Re: [CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Jerry Geis
> How do you measure the slowness? Use fio or bonnie++ to share some number.

By it taking more than 6 hours to "install" CentOS 8 in the guest :)

Jerry
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Alexander Dalloz

Am 13.10.2019 um 00:03 schrieb Jerry Geis:

Hi Alan,

Yes I have partitioned similar - with a swap. but as I mentioned slow!


How do you measure the slowness? Use fio or bonnie++ to share some number.

[ .. ]


Jerry


Alexander


___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Jerry Geis
Hi Alan,

Yes I have partitioned similar - with a swap. but as I mentioned slow!
 What command line do you use ?

   Device Boot  Start End  Blocks   Id  System
/dev/nvme0n1p12048   1024020475120   83  Linux
/dev/nvme0n1p2   102402048   110594047 4096000   82  Linux swap /
Solaris
/dev/nvme0n1p3   110594048   112642047 10240006  FAT16
/dev/nvme0n1p4   112642048  3907028991  1897193472   83  Linux

Thanks,

Jerry
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Alan McRae via CentOS
I have CentOS 8 install solely on one nvme drive and it works fine and 
relatively quickly.


/dev/nvme0n1p4  218G   50G  168G  23% /
/dev/nvme0n1p2  2.0G  235M  1.6G  13% /boot
/dev/nvme0n1p1  200M  6.8M  194M   4% /boot/efi

You might want to partition the device (p3 is swap)

Alan

On 13/10/2019 10:38, Jerry Geis wrote:

Hi All -  I use qemu on my centOS 7.7 box that has software raid of 2- SSD
disks.

I installed an nVME drive in the computer also. I tried to insall CentOS8
on it
(the physical /dev/nvme0n1  with the -hda /dev/nvme0n1 as the disk.

The process started installing but is really "slow" - I was expecting with
the nvme device it would be much quicker.

Is there something I am missing how to get a faster disk access ?

Thanks,

Jerry
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos

___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Ljubomir Ljubojevic
On 10/12/19 11:38 PM, Jerry Geis wrote:
> Hi All -  I use qemu on my centOS 7.7 box that has software raid of 2- SSD
> disks.
> 
> I installed an nVME drive in the computer also. I tried to insall CentOS8
> on it
> (the physical /dev/nvme0n1  with the -hda /dev/nvme0n1 as the disk.
> 
> The process started installing but is really "slow" - I was expecting with
> the nvme device it would be much quicker.
> 
> Is there something I am missing how to get a faster disk access ?

You should try with some other OS to make sure it is not a hardware
(BIOS/MB) problem. Maybe try with Windows or some other Linux and
compare speeds?

Also check if there is a firmware/BIOS update for the nVME controler...




> 
> Thanks,
> 
> Jerry
> ___
> CentOS mailing list
> CentOS@centos.org
> https://lists.centos.org/mailman/listinfo/centos
> 


-- 
Ljubomir Ljubojevic
(Love is in the Air)
PL Computers
Serbia, Europe

StarOS, Mikrotik and CentOS/RHEL/Linux consultant
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


[CentOS] qeum on centos 8 with nvme disk

2019-10-12 Thread Jerry Geis
Hi All -  I use qemu on my centOS 7.7 box that has software raid of 2- SSD
disks.

I installed an nVME drive in the computer also. I tried to insall CentOS8
on it
(the physical /dev/nvme0n1  with the -hda /dev/nvme0n1 as the disk.

The process started installing but is really "slow" - I was expecting with
the nvme device it would be much quicker.

Is there something I am missing how to get a faster disk access ?

Thanks,

Jerry
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Is it a way to upgrade CentOS 7 to 8?

2019-10-12 Thread Pete Biggs
On Sat, 2019-10-12 at 21:03 +0200, Pierre Malard wrote:
> Ok, thanks. it’s now very clear…
> I must stay in CentOS 7 as long as possible…
> 
No, that's not the way to look at it.  Yes, an upgrade of major CentOS
versions is a wipe and re-install (unless you really, really know what
you are doing), but the longevity of the OS is usually greater than the
lifetime of the hardware so there is no *urgency* to upgrade, CentOS 7
is not going to go away for a few years.

