Re: Seeking a Terminal Emulator on Debian for "Passthrough" Printing

2024-01-13 Thread Richard Hector
On 14/01/24 03:59, Greg Wooledge wrote: I have dealt with terminals with passthrough printers before, but it was three decades ago, and I've certainly never heard of a printer communicating *back* to the host over this channel I've also set up passthrough printers on terminals - which were

Re: find question

2024-01-13 Thread Richard Hector
On 30/12/23 01:27, Greg Wooledge wrote: On Fri, Dec 29, 2023 at 10:56:52PM +1300, Richard Hector wrote: find $dir -mtime +7 -delete "$dir" should be quoted. Got it, thanks. Will that fail to delete higher directories, because the deletion of files updated the mtime? Or does

find question

2023-12-29 Thread Richard Hector
Hi all, When using: find $dir -mtime +7 -delete Will that fail to delete higher directories, because the deletion of files updated the mtime? Or does it get all the mtimes first, and use those? And how precise are those times? If I'm running a cron job that deletes 7-day-old directories

Re: lists

2023-12-20 Thread Richard Hector
On 21/12/23 11:55, Pocket wrote: On 12/20/23 17:37, gene heskett wrote: On 12/20/23 12:05, Pocket wrote: On 12/20/23 11:51, gene heskett wrote: On 12/20/23 08:30, Pocket wrote: If I get one bounce email I am banned, I will never get to even 10% as 2% and I am gone. That may be a side

Re: sid

2023-11-29 Thread Richard Hector
On 28/11/23 04:52, Michael Thompson wrote: [lots of stuff] Quick question - are you subscribed to the list? I notice you've replied a couple of times to your own emails, but not to any of the people who've offered suggestions. It's probably a good idea to subscribe, or at least check the

[Openvpn-users] 2FA question

2023-11-19 Thread Richard Hector
Hi all, I've been experimenting with 2FA - with IPFire as the server, but I don't think that's relevant to my question. My understanding is that OpenVPN renegotiates keys every few minutes. It appears that when this happens, I also need to enter a new token. If that's true, it makes using

Re: Default DNS lookup command?

2023-11-12 Thread Richard Hector
On 31/10/23 16:27, Max Nikulin wrote: On 30/10/2023 14:03, Richard Hector wrote: On 24/10/23 06:01, Max Nikulin wrote: getent -s dns hosts zircon Ah, thanks. But I don't feel too bad about not finding that ... 'service' is not defined in that file, 'dns' doesn't occur, and searching

Re: systemd service oddness with openvpn

2023-11-12 Thread Richard Hector
On 12/11/23 04:47, Kamil Jońca wrote: Richard Hector writes: Hi all, I have a machine that runs as an openvpn server. It works fine; the VPN stays up. Are you sure? Have you client conneted and so on? Yes. I can ssh to the machines at the other end. However, after running for a while

Re: systemd service oddness with openvpn

2023-11-11 Thread Richard Hector
On 7/11/23 12:41, Richard Hector wrote: Hi all, I have a machine that runs as an openvpn server. It works fine; the VPN stays up. However, after running for a while, I get these repeatedly in syslog: I don't know if anyone's watching, but ... It appears that this happens when logrotate

Re: Request to Establish a Debian Mirror Server for Bangladeshi Users

2023-11-07 Thread Richard Hector
On 8/11/23 17:10, Md Shehab wrote: Dear Debian Community, I hope this email finds you well. I am writing to propose the establishment of a Debian mirror server in Bangladesh I am confident that a Debian mirror server in Bangladesh would be a valuable resource for the local tech community

Re: systemd service oddness with openvpn

2023-11-06 Thread Richard Hector
On 7/11/23 12:41, Richard Hector wrote: Hi all, I have a machine that runs as an openvpn server. It works fine; the VPN stays up. However, after running for a while, I get these repeatedly in syslog: I should also have mentioned - this is debian bookworm (12.2) Richard

systemd service oddness with openvpn

2023-11-06 Thread Richard Hector
Hi all, I have a machine that runs as an openvpn server. It works fine; the VPN stays up. However, after running for a while, I get these repeatedly in syslog: Nov 07 12:17:24 ovpn2 openvpn[213741]: Options error: In [CMD-LINE]:1: Error opening configuration file: opvn2.conf Nov 07

Re: Default DNS lookup command?

2023-10-30 Thread Richard Hector
On 24/10/23 06:01, Max Nikulin wrote: On 22/10/2023 18:39, Richard Hector wrote: But not strictly a DNS lookup tool: richard@zircon:~$ getent hosts zircon 127.0.1.1   zircon.lan.walnut.gen.nz zircon That's from my /etc/hosts file, and overrides DNS. I didn't see an option in the manpage

Re: Default DNS lookup command?

