Re: [rt-users] Deleting RTFM with RT 3.6.0pre1 and RTFM 2.2.0RC1

2006-05-02 Thread Alex Vandiver
On Tue, 2006-05-02 at 19:56 +0200, Dando - Email.it wrote: Tried with an already existing RTFM 2.04 upgrade to 2.2rc2 and with a clean RTFM 2.2rc2 install, same thing. I can't replicate this with RT 3.5-HEAD, and RTFM 2.2-HEAD, on mysql or Postgres. Can you replicate it on a clean install?

Re: [rt-users] RT 3.4.4 + SVN

2006-05-31 Thread Alex Vandiver
On Wed, 2006-05-31 at 14:24 -0300, Thiago Cristino dos Santos wrote: Hi, Is there some RT 3.4.4 module providing integration with subversion? How about http://search.cpan.org/dist/RT-Integration-SVN/ ? - Alex ___

[rt-users] Security vulnerability in RT 3.0 and up

2008-06-23 Thread Alex Vandiver
All versions of RT from 3.0.0 to 3.6.6 (including some, but not all RT 3.7 development releases) are vulnerable to a potential remote denial of service attack which could exhaust virtual memory or consume all available CPU resources. After a detailed analysis, we believe that an attacker would

Re: [rt-users] webmux.pl - Insecure dependency in chdir while running with -T switch

2011-01-18 Thread Alex Vandiver
On Tue, 2011-01-18 at 01:27 -0400, Kim Pedersen wrote: [error] Insecure dependency in chdir while running with -T switch at /usr/lib/perl5/5.10.1/File/Path.pm line 250.\nCompilation failed in require at (eval 2) line 1.\n We don't support running RT under taint mode. Remove the

[rt-users] [Rt-announce] Security vulnerability in RT 3.0 and up

2011-01-19 Thread Alex Vandiver
All released versions of RT from 3.0.0 through 3.8.9rc1 use an insecure hashing algorithm to store user passwords. If an attacker is able to gain read access to RT's database, it would be possible for the attacker to brute-force the hash and discover users' passwords. CVE-2011-0009 has been

[rt-users] [Rt-announce] Security vulnerabilities in RT

2011-04-14 Thread Alex Vandiver
In the process of preparing the release of RT 4.0.0, we performed an extensive security audit of RT's source code. During this audit, several vulnerabilities were found which affect earlier releases of RT. We are releasing versions 3.6.11, 3.8.10, and 4.0.0rc8 to resolve these vulnerabilities, as

Re: [rt-users] [Rt-announce] Security vulnerabilities in RT

2011-04-14 Thread Alex Vandiver
On Thu, 2011-04-14 at 10:18 -0400, Murphy, Kevin wrote: Just to clarify: after applying the patch to 3.8.9, do I have 3.8.10? The page footer and system configuration page still say 3.8.9 and don't mention the patch. No. The security patchsets are a minimal set of security patches which do

Re: [rt-users] iCAL error on screen

2011-04-15 Thread Alex Vandiver
On Fri, 2011-04-15 at 09:52 -0300, Luciano Silva wrote: I have RT 3.8.9 (applied the security patch to 3.8.10), The security patch does _not_ include all of the changes in 3.8.10; it is a minimal set of changes to address the security issues, and does not include the many other bugfixes that

Re: [rt-users] Tools/Report: 4 hours added to time repeatedly

2011-05-03 Thread Alex Vandiver
On Mon, 2011-05-02 at 14:58 -0400, Jeff Blaine wrote: Using security-patched RT 3.8.7 This is fixed in RT 3.8.8. - Alex

Re: [rt-users] Manual for Full-text search

2011-05-03 Thread Alex Vandiver
On Mon, 2011-05-02 at 13:52 +, Johan Sjöberg wrote: I am currently evaluating RT4 on our RT test-server. I noticed that improved fulltext-search is one of the things mentioned in the release notes, and I can also see some settings regarding FullTextSearch in RT_Config.pm. Is there any

Re: [rt-users] HTTP/HTTPS bug in 4.0?

2011-05-04 Thread Alex Vandiver
On Wed, 2011-05-04 at 14:27 -0500, Dario Landazuri wrote: We are running an RT instance under https only. I just noticed a small issue - when you're looking at a ticket, the links for a requestor's other tickets are non-https (http://...). On our system, that leads to a 404. Other links

Re: [rt-users] 4.0 Upgrade error

2011-05-06 Thread Alex Vandiver
On Fri, 2011-05-06 at 16:26 -0400, Voity, Michael T. wrote: Well I got a little bit farther... Now i got this error message... The solution to this, among other things, is documented in docs/UPGRADING-4.0 Please read the general upgrading instructions in README, as well as docs/UPGRADING-4.0

Re: [rt-users] RT 4.0.0, PostgresQL and Fulltext search

2011-05-20 Thread Alex Vandiver
On Fri, 2011-05-20 at 19:42 +, Patrick Fish wrote: I'm testing a new RT4 installation with Postgres to try FullText search. We've fixed these bugs and improved the documentation immeasurably on 4.0-trunk in git, which will be shortly branched for 4.0.1 release engineering. If you wanted to

