Re: Radius choices now that freeradius has been dropped from woody.

2002-04-15 Thread Chuck Peters

On Tue, 16 Apr 2002, J.H.M. Dassen (Ray) wrote:

> On Tue, Apr 16, 2002 at 00:28:04 -0400, Chuck Peters wrote:
> > One of our techs wants to use freeradius on a production box, but now that
> > it has been dropped from woody I would rather use something else.
>
> Looking at
> http://ftp-master.debian.org/testing/update_excuses.html#radiusd-freeradius
> the one problematic bug can be worked around by compiling from source - you
> could consider having both testing and unstable in the box's sources.list,
> pinning it to testing, but using freeradius from unstable.

I don't like the idea of doing that on production boxes running multiple
services becuase it seems likely that some security update will cause a
cascade of upgrades or break something.  Most of the time unstable stuff
works fine, but sometimes it bites you in the ass.  Maybe if we setup a
seperate box running not much other than the freeraduis it could be ok.

At
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=142217&repeatmerged=yes
it says "radiusd-freeradius is too buggy.  This is a grave bug, by Policy
s2.1.2. Maybe it will be ready for Woody+1."

What does the Woody+1 mean, a minor release/update to woody or does it
mean sid?

Thanks,
Chuck




>
> Ray
> --
> People think I'm a nice guy, and the fact is that I'm a scheming, conniving
> bastard who doesn't care for any hurt feelings or lost hours of work if it
> just results in what I consider to be a better system.
>   Linus Torvalds on the linux-kernel list
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Radius choices now that freeradius has been dropped from woody.

2002-04-15 Thread Chuck Peters


One of our techs wants to use freeradius on a production box, but now that
it has been dropped from woody I would rather use something else.  We do
want LDAP support and some kind of user accounting to limit users time.

What do you all suggest?

Thanks,
Chuck


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Look and See script

2002-04-12 Thread Chuck Peters


I did the following running from cron every 5 minutes.  Note cron output
was sent to /dev/null.  It was a test box.

#!/bin/sh
# ZOPE query
ZOPEQUERY=`ps auwx |grep z2.py | wc -l`

if test $ZOPEQUERY -lt 2; then
cd /usr/local/dc/Zope
./start &
echo "`date`: No response from Zope Service" >> /home/zope/zoperestartlog
fi


Chuck


On Fri, 12 Apr 2002, Vinai Kopp wrote:

>
> --On Donnerstag, April 11, 2002 18:53:19 -0500 "Daniel J. Rychlik"
> <[EMAIL PROTECTED]> wrote:
>
> > it crashes.  Is their a way to write a script that monitors the behavior
> > of the pid or some other kind of process that it runs from to check for
> > either yes its running or no its not?
>
> I use a small script like this:
> ---
> #! /bin/sh
>
> EXE=/path/to/mud
> LOGFILE=/var/log/mud.log
>
> if [ ! -x $EXE ]; then
>   echo "$EXE not executable" >> $LOGFILE
> else
>   while [ 1 ]; do
> $EXE >> $LOGFILE 2>&1
> sleep 10
>   done
> fi
> ---
>
> HTH,
>
> Vinai
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: mass email distribution software

2002-01-28 Thread Chuck Peters


I think it depends a lot on who uses it.  We have an ethical use for some
mass email distribution software.

My friend Kathy Miles writes a weekly column and publishes it on the web
at http://StarrySkies.com and we sometimes get requests to send it via
email.  We have tossed around the idea of setting up something to mail the
articles weekly, but I haven't really looked into setting it up mostly
because we aren't making any money with the site.

If anyone has any suggestion as to how we can ethically make money with
the site, please let us know.

