#linode IRC Logs for 2017-01-22

---Logopened Sun Jan 22 00:00:12 2017
00:04-!-borntospeed [] has quit [Ping timeout: 480 seconds]
00:04-!-mode/#linode [+l 303] by ChanServ
00:15-!-Jebula [] has quit []
00:15-!-mode/#linode [+l 302] by ChanServ
00:23-!-fergtm [] has quit [Quit: Leaving]
00:24-!-mode/#linode [+l 301] by ChanServ
00:32-!-fergtm [] has joined #linode
00:32-!-fergtm is "realname" on #linode
00:34-!-mode/#linode [+l 302] by ChanServ
00:47-!-Hideous [] has joined #linode
00:47-!-Hideous is "KUSmurf" on #linode
00:47-!-mode/#linode [+l 303] by ChanServ
00:50-!-_eyepulp [] has joined #linode
00:50-!-_eyepulp is "eyepulp" on #linode
00:50-!-eyepulp [] has quit [Read error: Connection reset by peer]
00:55-!-eyepulp [] has joined #linode
00:55-!-eyepulp is "eyepulp" on #linode
00:55-!-_eyepulp [] has quit [Read error: Connection reset by peer]
01:17-!-Hideous [] has quit []
01:17-!-Linkshot [] has joined #linode
01:17-!-Linkshot is "smf68" on #linode
01:17-!-Linkshot [] has quit [Remote host closed the connection]
01:19-!-mode/#linode [+l 302] by ChanServ
01:30-!-Eman1 [] has joined #linode
01:30-!-Eman1 is "tuhnis" on #linode
01:30-!-mode/#linode [+l 303] by ChanServ
01:53-!-kaare_ [~kaare@] has joined #linode
01:53-!-kaare_ is "Kaare Rasmussen" on #linode
01:54-!-mode/#linode [+l 304] by ChanServ
01:56-!-borntospeed [] has joined #linode
01:56-!-borntospeed is "Maxfield Hegedus" on #linode
01:57-!-mode/#linode [+l 305] by ChanServ
01:59-!-kaare__ [~kaare@] has quit [Ping timeout: 480 seconds]
02:00-!-Eman1 [] has quit []
02:00-!-mode/#linode [+l 303] by ChanServ
02:02-!-Keverw [] has quit [Quit: Textual IRC Client:]
02:02-!-mode/#linode [+l 302] by ChanServ
02:04-!-borntospeed [] has quit [Ping timeout: 481 seconds]
02:05-!-mode/#linode [+l 301] by ChanServ
02:05-!-Keverw [] has joined #linode
02:05-!-Keverw is "Textual User" on #linode
02:07-!-mode/#linode [+l 302] by ChanServ
02:10-!-Drew [] has joined #linode
02:10-!-Drew is "OFTC WebIRC Client" on #linode
02:10-!-mode/#linode [+l 303] by ChanServ
02:10-!-moonkyang [] has joined #linode
02:10-!-moonkyang is "Moonk Yang" on #linode
02:11-!-NomadJim_ [~Jim@] has quit [Read error: Connection reset by peer]
02:11-!-Bobseviltwin [] has joined #linode
02:11-!-Bobseviltwin is "realname" on #linode #debian-welcome
02:11-!-NomadJim_ [~Jim@] has joined #linode
02:11-!-NomadJim_ is "Nomad" on #debian #linode
02:12-!-mode/#linode [+l 305] by ChanServ
02:15-!-moonkyang [] has quit []
02:15-!-mode/#linode [+l 304] by ChanServ
02:19-!-Neon [] has joined #linode
02:19-!-Neon is "Morde" on #linode
02:19-!-mode/#linode [+l 305] by ChanServ
02:48-!-Neon [] has quit []
02:49-!-Jones [] has joined #linode
02:49-!-Jones is "Skyrider" on #linode
02:51-!-madbytes is "madbytes" on #debian
02:51-!-madbytes [~madbytes@] has joined #linode
02:52-!-mode/#linode [+l 306] by ChanServ
02:56-!-borntospeed [] has joined #linode
02:56-!-borntospeed is "Maxfield Hegedus" on #linode
02:57-!-mode/#linode [+l 307] by ChanServ
02:57-!-eyepulp [] has quit [Remote host closed the connection]
02:58-!-eyepulp [] has joined #linode
02:58-!-eyepulp is "eyepulp" on #linode
03:04-!-borntospeed [] has quit [Ping timeout: 480 seconds]
03:04-!-mode/#linode [+l 306] by ChanServ
03:04-!-sandeep [] has joined #linode
03:04-!-sandeep is "Laptop" on #linode
03:05-!-mode/#linode [+l 307] by ChanServ
03:07-!-kaare__ [~kaare@] has joined #linode
03:07-!-kaare__ is "Kaare Rasmussen" on #linode
03:07-!-mode/#linode [+l 308] by ChanServ
03:09-!-kaare_ [~kaare@] has quit [Ping timeout: 480 seconds]
03:09-!-mode/#linode [+l 307] by ChanServ
03:18-!-Jones [] has quit []
03:19-!-mode/#linode [+l 306] by ChanServ
03:33-!-sandeep [] has quit [Quit: sandeep]
03:34-!-mode/#linode [+l 305] by ChanServ
03:45-!-sam_ [~oftc-webi@] has joined #linode
03:45-!-sam_ is "OFTC WebIRC Client" on #linode
03:45-!-sam_ [~oftc-webi@] has quit []
04:03-!-Cromulent [] has joined #linode
04:03-!-Cromulent is "Cromulent" on #linode
04:04-!-mode/#linode [+l 306] by ChanServ
04:08-!-calvinx [~calvin@] has quit [Quit: calvinx]
04:09-!-mode/#linode [+l 305] by ChanServ
04:35-!-Cromulent [] has quit [Quit: KVIrc 4.2.0 Equilibrium]
04:35-!-mode/#linode [+l 304] by ChanServ
04:39-!-offender [] has joined #linode
04:39-!-offender is "KungFuHamster" on #linode
04:40-!-mode/#linode [+l 305] by ChanServ
04:44-!-calvinx [~calvin@] has joined #linode
04:44-!-calvinx is "Calvin Cheng" on #linode #ceph
04:44-!-mode/#linode [+l 306] by ChanServ
04:44-!-calvinx [~calvin@] has quit []
04:45-!-mode/#linode [+l 305] by ChanServ
04:53-!-RumpledElf [] has quit [Quit: My iMac has gone to sleep. ZZZzzz…]
04:54-!-mode/#linode [+l 304] by ChanServ
04:56-!-borntospeed [] has joined #linode
04:56-!-borntospeed is "Maxfield Hegedus" on #linode
04:57-!-mode/#linode [+l 305] by ChanServ
05:01-!-eagle [] has quit [Ping timeout: 480 seconds]
05:02-!-mode/#linode [+l 304] by ChanServ
05:03-!-eagle [] has joined #linode
05:03-!-eagle is "eagle" on #moocows #linuxfriends #linode-beta #linode
05:04-!-mode/#linode [+l 305] by ChanServ
05:04-!-borntospeed [] has quit [Ping timeout: 480 seconds]
05:05-!-mode/#linode [+l 304] by ChanServ
05:09-!-offender [] has quit []
05:10-!-mode/#linode [+l 303] by ChanServ
05:11-!-eagle [] has quit [Ping timeout: 480 seconds]
05:12-!-mode/#linode [+l 302] by ChanServ
05:18-!-Hejt [] has joined #linode
05:18-!-Hejt is "Rens2Sea" on #linode
05:19-!-mode/#linode [+l 303] by ChanServ
05:21-!-azwieg103 [~andrew@] has joined #linode
05:21-!-azwieg103 is "Andrew B. Zwieg" on #linode #lunchdudes
05:22-!-mode/#linode [+l 304] by ChanServ
05:33-!-Xz [] has left #linode []
05:34-!-mode/#linode [+l 303] by ChanServ
05:40-!-madbytes [~madbytes@] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
05:40-!-mode/#linode [+l 302] by ChanServ
05:41-!-madbytes is "madbytes" on #debian
05:41-!-madbytes [~madbytes@] has joined #linode
05:42-!-mode/#linode [+l 303] by ChanServ
05:48-!-Hejt [] has quit []
05:49-!-mode/#linode [+l 302] by ChanServ
05:49-!-madbytes [~madbytes@] has quit [Ping timeout: 480 seconds]
05:50-!-mode/#linode [+l 301] by ChanServ
05:56-!-marshmn [] has joined #linode
05:56-!-marshmn is "Matt Marsh" on #linode
05:57-!-mode/#linode [+l 302] by ChanServ
05:57-!-lmg [] has joined #linode
05:57-!-lmg is "AotC" on #linode
05:59-!-mode/#linode [+l 303] by ChanServ
06:01-!-borntospeed [] has joined #linode
06:01-!-borntospeed is "Maxfield Hegedus" on #linode
06:02-!-mode/#linode [+l 304] by ChanServ
06:03-!-eagle [] has joined #linode
06:03-!-eagle is "eagle" on #moocows #linuxfriends #linode-beta #linode
06:04-!-mode/#linode [+l 305] by ChanServ
06:05-!-Cromulent [] has joined #linode
06:05-!-Cromulent is "Cromulent" on #linode
06:05-!-mode/#linode [+l 306] by ChanServ