Re: [rt-users] Fulltext search in RT4

2011-05-23 Thread Alex Vandiver
On Mon, 2011-05-23 at 14:45 +0100, Gary Holmes wrote: Only thing that does not seem to work any more is searching for tickets by looking for words in the body of messages. In 3.8 we used fulltext:word to search. This returns nothing in RT4. Is there anything equivalent, or have I missed

Re: [rt-users] Indexed FTS with RT 4.0.1 and pgsql 8.3.9 doesn't work

2011-05-25 Thread Alex Vandiver
propagate from rt-fulltext-indexer.in to rt-fulltext-indexer before re-running make install. - Alex From 44ed7407c3e2bcdb207468afe4e7098eeffcd3fb Mon Sep 17 00:00:00 2001 From: Alex Vandiver ale...@bestpractical.com Date: Wed, 25 May 2011 09:07:47 -0400 Subject: [PATCH] Return the Attachment object

Re: [rt-users] Indexed FTS with RT 4.0.1 and pgsql 8.3.9 doesn't work

2011-05-26 Thread Alex Vandiver
On Thu, 2011-05-26 at 08:36 +0200, Robert Wysocki wrote: [snip] Please keep all replies on the list. Thanks for the patch, rt-fulltext-indexer now works fine (assuming that not trowing an error any more means everything is fine), but searches still return no tickets whereas the same phrases

Re: [rt-users] RT second instance

2011-06-20 Thread Alex Vandiver
On Mon, 2011-06-20 at 05:36 +0300, kobo...@udvarhely.net wrote: [snip] So, it's a bug, mod_perl limitation or i'm missing something? It's a mod_perl limitation; if you want to tun more than one RT instance in an Apache instance, run them under fastcgi. - Alex 2011 Training:

[rt-users] [Rt-announce] RT 4.0.1 Released

2011-06-22 Thread Alex Vandiver
I'm happy to announce that RT 4.0.1 is now available. http://download.bestpractical.com/pub/rt/release/rt-4.0.1.tar.gz http://download.bestpractical.com/pub/rt/release/rt-4.0.1.tar.gz.sig SHA1 sums d53bef5fbf9d4ed4536e626eed0b79a502d643a9 rt-4.0.1.tar.gz

Re: [rt-users] RT4.0.1 post-upgrade rt-server.fcgi won't start

2011-06-23 Thread Alex Vandiver
On Thu, 2011-06-23 at 15:17 -0500, Adam Thompson wrote: Followed the instructions in README: did configure, make upgrade, updated schema, now rt-server.fcgi+lighttpd is broken. Lighttpd error log only says: What does the RT error log say? What does your lighttpd configuration look like? I

Re: [rt-users] RT4.0.1 post-upgrade rt-server.fcgi won't start

2011-06-23 Thread Alex Vandiver
On Thu, 2011-06-23 at 16:12 -0500, Adam Thompson wrote: What RT error log? I included everything lighttpd logged, and RT didn't log anything except what I showed, not to stderr, nor syslog, nor any file. (Hence my question about what would be useful to turn on for debugging here...)

Re: [rt-users] Problem with upgrade from 3.8.9 to 4.0.1

2011-06-26 Thread Alex Vandiver
On Sun, 2011-06-26 at 18:53 +0200, hubert depesz lubaczewski wrote: so far everything worked. I had my previous pg in /opt/rt3, but for upgrade purposes I did cp -av /opt/rt3 /opt/rt4 [snip] Questions are: 1. what did I screw? From docs/UPGRADING-4.0: You really shouldn't

Re: [rt-users] RTV4.0.0: User Access Restrictions

2011-07-07 Thread Alex Vandiver
On Thu, 2011-07-07 at 09:52 -0400, Thomas Sibley wrote: On 07/06/2011 06:44 PM, Joanne Keown wrote: Back in June I emailed the below question/request for help and I don’t believe I have seen a response to that. Does anyone have any good ideas/pointers on this? I have searched archives

Re: [rt-users] Deep Recursion Error, rt-4.0.1

2011-07-21 Thread Alex Vandiver
On Thu, 2011-07-21 at 14:05 -0700, Randy Schwager wrote: My new installation of RT (4.0.1) causes mod_perl to throw fatal errors when trying to restart apache. This points to an error in your RT configuration (not your Apache configuration, which is what you provided). Please show us your

Re: [rt-users] Unable to transfer tickets to a queue with a different lifecycle

2011-07-21 Thread Alex Vandiver
On Thu, 2011-07-21 at 19:20 -0600, Ian Roy wrote: I’ve attempted to configure the status mapping in RT_SiteConfig.pm, but I must be missing something. Could someone confirm that I’ve got the formatting proper? Also, do I need to place this in each corresponding lifecycle, or just once in the

Re: [rt-users] Unable to transfer tickets to a queue with a different lifecycle

2011-07-22 Thread Alex Vandiver
On Thu, 2011-07-21 at 20:57 -0600, Ian Roy wrote: I've made the changes that you mentioned, but I'm still getting the error. It would be handy if you could clarify the positioning of this code. Does the above need to be located in the definition of swdev or default? Neither:

Re: [rt-users] Deep Recursion Error, rt-4.0.1

2011-07-25 Thread Alex Vandiver
On Thu, 2011-07-21 at 14:05 -0700, Randy Schwager wrote: I use Apache 2.2.11 with mod_perl 2.0.4. Perl is at version 5.10.10, MySQL at 5.0.83, and I'm running Fedora 10. There is no perl 5.10.10; do you mean 5.10.1? After I drop the apache configuration file for rt4 into the conf.d

