Re: [qubes-users] Experimenting with Wireguard VPN @Mullvad.net

2017-11-11 Thread Chris Laprise
in-template kernel, per the link I sent. If you're using Qubes 4.0 the kernel switch process is simpler: qvm-prefs vmname kernel '' -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received

Re: [qubes-users] /var/log excessive filesystem usage

2017-11-11 Thread Chris Laprise
. Lack of repo signatures allows an attacker to selectively prevent individual updates from being installed. On a typical non-Fedora distro, the attacker can only hold back the entire repository (and they can't change the timestamp to make it appear current). -- Chris Laprise, tas

Re: [qubes-users] Experimenting with Wireguard VPN @Mullvad.net

2017-11-11 Thread Chris Laprise
ted but easy to adapt for Fedora. Chris Laprise,tas...@posteo.net <mailto:tas...@posteo.net> https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 You received this message because you are subscribed to the Google G

Re: [qubes-users] Re: 4.RC2 CANT create / install VM from local iso

2017-11-11 Thread lowson . chris
On Saturday, October 28, 2017 at 1:25:33 PM UTC-4, Filip Magic wrote: > On 10/28/17 11:29, Foppe de Haan wrote: > > On Saturday, October 28, 2017 at 11:27:36 AM UTC+2, Foppe de Haan wrote: > >> On Saturday, October 28, 2017 at 9:49:19 AM UTC+2, Roy Bernat wrote: > >>> On Friday, 27 October 2017

Re: [qubes-users] Re: Installing Debian template 4.0rc2

2017-11-11 Thread Chris Laprise
90sec run a terminal and enter 'sudo rm /etc/systemd/system/multi-user.target.wants/wpa_supplicant@.service'. (Make sure you include the at-sign.) -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 18

Re: [qubes-users] Qubes & Quantum decryption Immunity

2017-11-11 Thread Chris Laprise
and most other disk encryption uses symmetric crypto. I believe qvm-backup crypto is also symmetric (although IIRC it may have specific security issues that need to be addressed). Finally, there is anti-evil-maid; I think it uses symmetric but not certain. -- Chris Laprise, tas...@posteo.net https

Re: [qubes-users] /var/log excessive filesystem usage

2017-11-11 Thread Chris Laprise
dora (can't compete with RHEL on update security!), No certification of PCs... They'll wait 7-10 years until their boys get around to doing it over. Redhat are the Knights Who Say NIH (Not Invented Here). Now Canonical is taking their business and they are flailing about. -- Chris La

Re: [qubes-users] installing a clean template

2017-11-09 Thread Chris Laprise
ing from the ITL repository. You can also download the template from yum.qubes-os.org, copy it to dom0 and install it there. If you're on Qubes 3.2, you can reinstall a template in one step: https://www.qubes-os.org/doc/reinstall-template/ This function doesn't work yet in R4.0. -- Chris Laprise, t

Re: [qubes-users] Recommendations for VPN on the debian8 template ?

2017-11-09 Thread Chris Laprise
On 11/09/2017 06:57 PM, brutellealexan...@gmail.com wrote: On Friday, 10 November 2017 00:39:32 UTC+1, Chris Laprise wrote: On 11/09/2017 05:51 PM,wrote: I've successfully installed a VPN Tunnel as a proxy-VM (on a Fedora 23 template) in my set up. However I don't seem to able to reproduce

Re: [qubes-users] Recommendations for VPN on the debian8 template ?

2017-11-09 Thread Chris Laprise
? When trying I get a TLS Error. Hope someone can help ! Setup is the same on the different templates (only variation is in Qubes R4.0 which isn't in the doc yet). How does the connection go when you start it manually from the terminal? -- Chris Laprise, tas...@posteo.net https://github.com

Re: [qubes-users] work: volume qubes dom0/vm-work-private missing

2017-11-09 Thread Chris Laprise
with 'sudo lvs'? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] reboot and shutdown qubes 4 rc2

2017-11-08 Thread Chris Laprise
? Roy I think its a common problem. What I use is this: qvm-shutdown --all --wait --timeout=20 sudo poweroff -f -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because

[qubes-users] How to make /lib/modules/* writable on R4.0 standalone?