Thanks,
Chuck

On Mon, 28 Jan 2002, jogi hofmueller wrote:

> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
>
> hi!
>
> the following is not technical but more ethical or so.
>
> recently i was asked to develop some sort of mass email distribution
> software for someone sending monthly newsletters about music events to a
> list of about 3000 addresses. now, before getting too deep into
> reading/searching information i would like to hear some statements about
> this because since i think about this 'project' i am torn between
> thinking of it as 'good idea' and 'spam-tool'.
>
> i know that everyone hates spam. therefore i think the idea to put a
> mailing-list-like mechanism with automated (un)subscribe procedure behind
> such a thing would be not so bad because it would make it possible to
> really unsubscribe from a list where i don't want to get anymore mails
> from.
>
> i would be glad to get some feedback here.
>
> sincerely
> - --
> j.h.
> jogi hofmueller <[EMAIL PROTECTED]>
>   GPG-public-key: http://mur.at/~jogi/text/public.key.txt
>   GPG-key-ID: B972CEC1
>   Key fingerprint = 2CD5 4786 AA9E F315 6430  868F 00FA E375 B972 CEC1
>
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.0.6 (GNU/Linux)
> Comment: Made with pgp4pine
>
> iD8DBQE8VYB6APrjdblyzsERAthmAKCjptcHpTNwLfWRMvbIM8dKb6MbNwCgxbYQ
> esjiBLqVuZX1YwYm5kCZtEw=
> =/3H/
> -END PGP SIGNATURE-
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: about new domain name and DNS server

2002-01-26 Thread Chuck Peters

On Sun, 27 Jan 2002, Jason Lim wrote:

> wtf?

I think he wants us to go into the Registrar, Internic or root
nameserver biz.  I doubt Debian as an organization would be interested.

Many of the registrars do use Linux to run their businesses.

The subject of going into business as a registrar is really off topic for
this list.  If Mr Lin is interested in starting a non-profit registrar or
for-profit registrar, it will require a plan, grants or other funding,
business and technical talent.

Thanks,
Chuck

>
> - Original Message -
> From: "Eric Lin" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Friday, January 25, 2002 10:37 AM
> Subject: about new domain name and DNS server
>
>
> > Dear Debian users or any linux users:
> >
> >   In the article, there is someone point out because there is an
> > authority manage or contral .com domain, so to get our newdomain.com
> > have to pay him or her to register.
> >
> >But why nowaday , there are more and more companies doing regiester
> > domain from 14 to 8.95 /yr - let you check wheter the domain you like
> > is available, also help you bind your newdomain with URL
> > address(additional charge in my case 6/yr)?
> >
> >Can we, linux, proud of internet reinger compete such business
> > with them?
> >
> >I know static ip is difficult to get by high shoot arin.net's 2500
> > usd, but 20/yr's DNS job should under our fire.
> >
> > sincere eric, [EMAIL PROTECTED]
> >
> >
> > --
> > To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> > with a subject of "unsubscribe". Trouble? Contact
> [EMAIL PROTECTED]
> >
> >
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: rsync backup scipt

2002-01-25 Thread Chuck Peters

On Fri, 25 Jan 2002, Hereward Cooper wrote:

> Hi there,
>
> I'm trying to setup a backup server to store stuff from a main sever + various
> other machines dotted around the place. What I'm really after is this:
>
> --server
> /home is backed up daily on a 7 day rotation
> / is backed up once a week
>
> --windows machine
> C:\My Documents\ is backed up daily via smb on a 7 day rotation
> C:\ is backed up once a week
>
> I've used rsync ok, (using one from a previous thread) but i'm not sure how to
> do the rotation system?

Use something like BACKUPDIR=`date +%A` in your scripts.

> Also when backing up / on the server, what stops it from
> copying the contents of a mounted cd aswell?

As others have mentioned exclude it.

I have found that when backing up / all at once on our server which has
about 1500 users that it fails, don't recall the details but I think it
was because it runs out of memory.

We also use ssh with authorization keys which limit what command and where
it can be run from.

Chuck


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Tutorial DNS

2002-01-18 Thread Chuck Peters

On Sun, 2002-02-17 at 14:10, Julio Cesar Torres wrote:
> I need a tutorial of DNS or Bind, can some one help me?

