00:26<synapt>I can't recall if I asked this in here yet or not, but I figure there are some tech-saavy cPanel users in here. Any of you manage to get PHP-FPM+Apache working without a ton of effort under cPanel? And/or also got SPDY with apache working under cPanel?
01:07<zifnab>synapt: does 'tech-saavy' and 'cpanel' ever go together?
06:36<Peng>Please don't do that.
07:22<AlexC_>koodit: No, you only need to do what if you want to use Linode DNS service. Which I would suggest you do, as it's a great service
07:23<koodit>ok, but then how wold i keep my emails working on godaddy?
07:23<AlexC_>koodit: Keep/configure the MX record so that point to GoDaddy
07:24<jimgroome>koodit: Sounds like you set the nameserves to Linode, which is what it tells you to do in the documentation
07:24<koodit>yeah exactly+
07:24<AlexC_>Your domain registrar, nameservers that you use, and server, are all separate. You could have your domain registered with GoDaddy, your nameservers with Company X and your server with Linode
07:24<AlexC_>koodit: What is your domain?
07:25<jimgroome>What I'd do: Log in to the Godaddy DNS panel and see if it's kept the (now overridden) MX records. Then log in to Linode's DNS manager and set the MX records to what they were on Godaddy
07:25<koodit>my domain is
07:25<AlexC_>jimgroome: He's not using Linode DNS
07:26<AlexC_>koodit: You have 2 options. Keep using the nameservers you're using, and edit the DNS records there. Or use ns[1-5] and use Linode DNS
07:26*jimgroome shuts up
07:28<koodit>this looks more clear now, so basically the options are [Godaddy Domain with A record to Linode IP] and [Godaddy domain with NS records to Linode Dns + Linode Dns Mx record to godaddy
07:29<AlexC_>Which ever solution you pick, the DNS records would be the same
07:32<koodit>ill try, thanks for your help guys, much appreciated
08:03-!-Yaazkal [] has joined #linode
08:07<Issa>where is your data center?
08:07<Issa>I need to take vps do you have any discount?
08:08<Issa>Do you have one in Amsterdam?
08:08<Peng>No, but it is in London.
08:09<Peng>One of them is, anyway.
08:09-!-Cromulent [] has quit [Quit: KVIrc 4.2.0 Equilibrium]
08:09<Peng>Issa: AlexC_'s link above lists the locations.
08:10<Issa>is the money always $
08:10<Issa>do you have VAT on top or it's including?
08:11<Peng>No VAT.
08:11<Issa>how about the backup?
08:12<Issa>I want to use for small open source search engine
08:27-!-stevepiercy is now known as stevepiercy_away
08:28<buhman>heh, never realized DO's disk space doesn't increase geometrically with price.
08:28<Peng>Me neither. 20 GB for $5 is pretty nice though.
08:30<pronto>i've heard some pretty bad reliability issues with DO (...from NOT linode elitists/fanpeople)
08:32-!-bbankes [] has joined #linode
12:10<synapt>That actually sounds like a great career choice
12:10<synapt>he got 60k to do the kill, and only had to pay a 10k fine for not doing it?
12:11<synapt>50k in the pocket while the original dude gets 2 years
12:11<synapt>shit I'm about to move there and start doing that
12:12<@rohara>I bet his reaction will be awesome when the contractor gets out of prison in two years.
12:12<synapt>dude will probably be gone after screwing a few more people out of 60k :P
12:12<synapt>off to some nice island country
12:13<Nivex>doubt he can pull that off twice. his name will be pretty well known
12:14<synapt>I imagine 50k can get you a different name :P
New news from forum: Traffic between nodes in Linux Networking
New news from forum: Traffic between nodes in Linux Networking
New news from forum: Email Issues After Moving Domain to New Linode in Email/SMTP Related Forum
13:06<Yaakov>I hate computers and everything about them.
13:07<MotoHoss>so the ipv6 addy in the remote access tab do I just add that address verbatim to the eth0 interface with the ip command... (and to make it permanent put it in the interfaces file)?? using the linode docs -
13:09<zifnab>akerl: its definitely enabled, 'xl dmesg' shows 'Type ctrl-a three times to switch input to xen'
13:10<akerl>I feel like the secret is the serial input bit, then
13:11<zifnab>yeah i guess, wonder if i can fake a serial device
13:12<akerl>Could just loop it?
13:12<zifnab>i'm demoing something on an thinkcenter, lack of any real ports
13:12<akerl>attach to /dev/ttySO?
13:12<akerl>screen should know how
13:14<zifnab>cool, now to just actually set it up to use that serial
13:16<MotoHoss>one confusing thing I have is one of my nodes ahs nothing ipv6 related in the interfaces file and the one I am attempting to configure... the ip acommand says there is no 'global' scope v6 address. :(
13:17<akerl>These are two Linodes?
13:17<synapt>I know this might be an odd question to ask #linode but, anyone have any remote-desktop software suggestions that are entirely local-based (ie; not teamviewer like), and can be multi-platform? :P
13:17<MotoHoss>two linodes.
13:17<akerl>So one of them has working IPv6 but nothing about v6 in the network config files, yes?
13:31<MotoHoss>oky, thanks akerl
13:32<nthint>if I have 3 websites, 2 WP blogs and 1 SF app, what happens if I have such an issue in my SF app? The other 2 websites will be affected?
13:32<akerl>MotoHoss: When you turn that on, it stops your system from accepting Router Advertisements, which are how StateLess Address AutoConfig works
13:32<nthint>is it possible to limit resources for this SF app while I am debugging it?
13:59-!-stevepiercy is now known as stevepiercy_away
14:03-!-stevepiercy_away is now known as stevepiercy
14:04<MotoHoss>very nice akerl, thank ye.
14:05<MotoHoss>didn't even have to reboot..
14:06<zifnab>dat xl
14:06<zifnab>or however they're doing it
14:06-!-lionmac [~lionmac@] has quit [Remote host closed the connection]
14:06<akerl>doing what?
14:06<zifnab>in place IP changes
14:06<akerl>? nah, he just stopped dropping RAs and suddently got his v6 addr via SLAAC
14:08<akerl>Does openvpn do v6?
14:09<buhman>better v6 support landed in 2.4, where they abolish the udp vs udp6 nonsense.
14:09<akerl>one of these days I might as well add magicvpn so containers don't have to think about what VM they're on
14:14<zifnab>we all know ipv6 is dead: long live ncp!
14:15<zifnab>you can send, you can recieve, but you can't do both
14:16<MotoHoss>akerl, oh yeah.. might as well rib ya while'st I can... "iptables6-save" doesn't work "ip6tables-save" does ;)
14:18<f00b44>who deals with pending accounts?
14:18<akerl>This is the user community
14:18<f00b44>support tickets only?
14:18<f00b44>No. This is Sparta!
14:18*alexf kicks akerl into a bottomless pit
14:19<MotoHoss>elastic support can be found here, it stretches from time to time....
