Recent Questions - Server Fault |
- What is the meaning of the "/dev/null 2>&1" in a Cronjob entry?
- openssl upgrade | fail validating certificate
- loading additional modules with ansible tower
- Reason why RHEL Apache is installed on middleware folder
- Azure SQL DB - Elastic Pool Vs Hyperscale
- Using Local Drive as a Web Server Directory
- AWS - Why is my ACM issued cert not appearing when creating a Load Balancer ("No existing certificates")
- Stopping UDP Attack
- SSH into GKE Kubernetes cluster?
- GCP VM Instance dysfunctioning
- Mysqli access denied , using UNIX socket
- Haproxy: Restrict access to untrusted IPs only to sub url
- Zabbix active agent can't connect to Zabbix server - connection was forcibly closed by the remote host
- Know which firmware my linux kernel has loaded since booting
- Waiting for localhost : getting this message on all browsers
- NGINX with proxy_pass behind AWS ALB, creating http://example.com:443 urls from https links - “The plain HTTP request was sent to HTTPS port”
- Network problems when I create Beanstalk environments from an AMI
- Setup ssl on nginx for a django project
- HBase Kerberos SaslException: GSS initiate failed (Mechanism level: Failed to find any Kerberos tgt)
- Jenkins: Waiting for next available executor on master, 4 workers idle
- How to apply xNetworking xIPAddress Desired State Configuration (DSC)?
- SOlr 4.10.2 500 Internal Server Error Error: {msg=SolrCore 'collection1' is not available due to init failure: Index locked for write
- Allow Google apps and block consumer Google accounts using squid proxy
- Struggling with Haproxy 1.5 ACLs using regular expressions and URL Parameters
- Group policy configuration error - Server Essentials 2012
- ClearOS SMTP Server Setup using Gmail SMTP
- How to manage hotspot web-filtering, centrally, for several hotspots?
- Random Connections to MySQL refused (Error 111)
- Can I host a VPN service on a shared Windows Host I already have?
What is the meaning of the "/dev/null 2>&1" in a Cronjob entry? Posted: 15 Aug 2021 10:06 PM PDT Can someone explain to me what is the meaning of "2>&1" doing here in the below cron job |
openssl upgrade | fail validating certificate Posted: 15 Aug 2021 09:44 PM PDT I am working on CentOS7 machine, and I am trying to upgrade my machine's openssl version 1.0.2k -> 1.1.0l. It seems like the handshake process with my server(which didn't change) fails after the upgrade and I'm trying to figure out the cause. Running the following command with both openssl version: openssl s_client -showcerts -connect server:port Resulted with failure with the newer one (if i provide the -CAfile validation works with both). A diff of the result: Old 1.0.2k (handshake successful): Server Temp Key: ECDH, P-256, 256 bits New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES128-GCM-SHA256 New 1.1.0l (fails handshake): Server Temp Key: X25519, 253 bits New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256 Verify return code: 20 (unable to get local issuer certificate) I would appreciate with help understanding the difference, and why are they different. fyi, I started a similar threat here: https://stackoverflow.com/questions/68763253/openssl-upgrade-fail-validating-certificate?noredirect=1#comment121583146_68763253 without much luck. Thanks :) |
loading additional modules with ansible tower Posted: 15 Aug 2021 08:55 PM PDT I'm trying to run a playbook on ansible tower but I'm having issues loading extra modules. I checked the playbook is configured right but it still fails with the message below... I might be blind but how do I get ansible tower to load these modules? I'm not sure if its a setting I've missed or extra config required in the playbook itself... Any help would really be appreciated. I'll pop in my playbook below. |
Reason why RHEL Apache is installed on middleware folder Posted: 15 Aug 2021 08:37 PM PDT What's on RHEL the cause which Apache (HTTPD) is installed on the folder "/opt/middleware/httpd/", instead the usual installation folder? What should I apply on my server to have this similar feature, since I am trying to replicate a client environment. |
Azure SQL DB - Elastic Pool Vs Hyperscale Posted: 15 Aug 2021 08:04 PM PDT We have an Azure SQL DB (DTU based, Standard 3, 50 GB). Business requirement is that the size of the DB might grow till 10 TB. We are considering moving to elastic pool to save cost. Hyperscale (Gen5) is another option under consideration. While analyzing, following points have been identified. Kindly suggest taking a right decision.