This one is a little training session I put together.
http://axs.org/~cp/DNS.html

http://www.linuxdoc.org/HOWTO/DNS-HOWTO.html

Thanks,
Chuck

-- 
Chuck Peters Systems Administrator and Linux Tech serving Chester County
InterLink, http://www.ccil.org, Starry Skies, http://StarrySkies.com
http://EverydayLinux.com and many other non-profit and community groups
of Chester County, PA.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: /bin/true and USR

2002-01-10 Thread Chuck Peters
On Thu, 10 Jan 2002, Glenn Hocking wrote:

> Hi all
>
> I have just tried the /bin/true trick for logins but find that ftp does
> not work. I use proftpd and the box tested is debian stable. Any ideas?

Add /bin/true to /etc/shells

Chuck





Re: /bin/true and USR

2002-01-10 Thread Chuck Peters

On Thu, 10 Jan 2002, Glenn Hocking wrote:

> Hi all
>
> I have just tried the /bin/true trick for logins but find that ftp does
> not work. I use proftpd and the box tested is debian stable. Any ideas?

Add /bin/true to /etc/shells

Chuck



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Lastlog accurately with pam_lastlog.so?

2001-12-19 Thread Chuck Peters

Hi,

I am trying to come up with a way to accurately delete old unused accounts
and its a problem.  We have about 1600 users on a few different machines.
On one machine imap and pop access isn't logged to lastlog and on another
ppp using ldap authenication isn't logged either, then another with
ftp...  I just tried adding the following to /etc/pam.d/imap and it isn't
working.

session optional pam_lastlog.so debug silent noterm

If if we do get it to work, adding this sort of thing across a few
machines isn't going to solve our problem unless we have some way to
accurately combine the lastlogs.  Any suggestions?

Thanks,
Chuck
CCIL Admin




Lastlog accurately with pam_lastlog.so?

2001-12-19 Thread Chuck Peters


Hi,

I am trying to come up with a way to accurately delete old unused accounts
and its a problem.  We have about 1600 users on a few different machines.
On one machine imap and pop access isn't logged to lastlog and on another
ppp using ldap authenication isn't logged either, then another with
ftp...  I just tried adding the following to /etc/pam.d/imap and it isn't
working.

session optional pam_lastlog.so debug silent noterm

If if we do get it to work, adding this sort of thing across a few
machines isn't going to solve our problem unless we have some way to
accurately combine the lastlogs.  Any suggestions?

Thanks,
Chuck
CCIL Admin


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: SSH & Debian Woody

2001-12-16 Thread Chuck Peters

/etc/ssh/sshd_config has PasswordAuthenication no
set it to yes.

Chuck

On Mon, 17 Dec 2001, James Mclean wrote:

>
>
> All,
>
> I am building a debian woody machine as we speak, and i have installed the
> latest .deb of OpenSSH...
>
> Installed fine, but it fails to authenticate a remote login, and if i try a
> login from the same machine's command line it also fails.
>
> This is the message from the command line...
> # ssh -l jamesmc xxx.xxx.xxx.xxx
> Neighbour Table Overflow
> ssh: connect to address xxx.xxx.xxx.xxx port 22. No Buffer Space
>
> I recieve no errors when attempting to login remotely, but fails to
> authenticate and continues to ask for the password...
> I cannot see anything the messages or syslog logfiles.
>
> # ssh -V
> OpenSSH_3.0.1p1, SSH Protocols 1.5/2.0, OpenSSL 0x0090602f
>
> I am tempted to install from source next. Any Ideas?
>
> Regards,
>
> James Mclean
>
> "Windows didn't get as bad as it is overnight -- it took over ten years of
> careful development."
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>




Re: SSH & Debian Woody

2001-12-16 Thread Chuck Peters


/etc/ssh/sshd_config has PasswordAuthenication no
set it to yes.

