Re: [qubes-users] Qubes 4.0RC2 KDE - NO SDDM

2017-10-26 Thread Chris Laprise
it running before I try :) Have you tried manually installing sddm? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups &q

[qubes-users] R4rc2 debian-9 template not working at all

2017-10-25 Thread Chris Laprise
rting a second or third time. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To uns

Re: [qubes-users] Network chain (VPN)

2017-10-21 Thread Chris Laprise
hain is OK: appVM -> VPNVM -> sys-net -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from thi

Re: [qubes-users] XEN)QUBES END POINT SECYRITY

2017-10-19 Thread Chris Laprise
g on links in emails; if you copy-paste first you can review the actual domain name of the link. And email clients like Thunderbird try to detect phishing scams. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received

Re: [qubes-users] Re: HCL - Dell XPS 13 (L322X)

2017-10-18 Thread Chris Laprise
oned above). Kind regards, Simon Hi Simon, Without VT-d the computer is vulnerable to DMA attacks via vulnerable interfaces such as network and USB. A lot of Qubes users consider this protection to be important. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20

Re: [qubes-users] Read-only file system in applVM

2017-10-12 Thread Chris Laprise
On 10/12/2017 06:42 AM, Foppe de Haan wrote: On Wednesday, October 11, 2017 at 10:08:18 PM UTC+2, Chris Laprise wrote: On 10/11/2017 04:05 PM, Chris Laprise wrote: I can explain the steps. You may wish to backup your appVM before continuing. 1. Start a dispVM (I'll call it disp1). Your

Re: [qubes-users] Read-only file system in applVM

2017-10-11 Thread Chris Laprise
On 10/11/2017 04:05 PM, Chris Laprise wrote: On 10/11/2017 11:00 AM, Franz wrote: On Tue, Oct 10, 2017 at 2:18 PM, Chris Laprise <mailto:tas...@posteo.net>> wrote:     On 10/10/2017 02:31 AM, Franz wrote:     On Mon, Oct 9, 2017 at 9:36 PM, Chris Laprise     m

Re: [qubes-users] Read-only file system in applVM

2017-10-11 Thread Chris Laprise
On 10/11/2017 11:00 AM, Franz wrote: On Tue, Oct 10, 2017 at 2:18 PM, Chris Laprise <mailto:tas...@posteo.net>> wrote: On 10/10/2017 02:31 AM, Franz wrote: On Mon, Oct 9, 2017 at 9:36 PM, Chris Laprise mailto:tas...@posteo.net> <mailto:ta

Re: [qubes-users] Read-only file system in applVM

2017-10-10 Thread Chris Laprise
On 10/10/2017 02:31 AM, Franz wrote: On Mon, Oct 9, 2017 at 9:36 PM, Chris Laprise <mailto:tas...@posteo.net>> wrote: On 10/09/2017 08:48 AM, Franz wrote: Hello, Trying to save a long document I got an error. So tried to open a new document to copy

Re: [qubes-users] (Urgent) How do I uninstall qubes or install anything else over it

2017-10-09 Thread Chris Laprise
icrosoft.com/en-us/library/cc770943(v=ws.11).aspx -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

Re: [qubes-users] Read-only file system in applVM

2017-10-09 Thread Chris Laprise
there a fix other than rebooting? Best Fran It probably means there is a logical inconsistency (corruption) in that filesystem, or it filled-up. You can avoid the latter by expanding the Private storage max size in the VM's settings. -- Chris Laprise, tas...@posteo.net https://twitte

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-08 Thread Chris Laprise
On 10/08/2017 05:34 AM, Sean Hunter wrote: On Fri, Oct 06, 2017 at 11:55:04PM -0400, Chris Laprise wrote: On 10/06/2017 11:26 PM, Person wrote: Cloning VMs is quite troublesome right now, so it is hard to update Fedora and Debian in order to use NetworkManager. You can easily install the

Re: [qubes-users] kswapd0 using 100% CPU with not even a MB swap in use

2017-10-08 Thread Chris Laprise
tion in this problem when I upgraded to the latest 4.9 kernels; currently using 4.9.45-21 and the problem isn't reappearing. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you ar

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-06 Thread Chris Laprise
-template-fedora-25 -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving e

Re: [qubes-users] Mac-Spoofing Doesn’t Work

2017-10-02 Thread Chris Laprise
address changes. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emai

Re: [qubes-users] HCL — ASUS Q325UA

2017-10-02 Thread Chris Laprise
s? Qubes: R3.2 Kernel: Supports the one in unstable (4.8.12-12), and in fact requires it for proper screen resolution support Remark: What I wrote above, including all relevant links Hi Tao, Could you post the report's yml file? Thanks... -- Chris Laprise, tas...@posteo.net https://twitter.