Seems Hyperscale is better option. Kindly suggest if I have missed any. |
Using Local Drive as a Web Server Directory Posted: 15 Aug 2021 07:35 PM PDT I'm trying to find the best way to include a local NAS Hard-drive folder in the Web server directory. The Web Server is Apache, running on a Public Debian Server. I've all the flexibility in the world to install/configure packages on both sides. So, essentially mounting a local folder say Can this be accomplished using SSHFS or is there another way? |
Posted: 15 Aug 2021 06:54 PM PDT I'm trying to create a Application Load Balancer for a LAMP stack ec2 server. Both the ec2 server and certificate is deployed in US East(Ohio) us-east-2 and I'm trying create the load balancer there also. But when I'm setting up the load balancer, and get to the step where I select a ACM managed cert, the dropdown says "No existing certificates". The certificate is Issued and not In Use. I created it some time ago (actually, about 2 years ago). I also tried creating a Classic Load Balancer and the certificate was not available there also. |
Posted: 15 Aug 2021 04:14 PM PDT I am now getting support emails from OVH that there is unusual activity on my server. This is a simple server that I have RDP connections for students to access QuickBooks, Excel, and Word, and there is nothing else on the server, and I have group policies set that they have almost no access to anything including the internet, files, etc ... The below is the message I am getting for OVH ... I have blocked all UDP outbound in the windows firewall and the computer configuration ... I am not an expert in this area ... will this stop the unusual behavior. |
SSH into GKE Kubernetes cluster? Posted: 15 Aug 2021 05:16 PM PDT I have a GKE Kubernetes cluster that I would like to debug. Is it possible to start a container inside the cluster using e.g. |
GCP VM Instance dysfunctioning Posted: 15 Aug 2021 03:13 PM PDT Currently using a GCP VM instance to run an ODK aggregate server, I cannot access the server since Friday evening. I guess it's not linked to ODK but rather to the server issue, indeed, I followed the following steps:
"Aug 13 16:24:27 enquetesouagabobo chronyd[2104]: Could not write to temporary driftfile /var/lib/chrony/chrony.drift.tmp Aug 13 16:39:16 enquetesouagabobo systemd-networkd[19493]: ens4: Configured Aug 13 17:09:17 enquetesouagabobo systemd-networkd[19493]: ens4: Configured [5034594.247692] systemd-journald[19543]: Failed to create new system journal: No space left on device" I think it's linked to the disk storage, which was indeed full. I have doubled its capacity today afternoon (from 10 GB to 20 GB) but I get the same scripts after that. See for instance : "Aug 15 18:50:55 enquetesouagabobo systemd[1]: snapd.service: Start operation timed out. Terminating. Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: State 'stop-sigterm' timed out. Killing. Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: Killing process 29463 (snapd) with signal SIGKILL. Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: Main process exited, code=killed, status=9/KILL Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: Failed with result 'timeout'. Aug 15 18:52:25 enquetesouagabobo systemd[1]: Failed to start Snap Daemon. Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: Service hold-off time over, scheduling restart. Aug 15 18:52:25 enquetesouagabobo systemd[1]: snapd.service: Scheduled restart job, restart counter is at 949. Aug 15 18:52:25 enquetesouagabobo systemd[1]: Stopped Snap Daemon. Aug 15 18:52:25 enquetesouagabobo systemd[1]: Starting Snap Daemon... Aug 15 18:52:25 enquetesouagabobo snapd[29509]: AppArmor status: apparmor is enabled and all features are available Aug 15 18:52:25 enquetesouagabobo snapd[29509]: AppArmor status: apparmor is enabled and all features are available Aug 15 18:53:56 enquetesouagabobo systemd[1]: snapd.service: Start operation timed out. Terminating." I don't know what would be better to do now, as I don't master Serial console and command lines : I have already created a persistent disk snapshot and would like to restore the data to a new disk and have access again to my current server. Do you have any idea ? Can I create a similar Instance VM with the same IP external address and the disk snapshot ? Thank you in advance for your help. N.T. |
Mysqli access denied , using UNIX socket Posted: 15 Aug 2021 08:22 PM PDT I am trying to learn PHP, and I am setting up the database connection. And here is my code. <?php The output is nothing in a browser. Then I tried this. The output is I don't have password for user I changed the actrual username to someone to protect privacy. You can see that |