Chuck

On Mon, 17 Dec 2001, James Mclean wrote:

>
>
> All,
>
> I am building a debian woody machine as we speak, and i have installed the
> latest .deb of OpenSSH...
>
> Installed fine, but it fails to authenticate a remote login, and if i try a
> login from the same machine's command line it also fails.
>
> This is the message from the command line...
> # ssh -l jamesmc xxx.xxx.xxx.xxx
> Neighbour Table Overflow
> ssh: connect to address xxx.xxx.xxx.xxx port 22. No Buffer Space
>
> I recieve no errors when attempting to login remotely, but fails to
> authenticate and continues to ask for the password...
> I cannot see anything the messages or syslog logfiles.
>
> # ssh -V
> OpenSSH_3.0.1p1, SSH Protocols 1.5/2.0, OpenSSL 0x0090602f
>
> I am tempted to install from source next. Any Ideas?
>
> Regards,
>
> James Mclean
>
> "Windows didn't get as bad as it is overnight -- it took over ten years of
> careful development."
>
>
> --
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
>
>


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




56K dialup for CCIL

2001-12-05 Thread Chuck Peters

CCIL.org, a non-profit freenet, is finally getting around to wanting 56K
dialup. A big part of the board wanting it now is our per line cost will
be cheaper and they want to double the number of users in 2002.  Too bad
they want all this done with declining donations.

One of our Network Admins Eric likes the USR Total Control and says we can
pick up a used one for a good price.  Does anyone have experience with
them or comments on the performance and reliablity?

We also offer text/shell dialup access because a few people still use slow
old machines and a number of seniors just use PINE for email.  We can keep
a few of the old analog lines going for them, but it would be prefable to
offer both ppp and shell on the same dialup pool like we are now.

We will be using OpenLDAP for authenication.  It is a must that we be able
to control users online time and vary it for a few, volunteers and other
specified people get extra time while most of the users get a couple of
hours per day and we limit it during heavy usage.  Does anyone have
comments on that issue?

CCIL is expecting to spend 5-7K on this so that kind of limits our
equipment options.  Maybe something besides the USR Total Control would be
a better choice.  Any recommendations?

We also need the digital lines (West Chester, PA), Eric is going to check
with Verizon for ISDN PRI line. 23B+1D configuration.  Does anyone have
recommendations for competing vendors?

Thanks,
Chuck





56K dialup for CCIL

2001-12-05 Thread Chuck Peters


CCIL.org, a non-profit freenet, is finally getting around to wanting 56K
dialup. A big part of the board wanting it now is our per line cost will
be cheaper and they want to double the number of users in 2002.  Too bad
they want all this done with declining donations.

One of our Network Admins Eric likes the USR Total Control and says we can
pick up a used one for a good price.  Does anyone have experience with
them or comments on the performance and reliablity?

We also offer text/shell dialup access because a few people still use slow
old machines and a number of seniors just use PINE for email.  We can keep
a few of the old analog lines going for them, but it would be prefable to
offer both ppp and shell on the same dialup pool like we are now.

We will be using OpenLDAP for authenication.  It is a must that we be able
to control users online time and vary it for a few, volunteers and other
specified people get extra time while most of the users get a couple of
hours per day and we limit it during heavy usage.  Does anyone have
comments on that issue?

CCIL is expecting to spend 5-7K on this so that kind of limits our
equipment options.  Maybe something besides the USR Total Control would be
a better choice.  Any recommendations?

We also need the digital lines (West Chester, PA), Eric is going to check
with Verizon for ISDN PRI line. 23B+1D configuration.  Does anyone have
recommendations for competing vendors?

Thanks,
Chuck



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: login prompt problem for windows users.

2000-03-09 Thread Chuck Peters


Well I tried changing the inittab entry and the login prompt, but it isn't
working.  Any suggestions?

Thanks,
Chuck

PS I still haven't heard from Equinox Tech Support.

On Thu, 9 Mar 2000, Chuck Peters wrote:

> 
> It seems it is an issue of mgetty, not ppp. Once he does get logged in via
> bring up the terminal window after dialing he can initate PPP just fine.  
> The login prompt is not being displayed until after one hits the enter key
> once and that seems to be what is making the problem for windows users.
> 
> I have everything setup as suggested below or the defaults except that I
> turned authenication off with noauth in options.ttyQ1a7.  And yes I know
> that is a bad idea/secuity issue, I'll fix that later after we get this
> login issue worked out.
> 
> I know we had this Equinox working fine before, a year or 2 ago the guy we
> bought it from had us set it up for him with Debian.  
> 
> I will try turing off the -s option in inittab and see if that helps.
> 
> Thanks,
> Chuck
> 
> On Tue, 7 Mar 2000, Gerard MacNeil wrote:
> 
> > On Sun, 5 Mar 2000, Chuck Peters wrote:
> > 
> > > 
> > > I sent the following to Equinox tech support, but I was hoping a kind
> > > Debian guru can tell me what the problem is.
> > 
> > Guru, not.  User of mgetty/PPP, yes.
> > > 
> > > Q07:23:respawn:/sbin/mgetty -D -s 115200 -m '"" ATZ OK"' ttyQ1a7
> > 
> > As long as 'ps' shows the mgetty process running on ttyQ1a7, this will
> > work.  The values on this line override the settings in
> > /etc/mgetty/mgetty.config.
> > 
> > > 
> > > I also asked Mark to dial in with HyperTerminal to confirm that the login
> > ...
> > > #
> > > *   -   -   /bin/login @
> > 
> > Yes, this is the /etc/mgetty/login.config that resulted in the prompt.
> > "Mark" (if he had permissions) would need to fire up PPP from the command
> > line at this stage.  Since, by default, /etc/ppp is not readable by
> > others, Mark needs to be assigned special priviliges to do so.
> > 
> > The "routine way" is to let mgetty hand over the authentication procedure
> > to PPP.  The user does not actually login, which the following log record
> > indicates:
> > 
> > > 03/04 15:46:53 1a7  waiting for ``_'' ** found **
> > > 03/04 15:46:55 # data dev=ttyQ1a7, pid=12205, caller='none',
> > > conn='115200', 
> > > name='', cmd='/usr/sbin/pppd', user='/AutoPPP/'
> > 
> > It is produced as a result of the /etc/mgetty/login.config (as
> > distributed):
> > /AutoPPP/ - a_ppp   /usr/sbin/pppd auth -chap +pap login debug
> > 
> > Everything is working OK so far.  The log record is also you indicator
> > that mgetty has finished doing it's thing and has handed off the
> > connection to PPP for authentication.  Time to look at the PPP
> > config/logs.
> > 
> > 1. /etc/ppp/options.ttyQ1a7
> > Assuming you are dynamically assigning IP addresses, you would want
> > :
> > 
> > 2. /etc/ppp/pap-secrets
> > As distributed ...
> > # Every regular user can use PPP and has to use passwords from /etc/passwd
> > *   *   ""  *
> > 
> > 3. /etc/ppp/options
> > which has your PPP default options.  On distribution there are no DNS
> > servers specified for obvious reasons.  
> > # Specify which DNS Servers the incoming Win95 or WinNT Connection should 
> > use
> > # Two Servers can be remotely configured
> > ms-dns 
> > ms-dns 
> > 
> > If those settings are complete and correct, you should see the result of
> > the attempted login via PPP in /var/log/auth.log 
> > 
> > If /etc/syslog.conf is configured with the line
> > local2.* -/var/log/ppp.log 
> > you have a complete session log in /var/log/ppp.log
> > 
> > Add the keyword directive (on a line by itself)
> > debug
> > to /etc/ppp/options.ttyQ1a7 for a detailed report of what PPP is really
> > doing during the authentication/network protocol negotiation.
> > 
> > Note: I change that 'a_ppp' above to a '-' and fight with PAM to have
> > mgetty log the PPP connections to the utmp/wtmp files.  This enables
> > commands like 'who' and 'last' to show results on the dialup servers.  It
> > looks like the latest version of PPP in the potato distribution has
> > stopped the fight between mgetty and PAM (not well tested by myself yet).
> > 
> > ---
> > Gerard MacNeil, P. Eng  [EMAIL PROTECTED]
> > System Administrator
> > Supercity Internet Services http://www.supercity.ns.ca
> > 
> > 
> > 
> 
> 
> --  
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
> 
> 



Re: login prompt problem for windows users.

