Re: [qubes-users] GPU is deal-breaker

2017-08-22 Thread cdgamlin
My laptop specs (if it helps): https://support.hp.com/au-en/document/c03146718

My situation: Don't have funds to get a new computer (for hardware compliance 
or multiple GPUs) or mobile phone (for Skype), and can't use an alternative to 
Skype (not my choice and beyond my control).

Screen-shooting rather than screen-sharing for Skype seems reasonable, as Skype 
shouldn't be on Dom0. I think that would solve my issues with Skype (I'd have 
to reinstall Qubes+Skype and check it out)- but I am still stuck with VLC video 
glitching up, even if the audio keeps playing well.

Summary: Deal-breaker probably is down to getting VLC working properly

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/fac99c74-26f7-4ea7-be12-00f48f7bcfe3%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] GPU is deal-breaker

2017-08-22 Thread Zrubi
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

On 08/22/2017 10:18 AM, cdgam...@gmail.com wrote:

> Summary: Deal-breaker probably is down to getting VLC working
> properly
> 

did you tried to switch video output?
I would start with X11 instead of automatic.



- -- 
Zrubi
-BEGIN PGP SIGNATURE-
Version: GnuPG v2

iQIcBAEBCAAGBQJZm+ndAAoJEH7adOMCkunm2h8P/iWgY9IyZtSpxvzK7c6EFhQO
LJSh6x7WVJkRwK4lUSHtvabzMQ5FjZkd/tJIOPjGF0pLpnqofKorfMf02ZGDNrIW
n1yuccSo+3bGIYL94UVV2biNHY9IXALm1QnPB/cp2dehkQYPHQhLRi1Jh1Yhfsps
5Fj+4jVWenqtzzjN0Q9shOthhN0d6xarcnig8jTidDQ1ss8FBI/rQ9Ds2ZrNsJ7B
DeyrC9/nUKr4ZsOqHoXXL/dVtJxs9t3mwvck1ed9a4KwB2jmHdW9smANyu5HV09W
3jD22RQPRe6FB4g0Sqb1He6mgAryWT55J43FwiL5VxWIaZXNG0IN02u15BQivmIA
VLGQpcBD0l8qUKrdtQnEMJIcyHFvvclA/3EnIAjqKFfN7SkLESuYZ5VPqFHm6b8E
6JtQhyW/AlnD9BWf8uatl8nqUHOjrBKfkH0FzHBeffdjTgOlkMknoUsyhg4VQgAD
APRUzrqJJSXLVkgK0I2KN3mbaaaY9gI74hzikuLnP/SJylLM3Cu7QJxXwhWD25yq
8QUeqUCkmTYx2PA6NnXSKRrXxOJ60RBCW5Xc1pruSdMYkrO3apKwRdDjqki7z+UZ
Io/EUHeOA5rMBZjFf7DlD3JfTpm4N2Qwy2yLzXn8jOk9QIG8tWgdgIDp4ssomFsS
bVq6MeralPxwE6y3vLzE
=OzTG
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b1b7152b-7e85-dc3d-b76f-566b2ebdae81%40zrubi.hu.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Upgrade path R3.2 to R4?

2017-08-22 Thread public
Thanks!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/dbfd7180-638a-4304-912f-6fdf38e296d2%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] GPU is deal-breaker

2017-08-22 Thread cdgamlin
> > Summary: Deal-breaker probably is down to getting VLC working
> > properly
> > 
> 
> did you tried to switch video output?
> I would start with X11 instead of automatic.
> 

Not sure what you mean, but have other pressing projects to work on right now. 
Will look into it further in the future when I have the time available.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/af7fd1c2-b7e3-40d6-b525-fbdf49f63385%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] GPU is deal-breaker

2017-08-22 Thread cdgamlin
> > Summary: Deal-breaker probably is down to getting VLC working
> > properly
> >
>
> did you tried to switch video output?
> I would start with X11 instead of automatic.
>

Not sure what you mean, but have other pressing projects to work on right now. 
Will look into it further in the future when I have the time available.