06:10-!-borntospeed [] has quit [Ping timeout: 480 seconds]
06:10-!-mode/#linode [+l 305] by ChanServ
06:12-!-pavlushka [] has joined #linode
06:12-!-pavlushka is "Pavel Sayekat" on #ubuntu-expats #tor-project #linode #alioth #debian #debian-mozilla #debian-offtopic #debian-printing #OpenBSD #oftc #debconf16-menzies-9 #debconf16-menzies-12 #debconf16-menzies-10 #debconf
06:14-!-mode/#linode [+l 306] by ChanServ
06:16-!-Sam_ [~oftc-webi@] has joined #linode
06:16-!-Sam_ is "OFTC WebIRC Client" on #linode
06:17-!-mode/#linode [+l 307] by ChanServ
06:20-!-eagle [] has quit [Ping timeout: 480 seconds]
06:20-!-mode/#linode [+l 306] by ChanServ
06:22-!-larsdesigns [] has quit [Quit: Leaving]
06:22-!-mode/#linode [+l 305] by ChanServ
06:24-!-eagle [] has joined #linode
06:24-!-eagle is "eagle" on #moocows #linuxfriends #linode-beta #linode
06:24-!-pavlushka [] has quit [Ping timeout: 480 seconds]
06:27-!-lmg [] has quit []
06:27-!-Popz [] has joined #linode
06:27-!-Popz is "Spessu" on #linode
06:28-!-marshmn [] has quit [Ping timeout: 480 seconds]
06:29-!-mode/#linode [+l 304] by ChanServ
06:42-!-madbytes is "madbytes" on #debian
06:42-!-madbytes [~madbytes@] has joined #linode
06:42-!-mode/#linode [+l 305] by ChanServ
06:45-!-moonkyang [] has joined #linode
06:45-!-moonkyang is "Moonk Yang" on #linode
06:45-!-mode/#linode [+l 306] by ChanServ
06:49-!-Sputnik7 [] has quit [Quit: -=SysReset 2.53=-]
06:50-!-mode/#linode [+l 305] by ChanServ
06:57-!-Popz [] has quit []
06:59-!-mode/#linode [+l 304] by ChanServ
07:00-!-levifig [] has joined #linode
07:00-!-levifig is "Levi Figueira" on #linode
07:00-!-mode/#linode [+l 305] by ChanServ
07:02-!-QuantumBeep [] has joined #linode
07:02-!-QuantumBeep is "Redshift" on #linode
07:02-!-mode/#linode [+l 306] by ChanServ
07:05-!-kaare__ [~kaare@] has quit [Remote host closed the connection]
07:05-!-eagle [] has quit [Ping timeout: 480 seconds]
07:05-!-kaare__ [~kaare@] has joined #linode
07:05-!-kaare__ is "Kaare Rasmussen" on #linode
07:05-!-Chris_ [~oftc-webi@] has joined #linode
07:05-!-Chris_ is "OFTC WebIRC Client" on #linode
07:06<Chris_>need some urgent assitance regarding a ticket I have open
07:08-!-Rudy [] has quit [Read error: Connection reset by peer]
07:08-!-KindOne_ [] has joined #linode
07:08-!-KindOne_ is "..." on #utdlug #suckless #qemu #php #ovirt #osm #oftc #nottor #moocows #linuxfs #linode #libevent #https-everywhere #globaleaks #gentoo #gcc #g7 #freenode #debian-next #debian #debconf #ceph #bcache #awesome #attic
07:11-!-Rudy [znc@2603:300b:b04:5ff0:250:56ff:feba:db01] has joined #linode
07:11-!-Rudy is "Rudy Valencia" on #Corsair #virt #prevue #pandorah #moocows #linuxpowered #linode
07:12-!-mode/#linode [+l 307] by ChanServ
07:12-!-Discovery [~Discovery@] has joined #linode
07:12-!-Discovery is "IlNominePatre" on #qemu #awesome #nottor #debian-next #ceph #osm #debian-mentors #linode #debian
07:13-!-KindOne- [] has joined #linode
07:13-!-KindOne- is "..." on #utdlug #suckless #qemu #php #ovirt #osm #oftc #nottor #moocows #linuxfs #linode #libevent #https-everywhere #globaleaks #gentoo #gcc #g7 #freenode #debian-next #debian #debconf #ceph #bcache #awesome #attic
07:13-!-KindOne [] has quit [Ping timeout: 480 seconds]
07:13-!-KindOne- is now known as KindOne
07:14-!-mode/#linode [+l 308] by ChanServ
07:19-!-eagle [] has joined #linode
07:19-!-eagle is "eagle" on #moocows #linuxfriends #linode-beta #linode
07:19-!-KindOne_ [] has quit [Ping timeout: 480 seconds]
07:20-!-Chris_ [~oftc-webi@] has left #linode []
07:20-!-mode/#linode [+l 307] by ChanServ
07:30-!-Sam_ [~oftc-webi@] has quit [Remote host closed the connection]
07:30-!-mode/#linode [+l 306] by ChanServ
07:31-!-pavlushka [] has joined #linode
07:31-!-pavlushka is "Pavel Sayekat" on #ubuntu-expats #tor-project #linode #alioth #debian #debian-mozilla #debian-offtopic #debian-printing #OpenBSD #oftc #debconf16-menzies-9 #debconf16-menzies-12 #debconf16-menzies-10 #debconf
07:32-!-QuantumBeep [] has quit []
07:37-!-madbytes [~madbytes@] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
07:39-!-mode/#linode [+l 305] by ChanServ
07:41-!-Bonzaii [] has joined #linode
07:41-!-Bonzaii is "dusti" on #linode
07:42-!-mode/#linode [+l 306] by ChanServ
07:43-!-pavlushka [] has quit [Ping timeout: 480 seconds]
07:44-!-mode/#linode [+l 305] by ChanServ
07:56-!-madbytes [~madbytes@] has joined #linode
07:56-!-madbytes is "madbytes" on #debian #linode
07:57-!-mode/#linode [+l 306] by ChanServ
08:05-!-pavlushka [] has joined #linode
08:05-!-pavlushka is "Pavel Sayekat" on #ubuntu-expats #tor-project #linode #alioth #debian #debian-mozilla #debian-offtopic #debian-printing #OpenBSD #oftc #debconf16-menzies-9 #debconf16-menzies-12 #debconf16-menzies-10 #debconf
08:05-!-mode/#linode [+l 307] by ChanServ
08:08-!-help-please [~oftc-webi@] has joined #linode
08:08-!-help-please is "OFTC WebIRC Client" on #linode
08:08<help-please>hi anybody online?
08:09-!-mode/#linode [+l 308] by ChanServ
08:09<help-please>i have a strange issue. i am getting 502 Bad Gateway on one of the website hosted on linode. all other sites are working fine
08:11-!-Bonzaii [] has quit []
08:11<help-please>when i Changing number of PHP sub-processes to new number it will start work again. but after few hours it will stop working and give 502
08:12-!-mode/#linode [+l 307] by ChanServ
08:18<@mcintosh>help-please: do your logs have any information that might indicate why its happening? syslog/apache/php logs (if you have them)
08:19<help-please>connect() to unix:/var/run/php5-fpm.sock failed (13: Permission denied) while connecting to upstream, client:, server: localhost, request: "GET / HTTP/1.1", upstream: "fastcgi://unix:/var/run/php5-fpm.sock:", host: "xx.xx.xx.xx"
08:20<help-please>socket dead automatically? or permission problem?
08:21-!-pavlushka_ [~pavlushka@] has joined #linode
08:21-!-pavlushka_ is "Pavel Sayekat" on #ubuntu-expats #tor-project #linode #alioth #debian #debian-mozilla #debian-offtopic #debian-printing #OpenBSD #oftc #debconf16-menzies-9 #debconf16-menzies-12 #debconf16-menzies-10 #debconf
08:21-!-purrdeta [] has quit [Ping timeout: 480 seconds]
08:21-!-pavlushka is now known as Guest1285
08:21-!-pavlushka_ is now known as pavlushka
08:23-!-purrdeta [] has joined #linode
08:23-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
08:24-!-mode/#linode [+l 308] by ChanServ
08:24<@mcintosh>help-please: give this a read
08:24-!-marshmn [] has joined #linode
08:24-!-marshmn is "Matt Marsh" on #linode
08:25<help-please>Already update the same and waiting to see those error again
08:25<help-please>in my case it will stop working after few hours .. no idea why
08:25-!-mode/#linode [+l 309] by ChanServ
08:25<help-please>all other sites working fine.. this site have very low traffic...