Re: [rt-users] mysql sphinx

2011-08-28 Thread Alex Vandiver
On Sun, 2011-08-28 at 13:49 +0200, Arkadiusz Miskiewicz wrote: I'm going to setup full text search with mysql 5.5, sphinxse 2.1 and sphinxd 0.9.9. [snip] This means that sphinx will never ever return new matching tickets that are above max_matches :-/ Would be acceptable if it use

Re: [rt-users] mysql sphinx

2011-08-29 Thread Alex Vandiver
On Mon, 2011-08-29 at 08:32 +0200, Arkadiusz Miskiewicz wrote: Did indexing text/html and having html_strip=1 [1] in sphinx produce any problems that caused only text/plain to be choosen for indexation in rt-setup-fulltext-index? With the caveats that you'll need additional html_strip=1

Re: [rt-users] RT 4.0.2 postgresql fulltext - error doing initial indexing

2011-09-19 Thread Alex Vandiver
On Mon, 2011-09-19 at 13:24 +1000, fab junkmail wrote: 2011-09-19 02:08:28 UTC ERROR: string is too long for tsvector (3831236 bytes, max 1048575 bytes) 2011-09-19 02:08:28 UTC STATEMENT: UPDATE Attachments SET ContentIndex = to_tsvector($1) WHERE id = $2 I think it is getting to a

Re: [rt-users] RT4 - mod_perl problem with apache2

2011-11-01 Thread Alex Vandiver
On Tue, 2011-11-01 at 09:32 -0600, Carlos Ramos wrote: As a side note, I do have a working RT4 installation in debian squeeze, but this was installed some time ago and it was the rt-4.0.0 tarball and I guess some of the CPAN modules are older too. Just here to confirm that this only

Re: [rt-users] Native FullText Search in mysql

2011-11-02 Thread Alex Vandiver
On Wed, 2011-11-02 at 11:59 -0700, Ram Moskovitz wrote: Hey folks, Looks like MySQL has FTS built in : http://dev.mysql.com/doc/refman/5.5/en/fulltext-search.html Is this supported by RT 4.0x? No. That fulltext indexing is only on MyISAM tables, which are not used in RT because they lack

[rt-users] [rt-announce] RT 3.8.11 released

2011-11-08 Thread Alex Vandiver
I'm happy to announce that RT 3.8.11 is now available. http://download.bestpractical.com/pub/rt/release/rt-3.8.11.tar.gz http://download.bestpractical.com/pub/rt/release/rt-3.8.11.tar.gz.sig SHA1 sums 96fe9babdca88224d6c8f2352f08bd62d613770d rt-3.8.11.tar.gz

[rt-users] [rt-announce] RT 4.0.3 released

2011-11-08 Thread Alex Vandiver
I'm happy to announce that RT 4.0.3 is now available. http://download.bestpractical.com/pub/rt/release/rt-4.0.3.tar.gz http://download.bestpractical.com/pub/rt/release/rt-4.0.3.tar.gz.sig SHA1 sums 3719237973df81f7e1b0a31f034b03ed1cc8f98e rt-4.0.3.tar.gz

[rt-users] [rt-announce] RT 4.0.4 released, fixes RT 3 - 4.0.3 upgrade regression

2011-11-10 Thread Alex Vandiver
RT 4.0.3 contained a serious bug wherein upgrades from any version of RT 3 to RT 4.0.3 broke template interpolation; please do not use it. If you had previously upgraded from RT 3 to RT 4.0.0, 4.0.1, or 4.0.2, before upgrading to RT 4.0.3, you are not affected by this bug. If you are currently

Re: [rt-users] Upgrade from 3.6.11 to 4.0.4 More Errors

2011-11-18 Thread Alex Vandiver
On Fri, 2011-11-18 at 11:07 -0800, Jared Griffith wrote: Can I use the same RT_SiteConfig.pm from the 3 install? Yes, though you will want to skim through the new RT_Config.pm to ensure that there are no new configuration variables that you should be setting. - Alex RT Training

Re: [rt-users] LDAP ExternalAuth broken after upgrade from 4.0.2 to 4.0.4

2011-11-23 Thread Alex Vandiver
8--- From e96831cf8f457b1601dc778cc336d43105f7a38b Mon Sep 17 00:00:00 2001 From: Alex Vandiver ale...@bestpractical.com Date: Wed, 9 Nov 2011 02:35:34 -0500 Subject: [PATCH] Restore database disconnection state after successful safe_run_child RT::Util's safe_run_child

Re: [rt-users] RT 4.0.4 - Single Value Autocomplete and Internet Explorer 8 and 9

2011-12-09 Thread Alex Vandiver
On Fri, 2011-12-09 at 15:33 -0500, Jim Lesinski wrote: I had determined that the cause of this issue is related to javascript in /opt/rt4/local/html/Elements/EditCustomFieldAutocomplete. There is an additional comma at the end of jQuery.autocomplete call and the browser is expecting another

Re: [rt-users] Full Text Search on mysql 5.6.4 off the shelf

2011-12-29 Thread Alex Vandiver
On Wed, 2011-12-28 at 13:31 -0800, Ram Moskovitz wrote: From the mysql 5.6.4 release notes: MySQL Server 5.6.4 (Milestone Release) is a new version of the world's most popular open source database. MySQL now supports FULLTEXT indexes for InnoDB tables.