As per above, VLC is a make or break for me - but others (eg: gamers) would 
benefit from detaching GPU from Dom0 and attaching GPU to their games domain 
qube, if it meant that OpenGL could then be available to the attached qube

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/ba60d101-38e9-479d-a8f0-422fa7b2cd34%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Install software inside dom0

2017-08-22 Thread Phil
>How can I delete all other partitions and resize Qubes to use all the hd?

I haven't done it with Qubes, but usually I use a live CD for that sort of job. 

Cheers

Phil Hobbs

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/d3cd8ed3-a69c-4aa7-b5f4-5855f39b103a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Installer Bug - has not been fixed since I reported it in Qubes 2.0 installer.

2017-08-22 Thread jespernexojorgensen
On Friday, June 24, 2016 at 12:11:21 PM UTC+2, Drew White wrote:
> Text based install.
> This issue has not been fixed since I reported it in Qubes 2.0 installer.
> 
> 
> 
> 
> INSTALLATION DESTINATION
> 
> 
> (LVM, LVM Thin Partitioning)
> ERROR AS FOLLOWS..
> 
> storage configuration failed: autopart failed:
> 
> Encryption requested for LUKS device sda2 but no encryption key specified for 
> this device.
> 
> 
> 
> 
> 
> 
> (Standard, Btrfs Partitioning)
> 
> 
> 
> storage configuration failed: autopart failed:
> 
> Encryption requested for LUKS device sda2 but no encryption key specified for 
> this device.
> Encryption requested for LUKS device sda3 but no encryption key specified for 
> this device.
> 
> 

Hi all.

This it stilla an issue. Ive created a VM in Virtualbox - the graphical 
installer does not show up, and the text based installer fails. This has been a 
serious problem since 3.1.

I realise this is described in 
https://github.com/QubesOS/qubes-issues/issues/2113 - but this is not a 
solution - its a bad workaround.

When will anyone take this problem seriously?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/63220b93-b7ee-415d-864a-cf7e42817829%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Installer Bug - has not been fixed since I reported it in Qubes 2.0 installer.

2017-08-22 Thread Alex
On 08/22/2017 01:46 PM, jespernexojorgen...@gmail.com wrote:
> This it stilla an issue. Ive created a VM in Virtualbox - the graphical 
> installer does not show up, and the text based installer fails. This has been 
> a serious problem since 3.1.
> 
> I realise this is described in 
> https://github.com/QubesOS/qubes-issues/issues/2113 - but this is not a 
> solution - its a bad workaround.
> 
> When will anyone take this problem seriously?
Since it's not a problem in Qubes itself, but in anaconda (please see
https://bugzilla.redhat.com/show_bug.cgi?id=1020345 as linked by
https://github.com/QubesOS/qubes-issues/issues/1161) and since it has
been closed as wontfix with the dry statement "LUKS configuration is not
available in text mode", I see it highly unlikely that it will be ever
fixed.

The bug in Qubes tracker may itself be considered closed once the text
mode setup will be disabled and a feature request is opened for a text
mode setup, which will get a very low priority and hang on indefinitely
because of the impossibility of setting up LUKS in text mode. Some
project managers may prefer having a pending feature request than having
a pending bug.

As a side remark, please note that installing qubes in a VM is obviously
and clearly stated as unsupported and most likely will produce bug
chains like the one you are encountering, which should originate with
the inability to load the "vboxvideo" X driver (thus the text mode
install attempt, that fails on LUKS). Please test Qubes on a spare
physical PC: it also makes very little sense to try to use it as a
production OS in a virtualized environment. If you need a virtualization
host OS you can try the free ESXi, Proxmox or other alternatives to those.

-- 
Alex

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/935c3fef-bb38-e8e0-0ce8-ba7fc0a6aad0%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: OpenPGP digital signature


Re: [qubes-users] Re: Installer Bug - has not been fixed since I reported it in Qubes 2.0 installer.

