Recent Questions - Server Fault |
- APP_PROTECT failed to get compilation status
- Port Forwarding not working (ZTE F660)
- Why can't I use AWS EC2 ImageBuilder to create a RHEL based container?
- Setting static IP manually works - Using ansible gives me issues
- Where are these printers coming from in "Devices and Printers?"
- Configuring SSSD to do SSH SSO using Active directory
- Unable to resolve host domain name
- How can I allow devices on two subnets from one ISP to communicate with each other?
- Measure traffic for an interface monthly
- Apache Redirect for HTTPS (Nextcloud) leads to redirect loop
- Prevent SlowLoris attack with ModSecurity (Apache)
- My Domain keeps disconnecting from Droplet IP
- Combining Network Connections for Additive Speed
- Ansible is it possible to use variable in template src
- How to automap shared mailbox **without** granting Full Access in Office365?
- Postfix - block by sender email domain ip
- How to redirect from one subfolder to a subsubfolder with htaccess
- No protocol handler was valid for the URL /url. If you are using a DSO version of mod_proxy
- Powershell Exchange Delete old Phone Sync Devices
- Turn on Gzip for combined JS or CSS files without file extension
- Percona XtraDB Cluster 5.6 does not start
- redirect traffic from 127.0.0.1:5003 to external interface
- pgpool2 parallel mode: Non-superusers must provide a password in the connection string
- Can windows credentials be stored for 'All Users'?
- How to restore Ubuntu server on a VMWare image after disk failure?
- MS SQL 2008 - Can I use Windows Authentication to connect from a Mac
- ErrorCode<ERRPS013>:SubStatus<ES0001>:Operation was aborted because user selected not to enable Cache with secondaries
- how to find out the valid store names for certutil
- Why is the chroot_local_user of vsftpd insecure?
- Using Gentoo's `ebegin`, `eend` etc under Ubuntu
APP_PROTECT failed to get compilation status Posted: 31 Oct 2021 08:22 PM PDT I have installed Nginx Plus and App Protect (provided by Nginx Plus and F5). I followed the config guide (https://docs.nginx.com/nginx-app-protect/configuration/). The issue is whenever I add the lines In nginx.conf (as shown in the config guide link above), I am getting a weird error which says APP_PROTECT failed to get compilation status. Nginx error log shows this: Please help if anyone else is facing the same problem. Emailed to nginx plus support and I am yet to receive a reply from them (48 hours have passed since emailing them) |
Port Forwarding not working (ZTE F660) Posted: 31 Oct 2021 08:05 PM PDT I have been trying to run a minecraft server and followed all the steps on port forwarding but it still doesn't work. Please help I have been working on this for quite a while. |
Why can't I use AWS EC2 ImageBuilder to create a RHEL based container? Posted: 31 Oct 2021 07:46 PM PDT In the AWS console for EC2 ImageBuilder the option to create a Container Recipe using RHEL as the base image seems to be disabled. From EC2 Image Builder console -> Container Recipes -> Create container recipe. The 'Base Image' section for 'Image Operating System' allows Amazon Linux, Windows, Ubuntu and CentOS to be selected. Also listed are 'Red Hat Enterprise Linux (RHEL)' and 'SUSE Linux Enterprise Server (SLES)', but both of these are disabled. I want to use RHEL as the base for my container. Is there something I need to do in my AWS account to make these operating systems selectable? The console itself says that RHEL is supported, and I can't locate any documentation to say otherwise. |
Setting static IP manually works - Using ansible gives me issues Posted: 31 Oct 2021 07:14 PM PDT so I have a couple raspberry pi's I'm trying to use as a cluster and I'm learning ansible to try and manage them easier. I'm running into an issue though. I can manually set the IP static using netctl but when I try to do it with ansible using the same exact commands I have issues. Also a weird note, the version that doesnt work, doesnt work on raspberry pi 4's but will work on raspberry pi b's. For example if I use the following (enter it in manually) I get no issues what so ever:
and after reboot it works fine. I can also get it to work if I use the following: But it fails to work if I use: or this also fails my and it's in the roles/role/templates folder, it's also being copied over correctly as I have checked manually on each pi. Any ideas why this may be happening? |
Where are these printers coming from in "Devices and Printers?" Posted: 31 Oct 2021 08:42 PM PDT EDIT: I think it is coming from I have a set of printers which deploy to computers via GPO. Today, I tried to change that printer mapping. The new printer mappings show up on the workstation, but the old ones are still being displayed. However, prior to login, the user profile does not exist on the computer. Nothing in C:\Users, nothing in Advanced System Settings. Yes, I have a lot of computers to test on. Even if I remove the GPO which deploys printers, the original printers continue to show up in the "Devices and Printers" window. If I delete the user from AD, and re-add a new user with same username and password, the original/old printers no longer show up. Additionally, if I use powershell's These are hybrid Azure AD joined PCs. But, we do not have AD premium and there is no enterprise state roaming configured. We are not using roaming profiles. We are not redirecting folders to any network shares. No other settings seem to roam or appear. Files saved are gone. This seems to effect all or several users on the same machines including a 'guest' user who's profile is 'temporary' and deleted on every logoff. HOW are these printers continuing to appear on computers that the user does not have a profile on and no GPO or script is deploying. Why do they show only in 'Devices and Printers' but not in wmic, powershell, or the registry? The user logged on to this computer and others in the past within our organization. |