Re: [rt-users] possible RT 4.0.4 attachment bug

2012-01-06 Thread Alex Vandiver
On Fri, 2012-01-06 at 16:11 -0500, mja...@guesswho.com wrote: The user had tried to submit a mysqldump that was 20GB as an attachment I'm surprised your mail server didn't fall over from that. But I didn't expect RT to increment the id when ticket creation failed. For reference, RT isn't the

Re: [rt-users] outgoing email comments stripped from Re in the subject line

2012-03-05 Thread Alex Vandiver
On Mon, 2012-03-05 at 21:34 +, Goran Marik wrote: We have some problems with tickets that contain Re in the subject line - like Remark, Request, etc. When replying from the web-interface, RT will strip the Re in the first word in the subject line for the outgoing email, so Request for help

Re: [rt-users] ExternalAuth to active directory over SSL

2012-03-23 Thread Alex Vandiver
On Fri, 2012-03-23 at 15:05 -0700, Brent Wiese wrote: I noticed in the notes that when you enable SSL/TLS, it invokes NET::SSLeay. This is why RT::Authen::ExternalAuth prompts about SSL LDAP Connections when you run `perl Makefile.PL`. Didn’t appear to be installed. I installed via cpan… and

[rt-users] [rt-announce] Security vulnerabilities in RT

2012-05-22 Thread Alex Vandiver
Internal audits of the RT codebase have uncovered a number of security vulnerabilities in RT. We are releasing versions 3.8.12 and 4.0.6 to resolve these vulnerabilities, as well as patches which apply atop all released versions of 3.8 and 4.0. The vulnerabilities addressed by 3.8.12, 4.0.6,

[rt-users] [rt-announce] RT 3.8.12 Released - Security Release

2012-05-22 Thread Alex Vandiver
This release of RT contains important bugfixes and security updates. You can download it from: http://download.bestpractical.com/pub/rt/release/rt-3.8.12.tar.gz http://download.bestpractical.com/pub/rt/release/rt-3.8.12.tar.gz.sig SHA1 sums aa657de2fd687c51f31216df6dc1f639a0bc1f7c

[rt-users] [rt-announce] RT 4.0.6 Released - Security Release

2012-05-22 Thread Alex Vandiver
RT 4.0.6 contains important security fixes, in addition to bugfixes. http://download.bestpractical.com/pub/rt/release/rt-4.0.6.tar.gz http://download.bestpractical.com/pub/rt/release/rt-4.0.6.tar.gz.sig SHA1 sums f5c0dd16da21f0af8e9c093057aa58cbab08d06b rt-4.0.6.tar.gz

Re: [rt-users] [rt-announce] Security vulnerabilities in RT

2012-05-22 Thread Alex Vandiver
On Tue, 2012-05-22 at 10:34 -0400, Alex Vandiver wrote: In addition to releasing RT versions 3.8.12 and 4.0.6 which address these issues, we have also collected patches for all releases of 3.8 and 4.0 into a distribution available for download at this link: http://download.bestpractical.com

Re: [rt-users] emails on ticket updates not being sent in 4.0.6

2012-05-23 Thread Alex Vandiver
On Wed, 2012-05-23 at 13:11 -0400, Jeff Blaine wrote: FWIW, we are seeing the same sendmail problem with 3.8.10 patched with latest patch set. We have replicated this problem when running 3.8.12, or 3.8.x + the security patches, when running under mod_perl; mod_fcgid and mod_fastcgi are

[rt-users] [rt-announce] Bugfix for security patch on mod_perl

2012-05-24 Thread Alex Vandiver
On Tue, 2012-05-22 at 10:34 -0400, Alex Vandiver wrote: Internal audits of the RT codebase have uncovered a number of security vulnerabilities in RT. We are releasing versions 3.8.12 and 4.0.6 to resolve these vulnerabilities, as well as patches which apply atop all released versions of 3.8

Re: [rt-users] Creating Search Results Bookmark w/o CSRF Warning

2012-05-24 Thread Alex Vandiver
On Thu, 2012-05-24 at 14:51 -0700, Chris Hiestand wrote: Firstly, I think that in general, you do not need to worry much about CSRF if the request method is GET. I do not know the internals of RT, but shouldn't all harmful operations be POSTs? If that were the case, I'd say you don't need to

Re: [rt-users] Another email problem with 3.8.12

2012-05-25 Thread Alex Vandiver
On Fri, 2012-05-25 at 18:31 +0300, Kim B. Heino wrote: I tried to run 3.8.12 with b7a5a53 patch on RHEL5 system. Outgoing emails work, but incoming doesn't. I see this on my maillog: Please show us your Apache and RT configuration, with passwords redacted as necessary. - Alex

Re: [rt-users] Another email problem with 3.8.12

2012-05-25 Thread Alex Vandiver
On Fri, 2012-05-25 at 18:31 +0300, Kim B. Heino wrote: I tried to run 3.8.12 with b7a5a53 patch on RHEL5 system. Outgoing emails work, but incoming doesn't. I see this on my maillog: Please try applying 38093f9: curl https://github.com/bestpractical/rt/commit/38093f9.patch | patch -p1 -d