Re: [qubes-users] HCL Dell Latitude 7480 + dock usb-c problems (dell wd15)

2017-10-02 Thread Chris Laprise
On 08/20/2017 11:31 AM, cyrinux wrote: It is a dock in thunderbolt* Hi cyrinux, If you'd like this computer to be listed on the HCL page, could you attach a yml file from the qubes-hcl-report script? -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-users] How to recover VMs copied before reinstall?

2017-09-26 Thread Chris Laprise
I've copied my appvms back to /var/lib/qubes/appvms/, but they don't show up in the VM Manager. Can anyone tell me how to get these appvms useable again? Thanks, Ron Try using `qvm-add-appvm vmname templatename`. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-users] Connect to LAN while VPN is running?

2017-09-17 Thread Chris Laprise
so that at least a few of my AppVMs can access the lan? There have been a couple discussions about this in the past. In general, the best way to handle this securely is to connect your LAN-using AppVMs to a non-VPN proxyVM (sys-firewall for example) instead of the VPN VM. -- Chris La

Re: [qubes-users] Reboot a VM that is connected as net/proxy VM

2017-09-14 Thread Chris Laprise
having to manually re-connect many connected appVMs can be daunting. I wonder if this is already a feature request? -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to

Re: [qubes-users] Additional VPN destinations via CLI config?

2017-09-14 Thread Chris Laprise
r. Next, link the chosen file to openvpn-client.ovpn. You could start this script automatically from rc.local using 'systemd-run xterm ' etc. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received thi

Re: [qubes-users] trying to setup VPN on NetVM, can't connect and no error

2017-09-12 Thread Chris Laprise
es the anti-leak features and is simpler to install: https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups

Re: [qubes-users] Re: to firejail or not to firejail

2017-08-30 Thread Chris Laprise
hing that log, are more processes, more attack surface. to add to extremely unlikely, ive only known of one ssh client exploit in the wild, and i think it was over 10 years ago. FWIW, AppArmor does work with Qubes VMs and doesn't revolve around a special launcher. [1] https://github.com/

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-22 Thread Chris Laprise
m last after a connection is made (probably from /rw/config/qubes-firewall-user-script). -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "q

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-21 Thread Chris Laprise
of configuration. Another option: Simply run the Anyconnect client in the appVM (no proxyVM for the VPN client). This may be the simplest route. -- Chris Laprise, tas...@posteo.net https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message

Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-21 Thread Chris Laprise
es-setup-dnat-to-ns to enable DNS forwarding over the VPN. Another setting to check is /proc/sys/net/ipv4/ip_forward which should contain a value of '1'. Also, the iptables 'POSTROUTING' chain should have a masquerade target: $ cat /proc/sys/net/ipv4/ip_forward $ sudo iptabl

Re: [qubes-users] Use of qubes question

2017-08-02 Thread Chris Laprise
l and put the rpm in the /rw folder of the appVM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To u

Re: [qubes-users] Not able to connect with 2 firewall-proxy/vpns at same time

2017-07-31 Thread Chris Laprise
On 07/31/2017 07:54 PM, 'Essax' via qubes-users wrote: AUTH: Received control message: AUTH_FAILED This sounds like an issue with the provider. If they ask for more detail you can set '--verb 5' for more verbosity from openvpn. -- Chris Laprise, tas...@openmailbox.or

Re: [qubes-users] Qubes OS Systemfiles are read only to root, need help

2017-07-25 Thread Chris Laprise
boot. Running 'mount' command by itself will tell you if / was mounted as read-only. If so, you can try re-mounting it with the '-o remount,rw' options. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1

Re: [qubes-users] qvm-run problem with strings containing & ?