2023-10-22 Thread Richard Hector
On 22/10/23 04:56, Greg Wooledge wrote: On Sat, Oct 21, 2023 at 05:35:21PM +0200, Reiner Buehl wrote: is there a DNS lookup command that is installed by default on any Debian getent hosts NAME getent ahostsv4 NAME That said, you get much finer control from dedicated tools. That is a

Re: Fresh install, Bookworm, XFCE keeps recreating directories

2023-09-15 Thread Richard Hector
On 16/09/23 12:19, Curt Howland wrote: Good evening. Did a fresh install of Bookworm, installing desktop with XFCE. I'm not interested in having directories like "Public" and "Videos", but every time I delete them something recreates those directories. I can't find where these are set to be

dosfstools for EFI partition?

2023-05-14 Thread Richard Hector
Hi, Hopefully this is the right, or close enough, place ... Given that EFI is common, should dosfstools now be a standard package, so that we can fsck the partition when required? Happy to file as a bug, if I know what to file it against. Cheers, Richard

Re: how to change default nameserver?

2023-04-11 Thread Richard Hector
On 11/04/23 15:17, gene heskett wrote: On 4/10/23 18:04, zithro wrote: So, I got curious about his claim : "that change to resolv.conf adding the search line [search hosts, nameserver] has been required since red hat 5.0 in 1998". (The bracket addition is mine) I'm not using RHEl-based

Re: how to change default nameserver?

2023-04-10 Thread Richard Hector
On 11/04/23 15:17, gene heskett wrote: In a man page from a good 20 years ago. I still have a copy of that original redhat 5.0 on a shelf above me, but not a floppy drive to read those disks with. Downloading an iso ... :-) Richard

Re: questions about cron.daily

2023-04-07 Thread Richard Hector
On 7/04/23 10:54, Greg Wooledge wrote: On Thu, Apr 06, 2023 at 05:45:08PM -0500, David Wright wrote: Users (including root) write their crontabs anywhere they like, typically in a directory like ~/.cron/. Is that... normal? I can't say I've ever seen anyone keep a private copy of their

Re: [systemd-devel] creating device nodes

2023-04-05 Thread Richard Hector
-nodes --format=tmpfiles On Wed, Apr 5, 2023 at 11:13 AM Richard Hector <mailto:rich...@walnut.gen.nz>> wrote: Hi all, I want to create a device (/dev/fuse) in an LXC container. The kernel bit works; I can mknod manually, but I'd rather use a systemd unit, and make it a d

[systemd-devel] creating device nodes

2023-04-05 Thread Richard Hector
Hi all, I want to create a device (/dev/fuse) in an LXC container. The kernel bit works; I can mknod manually, but I'd rather use a systemd unit, and make it a dependency of mounting filesystems from /etc/fstab. It looks like .device units are supposed to be created automatically if there's

Re: question about rc.local

2023-03-11 Thread Richard Hector
On 10/03/23 15:16, Corey Hickman wrote: On Fri, Mar 10, 2023 at 9:44 AM > wrote: I'm much happier with a "real" email client. what real email client do you use? :) I am using Mac as the regular desktop, Mac's Mail App is hard to use. Though my server is

Re: solution to / full

2023-03-02 Thread Richard Hector
On 2/03/23 06:00, Andy Smith wrote: Hi, On Wed, Mar 01, 2023 at 02:35:17PM +0100, lina wrote: My / is almost full. # df -h Filesystem Size Used Avail Use% Mounted on udev126G 0 126G 0% /dev tmpfs26G 2.3M 26G 1% /run /dev/nvme0n1p2 23G 21G 966M

Bug#1030843: needrestart: lxc exception

2023-02-08 Thread Richard Hector
Package: needrestart Version: 3.5-4+deb11u2 Severity: wishlist Dear Maintainer, Can needrestart leave lxc.service unselected by default? It restarts all the containers, which is often not desirable ... I can deselect it if I notice, but I don't always. [automatic system info omitted - running

Re: Setting up bindfs mount in LXC container

2023-01-17 Thread Richard Hector
On 18/01/23 16:38, Max Nikulin wrote: On 18/01/2023 03:52, Richard Hector wrote: On 17/01/23 23:52, Max Nikulin wrote: lxc.idmap = u 0 10 1000 lxc.idmap = u 1000 1000 1 lxc.mount.entry = /home/richard/sitename/doc_root srv/sitename/doc_root none bind,optional,create=dir My goal

Re: Setting up bindfs mount in LXC container

2023-01-17 Thread Richard Hector
On 17/01/23 23:52, Max Nikulin wrote: On 17/01/2023 04:06, Richard Hector wrote: I'm using bindfs in my web LXC containers to allow particular users to write to their site docroot as the correct user. I am not familiar with bindfs, so I may miss something important for your use case

Setting up bindfs mount in LXC container

2023-01-16 Thread Richard Hector
Hi all, I'm using bindfs in my web LXC containers to allow particular users to write to their site docroot as the correct user. Getting this to work has been really hacky, and while it does seem to work, I get log messages saying it didn't ... In /var/lib/lxc//config:

Re: bindfs for web docroot - is this sane?