14:20<zifnab>and, like elastic search, its not guaranteed to ever work how you want it to!
14:21-!-niemeyer [~niemeyer@] has quit [Ping timeout: 480 seconds]
14:22<MotoHoss>no warranty expressed nor implied... except to say that one should not get on linbot's bad side.
14:22-!-stevepiercy is now known as stevepiercy_away
14:25-!-anomie22 [] has quit [Quit: Leaving.]
14:25-!-_ez__ [] has joined #linode
14:25-!-_ez__ [] has quit []
14:29-!-anomie22 [] has joined #linode
14:31-!-niemeyer [~niemeyer@] has joined #linode
15:25-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
15:25<Nivex>Pages: 1312
15:26<Cromulent>even OpenBSD has moved away from sendmail
15:32<dwfreed>Jverk: for any purpose, that's irrelevant
15:33<dwfreed>you see 20 cores; as far as your Linode is concerned, those are real cores
15:33<Jverk>20 physical cores means 40 with hyperthreading
15:33<dwfreed>you don't get hyperthreading inside your Linode
15:33<dwfreed>you see 20 cores
15:35<synapt>I believe as far as linode allocates cores, hyperthreaded cores are allocated like normal cores
15:35<synapt>so those 20 cores you get may technically be HT cores
15:35<okoca>dwfreed what is the one core speed mhz ghz ?
15:35<dwfreed>okoca: 7
15:35<Jverk>then can I get 40 cores?
15:36<okoca>1core is 7ghz ur mean ?
15:36<gparent>dwfreed ur mean
15:36<synapt>7GHz cores
15:36<dwfreed>okoca: the point is that the speed is irrelevant
15:36<synapt>god damn linode is onsome cutting edge hardware
15:37<dwfreed>synapt: it's liquid helium cooled
15:37<okoca>so what the 1core compute power? exual to with cpu?
15:38<dwfreed>that's not something that is fixed
15:38<dwfreed>it depends on your workload
15:39<okoca>another account workloads affecting my cores ?
15:39<dwfreed>they can, but that is unlikely
15:39<dwfreed>the host only has so much CPU power, and that is shared by all Linodes on the host
15:40<okoca>can i buy 1000 vps account for 1hour, with 0.015 * 1000account = 15$
15:41<okoca>linode can supply this count account?
15:41<dwfreed>you can try; whether or not Linode has that much available capacity I do not know
15:42<synapt>okoca: There have to actually be 1000 available for one thing
15:42<synapt>personally I admit curiousity at what you need 1000 for
15:43<okoca>can i use it for multi thread clustering application.
15:45<dwfreed>you can use your Linode(s) for whatever legal purpose you want
15:45<dwfreed>you should read the ToS:
15:46-!-Yoda [] has joined #linode
New news from linodelibrary: LAMP Server on CentOS 7
New news from forum: How to generate and install an SSL certificate on Linode? in General Discussion
17:02-!-anomie [] has quit [Quit: Leaving]
New news from forum: Email Issues After Moving Domain to New Linode in Email/SMTP Related Forum
17:29-!-anuvrat [~chatzilla@] has quit [Ping timeout: 480 seconds]
17:29<zifnab>seeing as i already ask all my linux questions here (whether or not they're related to ilnode)
17:29<zifnab>lets say by some magic i have a disk thats connected to two machines, and i want to make it HA
17:30<zifnab>i've gotten that far
17:30<buhman>go on
17:30<zifnab>for part two: icsci mounts from said disk
17:30<zifnab>in a HA fashion, so I can reboot either node and it remains up
17:30<zifnab>or NFS, or smb, or anything really
17:30<zifnab>i can do the failover ip with pacemaker
17:31<buhman>nfs + ip failover would be ok
17:31-!-lionmac [~lionmac@] has joined #linode
17:32<zifnab>doesn't nfs have some sort of state though?
17:32<zifnab>'this client is connected on this port and has access to this', won't that die when the IP does its failover magic
17:32<buhman>yeah probably, and clients will probably hiccup
17:32<buhman>they should recover though
17:32<zifnab>if you're doing something like VMs though, that hiccup would turn into a kernel panic
17:33<buhman>ehh not really
17:33-!-xjgrant [] has quit [Remote host closed the connection]
17:33<buhman>are the VM's doing root-on-NFS?
17:34<zifnab>(btw i'm not doing any of this atm outside of storage, i'm just curious)
17:34-!-fstd [] has quit [Remote host closed the connection]
17:34<zifnab>lets say the VM is a disk image on an nfs share
17:34<buhman>and the nfs share is mounted on some 'vm execution' box, right?
17:34<zifnab>long story short: i've been doing lots with hyper-v recently
17:34<zifnab>and its staying hyper-v (sadly)
17:34<zifnab>but i'm curious how you'd get the same thing set up in linux
17:34-!-fstd [] has joined #linode
17:35<zifnab>we have 2 boxes on fiber channel doing storage (server 2012 r2 storage server, failover cluster + smb3.0 scale out file server), then 42 nodes connected to those via infiniband
17:35-!-bbankes [] has quit [Read error: Connection reset by peer]
17:35<zifnab>it seems like windows/vmware have kinda 'won' this market, but i feel like it could easily be done with xen (with the right tools)
17:35<zifnab>or kvm, or $INSERT_VM_SOFTWARE_HERE
17:37<buhman>there's really no way around ip failover without the client doing something special.
17:37<buhman>the vm execution box should be able to recover, and the guests would just have a blip of iowait.
17:37-!-cps_ [] has joined #linode
17:38-!-cps [] has quit [Read error: Connection reset by peer]
17:38-!-cps_ is now known as cps
17:38<zifnab>its a weird market that seems to be owned by microsoft: licensing sucks ass
17:39<zifnab>you go with vmware, there's a 990/socket fee. you go with microsoft, no per-socket-fees, but you get hit with CALs
17:39-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
17:41<buhman>zifnab: you could also try gluster
17:41<dwfreed>zifnab: or use the vmware keygen, and not pay a dime :D
17:42<buhman>I've never tried making the server not-replicate, but you should be able to make it work.
17:42<buhman>the gluster client can poll multiple servers and do the RightThing.
17:42-!-anuvrat [~chatzilla@] has joined #linode
17:42<zifnab>buhman: but then you're stuck to using linux exclusively, unless there's a windows glusterclient
17:43<zifnab>not really "stuck"
17:43<@rohara>*Obligatory WINE reference*
17:43<buhman>zifnab: glusterfsd can also export nfs mounts.
17:43<zifnab>and it looks like cifs via samba
17:43<buhman>mount.cifs is a little crusty though
17:44<buhman>whereas native windows does the right thing (using smb3 by default), samba and mount.cifs don't.
17:46<zifnab>buhman: so there is the option somewhere to treat cluster as a shared-block-device-fs instead of a replicated-clustered-fs?