The sensible way (i.e. what I do!), is to play with the new version for
a little while, testing critical infrastructure and getting a feel for
how it all works both standalone and with the rest of my estate. During
that process I get to grips with installation procedures, PXE,
kickstart, creating my bespoke RPMs and so on. Eventually, by probably
8.1 I will be deploying it for non mission-critical servers.  Only then
will I think about re-deploying current applications on to CentOS 8 and
the urgency with which that is done is governed by the need for the
newer versions of applications. But I will still be deploying CentOS 7
on new hardware for a while, but with the knowledge that the OS will
still outlast the machines.

P.


___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] CentOS 8 virt-manager

2019-10-12 Thread Jonathan Billings
On Oct 12, 2019, at 12:07 PM, Günther J. Niederwimmer  wrote:
> It is not possible to install a UEFI  client ?


Do you have the OVMF package installed on the Virtualization host?

--
Jonathan Billings 


___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Is it a way to upgrade CentOS 7 to 8?

2019-10-12 Thread Pierre Malard
Ok, thanks. it’s now very clear…
I must stay in CentOS 7 as long as possible…

Thanks and best regards

> Le 12 oct. 2019 à 20:49, Ljubomir Ljubojevic  a écrit :
> 
> On 10/12/19 8:19 PM, Pierre Malard wrote:
>> Hi,
>> 
>> I’m looking for a method to upgrade my centos 7 servers to 8 and I don’t 
>> find anything to do that!
>> 
>> I’m a very newbie with CentOS? My choices where gone to Debian or Ubuntu and 
>> it was very simple. Just some files must be changed (/etc/apt/source.list). 
>> My search suggest a RELH subscription. Is it the only way?
>> 
> 
> Hi Pierre.
> 
> RHEL/CentOS are different then Ubuntu, Debian or Fedora. RHEL/CentOS 6.x
> was based on Fedora 12 packages, RHEL/CentOS 7.x on Fedora 19 and
> RHEL/CentOS 8.0 on Fedora 28 packages. As you can see, Upgrading from
> CentOS 7 to 8 is like directly updating from Fedora 19 to Fedora 28, gap
> of whole 9 versions, and Ubuntu from 14.04 to 19.04 (skipping 14.10,
> 15.04, 15.10, 16.04, 16.10, 17.04, 17.10, 18.04 and 18.10). This happens
> because CentOS becomes EOL after 10 years and it's replacement 5 full
> years after initial release. In whole that time, main packages like
> glibc do not change version (except bugfixes).
> 
> So, differences between packages versions are VERY large, and simple
> "upgrade" would most likely mess things up.
> 
> Red Hat did release a RHEL tool for upgrade, but there is no interest in
> community to work to convert it for CentOS, so trying to upgrade CentOS
> 7 to 8 is risky at least.
> 
> I do not even think about upgrading my servers from 7 to 8, only clean
> install is option for me (with backup before it of course).
> 
> On another note, if you do not have a pressing need to upgrade CentOS to
> 8, I would argue you can stay on 7 for next 3-5 years, or maybe upgrade
> one at the time.
> 
> Many packages like php can be upgraded on CentOS 7. If you tell us why
> you NEED to upgrade your servers to 8, maybe we can dirrect you to
> solution like Software collection or IUS repository.
> 
> 
> 
>> Best regards
>> 
>> --
>> Pierre Malard
>> 
>>   «La France n'est pas schismatique, elle est révolutionnaire»
>>  Jean 
>> Jaures - 1905
>>  (`.-,')
>>.-' ;
>>_.-'   , `,-
>>  _ _.-' .'  /._
>>.' `  _.-.  /  ,'._;)
>>   (   .  )-| (
>>)`,_ ,'_,'  \_;)
>> ('_  _,'.'  (___,))πr
>> `-:;.-'
>> 
>> perl -e '$_=q#: 3|\ 5_,3-3,2_: 3/,`.'"'"'`'"'"' 5-.  ;-;;,_:  |,A-  ) )-,_. 
>> ,\ (  `'"'"'-'"'"': '"'"'-3'"'"'2(_/--'"'"'  `-'"'"'\_): 
>> 24πr::#;y#:#\n#;s#(\D)(\d+)#$1x$2#ge;print'
>> - --> Ce message n’engage que son auteur <--
>> 
>> 
>> ___
>> CentOS mailing list
>> CentOS@centos.org 
>> https://lists.centos.org/mailman/listinfo/centos 
>> 
>> 
> 
> 
> --
> Ljubomir Ljubojevic
> (Love is in the Air)
> PL Computers
> Serbia, Europe
> 
> StarOS, Mikrotik and CentOS/RHEL/Linux consultant