2022-10-11 Thread Richard Hector
On 12/10/22 00:26, Dan Ritter wrote: Richard Hector wrote: Hi all, I host a few websites, mostly Wordpress. I prefer to have the site files (mostly) owned by an owner user, and php-fpm runs as a different user, so that it can't write its own code. For uploads, those directories are group

Re: bindfs for web docroot - is this sane?

2022-10-11 Thread Richard Hector
On 11/10/22 22:40, hede wrote: On 11.10.2022 10:03 Richard Hector wrote: [...] Then for site developers (who might be contractors to my client) to be able to update teh site, they need read/write access to the docroot, but I don't want them all logging in using the same account/credentials

bindfs for web docroot - is this sane?

2022-10-11 Thread Richard Hector
Hi all, I host a few websites, mostly Wordpress. I prefer to have the site files (mostly) owned by an owner user, and php-fpm runs as a different user, so that it can't write its own code. For uploads, those directories are group-writeable. Then for site developers (who might be contractors

Re: nginx.conf woes

2022-10-10 Thread Richard Hector
On 3/10/22 02:07, Patrick Kirk wrote: Hi all, I have 2 sites to run from one server.  Both are based on ASP.Net Core. Both have SSL certs from letsencrypt.  One works perfectly.  The other sort of works. Firstly, I notice that cleardragon.com and kirks.net resolve to different addresses,

Re: Thoughts on logcheck?

2022-07-30 Thread Richard Hector
On 30/07/22 10:20, Andy Smith wrote: Hello, On Fri, Jul 29, 2022 at 04:30:19PM +1200, Richard Hector wrote: My thought is to configure rsyslog to create extra logfiles, equivalent to syslog and auth.log (the two files that logcheck monitors by default), which only log messages at priority

Thoughts on logcheck?

2022-07-28 Thread Richard Hector
Hi all, I've used logcheck for ages, to email me about potential problems from my log files. I end up spending a lot of time scanning the emails, and then occasionally a bunch of time updating the filter rules to stop most of those messages coming through. My thought is to configure

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-23 Thread Richard Hector
On 23/07/22 23:01, Cyril Brulebois wrote: As mentioned by Julien, getting the installer's syslog (compressed, to make sure it reaches the mailing list) would help understand what's going on. Oh - uncompressed, it made it into the BTS, but not to the list. Here's a compressed version.

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-23 Thread Richard Hector
On 23/07/22 23:01, Cyril Brulebois wrote: As mentioned by Julien, getting the installer's syslog (compressed, to make sure it reaches the mailing list) would help understand what's going on. Oh - uncompressed, it made it into the BTS, but not to the list. Here's a compressed version.

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-23 Thread Richard Hector
On 23/07/22 18:07, Geert Stappers wrote: Control: severity -1 wishlist Why? Because there's a workaround? Is everyone expected to be able to find that workaround? https is an option provided in the installer, that apparently doesn't work (at least with the netinst installer), and it's not

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-23 Thread Richard Hector
On 23/07/22 18:07, Geert Stappers wrote: Control: severity -1 wishlist Why? Because there's a workaround? Is everyone expected to be able to find that workaround? https is an option provided in the installer, that apparently doesn't work (at least with the netinst installer), and it's not

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-22 Thread Richard Hector
Package: debian-installer Severity: important Dear Maintainer, Using netinst bullseye 11.4 installer: https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/debian-11.4.0-amd64-netinst.iso I chose to add a network mirror, using https, and the default 'deb.debian.org'. I used

Bug#1015887: debian-installer: Adding https repo doesn't work without manually installing ca-certificates

2022-07-22 Thread Richard Hector
Package: debian-installer Severity: important Dear Maintainer, Using netinst bullseye 11.4 installer: https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/debian-11.4.0-amd64-netinst.iso I chose to add a network mirror, using https, and the default 'deb.debian.org'. I used

Bug#873852: reporting bug in debian-installer

2022-07-22 Thread Richard Hector
Hi, not sure if this is strictly the same bug ... I assume the link above was the old version of https://www.debian.org/releases/bullseye/amd64/release-notes/ch-moreinfo.en.html#bugs? If so, it doesn't help me decide what (pseudo-)package to report a bug against for the installer. And when

[nznog] IPv6 status?