08:26-!-Guest1285 [] has quit [Ping timeout: 480 seconds]
08:26<help-please>few people per day.. another site have 2000+ people online ... but this small site getting 502 after few hours
08:27<help-please>the PHP-FPM socket get killed? or..
08:27-!-mode/#linode [+l 308] by ChanServ
08:27<@mcintosh>help-please: if the socket is getting killed for some reason, your logs should likely reveal why
08:28<@mcintosh>anything in /var/log/syslog (might be /var/log/messages depending on your distro)
08:28<help-please>just a second. let met check that
08:31<@mcintosh>how are you getting the site back online when it crashes?
08:34<help-please>iChanging number of PHP sub-processes
08:34<help-please>Changing number of PHP sub-processes Via virtualmin will bring back the site online
08:35-!-steveski [] has joined #linode
08:35-!-steveski is "purple" on #linode
08:35<help-please>but after few hours it will went back to SAME STATE .. take very long time to respond (2+ Minutes or show w8ting for ever) or simply return 503
08:35-!-mode/#linode [+l 309] by ChanServ
08:36<help-please>i look syslog and not found anything useful
08:36<help-please>NOQUEUE: reject: RCPT from unknown[]: 550 5.1.1 <>: Recipient address rejected: User unknown in virtual alias table;
08:36<help-please>see the above logs few times
08:36<help-please>that is not our email
08:36<@mcintosh>probably unrelated to this
08:37<@mcintosh>did you restart php-fpm/apache after modifying the permissions like in the link I sent previously?
08:37<@mcintosh>if not, do that
08:37<help-please>may be listen.mode = 0660 fix this issue? for now it is working fine.. if it is came back where should i look for?
08:38<help-please>restart nginx fpm etc.. also done a full server resart L)
08:41<@mcintosh>help-please: php --info | grep error
08:41<@mcintosh>that might help
08:42<help-please>display_errors => Off => Off display_startup_errors => Off => Off error_append_string => no value => no value error_log => no value => no value error_prepend_string => no value => no value error_reporting => 22527 => 22527 html_errors => Off => Off ignore_repeated_errors => Off => Off log_errors => On => On log_errors_max_len => 1024 => 1024 track_errors => Off => Off xmlrpc_error_number => 0 => 0 xmlrpc_errors => Off => Off opcache.error_log => no va
08:43<@mcintosh>i'd recommend adding an error_log line in php.ini so that you can log potentially related errors
08:43<@mcintosh>error_log = /var/log/php/php.log
08:43<@mcintosh>something like that, restart php-fpm, then it should start logging errors
08:43<@mcintosh>may assist if it reoccurs
08:43<help-please>Thanks bro
08:48<@mcintosh>no problem
08:51-!-_404`d [~404d@] has quit [Ping timeout: 480 seconds]
08:51-!-cyphase1 [] has joined #linode
08:51-!-cyphase1 is "verbalins" on #linode
08:53-!-help-please [~oftc-webi@] has quit [Quit: Page closed]
08:54-!-mode/#linode [+l 308] by ChanServ
09:00-!-_404`d [] has joined #linode
09:00-!-_404`d is "YOU'LL NEVER KNOW" on #linode
09:00-!-mode/#linode [+l 309] by ChanServ
09:21-!-cyphase1 [] has quit []
09:22-!-moonkyang [] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
09:22-!-mode/#linode [+l 307] by ChanServ
09:22-!-moonkyang [] has joined #linode
09:22-!-moonkyang is "Moonk Yang" on #linode
09:23-!-moonkyang [] has quit []
09:25-!-moonkyang [] has joined #linode
09:25-!-moonkyang is "Moonk Yang" on #linode
09:25-!-mode/#linode [+l 308] by ChanServ
09:47-!-moonkyang [] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
09:47-!-mode/#linode [+l 307] by ChanServ
09:51-!-madbytes [~madbytes@] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
09:52-!-mode/#linode [+l 306] by ChanServ
10:04-!-madbytes [~madbytes@] has joined #linode
10:04-!-madbytes is "madbytes" on #debian #linode
10:04-!-mode/#linode [+l 307] by ChanServ
10:11-!-WedTM [] has joined #linode
10:11-!-WedTM is "TheDoudou_a" on #linode
10:12-!-mode/#linode [+l 308] by ChanServ
12:08<@jdfriedrikson>there are also ways of hosting ipv6-only servers while still making them reachable via ipv4
12:08<@jdfriedrikson>but that requires $work
12:10<Nivex>Speaking of which, $work still progressing on making a nodebalancer connect to its backend over v6?
12:12-!-madbytes [~madbytes@] has quit [Ping timeout: 480 seconds]
12:12<linoob>I mainly wanted to keep my domain names on separate IPs because I don't like them all being lumped together on agregate statistic sites under the same IP. I asked for just one extra ip for my linode so I could at least separate work and fun sites, but I got the usual shakedown about "needing" it and ended up with an ipv6 pool instead
12:13-!-madbytes [~madbytes@] has joined #linode
12:13-!-madbytes is "madbytes" on #debian #linode
12:15<@jdfriedrikson>have you tried cloudflare? if you're wanting to conceal whether or not sites are connected, cloudflare would be a better solution
12:16-!-whallz [~whallz@] has joined #linode
12:16-!-whallz is "whallz" on #linode #awesome
12:16<Peng>Different sites on one Cloudflare account can look connected-ish.
12:16<Peng>Same nameservers and TLS certificates and sometimes IPs
12:17-!-mode/#linode [+l 312] by ChanServ
12:19<Nivex>You could split the work and fun out to separate linodes too
12:21<@jdfriedrikson>Peng: that's an issue with the nameservers / certificates then. It's 2017 and SNI is here. Separate certs are possible. You can also get them from different CAs
12:21<@jdfriedrikson>also all those problems will exist for a separate IP as well
12:22<linoob>I'm considering separate linodes, but I don't know if I can justify the cost
12:22<Nivex>Are you on the lowest plan already?
12:23<linoob>hmm. divide and conquer approach?
12:25-!-steveski [] has quit [Remote host closed the connection]
12:25<Nivex>Yeah. If on a 4GB split it out to two 2GBs. Assuming your load will handle it.
12:25-!-mode/#linode [+l 311] by ChanServ
12:27<dwfreed>jdfriedrikson: CloudFlare needs to work for people still on old platforms that don't have SNI, so they do certs with long lists of subjectAltNames
12:28<Peng>back in my day, wget didn't support SAN
12:28<@jdfriedrikson>but can you use separate certs with cloudflare?
12:28<Peng>jdfriedrikson: $$$
12:29<Peng>Well, just $. $5/month, i think. Probably requires SNI?
12:29<FluffyFoxeh>It's $CURRENT_YEAR
12:30<dwfreed>Peng: VIPs are basically free from CloudFlare's perspective
12:30-!-ulterior [] has quit []
12:30-!-mode/#linode [+l 310] by ChanServ
12:31<dwfreed>also note that python2.7 did not get SNI support until 2.7.9; *many* python 2.7 installations are too old to have it
12:31<FluffyFoxeh>I'm trying to sign my own certs with my own "CA" but damn this is such a pain in the ass
12:31-!-madbytes [~madbytes@] has quit [Ping timeout: 480 seconds]
12:31<dwfreed>FluffyFoxeh: not really
12:31<Peng>dwfreed: Ha ha ha that doesn't matter because older Python doesn't validate certificates either ha ha ha
12:32<dwfreed>Peng: there's that
12:32*Peng screams
12:32<Peng>> A: Cloudflare Dedicated SSL Certificates require SNI sent from the browser.
12:32<FluffyFoxeh>dwfreed: there's so much shit that goes into an x509, and none of it is documented concisely
12:32-!-mode/#linode [+l 309] by ChanServ
12:32<@jdfriedrikson>FluffyFoxeh: you should use easy-rsa
12:32<FluffyFoxeh>in the context of SSL
12:32<@jdfriedrikson>it's intended for openvpn, but you can tweak the settings for other cases
12:33*jdfriedrikson uses his own CA for internal stuff (for useless fun)
12:33<Nivex>"We need better security!" "You broke my shit!"
12:34<FluffyFoxeh>jdfriedrikson: I'm doing it because my <$1 Comodo cert that I used for my IMAP expired last week :p
12:34<@jdfriedrikson>something something ACME
12:34<FluffyFoxeh>I'm the only one who uses my IMAP server so idc if it's self signed
12:35<DrJ>I will never use comodo
12:35<FluffyFoxeh>or expired for that matter, but I figure I should finally figure out how this certificate business actually *works*
12:35-!-spidu_ [] has joined #linode
12:35-!-spidu_ is "airsoftglock" on #linode
12:35<@jdfriedrikson>I'm the only one that uses my XMPP server :'( that feel when you go through the effort to self-host your comms but you have no one to talk to
12:35<DrJ>those people scans websites looking for certs that are about to expire and then cold call the owners and make it sound like the cert is already with them and they need to renew with them
12:35-!-mode/#linode [+l 310] by ChanServ
12:35<Nivex>Everyone's on Facebook now
12:36<FluffyFoxeh>most of my friends don't really use facebook actually :p
12:36<DrJ>I've yelled at comodo on the phone at work tens of times to stop calling me because I will never use them
12:36<dwfreed>because everybody's lazy and it's just easier to not self-host
12:37<Peng>I use Comodo. Not many ways to get an ECDSA certificate for $99.