--
Pierre Malard

  « Si l'on veut croire en l'humanité,
 il faut voir et comprendre l'inhumanité »
   |\  _,,,---,,_
   /,`.-'`'-.  ;-;;,_
  |,4-  ) )-,_. ,\ (  `'-'
 '---''(_/--'  `-'\_)   πr

perl -e '$_=q#: 3|\ 5_,3-3,2_: 3/,`.'"'"'`'"'"' 5-.  ;-;;,_:  |,A-  ) )-,_. ,\ 
(  `'"'"'-'"'"': '"'"'-3'"'"'2(_/--'"'"'  `-'"'"'\_): 
24πr::#;y#:#\n#;s#(\D)(\d+)#$1x$2#ge;print'
- --> Ce message n’engage que son auteur <--



signature.asc
Description: Message signed with OpenPGP
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] Is it a way to upgrade CentOS 7 to 8?

2019-10-12 Thread Ljubomir Ljubojevic
On 10/12/19 8:19 PM, Pierre Malard wrote:
> Hi,
> 
> I’m looking for a method to upgrade my centos 7 servers to 8 and I don’t find 
> anything to do that!
> 
> I’m a very newbie with CentOS? My choices where gone to Debian or Ubuntu and 
> it was very simple. Just some files must be changed (/etc/apt/source.list). 
> My search suggest a RELH subscription. Is it the only way?
> 

Hi Pierre.

RHEL/CentOS are different then Ubuntu, Debian or Fedora. RHEL/CentOS 6.x
was based on Fedora 12 packages, RHEL/CentOS 7.x on Fedora 19 and
RHEL/CentOS 8.0 on Fedora 28 packages. As you can see, Upgrading from
CentOS 7 to 8 is like directly updating from Fedora 19 to Fedora 28, gap
of whole 9 versions, and Ubuntu from 14.04 to 19.04 (skipping 14.10,
15.04, 15.10, 16.04, 16.10, 17.04, 17.10, 18.04 and 18.10). This happens
because CentOS becomes EOL after 10 years and it's replacement 5 full
years after initial release. In whole that time, main packages like
glibc do not change version (except bugfixes).

So, differences between packages versions are VERY large, and simple
"upgrade" would most likely mess things up.

Red Hat did release a RHEL tool for upgrade, but there is no interest in
community to work to convert it for CentOS, so trying to upgrade CentOS
7 to 8 is risky at least.

I do not even think about upgrading my servers from 7 to 8, only clean
install is option for me (with backup before it of course).

On another note, if you do not have a pressing need to upgrade CentOS to
8, I would argue you can stay on 7 for next 3-5 years, or maybe upgrade
one at the time.

Many packages like php can be upgraded on CentOS 7. If you tell us why
you NEED to upgrade your servers to 8, maybe we can dirrect you to
solution like Software collection or IUS repository.



> Best regards
> 
> --
> Pierre Malard
> 
>«La France n'est pas schismatique, elle est révolutionnaire»
>   Jean 
> Jaures - 1905
>   (`.-,')
> .-' ;
> _.-'   , `,-
>   _ _.-' .'  /._
> .' `  _.-.  /  ,'._;)
>(   .  )-| (
> )`,_ ,'_,'  \_;)
> ('_  _,'.'  (___,))πr
>  `-:;.-'
> 
> perl -e '$_=q#: 3|\ 5_,3-3,2_: 3/,`.'"'"'`'"'"' 5-.  ;-;;,_:  |,A-  ) )-,_. 
> ,\ (  `'"'"'-'"'"': '"'"'-3'"'"'2(_/--'"'"'  `-'"'"'\_): 
> 24πr::#;y#:#\n#;s#(\D)(\d+)#$1x$2#ge;print'
> - --> Ce message n’engage que son auteur <--
> 
> 
> ___
> CentOS mailing list
> CentOS@centos.org
> https://lists.centos.org/mailman/listinfo/centos
> 


-- 
Ljubomir Ljubojevic
(Love is in the Air)
PL Computers
Serbia, Europe

StarOS, Mikrotik and CentOS/RHEL/Linux consultant
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


[CentOS] Is it a way to upgrade CentOS 7 to 8?

