[Bug 275608] Re: nm-openvpn swaps ca and cert in openvpn commandline

2008-09-29 Thread Thierry Carrez
Can't reproduce with current intrepid (same version as you). My VPN configuration dialog shows (top to bottom): - User cert : selected client.crt - CA cert : selected ca.crt - User private key : selected client.key Then the command line is : /usr/sbin/openvpn --remote 192.168.122.41 --nobind --de

[Bug 274365] Re: Installation over Sun JVM might fail if JVM is not yet configured

2008-09-29 Thread Thierry Carrez
** Also affects: tomcat5.5 (Ubuntu) Importance: Undecided Status: New -- Installation over Sun JVM might fail if JVM is not yet configured https://bugs.launchpad.net/bugs/274365 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -

[Bug 248947] Re: asterisk init script is not LSB compliant (for heartbeat, i.e. linux-ha)

2008-09-29 Thread Thierry Carrez
status action so that it returns the LSB-compliant return codes (LP: #248947) * debian/control: added lsb-base dependency for using status_of_proc -- Thierry Carrez <[EMAIL PROTECTED]> Mon, 29 Sep 2008 14:21:59 +0200 ** Attachment added: "asterisk_1.4.21.2~dfsg-1ubuntu3.debdif

[Bug 212536] Re: [hardy] installation fails: cat: /etc/tomcat5.5/policy.d/05solr.policy: No such file or directory

2008-09-29 Thread Thierry Carrez
ndecided => Medium Assignee: (unassigned) => Thierry Carrez (tcarrez) Status: New => Confirmed -- solr-tomcat5.5 installation fails: cat: /etc/tomcat5.5/policy.d/05solr.policy: No such file or directory https://bugs.launchpad.net/bugs/212536 You received this bug notification

[Bug 212536] Re: solr-tomcat5.5 installation fails: cat: /etc/tomcat5.5/policy.d/05solr.policy: No such file or directory

2008-09-29 Thread Thierry Carrez
tomcat5.5 (5.5.26-3ubuntu2) intrepid; urgency=low * Don't fail install if Tomcat cannot be started (LP: #274365, LP: #212536) -- Thierry Carrez <[EMAIL PROTECTED]> Mon, 29 Sep 2008 15:03:01 +0200 ** Attachment added: "tomcat5.5_5.5.26-3ubuntu2.debdiff" http://l

[Bug 247082] [NEW] Apache-2.0 missing from common-licenses

2008-07-09 Thread Thierry Carrez
Public bug reported: Binary package hint: base-files Debian base-files 4.0.4 added the Apache-2.0 license to common-licenses. This triggers two problems : - the intrepid lintian reports errors for all packages that quote that license in debian/copyright (could be ignored) - in intrepid we may h

[Bug 247082] Re: Apache-2.0 missing from common-licenses

2008-07-11 Thread Thierry Carrez
Debdiff for a new release adding the missing license. Let me know if you prefer a complete merge with Debian base-files 4.0.4. ** Changed in: base-files (Ubuntu) Assignee: (unassigned) => Thierry Carrez (tcarrez) Status: New => In Progress ** Attachment added:

[Bug 247598] Re: dnsmasq might be vulnerable to recent DNS spoofing issue

2008-07-11 Thread Thierry Carrez
** Attachment added: "randsock-diff" http://launchpadlibrarian.net/15963273/randsock-diff ** Visibility changed to: Public ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-1447 -- dnsmasq might be vulnerable to recent DNS spoofing issue https://bugs.launchpad.net/bugs/2

[Bug 247598] Re: dnsmasq might be vulnerable to recent DNS spoofing issue

2008-07-11 Thread Thierry Carrez
** Bug watch added: Debian Bug tracker #490123 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490123 ** Also affects: dnsmasq (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490123 Importance: Unknown Status: Unknown -- dnsmasq might be vulnerable to recent DNS sp

[Bug 237109] [NEW] Main inclusion request for gtkglext

2008-06-03 Thread Thierry Carrez
Public bug reported: The gtkglext library is a dependency of the latest version of gtk-vnc. Please see https://wiki.ubuntu.com/MainInclusionReportGtkglext for details. ** Affects: gtkglext (Ubuntu) Importance: Undecided Status: New -- Main inclusion request for gtkglext https://bu

[Bug 129789] Re: sshd seems to be run multiple times at startup

2008-06-04 Thread Thierry Carrez
@xbx: There are two separate issues. First, the default setup is noisy : both ipv4 and ipv6 are configured on the network interface, and without a ListenAddress sshd will try to bind both, resulting in the "Address already in use" message. Second, everytime the network interface goes up (say, yo

[Bug 237580] Re: Network fails to start in VM if domain not set on ubuntu-vm-builder host

2008-06-05 Thread Thierry Carrez
** Attachment added: "uvb-empty-domain.patch" http://launchpadlibrarian.net/15055399/uvb-empty-domain.patch -- Network fails to start in VM if domain not set on ubuntu-vm-builder host https://bugs.launchpad.net/bugs/237580 You received this bug notification because you are a member of Ubuntu