2017-08-22 Thread jespernexojorgensen
Thanks for a quick reply Alex :-)

I think that most people would test Qubes OS (or any other new OS) in a VM 
before wiping a physical machine - and a lot of people probably dont even own 
spare physical machines, these days...so making it work within another 
hypervisor would make good sense. The docs does say that it is unsupported, but 
usually that doesnt mean "completely unusable" ;)

Perhaps just a meaningful error message would help people figure out why the 
installer seems to crash and/or behave like some buggy app. A project manager 
that disguises bugs like this as a low-prio feature req..well..hmm.. ;)

I guess the next step would be to see if VMWare will work with the graphical 
installer :)

Thanks for the explanation!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/289a3614-d736-422b-8897-158c7d68ea47%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: Installer Bug - has not been fixed since I reported it in Qubes 2.0 installer.

2017-08-22 Thread Alex
On 08/22/2017 02:15 PM, jespernexojorgen...@gmail.com wrote:
> I think that most people would test Qubes OS (or any other new OS) in
> a VM before wiping a physical machine - and a lot of people probably
> dont even own spare physical machines, these days...so making it work
> within another hypervisor would make good sense. The docs does say
> that it is unsupported, but usually that doesnt mean "completely
> unusable" ;)
It makes no sense in trying to make Xen work as a vm guest; Xen people
themselves said that they are not going to support that (sorry but I
don't have a link to that discussion at hand), and Qubes recently
(couple years at least) added the ability to be tested as a live distro
without touching the working OS installed.

Even if you manage to start anaconda/X, you'll probably encounter many
problems with Xen.

And yes, usually when you see "unsupported" it means "barely exists",
and it not only applies to Qubes but a lot of other things too - not
just software!

> Perhaps just a meaningful error message would help people figure out
> why the installer seems to crash and/or behave like some buggy app. A
> project manager that disguises bugs like this as a low-prio feature
> req..well..hmm.. ;)
Since it's actually not a bug in qubes the ticket could be just closed,
the text setup disabled, and that would be all. But not to lose the
detailed info about the issue, I think a nice thing to do to the users
that had experienced the problem would be reopening the issue as a
feature request. But I'm usually told that I'm too nice of a project
manager towards user requests.

Have a nice test (please consider the live cd / usb instead of virtual
machines!)

-- 
Alex

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b5bafb07-0304-50d1-b04e-e64b142668de%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


signature.asc
Description: OpenPGP digital signature


Re: [qubes-users] Re: Opening links in your preferred AppVM

2017-08-22 Thread John Maher
On Monday, August 21, 2017 at 11:14:15 AM UTC-4, John Maher wrote:
> On Tuesday, May 2, 2017 at 1:14:47 PM UTC-4, Gaiko wrote:
> > Thanks for the reply!
> > 
> > 
> > my ~/.local/share/applications/mimeapps.list is a bit different than yours, 
> > really I was most interested in it handling http/https 
> > 
> > 
> > [Default Applications]
> > text/html=open_work_vm.desktop
> > x-scheme-handler/http=open_work_vm.desktop
> > x-scheme-handler/https=open_work_vm.desktop
> > x-scheme-handler/about=open_work_vm.desktop
> > x-scheme-handler/unknown=open_work_vm.desktop
> > 
> > 
> > I tried just copying/pasting yours into mine (just for kicks) but that 
> > didn't work either :(
> > 
> > 
> > 
> > 
> > 
> > 
> > On Tue, May 2, 2017 at 4:36 AM,   wrote:
> > Gaiko  [2017-05-02 03:36 +0200]:
> > 
> > > > What happens if you run `qvm-open-in-vm work https://qubes-os.org` in
> > 
> > > > tbirdVM
> > 
> > >
> > 
> > > it seems to work just fine that way
> > 
> > >
> > 
> > > > and when you run xdg-open https://qubes-os.org in the work VM
> > 
> > > > (without the quotes)?
> > 
> > >
> > 
> > > ok, xdg-open I hadn't tried. But regardless this seems to work fine as 
> > > well.
> > 
> > 
> > 
> > Good! That means qvm-open-in-vm (sending the link to the work VM and
> > 
> > telling it to open it) and opening it internally in the work VM
> > 
> > works as intended.
> > 
> > 
> > 
> > What does ~/.local/share/applications/mimeapps.list in tbird look like?
> > 
> > It should look like this (from the mentioned how-to):
> > 
> > 
> > 
> >         [Default Applications]
> > 
> >         x-scheme-handler/unknown=open_work_vm.desktop
> > 
> >         x-scheme-handler/about=open_work_vm.desktop
> > 
> >         x-scheme-handler/http=open_work_vm.desktop
> > 
> >         x-scheme-handler/https=open_work_vm.desktop
> > 
> >         text/html=open_work_vm.desktop
> > 
> >         text/xml=open_work_vm.desktop
> > 
> >         image/gif=open_work_vm.desktop
> > 
> >         image/jpeg=open_work_vm.desktop
> > 
> >         image/png=open_work_vm.desktop
> > 
> >         application/xhtml+xml=open_work_vm.desktop
> > 
> >         application/xml=open_work_vm.desktop
> > 
> >         application/vnd.mozilla.xul+xml=open_work_vm.desktop
> > 
> >         application/rss+xml=open_work_vm.desktop
> > 
> >         application/rdf+xml=open_work_vm.desktop
> > 
> > 
> > 
> > Remove the lines for any MIME types you don't want to open with your
> > 
> > work VM.
> > 
> > 
> > 
> > --
> > 
> > ubestemt
> 
> Gaiko, did you get this to work? I have the exact same experience. And 
> placing the files in /usr/share/applications did not help. 
> 
> When running "desktop-file-validate browser_vm.desktop" from ~/. I get "file 
> does not exist". From ~/.local/share/applications I get 'browser_vm.desktop: 
> warning: key "Encoding" in group "Desktop Entry" is deprecated', similar to 
> you.
> 
> Thanks.
> John