Configuring SSSD to do SSH SSO using Active directory Posted: 31 Oct 2021 06:12 PM PDT I am currently thinking about a solution to be able to SSH via kerberos using SSSD linked to an active directory without joining the machine to the domain. The main constraint is not to join the machine to the AD domain. I would like to know if you have already tried this solution and if it is possible. I am not very familiar with the use of kerberos for SSO services. Currently I am working on a Centos 7, I have already set up an AD and configured SSSD to connect via SSH through the AD accounts. I would now like to be able to use kerberos tickets so that I can pivot from machine to machine in ssh with a single ticket using the AD accounts. Thank you in advance for your answers ! |
Unable to resolve host domain name Posted: 31 Oct 2021 06:06 PM PDT Recently, I noticed that time to time my client is unable to resolve my domain name. I have a Lightsail instance with a static IP, a Lightsail DNS Zone, and finally a Route53 domain name. The only thing I did for now is adding the Lightsail DNS Zone name servers to the Route53 registered domain name servers list (as described here). I currently don't have hosted zone on Route53. I have three questions. First, is the other way around more scalable? meaning, should I have a hosted zone on Route53 pointing Lightsail static IP (like this). Second, Is there a domain name access quota that I'm not aware of? and finally, Is there something flagrant that I'm doing wrong (I'm a newbie in networking). EditDomain name: yimaru.services Static IP address: 3.121.169.168 |
How can I allow devices on two subnets from one ISP to communicate with each other? Posted: 31 Oct 2021 04:31 PM PDT First, some context: I run a small business out of my home. My bedroom serves as the "office" area, and that's where I'm at most of my time. My ISP (Frontier) leads into their Arris modem in the living room that is also running a LAN (10.0.0.x), the modem is located at 10.0.0.1). I have another router (TP-Link AX1500, 10.0.1.x) in my bedroom that's plugged into the Arris modem at 10.0.0.10. Basically, I want every device from both (subnets? Hopefully I'm using that word correctly) to be able to communicate with any other device in the network as a whole. Currently, I can send a query from any device on the TP-Link router to any other device in the house (and get a response), but I can't send a query from a device on the Arris network to any specific device on the TP-Link network (unless I port-forward a specific device via the TP-Link router ahead of time and just ping the router itself). My goal is to allow any device in the house to communicate with any other device in the house, as if they were all hooked up to the same router (I'd like to keep my local IP addresses better organized, so that's why I have them on separate subnets). Here's a diagram, hopefully it conveys my network setup well enough. The (...) means there are more devices connected to its parent, but aren't necessarily relevant to the question. Like I said, I'd like to have all of my business devices on a different subnet (10.0.1.x) than the rest of the clients in the house (10.0.0.x) while still having completely open communication between them. I'm okay with switching some routers around (or even getting another router or another network switch or something) if that's necessary. Currently, every device on the 10.0.1.x network is able to initiate a connection to 10.0.0.x devices. For example, pinging 10.0.0.15 from 10.0.1.100 actually reaches the 10.0.0.15 client (and I verified this by having an HTTP server running on every device and using What I discovered was that when I pinged 10.0.0.15 from 10.0.1.100, the request was coming from the TP-Link router itself (10.0.0.10), not the client on its own subnet (like 10.0.1.100). Let me know if I should make a separate thread for this next question, but I also would really like to know why only the devices on 10.0.0.x can find each other via hostname; my devices used to be able to do that on the 10.0.1.x network, but they suddenly quit being able to. I now have to use each device's IP address in order to communicate with it. Thank you in advance, and my deepest apologies if this question exists elsewhere (might be a duplicate of One ISP, two switches, two subnets, but I really can't tell), it's just such a specific situation that I couldn't really tell what the issue would narrow down to, and therefore didn't really know what to search for. Nick W. |
Measure traffic for an interface monthly Posted: 31 Oct 2021 03:51 PM PDT I am running a small server in a remote home and I have a simcard with very limited data usage. I would like to have a file that measures cumulatively month by month (starting from the 27th of the month) the data consumption (MB) for a specific interface. I have tried different tools such as |