2019-10-12 Thread Pierre Malard
Hi,

I’m looking for a method to upgrade my centos 7 servers to 8 and I don’t find 
anything to do that!

I’m a very newbie with CentOS? My choices where gone to Debian or Ubuntu and it 
was very simple. Just some files must be changed (/etc/apt/source.list). My 
search suggest a RELH subscription. Is it the only way?

Best regards

--
Pierre Malard

   «La France n'est pas schismatique, elle est révolutionnaire»
  Jean 
Jaures - 1905
  (`.-,')
.-' ;
_.-'   , `,-
  _ _.-' .'  /._
.' `  _.-.  /  ,'._;)
   (   .  )-| (
)`,_ ,'_,'  \_;)
('_  _,'.'  (___,))πr
 `-:;.-'

perl -e '$_=q#: 3|\ 5_,3-3,2_: 3/,`.'"'"'`'"'"' 5-.  ;-;;,_:  |,A-  ) )-,_. ,\ 
(  `'"'"'-'"'"': '"'"'-3'"'"'2(_/--'"'"'  `-'"'"'\_): 
24πr::#;y#:#\n#;s#(\D)(\d+)#$1x$2#ge;print'
- --> Ce message n’engage que son auteur <--



signature.asc
Description: Message signed with OpenPGP
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] easy way to stop old ssl's

2019-10-12 Thread Warren Young
On Oct 12, 2019, at 4:06 AM, Markus Falb  wrote:
> 
> On 11.10.19 22:40, Warren Young wrote:
>> Just ship a new HTTPS configuration to each server.
> 
> Instead of configuring every application separataly it would be nice if
> "accepted levels of security" could be set system wide.

…which implies that there is some authority that defines “accepted level” the 
way you’d do it if you could be bothered to think through all of the use cases, 
combinations, and implications.

Who is that central organization?  Are you sure their notions match your own?

> With 8 it seems there is such a thing
> 
> https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening
> 
> Although I believe that FIPS mode is also available in 7

That’s FIPS 140-2, a standard from 2001, which is three TLS standards ago.

FIPS 140-3 just barely became effective a few weeks ago, which means it won’t 
be considered for inclusion in RHEL until 9, which I don’t expect to appear 
until 3-4 years from now, by which time FIPS 140-2 will be around 21 years old.

So, we not only have a situation where adopting FIPS 140-2 requires that you 
use badly outdated security technologies, it also means you might not be able 
to communicate with those that do support modern standards, if they’ve dropped 
compatibility with 2001 era tech sometime in the last 18 years.

If we can be well-guided by past events, there’s a better than 50/50 chance 
that any given person on this list won’t even be in IT any more when FIPS 140-4 
comes out.
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] CentOS 8 virt-manager

2019-10-12 Thread Günther J . Niederwimmer
Hello,

Am Samstag, 12. Oktober 2019, 16:57:28 CEST schrieb Tom Bishop:
> I am thinking about building a new host and trying to decide if
> virt-manager is working on CentOS 8. I thought I saw previously on the mail
> list that there were some issues but cannot find the thread right now. If
> anyone has migrated some workloads from 7 and seen any issues let me know.
> 
> Thanks :)

On my site, it is working after installing X-server, but not all :-(.

It is not possible to install a UEFI  client ?

-- 
mit freundlichen Grüßen / best regards

  Günther J. Niederwimmer


___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] CentOS 8 virt-manager

2019-10-12 Thread Robert P. J. Day
On Sat, 12 Oct 2019, Ljubomir Ljubojevic wrote:

> On 10/12/19 4:57 PM, Tom Bishop wrote:
> > I am thinking about building a new host and trying to decide if
> > virt-manager is working on CentOS 8. I thought I saw previously on the mail
> > list that there were some issues but cannot find the thread right now. If
> > anyone has migrated some workloads from 7 and seen any issues let me know.
> >
> > Thanks :)
> > ___
> > CentOS mailing list
> > CentOS@centos.org
> > https://lists.centos.org/mailman/listinfo/centos
> >
> MArk wrote that virt-manager is replaced by "cockpit" in EL8. Can not
> comfirm or deny.