Re: [rt-users] Another email problem with 3.8.12

2012-05-27 Thread Alex Vandiver
On Sun, 2012-05-27 at 17:08 +0300, Kim B. Heino wrote: Please try applying 38093f9: Thanks, that fixed the problem. 3.8.12 + b7a5a53 + 38093f9 is now running fine here. Excellent. I expect to roll 3.8.13rc2 shortly, then. curious to know what version of mod_perl you're running (check

[rt-users] [rt-announce] RT 3.8.13 Released

2012-05-30 Thread Alex Vandiver
I'm happy to announce that RT 3.8.13 is now available. http://download.bestpractical.com/pub/rt/release/rt-3.8.13.tar.gz http://download.bestpractical.com/pub/rt/release/rt-3.8.13.tar.gz.sig SHA1 sums adc7dab25a6454e47a9386f7d7aa8091b4ef46ca rt-3.8.13.tar.gz

Re: [rt-users] Creating Search Results Bookmark w/o CSRF Warning

2012-05-30 Thread Alex Vandiver
On Wed, 2012-05-30 at 12:14 -0700, Chris Hiestand wrote: Ah, that was my mistake. Are write GET parameters removed in RT 4? Nope. - Alex

[rt-users] [rt-announce] Security vulnerabilities in three commonly deployed RT extensions

2012-07-25 Thread Alex Vandiver
We have determined a number of security vulnerabilities in commonly installed RT extensions, enumerated below. You can determine which, if any, of these extensions your RT installation is using by navigating to Configuration - Tools - System Configuration, and examining the Plugins configuration

Re: [rt-users] RT4.0.6 Unknown encoding in received emails

2012-10-12 Thread Alex Vandiver
On Fri, 2012-10-12 at 10:52 +0200, Xavier Reigner wrote: It's better as the emails are not hanging in the mail box, but it still not the perfect solution as the content needs more time to be read. What is missing ? we8iso8859p1 appears to be an Oracle-only way of saying iso-8859-1. I suspect

Re: [rt-users] postgres 9.2.1, RT 4.0.5 - RT couldn't connect to database

2012-10-16 Thread Alex Vandiver
On Tue, 2012-10-16 at 20:55 +, Mike James wrote: Fresh install of Centos 6.3, fully patched. Added the postgresql repo and installed posgresql-9.2.1. RT 4.0.5 is config’d and looks ready to go. Just one last problem… I suspect SELinux shenanigans. Try disabling SELinux and trying again.

Re: [rt-users] spawn-fcgi and rt-server.fcgi fail

2012-10-19 Thread Alex Vandiver
On Wed, 2012-10-17 at 15:21 -0500, Alex Hanselka wrote: Ah I should have included this in the first place! I am using Scientific Linux 6.3 (RHEL repack thing) and the latest RT, 4.0.7. SELinux is disabled in this case. The owner and group of mason-data is set to my webserver user.

Re: [rt-users] spawn-fcgi and rt-server.fcgi fail

2012-10-19 Thread Alex Vandiver
--- From 0745a7c578ffb50ff17124334934fefdb0c61a2d Mon Sep 17 00:00:00 2001 From: Alex Vandiver ale...@bestpractical.com Date: Mon, 20 Jun 2011 21:58:30 -0400 Subject: [PATCH] Refactor rt-server.in into RT::PlackRunner This properly detects --port, --listen, and --socket options

Re: [rt-users] spawn-fcgi and rt-server.fcgi fail

2012-10-19 Thread Alex Vandiver
On Fri, 2012-10-19 at 14:25 -0500, Alex Hanselka wrote: You can find that at http://darkdna.net/strace.txt Was this from before or after the patch? I don't see any of the expected calls to bind or listen there, which is the problem the patch was meant to address. Can you strace the spawn-fcgi

Re: [rt-users] spawn-fcgi and rt-server.fcgi fail

2012-10-19 Thread Alex Vandiver
On Fri, 2012-10-19 at 14:59 -0500, Alex Hanselka wrote: I lied! I misapplied that patch! I feel stupid and now it is recorded for all time in the archives. In any case, the rt-server.fcgi works now by itself, but spawn-fcgi still fails to spawn a persistent process. Glad to hear that

Re: [rt-users] spawn-fcgi and rt-server.fcgi fail

2012-10-19 Thread Alex Vandiver
On Fri, 2012-10-19 at 15:13 -0500, Alex Hanselka wrote: I can! http://darkdna.net/spawn-fcgi.7021.txt and http://darkdna.net/spawn-fcgi.7022.txt. spawn-fcgi is redirecting stdout and stderr to /dev/null, which is hiding the helpful error message we're printing about /opt/rt4/var/log/rt.log not

[rt-users] [rt-announce] Security vulnerabilities in RT

2012-10-25 Thread Alex Vandiver
We have determined a number of security vulnerabilities which affect both RT 3.8.x and RT 4.0.x. We are releasing RT versions 3.8.15 and 4.0.8, and RTFM version 2.4.5, to resolve these vulnerabilities, as well as patches which apply atop all released versions of 3.8 and 4.0. The vulnerabilities