17:46<buhman>probably; rtfm ;p
17:46<zifnab>i am
17:47-!-MaliutaLap [] has quit [Remote host closed the connection]
17:47<buhman>if I were doing this, I'd probably nuke GFS2 and split up the iscsi.
17:48-!-lionmac [~lionmac@] has joined #linode
17:48<buhman>on the other hand, your storage hardware can probably replicate faster than the network can.
17:48<zifnab>haha, 20gbit fiberchannel
17:49<zifnab>buhman: it actually mounts the same block device to both storage servers
17:49<zifnab>so its a shared block device, instead of doing some weird replication thingy
17:49<zifnab>replication is done via raid, which is crazy fast
17:49<buhman>I mean the physical disks
17:49<buhman>yes, that == faster than gluster probably.
17:50<zifnab>the issue is finding a filesystem that can deal with shared block devices
17:50<buhman>you said you had gfs2 going
17:50<zifnab>and then doing some sort of front end failover
17:50<zifnab>in my test stuff i'm working on it now
17:50<zifnab>i have it installed at least
17:51<buhman>oh; you're going to have a lot of fun then ;p
17:51-!-userme [~oftc-webi@] has joined #linode
17:51<zifnab>mostly i'm in a 'i have no work to get done, lets fuck around' mode
17:52-!-sphenoid [] has joined #linode
17:56-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
17:57-!-sphenoid [] has quit []
17:57-!-userme [~oftc-webi@] has quit [Remote host closed the connection]
18:27-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
New news from forum: How to generate and install an SSL certificate on Linode? in General Discussion
18:30<MajObviousman>buy some randomness
18:30<James_T>use havege
18:33<MajObviousman>what's a term for all the "extra" mail provider things that are expected for those running mail servers?
18:33<MajObviousman>like SPF records, TXT records, etc etc
18:33<Cromulent>MajObviousman: you mean SPF, DKIM and DMARC?
18:40<James_T>google doesn't do forensic reports
18:41<James_T>some providers do tho
18:41<James_T>I do <3 dmarc tho
18:41-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
18:42<Cromulent>yeah I have it set so that only emails sent via my google apps account or Amazon SES are accepted - also I've noticed that if you pass all tests for SPF, DKIM and DMARC your email is less likely to be marked as spam
18:42<Cromulent>certainly haven't had any spam issues so far
18:45<zifnab>buhman: ocfs2 + pacemaker/corosync/resource-agents/heartbeat, failover icsci is working
18:45<zifnab>there's a 5s io lock on failover
18:46-!-fergtm [] has joined #linode
19:06-!-Dedalo [] has quit [Remote host closed the connection]
19:24<@drussell>rsdehart: Lol. I mean like, not hilighted but made green
19:32<zifnab>dependso n the os
19:32<zifnab>depends on the os*
19:32<@drussell>Isn't 5.3 EOL?
19:32-!-Kellin [] has joined #linode
19:32<@drussell>Pretty sure you should use 5.4
19:32<zifnab>does php ever EOL anything?
19:32<@drussell>zifnab: It does.
19:32<nthint>yeah, you are right
19:32<@drussell> <
19:32<trippeh_>ah. the linode lamp stack script is limited to ubuntu 12.04 as the newest supported, which uses php 5.3
19:33<nthint>so do I have to re-install or is it possible to update?
19:33<trippeh_>linode: plz add 14.04 to it ;)
19:33-!-steveski [] has joined #linode
19:34-!-kaare_ [] has quit [Ping timeout: 480 seconds]
19:34<trippeh_>nthint: you could do a ubuntu distro upgrade to ubuntu 14.04 LTS. but the apache parts can be a bit painful for 12.04 -> 14.04
19:35<nthint>I think this will work fine?
19:35<MajObviousman>anyone here have Verizon FiOS and have done "things" to move the default router out of the way?
19:35-!-wizonesolutions [] has joined #linode
19:36<MajObviousman>which option did you select and why?
19:36<trippeh_>nthint: I'd be careful with 3rd party repos (ppa's) - things like security support and later distro upgradeability can suffer.
19:37<nthint>is there official repo with PHP 5.4 or 5.5?
19:37<trippeh_>nthint: going to ubuntu 14.04 LTS is better long term. it ships with PHP 5.5.x
19:37<MajObviousman>PHP deliberately doesn't maintain its own repos
19:37<MajObviousman>it wants the distros to do that chore
19:38<MajObviousman>it only provides source
19:38<trippeh_>and win32 binaries :>
19:38-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
19:39-!-stevepiercy_away is now known as stevepiercy
19:39<nthint>trippeh_: thank you for the advice. I am not ready yet to upgrade linux, since it is my first day working with any VPS and I need to learn the basics before going there. I will rebuild this linode later in any case
19:40<trippeh_>drussell: update stack script for 14.04 plz :)
19:41<trippeh_>Compatible with: Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Debian 7 32bit, Ubuntu 10.04 LTS 32bit
19:43-!-lionmac [~lionmac@] has joined #linode
19:43<Ikaros>06:36:22 PM <MajObviousman> which option did you select and why? <-- Option 6, I've always used ethernet lines on my LAN and I wanted it for WAN too. That and I don't trust the Actiontec crap they gave me to be a primary. I would trust any other router over that garbage to be my primary.
19:43<dwfreed>trippeh_: 14.04 is apache 2.4, isn't it?
19:43<MajObviousman>yeah, I'm of the same opinion
19:44<trippeh_>dwfreed: yup. Candidate: 2.4.7-1ubuntu4.1
19:44<MajObviousman>you still get guide data et al?
19:44<MajObviousman>6 and 7 look pretty similar, with 7 being a superset functionality of 6
19:44<dwfreed>trippeh_: then it's going to have to be a whole new stackscript, or a lot of work will need to be done to the convenience library
19:44<arlen>when I had fios you still needed the actiontec
19:44<Ikaros>Yes, because the Actiontec is still utilizing MoCA for local data.
19:45<Ikaros>The only thing not supported in that setup is what is specified on that page - the CPE interface
19:45<Ikaros>Which I really don't give a damn about
19:46<trippeh_>dwfreed: a fun project! :)
19:46<Ikaros>Because screw Verizon. Enough said
19:46<MajObviousman>I'm not even sure what that is
19:46<MajObviousman>but I probably won't care for it
19:46<Ikaros>MajObviousman: It's a remote CPE access interface for Verizon techs to remotely do things with their router at your premises
19:46<trippeh_>MajObviousman/Ikaros: I'm glad my ftth provider lets me plug the fiber into my own switch with my own optics :)
19:46<MajObviousman>oh fuck that, absoultely no fuck ing way
19:47<MajObviousman>yeah, nope no CPE
19:47<MajObviousman>Customer Premesis E-something
19:47*MajObviousman will also likely be going for option 6 then
19:47<Ikaros>Customer Premises Equipment
19:47<trippeh_>a $15 SFP module and boom, WAN link
19:48<MajObviousman>I would kinda like that
19:48<MajObviousman>except I'm getting more than just internet from it
19:48<Ikaros>Thing you have to bear in mind though, is this - you will need to put Verizon's router back as primary if you ever need support from them.