Haproxy: Restrict access to untrusted IPs only to sub url Posted: 15 Aug 2021 03:05 PM PDT I would like to restrict access to my pastebin server (I'm using zerobin) so that untrusted IPs can only open secrets, but not create them. (note that the url Trusted IPs: allow access to https://fakepastebin.com (main page where they can generate secrets) Non trusted IPs: allow access only to secrets (eg https://fakepastebin.com/?29c6692368e9edc9#G4j8Y2w). Basically anything after Something like : How do I make it so that the unprotected pages can be accessed by all IPs? I've never tried to limit the main page before...only sub-pages so I'm unsure how to do this. Appreciate the feedbacks! UPDATE: With these in place I can now prevent untrusted IPs from going to the top level url: However I noticed that if I browse to Thanks |
Posted: 15 Aug 2021 10:06 PM PDT I am already using active agents on other servers and everything works really nice. I've performed installation of Zabbix agent on new server and I've set the same config as in other active agents. The problem is my agent can't connect to the server. Logs: I am sure that PSK key and ID is set correctly in both agent and server. My config (works on other agents): Port is opened on both sides and I have checked with Test-NetConnection in Powershell that I can connect from agent to server on specifed port (10051). Any idea what else I can check or try to do to fix the problem? |
Know which firmware my linux kernel has loaded since booting Posted: 15 Aug 2021 03:08 PM PDT On routinely updating my Debian system, I've never took the time to pick which firmware packages I do really need; basically I have them all installed, and always up-to-date. I've been wondering how can I pick which ones I do really need. I was thinking of using every device I have in my system (even the ones I rarely use like bluetooth, ethernet, camera, touchpad, multimedia keys and so on) and look at the list of loaded firmware. Is there an easy way to find out which firmware is currently loaded, or were loaded since last kernel boot? |
Waiting for localhost : getting this message on all browsers Posted: 15 Aug 2021 09:08 PM PDT I am using Ubuntu 14.04 and have php5 and mysql installed. I have 3 web applications on my /var/www/html folder. Until yesterday evening I was able to test and work on the applications. All of a sudden, I am not able to load any of my applications on any of the browsers. I have firefox and chrome installed. I have checked the availability of MySQL and Apache. Both are running correctly. I have also restarted Apache. I have cleared all the cookies and history from chrome and set it to default under chrome://flags. After removing all the history and cookies from Chrome, I could load the first login page and when I provide the UID and password, I get Of the three one of my smaller application loaded after 10 minutes, however a heavier application did not load at all. However, the browser loads plain html files. I have also tested on wifi, mobile internet dongle device and ethernet and there are no firewall issues. I have also cleared my machine's cache by None of this helped. Can someone guide me on how do I resolve this? |
Posted: 15 Aug 2021 06:04 PM PDT I currently have nginx running behind AWS Application Load Balancer. I have a ghost blog on another server which I have setup using proxy_pass. It works perfectly if I go to https://www.example.com/blog However, I have a link to https://www.example.com/blog on my homepage, but when I click on it it seems to 301 redirect me to http://www.example.com:443/blog resulting in "The plain HTTP request was sent to HTTPS port" The site is also setup to 301 HTTP to HTTPS. This appears to work flawlessly. ALB is taking care of my SSL certs. To keep it simple I have the ALB setup with two listeners (80 and 443) but only one process (80). I previously had 443 setup as another process but have removed it to reduce potential failure points. I'm at a loss as to why it would be 301'ing a perfectly good url by turning it into HTTP on port 443 when in all other cases it appears to turn HTTP into HTTPS. Some suggested answers were to add listener 443 ssl; to the nginx.conf but I cant do that as no SSL certs are setups on nginx. It's all on ALB. Any ideas?? |
Network problems when I create Beanstalk environments from an AMI Posted: 15 Aug 2021 04:03 PM PDT I'm using AWS elastic beanstalk web interface to create an environment based on an existing AMI that has our application deployed on it. The environment gets created, the app is accessible via the ec2 instance's IP. however the environment's health keeps as "Pending" for 15 minutes then degrades to Severe after that with these errors in the environment's log:
So what I understood here is that the instance is created, but it's failing to communicate with elastic beanstalk. In contrast to common security sense, and in order to pinpoint the problem, I've tried to keep my VPC setting as public as possible. Here is what I did:
No luck. I know there is a small networking tweak that I need to do. I've scratched my head (and my search engine) a lot. What am I missing? Can you help? |
Setup ssl on nginx for a django project Posted: 15 Aug 2021 03:03 PM PDT I want to setup ssl for Nginx, my project is a Django and I also use gunicorn as wsgi Http server. I add following lines in my I don't know if it's necessary to do this, then I configure my Nginx in the following form: Nginx configure is correct I think because its redirect 80 to 443,but nothing happens, 80 request sent, then Nginx redirect it to 443, but nothing happen, it can't connect to gunicorn or project. Should I do something with gunicorn? my certificate is self-signed, or what should I do? regards :) |