[rt-users] [rt-announce] RT 4.0.8 Released

2012-10-25 Thread Alex Vandiver
RT 4.0.8 contains important security fixes, in addition to bugfixes. http://download.bestpractical.com/pub/rt/release/rt-4.0.8.tar.gz http://download.bestpractical.com/pub/rt/release/rt-4.0.8.tar.gz.sig SHA1 sums 7be074e86929c69b4f17d10503646ff070f7fa3b rt-4.0.8.tar.gz

[rt-users] [rt-announce] RT 3.8.15 Released

2012-10-25 Thread Alex Vandiver
This release of RT contains important security updates. You can download it from: http://download.bestpractical.com/pub/rt/release/rt-3.8.15.tar.gz http://download.bestpractical.com/pub/rt/release/rt-3.8.15.tar.gz.sig SHA1 sums abb7b0d52cb9843e3154aeff2490211ddcdc59b8 rt-3.8.15.tar.gz

[rt-users] [rt-announce] RTFM 2.4.5 Released

2012-10-25 Thread Alex Vandiver
RTFM 2.4.5 contains important security fixes. http://download.bestpractical.com/pub/rt/release/rtfm-2.4.5.tar.gz http://download.bestpractical.com/pub/rt/release/rtfm-2.4.5.tar.gz.sig SHA1 sums 96c9800bf1eee94a5dd9978400a7cba8d9594b29 RTFM-2.4.5.tar.gz 1f136d9f047164d72c1cf3e0bd64839804fc49ae

Re: [rt-users] Full text index with MySQL 5.6

2012-12-12 Thread Alex Vandiver
On Wed, 2012-12-12 at 18:08 +, Daksh Chauhan wrote: I am wondering if any one has tried this with MySQL 5.6 and RT 4.x? FYI, MySQL 5.6 has still not hit general availability (GA), and is hence still a development release. I have RT 4.0.8 working on my test VM with MySQL 5.6.8, but need to

Re: [rt-users] Full text index with MySQL 5.6

2012-12-12 Thread Alex Vandiver
On Wed, 2012-12-12 at 19:31 +, LAW Andy wrote: If I migrate my 3.6.5 mySQL-based system to 4.x, the current content searches will still work at the same sort of speed that they do now, will they not? Is the full-text search in postgres-based systems an enhancement or is 4.0/mySQL/content

Re: [rt-users] Full text indexing failure (invalid byte sequence for encoding UTF8)

2013-02-01 Thread Alex Vandiver
On Fri, 2013-02-01 at 17:03 -0800, Ben Poliakoff wrote: We're currently running RT 4.0.5-3~bpo60+1 (from Debian backports) with Postgresql 8.4.12-0squeeze1. This is fixed in RT 4.0.9 and above, wich resolve this issue by skipping the attachment with bad data. RT 4.0.7 and above are better

Re: [rt-users] RT repo packages

2013-02-07 Thread Alex Vandiver
On Thu, 2013-02-07 at 15:38 -0500, Jay Ashworth wrote: As a field report, BTW: SuSE 12.1 has no packages at all, even in Packman, and CentOS5 has only rt3 (of unknown release), even with epel and remi. Fedora is making slow progress at packaging rt4, but it is in the wings:

Re: [rt-users] [SOLVED] rt-crontool broken in 4.0.10

2013-02-14 Thread Alex Vandiver
On Thu, 2013-02-14 at 20:13 +0100, Lars Bräuer wrote: I just spend about an hour wrestling with rt-crontool after an upgrade from 4.0.6 to 4.0.10. Sorry that this bug ate your time, and our apologies that it went unfound until now. I couldn't find the place where to report this bug to be

Re: [rt-users] Extra new-lines in emails from RT

2013-02-21 Thread Alex Vandiver
On Thu, 2013-02-21 at 10:15 -0600, Robert Nesius wrote: I don't see this option in my configs - would be nice if the docs showed the version these config settings first appeared in, though I suppose I could grep change logs for that too. Even so would be kind of nice. That option was first

[rt-users] [rt-announce] Security vulnerability in Perl

2013-03-05 Thread Alex Vandiver
This is a notification of a security vulnerability, not of RT, but of perl itself. That vulnerability, CVE-2013-1667, affects all production versions of perl from 5.8.2 to 5.16.x. From perl5-porters: In order to prevent an algorithmic complexity attack against its hashing mechanism,

Re: [rt-users] MessageBoxRichText and Internet Explorer 10.

2013-04-04 Thread Alex Vandiver
On Thu, 2013-04-04 at 12:01 -0700, speeder305 wrote: I also have the same problem. Compatibility mode cannot be enabled. Please test 4.0.11rc2, released yesterday. - Alex On Wed, 2013-04-03 at 09:32 -0400, Kevin Falcone wrote: RT 4.0.11rc2 is now available for testing.

Re: [rt-users] RT::Authen::ExternalAuth extension loading issue

2013-05-09 Thread Alex Vandiver
On Thu, 2013-05-09 at 11:51 +1200, Chris Foster wrote: Error while loading /opt/rt4/sbin/rt-server: Attempt to reload RT/Authen/ExternalAuth.pm aborted. \nCompilation failed in require at /opt/rt4/sbin…/lib/RT.pm line 730. Please show the complete error. There should be an error message above

Re: [rt-users] Default queue and the correspondence address.