2017-11-05 Thread Chris Laprise
of dependencies like modprobe does). Is there a way to do this permanently? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups

[qubes-users] How to change updates proxy VM on Qubes R4

2017-11-03 Thread Chris Laprise
I tried setting the global updatevm to the VM I created to handle updates, and I enabled 'qubes-updates-proxy' on it. However all the update traffic appears to go through sys-net anyway. How to configure this properly? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

Re: [qubes-users] Re: I can't remove VM

2017-11-02 Thread Chris Laprise
On 11/02/17 12:41, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Nov 02, 2017 at 12:31:11PM -0400, Chris Laprise wrote: On 11/02/17 12:15, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Nov 02, 2017 at 11

Re: [qubes-users] Re: I can't remove VM

2017-11-02 Thread Chris Laprise
On 11/02/17 12:15, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Nov 02, 2017 at 11:34:01AM -0400, Chris Laprise wrote: On 11/02/17 11:28, yuraei...@gmail.com wrote: On Thursday, November 2, 2017 at 3:11:03 PM UTC, bm-2ctrx1tl5lg8cfa

Re: [qubes-users] Re: I can't remove VM

2017-11-02 Thread Chris Laprise
On 11/02/17 11:56, yuraei...@gmail.com wrote: On Thursday, November 2, 2017 at 3:34:21 PM UTC, Chris Laprise wrote: On 11/02/17 11:28, yuraei...@gmail.com wrote: On Thursday, November 2, 2017 at 3:11:03 PM UTC, bm-2ctrx1tl5lg8cfa...@bitmessage.ch wrote: Hi, I restore my backup from Qubes OS

Re: [qubes-users] Re: I can't remove VM

2017-11-02 Thread Chris Laprise
and 'disp-no-netvm1' after restoring R3.2 backups. I've made sure no VMs use those... its easy to do with 'qvm-ls' command. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this

Re: [qubes-users] Re: How to qvm-attach VM volume to another VM?

2017-11-02 Thread Chris Laprise
On 11/02/17 00:13, aphidfar...@gmail.com wrote: On Wednesday, November 1, 2017 at 7:40:01 PM UTC-7, Chris Laprise wrote: I'm trying to repair a debian-9 root volume by first attaching it to an appVM, but the new syntax doesn't seem to allow it. I tried the following so far: qvm-block attach

[qubes-users] Debian 9 running on R4rc2 (was: How to qvm-attach...)

2017-11-02 Thread Chris Laprise
On 11/02/17 03:33, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Nov 01, 2017 at 10:39:36PM -0400, Chris Laprise wrote: I'm trying to repair a debian-9 root volume by first attaching it to an appVM, but the new syntax doesn't seem to allow it. I

[qubes-users] How to qvm-attach VM volume to another VM?

2017-11-01 Thread Chris Laprise
dom0:/dev/mapper/qubes_dom0-vm--debian--9--root -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] Re: Qubes 4.0-rc2 :: VMs fail to start

2017-10-31 Thread Chris Laprise
on from me.) -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Re: Qubes 4.0-rc2 :: VMs fail to start

2017-10-30 Thread Chris Laprise
days, this has usually worked: 1. Close any appVMs that appear to be using lots of RAM and are not giving it back. 2. Start an isolated (network setting is "none") appVM... it should start up. Leave it running... 3. Start the VMs you intend to use; they should also start now.

Re: [qubes-users] Qubes 4.0-rc2 :: VMs fail to start

2017-10-27 Thread Chris Laprise
, there is a RAM allocation problem that (so far) hasn't shown up after I re-start sys-net. Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed

Re: [qubes-users] Qubes 4.0 Display free disk space

2017-10-26 Thread Chris Laprise
On 10/26/17 15:32, Chris Laprise wrote: I'm looking for an easy way to show free drive space in Qubes R4, since Xfce's widget doesn't handle lvm. There is lots of advice for checking lvm space that doesn't seem to apply to thin-provisioned volumes, which is what R4 uses. (As a side-note, lvm