12:37<FluffyFoxeh>most people don't even know what self hosting means
12:37<Peng>$9 !
12:37<@jdfriedrikson>I host for my friends
12:37<FluffyFoxeh>it's just in the clouds
12:37<dwfreed>Peng: make your own!
12:37*jdfriedrikson lives in the clouds. come up to my level.
12:37<Nivex>♫ I get my with little host from my friends ♫
12:37<Nivex>get *by* *sigh* I can't type
12:38<FluffyFoxeh>I wonder if people my age would understand that reference
12:38<FluffyFoxeh>idk how popular it is still
12:38<dwfreed>I know the song
12:38<dwfreed>I'm 24
12:39<FluffyFoxeh>ah, I guess I assumed Nivex was old
12:40<FluffyFoxeh>just tripped over my dog, she camouflages too perfectly with this black rug
12:40<dwfreed>I'm pretty sure he's older than me, but he's not that old
12:41-!-whallz [~whallz@] has quit [Ping timeout: 480 seconds]
12:41<Nivex>(and yes I'll be 37 in a short number of weeks)
12:42-!-mode/#linode [+l 309] by ChanServ
12:48-!-seanh-corona [] has joined #linode
12:48-!-seanh-corona is "Adium User" on #linode
12:49-!-mode/#linode [+l 310] by ChanServ
12:49-!-seanh-corona [] has quit []
12:50-!-blaflamm_ [~blaflamme@2001:18c0:25e:926:7099:b5cd:89be:695e] has joined #linode
12:50-!-blaflamm_ is "Blaise Laflamme" on #linode-beta #linode
12:52<jiggawattz>Nivex: happy birthday you old fart
12:54-!-blaflamme [~blaflamme@2001:18c0:25e:926:7485:e085:609c:6fa8] has quit [Ping timeout: 480 seconds]
12:55-!-mode/#linode [+l 309] by ChanServ
12:55<@jdfriedrikson>(in a short number of weeks) != happy birthday
12:56<FluffyFoxeh>happy birthday eventually
12:56<@jdfriedrikson>it's going to be my birthday in a short number of weeks too
12:56-!-linoob [~oftc-webi@2601:6c2:4002:20f7:1d19:1786:88c9:1590] has quit [Quit: Page closed]
12:57-!-mode/#linode [+l 308] by ChanServ
12:57<Peng>49 weeks, whooo!
12:59-!-Cromulent [] has quit [Ping timeout: 480 seconds]
12:59<@jdfriedrikson>that's a short number IMO
13:00-!-mode/#linode [+l 307] by ChanServ
13:05-!-spidu_ [] has quit []
13:05-!-mode/#linode [+l 306] by ChanServ
13:12-!-whallz [~whallz@] has joined #linode
13:12-!-whallz is "whallz" on #linode #awesome
13:14-!-mode/#linode [+l 307] by ChanServ
13:15-!-cyberactivities [~oftc-webi@2600:1012:b124:7c0a:d845:ee5b:8b42:216a] has joined #linode
13:15-!-cyberactivities is "OFTC WebIRC Client" on #linode
13:15-!-mode/#linode [+l 308] by ChanServ
13:16<cyberactivities>anybody home
13:17-!-cyberactivities [~oftc-webi@2600:1012:b124:7c0a:d845:ee5b:8b42:216a] has quit []
13:17-!-mode/#linode [+l 307] by ChanServ
13:19<FluffyFoxeh>it's Sunday of course I'm at home
13:23-!-Izanagi [] has joined #linode
13:23-!-Izanagi is "demonspork" on #linode
13:24-!-mode/#linode [+l 308] by ChanServ
13:33-!-seanh-corona [] has joined #linode
13:33-!-seanh-corona is "Adium User" on #linode
13:34-!-mode/#linode [+l 309] by ChanServ
13:38-!-marshmn [] has quit [Ping timeout: 480 seconds]
13:39-!-mode/#linode [+l 308] by ChanServ
13:51-!-seanh-corona [] has quit [Quit: Leaving.]
13:52-!-mode/#linode [+l 307] by ChanServ
13:53-!-Izanagi [] has quit []
13:54-!-mode/#linode [+l 306] by ChanServ
14:06-!-rhonabwy [] has joined #linode
14:06-!-rhonabwy is "JWilbur" on #linode
14:07-!-mode/#linode [+l 307] by ChanServ
14:08-!-Discovery [~Discovery@] has quit [Read error: Connection reset by peer]
14:09-!-mode/#linode [+l 306] by ChanServ
14:17-!-Cromulent [] has joined #linode
14:17-!-Cromulent is "Cromulent" on #linode
14:17-!-mode/#linode [+l 307] by ChanServ
14:26-!-Cromulent [] has quit [Quit: KVIrc 4.2.0 Equilibrium]
14:27-!-mode/#linode [+l 306] by ChanServ
14:36-!-rhonabwy [] has quit []
14:36-!-n0x1d [] has joined #linode
14:36-!-n0x1d is "murmur" on #linode
14:46-!-JoshuaAC- is now known as JoshuaACasey
15:01-!-eyepulp [] has quit [Remote host closed the connection]
15:01-!-eyepulp [] has joined #linode
15:01-!-eyepulp is "eyepulp" on #linode
15:06-!-n0x1d [] has quit []
15:07-!-mode/#linode [+l 305] by ChanServ
15:11-!-Bj_o_rn [] has joined #linode
15:11-!-Bj_o_rn is "Architect" on #linode
15:12-!-mode/#linode [+l 306] by ChanServ
15:14-!-pavlushka [] has quit [Quit: See you on the other side.....]
15:15-!-Baruch [] has joined #linode
15:15-!-Baruch is "OFTC WebIRC Client" on #linode
15:15-!-eyepulp [] has quit [Read error: Connection reset by peer]
15:15-!-mode/#linode [+l 305] by ChanServ
15:15-!-eyepulp [] has joined #linode
15:15-!-eyepulp is "eyepulp" on #linode
15:17-!-mode/#linode [+l 306] by ChanServ
15:18-!-Baruch [] has quit []
15:18-!-schwa [] has quit [Ping timeout: 480 seconds]
15:19-!-mode/#linode [+l 304] by ChanServ
15:34-!-Steve^^ [~Steve^^^^] has joined #linode
15:34-!-Steve^^ is "realname" on #linode
15:35-!-mode/#linode [+l 305] by ChanServ
15:41-!-Bj_o_rn [] has quit []
15:42-!-mode/#linode [+l 304] by ChanServ
15:45-!-richardus1 [] has joined #linode
15:45-!-richardus1 is "Lite" on #linode
15:45-!-mode/#linode [+l 305] by ChanServ
16:03-!-Steve^ [] has joined #linode
16:03-!-Steve^ is "Got ZNC?" on #linode
16:04-!-mode/#linode [+l 306] by ChanServ
16:04-!-Steve^^ [~Steve^^^^] has quit [Quit: Leaving]
16:04-!-Steve^ [] has quit [Remote host closed the connection]
16:05-!-mode/#linode [+l 304] by ChanServ
16:13-!-V-Pariah_ [] has quit [Read error: Connection reset by peer]
16:14-!-mode/#linode [+l 303] by ChanServ
16:15-!-richardus1 [] has quit []
16:15-!-mode/#linode [+l 302] by ChanServ
16:17-!-V-Pariah_ [] has joined #linode
16:17-!-V-Pariah_ is "Vicious Pariah" on #linode
16:17-!-mode/#linode [+l 303] by ChanServ
16:20-!-Keiya [] has joined #linode
16:20-!-Keiya is "luckz" on #linode
16:20-!-mode/#linode [+l 304] by ChanServ
16:45-!-aleem [~oftc-webi@] has joined #linode
16:45-!-aleem is "OFTC WebIRC Client" on #linode
16:45-!-schwa [] has joined #linode
16:45-!-schwa is "purple" on #linode
16:45-!-mode/#linode [+l 306] by ChanServ
16:50-!-eyepulp [] has quit [Remote host closed the connection]
16:50-!-Keiya [] has quit []
16:50-!-eyepulp [] has joined #linode
16:50-!-eyepulp is "eyepulp" on #linode
16:50-!-mode/#linode [+l 305] by ChanServ
16:53-!-aleem [~oftc-webi@] has quit [Quit: Page closed]
16:54-!-mode/#linode [+l 304] by ChanServ
17:08-!-QuantumBeep [] has joined #linode
17:08-!-QuantumBeep is "Averad" on #linode
17:09-!-mode/#linode [+l 305] by ChanServ
17:20-!-marshmn [] has joined #linode
17:20-!-marshmn is "Matt Marsh" on #linode
17:20-!-mode/#linode [+l 306] by ChanServ
17:27-!-SimonHampel [~SimonHamp@2001:44b8:313f:400:4c6b:50ed:eda8:f3b5] has joined #linode
17:27-!-SimonHampel is "realname" on #linode
17:27-!-mode/#linode [+l 307] by ChanServ
17:35-!-Sputnik7 [] has joined #linode
17:35-!-Sputnik7 is "floating" on #linode
17:35-!-mode/#linode [+l 308] by ChanServ
17:38-!-QuantumBeep [] has quit []
17:39-!-mode/#linode [+l 307] by ChanServ
17:41<MJCS>!wx ksna
17:41<linbot>MJCS: [metar] OBS at KSNA: 57.2F/14C, visibility 1 miles, wind 17.26 mph, chill 53.47F (altimeter: ) [KSNA 222238Z 16015G25KT 1SM R20R/4500V6000FT +RA BR FEW009 BKN012 OVC018 14/13]
17:56-!-Lunk2 [] has joined #linode
17:56-!-Lunk2 is "offender" on #linode
17:56-!-Hazelesque [] has joined #linode
17:56-!-Hazelesque is "Hazel" on #linode #bongo #osm #ceph #nlug
17:57-!-mode/#linode [+l 309] by ChanServ
17:59-!-borntospeed [] has joined #linode
17:59-!-borntospeed is "Maxfield Hegedus" on #linode
18:00-!-mode/#linode [+l 310] by ChanServ
18:02<Hazelesque>Hi, I'm having a slightly weird issue with a Linode I built only today, running Fedora 25
18:02<Hazelesque>for some reason, IPv6 connectivity appears to be completely broken
18:03<Hazelesque>and yet, on a linode I built at around the same time, with Ubuntu 16.04 LTS, it is working OK
18:03<@jdfriedrikson>Hazelesque: describe completely broken. How are you configuring your IPv6 address?
