Re: [qubes-users] Salt management questions

2018-02-15 Thread Connor Page
Please consult https://www.qubes-os.org/news/2017/06/27/qubes-admin-api/ https://www.qubes-os.org/news/2017/10/03/core3/ for more information about admin possibilities and how they’re supposed to work. There are simple demo examples as well. -- You received this message because you are

[qubes-users] template debian-9 no network (Q4r4) ?

2018-02-06 Thread Connor Page
you probably ticked update over Tor option when installing. templates do not connect to network directly, they use an updates proxy. I' not sure it can be changed in GUI, but you can find the appropriate rpc policy in /etc/qubes-rpc alternatively you can temporarily set template vm's network

[qubes-users] after update no VM 'starts' apps anymore.

2018-01-30 Thread Connor Page
sudo xl console -t serial Work -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to

Re: [qubes-users] Qubes 4.0-rc3

2018-01-10 Thread Connor Page
The official templates use nftables so shouldn’t be mixed with iptables. I didn’t have time to learn about nftables, so just removed nftables package from debian 9 template. YMMV. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

[qubes-users] Enable PCI_HOTPLUG

2018-01-03 Thread Connor Page
Hmmm, this kind of makes qvm-pci useless... I think this should be enabled in vm kernels and then users who want hotplug enabled could just add that kernel flavour to their grub. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

Re: [qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-12 Thread Connor Page
I’ll disagree with comparison of btrfs to lvm. there is a very significant difference between btrfs and lvm. btrfs is like a namespace and lvm volumes are block devices. one can put a namespace on a block device. but yes, layers and layers of metadata processing required. BTW, has anyone

Re: [qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-12 Thread Connor Page
sudo lvcreate -L --type thin-pool --thinpool qvm-pool --add lvm_thin -o volume_group=,thin_pool= qvm-create -P ... or qvm-clone -P set desired private image size using standard tools. this will put the private volume in the new thin pool. private volumes are mounted in /rw btrfs

Re: [qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-12 Thread Connor Page
I agree with Chris. Data specific to a qube should be stored on one of that qube’s volume. Backups work then. so in short, first create a qubes storage pool qvm-pool --add qvm-create -P if you go for a thin pool, create it first and use volume group and thin pool names as options for

Re: [qubes-users] Q4: vm-templates and updates

2017-12-11 Thread Connor Page
Please refer to Qubes issue #3118 which spells it out. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this

[qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-11 Thread Connor Page
I hope you do understand that there is no encryption in what you propose. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Q4: vm-templates and updates

2017-12-11 Thread Connor Page
did you update it in R4 before cloning and upgrading? templates establish a connection to a proxy running in some netvm defined in dom0 over a vchan. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

[qubes-users] Q4: vm-templates and updates

2017-12-11 Thread Connor Page
did you update it in R4 before cloning and upgrading? templates establish a connection to a proxy running in some netvm defined in dom0 over a vchan. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] Where is ability to backup and restore backups on 4?

2017-12-07 Thread Connor Page
There are more critical problems than lack of gui frontend at the moment. Still, backup ui is on the devs' list. See issue #3354 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it,

[qubes-users] How to change / swap behavior of Ctrl, Alt, Win, and fn keys?

2017-08-06 Thread Connor Page
AFAIK fn does not emit a code and bios will process it only in combinations with predefined keys. other keys can probably be remapped. but from my exprience I failed to swap fn and ctrl. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To

Re: [qubes-users] VPN-ProxyVM: "Leakproof VPN" by Rudd-O vs. "more involved" method in Qubes Wiki

2017-07-12 Thread Connor Page
On Thursday, February 2, 2017, Chris Laprise <tas...@openmailbox.org> wrote: > On 02/01/2017 07:36 PM, Connor Page wrote: > >> actually I think that reliance on mangle can be avoided since routing >> table selection can be done by source address rather than firewall

[qubes-users] Bug in qubes-backup or tar?

