Ssh security with hosts.allow

2004-10-25 Thread Steve Warwick
Hi All, Since implementing a hosts.allow "deny" on SSHD for all but my IP I am seeing a slew of ssh attempts from overseas. My questions are: Is a good password and hosts.allow enough to keep out the bad guys? Is this normal? (I assume these attempts are automated) Thanks Steve

Extra sendmail processes after install of spamassassin 3.0.1

2004-10-25 Thread Steve Warwick
Hi All, I have started seeing a problem with "extra" sendmail processes since upgrading to SpamAssassin 3.0.1 from 2.63 yesterday. I would normally have only a few sendmail processes at any one time unless I am mailing out. Now I seem to get an extra 20 or so extra after a while. They seem to be

How to mirror

2003-09-23 Thread Steve Warwick
Hi All, It would appear my FreeBSD 4.8 server is down again due to another HD crash but that's a whole other problem. However the related question is - what is the standard way to mirror a server? I will need to mirror mail, dns, apache and MySQL so that if one machine goes down, the other will

Something rotten in the OS?

2003-08-22 Thread Steve Warwick
Hey All, I have just had my 2nd HD crash in a year - different machine, different type of drive etc - the only consistency is the OS and the installed software. It looks like this is some kind of overflow This problem seems to start after about a month and is indicated by there being fragme

Kernel about to crash?

2003-07-22 Thread Steve Warwick
Hi All, My daily security run is starting to show pieces of the kernel config file it's kernel log messages - when this happens the OS starts to use up more and more swap space too. Last time this happened I let it go and the server went down so I have been rebooting if I see this happening and a

Freebsd - restarting itself?!

2003-03-24 Thread Steve Warwick
Hi All, Is it possible for FreeBSD to shut itself down and restart for no reason? My machine was restarted last night and my hosting company claims they did not touch the server or have any problems. This has been going of for a few months now -- intermittent restarts that no one claims responsi

Ifconfig - no aliases?

2003-03-12 Thread Steve Warwick
Hey All, Can some bright spark spot a mistake in this? For some reason I cannot get my NIC aliases to come up. Everything looks fine but no go. Here are the entries in rc.conf for the card (the first two digits are xx'd for this email): hostname="not-sharing-that-rightnow" defaultrouter xx.10

nasty HD crash -- can any one help with suggestions?

2003-03-11 Thread Steve Warwick
Murphy struck with a vengeance this morning. I have all my clients data on drive 2 in my server (why, because I was about to do a machine / OS swap). However, for some reason the second drive went down raaaly hard early this morning, some 4-5 hours before the changeover. So the question is, c

SMTP-AUTH + SSL - Possible?

2003-03-10 Thread Steve Warwick
Hi All, I am looking at ways to provide my clients with more convenience. One of those ways is to be able to send and receive email via my server. However, I know this can be a huge security hole and not one I would like to open. I feel that SMTP-AUTH without SSL is probably not that secure so -

Upgrade to 4.7 possible?

2003-02-28 Thread Steve Warwick
Hi again, I am looking at (finally) upgrading from 4.3 to 4.7 and before I dive in, has anyone had the pleasure of doing this? Did it go OK? Are there any gotchas to watch out for? Suggestions and upgrade experiences welocome :) Steve To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsu

Sendmail - blackhole da spam?

2003-02-28 Thread Steve Warwick
Hey All, I seem to be getting more spam lately and in an effort to protect my clients I use a catch all in the the virtuser table @domain-name.ext error:nouser However, this is resulting in more traffic as the spam needs to be bounced back out, to a server that refuses the mail and so on. Ques

Deleting a soft link that points to a directory - how?

2003-02-26 Thread Steve Warwick
Hey All, I cannot seem to delete a soft link (ln -s) that is pointing to a directory without renaming the directory first. If I try to delete the link it complains that the link is a directory (which it is pointing to). If I delete using rm -rf, it deletes the directory that is pointed to but not

Moving sendmail mail files

2003-01-29 Thread Steve Warwick
Hi All, I am trying to move Sendmail mail files from /var/mail to each users home directory (this will help with back up and disk space). However, I have not managed to get sendmail to recognize the new mail file location. Any suggestions? TIA Steve To Unsubscribe: send mail to [EMAIL PROTE

Mail: operation timed out... Why?

2003-01-14 Thread Steve Warwick
Hi All, I have mail stacking up in the outbound mail queue all with the same error: "Deferred: Operation timed out with " I have gone through my configs and everything looks correct. Could some one tell me what could cause this error as I have checked everything I can think of. The only thing

Bazillion kernel messages?

2003-01-09 Thread Steve Warwick
I have a bazillion of these kernel messages showing up in my logs... Jan 9 13:53:30 la last message repeated 7 times Jan 9 13:59:21 la /kernel: arp: 00:05:32:0e:64:12 attempts to modify permanententry for 12.158.234.65 on rl0 I know rl0 is my ethernet but I don't host the .65 address. I have no

DNS / Sendmail

2003-01-09 Thread Steve Warwick
Hi All, After moving a site to a new server I am having an email/DNS problem. Hopefully some kind soul can help as I cannot seem to fix this. --- I am using PHP to send email to the website users at they request (reminders etc). Apache runs as user nobody. Server is la.mylocalnet.com on 12.158.

