very large (256kb) MIN-IO and DISC-GRAN values

2019-05-28 Thread Chris Laprise
On 5/28/19 8:42 AM, brendan.h...@gmail.com wrote: On Saturday, May 25, 2019 at 2:28:13 PM UTC-4, Chris Laprise wrote: I think the only _good_ way to deal with COW metadata expansion, since its always related to data fragmentation, is to keep expanding it and let system performance degrade

Re: [qubes-users] How to automate cloud backups of trusted vault files?

2019-05-28 Thread Chris Laprise
not well acquainted with the specifics, I'd suggest dropping the requirement to backup individual folders and instead using a passphrase with Qubes backup to backup the vaultvm to the backupvm, then use whatever file transfer software your cloud provider requires in the backupvm. --

Re: [qubes-users] How to automate cloud backups of trusted vault files?

2019-05-28 Thread Chris Laprise
On 5/28/19 5:04 AM, Side Realiq wrote: From: Chris Laprise Sent: Mon May 27 19:58:35 CEST 2019 To: David Hobach , Side Realiq , Subject: Re: [qubes-users] How to automate cloud backups of trusted vault files? On 5/27/19 9:05 AM, David Hobach wrote

Re: [qubes-users] How to automate cloud backups of trusted vault files?

2019-05-27 Thread Chris Laprise
x27;, then unmounts and closes the container. Finally, it pipes the container img file through ssh to the destination system. Initial setup of the container looks like (in vault vm): truncate -s 50M backup.img # Size is 50 megabytes cryptsetup luksFormat backup.img cryptsetup luksOpen back

Re: [qubes-users] After last update system DEAD

2019-05-26 Thread Chris Laprise
ne with M.2 slot to recover. Or how to do this? :( :( :( Thanks. (new email because no access to my password and data :( ) Based on what others have posted about the update, you should try to select the prior kernel version under "Advanced options" in the grub boot menu. -- Chris Lap

Re: [qubes-users] Secondary hdd as storage

2019-05-26 Thread Chris Laprise
t points to it. If you don't setup a pool you can still use 'qvm-block attach' to let VMs access the space as secondary disks. I guess need to reduce size of current windows partition then empty part of hdd to format to ext4 or other linux filesystem and then it will be possible

Re: [qubes-users] Q4.0 - LVM Thin Pool volumes - lsblk returns very large (256kb) MIN-IO and DISC-GRAN values

2019-05-25 Thread Chris Laprise
On 5/25/19 12:45 PM, Brendan Hoar wrote: On Sat, May 25, 2019 at 12:09 PM Chris Laprise <mailto:tas...@posteo.net>> wrote: It would be interesting if thin-lvm min transfer were the reason for this difference in behavior between fstrim and the filesystem. Indeed. Pretty sur

Re: [qubes-users] Q4.0 - LVM Thin Pool volumes - lsblk returns very large (256kb) MIN-IO and DISC-GRAN values

2019-05-25 Thread Chris Laprise
ding cloning/snapshotting and/or modifying many small files then that figure could balloon close to 100% in a very short period. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received thi

Re: [qubes-users] qubes-template-debian-10

2019-05-23 Thread Chris Laprise
read 's/stretch/buster/g' instead. Also, references to debian-8 & debian-9 should be changed to debian-9 and debian-10, respectively. Finally, the compacting procedure doesn't apply on Qubes 4. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-05-23 Thread Chris Laprise
ega8-Graphics-1TB-HDD-4GB-RAM-i5575-A410BLU-PUS/212669685 [4] https://wiki.archlinux.org/index.php/Dell_Inspiron_5575 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message be

[qubes-users] pulseaudio-equalizer in dom0 works, then conflicts

2019-05-22 Thread Chris Laprise
no way to play audio from VMs. I'd be interested if anyone thinks they know why this conflict occurs and/or possible workarounds. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- Yo

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-05-22 Thread Chris Laprise
oice isn't random consumer gear. AMD processors tend to be more secure in the face of sidechannel attacks and suffer less performance degradation[1] from resulting security patches; that's certainly a reason to go in AMD's direction. 1. https://www.tomshardware.com/news/intel-amd-

Re: [qubes-users] Re: apps from whonix-ws-14-dvm fail to start irregularly

2019-05-19 Thread Chris Laprise
t obvious from those, afraid I wouldn't know where to look next. There is a memory-allocation bug with a fix in dom0 current-testing. The package is qubes-core-dom0-4.0.43 and the issue is here: https://github.com/QubesOS/qubes-issues/issues/4891 Applying this fix makes a very noticeable