2017-06-17 Thread Connor Page
qvm-backup has a different syntax and vms are excluded from rather than included in a backup. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Re: PFSense

2017-05-31 Thread Connor Page
I don't do hotplugging to pfSense. I've created separate Fedora based netvms with bridges named LAN and DMZ and connected pfSense to those at start. Then other VMs can use those netvms and connect either to a bridge or do the usual Qubes routing. Physycal NIC's can be added to tjose vms and

[qubes-users] Re: PFSense

2017-05-29 Thread Connor Page
I've encountered some problems myself. Out of two identical standard Realtek cards only one is recognised. :( -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Re: PFSense

2017-05-24 Thread Connor Page
Drew, as I've said my wifi card is not supported . Perhaps, yours isn't either. I need to test something that pfsense can talk to. all I changed in VM config was to do with virtual interfaces. those are correctly recognised as xn0 and xn1. -- You received this message because you are

[qubes-users] PFSense

2017-05-23 Thread Connor Page
I've managed to install pfSense as a HVM. not sure if it makes sense to run it as a trusted firewall but that is possible. I created 2 netvms called LAN and DMZ and created bridges in those. i made a copy of pfSense HVM config and changed interface type to bridge, added a second virtual

[qubes-users] sys-net internet stops after a few minutes

2017-03-08 Thread Connor Page
you can create a debian-based sys-net and assign network cards to that. hope you can get Qubes working for you. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] traveling - best practice

2017-02-07 Thread Connor Page
if you're afraid of cameras, just cover it all when entering sensitive information like citizen four did. don't ever enter LUKS passphrase if someone else had an opportunity to boot your laptop without your direct supervision.in that case yes, a live USB drive is your friend until it is safe to

[qubes-users] traveling - best practice

2017-02-07 Thread Connor Page
if you're afraid of cameras, just cover it all when entering sensitive information like citizen four did. don't ever enter LUKS passphrase if someone else had an opportunity to boot your laptop without your direct supervision.in that case yes, a live USB drive is your friend until it is safe to

[qubes-users] Re: Two ways of "true" security.

2017-02-02 Thread Connor Page
I have successfully castrated ME firmware on 2 Haswell laptops so I'd go for something more recent but well supported by Linux, reflash and put a non-Intel network card for peace of mind. ideally a free BIOS would be desirable but that restricts the selection to quite old generations of chips

Re: [qubes-users] VPN-ProxyVM: "Leakproof VPN" by Rudd-O vs. "more involved" method in Qubes Wiki

2017-02-01 Thread Connor Page
actually I think that reliance on mangle can be avoided since routing table selection can be done by source address rather than firewall marks. marks are good to differentiate different types of traffic but in our case all traffic should be trated the same. there is difference in how traffic

[qubes-users] VPN-ProxyVM: "Leakproof VPN" by Rudd-O vs. "more involved" method in Qubes Wiki

2017-02-01 Thread Connor Page
Rudd-O's solution uses a separate routing table thus ensuring that all traffic from VMs go either to VPN or a "blackhole". This is more robust than relying on the main routing table that can be messed up. However, that requires relaxing the reverse path filter and I don't remember any

Re: [qubes-users] Fedora 25

2017-01-30 Thread Connor Page
I guess qubes tools need to be recompiled against new libraries but userspace pulseaudio version is not a problem. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email

[qubes-users] Fedora 25

2017-01-30 Thread Connor Page
I've been using only f25 for about a month now. the upgrade was smooth. just needed to tweak qt5 styles and scaling. looks like now there is a version conflict. qubes-gui-vm requires pulseaudio 9 but I guess f25 has moved on to version 10. -- You received this message because you are

Re: [qubes-users] Linux HVM through Whonix Gateway or VPN

2017-01-26 Thread Connor Page
Linux HVMs don't get network settings from stub domains so all the IPs have to be set manually. When network topology is changed, new addresses have to be entered. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group

[qubes-users] Cannot persistently mount extra partitions

2017-01-25 Thread Connor Page
you can specify your modified config copy in qvm-start --custom-config=/path/to/config vm-name -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Disable Intel ME

2017-01-13 Thread Connor Page
thank you for the link. I have successfuly tried it on a Haswell notebook. it doesn't disable ME but (supposedly) limits it's functionality by removing all modules but 2. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this

Re: [qubes-users] Query - Why unable to clone net-sys VM ?

2017-01-13 Thread Connor Page
you would have to create a new VM, configure it properly and then copy the private image from the source VM. same limitation apply to proxyvms :( -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving

[qubes-users] Re: Is Fedora Really A Good Choice For QubeOS?

2017-01-09 Thread Connor Page
Sorry Drew, you asked what needs to be installed to make another dom0, not the bare minimum that is required. Every Qubes specific package provides a list of prerequisites and version conflicts. For instance, Name: qubes-core-dom0 Version:%{version} Release:1%{dist}

[qubes-users] Re: Is Fedora Really A Good Choice For QubeOS?