Well, I got this to work mostly as desired. Turns out that even after running 
"xdg-settings set default-web-browser browser_vm.desktop" (and confirmed with 
"xdg-settings get default-web-browser"), I had to remove all .desktop files in 
the working VM (not the browser VM) related to Chrome and Firefox. That 
included files located in ~/.local/share/applications and in 
/usr/share/applications.

Unfortunately, I really want to use Firefox in the browser VM, but only Chrome 
will launch. Still working on addressing that.

John

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9bc3c2b2-32f4-45c7-b1d9-8f9a6e809f76%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Windows 7 problems (R3.2)

2017-08-22 Thread Hugo Costa
On Tuesday, 22 August 2017 06:54:44 UTC+1, Drew White  wrote:
> Try installing as a template then. see if that helps?
> SP1 has SP1, and is still missing about 1.* GB of updates.
> 
> If you update, it may help too.
> 
> Try tools version 3.0.2
> 
> I have the latest installed in my Win7 Standard Edition on my PC here, and it 
> runs seamless with all the perks no issue. It's only on 30 day trial until I 
> enter my key, only trial because i am currently just testing things out 
> before i use my key again.

> > I've also noticed a new error. Qubes is unable to start the qrexec-daemon.
> > 
> 
> That is normal, you will need to use qvm-prefs to set the timeout to maybe 
> 120 seconds. Depends how long it takes for your win7 guest to boot. mine 
> takes 12 seconds but i still have it set to 120 seconds timeout incase 
> sometimes i have overloaded win7 and it takes forever to boot, or has to do a 
> scan or an update install.

Yeah I had that at 300, didn't work either even when the system was fully boot 
up.

For now I tried with Windows Ultimate x64 with and without the most recent 
updates (w SP1), with the latest and the 3.0.2 versions of the Win Tools. 
Neither worked. I'll just give up and use it as a non seemless HVM, it does 
what I want.