19:48<trippeh_>we got the tv signals on a different fiber
19:48*MajObviousman had to do that every time he called TWC
19:48<trippeh_>one fiber for data, another for tv
19:48<MajObviousman>trippeh_: I'm a fan of that
19:49<Ikaros>But Option 6 is what I'm using now, and guide, VOD, all that STB jazz works fine
19:49<MajObviousman>is it local coop fiber?
19:49<MajObviousman>Ikaros: thank you very much for explaining
19:49<MajObviousman>you saved me some time :)
19:49<trippeh_>MajObviousman: sorta - housing coop put down the fiber and rents out out to a layer1-2 broker
19:49<acald3ron>linode configure its nt working. some perl package i need.
19:50<trippeh_>MajObviousman: so its also open access.
19:50<Ikaros>If your WAN is currently set to coax though you'll need to call Verizon's FSC first and have them switch it to ethernet, you'll need to verify with them that you've done the setup for that yourself.
19:50<zifnab>i sucessfully have vrrp and iscsi running between two nodes with a shared disk
19:50*MajObviousman was out looking at the ONT today
19:50<MajObviousman>while I was discovering that I had a different power grid provider than my current address
19:50<MajObviousman>and therefore couldn't just change addresses at my current company
19:50<Ikaros>It was easy for me to do because my ONT is indoors (I'm in an apartment)
19:51<MajObviousman>the cat5 is run right up to it, just clipped at the end instead of plugged in
19:51<MajObviousman>it'll be <5 min to get it ready to go
19:51-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
19:51<Ikaros>There's a hub mounted on the side of the building I'm in, the ONT gets its link through that.
19:51<acald3ron>linode cli any help:
19:51<MajObviousman>so if you really wanted to piss neighbors off, take an axe to that box
19:52<MajObviousman>I think somebody has broken into my former apartment and set up a grow op in there
19:52<Ikaros>I'd piss off about 8 different families.
19:52<Kellin>my FiOS ONT is in my neighbor's basement
19:52<MajObviousman>the power usage suddenly leapt to about $25 a day last week
19:52*Kellin was displeased with that, but there was no way to run it into his apartment with how stuff is wired.
19:52<Ikaros>No, 16
19:52-!-shortdudey123 [~textual@] has quit [Quit: My MacBook Pro has gone to sleep. ZZZzzz…]
19:52<@drussell>acald3ron: Might be worth opening a support ticket on that one.
19:53<MajObviousman>it's been vacant for over a month
19:53<acald3ron>MajObviousman, ok thanks !
19:53<Ikaros>Counting the number of wifi networks in range and the SSID naming schemes, more than 90% of this damn complex has FiOS running
19:53<MajObviousman>acald3ron: I don't recall giving you any advice
19:53<dwfreed>MajObviousman: why didn't you have the power turned off, then?
19:54<MajObviousman>because I was playing fast and loose
19:54<Ikaros>The rest I can probably assume are Time Warner crap.
19:54<MajObviousman>vacant, smoke damaged, clearly uninhabitable
19:54<MajObviousman>I figured that surely nobody would go in there
19:54<MajObviousman>and since the power co was going to charge me $150 to terminate my contract early ... I figured I'd just let it ride for a month and then do change-of-address
19:54<MajObviousman>but that's backfired on e
19:54<dwfreed>> contract
19:54<dwfreed>what is this?
19:55<Ikaros>I remember when the FiOS tech was in here checking the coaxial...he pulled out the existing plug and said "Heh. Time Warner garbage."
19:55<MajObviousman>well, when a mommy power company hates her child user very very much ...
19:55<MajObviousman>she makes him sign a contract to get power at a not-ridiculously-overpriced rate so that he'll keep getting power from her for a year
19:55<Kellin>my FiOS techs have all been pretty bad - they don't listen to what I want and just wire it anywhere they want / anyway they want =/
19:55<Ikaros>Pulled that plug off, installed a new one with new outlet faceplate and everything.
19:55<MajObviousman>one of the less savory aspects of Texas-style power deregulation
19:56-!-lionmac [~lionmac@] has joined #linode
19:56<Ikaros>Yeah, Kellin, the guy I dealt with was thorough and always checked with me when there was the option of doing something different, e.g where I wanted to place things.
19:57<MajObviousman>it's ok though, at the new house, I'm locked in to buying power from a local coop that I'm absolutely positively certain will NOT mistreat me
19:57<Ikaros>Not to mention he was early.
19:57<MajObviousman>yay local monopolies
19:57<MajObviousman>some day soon, I'm going to move the fuck out into the country side, buy some land, and build my own frickin power plant
19:58<Ikaros>But yeah. Only thing missing with them that I have yet to see here...native IPv6
19:58<Ikaros>Another driving reason I wanted to put my router up as primary.
19:58<MajObviousman>FiOS doesn't do native IPv6?
19:58<trippeh_>hm. I use about $2/day for power.
19:58<MajObviousman>trippeh_: do you hang dry your clothes?
19:59<MajObviousman>run a dryer for an hour, see how much power you spend
19:59<Ikaros>MajObviousman: They were supposed to be working on that since, oh, 2012 or so.
19:59<trippeh_>MajObviousman: no. power is just cheap over here.
19:59<MajObviousman>or dry your hair with a blow drier
19:59<MajObviousman>must be nice
19:59-!-seanh-corona [] has quit [Ping timeout: 480 seconds]
19:59<Ikaros>I can't speak for other FiOS markets obviously but I know I haven't seen it on the Dallas market yet
19:59<Peng>trippeh_: wtf, do you live in a coal mine?
20:00-!-fstd [] has quit [Remote host closed the connection]
20:00<Ikaros>I'm actually using IPv6 now, but a tunnel, if you checked my current address you'd see that probably.
20:00<trippeh_>in our neighbour country - denmark - power sometimes have negative price ;)
20:00-!-fstd [] has joined #linode
20:01<MajObviousman>so it is
20:01<trippeh_>not quite that cheap here, though.
20:01<trippeh_>we got lots of hydro
20:02*MajObviousman is also Dallas area, NE ish
20:03<MajObviousman>hopefully I have a similar experience in techs that you did
20:03<MajObviousman>it gets installed on Monday, along with all my shit being delivered
20:03<MajObviousman>it's going to be a busy day I think
20:03<MajObviousman>errr, stuff. Getting my stuff delivered.
20:03*MajObviousman coughs quietly
20:04<Ikaros>Well I've not had a negative experience with them here thus far. I will say that much.
20:04-!-shortdudey123 [] has joined #linode
20:04-!-stevepiercy is now known as stevepiercy_away
20:04-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
20:05<MajObviousman>what quadrant of Dallas, if I may ask?
20:05<Ikaros>And I'm tech-inclined so one huge pet peeve of mine is being talked to like I'm some sort of newbie in that regard.