[Bug 237580] [NEW] Network fails to start in VM if domain not set on ubuntu-vm-builder host

2008-06-05 Thread Thierry Carrez
Public bug reported: Binary package hint: ubuntu-vm-builder I'm using 0.4-0ubuntu0.3 and running ubuntu-vm-builder with "--ip" to set the IP address. On the resulting VM, network fails to start at boot with the following error : /etc/network/interfaces:18: option with empty value ifup: couldn't

[Bug 237616] Re: ubuntu-vm-builder VMs don't use local keymap

2008-06-05 Thread Thierry Carrez
** Attachment added: "uvb-copy-keymap.patch" http://launchpadlibrarian.net/15057811/uvb-copy-keymap.patch -- ubuntu-vm-builder VMs don't use local keymap https://bugs.launchpad.net/bugs/237616 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to U

[Bug 237616] [NEW] ubuntu-vm-builder VMs don't use local keymap

2008-06-05 Thread Thierry Carrez
Public bug reported: Binary package hint: ubuntu-vm-builder Version: 0.4-0ubuntu0.3 ubuntu-vm-builder doesn't have a --keymap option, it tries to carry out the host keymap settings so that the VM is configured with the same. However, the settings are only partially copied, and the VM boots with

[Bug 250444] [NEW] Multiple regressions in dnsmasq 2.43, merge to 2.45 needed

2008-07-21 Thread Thierry Carrez
Also reject out-of-range port spec, which could break things too: suggestion from Gilles Espinasse. ** Affects: dnsmasq (Ubuntu) Importance: Medium Assignee: Thierry Carrez (tcarrez) Status: In Progress ** Changed in: dnsmasq (Ubuntu) Assignee: (unassigned) =>

[Bug 250444] Re: Multiple regressions in dnsmasq 2.43, merge to 2.45 needed

2008-07-21 Thread Thierry Carrez
Debdiff for the merge from Debian 2.45-1 ** Attachment added: "dnsmasq_2.45-1ubuntu1.debdiff" http://launchpadlibrarian.net/16209289/dnsmasq_2.45-1ubuntu1.debdiff ** Changed in: dnsmasq (Ubuntu) Importance: Medium => High Status: In Progress => Confirmed -- Multiple regressions in

[Bug 245893] Re: openvpn update-resolv-conf script does not support multiple domain

2008-07-21 Thread Thierry Carrez
Thank you for this report and patch. However I'm not convinced this patch should be included into Ubuntu. According to RFC1533 (section 3.17), the DHCP "DOMAIN" option is supposed to only contain one domain name (as is the "domain" line in /etc/resolv.conf, if you look at man resolv.conf). Though

[Bug 242219] Re: wrong filename in easy-rsa Makefile

2008-07-21 Thread Thierry Carrez
Thank you for your bug report. Though easy-rsa is not really installed and more provided as part of the openvpn docs, this should probably be fixed. One better way to do it would be to provide an easy-rsa package that would be installed properly and separately from the rest of openvpn... ** Change

[Bug 241461] Re: OpenVPN deletes its own user group in Hardy.

2008-07-21 Thread Thierry Carrez
Thank you for your bug report. I might be missing some information, but as far as I can tell the OpenVPN package (in Gutsy or hardy) does not create an "openvpn" user account or group, so I cannot reproduce the behavior you describe. Could you please explain what exactly happened : name of the use

[Bug 231199] Re: revoke-full fails

2008-07-21 Thread Thierry Carrez
We are not using PKCS#11, and the "pkcs11 = pkcs11_section" line in openssl.cnf is properly commented out. The problem is that openssl doesn't just ignore the [ pkcs11_section ]: it still parses its configuration lines and MODULE_PATH = $ENV::PKCS11_MODULE_PATH results in an undefined variable : -

[Bug 226185] Re: update-resolv-conf script does not restore old values

2008-07-21 Thread Thierry Carrez
Thanks for your bug report. update-resolv-conf uses /sbin/resolvconf (if installed) -a and -d options to handle the update of the /etc/resolv.conf file. If you have resolvconf installed, the /etc/resolv.conf file should no longer be edited by hand, otherwise your changes will be lost at next updat

[Bug 194487] Re: network-manager[-openvpn] doesn't handle properly routes pushed by OpenVPN 2.1_Rc7

2008-07-21 Thread Thierry Carrez
** Summary changed: - OpenVPN 2.1_Rc7: Does not route properly in Ubuntu 8.04 + network-manager[-openvpn] doesn't handle properly routes pushed by OpenVPN 2.1_Rc7 ** Description changed: Openvpn 2.1_rc7 was included in the Ubuntu 8.04 hardy 2008-02-22 and after that upgrade openvpn does n

[Bug 206569] Re: hardy's OpenVPN 2.1_Rc7 not connecting

2008-07-21 Thread Thierry Carrez
shaggy: the error you get looks like you don't reach the OpenVPN server at all. Could you retry without the "local 127.0.0.1" line in your config ? Providing a "local" will force openvpn to bind only from that address, possibly preventing your connection to succeed. Without "local", OpenVPN can bin