HBase Kerberos SaslException: GSS initiate failed (Mechanism level: Failed to find any Kerberos tgt) Posted: 15 Aug 2021 08:01 PM PDT I am trying to set up Kerberos authentication for HBase using this http://hbase.apache.org/0.94/book/security.html documentation and have very little progress so far. HBase 1.1.1 from Apache without any Cloudera influences. Host machine is running under Centos 6.5. I've already set up Kerberos KDC and client after following instruction https://gist.github.com/ashrithr/4767927948eca70845db KDC is located on the same machine as HBase I'm trying to secure. All-in-all, here's current environment state: keytab file is here /opt/hbase.keytab hbase-site.xml contents It's a pseudo-distributed mode and I didn't bother with undelying HDFS to keep things as simple as possible. However when I start hbase with ./start-hbase command I get following error in regionserver.log I presume Kerberos works because I can obtain hbase shell produces the same exception as provided above when trying to run status (or whatever) command If anyone has any suggestions or advices please let me know Thanks in advance |
Jenkins: Waiting for next available executor on master, 4 workers idle Posted: 15 Aug 2021 06:04 PM PDT I have a jenkins (initially 1.596.2, later upgraded to .3) master on Ubuntu, with some jobs. Last week i started seeing jobs being put on queue (pending—Waiting for next available executor). I checked the job config (Restrict where this project can be run) and it says Slaves in label: 1. The master workers all report idle. I upgraded to 1.596.3, restarted the node, but after a couple of hours of working (around 10-12) it starts to put jobs on queue although workers are idle. It doesn't have any slaves, there are plenty of resources (node is a VM with 8 GB of RAM and 500 GB disk) and there are no errors in dmesg or logs. What can i do to unblock it? Thanks, Ed |
How to apply xNetworking xIPAddress Desired State Configuration (DSC)? Posted: 15 Aug 2021 09:08 PM PDT Using Windows Server 2012 R2. The goal is to set the IPv4 address of a server. As DSC correctly states in the verbose message below, the Expected [ip is] 192.168.0.203, [while the] actual [ip is] 192.168.0.205 The following error message: ... is thrown when applying the following xNetworking DSC configuration: where $IPv4 = '192.168.0.203'. I have noticed that the Local Configuration Manager is capable of Test-DSCConfiguration, only unable to apply any IP related changes. I have tested this by running the configuration above on the system while the IP is already correctly set. The message "Can not set or find valid IPAddress using InterfaceAlias Ethernet and AddressFamily IPv4" is confusing since the LCM has obviously been able to find the the adapter during the Test-DSCConfiguration operation. Any clues as to why the Local Configuration Manager is unable to apply the configuration? What am I not seeing? |
Posted: 15 Aug 2021 03:03 PM PDT I have a SOLR Master and a Slave running. After upgrading to SOLR 4.10.2, and fixing all other errors, I cannot get pass this one:
I have:
The issue persists. I have also tried other solutions, like changing the following into the solrconfig.xml: This caused different errors, so I rolled back to (the above part is now commented out. I have compared the configuration files with an environment that works and they look identical. Thank you. |
Allow Google apps and block consumer Google accounts using squid proxy Posted: 15 Aug 2021 07:07 PM PDT In my organisation, I am trying to allow the Google apps account and block consumer Google accounts using squid proxy. According to this link, Google says we can do it using following steps: After referring few online blogs and guides I compiled and installed the squid and added the following entries in my squid.conf: Using above configuration every request (http and https) is routing through my proxy server but it is not able to block consumer Google account and I am able to login to it. I have also added the proxy IP as my gateway to the node system and in my proxy server I added following rules in Iptable So what more I need to do to block consumer Google account? Am I missing something here? EDIT: After working on the above issue I came to know that I was doing one mistake. My port setting in squid.conf file is like follows: I had set the global proxy in my node system. In IP field I had put proxy server's IP and in port field I had put 3129. So, all of my requests were going through 3129 port and hence it was not getting intercepted and was able to login into consumer Google accounts. SO I removed the proxy settings from node system and only kept proxy server ip as it's gateway. After this my every request is reaching the proxy server but I think it's not getting routed to ports specified in squid.conf. i.e 80 port to 3128 and 443 port to 3130, and now because of this everything is blocked. I have tried to set rules in Iptables for this internal routing of ports but nothing is working. I have only one Ethernet interface as eth0 to my proxy server. So will anybody guide me on this issue? |