  from RHEL 8 virtualization guide:

"The Virtual Machine Manager (virt-manager) application is still
supported in RHEL 8 but has been deprecated. The RHEL 8 web console is
intended to become its replacement in a subsequent release. It is,
therefore, recommended that you get familiar with the web console for
managing virtualization in a GUI."

rday

-- 


Robert P. J. Day Ottawa, Ontario, CANADA
 http://crashcourse.ca

Twitter:   http://twitter.com/rpjday
LinkedIn:   http://ca.linkedin.com/in/rpjday

___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] CentOS 8 virt-manager

2019-10-12 Thread Ljubomir Ljubojevic
On 10/12/19 4:57 PM, Tom Bishop wrote:
> I am thinking about building a new host and trying to decide if
> virt-manager is working on CentOS 8. I thought I saw previously on the mail
> list that there were some issues but cannot find the thread right now. If
> anyone has migrated some workloads from 7 and seen any issues let me know.
> 
> Thanks :)
> ___
> CentOS mailing list
> CentOS@centos.org
> https://lists.centos.org/mailman/listinfo/centos
> 
MArk wrote that virt-manager is replaced by "cockpit" in EL8. Can not
comfirm or deny.

-- 
Ljubomir Ljubojevic
(Love is in the Air)
PL Computers
Serbia, Europe

StarOS, Mikrotik and CentOS/RHEL/Linux consultant
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


[CentOS] CentOS 8 virt-manager

2019-10-12 Thread Tom Bishop
I am thinking about building a new host and trying to decide if
virt-manager is working on CentOS 8. I thought I saw previously on the mail
list that there were some issues but cannot find the thread right now. If
anyone has migrated some workloads from 7 and seen any issues let me know.

Thanks :)
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] easy way to stop old ssl's

2019-10-12 Thread Brian Reichert
On Fri, Oct 11, 2019 at 02:40:42PM -0600, Warren Young wrote:
> On Oct 11, 2019, at 12:12 PM, Jerry Geis  wrote:
> > 
> > is there a script that is available that can be ran to bring
> > a box up to current "accepted" levels ?

Bear in mind, there are a number of moving parts here.

- Many different services, besides web servers, can be configured
  to employ SSL/TLS.  LDAP databases, SMTP servers, etc.

- There are different SSL engines in play.  Many services use OpenSSL
  at their core, but Java-based services have their own SSL engine.
  GnuTLS is another engine in play.

- Services linked to OpenSSL nominally aught to be able to be
  configured to clamp down as you see fit, but sometimes your
  service's wrapper of OpenSSL doesn't expose enough of the
  fine-grained details to accomplish as you want.

  For example, I have a legacy Perl-based web service that used an
  old version of Net::SSLeay that hampered my ability to constrain
  SSL versions/ciphers.

- Java-based services have config details all over the place.
  There's a core set of config items for the JVM itself, but your
  servlet engine will have it's own config files for describing
  listeners, etc.

Besides things acting as SSL servers on a host, there are any number of
things that may act as an SSL _client_.  Those need to be considered as
well, and there are many vagaries about the semantics within config files.

-- 
Brian Reichert  
BSD admin/developer at large
___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos


Re: [CentOS] easy way to stop old ssl's

2019-10-12 Thread Markus Falb
On 11.10.19 22:40, Warren Young wrote:
> On Oct 11, 2019, at 12:12 PM, Jerry Geis  wrote:
>>
>> is there a script that is available that can be ran to bring
>> a box up to current "accepted" levels ?
> 
> I don’t know why you’d use a script for this at all.  Just ship a new HTTPS 
> configuration to each server.  Apache loads all *.conf files in its 
> configuration directory, so you might be able to just add another file to the 
> existing config set.  If not, then replace the existing config file instead.

Instead of configuring every application separataly it would be nice if
"accepted levels of security" could be set system wide.

With 8 it seems there is such a thing

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening

Although I believe that FIPS mode is also available in 7

I did not used neither system wide cryptographic policies nor FIPS mode
so my post is more the theoretical one, but I thought it is on topic.

-- 
Kind Regards, Markus Falb

___
CentOS mailing list
CentOS@centos.org
https://lists.centos.org/mailman/listinfo/centos