2022-07-13 Thread Richard Hector
Hi all, We've passed the 10th anniversary of World IPv6 Launch Day, but it doesn't seem like we've got very far? What happened to the Task Force? The site says it's archived, or is there a new one? Cheers, Richard ___ NZNOG mailing list --

Re: Synaptic missing in "Bookworm"

2022-06-30 Thread Richard Hector
On 1/07/22 12:08, Peter Hillier-Brook wrote: anyone with thoughts, or info about Synaptic missing in "Bookworm"? https://tracker.debian.org/pkg/synaptic Richard

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-29 Thread Richard Hector
On 23/06/22 02:05, David Sommerseth wrote: /usr/lib/systemd/system/openvpn-server@.service ^^  This is the proper service file being packaged.  Even though, as this is from a Debian package, I would have expected it under /lib/systemd/system. Thanks to the big /usr merge, they're going to

Re: regarding firewall discussion

2022-06-03 Thread Richard Hector
On 2/06/22 05:26, Joe wrote: On Tue, 31 May 2022 03:17:52 +0100 mick crane wrote: regarding firewall discussion I'm uncertain how firewalls are supposed to work. I think the idea is that nothing is accepted unless it is in response to a request. What's to stop some spurious instructions being

Re: grep: show matching line from pattern file

2022-06-03 Thread Richard Hector
On 3/06/22 07:17, Greg Wooledge wrote: On Thu, Jun 02, 2022 at 03:12:23PM -0400, duh wrote: > > Jim Popovitch wrote on 28/05/2022 21:40: > > > I have a file of regex patterns and I use grep like so: > > > > > > ~$ grep -f patterns.txt /var/log/syslog > > > > > > What I'd like to get is

Re: Permanent email address?

2022-05-16 Thread Richard Hector
On 16/05/22 05:11, Dan Ritter wrote: I note that nobody owns rhkramer.org: $ host rhkramer.org Host rhkramer.org not found: 3(NXDOMAIN) NXDOMAIN means no such domain. Not quite. It doesn't mean no-one owns it; it just means (IIRC) there's no A or record for that domain.

Re: wtf just happened to my local staging web server

2022-05-11 Thread Richard Hector
On 5/05/22 19:57, Stephan Seitz wrote: Am Do, Mai 05, 2022 at 09:30:42 +0200 schrieb Klaus Singvogel: I think there are more. Yes, I only know wtf as ... Yes, but such language is not permitted on this list. Richard

[nznog] Re: routing problem?

2022-05-11 Thread Richard Hector
On 11/05/22 20:46, Nathan Ward wrote: On 11/05/2022, at 8:06 PM, Richard Hector wrote: Hi all, Hopefully this is acceptable here ... I have a VPS (with a well-known NZ provider) which I can ping, but can't ssh to. tcptraceroute stops a couple of hops in (I think the first to not respond

[nznog] routing problem?

2022-05-11 Thread Richard Hector
Hi all, Hopefully this is acceptable here ... I have a VPS (with a well-known NZ provider) which I can ping, but can't ssh to. tcptraceroute stops a couple of hops in (I think the first to not respond is our immediate ISP's immediate upstream). From a different house/ISP, I can connect

Re: stretch with bullseye kernel?

2022-05-04 Thread Richard Hector
On 4/05/22 18:57, Tixy wrote: On Wed, 2022-05-04 at 00:44 +0300, IL Ka wrote: Linux kernel is backward compatible. Linus calls it "we do not break userspace". That means _old_ applications should work on new kernel There's also the issue of what config options the kernel is built with. I'm

stretch with bullseye kernel?

2022-05-03 Thread Richard Hector
Hi all, For various reasons, I have some stretch LXC containers, on a buster host that I now need to upgrade. That will mean they end up running on buster's 5.10 kernel. Is that likely to be a problem? If so, I guess I can leave the host on buster's kernel for the time being, but that's

Re: doveadm pw usage

2022-04-25 Thread Richard Hector
On 24/04/22 22:45, ミユナ (alice) wrote: ok the helps says: pw   [-l] [-p plaintext] i just thought it specifies the text file. thanks for clarifying it. Bernardo Reino wrote: The argument to "-p" is not a file containing the password, but the password itself! The downside of

Re: how to setup IMAPs with letsencrypt

2022-04-25 Thread Richard Hector
On 24/04/22 13:14, ミユナ (alice) wrote: Richard Hector wrote: otherwise you'll have to use DNS challenge method to support multiple hostnames on the same certificate. Um, no I didn't. I replied to that. Please check your attributions :-) Cheers, Richard

Re: how to setup IMAPs with letsencrypt

2022-04-23 Thread Richard Hector
On 22/04/22 11:57, Joseph Tam wrote: Keep in mind the subject name (CN or SAN AltNames) of your certificate must match your IMAP server name e.g. if your certificate is made for "www.mydomain.com", you'll have to configure your IMAP clients to also use "www.mydomain.com" as the IMAP server name.