18:03<Hazelesque>on the former, doing "ping6 ff02::2%eth0" fails
18:03-!-marshmn [] has quit [Ping timeout: 480 seconds]
18:03<Hazelesque>but on the latter, I get replies from the routers on the link
18:03<Hazelesque>(ff02::2 being the all-routers multicast address)
18:03<@jdfriedrikson>are you manually assigning it? are you using SLAAC? Trying to use DHCPv6?
18:04-!-mode/#linode [+l 309] by ChanServ
18:04<Hazelesque>jdfriedrikson: I've not changed it from how it came out of the image
18:04<Hazelesque>it's configured in /etc/sysconfig/network-scripts/ifcfg-eth0
18:05<@jdfriedrikson>I'm thinking maybe SLAAC is taking a little bit of time
18:06<Hazelesque>I built the machine today, but it was several hours ago
18:06<@jdfriedrikson>which datacenter?
18:06<Hazelesque>it's been up 5 hours
18:07<@jdfriedrikson>give me a moment. testing this myself
18:07<Hazelesque>OK, thanks
18:07<Hazelesque>(it's a Fedora 25 box it's failing on, and a Ubuntu 16.04 LTS box that it is working OK on)
18:07<Hazelesque>(both brand new linodes, created around the same time)
18:07<@jdfriedrikson>we very recently pushed out our F25 image
18:08<Hazelesque>I see
18:08<Hazelesque>well, "ping6 ff02::2%eth0" fails on the fedora box, as does "ping6"
18:08<Hazelesque>and the thing that perplexed me was that "traceroute6" just gives me all stars
18:08<Peng>Hazelesque: pastebin 'ip -6 a' and 'ip -6 r' ?
18:08<Hazelesque>I don't get responses from any hops at all
18:08<Hazelesque>Peng: sure...
18:09<@jdfriedrikson>ugh I know what it is
18:09<@jdfriedrikson>I think we're already working to fix it
18:09<Hazelesque>jdfriedrikson: oh?
18:11<@jdfriedrikson>hmmm nah
18:11<@jdfriedrikson>I was wrong
18:11<Hazelesque>ah, ok
18:11<Hazelesque>jdfriedrikson: were you able to repro? does it fail for you if you build a fresh F25 linode?
18:12<Hazelesque>well, I'm glad it's not just me going mad
18:13<Peng>Hazelesque: grep slaac /etc/dhcpcd.conf
18:14<Peng>Hazelesque: sysctl -a | grep use_tempaddr
18:14<Hazelesque>grep: /etc/dhcpcd.conf: No such file or directory
18:18<Hazelesque>Peng: have updated with the output of those commands
18:18<Hazelesque>for both the broken (fedora 25) linode and the working (ubuntu 1604) linode
18:19<@jdfriedrikson>try disabling firewalld
18:19<Peng>Clearly something gave Fedora the wonderful idea to generate privacy IPv6 addresses. The question is what. D:
18:20<Peng>If it was Arch i'd blame dhcpdc and /etc/dhcpcd.conf but it's either something else or stored somewhere else...
18:20<@jdfriedrikson>systemctl stop firewalld; systemctl disable firewalld
18:20<Hazelesque> Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)
18:20<Hazelesque> Active: inactive (dead) since Sun 2017-01-22 18:48:58 UTC; 4h 31min ago
18:20<Hazelesque>^ already done 4h31m ago
18:21<Peng> might be it
18:21<@jdfriedrikson>I was getting through for a few moments after disabling. weird.
18:21<Peng>that's for GUI Fedora and blames NetworkManager and /etc/sysconfig/network-scripts/ifcfg-eth0
18:22<@jdfriedrikson>Peng: you're correct
18:22<Hazelesque>I presume that Linode is doing some kind of filtering on the IPv6 /64 to only allow SLAAC addresses that are derived from the MAC address assigned to the host?
18:22<@jdfriedrikson>well yeah. we definitely do not want Linodes using IPs that aren't assigned to them? could you imagine??
18:23<Peng>Hazelesque: They filter anything but your assigned IP addresses, yes. By default you only have one IPv6 IP, a standard EUI-64 address that can be configured using SLAAC. You can request more IPs, though.
18:24<Hazelesque>I note that the Linode Manager control panel says that ipa4's address is 2a01:7e00::f03c:91ff:fee7:eb58 / 64 but the linode itself has 2a01:7e00::7dc:9c42:36bb:93cf (global) and fe80::ddef:fb2c:6469:1d98 (link local) configured...
18:24<Hazelesque>s/configured/according to the output of "ip -6 addr show"/
18:24<Peng>Hazelesque: Yes, exactly. The node's networking stack is configured to derive some random IP address for privacy purposes, which Linode's infrastructure blocks because it's not your IP.
18:25<Hazelesque>Peng: yeah, I have "2a01:7e00::34:4000 - 2a01:7e00::34:4fff (4096 addresses)" and "2a01:7e00:e001:3e00:: / 56 routed to 2a01:7e00::34:4000"
18:25<Peng>Oh, nice.
18:25<Peng>So you can use any of those IPs, or invent random IPs from anywhere inside that /56, but 2a01:7e00::7dc:9c42:36bb:93cf is very much not assigned to you. :X
18:26<Peng>2a01:7e00:e001:3eff:7dc:9c42:36bb:93cf? Sure! 2a01:7e00::7dc:9c42:36bb:93cf? No.
18:26-!-Lunk2 [] has quit []
18:26<Peng>jdfriedrikson: Was i right that that's the specific setting involved?
18:26<@jdfriedrikson>you were not :(
18:27<Hazelesque>Peng: in my defence, as far as I can tell this is how Fedora was configured when I booted the machine from Linode's prebaked image... so /I/ didn't break it ;)
18:27<Hazelesque>I did think it a little odd when I noticed it
18:27-!-mode/#linode [+l 308] by ChanServ
18:27<Peng>Hazelesque: Sure. I'm not blaming you. :)
18:28<Hazelesque>I tried reading the docs at but got a little confused as to why it was telling me to configure IPV6ADDR_SECONDARIES
18:28<Peng>*What* it's doing is clear. Which software and which configuration files are responsible, i have noooo idea. I don't run Fedora.
18:28<Hazelesque>Ah, right, okay
18:28<Hazelesque>so if I can figure out how to tell Fedora to not use privacy addresses, then it should work?