[Bug 106819] Re: openvpn blocks normal network connection

2008-07-21 Thread Thierry Carrez
Could you please post your openvpn config files (client-side and server- side), the log files extracts corresponding to a VPN connection (client- side and server-side), and possibly the result of the "ip route show" command on the client and on the server, just before the VPN is established and jus

[Bug 46400] Re: generating keys does not work

2008-07-21 Thread Thierry Carrez
Please report if running the "vars" script prior to calling build-ca makes it work for you. It is part of normal easy-rsa usage. ** Changed in: openvpn (Ubuntu) Importance: Medium => Undecided Status: New => Incomplete -- generating keys does not work https://bugs.launchpad.net/bugs/46

[Bug 41794] Re: VPN tunnel is closed before network drives are unmounted when shutting down

2008-07-21 Thread Thierry Carrez
I would say it all depends on what your configuration looks like. In one case you may have some openvpn bits lying on a NFS or CIFS mount, so you prefer to unmount those at the very last time. In another case you established an NFS or CIFS mount over your OpenVPN tunnel, and you prefer to shutdown

[Bug 226185] Re: update-resolv-conf script does not restore old values

2008-07-22 Thread Thierry Carrez
Reopening for more discussion. What are you using as DHCP client ? Also are you using Network-Manager ? Are you using Network-Manager-OpenVPN ? I'm still convinced openvpn calls resolvconf properly, however if the other elements of the system (DHCP client / Network Manager...) modify /etc/resol

[Bug 241461] Re: OpenVPN deletes its own user group in Hardy.

2008-07-23 Thread Thierry Carrez
I entirely agree. However the "is" and "should be" situations aren't the same: 1/ openvpn runs as root when installed, and if you change it later to run as "openvpn", whenever you upgrade you're back to root. openvpn should be running as the user 'openvpn' for security reasons. 2/ openvpn is conf

[Bug 81546] Re: OpenVPN learn-address script does not get the usual environment

2008-07-23 Thread Thierry Carrez
Tested with current version in hardy, this issue has been fixed upstream. Both client-connect and learn-address return the same environment. ** Changed in: openvpn (Ubuntu) Status: New => Invalid -- OpenVPN learn-address script does not get the usual environment https://bugs.launchpad.net

[Bug 110166] Re: openvpn doesn't reconnect after suspend/resume

2008-07-23 Thread Thierry Carrez
I just tested on hardy and it seems to work correctly in my configuration... Could you test and confirm if the bug is still present ? It doesn't restore VPNs on resume with network-manager-openvpn but this might be called a feature... ** Changed in: openvpn (Ubuntu) Status: Confirmed => In

[Bug 45389] Re: routes are not restored if "user" and "group" configuration options are used

2008-07-23 Thread Thierry Carrez
This seems to work with 2.1~rc7 in hardy : Using on the client side conf: user nobody group nogroup And on the server side conf: push "route x.x.x.x 255.255.255.0" The routes get added and removed correctly. Could you please confirm if you can still see this bug in hardy ? ** Changed in: openvp

[Bug 110166] Re: openvpn doesn't reconnect after suspend/resume

2008-07-24 Thread Thierry Carrez
OK, so this fix must be part of the numerous ACPI fixes in Gutsy/hardy, I'm closing this bug. Thanks for posting it and sorry that nobody found the time to answer to you before. ** Changed in: openvpn (Ubuntu) Status: Incomplete => Invalid -- openvpn doesn't reconnect after suspend/resu

[Bug 241461] Re: OpenVPN deletes its own user group in Hardy.

2008-07-25 Thread Thierry Carrez
>> 2/ openvpn is configured to run as openvpn user out-of-the-box >> in Gutsy, and when you upgrade to hardy it runs as root. > > Case number 2. Like I said, my testing on a fresh gutsy install has failed to reproduce that : $ sudo apt-get install openvpn [...] $ grep openvpn /etc/passwd | wc -l

[Bug 275608] Re: nm-openvpn swaps ca and cert in openvpn commandline

2008-09-30 Thread Thierry Carrez
OK I think I got it. When using authentication type "Password with Certificate (TLS)", the two labels "CA certificate" and "User certificate" are swapped. If you click on the corresponding file selector, the file selector dialog window name correctly shows "Choose a Certificate Authority certifica

[Bug 268928] Re: File Choosers in configuration GUI mislabeled

2008-09-30 Thread Thierry Carrez
*** This bug is a duplicate of bug 275608 *** https://bugs.launchpad.net/bugs/275608 ** This bug has been marked a duplicate of bug 275608 nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode -- File Choosers in configuration GUI mislabeled htt

[Bug 276145] Re: Apace2 default configuration incorrect for allowoverride

2008-09-30 Thread Thierry Carrez
Values at install-time with current Intrepid/apache2 are: Options FollowSymLinks AllowOverride None Options Indexes FollowSymLinks MultiViews AllowOverride None Order allow,deny

[Bug 192594] Re: unplug - plug again network cable

2008-10-01 Thread Thierry Carrez
As suggested on the upstream bug, likewise-open does come back from unplugged-mode, after "winbind cache time" seconds (default is 900). Setting this to a lower value will make it reconnect faster, though it might not be needed, as using cache credentials is perfectly valid if its not permanent. K

[Bug 262454] Re: spurious build-depends on binutils-dev, patchutils?