Re: [qubes-users] Qubes 4.0RC2 KDE - NO SDDM

2017-10-26 Thread Chris Laprise
On 10/26/17 13:00, Chris Laprise wrote: On 10/26/17 12:35, Outback Dingo wrote: seems kde plasma isnt even installable right now, i tried based on the doc yet its missing dependencies in 4.0RC2 https://www.qubes-os.org/doc/kde/ Would be best to open an issue for this. See here: https

Re: [qubes-users] Qubes 4.0RC2 KDE - NO SDDM

2017-10-26 Thread Chris Laprise
On 10/26/17 12:35, Outback Dingo wrote: seems kde plasma isnt even installable right now, i tried based on the doc yet its missing dependencies in 4.0RC2 https://www.qubes-os.org/doc/kde/ Would be best to open an issue for this. -- Chris Laprise, tas...@posteo.net https://github.com

Re: [qubes-users] Qubes 4.0RC2 KDE - NO SDDM

2017-10-26 Thread Chris Laprise
before I try :) Have you tried manually installing sddm? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-

[qubes-users] R4rc2 debian-9 template not working at all

2017-10-25 Thread Chris Laprise
rting a second or third time. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To uns

Re: [qubes-users] XEN)QUBES END POINT SECYRITY

2017-10-19 Thread Chris Laprise
first you can review the actual domain name of the link. And email clients like Thunderbird try to detect phishing scams. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed

Re: [qubes-users] Read-only file system in applVM

2017-10-12 Thread Chris Laprise
On 10/12/2017 06:42 AM, Foppe de Haan wrote: On Wednesday, October 11, 2017 at 10:08:18 PM UTC+2, Chris Laprise wrote: On 10/11/2017 04:05 PM, Chris Laprise wrote: I can explain the steps. You may wish to backup your appVM before continuing. 1. Start a dispVM (I'll call it disp1). Your appVM

Re: [qubes-users] Read-only file system in applVM

2017-10-11 Thread Chris Laprise
On 10/11/2017 04:05 PM, Chris Laprise wrote: On 10/11/2017 11:00 AM, Franz wrote: On Tue, Oct 10, 2017 at 2:18 PM, Chris Laprise <tas...@posteo.net <mailto:tas...@posteo.net>> wrote:     On 10/10/2017 02:31 AM, Franz wrote:     On Mon, Oct 9, 2017 at 9:36 PM, C

Re: [qubes-users] Read-only file system in applVM

2017-10-11 Thread Chris Laprise
On 10/11/2017 11:00 AM, Franz wrote: On Tue, Oct 10, 2017 at 2:18 PM, Chris Laprise <tas...@posteo.net <mailto:tas...@posteo.net>> wrote: On 10/10/2017 02:31 AM, Franz wrote: On Mon, Oct 9, 2017 at 9:36 PM, Chris Laprise <tas...@posteo.net <mailto

Re: [qubes-users] Read-only file system in applVM

2017-10-10 Thread Chris Laprise
On 10/10/2017 02:31 AM, Franz wrote: On Mon, Oct 9, 2017 at 9:36 PM, Chris Laprise <tas...@posteo.net <mailto:tas...@posteo.net>> wrote: On 10/09/2017 08:48 AM, Franz wrote: Hello, Trying to save a long document I got an error. So tried to open a

Re: [qubes-users] (Urgent) How do I uninstall qubes or install anything else over it

2017-10-09 Thread Chris Laprise
.11).aspx -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving e

Re: [qubes-users] Read-only file system in applVM

2017-10-09 Thread Chris Laprise
? and if  is there a fix other than rebooting? Best Fran It probably means there is a logical inconsistency (corruption) in that filesystem, or it filled-up. You can avoid the latter by expanding the Private storage max size in the VM's settings. -- Chris Laprise, tas...@posteo.net https://twitter.com

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-08 Thread Chris Laprise
On 10/08/2017 05:34 AM, Sean Hunter wrote: On Fri, Oct 06, 2017 at 11:55:04PM -0400, Chris Laprise wrote: On 10/06/2017 11:26 PM, Person wrote: Cloning VMs is quite troublesome right now, so it is hard to update Fedora and Debian in order to use NetworkManager. You can easily install

Re: [qubes-users] kswapd0 using 100% CPU with not even a MB swap in use

2017-10-08 Thread Chris Laprise
in this problem when I upgraded to the latest 4.9 kernels; currently using 4.9.45-21 and the problem isn't reappearing. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscrib

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-06 Thread Chris Laprise
-template-fedora-25 -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving e

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-02 Thread Chris Laprise
. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, sen

Re: [qubes-users] HCL — ASUS Q325UA

2017-10-02 Thread Chris Laprise
R3.2 Kernel: Supports the one in unstable (4.8.12-12), and in fact requires it for proper screen resolution support Remark: What I wrote above, including all relevant links Hi Tao, Could you post the report's yml file? Thanks... -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PG

Re: [qubes-users] HCL Dell Latitude 7480 + dock usb-c problems (dell wd15)

2017-10-02 Thread Chris Laprise
On 08/20/2017 11:31 AM, cyrinux wrote: It is a dock in thunderbolt* Hi cyrinux, If you'd like this computer to be listed on the HCL page, could you attach a yml file from the qubes-hcl-report script? -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-users] How to recover VMs copied before reinstall?

2017-09-26 Thread Chris Laprise
copied my appvms back to /var/lib/qubes/appvms/, but they don't show up in the VM Manager. Can anyone tell me how to get these appvms useable again? Thanks, Ron Try using `qvm-add-appvm vmname templatename`. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] Connect to LAN while VPN is running?

2017-09-17 Thread Chris Laprise
that at least a few of my AppVMs can access the lan? There have been a couple discussions about this in the past. In general, the best way to handle this securely is to connect your LAN-using AppVMs to a non-VPN proxyVM (sys-firewall for example) instead of the VPN VM. -- Chris Laprise, tas

Re: [qubes-users] Reboot a VM that is connected as net/proxy VM

2017-09-14 Thread Chris Laprise
having to manually re-connect many connected appVMs can be daunting. I wonder if this is already a feature request? -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed

Re: [qubes-users] Additional VPN destinations via CLI config?

2017-09-14 Thread Chris Laprise
osen file to openvpn-client.ovpn. You could start this script automatically from rc.local using 'systemd-run xterm ' etc. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subs

Re: [qubes-users] trying to setup VPN on NetVM, can't connect and no error

2017-09-12 Thread Chris Laprise
and is simpler to install: https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] Re: to firejail or not to firejail

2017-08-30 Thread Chris Laprise
likely, ive only known of one ssh client exploit in the wild, and i think it was over 10 years ago. FWIW, AppArmor does work with Qubes VMs and doesn't revolve around a special launcher. [1] https://github.com/tasket/Qubes-VM-hardening/tree/systemd -- Chris Laprise, tas...@posteo.net https://

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-22 Thread Chris Laprise
s-firewall-user-script). -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop r

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-21 Thread Chris Laprise
the appVM (no proxyVM for the VPN client). This may be the simplest route. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" g

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-21 Thread Chris Laprise
to enable DNS forwarding over the VPN. Another setting to check is /proc/sys/net/ipv4/ip_forward which should contain a value of '1'. Also, the iptables 'POSTROUTING' chain should have a masquerade target: $ cat /proc/sys/net/ipv4/ip_forward $ sudo iptables -L -t nat - Chris Laprise, tas...@p

Re: [qubes-users] Use of qubes question

2017-08-02 Thread Chris Laprise
in the /rw folder of the appVM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Not able to connect with 2 firewall-proxy/vpns at same time

2017-07-31 Thread Chris Laprise
On 07/31/2017 07:54 PM, 'Essax' via qubes-users wrote: AUTH: Received control message: AUTH_FAILED This sounds like an issue with the provider. If they ask for more detail you can set '--verb 5' for more verbosity from openvpn. -- Chris Laprise, tas...@openmailbox.org https://github.com

Re: [qubes-users] Qubes OS Systemfiles are read only to root, need help

2017-07-25 Thread Chris Laprise
. Running 'mount' command by itself will tell you if / was mounted as read-only. If so, you can try re-mounting it with the '-o remount,rw' options. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received

Re: [qubes-users] qvm-run problem with strings containing & ?

2017-07-25 Thread Chris Laprise
ecause you don't have to be vigilant about escaping different characters... just escaping the extra quotes should do it. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are sub

Re: [qubes-users] qvm-run problem with strings containing & ?