2017-07-25 Thread Chris Laprise
eems mose usable because you don't have to be vigilant about escaping different characters... just escaping the extra quotes should do it. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this mess

Re: [qubes-users] qvm-run problem with strings containing & ?

2017-07-25 Thread Chris Laprise
d, have you tried escaping the character with a backslash like this: \& -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&

Re: [qubes-users] Re: Setup sys-vpn?

2017-07-21 Thread Chris Laprise
https://github.com/tasket/Qubes-vpn-support/ I just released it as 'beta' but operation is smooth so far. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribe

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-18 Thread Chris Laprise
On 07/18/2017 06:02 PM, Gaiko wrote: > On Tuesday, July 18, 2017 at 11:27:00 AM UTC-4, Chris Laprise wrote: >> On 07/17/2017 07:37 PM, Gaiko wrote: >>> On Sunday, July 16, 2017 at 9:41:53 PM UTC-4, Chris Laprise wrote: >>>> On 07/16/2017 09:23 PM, Gaiko Kyofusho wrot

[qubes-users] Enigmail not working with Split GPG

2017-07-18 Thread Chris Laprise
e disregarded. I'm using Debian 9 appVMs. Issue #2170 doesn't appear to be the same as this problem. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to th

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-18 Thread Chris Laprise
On 07/17/2017 07:37 PM, Gaiko wrote: On Sunday, July 16, 2017 at 9:41:53 PM UTC-4, Chris Laprise wrote: On 07/16/2017 09:23 PM, Gaiko Kyofusho wrote: Sun Jul 16 21:16:22 2017 us=614593 RESOLVE: Cannot resolve host address: vpnprovidermod'dname.com <http://dname.com/>: No address

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
On 07/16/2017 09:23 PM, Gaiko Kyofusho wrote: Sun Jul 16 21:16:22 2017 us=614593 RESOLVE: Cannot resolve host address: vpnprovidermod'dname.com <http://dname.com/>: No address associated with hostname Hmmm, looks like a malformed address to me. -- Chris Laprise, tas...@openmailbo

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
journalctl'. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emai

Re: [qubes-users] Can't access the net via my VpnVM now? (could before)

2017-07-16 Thread Chris Laprise
eally*_ be appreciated. Have you looked at the openvpn log messages? Do you see a popup saying the link is up? Can you ping IP addresses from an appVM? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received th

Re: [qubes-users] Paranoid Recovery Error

2017-07-15 Thread Chris Laprise
id mode but not for regular restore. My guess is the latter is being overly strict and that this could be a bug... -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscrib

Re: [qubes-users] VPN-ProxyVM: "Leakproof VPN" by Rudd-O vs. "more involved" method in Qubes Wiki

2017-07-12 Thread Chris Laprise
d service. New version will have a simplified installer, which I will be posting in the next day or so: https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this me

Re: [qubes-users] Attaching non-PCI block devices to VM

2017-07-11 Thread Chris Laprise
usb as a source; you can specify any VM that contains the volume. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&qu

Re: [qubes-users] Why does VPN needs its own firewall VM?

2017-07-10 Thread Chris Laprise
On 07/10/2017 03:15 PM, yreb-qusw wrote: On 07/09/2017 11:56 PM, Chris Laprise wrote: On 07/09/2017 11:48 PM, yreb-qusw wrote: at the end of the VPN CLI setup it says : == If you want to be able to use the Qubes firewall, create a new FirewallVM (as a ProxyVM) and set it to use the VPN VM as

Re: [qubes-users] Lenovo Thinkpad 335-72G - freeze during installation at networking setup

2017-07-10 Thread Chris Laprise
ly all one device masquerading as multiple devices. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubsc

Re: [qubes-users] Re: Qubes silently ditches Librem

2017-07-10 Thread Chris Laprise
ld be lauded for creating this process and standing by it; It guards against the erroneous perceptions people have about "PC hardware" being a uniform blank canvas for creating an OS. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764

Re: [qubes-users] VPN gateway using iptables and CLI scripts fails

2017-07-10 Thread Chris Laprise
On 07/10/2017 09:28 AM, Gaijin wrote: On 2017-07-10 02:40, Chris Laprise wrote: On 07/09/2017 05:35 PM, Gaijin wrote: I've been trying to setup my VPN using the instructions here: Set up a ProxyVM as a VPN gateway using iptables and CLI scripts https://www.qubes-os.org/doc/vpn/ I can ge

Re: [qubes-users] Why does VPN needs its own firewall VM?