2008-10-01 Thread Thierry Carrez
ansidecl.h issue forwarded to upstream bug tracker. -- spurious build-depends on binutils-dev, patchutils? https://bugs.launchpad.net/bugs/262454 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@li

[Bug 274350] Re: cups-pdf cannot create ~/PDF and files in it

2008-10-01 Thread Thierry Carrez
It's not easy to fix this in a clean way... as (un)editing /etc contents on domain join/leave is not really clean. The best way would be to make apparmor aware of domain existence so that it adapts @{HOMEDIRS} accordingly. ** Changed in: likewise-open (Ubuntu) Importance: Undecided => Medium

[Bug 231007] Re: check_radius command uses wrong syntax

2008-10-01 Thread Thierry Carrez
** Changed in: nagios-plugins (Ubuntu) Importance: Undecided => Low Status: New => Confirmed -- check_radius command uses wrong syntax https://bugs.launchpad.net/bugs/231007 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- u

[Bug 241952] Re: check_disk_smb doesn't deal with special characters in the password fields correctly

2008-10-01 Thread Thierry Carrez
** Changed in: nagios-plugins (Ubuntu) Importance: Undecided => Medium Status: New => Confirmed -- check_disk_smb doesn't deal with special characters in the password fields correctly https://bugs.launchpad.net/bugs/241952 You received this bug notification because you are a member of

[Bug 275608] Re: nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode

2008-10-02 Thread Thierry Carrez
Slightly-modified patch from the one Christoph Höger posted at: http://mail.gnome.org/archives/networkmanager-list/2008-September/msg00287.html Patch will need some refresh before being able to apply to pending release. ** Attachment added: "order.patch" http://launchpadlibrarian.net/18134120/o

[Bug 211246] Re: spurious debconf prompts on dapper upgrades

2008-10-02 Thread Thierry Carrez
dapper ships 1.4.2-5ubuntu3 which is a pre-ucf version of nagios-plugins. Migrating to anything >= 1.4.4-1 will generate those spurious prompts. However once migrated they should not show up anymore in future upgrades. We could fix it in a hardy SRU so that remaining dapper->hardy upgrades are un

[Bug 277120] Re: openssh-server init script contains irrelevant --pidfile argument to start-stop-daemon

2008-10-02 Thread Thierry Carrez
My understanding is that start-stop-daemon "--pidfile" option is used to match an existing process (and not start anything is it already exists), not to create a pidfile. So it should be present AND match whatever is in PidFile ? -- openssh-server init script contains irrelevant --pidfile argume

[Bug 262454] Re: spurious build-depends on binutils-dev, patchutils?

2008-10-03 Thread Thierry Carrez
Patch included upstream http://sourceforge.net/tracker/?func=detail&atid=712784&aid=2140320&group_id=128809 -- spurious build-depends on binutils-dev, patchutils? https://bugs.launchpad.net/bugs/262454 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 263782] Re: intrepid hang with screen corruption during boot with 2.6.27-2-generic on x61

2008-10-07 Thread Thierry Carrez
It occurred again for me this morning after upgrading to 2.6.27-5. I don't think it ever occurred while I was using the the 2.6.27-4 series, but since it's so random it's difficult to draw conclusions. -- intrepid hang with screen corruption during boot with 2.6.27-2-generic on x61 https://bugs.

[Bug 275608] Re: nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode

2008-10-08 Thread Thierry Carrez
James: You will have to validate the "Certificate (TLS)" configuration, then when back to the list of VPNs you select and edit it, then switch to "Password with certificate(TLS)". Without any file selected, you can still easily see that the label and the file selector are mismatched in the "Pass

[Bug 260687] Re: Purging samba breaks login (pam_smbpass.so segfaults)

2008-10-08 Thread Thierry Carrez
surfed: Most people on this bug and duplicates explained that they encountered the problem after removing Samba. That's the case I've been trying to solve. Yours might be slightly different. Could you give us more information about your case, for example : - can you reproduce it starting from a

[Bug 280160] [NEW] n-m-openvpn shuts down VPN when openvpn soft-restarts

2008-10-08 Thread Thierry Carrez
Public bug reported: Binary package hint: network-manager-openvpn Using openvpn rc9-3ubuntu2 and network-manager-openvpn 0.7~~svn20080928t225540-0ubuntu1. When openvpn sends itself a SIGUSR1, network-manager-openvpn calls nm- openvpn-service-openvpn-helper with the "restart" parameter but that f