2000-03-09 Thread Chuck Peters

It seems it is an issue of mgetty, not ppp. Once he does get logged in via
bring up the terminal window after dialing he can initate PPP just fine.  
The login prompt is not being displayed until after one hits the enter key
once and that seems to be what is making the problem for windows users.

I have everything setup as suggested below or the defaults except that I
turned authenication off with noauth in options.ttyQ1a7.  And yes I know
that is a bad idea/secuity issue, I'll fix that later after we get this
login issue worked out.

I know we had this Equinox working fine before, a year or 2 ago the guy we
bought it from had us set it up for him with Debian.  

I will try turing off the -s option in inittab and see if that helps.

Thanks,
Chuck

On Tue, 7 Mar 2000, Gerard MacNeil wrote:

> On Sun, 5 Mar 2000, Chuck Peters wrote:
> 
> > 
> > I sent the following to Equinox tech support, but I was hoping a kind
> > Debian guru can tell me what the problem is.
> 
> Guru, not.  User of mgetty/PPP, yes.
> > 
> > Q07:23:respawn:/sbin/mgetty -D -s 115200 -m '"" ATZ OK"' ttyQ1a7
> 
> As long as 'ps' shows the mgetty process running on ttyQ1a7, this will
> work.  The values on this line override the settings in
> /etc/mgetty/mgetty.config.
> 
> > 
> > I also asked Mark to dial in with HyperTerminal to confirm that the login
> ...
> > #
> > *   -   -   /bin/login @
> 
> Yes, this is the /etc/mgetty/login.config that resulted in the prompt.
> "Mark" (if he had permissions) would need to fire up PPP from the command
> line at this stage.  Since, by default, /etc/ppp is not readable by
> others, Mark needs to be assigned special priviliges to do so.
> 
> The "routine way" is to let mgetty hand over the authentication procedure
> to PPP.  The user does not actually login, which the following log record
> indicates:
> 
> > 03/04 15:46:53 1a7  waiting for ``_'' ** found **
> > 03/04 15:46:55 # data dev=ttyQ1a7, pid=12205, caller='none',
> > conn='115200', 
> > name='', cmd='/usr/sbin/pppd', user='/AutoPPP/'
> 
> It is produced as a result of the /etc/mgetty/login.config (as
> distributed):
> /AutoPPP/ - a_ppp   /usr/sbin/pppd auth -chap +pap login debug
> 
> Everything is working OK so far.  The log record is also you indicator
> that mgetty has finished doing it's thing and has handed off the
> connection to PPP for authentication.  Time to look at the PPP
> config/logs.
> 
> 1. /etc/ppp/options.ttyQ1a7
> Assuming you are dynamically assigning IP addresses, you would want
> :
> 
> 2. /etc/ppp/pap-secrets
> As distributed ...
> # Every regular user can use PPP and has to use passwords from /etc/passwd
> *   *   ""  *
> 
> 3. /etc/ppp/options
> which has your PPP default options.  On distribution there are no DNS
> servers specified for obvious reasons.  
> # Specify which DNS Servers the incoming Win95 or WinNT Connection should use
> # Two Servers can be remotely configured
> ms-dns 
> ms-dns 
> 
> If those settings are complete and correct, you should see the result of
> the attempted login via PPP in /var/log/auth.log 
> 
> If /etc/syslog.conf is configured with the line
> local2.* -/var/log/ppp.log 
> you have a complete session log in /var/log/ppp.log
> 
> Add the keyword directive (on a line by itself)
> debug
> to /etc/ppp/options.ttyQ1a7 for a detailed report of what PPP is really
> doing during the authentication/network protocol negotiation.
> 
> Note: I change that 'a_ppp' above to a '-' and fight with PAM to have
> mgetty log the PPP connections to the utmp/wtmp files.  This enables
> commands like 'who' and 'last' to show results on the dialup servers.  It
> looks like the latest version of PPP in the potato distribution has
> stopped the fight between mgetty and PAM (not well tested by myself yet).
> 
> ---
> Gerard MacNeil, P. Eng  [EMAIL PROTECTED]
> System Administrator
> Supercity Internet Services http://www.supercity.ns.ca
> 
> 
> 



login prompt problem for windows users.