2017-07-10 Thread Chris Laprise
/github.com/tasket/Qubes-vpn-support/blob/new-1/rw/config/vpn/qubes-vpn-ns ...then add this to the end of "qubes-firewall-user-script": /rw/config/vpn/qubes-vpn-ns fwupdate -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4

Re: [qubes-users] Lenovo Thinkpad 335-72G - freeze during installation at networking setup

2017-07-09 Thread Chris Laprise
save button is greyed out and I can only click cancel. I suggest checking the Devices tab of your netVM to make sure your network interfaces are available to that VM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] VPN gateway using iptables and CLI scripts fails

2017-07-09 Thread Chris Laprise
s a bit without negatively affecting the leak protection for connected appVMs. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qu

Re: [qubes-users] Lenovo Thinkpad 335-72G - freeze during installation at networking setup

2017-07-09 Thread Chris Laprise
etworking interfaces that you need? For example, if you have an external USB Wifi dongle, can you add the USB controller(s) to sys-net and then use the dongle? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You r

Re: [qubes-users] almost HCL?

2017-07-09 Thread Chris Laprise
not so much for qubes. i suspect a newer dom0, fedora 25 maybe, would be able to suspend as that works on bare metal. so, my plan was to wait for qubes-4 first. Its up to you if you want to run the script and submit a yml file. Negative reports can be valuable, too. -- Chris Laprise, tas

Re: [qubes-users] here is how to randomize mac address

2017-07-08 Thread Chris Laprise
my "new net VM" doesn't have Linux firmware installed. If this helps. Thank you a lot. (Posting back to qubes-users.) It sounds like you almost got it: The conf file is saved in the template, not the netVM. After you do that, shutdown both the template and the netVM,

Re: [qubes-users] BIOS check before Qubes installation

2017-07-08 Thread Chris Laprise
nities, as they regularly deal with such protection measures. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" g

Re: [qubes-users] ntp in debain-VMs

2017-07-06 Thread Chris Laprise
Thank you, Bernhard I'm getting consistent time in my Debian 9 VMs. Do you have your 'ClockVM' setting populated in your Qubes Manager Global Settings? Its normally set to sys-net. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] HCL -- Lenovo Yoga 3 Pro?

2017-07-06 Thread Chris Laprise
Mitch Hi Mitch, If you are not yet to the point of submitting an HCL report (from the qubes-hcl-report script), it would be best to repost your issues to qubes-users separately without the 'HCL' subject. This will get more attention from the other users. -- Chris Laprise, tas...

Re: [qubes-users] HCL - HP Pavilion

2017-07-06 Thread Chris Laprise
number for this laptop? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] here is how to randomize mac address

2017-07-04 Thread Chris Laprise
One way to address this is to use 'sudo tasksel' after the upgrade completes; selecting a Gnome desktop will bring in most of the usual apps. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received thi

Re: [qubes-users] here is how to randomize mac address

2017-07-03 Thread Chris Laprise
te in dom0: sudo qubes-dom0-update qubes-template-debian-8 Then upgrade: https://www.qubes-os.org/doc/template/debian/upgrade-8-to-9/ I personally prefer Debian because it has more software and its update process is more secure than Fedora. Hope that helps! -- Chris Laprise, tas...@openmailbo

Re: [qubes-users] here is how to randomize mac address

2017-07-03 Thread Chris Laprise
On 07/03/2017 01:51 PM, Chris Laprise wrote: On 07/03/2017 11:11 AM, ausafrashid...@gmail.com wrote: I did this exactly and it worked. The Mac address was changed. But can you confirm it is the right way/most Anonymous way of anonymizing mac address, because there are some different and very

Re: [qubes-users] here is how to randomize mac address

2017-07-03 Thread Chris Laprise
9 or Fedora 25 will do) 2) check Network Manager version 3) create a settings file in /etc/NetworkManager/conf.d folder. The "Configuring Qubes with macchanger" section is a separate method that often fails; it should be disregarded. -- Chris Laprise, tas...@openmailbox.org https://twitt