[Bug 279655] Re: [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-08 Thread Thierry Carrez
Testing with n-m-openvpn doesn't show a regression. That said it doesn't work very well with rc9-3 (in particular it doesn't like openvpn soft- restarts very much), will follow up with corresponding n-m-openvpn bugs. -- [FFe] Merge openvpn 2.1_rc11-1 from Debian https://bugs.launchpad.net/bugs/27

[Bug 280123] Re: dhcp3-server needs initscript adjustment for network manager managed mode

2008-10-08 Thread Thierry Carrez
dhcp3-server already starts after NetworkManager, so I'll adjust the title. ** Summary changed: - dhcp3-server needs initscript adjustment for network manager managed mode + dhcp3-server needs if-up.d/if-down.d scripts for better network-manager compatibility -- dhcp3-server needs if-up.d/if-d

[Bug 275608] Re: nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode

2008-10-09 Thread Thierry Carrez
Bug 280265 is not really a duplicate, but since that touches the same panel it should probably be fixed at the same time. Will update title to reflect that. The "Passwords with Certificates (TLS)" config panel not only inverts the labels/fileselectors, it also inverts the password fields when it s

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-09 Thread Thierry Carrez
My patch just fixes the first issue, feel free to unsubscribe u-u-s to avoid noise while I work on the second issue. ** Changed in: network-manager-openvpn (Ubuntu) Assignee: (unassigned) => Thierry Carrez (tcarrez) ** Changed in: network-manager-openvpn (Ubuntu) Status: Confir

[Bug 278784] Re: openvpn configuration with token (pkcs11 provider) blocks the boot

2008-10-09 Thread Thierry Carrez
A few clarifications : in hardy openvpn also autostarts all /etc/openvpn/*.conf VPNs at boot (if /etc/default/openvpn has AUTOSTART=all, which is the default) so there is no change in that area. However, one difference between the hardy and the intrepid version is that we merged the fix for the f

[Bug 280428] Re: Prompted for VPN (openvpn) user info at boot-up

2008-10-09 Thread Thierry Carrez
Though the right solution is to do some /etc/default/openvpn configuration (see related answer), it might be a good idea to preserve hardy's behavior in that case. This difference in behavior was introduced when we merged the fix for the following Debian bug : http://bugs.debian.org/cgi-bin/bugre

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-09 Thread Thierry Carrez
network-manager-openvpn_0.7%7E%7Esvn20080928t225540-0ubuntu2.debdiff ** Changed in: network-manager-openvpn (Ubuntu) Assignee: Thierry Carrez (tcarrez) => (unassigned) Status: In Progress => Confirmed -- nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inv

[Bug 280160] Re: n-m-openvpn shuts down VPN when openvpn soft-restarts

2008-10-09 Thread Thierry Carrez
Analysis: network-manager-openvpn calls openvpn with the "--up /usr/lib/network- manager-openvpn/nm-openvpn-service-openvpn-helper" and "--up-restart" parameters. This means that nm-openvpn-service-openvpn-helper will be called when the VPN is initiated ("init" parameter) and restarted ("restart"

[Bug 280160] Re: n-m-openvpn shuts down VPN when openvpn soft-restarts

2008-10-09 Thread Thierry Carrez
Hm. Except that apparently it needs that information : nm-openvpn[5945]: [server] Inactivity timeout (--ping-restart), restarting nm-openvpn[5945]: SIGUSR1[soft,ping-restart] received, process restarting [...] nm-openvpn[5945]: /usr/lib/network-manager-openvpn/nm-openvpn-service-openvpn-helper tu

[Bug 254178] Re: package tomcat5.5-webapps 5.5.25-5ubuntu1 failed to install/upgrade: probl?mes de d?pendances - laiss? non configur?

2008-10-09 Thread Thierry Carrez
In that case, that would be bug 179447, which is waiting for a SRU approval for hardy. -- package tomcat5.5-webapps 5.5.25-5ubuntu1 failed to install/upgrade: probl?mes de d?pendances - laiss? non configur? https://bugs.launchpad.net/bugs/254178 You received this bug notification because you are

[Bug 280711] Re: network-manager-openvpn-gnome fails to quote passwords

2008-10-10 Thread Thierry Carrez
Thanks for reporting this bug and helping to make Ubuntu better ! Looking at the code, this has apparently been fixed in the network-manager in intrepid. Any chance that you could confirm that the current development release is fixed ? ** Changed in: network-manager-openvpn (Ubuntu) Statu

[Bug 270630] Re: Script '/etc/NetworkManager/dispatcher.d/01ifupdown' exited with error status 1

2008-10-10 Thread Thierry Carrez
*** This bug is a duplicate of bug 280160 *** https://bugs.launchpad.net/bugs/280160 This is a duplicate of 280160 : network-manager-openvpn shouldn't drop the connection when openvpn self-restarts. You should also see less "decryption errors" soft-restarts with the latest openvpn update. **