2000-03-07 Thread Chuck Peters

I sent the following to Equinox tech support, but I was hoping a kind
Debian guru can tell me what the problem is.

We are using Debian Linux with an Equinox SST box to offer some users free
PPP dialup. Most everything appears to be working fine except that Windows
users are not automatically logging in.  The Windows users should just be
able to enter the phone number, username and password. But for some reason
they are not logging in.  I had one of the users test it with bring up a
terminal window after dialing and he is able to login and initiate ppp
without problems, but we need the process to work the way it should.  The
login prompt is not being displayed until after one hits the enter key
once.

Mark, a windows user, has been dialing in on Q07, in inittab it has 

Q07:23:respawn:/sbin/mgetty -D -s 115200 -m '"" ATZ OK"' ttyQ1a7

I also asked Mark to dial in with HyperTerminal to confirm that the login
prompt was not appearing until he pressed enter, and he confirmed that is 
the case.

The following may not be helpful, but maybe it is. 
 
dialup prompt
news!login:

telnet prompt
news login: 


Part of /etc/mgetty/login.config 

# This is the "standard" behaviour - *dont* set a userid or utmp
#  entry here, otherwise /bin/login will fail!
#  This entry isn't really necessary: if it's missing, the built-in
#  default will do exactly this.
#
*   -   -   /bin/login @


The following are some mgetty enties of failed logins, and successful
logins using the manual bring up the termal window.
 
--
03/04 15:41:01 1a7  mgetty: experimental test release 1.1.18-Sep11
03/04 15:41:01 1a7  check for lockfiles
03/04 15:41:01 1a7  locking the line
03/04 15:41:02 1a7  lowering DTR to reset Modem
03/04 15:41:02 1a7  send: ATZ[0d]
03/04 15:41:02 1a7  waiting for ``OK'' ** found **
03/04 15:41:03 1a7  waiting...
03/04 15:46:33 1a7  wfr: waiting for ``RING''
03/04 15:46:33 1a7  send: ATA[0d]
03/04 15:46:33 1a7  waiting for ``CONNECT'' ** found **
03/04 15:46:53 1a7  send: 
03/04 15:46:53 1a7  waiting for ``_'' ** found **
03/04 15:46:55 # data dev=ttyQ1a7, pid=12205, caller='none',
conn='115200', 
name='', cmd='/usr/sbin/pppd', user='/AutoPPP/'

--
03/04 15:50:01 1a7  mgetty: experimental test release 1.1.18-Sep11
03/04 15:50:01 1a7  check for lockfiles
03/04 15:50:01 1a7  locking the line
03/04 15:50:02 1a7  lowering DTR to reset Modem
03/04 15:50:02 1a7  send: ATZ[0d]
03/04 15:50:02 1a7  waiting for ``OK''
03/04 15:50:02 1a7  found action string: ``NO CARRIER''
03/04 15:50:02 1a7  init chat failed, exiting...: Invalid argument
03/04 15:50:02 # failed in mg_init_data, dev=ttyQ1a7, pid=12225

--
03/04 15:50:03 1a7  mgetty: experimental test release 1.1.18-Sep11
03/04 15:50:03 1a7  check for lockfiles
03/04 15:50:03 1a7  locking the line
03/04 15:50:03 1a7  lowering DTR to reset Modem
03/04 15:50:04 1a7  send: ATZ[0d]
03/04 15:50:04 1a7  waiting for ``OK'' ** found **
03/04 15:50:04 1a7  waiting...
03/04 16:17:17 1a7  wfr: waiting for ``RING''
03/04 16:17:17 1a7  send: ATA[0d]
03/04 16:17:17 1a7  waiting for ``CONNECT'' ** found **
03/04 16:17:37 1a7  send: 
03/04 16:17:37 1a7  waiting for ``_'' ** found **
03/04 16:17:53 # data dev=ttyQ1a7, pid=12226, caller='none',
conn='115200', 
name='', cmd='/bin/login', user='marksamm'

--

Thanks,
Chuck