20:05<Ikaros>They actually came to my level.
20:05<MajObviousman>that's quite nice
20:05<MajObviousman>a great change from TWC
20:05<MajObviousman>after 20 calls to their tech support line in 4 months, they just started connecting me straight to the L3 guy
20:06<MajObviousman>who magically got things more or less fixed
20:06<Kellin>yeah - I had that relationship with the vendor in Norman when I lived in OK
20:07<Ikaros>07:05:07 PM <MajObviousman> what quadrant of Dallas, if I may ask? <-- Roughly western/northwestern quadrant (Irving)
20:07<Tea>So I have an SSL cert for - how come it's flagging as invalid when being used as the IMAP server? Can one SSL not be used for both IMAP and HTTP? Because I also have it validating my webmail
20:07<MajObviousman>ahh yes
20:07<MajObviousman>good connectivity over there
20:07<Ikaros>Tell that to my cell phone.
20:07<MajObviousman>fiber heaven!
20:07<MajObviousman>you can't throw a rock without hitting a data center
20:07*MajObviousman lays it on thick
20:08<Ikaros>Being near the airport kinda has a downside. So having the connectivity that I do makes my phone happy when it's connected with my wifi. Sad when on cell data.
20:08<Tea>oh wait - i had it wrong. forgot to restart dovecot
20:09<Ikaros>Don't matter if I have 3G or even LTE connectivity, the throughput is crap because I'm likely bouncing off a tower that's god knows how many miles away.
20:09-!-lionmac [~lionmac@] has joined #linode
20:11<James_T>Ikaros: my town has... two towers
20:11<James_T>both are over capacity
20:11<rsdehart>and that huge glowing eye causes major interference
20:12*James_T curses Sauron
20:12<Peng>and those marching armies of orcs have no respect for shallow buried cables
20:13-!-luckst0rr [] has joined #linode
20:14<Ikaros>But yeah, all in all phone <3's my FiOS connection.
20:14<rsdehart>I"m looking forward to FiOS
20:14<rsdehart>gotta move to the bottom of the freakin world to get it
20:15<rsdehart>actually if my info is right, I'll be living a block over from the extent of the fiber, so once again I'll be SOL
20:15-!-The-spiki [] has joined #linode
20:15<Ikaros>Which another thing I'd like to point out - the wireless N on the Actiontec is a joke. My router has simultaneous dual-band N and, soon as I get my tax refund (I'll be among the first after the 20th, I just filed today), I'm going 802.11ac
20:16-!-luckst0r [] has quit [Ping timeout: 480 seconds]
20:16<devilspgd>You could have saved some typing... Just drop "the wireless N on " and you're good.
20:17<MajObviousman>Ikaros: have you selected your AC hardware of choice?
20:17-!-shortdudey123 [] has quit [Ping timeout: 480 seconds]
20:17<Ikaros>Not just yet.
20:17*dwfreed suggests the Asus RT-AC68U
20:17<akerl>dwfreed: heh
20:17-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
20:17<akerl>I was just going to suggest ASUS for their solid security
20:17<dwfreed>akerl: I finally put tomato on mine; needed VLANs
20:18<James_T>rsdehart: no, you'll get some airfibre and get fios that way
20:18<James_T>Does any AC hardware work with openwrt
20:18<rsdehart>James_T: I plan to figure something out
20:18<dwfreed>there's some draft AC hardware that does
20:18<MajObviousman>with modern wifi, I'm starting to get comfortable with NOT putting my fileserver on a wire
20:18<James_T>ah ok
20:19<James_T>>modern wifi
20:19<James_T>>not using wires
20:19<devilspgd>Modern wifi is next generation. Always next generation, never today.
20:19<James_T>What speed does AC do
20:19<James_T>through a faraday cage
20:21<trippeh_>James_T: 4-500 typical in good conditions AFAIK
20:21<trippeh_>Mbps TCP throughput
20:21-!-learner [] has joined #linode
20:31*MajObviousman is reading up on how ISO/IEC connects are supposedly supplanting EIA/TIA connects
20:31<MajObviousman>but so far I haven't seen any up close
20:32-!-steveski [] has quit [Remote host closed the connection]
20:32-!-zivester [] has joined #linode
20:32<James_T>what? confuse
20:33<MajObviousman>yeah I am too
20:34<MajObviousman>so far I'm not seeing a listed difference, but it's probably buried in the standard somewhere
20:35-!-lionmac [~lionmac@] has joined #linode
20:35<MajObviousman>so, looks like you can run 10g just fine across typical cat 6 or 6A
20:35<James_T>need cat6 to do it
20:36<MajObviousman>but if you want to push it to 40 or 100, you'll need this new connector standard or whatever, and you've got limited lengths, 40m and 15m respectively
20:36<James_T>gets a reasonable range too afaik
20:36<MajObviousman>instead of 100m
20:36-!-nthint [~oftc-webi@] has quit [Quit: Page closed]
20:36<James_T>mmm yup
20:36<MajObviousman>and I expect the newish 400g is fiber only
20:36<James_T>10gig switches aren't too expensive either
20:36<MotoHoss>so how fast do ssd's write?
20:36<James_T>faster than a gigabit ethernet connection can handle
20:37*MajObviousman was aiming towards an ubqt edgerouter
20:37<James_T>afaik you can do 10gig on cat5e... but...
20:37<zifnab>James_T: cat6 required
20:37<dwfreed>depending on the controller, you're often more limited by the bus it's running across
20:37<MajObviousman>I think you'd be getting issues with cat5e
20:37<James_T>zifnab: lol
20:37<MotoHoss>MajObviousman, they are nice.
20:37<James_T>MajObviousman: yeah
20:37<dwfreed>you can use quality cat5e for 10gig
20:37<zifnab>and a line speed 10gbit switch is going to be a shit ton
20:37<MajObviousman>define quality :)
20:37<MajObviousman>crossbar switch, here I come!
20:37<zifnab>sure, you can get one that has 10gbit throughput in total for cheap
20:37<James_T>dwfreed: so, solid core copper?
20:38<MajObviousman>define cheap
20:38<MajObviousman>e.g. can you link a product?