[Bug 271070] Re: "Aperture beyond 4GB. Ignoring." message when booting

2008-10-10 Thread Thierry Carrez
I used to have that message (amd64, 2Gb of RAM). Today I'm having a slight variation : [0.004000] Checking aperture... [0.004000] No AGP bridge found [0.004000] Node 0: aperture @ 2800 size 32 MB [0.004000] Aperture pointing to e820 RAM. Ignoring. I don't know what changed, in

[Bug 260687] Re: Purging samba breaks login (pam_smbpass.so segfaults)

2008-10-10 Thread Thierry Carrez
Debdiff for proposed fix samba (2:3.2.3-1ubuntu3) intrepid; urgency=low * Fix pam-smbpass.so crashing because it misses /var/lib/samba (LP: #260687) - debian/samba-common.dirs: create /var/lib/samba in samba-common - debian/samba.postrm: don't completely remove /var/lib/samba on purge

[Bug 278089] Re: StartupNotify should be false in gnome-power-manager desktop file

2008-10-10 Thread Thierry Carrez
I agree it doesn't look very good when you log in. Apparently StartupNotify=true has been there for some time (since 2.14.3-3), and is set explicitely so that a busy cursor is displayed... What seems new in recent upgrades is that the "Starting Power Manager" taskbar item remains active for quite

[Bug 260687] Re: Purging samba breaks login (pam_smbpass.so segfaults)

2008-10-10 Thread Thierry Carrez
** Changed in: samba (Ubuntu) Assignee: Thierry Carrez (tcarrez) => (unassigned) Status: Triaged => Confirmed -- Purging samba breaks login (pam_smbpass.so segfaults) https://bugs.launchpad.net/bugs/260687 You received this bug notification because you are a member of Ubunt

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-10 Thread Thierry Carrez
I'm on it for network-manager-openvpn. ** Changed in: network-manager-openvpn (Ubuntu) Assignee: (unassigned) => Thierry Carrez (tcarrez) Status: Confirmed => In Progress -- nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and in

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-10 Thread Thierry Carrez
The fixes were reported on upstream SVN. That said, upstream fixed one more issue with the openvpn panel (the "certificate password" that was asked for really was a "private key password"), so it's probably better to take the full rev4127 upstream patch. http://svn.gnome.org/viewvc/NetworkManager?

[Bug 234279] Re: OpenVPN plugin in network manager status error

2008-10-10 Thread Thierry Carrez
Marking as fix released since the reporter reports it as fixed. Please reopen if you still experience this bug. ** Changed in: network-manager-openvpn (Ubuntu) Status: New => Fix Released -- OpenVPN plugin in network manager status error https://bugs.launchpad.net/bugs/234279 You received

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-10 Thread Thierry Carrez
New upstream snapshot ** Attachment added: "network-manager-openvpn_0.7~~svn20081008t224042.orig.tar.gz" http://launchpadlibrarian.net/18402327/network-manager-openvpn_0.7%7E%7Esvn20081008t224042.orig.tar.gz -- nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and invert

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-10 Thread Thierry Carrez
New diff.gz ** Attachment added: "network-manager-openvpn_0.7~~svn20081008t224042-0ubuntu1.diff.gz" http://launchpadlibrarian.net/18402412/network-manager-openvpn_0.7%7E%7Esvn20081008t224042-0ubuntu1.diff.gz -- nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and invert

[Bug 275608] Re: nm-openvpn "Passwords with Certificate (TLS)" panel has wrong labels and inverts passwords

2008-10-10 Thread Thierry Carrez
ded: "network-manager-openvpn_0.7~~svn20081008t224042-0ubuntu1.interdiff" http://launchpadlibrarian.net/18402497/network-manager-openvpn_0.7%7E%7Esvn20081008t224042-0ubuntu1.interdiff ** Changed in: network-manager-openvpn (Ubuntu) Assignee: Thierry Carrez (tcarrez) =

[Bug 278617] Re: login crashed with SIGSEGV in dump_core()

2008-10-05 Thread Thierry Carrez
*** This bug is a duplicate of bug 260687 *** https://bugs.launchpad.net/bugs/260687 ** This bug has been marked a duplicate of bug 260687 pam_smbpass.so segfaults -- login crashed with SIGSEGV in dump_core() https://bugs.launchpad.net/bugs/278617 You received this bug notification becaus

[Bug 278610] Re: login crashed with SIGSEGV in dump_core()

2008-10-05 Thread Thierry Carrez
*** This bug is a duplicate of bug 260687 *** https://bugs.launchpad.net/bugs/260687 ** This bug is no longer a duplicate of bug 278617 login crashed with SIGSEGV in dump_core() ** This bug has been marked a duplicate of bug 260687 pam_smbpass.so segfaults -- login crashed with SIGSEG

[Bug 260687] Re: pam_smbpass.so segfaults

2008-10-05 Thread Thierry Carrez
** Changed in: samba (Ubuntu) Importance: Undecided => High -- pam_smbpass.so segfaults https://bugs.launchpad.net/bugs/260687 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com h

