Re: [qubes-users] split gpg: multiple authorization windows popping, autoaccept not working

2018-05-09 Thread Todd Lasman
On 05/08/18 10:12, Quentin wrote:
> Trying to get split gpg to work with thunderbird.
>
> When I click on write in thunderbird it opens three authorization
> windows. First time I give authorization to access my gpg qube, it asks
> to give the permission for 5 minutes. After accepting that, there are
> still authorization windows popping.
>
>
> How to give the authorizations to access the gpg qube for 5 minutes?
>
>From the website, and new in Qubes 4.0:

New qrexec policies in Qubes R4.0 by default require the user to enter
the name of the domain containing GPG keys each time it is accessed. To
improve usability for Thunderbird+Enigmail, in dom0 place the following
line at the top of the file /etc/qubes-rpc/policy/qubes.Gpg:

work-email  work-gpg  allow
where work-email is the Thunderbird+Enigmail AppVM and work-gpg contains
your GPG keys.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a11fee92-6e62-4bef-10b0-74d0f5a50da7%40nowlas.org.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: OpenPGP digital signature


Re: [qubes-users] Re: Networking unavailable on Dell XPS 9350, QubesOS 4

2018-05-09 Thread Andreas
Qubed One - where do I email you re: upgrading the network card? Am actually 
doing on a G505s, is that any different?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1d59bc8b-a335-4005-8192-ebcc277bba12%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Cannot Update TemplateVMs

2018-05-09 Thread dangmadzyu
On Wednesday, May 9, 2018 at 5:42:58 PM UTC-7, dangm...@gmail.com wrote:
> user@deb-stretch:~$ sudo apt update && sudo apt dist-upgrade -yt 
> stretch-backports
> Ign:1 http://deb.debian.org/debian stretch InRelease
> Ign:2 http://security.debian.org stretch/updates InRelease
> Ign:3 https://updates.signal.org/desktop/apt xenial InRelease
> Ign:4 http://deb.qubes-os.org/r4.0/vm stretch InRelease 
> Ign:5 http://deb.debian.org/debian stretch-backports InRelease
>  
> Err:6 http://security.debian.org stretch/updates Release  
>  
>   500  Unable to connect
> Ign:7 http://deb.qubes-os.org/r4.0/vm stretch-testing InRelease
> Err:8 https://updates.signal.org/desktop/apt xenial Release
>   Received HTTP code 500 from proxy after CONNECT
> Err:9 http://deb.debian.org/debian stretch Release
>   500  Unable to connect
> Ign:10 http://deb.qubes-os.org/r4.0/vm stretch-securitytesting InRelease
> Err:11 http://deb.debian.org/debian stretch-backports Release
>   500  Unable to connect
> Err:12 http://deb.qubes-os.org/r4.0/vm stretch Release
>   500  Unable to connect
> Err:13 http://deb.qubes-os.org/r4.0/vm stretch-testing Release
>   500  Unable to connect
> Err:14 http://deb.qubes-os.org/r4.0/vm stretch-securitytesting Release
>   500  Unable to connect
> Reading package lists... Done
> E: The repository 'http://security.debian.org stretch/updates Release' does 
> no longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'https://updates.signal.org/desktop/apt xenial Release' 
> does no longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'http://deb.debian.org/debian stretch Release' does no 
> longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'http://deb.debian.org/debian stretch-backports Release' 
> does no longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch Release' does no 
> longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch-testing Release' 
> does no longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch-securitytesting 
> Release' does no longer have a Release file.
> N: Updating from such a repository can't be done securely, and is therefore 
> disabled by default.
> N: See apt-secure(8) manpage for repository creation and user configuration 
> details.
> 
> 
> 
> user@host:~$ sudo apt update && sudo apt dist-upgrade -yt stretch-backports 
> && sudo apt-get autoremove && sudo poweroff
> Ign:1 http://ftp.us.debian.org/debian stretch InRelease   
>   
> Ign:2 tor+http://sgvtcaew4bxjd7ln.onion stretch/updates InRelease 
>   
> Ign:3 http://deb.qubes-os.org/r4.0/vm stretch InRelease   
> 
> Err:4 http://ftp.us.debian.org/debian stretch Release 
> 
>   500  Unable to connect
> Err:5 tor+http://sgvtcaew4bxjd7ln.onion stretch/updates Release   
> 
>   500  Unable to connect
> Ign:6 http://deb.qubes-os.org/r4.0/vm stretch-testing InRelease   
> 
> Ign:7 tor+http://vwakviie2ienjx6t.onion/debian stretch InRelease  
>   
> Ign:8 http://security.debian.org stretch/updates InRelease
>   
> Ign:9 
> tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion 
> stretch-testers InRelease
> Err:10 http://security.debian.org stretch/updates Release 
>