20:38<buhman>MajObviousman: like $10
20:38<zifnab>but good luck not spending 5-10k on a 10gbit copper switch that does throughput
20:38<dwfreed>it basically has to handle the frequencies of cat6a and cat7
20:38<zifnab>MajObviousman: the only one i have is from some weird chinese website, no idea what model o ranything
20:38<MajObviousman>right, so wiring for cat 6A is not a bad idea, but wait on the rest
20:38<buhman>10gbit switch fabric is like a 48-port 100Mbit/s switch
20:38<MajObviousman>give it a few years to catch up
20:39<zifnab>buhman: 4500x ftw
20:39<zifnab>but its fiber or their weird sfp copper
20:39<MajObviousman>not exactly consumer grade
20:39<zifnab>tbh i'd just pick up a cheap 10gbit fiber switch
20:39<buhman>ancient 'enterprise' grade == consumer grade
20:40<MajObviousman>I was exploring wiring certain rooms with fiber
20:40<MajObviousman>but then you've got radius issues and it's so much more finicky
20:40<MajObviousman>still too early for that also
20:40-!-donspaulding [] has quit [Quit: donspaulding]
20:40<James_T>You can buy a TP-Link
20:40<James_T> for <$2000
20:40<James_T>derp, where'd that newlines come from
20:40<zifnab>routerboard used to have a 24x 10gbit sfp switch for ~1100
20:40<zifnab>not sure where it went
20:40<MajObviousman>point is, when I run the cat6A, I'll also run a spare piece of rope and secure it at either end so I can then come back later much easier
20:41<buhman>I bet James_T has a pair of 42U switches in his basement
20:41<MajObviousman>and if/when a new cabling standard comes along which I need to hop to, I'll be ready
20:41<zifnab>buhman: i have a nexus at work, they make way too much noise fo rmy house
20:41<James_T>MajObviousman: :D
20:41<zifnab>cisco n7010, they're fucking loud
20:41<zifnab>too many fans
20:41*MajObviousman reiterates the desire for CONSUMER or PROSUMER grade gear
20:41<James_T>But yeah, copper 10gig for <$1300 is a thing
20:41<MajObviousman>a very new thing?
20:42<James_T>not new, really
20:42<MajObviousman>ebay: a trusted seller of ultra high end networking equipment since 1998
20:42<James_T>been a standard for ages but people just didn't use it
20:42<James_T>totally trusted
20:42<James_T>;) ;) ;)
20:43<MajObviousman>I imagine the ASICs in these run pretty hot to keep up
20:43-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
20:43-!-anuvrat [~chatzilla@] has quit [Ping timeout: 480 seconds]
20:43<James_T>hence the fans
20:43<MajObviousman>you said you had one
20:43<MajObviousman>or somebody did?
20:44<MajObviousman>whoever owns a 10g copper speak up and tell us how loud it is
20:44<MajObviousman>inquiring minds want to know!
20:44<James_T>Put it in your garage?
20:44<James_T>and look! also has two SFP+ ports
20:44<MajObviousman>sawdust complications
20:45<MajObviousman>mini cleanroom in the garage perhaps?
20:45-!-niemeyer [~niemeyer@] has quit [Ping timeout: 480 seconds]
20:45<MajObviousman>I kinda sorta want to buy a house in the country and pay to have LR fiber trenched to the home
20:45<MajObviousman>a nice 500/500 and then split it out to neighbors
20:46<MajObviousman>I figure the trenching would be 15-20k
20:46<MajObviousman>depending on how far
20:46<MajObviousman>where I'm thinking is only 10-15 miles "off grid"
20:46<MajObviousman>and solid ground, not many faults or swamps or anything
20:47<Kellin>at least not until you go digging up all the ground!
20:48<MajObviousman>that's what I pay somebody else for
20:48-!-lionmac [~lionmac@] has joined #linode
20:48<MajObviousman>so when their dumb ass hits a water main, they get to file the insurance claim not me
20:48<ctpdump>I can't seem to find out if I need to tinker with SOA-EDIT (in powerdns) if I use a bind-backend. Anyone?
20:48<ctpdump>and non-powerdns slaves (eg: linode)
20:49<buhman>ctpdump: what are you actually trying to do?
20:49<ctpdump>ah, that would help, yes. DNSSEC
20:50<buhman>if pdns is your master, it's like two commands to make it do the RightThing™
20:50<rsdehart>obey your master
20:50<ctpdump>pdns is the master, linode is slave
20:50<buhman>and all you want to do is start auto-signing all the things in some zone?
20:52<buhman>you can't just do pdnssec secure-zone $foozone ?
20:53<ctpdump>I can but based on the documentation:
20:53<ctpdump>Warning: If you have DNSSEC-signed zones and non-PowerDNS slaves, please check your SOA-EDIT settings.
20:53-!-jincai [~oftc-webi@] has joined #linode
20:53<ctpdump>under master operation
20:53-!-anuvrat [~chatzilla@] has joined #linode
20:54<buhman>I can't see how the defaults could possibly cause anything to go wrong
20:54<buhman>ctpdump: did you try it?
20:54-!-jincai [~oftc-webi@] has quit []
20:55<ctpdump>not yet. apparently if you don't set the SOA-EDIT correctly, zones will not update after a while
20:55<zifnab>test it out - you don't *have* to point yoru domain at it
20:55<MajObviousman>rsdehart: chop your breakfast on a mirror
20:55<ctpdump>zifnab: how could I test it non-live?
20:55<zifnab>ctpdump: set your dns server to
20:55<zifnab>it won't do recursive
20:55<zifnab>but you should be able to test it
20:56<zifnab>or 'dig domain'
20:56<rsdehart>MajObviousman: tbh I don't actually know the lyrics haha
20:56<ctpdump>wouldn't I need to put the DS records at my registrar first?
20:56-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
20:56<zifnab>you can skip that step entirely and it won't b elive
20:56<MajObviousman>demmit now I want to listen to that song
20:56<buhman>ctpdump: you can skip DS until you're ready.
20:56<zifnab>dig in ns; dig in ns
20:56<ctpdump>dig -4 +dnssec -t soa shows the RRSIG records
20:56<ctpdump>so it looks to be fine
20:57<ctpdump>but there are some warnings on using non-powerdns slaves and the need of SOA-EDIT
20:57<MajObviousman>rsdehart: haha, awesome youtube comment: "Lars is the only drummer in the world that plays drums better without a drum kit."
20:58<buhman>ctpdump: what's your current serial?
20:58<ctpdump>manually set in the bind-like zone file
20:59<rsdehart>MajObviousman: I personally think he belongs alone in a soundproof box
20:59<MajObviousman>with no mics inside?
20:59<MajObviousman>while another drummer plays along side him
20:59<MajObviousman>and is mic'd
20:59<MajObviousman>maybe stick a camera and a little A/C unit in there so he still feels like he's a part of things
20:59<buhman>ctpdump: 02 == not-INCEPTION
20:59<buhman>ctpdump: which means you're good
20:59<ctpdump>not sure what you mean?
21:00<ctpdump>hang on, that's a serial number I incremented manually in the zone file
21:00<ctpdump>it was 01 when I started the day (as it should)
21:00<ctpdump>but I'm using a bind backend, not mysql
21:01<zifnab>i like the windows method: start at 1, increment by 1 for every change
21:01<buhman>I have no idea what you're doing
21:01<zifnab>less chance of a fuckup
21:01-!-lionmac [~lionmac@] has joined #linode
21:01<buhman>zifnab: unless the slaves are already >1 ;p
21:01<zifnab>good point!
21:01-!-dmarr [] has joined #linode
21:01<zifnab>you could nuke the slaves and start over (i think?)
21:02<buhman>too much work
21:02<ctpdump>one more thing, where the heck do I setup the SOA-EDIT?