Re: [ansible-project] Reading in extra files, as or into dicts?

2022-04-16 Thread Richard Hector
On 16/04/22 22:13, Richard Hector wrote: Hi all, I have created a directory 'users' alongside my inventory. It has a directory 'user_vars', intended to be used like host_vars, but for users, obviously. In there, I have files like this: = --- name: richard gecos

[ansible-project] Reading in extra files, as or into dicts?

2022-04-16 Thread Richard Hector
Hi all, I have created a directory 'users' alongside my inventory. It has a directory 'user_vars', intended to be used like host_vars, but for users, obviously. In there, I have files like this: = --- name: richard gecos: 'Richard Hector,,,' shell: '/bin/bash' ssh_keys

Re: [ansible-project] Keeping inventory and other data separate from code

2022-04-16 Thread Richard Hector
On 2/04/22 16:07, Nico Kadel-Garcia wrote: On Fri, Apr 1, 2022 at 10:27 PM Richard Hector wrote: Hi all, Currently my inventory is stored in the same git repo as my play(book)s, roles etc, which I don't like. Consider using git submodules if you want a unified workspace. Hmm. I got

Re: [ansible-project] [OT?] What do you call a container container?

2022-04-16 Thread Richard Hector
uot;Turtles All The Way Down". "The inevitable product of people taught only recursion as a valid way to do anything" "Pay no attention to that server behind the layer of abstraction" The list could go on and on, much like what you're describing. On Fri, Apr 1, 2022 at 5:46 P

Re: Libreoffice: printing "dirties" the file being printed

2022-04-11 Thread Richard Hector
On 9/04/22 00:17, gene heskett wrote: IMO its up to the pdf interpretor to make the pdf its handed fit the printer. Period, IMO it is not open for discussion. "Make it fit" might include scaling. You don't necessarily want that happening automatically - what if you're printing something like

Re: libvirt tools and keyfiles

2022-04-02 Thread Richard Hector
On 2022-04-01, Celejar wrote: What is going on here? Since I'm specifying a keyfile on the command line, and it's being used - otherwise I wouldn't even get the list of VMs - why am I being prompted for the password? Celejar Apologies for replying to the wrong message - I've deleted the

[ansible-project] Keeping inventory and other data separate from code

2022-04-01 Thread Richard Hector
Hi all, Currently my inventory is stored in the same git repo as my play(book)s, roles etc, which I don't like. What are common ways to avoid this? Perhaps keep inventory in a subdir which is .gitignored, and make that a separate repo? I also want to keep data which is not strictly

[ansible-project] [OT?] What do you call a container container?

2022-04-01 Thread Richard Hector
Hi all, I have several leased VPS in which I run LXC containers. At the moment, the group I use for those is "lxc_hosts", but that has a few problems: - Everything in inventory is a host, so lxc_host could just as well be a container as the machine it lives on. - Separators in general are

Re: OT EU-based Cloud Service

2022-03-18 Thread Richard Hector
On 18/03/22 21:14, Byung-Hee HWANG wrote: https://hetzner.cloud German company, a single VPS cost is about 5€ per month. Oh Nuremberg! Racing Circuit, fantastic!! Um - you might be thinking of Nürburg? Home of the Nürburgring? :-) Nuremburg has other associations in my mind, but I'm sure

Re: cups/avahi-daemon - worrying logs

2022-03-17 Thread Richard Hector
On 17/03/22 19:37, mick crane wrote: On 2022-03-17 05:09, Richard Hector wrote: On 8/03/22 13:25, Richard Hector wrote: Hi all, I've recently set up a small box to run cups, to provide network access to a USB-only printer. It's a 32-bit machine running bullseye. I'm seeing log messages

Re: cups/avahi-daemon - worrying logs

2022-03-16 Thread Richard Hector
On 8/03/22 13:25, Richard Hector wrote: Hi all, I've recently set up a small box to run cups, to provide network access to a USB-only printer. It's a 32-bit machine running bullseye. I'm seeing log messages like these: Mar  7 15:47:47 whio avahi-daemon[310]: Record [Brother\032HL-2140\032