18:33<Hazelesque>so, I already have IPV6_ADDR_GEN_MODE=eui64 in /etc/sysconfig/network-scripts/ifcfg-eth0
18:33<@jdfriedrikson>it's tring the wrong route
18:33<@jdfriedrikson>ugh I can barely think rn
18:34<@jdfriedrikson>I get things like 23:34:28.578926 IP6 li1520-158 > ff02::1:ff00:0: ICMP6, neighbor solicitation, who has 2a01:7e00::, length 32 when I try pinging out
18:34<@jdfriedrikson>should be fe80::1
18:39<@jdfriedrikson>SLAAC is misconfigured
18:41<@jdfriedrikson>this is definitely static routing issues
18:44<@jdfriedrikson>nailed it
18:45<Hazelesque>net.ipv6.conf.eth0.accept_ra_defrtr = 0
18:45<@jdfriedrikson>you want to set that to 1
18:45<Hazelesque>on fedora 25, vs net.ipv6.conf.eth0.accept_ra_defrtr = 1 on ubuntu 16.04
18:45<Hazelesque>jdfriedrikson: that would make sense! :)
18:45<@jdfriedrikson>what's happening is your Linode is trying to use the first address in it's own address's prefix by default
18:45<@jdfriedrikson>instead of using fe80::1
18:46<@jdfriedrikson>try looking at the other options. seems to be related
18:46<@jdfriedrikson>(in my paste)
18:46<Hazelesque>jdfriedrikson: yeah, I see you mention net.ipv6.conf.eth0.accept_ra_pinfo as well
18:46<@jdfriedrikson>it's a diff against working ipv6 output
18:47<Hazelesque>ahhh, right!
18:47<Hazelesque>that makes sense :)
18:47<@jdfriedrikson>if I were a bettin' man, I'd guess that your Ubuntu 16.04 Linode has that set
18:47<@jdfriedrikson>can you check?
18:47<Hazelesque>one sec...
18:49<@jdfriedrikson>fedora has shitty documentation on v6 and nm -_-
18:49<Hazelesque>jdfriedrikson: you shock me ;)
18:50<@jdfriedrikson>they look identical :(
18:51<@jdfriedrikson>how'd accept_ra_defrtr get set? did you do that?
18:51<@jdfriedrikson>oh wait
18:52<@jdfriedrikson>excuse me while I derp about for a moment
18:52<Hazelesque>they are slightly different
18:53<@jdfriedrikson>it's the eth0 conf that gets me
18:53-!-basicxman [] has joined #linode
18:53-!-basicxman is "mrapple" on #linode
18:53<@jdfriedrikson>it's making me think that NM is interfering
18:54-!-mode/#linode [+l 309] by ChanServ
18:54<Hazelesque>so, I added the output of that command from the ubuntu machine to /etc/sysctl.conf on the fedora machine
18:54<Hazelesque>then restarted networkmanager, then waited a bit
18:54<Hazelesque>and now it seems that I can ping6
18:54<Hazelesque>though ping6 ff02::2%eth0 still does nowt
18:55<@jdfriedrikson>now to go through /usr/share/doc/initscripts-*/sysconfig.txt
18:56<Hazelesque>and now i can successfully wget
18:56<Hazelesque>which was the reason I noticed (and started swearing at) the broken ipv6
18:57<Hazelesque>I could have just gone "NOPE, TURNING IPV6 OFF NOW" but I don't want to be a terrible human
18:57<@jdfriedrikson>lol I do it for my personal servers
18:57<Hazelesque>(besides, I have native IPv6 at home, it's quite nice)
18:57<Hazelesque>what, just turning it off?
18:57<@jdfriedrikson>I will never feel confident in my v6 skills until I get the fancy HE cert
18:58<Hazelesque>jdfriedrikson: I've spent most of this weekend setting up the Cisco Wireless LAN Controller I bought on ebay
18:58<Peng>and that fancy HE shirt
18:58<@jdfriedrikson>literally the v6 version of "I participated"
18:58<@jdfriedrikson>HE > Cogent
18:58<@jdfriedrikson>and nice Hazelesque!!
18:59<Hazelesque>I've got a couple of Cisco AIR-LAP1242AG access points hanging off it
18:59<Hazelesque>which I managed to get to join the WLC
18:59<Hazelesque>after I got my DHCP and VLAN configs right
18:59<Hazelesque>I have an older 1200 series AP which requires me to piss about with a Windows(!) tool to "upgrade" it to Lightweight mode though
19:00<Hazelesque>as the earlier 1200 series don't have a MIC (Manufacturer Installed Certificate)
19:00<Hazelesque>so it has to generate a self-signed cert, then enrol that with the WLC
19:01-!-borntospeed [] has quit [Ping timeout: 480 seconds]
19:02<Hazelesque>jdfriedrikson: quick #pcbselfie from yesterday >>
19:02-!-mode/#linode [+l 308] by ChanServ
19:02<Hazelesque>there's a "hidden" RJ45 port inside the chassis, on the Wireless LAN controller board
19:02<Hazelesque>marked "MIRROR PORT"
19:03<Hazelesque>I presume that's not presented on the back panel on the basis that a single 1Gbps port is not especially useful as a mirror of 2x 1Gbps SFP slots
19:03<Hazelesque>I *think* the Cisco 3750G switch that the WLC is embedded inside should be capable of doing SPAN-style port mirroring
19:04-!-Steve^ [~Steve^] has joined #linode
19:04-!-Steve^ is "Got ZNC?" on #linode
19:04-!-mode/#linode [+l 309] by ChanServ
19:04<Hazelesque>so I should be able to mirror the two SFP ports (that are in an etherchannel group) at the *switch* end
19:04-!-borntospeed [] has joined #linode
19:04-!-borntospeed is "Maxfield Hegedus" on #linode
19:04<Hazelesque>which should be functionally equivalent
19:04<Hazelesque>nonetheless, it was an amusing find
19:05<@jdfriedrikson>I like hidden things
19:05-!-mode/#linode [+l 310] by ChanServ
19:06<Hazelesque>jdfriedrikson: apparently the company I bought it from on eBay were less inquisitive
19:06<Hazelesque>this unit had a "DATA ERASED" sticker
19:06<Hazelesque>except, well...
19:06<Hazelesque>they only erased the config on the switch, not the /totally separate/ config on the embedded WLC
19:06<Hazelesque>which is probably more sensitive
19:06<@jdfriedrikson>what'd you find?
19:07<Hazelesque>I didn't look that closely, but there were wifi SSIDs, some RSA private keys, ...
19:07<Hazelesque>(from running strings on the image I took of the CompactFlash card...)
19:07<Hazelesque>(strings(1), that is)
19:08<Hazelesque>(the compact flash card that you have to TAKE THE FUCKING THING APART to get to...)
19:08<Hazelesque>(and there's some kind of glue to make it even harder to remove the CF card, heh.)
19:08<Hazelesque>(not that that stopped me :P)
19:11<Hazelesque>jdfriedrikson / Peng: thanks for your help!
19:12<@jdfriedrikson>any time!
19:12<@jdfriedrikson>just trying to figure out why Fedora's network configuration stuff is a dumpster fire
19:15-!-borntospeed [] has quit [Ping timeout: 480 seconds]
19:15-!-borntospeed [] has joined #linode
19:15-!-borntospeed is "Maxfield Hegedus" on #linode
19:17<@jdfriedrikson>I sincerely hate NM. It needs to die a slow death. I don't understand why we're always using these useless layers of abstraction for simple problems
19:17<Sputnik7>yah, fuck new mexico
19:17<millisa>s/nm/systemd/ ?
19:18<@jdfriedrikson>systemd != nm
19:18<millisa>i think I have the same level of hate for about the same reasons for both
19:18<@jdfriedrikson>fedora + centos rely on NM for its network stuff
19:18<@jdfriedrikson>systemd at least makes sense when you take the time to learn it
19:18<@jdfriedrikson>though, I do also really like OpenRC
19:20<Nivex>networkmanager is nice on laptops where the network is dynamically changing, but I have no idea who thought it would be a good idea to use it on a server
19:21<Nivex>though the nmcli on the 1.0 series is kinda nice
19:21<Hazelesque>Nivex: my experience of nmcli is that the output changes, incompatibly, far too often
19:22<Hazelesque>I was writing a vagrantfile to test the company VPN setup against different linux versions... and to script the testing, I used nmcli...
19:22<Hazelesque>but I had to fuck about quite a lot to get something that would Do The Right Thing with nmcli across, say, three successive versions of Ubuntu
19:23<FluffyFoxeh>systemd has its own network beast doesn't it
19:23-!-basicxman [] has quit []
19:23-!-aspis [] has quit [Quit: Leaving]
19:23<@jdfriedrikson>not really
19:23<@jdfriedrikson>well yeah
19:23<Nivex>and don't forget that RHEL changed from 0.9.x to 1.0.x on a minor rev. That won't screw anything up, noooooo
19:23-!-aspis [] has joined #linode
19:23-!-aspis is "aspis" on #linode
19:23<FluffyFoxeh>ifupdown is reasonably simple
19:24-!-mode/#linode [+l 309] by ChanServ
19:24<Nivex>the major disadvantage to the /etc/network/interfaces model is that it's not easily machine/script updatable
19:25*Hazelesque finds the code...