2017-01-06 Thread Connor Page
why wouldn't you consult the list of actually installed packages? https://github.com/QubesOS/qubes-installer-qubes-os/blob/master/conf/comps-qubes.xml -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] mounting a disk image or volume in app-vm, fast backups

2016-11-14 Thread Connor Page
On Monday, 14 November 2016 19:24:06 UTC, Unman wrote: > qvm-block -A allows you to attach an image file to a qube. BTW, what's the correct way to detach one image file? it's not mentioned in the man page :( -- You received this message because you are subscribed to the Google Groups

Re: [qubes-users] Display Calibration

2016-11-11 Thread Connor Page
the filename of the colour profile .icc-file is stored in the X atom _ICC_PROFILE. perhaps, if that is available then the correct profile can be selected by gnome settings manager which currently says there are no colour managed devices in vms. I think colord service would need to be enabled as

Re: [qubes-users] Display Calibration

2016-11-09 Thread Connor Page
darktable and firefox can use a defined profile without colord. the profile has to be in a specific place and selected as the display profile (with colord option switched off). for firefox the full path to the profile should be entered in some property that I don't remember exactly right now

Re: [qubes-users] Display Calibration and Audio Equalizer for Dom0 ?

2016-11-04 Thread Connor Page
On Friday, 28 October 2016 12:19:56 UTC+1, Laszlo Zrubecz wrote: > On 09/03/2016 12:49 AM, Connor Page wrote: > > I have calibrated my yellow screen using argyllcms. > > I don't attach usb devices to dom0 so installed it in sys-usb as well. > > used > > https://encr

[qubes-users] проблемы с установкой usb wi-fi адаптера rtl8188eus

2016-10-19 Thread Connor Page
контроллер usb должен быть в той же виртуальной машине. please use English on this mailing list. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [qubes-users] Re: BTRFS?

2016-09-23 Thread Connor Page
Thanks Rusty. People should be aware of this. I think I did reclaim all space but fiddled too much with the settings. Anyway, it was a good excercise, I learned about btrfs, LUKS and dracut, that wouldn't happen otherwise. -- You received this message because you are subscribed to the Google

Re: [qubes-users] BTRFS?

2016-09-22 Thread Connor Page
In fact, I think the right question is "Will Qubes 4 be compatible with btrfs root if vm storage is expected to reside on a LVM thin pool?" -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails

[qubes-users] Re: BTRFS?

2016-09-22 Thread Connor Page
I have root, home and var as subvolumes on a btrfs volume. I intended to create snapshots before updates. The tricky bit was to put it on a LUKS partition as somehow the installer encrypted only the swap partition. Maybe it was my fault, not sure now. Anyway, if you do it check that it is on

[qubes-users] Re: rc.local iptables persistence on reboot

2016-09-22 Thread Connor Page
world writable script executed as root is the worst advice I've ever seen on this mailing list. please don't do that! -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an

Re: [qubes-users] Does QubesOs does not source ~/.profile on purpose?

2016-09-20 Thread Connor Page
the source code of qvm-run is your best documentation of how applications are run without logging in :) here is the session that is started in vms. I like the hangman :) https://github.com/QubesOS/qubes-gui-agent-linux/blob/master/appvm-scripts/usrbin/qubes-session -- You received this message

[qubes-users] Re: rc.local iptables persistence on reboot

2016-09-20 Thread Connor Page
would you mind posting the whole script? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send

[qubes-users] Blank screen after 10 minutes

2016-09-20 Thread Connor Page
try Presentation mode in the power manager panel plugin. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to

[qubes-users] Re: Proper way of implementing unlock with keyfile instead of passphrase

2016-09-18 Thread Connor Page
https://www.kernel.org/pub/linux/utils/boot/dracut/dracut.html#_crypto_luks_key_on_removable_device_support -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] rc.local iptables persistence on reboot

2016-09-18 Thread Connor Page
does it start with this? #!/bin/sh -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to

[qubes-users] Re: netvm doesn't recognize physical hardware switch state

2016-09-15 Thread Connor Page
no. it looks exactly as acpi problem. have you tried a Fedora live dvd/usb? If it doesn't work then the problem is not specific to Qubes. please try. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

[qubes-users] Re: netvm doesn't recognize physical hardware switch state

2016-09-14 Thread Connor Page
with such a fairly fresh kernel you probably should make sure you also have the latest bios. some people also claim that resetting bios settings miraculously makes their wifi work in Linux. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To

[qubes-users] netvm doesn't recognize physical hardware switch state

2016-09-13 Thread Connor Page
does it work in plain Fedora? your problem most probably is not directly related to the network card itself. it could be caused by bios settings and wrong acpi config in kernel. I used to have the same problem when I first tried Qubes R2 on Lenovo Yoga 2 13. ideapad_laptop module back then

Re: [qubes-users] Newbie Qubes questions.. please help!