[Bug 277447] Re: script failed: could not execute external program

2008-10-06 Thread Thierry Carrez
Thanks for reporting this bug. Could you post an extract of your configuration that shows the exact value of the "up" and "down" parameters, as well as the value of the "script-security" parameter (if any) ? ** Changed in: openvpn (Ubuntu) Status: New => Incomplete -- script failed: could

[Bug 277508] Re: tomcat cannot configure use of syslog

2008-10-06 Thread Thierry Carrez
** Changed in: tomcat5.5 (Ubuntu) Importance: Undecided => Wishlist Status: New => Confirmed -- tomcat cannot configure use of syslog https://bugs.launchpad.net/bugs/277508 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ub

[Bug 278480] Re: tomcat6's tomcat-users.xml in wrong place

2008-10-06 Thread Thierry Carrez
Paths in server.xml are declared relative to CATALINA_BASE (/var/lib/tomcat6) so UsersDatabase is located in /var/lib/tomcat6/conf /tomcat-users.xml. Since there is a symbolic link from /var/lib/tomcat6/conf to /etc/tomcat6, it points to /etc/tomcat6/tomcat- users.xml. If you configure users in thi

[Bug 278784] Re: openvpn configuration with token (pkcs11 provider) blocks the boot

2008-10-06 Thread Thierry Carrez
I agree the boot should not be blocked, an option to cancel the start of that VPN should be provided. I'll have a look to see if I find an easy fix, I may need your help to test it though, since I don't own such a token ;) About the autostart feature, note that you can configure which configurati

[Bug 275608] Re: nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode

2008-10-06 Thread Thierry Carrez
0.7~~svn20080928t225540-0ubuntu1 revamped that panel. The issue still exists, the patch needs adaptation. Reproduction: Create a new VPN. Select authentication type "Certificate (TLS)". Select : User Certificate: user.crt Certificate password: (empty) CA Certificate: ca.crt Private key: user.key S

[Bug 275608] Re: nm-openvpn swaps ca-cert and user-cert labels when using "Passwords with Certificate (TLS)" mode

2008-10-06 Thread Thierry Carrez
Proposed fix -- network-manager-openvpn (0.7~~svn20080928t225540-0ubuntu2) intrepid; urgency=low * debian/patches/07_fileselectors_order.diff: Fix ordering of certificate file selectors in the "Passwords with certificates" case (LP: #275608) -- Thierry Carrez <[EMAIL PROTECT

[Bug 274365] Re: Installation over Sun JVM might fail if JVM is not yet configured

2008-10-06 Thread Thierry Carrez
Fix for tomcat6 tomcat6 (6.0.18-0ubuntu2) intrepid; urgency=low * debian/rules: call dh_installinit with --error-handler so that install doesn't fail if Tomcat cannot be started during configure (LP: #274365) -- Thierry Carrez <[EMAIL PROTECTED]> Mon, 06 Oct 2008 13:

[Bug 277447] Re: script failed: could not execute external program

2008-10-06 Thread Thierry Carrez
This is a rc9 bug, fixed upstream in rc10. Commands with parameters don't get executed. ** Changed in: openvpn (Ubuntu) Status: Incomplete => Confirmed ** Bug watch added: Debian Bug tracker #495964 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495964 ** Also affects: openvpn (Debia

[Bug 277447] Re: script failed: could not execute external program

2008-10-06 Thread Thierry Carrez
RC10 introduces lots of new options so it might not be suitable at that point in the release. See http://openvpn.net/index.php/documentation/change-log/changelog-21.html for details. -- script failed: could not execute external program https://bugs.launchpad.net/bugs/277447 You received this b

[Bug 277447] Re: script failed: could not execute external program

2008-10-06 Thread Thierry Carrez
Upstream patch to fix just this issue. svn diff http://svn.openvpn.net/projects/openvpn/branches/BETA21/[EMAIL PROTECTED] http://svn.openvpn.net/projects/openvpn/branches/BETA21/[EMAIL PROTECTED] ** Attachment added: "commands.diff" http://launchpadlibrarian.net/18262985/commands.diff -- scr

[Bug 277447] Re: script failed: could not execute external program

2008-10-06 Thread Thierry Carrez
Well, it's been 2 years since OpenVPN 2.1_rc1 so you should probably not consider them as "release candidates", but rather as "development releases". They are at rc12 today without any sign that a "real release" is near. It's been changing rapidly in the recent months because there was some invasiv

[Bug 277492] Re: lwinet crashes when joining a windows domain with likewise

2008-10-07 Thread Thierry Carrez
There might be a case where get_sorted_dc_list can be called with null arguments, resulting in the SIGSEGV. In samba/source/libads/ldap.c (function ads_find_dc) : --- if ( !got_realm && !lp_disable_netbios() ) { c_realm = ads->server.workg

[Bug 241952] Re: check_disk_smb doesn't deal with special characters in the password fields correctly

2008-10-07 Thread Thierry Carrez
Fixed in Debian's 1.4.12-1 ** Changed in: nagios-plugins (Ubuntu) Importance: Medium => Low -- check_disk_smb doesn't deal with special characters in the password fields correctly https://bugs.launchpad.net/bugs/241952 You received this bug notification because you are a member of Ubuntu Bug