Struggling with Haproxy 1.5 ACLs using regular expressions and URL Parameters Posted: 15 Aug 2021 07:07 PM PDT I am using Haproxy 1.5.3 setup with ssl on the frontend and also sending ssl to the backend servers. the mode is http and using acls to determine stickyness. My test requests are as follows:
I need to create sticky requests on this 3rd Parameter and there seems to be many ways to do this using Haproxy and even though using regex is expensive it provides us the most flexibility, so that is what we chose (in this example we moved away from regex to simplify the problem and decided just to look at the last character of the parameter, so to make sure the regex is not the problem. Our ACL setup (more of a test bed to see if we can get it to work) With the testing we have done we believe that only the first parameter it finds in the URL can be matched (it does not search the rest of the parameters). This may be a bug or maybe by design (the docs seem a little ambiguous around urlp at least to us) but it would make sense that you should be able to match all parameter in the URL. Shouldn't they both pass with this ACL? Any thoughts? Many thanks, Andre |
Group policy configuration error - Server Essentials 2012 Posted: 15 Aug 2021 05:01 PM PDT I am trying to use the "Implement Group Policy" wizard in Windows Server 2012 Essentials. I have a domain created and a computer included in that domain. When I choose to "Implement Group Policy" I select "all" in the Enable Folder Redirection Group Policy and also select "Windows Update", "Windows Defender" and "Network Firewall". I finish the wizard and get the error
The user's machine is Windows 8 Pro. I have checked the event logs and for .log files and cannot find anything that helps. I have also tried selecting no folders to redirect and different combinations of the "Security Policy Settings" Can anyone here offer some guidance as to why this is failing. Thanks Pat |
ClearOS SMTP Server Setup using Gmail SMTP Posted: 15 Aug 2021 05:01 PM PDT How to set up ClearOS SMTP server using gmail SMTP? I'm using ClearOS as IMAP mail server. Receiving mails from pop hosting is no problem. But to setup SMTP for client using the same server is a challenge. Anybody knows how to use Google mail account as an SMTP server for ClearOS? Thank you. |
How to manage hotspot web-filtering, centrally, for several hotspots? Posted: 15 Aug 2021 08:01 PM PDT I manage a number of public hotspots, at different sites, with routers running the dd-wrt firmware and I now want to (centrally) control the websites they have access to. So, my idea initially was to implement Squid as a transparent proxy (using iptables to forward router traffic) and set it up for filtering only. The only problem with this (if I understand it correctly?) is the Squid server will have to have sufficient bandwidth to handle both outbound (from routers) and inbound traffic (to routers) - the server will be remote to the routers, on the internet. I have the following server restrictions:
My first question: is it possible to configure Squid to only intercept, and filter, the outbound data from the routers and allow the inbound traffic to go directly back to the routers, from the websites they requested? Please note: I have considered using a Captive Portal solution but this will take longer, than I have time for, to implement and will have the same traffic problem!? I have also looked at OpenDNS for filtering, but the logging is not realtime - good, realtime logging is important for me. Any suggestions on how this can be done using Squid, or any other relevant solutions, would be appreciated... |
Random Connections to MySQL refused (Error 111) Posted: 15 Aug 2021 04:03 PM PDT A Perl/CGI webapp that has been running fine for almost a year has started to randomly been unable to connect to a remotely hosted MySQL. The Error thrown is :
Reloading the page often solves the problem The client is using Perl, DBI and SSL to connect to MySQL using the same configuration file each time. MySQL 5.0 Server Running RH EL5
I have my host looking into the problem but so far we're all stumped as to way the occasional connection is (increasingly getting refused) Any advice what to check that would cause the random refusal of connections? |
Can I host a VPN service on a shared Windows Host I already have? Posted: 15 Aug 2021 10:06 PM PDT I have a windows hosting plan with Plesk control panel, FTP, email and other popular options already found in common windows hosting plans. I want to know whether I can convert my hosting plan to a L2TP/IPSec or PPTP VPN service or not. Your answers are really appreciated. |
You are subscribed to email updates from Recent Questions - Server Fault. To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States |
No comments:
Post a Comment