Re: [qubes-users] whonix-gw: 'Hash sum mismatch' on update

2019-05-19 Thread Chris Laprise
On 5/18/19 8:54 PM, 'awokd' via qubes-users wrote: Chris Laprise: On 5/16/19 6:27 AM, Chris Laprise wrote: I'm getting a hash sum error when updating my whonix-gw-14 template today. No error occurred when updating whonix-ws-14. See below for the apt-get output... Any idea

Re: [qubes-users] whonix-gw: 'Hash sum mismatch' on update

2019-05-18 Thread Chris Laprise
On 5/16/19 6:27 AM, Chris Laprise wrote: I'm getting a hash sum error when updating my whonix-gw-14 template today. No error occurred when updating whonix-ws-14. See below for the apt-get output... Any ideas why a freshly-installed Whonix 14 template would experience an update verific

Re: [qubes-users] dark colour mode

2019-05-18 Thread Chris Laprise
add-in with the "Midnight Surfing" palette. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&qu

Re: [qubes-users] dark colour mode

2019-05-18 Thread Chris Laprise
palettes of Gnome/Gtk apps but the opposite hasn't been true in my experience. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Go

[qubes-users] whonix-gw: 'Hash sum mismatch' on update

2019-05-16 Thread Chris Laprise
I'm getting a hash sum error when updating my whonix-gw-14 template today. No error occurred when updating whonix-ws-14. See below for the apt-get output... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4

[qubes-users] Re: [qubes-devel] QSB #49: Microarchitectural Data Sampling speculative side channel (XSA-297)

2019-05-16 Thread Chris Laprise
consider recommending a switch to AMD processors as a short-term mitigation against CPU vulnerabilities. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are

Re: [qubes-users] Fedora Deprecation

2019-05-15 Thread Chris Laprise
On 5/13/19 6:52 PM, 'awokd' via qubes-users wrote: Chris Laprise: Its also the case that Fedora is intended to be a testbed, NON-production OS and Qubes has plans to migrate away from it. Interesting; more details on this somewhere, or was it IRC chatter? There's an issue

Re: [qubes-users] VPN before Tor setup using Whonix help

2019-05-13 Thread Chris Laprise
u should also read the vpn-related sections of the Whonix docs; There are tradeoffs to using a vpn with Whonix. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you a

Re: [qubes-users] qubes vpn autostart

2019-05-13 Thread Chris Laprise
fedora-29 template.| |thanks in advance.| At this point I'd suggest using Fedora 28 with Qubes-vpn-support, as a bug has been logged about a problem with Fedora 29. OTOH, you could try using NM with Fedora 29 to see if that works. -- Chris Laprise, tas...@posteo.net https://github.com/

Re: [qubes-users] Thin Pool metadata full

2019-05-12 Thread Chris Laprise
ap # swapon -a # lvextend --poolmetadatasize +200M qubes_dom0/pool00 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-use

Re: [qubes-users] Re: Qubes - Critique (long)

2019-05-10 Thread Chris Laprise
s first requires re-flashing the firmware with Coreboot... an exercise that I'm about to try. :) -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subsc

Re: [qubes-users] R4.0.1: Various tray icons transparent/invisible (nm-applet, etc.) in KDE

2019-05-08 Thread Chris Laprise
ehavior of existing apps. Various troubleshooting threads around the net usually assume that KDE is installed with 'plasma-nm' widget, but my tests with a Qubes template running KDE show the problem still exists. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://

Re: [qubes-users] fedora 29 & missing firefox 66.0.4 version

2019-05-07 Thread Chris Laprise
Sid; I didn't check. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

Re: [qubes-users] Any recommended compatible motherboard for INTEL i7-8700?

2019-04-29 Thread Chris Laprise
best compatibility. Finally, Nvidia has a rotten reputation for compatibility because they're so secretive about driver code; OTOH there are plenty of Intel and AMD graphics options available. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BE

Re: [qubes-users] Help with a good laptop!

2019-04-29 Thread Chris Laprise
forums for recent posts with 'HCL' in the title. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] Very confused setting up a vpn

2019-04-29 Thread Chris Laprise
internet No characters should appear on the password line. You can check it manually by looking in the userpassword.txt file as I mentioned. Also, it will be necessary to look at the log as I described to find out what is causing the problem. -- Chris Laprise, tas...@posteo.net https://github.c

<    1   2   3   4   5   6   7   8   9   10   >