[qubes-users] Cannot Update TemplateVMs

2018-05-09 Thread dangmadzyu
user@deb-stretch:~$ sudo apt update && sudo apt dist-upgrade -yt 
stretch-backports
Ign:1 http://deb.debian.org/debian stretch InRelease
Ign:2 http://security.debian.org stretch/updates InRelease
Ign:3 https://updates.signal.org/desktop/apt xenial InRelease
Ign:4 http://deb.qubes-os.org/r4.0/vm stretch InRelease 
Ign:5 http://deb.debian.org/debian stretch-backports InRelease 
Err:6 http://security.debian.org stretch/updates Release   
  500  Unable to connect
Ign:7 http://deb.qubes-os.org/r4.0/vm stretch-testing InRelease
Err:8 https://updates.signal.org/desktop/apt xenial Release
  Received HTTP code 500 from proxy after CONNECT
Err:9 http://deb.debian.org/debian stretch Release
  500  Unable to connect
Ign:10 http://deb.qubes-os.org/r4.0/vm stretch-securitytesting InRelease
Err:11 http://deb.debian.org/debian stretch-backports Release
  500  Unable to connect
Err:12 http://deb.qubes-os.org/r4.0/vm stretch Release
  500  Unable to connect
Err:13 http://deb.qubes-os.org/r4.0/vm stretch-testing Release
  500  Unable to connect
Err:14 http://deb.qubes-os.org/r4.0/vm stretch-securitytesting Release
  500  Unable to connect
Reading package lists... Done
E: The repository 'http://security.debian.org stretch/updates Release' does no 
longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'https://updates.signal.org/desktop/apt xenial Release' does 
no longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'http://deb.debian.org/debian stretch Release' does no longer 
have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'http://deb.debian.org/debian stretch-backports Release' does 
no longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch Release' does no 
longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch-testing Release' 
does no longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.
E: The repository 'http://deb.qubes-os.org/r4.0/vm stretch-securitytesting 
Release' does no longer have a Release file.
N: Updating from such a repository can't be done securely, and is therefore 
disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration 
details.



user@host:~$ sudo apt update && sudo apt dist-upgrade -yt stretch-backports && 
sudo apt-get autoremove && sudo poweroff
Ign:1 http://ftp.us.debian.org/debian stretch InRelease 

Ign:2 tor+http://sgvtcaew4bxjd7ln.onion stretch/updates InRelease   

Ign:3 http://deb.qubes-os.org/r4.0/vm stretch InRelease 
  
Err:4 http://ftp.us.debian.org/debian stretch Release   
  
  500  Unable to connect
Err:5 tor+http://sgvtcaew4bxjd7ln.onion stretch/updates Release 
  
  500  Unable to connect
Ign:6 http://deb.qubes-os.org/r4.0/vm stretch-testing InRelease 
  
Ign:7 tor+http://vwakviie2ienjx6t.onion/debian stretch InRelease

Ign:8 http://security.debian.org stretch/updates InRelease  

Ign:9 
tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion 
stretch-testers InRelease
Err:10 http://security.debian.org stretch/updates Release   
  
  500  Unable to connect
Ign:11 https://updates.signal.org/desktop/apt xenial InRelease  
  
Err:12 
tor+http://deb.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion 
stretch-testers Release
  500  Unable to connect

Re: [qubes-users] Intel ME Backdoor, called Odin's Eye

2018-05-09 Thread dangmadzyu
On Wednesday, January 10, 2018 at 2:02:36 PM UTC-8, awokd wrote:
> On Wed, January 10, 2018 8:35 pm, dangmad...@gmail.com wrote:
> > On Sunday, January 7, 2018 at 10:14:26 AM UTC-8, haaber wrote:
> 
> 
> > That Red Pill is a bitter one, isn't it?
> 
> I don't trust ME either and run me_cleaner but that link is just some
> unsubstantiated text. If he'd really been working at Intel 15 years he
> should have been able to get copies of internal documentation at least. A
> blacked out W-2 form doesn't cut it either.

Do you find that sticking your head in the sand to be a productive form of 
security?


I'm sorry that this information upset you so much, but by denying it you're 
only putting others in harms way.


Maybe you'd like for others to have security vulnerabilities? 


Perhaps you are exposing your agenda too much?


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/0bd0d196-4a11-4257-9e2f-3acaba7af63f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] USB auto remove help

2018-05-09 Thread theflakes
I have a usb mic that I always leave connected to one Qube.  I often forget to 
remove it from that Qube before shutting the Qube down.  When I do this, I can 
no longer add it to another Qube or that same Qube after I bring it back up.

Is there a way to disconnect this usb device on shutdown automatically?  Or, 
for that usb device to be usable when I forget to disconnect it again?


thanks

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/3a9d10e3-02ee-4dfe-a0c6-4c3885330fa6%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: How to Add additional Drive and Erase/Clean it?

2018-05-09 Thread Sergio Matta
Em quarta-feira, 9 de maio de 2018 17:43:57 UTC-3, levo...@gmail.com  escreveu:
> I have 1TB Drive (with name /dev/sdc2 in Dom0). But the same time this drive 
> has 3 partitioins.
> 
> 
> How can I erase all partitions or all drive so that at the output I can get a 
> drive with 1 partition?
> 
> Is it possible to do this in Dom0 or I must mount this in one of the 
> templates and do this all stuff in there?