Port 4976 ?

2002-12-30 Thread Steve Warwick
Hi All, Just checking my security and noticed port 4976 is open. I cannot find a listing / notation for this and it appears to be under named - do I need this? Sockstat -4 output root named 864 udp4 *:4976 root named 86 20 udp4 12.158.234.68:53 *:* root n

Pw - name too long ??

2002-12-30 Thread Steve Warwick
Hi All, I am trying to add a user name with the pw command and get the "name too long" error after 15 or 16 characters. However, I also use Webmin which has allowed me to use much longer user names. Is there a switch or setting I am missing? Example: pw adduser longdomain-henry2 -w random -d "/h

Pw - name too long ??

2002-12-29 Thread Steve Warwick
Hi All, I am trying to add a user name with the pw command and get the "name too long" error after 15 or 16 characters. However, I also use Webmin which has allowed me to use much longer user names. Is there a switch or setting I am missing? Example: pw adduser longdomain-henry2 -w random -d "/h

Re: Separating the OS from the data [Addendum]

2002-10-31 Thread Steve Warwick
[Addendum] Cvsup / makeworld: I apologize for missing that piece of information Yes, I could use the usual update procedure, however, this is a production machine. So my thought is: build a new OS on a staging machine, add required symlinks, pull the drive (sled) and slot it into the production m

Separating the OS from the data - tough to do?

2002-10-31 Thread Steve Warwick
Hi, -- Problem: Separating OS from underlying data. Which parts of the BSD OS are not part of the initial, never modified OS? Or, which pieces of the OS change due to useage. -- Goal: To have a slightly modified BSD OS structure where the OS can be upgraded, yet the variable data remains the un

Sendmail: non-relay & secure

2002-10-30 Thread Steve Warwick
Hi, I have sendmail / qpopper running on a production machine and have yet to figure out a way to open mail up to my client sin a secure way. Eg. Client logs in from aol.com to check and send mail. Is there a way to do this that will not open my machine up to abuse? TIA Steve To Unsubscri

Apache will not start on new setup

2002-10-29 Thread Steve Warwick
Hi, Apache will not start. New BSD 4.7 installation. la# apachectl configtest Syntax OK la# apachectl start /usr/local/sbin/apachectl start: httpd could not be started la# httpd.config only has one virtual host, the directory and index.html file exist for the host, there are no log file entrie

2 drives + 2 IDE channels = better?

2002-10-29 Thread Steve Warwick
Hi, Is is better to run a 2nd drive on another IDE channel or on the same bus? Eg. IDE channel 1 = ad0 (main OS), IDE channel 2 = ad1 (other data - maybe MySQL and websites?) Thoughts, opinions? TIA Steve. PS. Is it obvious I'm building a new machine :) To Unsubscribe: send mail to [EMAIL

Re: Yes, but how do I upgrade?

2002-10-29 Thread Steve Warwick
Hmmm, if as Kent mentions, there are many changes since 4.3, perhaps a better solution would be to reverse the process. Build an entirely new OS from 4.7 and then move all the "personal/client" files into that? Thoughts? Steve > Doug Poland wrote: >> Steve Wingate said: &

Yes, but how do I upgrade?

2002-10-29 Thread Steve Warwick
Hi I have a 4.3 BSD machine to upgrade, and it's a production machine :( On a test machine I have learned to CVSUP. I have used sysinstall and played around with the "upgrade" potion of the menu. I have configured, built and installed the kernel a few times. Ok, got that, but how do I upgrade?

OS upgrade planning?

2002-10-23 Thread Steve Warwick
Hi All, Thanks to everyone for their help with my odd problems. This is just a "venture an opinion if you have a moment" question. Problem: need to upgrade FreeBSD 4.3 on a production machine. My plan so far - feel free to shoot this down :P DEFINITIONS: - Drive1/Master = D1 - Drive2/Slave = D

UDMA limited to 33 - resolution

2002-10-23 Thread Steve Warwick
placement of the UDMA100 Master and the UDMA66 Slave on the bus and all items were recognized correctly. Master is now last on the chain. hth Steve Warwick To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-questions" in the body of the message

Setup: UDMA133 - recognized?

2002-10-22 Thread Steve Warwick
Hi, I noticed that during boot ad0 is "limited to UDMA33" - I have UDMA133 motherboard and drive so, is this really true? TIA Steve To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-questions" in the body of the message

Chroot SSH

2002-10-22 Thread Steve Warwick
Hi, I have been looking through the docs to see how I can chroot SSH sessions in the same way as FTP (using proftp). ie when a user logs in they can only play in their home directory. Is it possible? TIA Steve To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-question

Oops! rc.conf mistake

2002-10-21 Thread Steve Warwick
Hey all, I wonder if anyone can tell me how to get out of this stupid mistake. I edited rc.conf to add a virtual interface and left a quote off the end (unterminated string) - now I cannot get past mounting root, so no editors. And before you ask, no, I did not backup rc.conf... I told you it wa

"Make" always fails on new system

2002-09-30 Thread Steve Warwick
Hi All, Just starting a new system and every attempt to build / make anything fails with some kind of LD failure, followed by signal 11 errors. The install of the system seemed to go fine. Any suggestions what I have missed? -- New install: 4.6.2 from floppy / FTP On Athlon 1600 / shuttle AK3