19:25<Hazelesque>p = subprocess.Popen(['/usr/bin/env', 'nmcli', '-t', '-f', 'NAME,UUID', 'con'], shell=False, stdout=subprocess.PIPE)
19:25<Hazelesque>that was what I had to do in the end
19:25<Hazelesque>(the function that was in was called "_get_nm_con_name_for_uuid")
19:26<Hazelesque>(it was in an nm-dispatcher.d script)
19:26<Hazelesque>(to automatically reconfigure dnsmasq on VPN up/down events)
19:27<Nivex>of course the fact that we even have interfaces, network-scripts, networkmanager, systemd-networkd, etc:
19:27<Hazelesque>took me days, but I eventually got the script and the automated tests working on ubuntu 12.04, 14.04, 14.10, 15.04 and fedora 22
19:28<Hazelesque>Nivex: heh.
19:29-!-eyepulp [] has quit [Remote host closed the connection]
19:29-!-eyepulp [] has joined #linode
19:29-!-eyepulp is "eyepulp" on #linode
19:32-!-danielsj [] has joined #linode
19:32-!-danielsj is "Dinnerbone" on #linode
19:32-!-mode/#linode [+l 310] by ChanServ
19:36-!-beuker [] has joined #linode
19:36-!-beuker is "tim" on #linode #powerdns-dev #tor-project #tor #tails #subgraph #powerdns #otr #oftc #globaleaks #gcc #dfri_se @#BN
19:37-!-mode/#linode [+l 311] by ChanServ
19:53-!-beuker [] has quit [Quit: WeeChat 1.8-dev]
19:54-!-mode/#linode [+l 310] by ChanServ
19:54-!-Drew [] has quit [Remote host closed the connection]
19:55-!-mode/#linode [+l 309] by ChanServ
19:59-!-bbankes [] has joined #linode
19:59-!-bbankes is "realname" on #linode
19:59-!-mode/#linode [+l 310] by ChanServ
20:02-!-danielsj [] has quit []
20:02-!-mode/#linode [+l 309] by ChanServ
20:04-!-Beuker [] has joined #linode
20:04-!-Beuker is "tim" on #linode #tor-project #tor #tails #subgraph #powerdns #otr #oftc #globaleaks #gcc #dfri_se @#BN
20:04-!-mode/#linode [+l 310] by ChanServ
20:14-!-kaare__ [~kaare@] has quit [Ping timeout: 480 seconds]
20:15-!-mode/#linode [+l 309] by ChanServ
20:15-!-Neon [] has joined #linode
20:15-!-Neon is "w0lfeh" on #linode
20:17-!-mode/#linode [+l 310] by ChanServ
20:19-!-Beuker [] has quit [Quit: WeeChat 1.8-dev]
20:20-!-Beuker [] has joined #linode
20:20-!-Beuker is "tim" on #tor-project #tor #tails #subgraph #powerdns-dev #powerdns #otr #oftc #linode #globaleaks #gcc #dfri_se @#BN @#babylonnetwork
20:26-!-Beuker [] has quit [Quit: WeeChat 1.8-dev]
20:27-!-beuker [] has joined #linode
20:27-!-beuker is "tim" on #tor-project #tor #tails #subgraph #powerdns-dev #powerdns #otr #oftc #linode #globaleaks #gcc #dfri_se @#BN @#babylonnetwork
20:42-!-acald3ron [] has joined #linode
20:42-!-acald3ron is "realname" on #debian-es #debian-mx #debian #linode
20:42-!-mode/#linode [+l 311] by ChanServ
20:45-!-Neon [] has quit []
20:45-!-Sophie1 [] has joined #linode
20:45-!-Sophie1 is "Rosenbluth" on #linode
20:55-!-kaare_ [~kaare@] has joined #linode
20:55-!-kaare_ is "Kaare Rasmussen" on #linode
20:55-!-mode/#linode [+l 312] by ChanServ
20:58-!-eyepulp [] has quit [Remote host closed the connection]
20:59-!-mode/#linode [+l 311] by ChanServ
21:10-!-whallz [~whallz@] has quit [Ping timeout: 480 seconds]
21:12-!-mode/#linode [+l 310] by ChanServ
21:15-!-Sophie1 [] has quit []
21:15-!-zviratko [] has joined #linode
21:15-!-zviratko is "CorneliousJD|AtWork" on #linode
21:20-!-eyepulp [] has joined #linode
21:20-!-eyepulp is "eyepulp" on #linode
21:20-!-mode/#linode [+l 311] by ChanServ
21:22-!-kaare_ [~kaare@] has quit [Remote host closed the connection]
21:24-!-mode/#linode [+l 310] by ChanServ
21:24-!-kaare_ [~kaare@] has joined #linode
21:24-!-kaare_ is "Kaare Rasmussen" on #linode
21:25-!-mode/#linode [+l 311] by ChanServ
21:27-!-audsa [] has joined #linode
21:27-!-audsa is "audsa" on #linode #linuxfriends #debian-france #tails
21:27<audsa>hi everyone
21:28-!-eyepulp [] has quit [Ping timeout: 480 seconds]
21:31<audsa>amnesia :0 :0 14Dec16 ?xdm? 55:11 0.04s gdm-session-wor
21:31<audsa>amnesia pts/0 :0 00:50 43:02 0.16s 30.97s /usr/lib/gnome-
21:31<audsa>amnesia pts/1 :0 00:54 1.00s 0.26s 30.97s /usr/lib/gnome-
21:31<audsa>amnesia pts/2 :0 01:40 9:43 0.16s 30.97s /usr/lib/gnome-
21:31<staticsafe>use a pastebin please
21:32<audsa>is that normal if i have 3 terminals open
21:32<audsa>I apologize i dont know what is a paste bin
21:32<audsa>im curious about your id
21:33<audsa>what is a staticsafe?
21:33<audsa>can anyone help?
21:33<audsa>i am worried that someone might be remote viewing my desktop
21:36-!-acald3ron [] has quit [Remote host closed the connection]
21:37-!-fantasymashups [~oftc-webi@2601:446::5e5d:14eb:d319:534a:1ca0] has joined #linode
21:37-!-fantasymashups is "OFTC WebIRC Client" on #linode
21:40<fantasymashups>We are going to be doing a large initial push with our app (100,000 USD advertising over a few weeks time), this means going from 0 users to up to 250,000 users. Realistically we will probably see 10,000 to 25,000 users. I've set up the infrastructure to heavily cache at the CDN and then hit a Node Balancer with a single 8GB instance behind that. Plan being if the infrastructure starts to break max out the linode instance
21:40<fantasymashups>if that still starts to die then switch over to a distributed model behind the node balancer
21:41-!-bellend [~bellend@] has joined #linode
21:41-!-bellend is "realname" on #zcash #virt #tor-project #tor-bots #subgraph #redditprivacy #qubes #oftc #nottor #moocows #lowRISC #love #linux #linode #globaleaks #freedombox #debian-reproducible #debian-next #debian-mirrors #debian #apparmor
21:41<fantasymashups>WIth 10,000 to 25,000 users will a single node balancer be sufficient or should I round-robin across a couple? How concerned do I need to be about node balancers dieing?
21:41-!-eyepulp [] has joined #linode
21:41-!-eyepulp is "eyepulp" on #linode
21:41<fantasymashups>I am spec'ing out the performance expansion documentation to make sure we can quickly roll out performance modifications based on different possible scenarios
21:42<fantasymashups>I have managed services but I am not sure how much they will really be able to help
21:42-!-mode/#linode [+l 313] by ChanServ
21:42<fantasymashups>I figure if everything starts to go crazy I will jump on the phone and try to hire professional services to expand out quickly, I was thinking of maybe proactively doing this so the contract is in place and we can just give the approval
21:43<Nivex>proactive is good when money is on the line
21:43<Nivex>nodebalancers are good for 10K concurrent:
21:43<Nivex>so you may need to spread the load. some geo diversity might not go amiss either
21:45<@jchun>Eliz: no. you just have pms blocked -_-
21:45-!-zviratko [] has quit []
21:45-!-Kalado [] has joined #linode
21:45-!-Kalado is "Harryhy" on #linode
21:48<Peng>fantasymashups: IMO you should start out with two 4 GBs, not one 8 GB.
21:48<Nivex>yeah, single instance behind a nodebalancer makes no sense, especially already being behind a CDN
21:48<fantasymashups>Peng, I am rolling with a simplified non-distributed model right now, if I do the two 4 GBs I'd have to rotate to an independent MySQL DB or go distributed
21:49<fantasymashups>Nivex Peng the idea is that we will probably have to expand to a distributed model but I dont want to add unneeded complexity but I don't want to have to setup the node balancer at that time
21:49<fantasymashups>The node balancer is cheap and adds an extra connection management layer to simplify things
21:49-!-eyepulp [] has quit [Ping timeout: 480 seconds]
21:50<fantasymashups>Easier to setup now than in a pseudo emergency
21:50<fantasymashups>It's just tough to really predict if we will get 5 users or 50,000. But since we are spending enough I'd like to be prepared.