2013-05-09 Thread Alex Vandiver
On Thu, 2013-05-09 at 10:18 -0500, Russell Jones wrote: I have noticed that when sending a new email to my CorrespondenceAddress, a new ticket is created in my General queue. I now noticed that the DefaultQueue setting is not the reasoning for this behavior according to the manual, and I am

[rt-users] [rt-announce] Security vulnerability in RT::Extension::MobileUI

2013-06-12 Thread Alex Vandiver
Two of the May 2013 security vulnerabilities also affect the MobileUI extension, which provides a mobile interface for RT versions 3.8.x. The extension was merged with core RT starting in version 4.0.0, and the respective vulnerabilies in RT 4.0.0 to 4.0.12 were fixed by the May 2013 patches and

[rt-users] [rt-announce] RT 4.0.16 released

2013-07-29 Thread Alex Vandiver
This release fixes an important regression in the Shredder tool included in 4.0.14 and 4.0.15. Attempting to run the Shredder tool from the command line would fail with a compile-time error. http://download.bestpractical.com/pub/rt/release/rt-4.0.16.tar.gz

[rt-users] [rt-announce] RT 4.0.17 released

2013-08-02 Thread Alex Vandiver
This release fixes an important regression in the upgrade script included in 4.0.14, 4.0.15, and 4.0.16. Attempting to upgrade from 3.x would skip key upgrade steps. New installs, and sites upgrading from within the 4.0.x series, are unaffected. Affected installations (i.e., who upgraded from

Re: [rt-users] Login issues

2013-08-03 Thread Alex Vandiver
On Sun, 2013-08-04 at 03:38 +0530, Arun ragini wrote: RT 4.0.16 ia acting up and it is resetting password after login. If you upgraded from RT 3.x to RT 4.0.16, please see the release notes for RT 4.0.17: http://blog.bestpractical.com/2013/08/rt-4017-released.html - Alex

[rt-users] [rt-announce] RT 4.2.0rc1 released

2013-09-05 Thread Alex Vandiver
in RT 4.2.0 is included below. Many of the new features will also be described and demoed in a series of blog posts on http://blog.bestpractical.com/ in the coming weeks. - Alex Vandiver, for Best Practical * Much improved reporting via search result charting - Multiple group

Re: [rt-users] Big problem with encoding subject

2013-09-27 Thread Alex Vandiver
On Mon, 2013-09-23 at 23:29 +0200, Albert Shih wrote: YESSSI find the problem. The problem come with the new version of p5-Encode-2.55 We've confirmed the bug; it is caused by Encode = 2.53, and will be fixed in RT 4.0.18 and 4.2.0. Until 4.0.18 is released, we suggest

Re: [rt-users] Upgrade to 4.2 fail

2013-10-02 Thread Alex Vandiver
On Wed, 2013-10-02 at 21:26 -0500, Max McGrath wrote: Trying to get from 4.0.16 to 4.2.0rc5. Make upgrade and make database-upgrade go fine, but when I restart Apache I get: root@help:/tmp/rt-4.2.0rc5# /etc/init.d/apache2 restart Syntax error on line 44 of

Re: [rt-users] Upgrade to 4.2 fail

2013-10-02 Thread Alex Vandiver
On Wed, 2013-10-02 at 21:53 -0500, Max McGrath wrote: Nope...definitely did that step: [snp] Ah. Then the perl that your mod_perl is linked against is not the perl that you configured RT with -- did you recompile a newer perl to meet the = 5.10.1 dep, but not recompile mod_perl? Deploying with

[rt-users] [rt-announce] RT 4.2.0 released

2013-10-03 Thread Alex Vandiver
professional support from the folks who built RT, drop us a line at cont...@bestpractical.com. - Alex Vandiver, for Best Practical * Much improved reporting via search result charting - Multiple group by and statistic calculations in a table - Time statistics such as average, minimum

Re: [rt-users] Invalid Group Name and Domain

2013-10-04 Thread Alex Vandiver
On Fri, 2013-10-04 at 21:02 -0400, Mathew Snyder wrote: I'm able to access the configuration interface when I run /opt/rt4/sbin/rt-server. I step through the configuration until I get to the initialize database step. When I continue from there I get an error indicating Invalid Group Name and

Re: [rt-users] Skipping Scrip because it didn't Prepare

2013-10-08 Thread Alex Vandiver
On Mon, 2013-10-07 at 22:02 +, Jesse Davidson wrote: Up until recently, this has worked fine, and any time a reply was made to a ticket, the web interface would note in the ticket history that an outgoing e-mail was recorded. Now, the web interface says nothing below the reply and no

Re: [rt-users] Updating Ticket fails in 4.2.0 using IE9

2013-10-11 Thread Alex Vandiver
the attached patch, which will be in 4.2.1. - Alex From e8277894b339bf12dce1ca1f8b6d5a8fb5eb20de Mon Sep 17 00:00:00 2001 From: Alex Vandiver ale...@bestpractical.com Date: Fri, 11 Oct 2013 15:14:46 -0400 Subject: [PATCH] Insert hidden name=value input after button, not inside of it jQuery's .append