[Bug 260687] Re: pam_smbpass.so segfaults

2008-10-07 Thread Thierry Carrez
Reproduction on a minimal intrepid system: $ sudo apt-get install samba libpam-smbpass && sudo apt-get purge samba then try to login. Updating title to better reflect where the problem stands. ** Summary changed: - pam_smbpass.so segfaults + Purging samba breaks login (pam_smbpass.so segfaults)

[Bug 260687] Re: Purging samba breaks login (pam_smbpass.so segfaults)

2008-10-07 Thread Thierry Carrez
libpam-smbpass needs the /var/lib/samba directory to exist (even empty). You can also reproduce simply by installing libpam-smbpass without installing samba... easy fix: make libpam-smbpass depend on samba better fix: create /var/lib/samba in samba-common.dirs and transfer purging of that direct

[Bug 278784] Re: openvpn configuration with token (pkcs11 provider) blocks the boot

2008-10-07 Thread Thierry Carrez
According to http://svn.openvpn.net/projects/openvpn/branches/BETA21/openvpn/management /management-notes.txt the NEED-OK line is a notification that is supposed to be acked using the management interface (issue a "needok token-insertion-request ok" command to the management port)... That makes it

[Bug 277447] Re: script failed: could not execute external program

2008-10-07 Thread Thierry Carrez
Detailed Changelog from our rc9 to rc11-1 in Debian: [regressionfix] Fixed --lladdr bug introduced in 2.1-rc9 where input validation code was incorrectly expecting the lladdr parameter to be an IP address when it is actually a MAC address (HoverHell). [bugfix] Fixed a bug that can cause SSL/TLS

[Bug 279655] [NEW] [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-07 Thread Thierry Carrez
I'll prepare a merge with that version and submit it for Feature Freeze exception approval. ** Affects: openvpn (Ubuntu) Importance: Undecided Assignee: Thierry Carrez (tcarrez) Status: New ** Changed in: openvpn (Ubuntu) Assignee: (unassigned) => Thierry Carrez (tcarr

[Bug 162389] Re: ntp check is worse than useless

2008-10-07 Thread Thierry Carrez
When NTP is not running we currently get: $ /usr/lib/nagios/plugins/check_ntp -H 127.0.0.1; echo $? NTP CRITICAL: No response from NTP server 2 However, I can reproduce James' case : - install nagios-plugins and ntp - edit /etc/ntp.conf to comment out the "server" line and restart ntp "ntpq -p" sh

[Bug 279655] Re: [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-07 Thread Thierry Carrez
Diffstat between current rc9-3ubuntu2 and proposed rc11-1ubuntu1 ** Attachment added: "rc9-3ubuntu2_rc11-1ubuntu1.diffstat" http://launchpadlibrarian.net/18295796/rc9-3ubuntu2_rc11-1ubuntu1.diffstat -- [FFe] Merge openvpn 2.1_rc11-1 from Debian https://bugs.launchpad.net/bugs/279655 You recei

[Bug 279655] Re: [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-07 Thread Thierry Carrez
Detailed changelog: [regressionfix] Fixed --lladdr bug introduced in 2.1-rc9 where input validation code was incorrectly expecting the lladdr parameter to be an IP address when it is actually a MAC address (HoverHell). [bugfix] Fixed a bug that can cause SSL/TLS negotiations in UDP mode to fail i

[Bug 279655] Re: [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-07 Thread Thierry Carrez
Debdiff from Debian version to merged version Remaining diffs: * debian/openvpn.init.d: Added 'status' action to init script, show per-VPN result messages and add "--script-security 2" by default for backwards compatibility * debian/control: Added lsb-base>=3.2-14 depend to allow status_of_proc(

[Bug 279655] Re: [FFe] Merge openvpn 2.1_rc11-1 from Debian

2008-10-07 Thread Thierry Carrez
Testing: New package builds and upgrades correctly. Basic functional testing has been performed. ** Changed in: openvpn (Ubuntu) Assignee: Thierry Carrez (tcarrez) => (unassigned) -- [FFe] Merge openvpn 2.1_rc11-1 from Debian https://bugs.launchpad.net/bugs/279655 You received this

[Bug 270512] Re: openssh-client could suggest xauth rather than recommend it

2008-09-15 Thread Thierry Carrez
Note that dropping it to a "Suggests" doesn't prevent it from being installed by other packages. If you install a GUI on the server then xauth should get installed as a dependency of the X server. The goal is to mimic what was done in hardy, where recommends were not installed by default : the min

[Bug 262264] Re: Fails to join a domain: Unknown pam configuration

2008-09-16 Thread Thierry Carrez
pam-auth-update.diff makes it segfault at domain join/leave, I'm trying to disable the pam module in domainjoin more completely, stay tuned ** Changed in: likewise-open (Ubuntu Intrepid) Assignee: (unassigned) => Thierry Carrez (tcarrez) Status: Triaged => In Progress -

<    3   4   5   6   7   8   9   10   11   12   >