21:02<buhman>ctpdump: in mysql there's a 'domainmetadata' table
21:02<buhman>you insert a row
21:02<ctpdump>that's the thing, I don't use mysql
21:02<ctpdump>this is why it all started
21:02<buhman>you've mentioned this ;p
21:02<ctpdump>I use bind-backend
21:03<ctpdump>hence the confusion ;)
21:03<buhman>not to derail your question, but why bind-backend?
21:03<buhman>seems like that's probably much less efficient than mysql?
21:04<zifnab>ha, efficiency of zone files
21:04<ctpdump>since the serial is "hard coded" in the zone file I don't think soa-edit might work..
21:04<ctpdump>for simplicity more than anything
21:04<buhman>zifnab: efficiency is important as the size of zones approach infinity.
21:04<ctpdump>and 'vi' is much better than all powerdnswebadmins
21:04<zifnab>buhman: on the slave they're loaded into ram anyways?
21:04<ctpdump>I tried poweradmin and it was horrific
21:04<zifnab>idr how bind actually does its magic
21:05<buhman>when you do dnssec in bind-proper, the serial in signed zone doesn't necessarily match the zone file.
21:05<zifnab>and using the linode servers kind of me makes me not care what my master is running
21:05<buhman>bind manages that
21:05<buhman>it should definitely not match what's in your zonefile after the first key update
21:06<ctpdump>ok, so I need SOA-EDIT after all
21:06<ctpdump>if they don't match
21:06<ctpdump>the keys update weekly if I read correctly?
21:06<buhman>you can change that too
21:07<ctpdump>When serving this zone, modify the SOA serial number in one of several ways. Mostly useful to get slaves to re-transfer a zone regularly to get fresh RRSIGs.
21:07<MajObviousman>did someone put efficiency and bind in the same sentence?
21:07<buhman>MajObviousman: the opposite
21:07<MajObviousman>ok, that's good
21:07<ctpdump>I guess as a last resort I can update the serial daily and force an update to the slaves
21:07<MajObviousman>preach the truth brotha!
21:07<ctpdump>nasty hack but may do it
21:07<dwfreed>MajObviousman: BIND is actually pretty efficient, given what it does
21:07<dwfreed>MajObviousman: runs at least one of the root nameservers
21:07<MajObviousman>it's just reading bits out of files and returning them
21:08*buhman doesn't see what's wrong with doing insert/update queries and/or nsupdate.
21:08<MajObviousman>and a web server is just taking file requests and returning files in response
21:08<MajObviousman>buhman: on a small scale? Absolutely nothing
21:08<MajObviousman>but people tend to go Big
21:08<MajObviousman>100k entries in one zone file? WHY NOT
21:08<buhman>if you're going Big you're probably not using your fingers to do the actual zone updates.
21:08<MajObviousman>we were at 30k and increasing by 200-500 per day at my last job
21:09<MajObviousman>due to extremely poor decision making up front
21:09-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
21:09<MajObviousman>also frequency of updates/commits starts to play a role
21:09-!-dmarr [] has quit [Ping timeout: 480 seconds]
21:09<MajObviousman>when you have either tons of zones or tons of entries in a single zone
21:10<MajObviousman>it approaches the classic database performance issues without any of the classic database performance helpers
21:10<MajObviousman>well, that's not true. If you set it to not immediately write changes, then that's kinda like a DB cache layer
21:13<buhman>ctpdump: what's your bind-dnssec-db ?
21:13<buhman>ctpdump: apparently you make separate special database for the dnssec metadata to play with the SOA-EDIT.
21:13<buhman>ctpdump: says 'Autoserial: No' which looks pretty scary.
21:14-!-lionmac [~lionmac@] has joined #linode
21:14<buhman>ctpdump: #powerdns probably knows ;p
21:14<MajObviousman>yeah, I think we're stretching beyond the boundaries of what this channel can help with
21:14<MajObviousman>which isn't to say it's not interesting
21:14<ctpdump>autoserial - no because they are plain files and need to be manually updated
21:15<buhman>hybrid bind-mode sounds interesting
21:16<ctpdump>This mode is only supported in 3.0, 3.0.1 and 3.4.0
21:16<ctpdump>I have 3.3 which came with ubuntu 14.04..
21:16<buhman>sounds like your distribution is failing to provide the packages you need
21:17-!-shortdudey123 [~textual@] has joined #linode
21:19<ctpdump>I was following this guide
21:19<ctpdump>he's using bind backend and mentiones the need of soa-edit
21:19<buhman>did you do that?
21:20<buhman>sounds like you should fire up sqlite and poke around in that metadatadb ;p
21:20<MotoHoss>why not just use bind?
21:20<ctpdump>I was thinking about that, let's see
21:21<ctpdump>aha, I think this is it
21:22<ctpdump>sqlite> .tables
21:47<akerl>signed with a private key, but yea
21:50<zifnab>buhman: memorize your fingerprint
21:50<+linbot>New news from forum: homepage not updating in General Discussion <>
21:50<buhman>sure; how about memorizing 9000 fingerprints?
21:50-!-lionmac [~lionmac@] has joined #linode
21:50<trippeh_>All my puters have local dnssec validators. Boooya.
21:51<buhman>trippeh_ ftw
21:51<akerl>In all the cases I've run into, OpenSSH's CA support ended up being much saner to work with
21:51<akerl>Primarily because I didn't need to link the authentication system in with the DNS systems
21:51<trippeh_>only missing on my TV and phone.
21:51<zifnab>personally i like my 'lets all be nice' idea
21:52<zifnab>all traffic *should* be able to be plaintext without someone snooping
21:52<buhman>trippeh_: toaster?
21:52<zifnab>obviously perfect world
21:52<akerl>zifnab: Reminds me about the codinghorror article about becoming a deity
21:53<zifnab>personally, i don't know why i should trust comodo or startcom to tell me that google is google
21:54<buhman>you shouldn't
21:54<zifnab>lets start a p2p ca
21:54<zifnab>i accept any keys for people i know, and one step out from that (people they know)
21:54<buhman>nor any of the other few hundred CA's mozzila has anointed so far
21:54<akerl>zifnab: lol
21:54<akerl>zifnab: You realize that's a thing, yes?
21:54<zifnab>akerl: oO really?
21:54<akerl>cacert, I think?
21:56<zifnab>maybe a blockchain style list of signatures somewhere
21:56<zifnab>(i had to throw bitcoin in here to piss off everyone)
21:56<zifnab>although from a data standpoint
21:56<buhman>x509 has no concept of 'web of trust'
21:57<zifnab>bitcoin is kinda cool
21:57<zifnab>just the data behind it
21:57<akerl>21:54:18 <zifnab> lets start a p2p ca
21:57<zifnab>oh god
21:57<zifnab>i'm so sorry
21:57<zifnab>lets call it a p2p certificate chain
21:57<buhman>sure, where zifnab's authority is zifnab
21:57<buhman>that works
21:57<Cromulent>zifnab: how about just getting all major browsers to support DAME
21:57<Nivex>zifnab: so, GPG?