Re: voltage monitoring Q

2022-03-15 Thread Richard Hector
On 13/03/22 21:15, gene heskett wrote: they are the last seacrate drives I'll own... Ever. Lots of brands seem to go through bad patches. Even just bad batches. For stuff I care about, I use RAID1 (mdraid), on NAS drives, from mixed manufacturers. So I'll have a pair consisting of a Seagate

Re: Trying to elevate rsync privileges when connecting over ssh without using NOPASSWD in sudoers

2022-03-12 Thread Richard Hector via rsync
On 12/03/22 19:36, Bri Hatch via rsync wrote: On Fri, Mar 11, 2022 at 10:22 PM Kevin Korb via rsync mailto:rsync@lists.samba.org>> wrote: Rsync includes a script named rrsync that handles this perfectly. And authprogs provides similar functionality, though you use yaml to define what

Re: Trying to elevate rsync privileges when connecting over ssh without using NOPASSWD in sudoers

2022-03-12 Thread Richard Hector via rsync
, Richard On 12/03/22 21:01, Richard Hector via rsync wrote: It may do the job; it doesn't AFAIK explain why the options are undocumented :-) Cheers, Richard On 12/03/22 19:22, Kevin Korb via rsync wrote: Rsync includes a script named rrsync that handles this perfectly. On 3/12/22 01:08, Richard

Re: Trying to elevate rsync privileges when connecting over ssh without using NOPASSWD in sudoers

2022-03-12 Thread Richard Hector via rsync
It may do the job; it doesn't AFAIK explain why the options are undocumented :-) Cheers, Richard On 12/03/22 19:22, Kevin Korb via rsync wrote: Rsync includes a script named rrsync that handles this perfectly. On 3/12/22 01:08, Richard Hector via rsync wrote: On 12/03/22 18:38, Richard

Re: Trying to elevate rsync privileges when connecting over ssh without using NOPASSWD in sudoers

2022-03-11 Thread Richard Hector via rsync
On 12/03/22 18:38, Richard Hector via rsync wrote: And I do my backups (using dirvish) as root, using a key with a forced command. FWIW, that forced command is here: https://github.com/rwhector/dirvish-forced-command It's rather unpolished and undocumented, but comments very welcome

Re: Trying to elevate rsync privileges when connecting over ssh without using NOPASSWD in sudoers

2022-03-11 Thread Richard Hector via rsync
On 12/03/22 06:06, Dr. Mark Asbach via rsync wrote: Hi Dan, Why not rsync directly as root? Then you can use a passwordless, passphraseless RSA (or similar) keypair. I'm not saying I agree with this, but ... That’s because these are cloud instances that get maintained by multiple

Re: Launch a minimal MATE DE

2022-03-11 Thread Richard Hector
On 9/03/22 04:06, David Wright wrote: On Tue 08 Mar 2022 at 07:00:08 (+0100), to...@tuxteam.de wrote: On Tue, Mar 08, 2022 at 01:54:11PM +1300, Richard Hector wrote: [...] > Just to solve the infinite recursion problem: > > richard@zircon:~$ apt-file search bin/apt-file > apt-fi

Re: Launch a minimal MATE DE

2022-03-07 Thread Richard Hector
On 6/03/22 22:20, to...@tuxteam.de wrote: On Sun, Mar 06, 2022 at 09:34:36AM +0100, Christian Britz wrote: On 2022-03-06 09:30 UTC+0100, Richard Owlett wrote: >> apt-get --no-install-recommends install mate-desktop-environment > When I attempted to run startx I received the message >>

cups/avahi-daemon - worrying logs

2022-03-07 Thread Richard Hector
Hi all, I've recently set up a small box to run cups, to provide network access to a USB-only printer. It's a 32-bit machine running bullseye. I'm seeing log messages like these: Mar 7 15:47:47 whio avahi-daemon[310]: Record

Re: [Fail2ban-users] multiline match?

2022-03-07 Thread Richard Hector
On 8/03/22 00:11, Dominic Raferd wrote: On 07/03/2022 10:37, Richard Hector wrote: On 7/03/22 23:15, Richard Hector wrote: On 6/03/22 20:54, Dominic Raferd wrote: On 06/03/2022 04:35, Richard Hector wrote: I have lines like these in my logs (reported by logcheck, in this case): Mar  6 16:17

Re: [Fail2ban-users] multiline match?