Re: [qubes-users] AEM / SINIT module

2017-07-03 Thread Chris Laprise
download i would be very gratefull. cheers The '3' at the beginning of '3667U' indicates its a third-generation Core processor. So the module would be 3rd_gen_i5_i7_SINIT_67.BIN. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] Best Desktop for Qubes

2017-07-03 Thread Chris Laprise
On 07/03/2017 02:09 AM, taii...@gmx.com wrote: On 07/02/2017 09:18 PM, Chris Laprise wrote: It may have an IOMMU, but does Xen 4.6 work properly with it? Someone had reported that a different AMD desktop configuration appeared on the surface to be IOMMU compatible in Qubes, but in actually it

Re: [qubes-users] Best Desktop for Qubes

2017-07-02 Thread Chris Laprise
ly with it? Someone had reported that a different AMD desktop configuration appeared on the surface to be IOMMU compatible in Qubes, but in actually it wasn't being enabled at startup. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4

Re: [qubes-users] Terrible audio quality in one VM

2017-07-01 Thread Chris Laprise
in pavucontrol. Anyone have any idea on what may be causing this? Andrew Morgan I would guess its a pulse audio setting in your home folder. Easy way out may be to simply copy your data files over to a new appVM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-users] Rules for when "Update VM" is an active menu item

2017-07-01 Thread Chris Laprise
On 07/01/2017 01:33 PM, motech man wrote: On Saturday, July 1, 2017 at 5:37:53 AM UTC-5, Chris Laprise wrote: On 06/29/2017 01:13 PM, motech man wrote: I updated the fedora 23 template with changes to the hosts /etc/file, and I noticed that all other VMs that used that template had the update

Re: [qubes-users] Rules for when "Update VM" is an active menu item

2017-07-01 Thread Chris Laprise
ws that the VM's template has been changed in some way. Shutting down the template and re-starting the derivative VM is how you make the update take effect in the VM. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] System-wide equalizer in dom0 (alsaeq or pulseaudio-equalizer)

2017-06-30 Thread Chris Laprise
dom0-update to see if the particular packages are available to dom0. It should also be possible to dnf download the packages in a Fedora 23 template, then transfer them to dom0 (which is also Fedora 23) for installation. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP:

Re: [qubes-users] Copying between VMs from dom0

2017-06-29 Thread Chris Laprise
qvm-copy code for a utility that works in a dom0-initiated mode. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" g

Re: [qubes-users] Re: Is it possible to change sys-net's network class in case of collisions with VPN networks?

2017-06-29 Thread Chris Laprise
e /16. But you have to consider if there are many (addressable to you) hosts on that VPN net and if their effective host addresses range beyond 16 bits; there probably aren't but if so then this solution may not work. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett

Re: [qubes-users] How can I test that my AEM configuration is correct?

2017-06-29 Thread Chris Laprise
your HD which leads to re-sealing with the new config. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To u

Re: [qubes-users] Copying between VMs from dom0

2017-06-29 Thread Chris Laprise
On 06/29/2017 09:09 AM, wordswithn...@gmail.com wrote: On Wednesday, June 28, 2017 at 4:21:36 PM UTC-4, Chris Laprise wrote: On 06/28/2017 12:19 PM, wordswithn...@gmail.com wrote: Thanks, and point taken on not focusing on security implications. I found a thread from last year where some

Re: [qubes-devel] Re: [qubes-users] Re: Request for feedback: 4.9 Kernel

2017-06-28 Thread Chris Laprise
f kernel VM 4.4 - but not in case of VM kernel 4.9 I noticed this, too. So reverting a dispVM's template back to 4.4 should fix it? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this mes

Re: [qubes-users] Copying between VMs from dom0

2017-06-28 Thread Chris Laprise
achines like so: qvm-run -p sys-net "tar -cf - /etc/NetworkManager/system-connections" | qvm-run -p sys-net-profiles "tar -xf -" This entails a small amount of risk to the profiles VM (because tar file is parsed there), but not to dom0. -- Chris Laprise, tas...@openmailbox.o

Re: [qubes-users] How much inital and max memory for sys and template VMs?