2017-07-25 Thread Chris Laprise
orkaround, have you tried escaping the character with a backslash like this: \& -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&

Re: [qubes-users] Re: Setup sys-vpn?

2017-07-21 Thread Chris Laprise
://github.com/tasket/Qubes-vpn-support/ I just released it as 'beta' but operation is smooth so far. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-18 Thread Chris Laprise
On 07/18/2017 06:02 PM, Gaiko wrote: > On Tuesday, July 18, 2017 at 11:27:00 AM UTC-4, Chris Laprise wrote: >> On 07/17/2017 07:37 PM, Gaiko wrote: >>> On Sunday, July 16, 2017 at 9:41:53 PM UTC-4, Chris Laprise wrote: >>>> On 07/16/2017 09:23 PM, Gaiko Kyofusho wrot

[qubes-users] Enigmail not working with Split GPG

2017-07-18 Thread Chris Laprise
regarded. I'm using Debian 9 appVMs. Issue #2170 doesn't appear to be the same as this problem. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-18 Thread Chris Laprise
On 07/17/2017 07:37 PM, Gaiko wrote: On Sunday, July 16, 2017 at 9:41:53 PM UTC-4, Chris Laprise wrote: On 07/16/2017 09:23 PM, Gaiko Kyofusho wrote: Sun Jul 16 21:16:22 2017 us=614593 RESOLVE: Cannot resolve host address: vpnprovidermod'dname.com <http://dname.com/>: No address asso

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
On 07/16/2017 09:23 PM, Gaiko Kyofusho wrote: Sun Jul 16 21:16:22 2017 us=614593 RESOLVE: Cannot resolve host address: vpnprovidermod'dname.com <http://dname.com/>: No address associated with hostname Hmmm, looks like a malformed address to me. -- Chris Laprise, tas...@openmailbox.org

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
'. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, sen

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
*_ be appreciated. Have you looked at the openvpn log messages? Do you see a popup saying the link is up? Can you ping IP addresses from an appVM? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message

Re: [qubes-users] VPN-ProxyVM: "Leakproof VPN" by Rudd-O vs. "more involved" method in Qubes Wiki

2017-07-12 Thread Chris Laprise
will have a simplified installer, which I will be posting in the next day or so: https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are

Re: [qubes-users] Attaching non-PCI block devices to VM

2017-07-11 Thread Chris Laprise
ify any VM that contains the volume. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from

Re: [qubes-users] Why does VPN needs its own firewall VM?

2017-07-10 Thread Chris Laprise
On 07/10/2017 03:15 PM, yreb-qusw wrote: On 07/09/2017 11:56 PM, Chris Laprise wrote: On 07/09/2017 11:48 PM, yreb-qusw wrote: at the end of the VPN CLI setup it says : == If you want to be able to use the Qubes firewall, create a new FirewallVM (as a ProxyVM) and set it to use the VPN VM

Re: [qubes-users] Re: Qubes silently ditches Librem

2017-07-10 Thread Chris Laprise
lauded for creating this process and standing by it; It guards against the erroneous perceptions people have about "PC hardware" being a uniform blank canvas for creating an OS. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4A

Re: [qubes-users] VPN gateway using iptables and CLI scripts fails

2017-07-10 Thread Chris Laprise
On 07/10/2017 09:28 AM, Gaijin wrote: On 2017-07-10 02:40, Chris Laprise wrote: On 07/09/2017 05:35 PM, Gaijin wrote: I've been trying to setup my VPN using the instructions here: Set up a ProxyVM as a VPN gateway using iptables and CLI scripts https://www.qubes-os.org/doc/vpn/ I can get

Re: [qubes-users] Why does VPN needs its own firewall VM?