2022-03-07 Thread Richard Hector
On 7/03/22 23:15, Richard Hector wrote: On 6/03/22 20:54, Dominic Raferd wrote: On 06/03/2022 04:35, Richard Hector wrote: I have lines like these in my logs (reported by logcheck, in this case): Mar  6 16:17:38 akl-host6 sshd[33035]: error: kex_exchange_identification: Connection closed

Re: [Fail2ban-users] multiline match?

2022-03-07 Thread Richard Hector
On 6/03/22 20:54, Dominic Raferd wrote: On 06/03/2022 04:35, Richard Hector wrote: I have lines like these in my logs (reported by logcheck, in this case): Mar  6 16:17:38 akl-host6 sshd[33035]: error: kex_exchange_identification: Connection closed by remote host Mar  6 16:17:38 akl-host6 sshd

[Fail2ban-users] multiline match?

2022-03-05 Thread Richard Hector
Hi all, I have to confess I find the existing filters somewhat opaque, so I might be missing something. I have lines like these in my logs (reported by logcheck, in this case): Mar 6 16:17:38 akl-host6 sshd[33035]: error: kex_exchange_identification: Connection closed by remote host Mar

[Fail2ban-users] IRC channel?

2022-03-05 Thread Richard Hector
Hi, The page at https://www.fail2ban.org/wiki/index.php/HOWTO_Seek_Help says there's a #fail2ban channel on freenode - is that still the right network? Or is the one on libera.chat the right one now? It has users, but no topic ... Thanks, Richard

Re: systemd user@###.service failure causing 90 sec delays during boot, login

2022-03-01 Thread Richard Hector
On 1/03/22 12:05, Greg Wooledge wrote: On Mon, Feb 28, 2022 at 10:28:49PM +, KCB Leigh wrote: This operating system has worked excellently for months, but for the last 2 days has suddenly been taking a very long time to boot.  The cause of the delay can be seen from the syslog: Obvious

Re: Wrong libvirt version in bullseye installation

2022-02-07 Thread Richard Hector
On 8/02/22 11:34, Gary L. Roach wrote: I have been trying to get a cleen copy of qemu/kvm installed but when I try to install qemu-system I get:     libvirt-clients : Depends: libvirt0 (= 7.0.0-3) but 8.0.0-1~bpo11+1 is to be installed.  The same for libvirt-daemon and some others.

Re: Security

2022-02-01 Thread Richard Hector
On 2/02/22 00:26, Vincent Lefevre wrote: On 2022-01-31 01:36:06 +1300, Richard Hector wrote: On 29/01/22 04:17, Vincent Lefevre wrote: > Servers shouldn't have pkexec installed in the first place, anyway. libvirt-daemon-system depends on policykit-1. Should that not be on my (kvm) ser

Re: Security

2022-01-30 Thread Richard Hector
On 29/01/22 04:17, Vincent Lefevre wrote: Servers shouldn't have pkexec installed in the first place, anyway. libvirt-daemon-system depends on policykit-1. Should that not be on my (kvm) server either? Cheers, Richard

Re: cooperative.co.uk has address 127.0.0.1

2022-01-19 Thread Richard Hector
On 19/01/22 04:08, Andrew M.A. Cater wrote: So - the Cooperative Society - is at https://www.coop.co.uk Oddly, when I searched for "Co-operative Group Limited" (which I got from whois), I found a different site: https://co-operative.coop It seems to be the same people, but a totally

Re: Single broken package blocks whole package management

2022-01-05 Thread Richard Hector
On 6/01/22 02:32, Urs Thuermann wrote: After an dist-upgrade from Raspian 8 (jessie) to 9.13 (stretch) hundreds of packages still need to be upgraded and aptitude reports numerous conflicts. Firstly, the standard response is that Raspbian is not Debian :-) There are differences which might be

Re: Thunderbird not allowing local accounts

2022-01-05 Thread Richard Hector
On 6/01/22 02:35, Paul M. Foster wrote: Folks: I just restarted my machine, and am using Thunderbird 91.4.1 (the latest) 64 bit on Debian 11. I didn't reinstall Thunderbird or upgrade it. Before I restarted the machine, I had a Thunderbird email account for local emails, which grabbed email

Re: reportbug fail

2021-11-21 Thread Richard Hector
On 21/11/21 3:04 am, Lee wrote: I wanted to create a bug report for meld but couldn't find any info on how to other than "use reportbug" :( I see your problem is solved, but for future reference, this page has info on reporting bugs via email: https://www.debian.org/Bugs/Reporting Cheers,

Bug#1000139: lxc-templates: Bad security sources on bullseye container built on buster

2021-11-18 Thread Richard Hector
Package: lxc-templates Version: 3.0.4-0+deb10u1 Severity: normal Dear Maintainer, Bug #970067 has been fixed, enabling the building of bullseye machines with a correct sources.list It is only available in bullseye+, however, so building a bullseye container on buster doesn't work correctly (the

[ansible-project] lineinfile in lxc_container?