Thank you!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4d6f2d44-0755-4bf5-b11f-0de0b8c868ba%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] GPU is deal-breaker

2017-08-22 Thread Matty South
On Tuesday, August 22, 2017 at 4:10:57 AM UTC-5, cdga...@gmail.com wrote:
> > > Summary: Deal-breaker probably is down to getting VLC working
> > > properly
> > >
> >
> > did you tried to switch video output?
> > I would start with X11 instead of automatic.
> >
> 
> Not sure what you mean, but have other pressing projects to work on right 
> now. Will look into it further in the future when I have the time available.
> 
> As per above, VLC is a make or break for me - but others (eg: gamers) would 
> benefit from detaching GPU from Dom0 and attaching GPU to their games domain 
> qube, if it meant that OpenGL could then be available to the attached qube

When you have more time to look into this again, looks like this guy was able 
to pass his GPU through to his Windows HVM: 
https://www.reddit.com/r/Qubes/comments/66wk4q/gpu_passthrough/ 

Might be an option for you. You could Skype/VLC in your Windows VM. I use my 
WinVM do to Sharepoint and MS Office stuff and it works pretty well. Good luck!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/e099f4be-7310-4553-88cf-c536774fbdac%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Problem connecting via VPN ProxyVM (VPN works, but AppVM can't connect)

2017-08-22 Thread Chris Laprise

On 08/21/2017 07:32 PM, PhR wrote:


Chain ciscovpn (3 references)
target prot opt source   destination
ACCEPT all  --  anywhere anywhere state 
RELATED,ESTABLISHED

ACCEPT all  --  anywhere anywhere
ACCEPT all  --  anywhere anywhere
ACCEPT udp  --  anywhere anywhere udp 
spt:bootpc dpt:bootps
ACCEPT udp  --  anywhere anywhere udp 
spt:bootps dpt:bootpc
ACCEPT udp  --  anywhere anywhere udp 
spt:dhcpv6-client dpt:dhcpv6-server
ACCEPT udp  --  anywhere anywhere udp 
spt:dhcpv6-server dpt:dhcpv6-client
ACCEPT tcp  --  10.137.2.26  213.xxx.xxx.xxx   tcp 
dpt:https
ACCEPT tcp  --  213.xxx.xxx.xxx   10.137.2.26  tcp 
spt:https
ACCEPT udp  --  10.137.2.26  213.xxx.xxx.xxx   udp 
dpt:https
ACCEPT udp  --  213.xxx.xxx.xxx   10.137.2.26  udp 
spt:https

RETURN all  --  10.137.2.26  anywhere
RETURN all  --  anywhere 10.137.2.26
RETURN all  --  10.137.2.26  10.137.2.26
RETURN all  --  10.137.2.26  10.137.2.26
RETURN udp  --  10.137.2.26  224.0.0.251  udp 
dpt:mdns
RETURN udp  --  10.137.2.26 after launching it I can 
224.0.0.251  udp dpt:mdns
RETURN udp  --  10.137.2.26  239.255.255.250  udp 
dpt:ssdp
RETURN udp  --  10.137.2.26  239.255.255.250  udp 
dpt:ssdp

RETURN all  --  anywhere base-address.mcast.net/4
RETURN all  --  10.137.2.26  base-address.mcast.net/4
RETURN all  --  anywhere 255.255.255.255
RETURN all  --  10.137.2.26  255.255.255.255
RETURN all  --  172.21.2.13  a.de/24
RETURN all  --  isys-team.de/24  172.21.2.13
RETURN all  --  172.21.2.13  192.168.3.0/24
RETURN all  --  192.168.3.0/24   172.21.2.13
RETURN all  --  172.21.2.13  10.5.48.0/24
RETURN all  --  10.5.48.0/24 172.21.2.13
RETURN all  --  172.21.2.13  192.168.5.0/24
RETURN all  --  192.168.5.0/24   172.21.2.13
RETURN all  --  172.21.2.13  192.168.100.0/24
RETURN all  --  192.168.100.0/24 172.21.2.13
RETURN all  --  172.21.2.13  vsrv-dc-3.xxx.yyy.de
RETURN all  --  vsrv-dc-3.xxx.yyy.de   172.21.2.13
RETURN all  --  172.21.2.13  vsrv-dc-2.xxx.yyy.de
RETURN all  --  vsrv-dc-2.xxx.yyy.de   172.21.2.13
RETURN udp  --  172.21.2.13  anywhere udp 
dpt:domain
RETURN udp  --  anywhere 172.21.2.13  udp 
spt:domain

RETURN all  --  anywhere 255.255.255.255
RETURN all  --  172.21.2.13  255.255.255.255
DROP   all  --  anywhere anywhere
DROP   all  --  anywhere anywhere

Chain ciscovpnfw (3 references)
target prot opt source   destination



First, I surmise that 10.137.2.26 is the proxyVM address, not appVM.