21:58<zifnab>Nivex: doesn't gpgp have a central server still?
22:02<learner>how would you expect people to trust their money to a PGP
22:02<buhman>how would you expect people to trust their money simultaneously to hundreds of random CAs?
22:02-!-donspaulding [~donspauld@] has joined #linode
22:02<buhman>I'd trust a WoT over x.509 PKI any day.
22:02<learner>buhman, I wouldn't I would only trust it with a properly documented entity's CA
22:02<zifnab>i wonder if a CA has ever aid out
22:03-!-lionmac [~lionmac@] has joined #linode
22:03<akerl>"properly documented entity's CA"
22:03<akerl>buhman: I didn't think learner knew how to troll, but I think he's trolling you
22:03<buhman>well then
22:04<akerl>zifnab: Not that I'm aware of
22:04<zifnab>better question: i wonder if they have small print
22:04<zifnab>"We only pay out of if we choose to"
22:04<learner>buhman, you need a financial firm's backing, a properly channeled, rigorously evaluated company registry checking, financial record checking etc system, before issuing an acceptable certificate
22:05<learner>and certificate trust is relative
22:05<zifnab>"If we can find any possible reason that it was your fault, including keeping your private key on a server connected to the internet, it is 'Not Our Fault'(tm)"
22:06<learner>zifnab, that's financial fraud, yes not every insurance company can be trusted
22:07<learner>and in the end everything works to a relative trust
22:08-!-tzi [] has joined #linode
22:08<learner>would you trust a bank with an initial investment of 1 billion dollars to handle a 10 billion dollar wire transfer?
22:08<learner>definitely not!
22:09<tzi>Hello - just wondering, is anyone else seeing weirdness with DHCP on boot, but not whet running dhclient manually? My Ubuntu machine’s not acquiring an address on boot (times out), but after logging in, dhclient completes successfully straight away!
22:10<learner>tzi look into yor bashrc / whatever shell you're running's config
22:10<buhman>tzi: sounds like your interface may not be up.
22:11-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
22:11<learner>maybe you have something there that makes your interface go up when you log in
22:11<ctpdump>buhman: success, the insert into the sqlite3 database worked
22:11<MotoHoss>how do you log in without an ip on a linode?
22:11<ctpdump>sqlite> insert into domainmetadata values ("1","","SOA-EDIT","INCREMENT-WEEKS");
22:11<ctpdump>and dig now shows another serial
22:11<tzi>Interesting theory! I’ll have a look
22:11<zifnab>MotoHoss: lish!
22:12<ctpdump>have tried with EPOCH instead of INCREMENT-WEEKS and the serial was updating (obviously) every second
22:12<buhman>well, lish is still 'an ip'
22:13<buhman>ctpdump: heh
22:14<buhman>ctpdump: I was wondering why that section didn't say which was the default
22:14<buhman>clearly the default is null
22:14<ctpdump>there is no default apparently
22:14<ctpdump>it's up to you which one you should use
22:14<ctpdump>at least they've put a warning not to use EPOCH if you have slave servers :)
22:14<ctpdump>as they would continously refresh
22:14<buhman>are you actually spamming notifies?
22:15<buhman>that would be extremely hilarious.
22:15<ctpdump>heck yes
22:15<ctpdump>I've left it on INCREMENT-WEEKS
22:15-!-lionmac [~lionmac@] has joined #linode
22:16<ctpdump>serial now looks 2015013851
22:16<ctpdump>if I increment it in the zone file (which is 2015011503) it will become 2015013852
22:16<ctpdump>in dig
22:16<ctpdump>so it's a bit of magic
22:17<tzi>Nothing present in bashrcs (systemwide or local) that appears to touch networking; I’ve certainly made no networking changes, too. Mystery continues =)
22:18<tzi>I see “resolvconf pre-start process (1432) terminated with status 127” and “init: networking pre-start process (1960) terminated with status 1”, nothing else of interest in syslog/dmesg
22:19<buhman>upstart is all kinds of fun
22:21<tzi>During boot, after the above resolvconf message pre-start/post-stop messages, it reports “Waiting for network configuration... / Waiting up to 60 more seconds for network configuration... / Booting system without full network configuration…”, so I’m wondering if resolvconf is related
22:21<learner>tzi, send your linode to reboot while logged into lish, see what errors you get when it comes back up
22:22<tzi>Yup, that’s where I just come from learner - here’s what I see:
22:22<learner>tzi, if that's the case look into /etc/resolv.conf and /etc/resolvconf/ files
22:23-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
22:25<learner>also pastebin your /etc/network/interfaces
22:25<learner>are you sure it's configured right
22:26<tzi>Looks correct to me, yeah!
22:26-!-ctpdump [~tcpdump@2602:ffda:da:2:216:3eff:feae:d69c] has quit [Quit: Leaving]
22:26<tzi>Resolvconf stuff looks correct too;, and 5...
22:27<tzi>I presume that’s all coming from dhcp anyway
22:27<learner>tzi while on lish, do this: ifdown -a && ifup -a and see if you get any errors
22:27<learner>tzi, yep that looks ok
22:27-!-lionmac [~lionmac@] has joined #linode
22:28<tzi>Yeah, that looks fine too:
22:31<tzi>Hmm - could iptables rules be interfering with dhcp setup, in a way that *doensn’t* interfere once boot has completed?
22:31<learner>yep that's my next thing to look at
22:31<tzi>I guess I could disable my iptables setup and reboot to find out, but it’s an active and fairly busy server, so I’m loathe to pull it down
22:31<learner>pastebing iptables-save
22:31<learner>yeah don't pull it down
22:34<learner>-A FORWARD -j DROP that might be the culprit
22:35<jrhunt>for DHCP?
22:35<tzi>Yeah, could be (wouldn’t it be the “-A INPUT” line though?) - but wouldn’t that kill DHCP after boot, too?
22:35<tzi>I can’t figure out why it’d not work during boot, but work fine afterwards (once iptables is all set up)
22:36-!-lionmac [~lionmac@] has quit [Ping timeout: 480 seconds]
22:36<jrhunt>order of operations of the upstart?
22:37<learner>tzi, tail -50 /var/log/syslog
22:37<tzi>Yeah, but surely running dhcpcd *before* setting up iptables should work fine, and after shouldn’t, then?
22:38<jrhunt>i highly doubt your forward chain is involved at all in DHCP
22:39<tzi>Yeah, ditto
22:39<tzi>That final DHCP procedure was initiated manually, after logging in via lish
22:39-!-lionmac [~lionmac@] has joined #linode
22:40-!-Kellin_ [] has joined #linode
22:40-!-Kellin [] has quit [Ping timeout: 480 seconds]
22:41-!-HedgeMage [~HedgeMage@2600:3c00::f03c:91ff:fe93:c0df] has quit [Quit: Real life calls.]