2021-11-18 Thread Richard Hector
Hi all, I'm using ansible to set up lxc containers, using delegation to the container host. One task looks like this: - name: add ansible user to sudoers lineinfile: dest: "/var/lib/lxc/{{ inventory_hostname }}/rootfs/etc/sudoers" state: present regexp: "^ansible" line:

Re: question from total newbie. a little help please

2021-10-28 Thread Richard Hector
On 18/10/21 2:55 am, john doe wrote: With W10 you have also the possibility of using 'WLS' an order alternative would be to install Debian as a VM. I think perhaps you mean WSL - Windows Subsystem for Linux? https://docs.microsoft.com/en-us/windows/wsl/install I've never used it myself.

Re: [Sid] Firefox problem

2021-10-28 Thread Richard Hector
On 17/10/21 9:55 pm, Grzesiek wrote: Hi there, On some of machines I use, after opening of Firefox I get empty browser window (with menus, decorations etc) but nothing else is displayed. Its impossible to open menu, type address, etc. The only thing you can do is to close the window. After

Re: replacement of sqsh for debian 11

2021-10-28 Thread Richard Hector
On 28/10/21 3:05 pm, Greg Wooledge wrote: Nobody could figure out that you were trying to connect to an existing proprietary database. Well, I did. Because that's what sqsh is for - it's a client, not a DBMS. But I guess it could have been clearer. Cheers, Richard

Re: buggy N-M (was: Debian 11: Unable to detect wireless interface on an old laptop) computer

2021-09-28 Thread Richard Hector
This isn't really a good place to chip in, but the best I can find from the messages I haven't deleted ... On 29/09/21 2:00 am, Henning Follmann wrote: My comment to the OP was basically on the nebulous source (most VPN Providers) and the generalized categorization (N-M is buggy), which I

Re: silence audio on locked screen?

2021-09-28 Thread Richard Hector
On 28/09/21 11:33 pm, Dan Ritter wrote: Richard Hector wrote: On 27/09/21 11:39 pm, Dan Ritter wrote: > > One option is to run a mute and stop-playing command immediately > on screensaver interaction. > > For XFCE4, that's as easy as adding a panel object which runs an

Re: silence audio on locked screen?

2021-09-28 Thread Richard Hector
On 27/09/21 11:39 pm, Dan Ritter wrote: Richard Hector wrote: I'm using buster with xfce4, pulseaudio, and (I think) light-locker. When I lock my screen, audio continues to play (and system sounds are still heard). This seems to me like a way to leak information, and is also annoying

silence audio on locked screen?

2021-09-26 Thread Richard Hector
Hi all, I'm using buster with xfce4, pulseaudio, and (I think) light-locker. When I lock my screen, audio continues to play (and system sounds are still heard). This seems to me like a way to leak information, and is also annoying to anyone nearby. It's then annoying for me when I discover

Re: Bug#994750: RFS: mazeofgalious/0.63-1 [ITA] -- The Maze of Galious

2021-09-20 Thread Richard Hector
On 21/09/21 1:24 am, Parodper wrote:  * URL : http://www.braingames.getput.com/mog/ No such site? Cheers, Richard

Re: copy directory tree, mapping to new owners

2021-09-14 Thread Richard Hector
On 14/09/21 6:50 pm, to...@tuxteam.de wrote: On Tue, Sep 14, 2021 at 12:17:05PM +1200, Richard Hector wrote: On 13/09/21 7:04 pm, to...@tuxteam.de wrote: >On Mon, Sep 13, 2021 at 11:45:02AM +1200, Richard Hector wrote: >>On 12/09/21 6:52 pm, john doe wrote: > >[...] > &

Re: copy directory tree, mapping to new owners

2021-09-14 Thread Richard Hector
On 13/09/21 7:04 pm, to...@tuxteam.de wrote: On Mon, Sep 13, 2021 at 11:45:02AM +1200, Richard Hector wrote: On 12/09/21 6:52 pm, john doe wrote: [...] >If you are doing this in a script, I would use a temporary directory. >That way, in case of failure the destination dir

Re: copy directory tree, mapping to new owners

2021-09-12 Thread Richard Hector
On 12/09/21 7:46 pm, Teemu Likonen wrote: * 2021-09-12 12:43:29+1200, Richard Hector wrote: The context of my question is that I'm creating (or updating) a test copy of a website. The files are owned by one of two owners, depending on whether they were written by the server (actually php-fpm

  1   2   3   4   5   6   7   8   9   10   >