Its hard to see the problem clearly because of the complexity of what 
its adding, but I think your appVM packets are probably hitting the 2 
DROP targets at the end of 'ciscovpn' chain. This may be because the 
chain explicitly allows packets from 'source' address of your VPN 
proxyVM, but there is nothing explicitly in that chain allowing 'source' 
addresses for downstream appVMs. This is a problem when 'ciscovpn' chain 
is called from the FORWARD chain.


As a test remedy you could try the following in the proxyVM (_after_ 
your appVM is already running):


$ sudo iptables -I FORWARD -i vif+ -j ACCEPT

...then try connections from the appVM.

This will cause anything coming from downstream VMs to be accepted for 
forwarding (which is OK if you don't intend to use Qubes firewall 
restrictions in appVM Settings). A full long-term solution would involve 
reconciling the cisco firewall commands with the Qubes firewall service 
(would be ideal if Anyconnect used a firewall script and it could be 
located in the system, then you could have the right commands issued 
from /rw/config/qubes-firewall-user-script).




I have already tried to use the openconnect plugin for network 
manager, but when I click on Add in the network manager and choose VPN 
and then "Cisco AnyConnect Compatible VPN (openconnect)" I get a new 
windows but can't add any information here as every field looks 
disabled :-/ ?

Working with OpenConnect would be great.


There is also a GUI part that needs to be installed: 
NetworkManager-openconnect-gnome in Fedora.


I also thought that is Qubes Best practise to use a dedicated VPN 
Proxy VM vs. launching VPN from within an AppVM ?




Should be OK for a work-only VPN where your appVM is also work-only; Its 
a different threat model than an Internet-focused VPN.


-

Finally, I should mention leak prevention measures. If you are able to 
get the VPN to function with proxyV

[qubes-users] Re: Suggestions for video card

2017-08-22 Thread Gallandae
2017-08-20 17:18 GMT+02:00 cooloutac :

> On Sunday, August 20, 2017 at 10:05:39 AM UTC-4, gall...@gmail.com wrote:
> > On Sunday, July 23, 2017 at 3:02:43 PM UTC+2, Fun Zork wrote:
> > > On Friday, July 21, 2017 at 7:05:56 PM UTC-4, pixel fairy wrote:
> > > > have you tried the 4.0 alpha? thats based on fedora 25, which should
> be able to use the 1080.
> > >
> > > No luck.  I get the same results as I get after I update to the
> current-testing kernel- it reboots right after X tries to start, without
> logging anything whatsoever.  I am no expert, but from what I can glean,
> 3.2 out of the box has two issues with the 1080: the default kernel doesn't
> support it and Xen doesn't support it.  Updating the kernel gets you past
> that issue, but there still is an issue from Xen, even after updating it to
> 4.6.5.  That's my working theory anyways.
> > >
> > > In any case, I ordered a 7750.
> >
> >
> > I am also looking for ways to have a 4K 60Hz (with 4:4:4, a must for PC
> use)  TV (43" so I don't care about DPI) running Qubes 3.2 with latest 4.9
> kernel.
> >
> > I'll have to buy a video card, and I was looking at the AMD RX560 (which
> is Polaris 11) since it does have true 4:4:4 4K60 HDMI 2.0 and Dom0 with
> kernel 4.9 has the module for Polaris 11 (see /lib/firmware/amdgpu/), so
> that side is covered.
> >
> > The problem comes from kernel 4.9 release notes, where it says they
> added AMDGPU but to use it: "you'll need X.Org Server 1.19.0 and
> xf86-video-amdgpu 1.2.0 too."
> >
> > And this seems to be a problem because Qubes 3.2 Dom0 is Fedora 23
> based, which has Xorg 1.18.3, and lacks X driver for amdgpu (see
> https://apps.fedoraproject.org/packages/xorg-x11-drv-amdgpu/overview/).
> >
> > Maybe this is why X can not start on your case.
> >
> > Does anybody have a RX5* AMD card working on Qubes (even if not at 4K)?
> How? Xorg.0.log please?
>
> I have an nvidia 650 ti that works fine with qubes.  I would just get any
> card that was released 3 or more years ago, that supports 4k resolution.
> Get the cheapest one.