There is fdisk or with gparted on dom0: 
sudo qubes-dom0-update gparted
sudo gparted
* remember to eject the drives wherever they are monted, even on dom0.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/bfb43a22-fd9d-47ce-a5f3-a685b78a515b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] How to Add additional Drive and Erase/Clean it?

2018-05-09 Thread levonsar8
I have 1TB Drive (with name /dev/sdc2 in Dom0). But the same time this drive 
has 3 partitioins.


How can I erase all partitions or all drive so that at the output I can get a 
drive with 1 partition?

Is it possible to do this in Dom0 or I must mount this in one of the templates 
and do this all stuff in there?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/ac51dc06-0cd7-407b-bbba-5485fab15820%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: HCL - Thinkpad X1 Carbon 6th gen - Qubes 4.0

2018-05-09 Thread erikedin . name
I don't _think_ I have a touch screen, so I hadn't even considered it.

I started following the DSDT patching instructions, and it seemed relatively 
easy to follow, but I had to stop once the instructions started talking about 
configuring grub. I use UEFI for booting, so I'm not sure this even makes sense 
in my case. Are DSDT tables used for UEFI too? I'm genuinely pretty clueless 
about these things.

I tried setting a kernel parameter acpi.ec_no_wakeup=1 at boot, and I'm fairly 
certain I got it right, but suspend still doesn't work. Or rather, to be 
specific, waking up from suspend doesn't work.

I also tried looking in the systemd logs for any suspend errors, but I found 
nothing (but I don't know what to look for).
In dom0, I ran

  dom0$ sudo journalctl

and I found the logs for when it does suspend, but nothing for waking up.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a0caa623-d07e-4a86-88d1-9360b446d579%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: HCL - Thinkpad X1 Carbon 6th gen - Qubes 4.0

2018-05-09 Thread beastgoalie
This is excellent. I can't risk having issues with this machine for a few days, 
but starting Monday I will have a week off and will try this. Let me know if 
this works for you ahead of time. Have you used the details at the same link to 
get the touchscreen working, or does you not have the touch screen?
Thanks, and I can't believe I didn't look this up before.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b27e6fe9-a5ad-4ed2-b31c-55e88d279e08%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] HCL - LENOVO-20KHCTO1WW

2018-05-09 Thread Germann Fabio
Hi everyone,

Set boot option in order for the trackpad to work:
psmouse.synaptics_intertouch=1

The issue with sleep mode remails - it sleeps and can't be woken up.
For the moment I just disabled sleep mode.

Cheers,
Fabio

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAKggCnTHJ44vfXPYUXX%2BpL44SXkoB4mddfS1NnVFp%2Bw1q%3DFh-g%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


Qubes-HCL-LENOVO-20KHCTO1WW-20180509-183946.yml
Description: Binary data


[qubes-users] gnupg-curl installation issue

2018-05-09 Thread qubes-fan
I try to install the gnupg-curl into a debian-9 template with:

$ sudo apt install gnupg-curl

I get in return this:

Reading package lists... Done
Building dependency tree   
Reading state information... Done
Package gnupg-curl is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Package 'gnupg-curl' has no installation candidate

Any idea how can I get it in?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/LC3Ziql--3-0%40tutanota.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Installing the boot loader to /dev/sda6 instead of /dev/sda

2018-05-09 Thread Teqleez Motley
> — install Qubes to sda6 without the boot loader
> — boot your primary Linux OS (the one that originally set up GRUB on your
> HDD)
> — run grub-mkconfig and/or edit grub.cfg manually to add entry for Qubes

Hence, Qubes installer does not offer this option, which IMO it should.
I miss this too.

This should be a feature request, then.

-- 
Regards,
Teqleez

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1525859514.2106951.1365934440.24BB5141%40webmail.messagingengine.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] gpg-split revoke command $ export QUBES_GPG_DOMAIN=work-gpg

2018-05-09 Thread qubes-fan
I am playing with gpg-split and I did a missclick. I would need to revoke the 
command.

I executed the  command   
$ export QUBES_GPG_DOMAIN=work-gpg 
by mistake in vault qube instead of work-gpg cube. 

Is there a way to revoke it? 

Thank you

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/LC2fxBC--3-0%40tutanota.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: HCL - Thinkpad X1 Carbon 6th gen - Qubes 4.0

2018-05-09 Thread erikedin . name
According to my googling yesterday, this is not an issue isolated to Qubes. It 
appears to be an issue across the board for Linux and 6th gen X1 Carbon (and 
some Yoga models). The issue is apparently that the BIOS does not list S3 as a 
supported suspend mode. Instead, Lenovo opted for another type of suspend from 
Microsoft called S0i3. Now, this _should_ have support from kernel version 
4.13+, so it _should_ not be an issue, but it appears the problems are at least 
widespread.

There is a collection of links and information on the Arch wiki relating to 
this issue.

https://wiki.archlinux.org/index.php/Lenovo_ThinkPad_X1_Carbon_(Gen_6)

One workaround that people have apparently had success with is to manually 
patch ACPI DSDT tables (whatever those are). As far as I understand, this makes 
the BIOS report S3 as a supported mode.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/52632d92-6ace-40f0-bdb4-f6a2e22f511e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.