2017-07-10 Thread Chris Laprise
ubes-vpn-support/blob/new-1/rw/config/vpn/qubes-vpn-ns ...then add this to the end of "qubes-firewall-user-script": /rw/config/vpn/qubes-vpn-ns fwupdate -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] Lenovo Thinkpad 335-72G - freeze during installation at networking setup

2017-07-09 Thread Chris Laprise
the save button is greyed out and I can only click cancel. I suggest checking the Devices tab of your netVM to make sure your network interfaces are available to that VM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] VPN gateway using iptables and CLI scripts fails

2017-07-09 Thread Chris Laprise
negatively affecting the leak protection for connected appVMs. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] Lenovo Thinkpad 335-72G - freeze during installation at networking setup

2017-07-09 Thread Chris Laprise
interfaces that you need? For example, if you have an external USB Wifi dongle, can you add the USB controller(s) to sys-net and then use the dongle? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received th

Re: [qubes-users] almost HCL?

2017-07-09 Thread Chris Laprise
, but not so much for qubes. i suspect a newer dom0, fedora 25 maybe, would be able to suspend as that works on bare metal. so, my plan was to wait for qubes-4 first. Its up to you if you want to run the script and submit a yml file. Negative reports can be valuable, too. -- Chris Laprise, tas

Re: [qubes-users] here is how to randomize mac address

2017-07-08 Thread Chris Laprise
quot;new net VM" doesn't have Linux firmware installed. If this helps. Thank you a lot. (Posting back to qubes-users.) It sounds like you almost got it: The conf file is saved in the template, not the netVM. After you do that, shutdown both the template and the netVM, then re-s

Re: [qubes-users] BIOS check before Qubes installation

2017-07-08 Thread Chris Laprise
, as they regularly deal with such protection measures. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To u

Re: [qubes-users] ntp in debain-VMs

2017-07-06 Thread Chris Laprise
you, Bernhard I'm getting consistent time in my Debian 9 VMs. Do you have your 'ClockVM' setting populated in your Qubes Manager Global Settings? Its normally set to sys-net. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106

Re: [qubes-users] HCL -- Lenovo Yoga 3 Pro?

2017-07-06 Thread Chris Laprise
re not yet to the point of submitting an HCL report (from the qubes-hcl-report script), it would be best to repost your issues to qubes-users separately without the 'HCL' subject. This will get more attention from the other users. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett

Re: [qubes-users] HCL - HP Pavilion

2017-07-06 Thread Chris Laprise
number for this laptop? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] here is how to randomize mac address

2017-07-04 Thread Chris Laprise
use 'sudo tasksel' after the upgrade completes; selecting a Gnome desktop will bring in most of the usual apps. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to

Re: [qubes-users] here is how to randomize mac address

2017-07-03 Thread Chris Laprise
in dom0: sudo qubes-dom0-update qubes-template-debian-8 Then upgrade: https://www.qubes-os.org/doc/template/debian/upgrade-8-to-9/ I personally prefer Debian because it has more software and its update process is more secure than Fedora. Hope that helps! -- Chris Laprise, tas...@openmailbox.org

Re: [qubes-users] here is how to randomize mac address

2017-07-03 Thread Chris Laprise
On 07/03/2017 01:51 PM, Chris Laprise wrote: On 07/03/2017 11:11 AM, ausafrashid...@gmail.com wrote: I did this exactly and it worked. The Mac address was changed. But can you confirm it is the right way/most Anonymous way of anonymizing mac address, because there are some different and very

Re: [qubes-users] Best Desktop for Qubes

2017-07-03 Thread Chris Laprise
On 07/03/2017 02:09 AM, taii...@gmx.com wrote: On 07/02/2017 09:18 PM, Chris Laprise wrote: It may have an IOMMU, but does Xen 4.6 work properly with it? Someone had reported that a different AMD desktop configuration appeared on the surface to be IOMMU compatible in Qubes, but in actually

Re: [qubes-users] Best Desktop for Qubes

2017-07-02 Thread Chris Laprise
with it? Someone had reported that a different AMD desktop configuration appeared on the surface to be IOMMU compatible in Qubes, but in actually it wasn't being enabled at startup. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] Terrible audio quality in one VM

2017-07-01 Thread Chris Laprise
. Anyone have any idea on what may be causing this? Andrew Morgan I would guess its a pulse audio setting in your home folder. Easy way out may be to simply copy your data files over to a new appVM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB

Re: [qubes-users] Rules for when "Update VM" is an active menu item

2017-07-01 Thread Chris Laprise
On 07/01/2017 01:33 PM, motech man wrote: On Saturday, July 1, 2017 at 5:37:53 AM UTC-5, Chris Laprise wrote: On 06/29/2017 01:13 PM, motech man wrote: I updated the fedora 23 template with changes to the hosts /etc/file, and I noticed that all other VMs that used that template had the update

Re: [qubes-users] Rules for when "Update VM" is an active menu item

2017-07-01 Thread Chris Laprise
s template has been changed in some way. Shutting down the template and re-starting the derivative VM is how you make the update take effect in the VM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received th

Re: [qubes-users] System-wide equalizer in dom0 (alsaeq or pulseaudio-equalizer)

2017-06-30 Thread Chris Laprise
ate to see if the particular packages are available to dom0. It should also be possible to dnf download the packages in a Fedora 23 template, then transfer them to dom0 (which is also Fedora 23) for installation. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-users] Copying between VMs from dom0

2017-06-29 Thread Chris Laprise
hat works in a dom0-initiated mode. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Re: Is it possible to change sys-net's network class in case of collisions with VPN networks?

2017-06-29 Thread Chris Laprise
. But you have to consider if there are many (addressable to you) hosts on that VPN net and if their effective host addresses range beyond 16 bits; there probably aren't but if so then this solution may not work. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-users] How can I test that my AEM configuration is correct?

2017-06-29 Thread Chris Laprise
to re-sealing with the new config. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from

Re: [qubes-users] Copying between VMs from dom0

2017-06-29 Thread Chris Laprise
On 06/29/2017 09:09 AM, wordswithn...@gmail.com wrote: On Wednesday, June 28, 2017 at 4:21:36 PM UTC-4, Chris Laprise wrote: On 06/28/2017 12:19 PM, wordswithn...@gmail.com wrote: Thanks, and point taken on not focusing on security implications. I found a thread from last year where some

Re: [qubes-devel] Re: [qubes-users] Re: Request for feedback: 4.9 Kernel

2017-06-28 Thread Chris Laprise
- but not in case of VM kernel 4.9 I noticed this, too. So reverting a dispVM's template back to 4.4 should fix it? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-users] Copying between VMs from dom0

2017-06-28 Thread Chris Laprise
: qvm-run -p sys-net "tar -cf - /etc/NetworkManager/system-connections" | qvm-run -p sys-net-profiles "tar -xf -" This entails a small amount of risk to the profiles VM (because tar file is parsed there), but not to dom0. -- Chris Laprise, tas...@openmailbox.org https://twit

Re: [qubes-users] How much inital and max memory for sys and template VMs?

2017-06-28 Thread Chris Laprise
for sys-net, sys-firewall and VPN. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Qubes Community Event in Cologne, Germany on July 15th

2017-06-27 Thread Chris Laprise
ospective users' expectations carefully as you are working with the compatibility quirks of Linux multiplied-by Xen (both projects which focus on server hardware). Urging attendees to bring machines from more compatible product lines can help keep the experience a positive one. -- Chris L

Re: [qubes-users] Best Laptop For Qubes

2017-06-27 Thread Chris Laprise
f undocumented shortcuts and bugs that greatly impact non-Windows systems.) -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&quo

Re: [qubes-users] Re: Best Laptop For Qubes

2017-06-27 Thread Chris Laprise
compatibility. There is no strictly compatible system for Qubes and this makes me think the project should eventually get into the business of detailed hardware specification... what ideal Qubes hardware looks like. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-users] switch to integrated Intel graphic

2017-06-25 Thread Chris Laprise
that the PCI order/ID of your devices changed when you removed the Radeon card, causing the NIC to no longer be recognized by its old ID. If you go into Devices tab for your sys-net and remove/re-add the NIC (then restart) it may work. -- Chris Laprise, tas...@openmailbox.org https

Re: [qubes-users] Debian 9 templates

2017-06-22 Thread Chris Laprise
. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails fro

Re: [qubes-users] Re: Screen recorder for Qubes..?

2017-06-22 Thread Chris Laprise
rs (as DOM0 is only being used as an input source to another AppVM which does the heavywork encoding and streaming the data). This looks interesting... Thanks! -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You rec

<    3   4   5   6   7   8   9   10   11   12   >