Thanks for the tip. Unfortunately the Nvidia 650 TI does only 4K 30,
otherwise it looked good.

Another option would be to upgrade the whole PC, since my Intel i7 didn't
have VT-d (required now for Qubes 4.0), so since I'm not going to play
games/3D I could go by with a recent i7-6* or i7-7*, whose DisplayPort does
support 4K60 4:4:4.

But that means: CPU + mobo + memory, so while Qubes 3.2 lasts, I'd rather
just get a supported 4K60 video card.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAFZgHW5S6GDihTBBx-q8SCk%2BA4GRiy17Fc1p4uuL4Yu5r8kYgQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Unofficial forward-ported grsec 4.9 Qubes kernel branch

2017-08-22 Thread nicholas roveda
Why the repo can't be cloned without credentials?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/3b475e97-de19-4819-90ad-138ab4ff74ff%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Qubes-R4.0-rc1-x86_64 how to Install a Browser

2017-08-22 Thread QubesOS-ML

hello
maybe a strange question, but how do i install a Webbroser?
have a nice day
vinc

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/2721a1bbac80eeeb5845f284a3b7fc87%40kozo.ch.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Qubes-R4.0-rc1-x86_64 how to Install a Browser

2017-08-22 Thread Yethal
W dniu wtorek, 22 sierpnia 2017 19:59:39 UTC+2 użytkownik QubesOS-ML napisał:
> hello
> maybe a strange question, but how do i install a Webbroser?
> have a nice day
> vinc

Fedora 25 template should come with Firefox preinstalled.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4845ea26-5e63-4a68-b1ef-854dade6c69b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Windows 7 HVM: how to remove Users-Folder-Redirection?

2017-08-22 Thread Yethal
W dniu wtorek, 22 sierpnia 2017 02:05:41 UTC+2 użytkownik PR napisał:
> Hello,
> 
> I would like to remove the redirection which has been made by Qubes Tools:
> 
> C:\Users --> E:\Users
> 
> As I can't run this within windows is there any trick to remove the link 
> without booting up a 2nd OS?
> 
> Next question is, what is the downside if I have my USERS-folders on c:\ 
> instead of e:\
> 
> - PhR

Users folder is moved to the E:\ drive so every AppVM created from this HVM can 
have its own Users directory

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/58cfb5f0-787b-4f3e-844d-75b5ae7c438a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: Install software inside dom0

2017-08-22 Thread Gecko
It didn't let me do the gparted install. I have since given up. I have decided 
to wipe the qubes os partition, go back to windows, connect another computer 
using ethernet, backup my files, then wipe the hard drive, and maybe try to 
install qubes again.

There seems to be too many issues with qubes. I'm doubting whether it's worth 
the effort. Maybe a live CD + Encrypted USB will perform just as good. A lot 
easier to manage and copy files etc.

Thank you for trying to help though. Maybe I should look for an OS that doesn't 
use your graphics card as a paper weight.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/3b2fa6d7-128d-4ce7-b917-3b6ca3e3f520%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Audio broken in 4.0 rc1

2017-08-22 Thread nicholas roveda
I've used Qubes 3.2 and everythings there worked fine, but now I'm trying 4.0 
rc1 and I can't figure out why the sound doesn't work.

`qvm-pci` reports 2 Intel Audio Devices (00:03.0  and 00:1b.0), so I've tried 
to attach them to an base AppVm, such personal and start it with `qvm-run`, but 
it returns:
"Start failed: internal error: libxenlight failed to create new domain 
'personal'",
while without those audio devices the VM starts without any ptoblems.

Is there an issue with the rc1, since my hardware is not old and it worked fine 
with 3.2?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1e032119-1291-4b27-86e0-811949323358%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.