Re: [rt-users] Unable to create ticket in RT 4.2

2013-10-14 Thread Alex Vandiver
On Mon, 2013-10-14 at 10:15 -0500, Max McGrath wrote: Hi all - Upgraded from 4.0.16 to 4.2 on a test VM. I am unable to create a ticket via the web interface...this is what I'm seeing in rt.log. [6608] [Mon Oct 14 15:11:46 2013] [error]: Can't locate object method DefaultOnCreate via

[rt-users] [rt-announce] RT 4.0.18 released

2013-10-15 Thread Alex Vandiver
We're pleased to announce that RT 4.0.18 is now available. http://download.bestpractical.com/pub/rt/release/rt-4.0.18.tar.gz http://download.bestpractical.com/pub/rt/release/rt-4.0.18.tar.gz.sig SHA1 sums c023227267b6fdfc4514b233d53e1b1bc31b51a1 rt-4.0.18.tar.gz

Re: [rt-users] Can't call method Name without a package or object reference

2013-10-22 Thread Alex Vandiver
On Tue, 2013-10-22 at 12:55 -0400, Kevin Falcone wrote: I'm replying to this question because you've asked variants on it 3 times today and I assume this is the closest to your current code. On Mon, Oct 21, 2013 at 08:53:17PM -0400, Mathew Snyder wrote: I'm trying to use RT::Queue to

Re: [rt-users] TicketHistory slow on 4.2.0

2013-10-23 Thread Alex Vandiver
On Wed, 2013-10-23 at 12:14 -0400, Tod Detre wrote: I have just upgraded an RT install to 4.2.0. We are experiencing a problem where the ticket history is very slow. Everything else seems to load just fine and the history will load in ~50-60 seconds. Also, if you go to the same ticket in a

Re: [rt-users] TicketHistory slow on 4.2.0

2013-10-23 Thread Alex Vandiver
On Wed, 2013-10-23 at 12:27 -0400, Tod Detre wrote: Mysql 5.5.23 You'll want to turn on the MySQL slow query log to find what SQL queries are taking overly long -- see http://dev.mysql.com/doc/refman/5.5/en/slow-query-log.html for instructions, but they mostly boil down to setting

Re: [rt-users] TicketHistory slow on 4.2.0

2013-10-23 Thread Alex Vandiver
On Wed, 2013-10-23 at 13:47 -0400, Tod Detre wrote: I've had the mysql slow log on, but it does not show any slow queries. That is surprising to me, as the symptoms of first load is slow, successive ones are fast sounds like the MySQL query cache to me, as I'm not aware of any other caching

Re: [rt-users] 4.2 Queue question

2013-10-23 Thread Alex Vandiver
On Tue, 2013-10-22 at 08:39 -0500, Max McGrath wrote: If you look at the attached screenshot, I have tickets in all of my queues. But on the right side, under Quick Search, it shows that all of my tickets reside in the Other queue. Not sure what is wrong or how to fix that. Any

Re: [rt-users] configure --enable-ssl-mailgate option is gone in RT 4.2 ?

2013-10-24 Thread Alex Vandiver
On Thu, 2013-10-24 at 15:59 -0400, John Apodaca wrote: Are the Perl modules required for SSL now included by default? Yes. - Alex

Re: [rt-users] Upgrading 4.0.8 - 4.2.0 breaking outgoing email

2013-10-25 Thread Alex Vandiver
On Fri, 2013-10-25 at 19:45 +, Wright, Cory (CDC/OID/NCIRD) (CTR) wrote: After an upgrade to 4.2.0 our instance of RT will not send out email. I don’t even get the “Outgoing email recorded” message in a ticket, so I assumed a problem with scrips. I’ve created new post-upgrade scrips for

Re: [rt-users] TicketHistory slow on 4.2.0

2013-10-25 Thread Alex Vandiver
On Thu, 2013-10-24 at 09:55 -0400, Tod Detre wrote: I'm learning more and more about mysql and RT trying to track down this problem. 8-) I ran mysqldumpslow to try to find queries that are showing up a lot and found the queries listed below. However, I'm not convinced it is on the sql server

Re: [rt-users] Upgrading 4.0.8 - 4.2.0 breaking outgoing email

2013-10-25 Thread Alex Vandiver
On Fri, 2013-10-25 at 20:38 +, Wright, Cory (CDC/OID/NCIRD) (CTR) wrote: Thanks for the tip Alex -- this is what I tried at first and there were no suspicious messages which made me think that somehow I have a flag turned off or something else. Please keep your replies on-list. It is

Re: [rt-users] TicketHistory slow on 4.2.0

2013-10-25 Thread Alex Vandiver
On Fri, 2013-10-25 at 16:56 -0400, Tod Detre wrote: Here are the EXPLAIN results: [snip] So it looks like the first query is using an index, but the second is not. I've confirmed that the ObjectCustomFieldValues table has the correct indexes listed in the schema.mysql. However the disabled

Re: [rt-users] Upgrading 4.0.8 - 4.2.0 breaking outgoing email

2013-10-28 Thread Alex Vandiver
On Mon, 2013-10-28 at 12:58 +, Wright, Cory (CDC/OID/NCIRD) (CTR) wrote: Thanks Alex -- what's attached is me logging in and performing one correspond in which I expect an email. Hostnames/IPs/db names have been anonymized. Your logs are chock full of SQL statement execution errors, which

  1   2   3   4   5   >