21:50-!-mode/#linode [+l 312] by ChanServ
21:52<Peng>If you plan to, or have to, scale horizontally in the future, it's better to already have it set up now, than to have to figure it out in a crisis.
21:52<Peng>And it's good to have redundancy.
21:52-!-borntospeed [] has quit [Ping timeout: 480 seconds]
21:53-!-audsa [] has left #linode []
21:54-!-mode/#linode [+l 310] by ChanServ
21:55<fantasymashups>Peng I don't disagree unfortunately it's an optimization problem and business wise I have to balance all the costs/risks and such. Peng would you suggest I do the two 4 GBs with no independent DB instance and just install MySQL on both of the 4GBs along side the apps?
21:56<millisa>it's better to overspec a launch and the scale back later than it is to underspec one and look bad during the launch...
21:57<fantasymashups>What do you recommend for the distributed database model
21:59<millisa>I like dedicated db instances, personally. it lets you scale up just the db if that's where the proc/memory needs. you don't have it fighting with the webserver/php/applayer for resources.
22:00<millisa>when building your web/app layer, give yourself an easy way to switch the db IP (use a single place with the IP so you aren't having to hunt around ify ou decide you want to switch to a different/bigger/smaller instance)
22:01<fantasymashups>so 4 4GB instances millisa? 2 for the app and 2 for the db?
22:01<millisa>I have no idea. I don't know your dataset.
22:01<fantasymashups>I'm just saying model wise, not performance wise
22:01<fantasymashups>I am just laying out the ideal model
22:02<fantasymashups>I don't disagree
22:02<millisa>if you have a 100k budget, why are you going with such small systems?
22:03<Nivex>he said 100k _advertising_ budget. That doesn't leave anything for the tech :P
22:04<fantasymashups>100k tech budget, 60k spent on design
22:04-!-blaflamm_ [~blaflamme@2001:18c0:25e:926:7099:b5cd:89be:695e] has quit [Quit: Textual IRC Client:]
22:05<fantasymashups>We have the money but it's an optimization problem, business cost/risk assessment
22:05<fantasymashups>I'll probably setup the distributed model and switch over to it so I can easily just expand nodes
22:05-!-acald3ron [] has joined #linode
22:05-!-acald3ron is "realname" on #debian-es #debian-mx #debian #linode
22:05-!-larsdesigns [] has joined #linode
22:05-!-larsdesigns is "larsdesigns" on #linode
22:06<fantasymashups>millisa Nivex only other technical question is will 1 Node Balancer be fine or 2 with the CDN round-robin them?
22:06<fantasymashups>They can handle 10k concurrent connections I believe which is probably fine
22:07-!-mode/#linode [+l 311] by ChanServ
22:11-!-eyepulp [] has joined #linode
22:11-!-eyepulp is "eyepulp" on #linode
22:11<JeremyE77>Test, test, test before you blow your marketing budget. :P
22:12-!-mode/#linode [+l 312] by ChanServ
22:15-!-Kalado [] has quit []
22:15-!-mode/#linode [+l 311] by ChanServ
22:18-!-fantasymashups [~oftc-webi@2601:446::5e5d:14eb:d319:534a:1ca0] has quit [Quit: Page closed]
22:19-!-eyepulp [] has quit [Ping timeout: 480 seconds]
22:19-!-mode/#linode [+l 309] by ChanServ
22:30-!-fstd_ [] has joined #linode
22:30-!-fstd_ is "fstd" on #gentoo #linuxfs #gcc #awesome #oftc #vserver #suckless #osm #linode #debian #kernelnewbies
22:30-!-fstd [] has quit [Read error: Connection reset by peer]
22:30-!-fstd_ is now known as fstd
22:33-!-eyepulp [] has joined #linode
22:33-!-eyepulp is "eyepulp" on #linode
22:34-!-mode/#linode [+l 310] by ChanServ
22:38-!-Jaska [] has joined #linode
22:38-!-Jaska is "Dragonshadow" on #linode
22:39-!-mode/#linode [+l 311] by ChanServ
22:41-!-eyepulp [] has quit [Ping timeout: 480 seconds]
22:42-!-mode/#linode [+l 310] by ChanServ
22:47-!-purrdeta [] has quit [Quit: ZNC -]
22:48-!-purrdeta [] has joined #linode
22:48-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
22:49-!-bbankes [] has quit [Ping timeout: 480 seconds]
22:50-!-mode/#linode [+l 309] by ChanServ
22:55-!-eyepulp [] has joined #linode
22:55-!-eyepulp is "eyepulp" on #linode
22:55-!-mode/#linode [+l 310] by ChanServ
22:58-!-purrdeta [] has quit [Quit: ZNC -]
22:59-!-mode/#linode [+l 309] by ChanServ
23:00-!-purrdeta [] has joined #linode
23:00-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
23:00-!-mode/#linode [+l 310] by ChanServ
23:02<FluffyFoxeh>why is almost every result either a school, or some site trying to sell a book
23:03-!-eyepulp [] has quit [Ping timeout: 480 seconds]
23:04-!-mode/#linode [+l 309] by ChanServ
23:08-!-Jaska [] has quit []
23:09-!-mode/#linode [+l 308] by ChanServ
23:09-!-purrdeta [] has quit [Quit: ZNC -]
23:10-!-mode/#linode [+l 307] by ChanServ
23:11-!-purrdeta [] has joined #linode
23:11-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
23:12-!-mode/#linode [+l 308] by ChanServ
23:18-!-acald3ron [] has quit [Remote host closed the connection]
23:19-!-mode/#linode [+l 307] by ChanServ
23:20-!-purrdeta [] has quit [Quit: ZNC -]
23:20-!-mode/#linode [+l 306] by ChanServ
23:22<JigmeDatse[m]>FluffyFoxeh: Because that's what Google thinks you want. It's not what I get.
23:22-!-purrdeta [] has joined #linode
23:22-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
23:24-!-mode/#linode [+l 307] by ChanServ
23:24-!-joecool|mobile [] has quit [Quit: ZNC 1.6.4 -]
23:24<JigmeDatse[m]>Only one school in the first page, and it is lecture notes.
23:25-!-joecool|mobile [~joecool@2601:8a:500:f00:75cd:ffc4:b423:5b1] has joined #linode
23:25-!-joecool|mobile is "Joe" on #linode #ck
23:25<FluffyFoxeh>ah I get the local university
23:26<FluffyFoxeh>as one of them
23:26<FluffyFoxeh>and a different university for another one
23:28<dwfreed>the suggestion box before the results list for me is "Non-functional requirement" from Wikipedia
23:28<dwfreed>I spend *a lot* of time on Wikipedia from Google, though
23:29<FluffyFoxeh>for me it's this stupid thing
23:29<dwfreed>oh, that's the first result after the suggestion box
23:30<FluffyFoxeh>which has "Click Here To Create Your First Requirement in ReQtest & Become a Business Analyst Pro (Free 10-Day Trial)" after every second paragraph
23:32-!-purrdeta [] has quit [Quit: ZNC -]
23:32-!-eyepulp [] has joined #linode
23:32-!-eyepulp is "eyepulp" on #linode
23:33-!-purrdeta [] has joined #linode
23:33-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
23:34-!-mode/#linode [+l 308] by ChanServ
23:35-!-seanh-corona [] has joined #linode
23:35-!-seanh-corona is "Adium User" on #linode
23:35-!-mode/#linode [+l 309] by ChanServ
23:40-!-eyepulp [] has quit [Ping timeout: 480 seconds]
23:40-!-mode/#linode [+l 308] by ChanServ
23:41-!-madbytes [~madbytes@] has joined #linode
23:41-!-madbytes is "madbytes" on #linode
23:42-!-mode/#linode [+l 309] by ChanServ
23:42-!-madbytes [~madbytes@] has quit [Remote host closed the connection]
23:43-!-purrdeta [] has quit [Quit: ZNC -]
23:43-!-madbytes [~madbytes@] has joined #linode
23:43-!-madbytes is "madbytes" on #debian #linode
23:44-!-mode/#linode [+l 308] by ChanServ
23:44-!-purrdeta [] has joined #linode
23:44-!-purrdeta is "Alex" on #tardigans #sd #oftc #moocows #help #linode #Corsair
23:45-!-madbytes_ [~madbytes@] has joined #linode
23:45-!-madbytes_ is "madbytes" on #linode
23:45-!-mode/#linode [+l 310] by ChanServ
23:50-!-madbyte__ is "madbytes" on #debian
23:50-!-madbyte__ [~madbytes@] has joined #linode
23:51-!-madbytes [~madbytes@] has quit [Ping timeout: 480 seconds]
23:53-!-madbytes_ [~madbytes@] has quit [Ping timeout: 480 seconds]
23:54-!-mode/#linode [+l 309] by ChanServ
23:57-!-bret1 [] has joined #linode
23:57-!-bret1 is "Sigma" on #linode
23:59-!-mode/#linode [+l 310] by ChanServ
---Logclosed Mon Jan 23 00:00:13 2017