2017-06-28 Thread Chris Laprise
sys-net, sys-firewall and VPN. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Qubes Community Event in Cologne, Germany on July 15th

2017-06-27 Thread Chris Laprise
ospective users' expectations carefully as you are working with the compatibility quirks of Linux multiplied-by Xen (both projects which focus on server hardware). Urging attendees to bring machines from more compatible product lines can help keep the experience a positive one. -- Ch

Re: [qubes-users] Best Laptop For Qubes

2017-06-27 Thread Chris Laprise
used and full of undocumented shortcuts and bugs that greatly impact non-Windows systems.) -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "

Re: [qubes-users] Re: Best Laptop For Qubes

2017-06-27 Thread Chris Laprise
raised with Qubes, esp when discussing compatibility. There is no strictly compatible system for Qubes and this makes me think the project should eventually get into the business of detailed hardware specification... what ideal Qubes hardware looks like. -- Chris Laprise, tas...@openmailbox.org htt

Re: [qubes-users] switch to integrated Intel graphic

2017-06-25 Thread Chris Laprise
2000 ) ? I'd guess that the PCI order/ID of your devices changed when you removed the Radeon card, causing the NIC to no longer be recognized by its old ID. If you go into Devices tab for your sys-net and remove/re-add the NIC (then restart) it may work. -- Chris Laprise, tas...@openmailbox.

Re: [qubes-users] Debian 9 templates

2017-06-22 Thread Chris Laprise
ian 8. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving email

Re: [qubes-users] Re: Screen recorder for Qubes..?

2017-06-22 Thread Chris Laprise
ack vectors (as DOM0 is only being used as an input source to another AppVM which does the heavywork encoding and streaming the data). This looks interesting... Thanks! -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

Re: [qubes-users] Containing Twitter sessions

2017-06-22 Thread Chris Laprise
r approach?) I do two things: * Refrain from clicking links; copy to untrusted VM browser instead * Turn on https everywhere addon in https-only mode The latter means that even if I click on a link, the site visited will at least have some verification (or else it won't load). -- Chr

Re: [qubes-users] Vault-appvm empty after Debian-8 template dist-upgrade

2017-06-22 Thread Chris Laprise
h to use current releases you could try Debian 9 instead; I have been using it for about a year without such issues. Only catch is you currently have to follow the Qubes doc for upgrading a Debian 8 template to 9. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C

Re: [qubes-users] Request for feedback: 4.9 Kernel

2017-06-20 Thread Chris Laprise
On 05/24/2017 03:51 PM, Chris Laprise wrote: 4.9 is working OK so far. I was using 4.8 prior to this. Additional note: 4.9 seems to resolve a zombie process issue I was having with 4.8 (domU), and the 4.9.33-18 security update is working well so far. -- Chris Laprise, tas

Re: [qubes-users] Re: Possible rootkit found on my Fedora 24 template?

2017-06-20 Thread Chris Laprise
;immutable'. This has the benefit of preventing non-priv-escalation malware from persisting at startup, and prevents alias shims from stealing passwords, etc. The next version can also compare file hashes and deactivate root-level malware at startup before /rw is brought online. -- Chr

Re: [qubes-users] Re: Possible rootkit found on my Fedora 24 template?

2017-06-20 Thread Chris Laprise
nd related xenlight libs. You should be able to find sums for (same versions of) those files at fedora's site. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscr

Re: [qubes-users] Re: Xen high CPU usage, but nothing is running in the VM

2017-06-18 Thread Chris Laprise
On 06/18/2017 10:01 AM, qubenix wrote: 'Vincent Adultman' via qubes-users: This happens to me sometimes on the current Xen/Linux versions. When I look at top in the offending VM its "kswapd" that has gone berserk. -- Chris Laprise, tas...@openmailbox.org https://twitter.co

Re: [qubes-users] Re: Xen high CPU usage, but nothing is running in the VM

2017-06-17 Thread Chris Laprise
ed that the fan was blowing and that's when I noticed the problem. This happens to me sometimes on the current Xen/Linux versions. When I look at top in the offending VM its 'kswapd' that has gone berserk. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett

Re: [qubes-users] Keyboard input going into dom0 but not into vms

2017-06-17 Thread Chris Laprise
iso. My hardware might be compromised. Is there a way to confirm without a doubt? What happens when you grab a console from dom0... $ sudo xl console vmname -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You

Re: [qubes-users] Virtualization in the cloud

2017-06-17 Thread Chris Laprise
d change that: http://theinvisiblethings.blogspot.com/2013/08/thoughts-on-intels-upcoming-software.html Note, this is a desktop PC-focused list so is not the best place to ask about the dynamics of server/cloud security. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-users] Setting up privateinternetaccess on qubes 3.2

2017-06-16 Thread Chris Laprise
On 06/15/2017 11:02 PM, Chris Laprise wrote: On 06/15/2017 08:15 PM, Steven Walker wrote: Can anyone give me any feedback on how to setup privateinternetaccess on qubes. I wrote to pia, and they didn't really give me much help on how to set this up. Any help greatly appreciated. T

Re: [qubes-users] Setting up privateinternetaccess on qubes 3.2

2017-06-15 Thread Chris Laprise
-as-a-vpn-gateway-using-iptables-and-cli-scripts -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscr

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2017-06-13 Thread Chris Laprise
On 06/13/2017 04:39 PM, LEVIS Cyril wrote: So :( I updated tboot in 1.9.5, and same problem. Try to update to last 1.28 bios, same thing. So Sad Did you also specify the parameter min_ram=0x200 ? -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2017-06-12 Thread Chris Laprise
partition. To get a verified copy, its probably easier to download the current version (1.9.5) from here: https://sourceforge.net/projects/tboot/files/?source=navbar ...then do normal GPG verification, and use 'make' to compile it and replace the two files mentioned above. -- Chr

Re: [qubes-users] Suggestion on VPN Docs Qubes instructions

2017-06-10 Thread Chris Laprise
gular user in there. If that's the case you can disregard the warning. OTOH, if you wish to satisfy the warning you can set privs like this: chmod 600 /rw/config/vpn/filename.txt -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D

Re: [qubes-users] Re: Fedora updates in small sessions, and I must reboot my VMs

2017-06-10 Thread Chris Laprise
ore reasonable, and you can choose to update only from the security repository making the update frequency even sparser. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-users] Update RPC does not work in debian-8 / missing $DISPLAY when running RPC as root

2017-06-08 Thread Chris Laprise
essie-testing in /etc/apt/sources-list.d/qubes-r3.list. Sometimes updating the Qubes packages can help with issues like this. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are

Re: [qubes-users] Update RPC does not work in debian-8 / missing $DISPLAY when running RPC as root

2017-06-07 Thread Chris Laprise
), none of them is directly related to environment variables. So, maybe either some load or delay in rc.local causes the race condition to be won. Regards, Vít Šesták 'v6ak' BTW, have you tried enabling 'jessie-testing' and updating to see if that helps? -- Chris La

Re: [qubes-users] Update RPC does not work in debian-8 / missing $DISPLAY when running RPC as root

2017-06-07 Thread Chris Laprise
in Debian 8 is rather fragile. Debian 9 has been more stable and its what I've been using for 98% of my computing needs for the past year. -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this messag

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2017-06-07 Thread Chris Laprise
parameter... at this stage I don't know if the newer tboot is the factor that allows my system to boot with AEM. An additional issue which I'm still experiencing with AEM is sleep/wake not working. My other versions are Xen 4.6.5 and Linux 4.9.28-16 (from qubes*testing). -- Chris L

Re: [qubes-users] Hadrware Requirement List

2017-06-07 Thread Chris Laprise
ly OK. But if you can turn off NVIDIA in BIOS (switch to Intel HD graphics) there is a better chance Qubes will work. A Qubes Live DVD/USB distro is available for download and booting it will give you an indication of compatibility with your system. -- Chris Laprise, tas...@openmailbox.org

Re: [qubes-users] Update RPC does not work in debian-8 / missing $DISPLAY when running RPC as root

2017-06-07 Thread Chris Laprise
ition... -- Chris Laprise, tas...@openmailbox.org https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails f

<    3   4   5   6   7   8   9   10   11   12   >