2016-09-08 Thread Connor Page
Think of Whonix as a possible compartment of your digital life that gives more anonymity online. It would be more or less securely separated from other compartments. In order to save space and admin effort common parts of these compartments (i.e., the root filesystem, kernels, modules) are made

Re: [qubes-users] Streisand - AntiCensorship software

2016-09-07 Thread Connor Page
agree, when I looked at it some time ago I could not imagine why I would need all of that. too large an attack surface for my taste. however, I did investigate what individual elements are capable of and borrowed some ideas, like using port 636 and tls-auth for openvpn. -- You received this

[qubes-users] Networking between Linux and Windows VMs

2016-09-05 Thread Connor Page
they should be connected to the same firewallvm, not netvm. iptables in netvms are set up differently. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Recovery Disk & Suggest Live Linux CD to recovery system like WinPE

2016-09-04 Thread Connor Page
I think nowadays many live installers that have capability to install on encrypted partitions give possibility use the tools in a terminal window. For instance, when I realised that somehow only a swap partition got encrypted in a fresh Qubes install I launched Manjaro live ISO, dd root

[qubes-users] security question: keepass vault password

2016-09-04 Thread Connor Page
it makes an evil maid's mission a bit more complicated -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this

[qubes-users] Display Calibration and Audio Equalizer for Dom0 ?

2016-09-02 Thread Connor Page
I have calibrated my yellow screen using argyllcms. I don't attach usb devices to dom0 so installed it in sys-usb as well. used https://encrypted.pcode.nl/blog/2013/11/24/display-color-profiling-on-linux/ as a rough guide. to get the calibration done you just need to run dispcal and then

[qubes-users] Suggestions for running media server?

2016-09-02 Thread Connor Page
No. 4 makes sense. sys-usb shouldn't know the encryption keys. encrypted block device can be attached to a server vm where it would be appropriately decrypted and mounted, possibly from dom0 via qvm-run (you can start a vm, attach storage, decrypt and mount it by a short script using qvm-*

Re: [qubes-users] Custom initramfs

2016-08-27 Thread Connor Page
after giving it a thought I decided keep usb devices out of dom0. the solution for debian is real 2FA but ykfde is for lazy people. I gave it as an example of dracut hooks. theoretically you can rearrange hooks so that yubikey authentification happens before rd.qubes.hide_all_usb is processed

[qubes-users] Custom initramfs

2016-08-26 Thread Connor Page
this is an interesting idea. initramfs is generated by dracut. read this https://github.com/nj0y/ykfde/blob/master/README-dracut.md -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from

[qubes-users] Re: Manual dpi control in vm's for HIDPI diplays

2016-08-26 Thread Connor Page
this is not a universal approach but should work fine for gnome apps. you should type them in terminal applications in each vm. a more comprehensive approach to cover all bases is to set proper dpi for X server, Xft, gsettings (if gnome-settings-daemon runs), xsettings (IIRC Debian template

[qubes-users] Re: Fedora Minimal ProxyVPN template?

2016-08-09 Thread Connor Page
you can install dunst for minimalist notifications. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this

[qubes-users] Play Audio from AppVm on device attached to USB Cube

2016-07-30 Thread Connor Page
Read the last part at https://www.qubes-os.org/doc/usb/ This should solve your problem unless you want to mix sound from multiple vms. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from

[qubes-users] Re: What do you think about the idea of a FileVM?

2016-07-30 Thread Connor Page
I used to run samba server on Archlinux inside Qubes. Actual data was stored on a separate volume group and mounted in the server vm on boot. The main difficulty was to do routing and firewalling properly on every change of network topology. The main risk was that eventually many vms had to be

[qubes-users] VIF interfaces

2016-07-08 Thread Connor Page
use arp to see ip and mac addresses of vms connected to interfaces. lookup ip in qvm-ls -n or qubes-manager mac addresses are visible in qvm-prefs. assuming your vms don't spoof these addresses ;) -- You received this message because you are subscribed to the Google Groups "qubes-users"