Apache Redirect for HTTPS (Nextcloud) leads to redirect loop Posted: 31 Oct 2021 03:49 PM PDT How can I correctly configure Nextcloud and Apache, to have correct URL redirection? I have configured Apache for redirection of HTTP to HTTPS, using a simple NextCloud configuration specifies that it should (via automatically generated The server fails to redirect, instead getting into a redirect loop. With The intention is to use Nextcloud's configuration to rewrite its URLs nicely, and to use Apache |
Prevent SlowLoris attack with ModSecurity (Apache) Posted: 31 Oct 2021 03:40 PM PDT I'm unable to stop a SlowLoris attack using ModSecurity in my apache (2.4) server from a computer that is in the same network. I'm on Debian 11. I add this to the /etc/modsecurity/modsecurity.conf :
And set this to On: I'm using this to execute the attack: And yes I do: |
My Domain keeps disconnecting from Droplet IP Posted: 31 Oct 2021 03:43 PM PDT I recently completed this tutorial on setting up multiple wordpress servers on nginx https://www.youtube.com/watch?v=P7W4iYkFaOU&t=168s I have 1 Domain and 4 subdomains connected each with their own server blocks. The issue I'm having is that the domain and subdomains seem to keep disconnecting from the ip address turn off and on every 10 minutes. I've tested it just using the ip address instead of the domain name and it works. My cpu, memory and bandwidth usage definitely fine. Not sure what the issue is. |
Combining Network Connections for Additive Speed Posted: 31 Oct 2021 06:44 PM PDT Edit: I've removed the errors I was receiving while starting the bond by using the teamd utility. However, my goal to increase the total speed by combining the networks is still open. Skip down to EDIT2 below if interested. I may delete in between soon, because it is an artifact of using the 'interfaces' config and commands like I narrowed down errors in starting a bond0 to some circular logic. I'm trying to use Edit: https://www.ibm.com/docs/en/linux-on-systems?topic=recommendations-bonding-modes Quora question maybe clarify the terms used for L2 load balancing as 'link aggregation': https://www.quora.com/How-is-load-balancing-achieved-with-layer-2-devices
EDIT2: It looks like 'network teaming' with teamd may work. Yes this prevents any errors from the interfaces config file, while still bonding the networks with different bonding modes including load balancing. Load balancing multiple NICs on single machine presenting a virtual IP There may be difficulty in combining networks for speed. Failover and load balancing seem to be switching between networks based on which is more available, but that doesn't combine them additively. A given process is looking to a single IP address at a time to reassemble packet streams. I would need something that requests packets over two different networks and reassembles the streams, as in 'redundant routing'. Some kind of VPN may be required for that, similar to what Speedify does. However, a local VPN would be more ideal. If they use physical devices to combine the networks, virtual devices might be able to simulate them. https://networklessons.com/cisco/ccie-routing-switching/introduction-gateway-redundancy |
Ansible is it possible to use variable in template src Posted: 31 Oct 2021 06:00 PM PDT In ansible we are trying to access different templates based on variable. We have following template files like: In tasks we need to copy template file based on the app name. for eg: we will specify a variable named "instance_name" to either app1 or app2 or app3. Now based on the variable we need to copy the app file to /opt/(( instance_name }}/conf.d/. we created ansbile task as follows but its not working.
When we hard code "src" to app1.conf.j2 its working for app1. From this url https://docs.ansible.com/ansible/latest/modules/template_module.html#parameter-src it specifies value can be a relative or an absolute path. Please let us know is it possible with this method? We are having around 20 apps and whats the best method to simplify the ansible playbook to specify only the variable. |
How to automap shared mailbox **without** granting Full Access in Office365? Posted: 31 Oct 2021 04:12 PM PDT I want to establish a shared mailbox for a project team. I want this mailbox to be auto-mapped into the team members' Outlook profiles. However, I do not want them to have Full Access, so I can still control access permissions on individual folders inside that mailbox - for instance, to hide all the superfluous default folders they won't need, but also to have different folder permissions for project leads and mere stakeholders. For test purposes I already solved this on our on-premise Exchange Server: Simply entering the DNs of the team members into the shared mailbox's I feel I must be missing something essential here: Why exactly is auto-mapping tied to Full Access in the first place? Is my use case really that outlandish? Are there other approaches for this that I simply haven't thought of? |
Postfix - block by sender email domain ip Posted: 31 Oct 2021 07:06 PM PDT For some time now I receive a lot of spam emails. The emails are all different but if I lookup the domain of the email address it always resolves to the same IP address. So:
In postfix I can reject each email address but in this case it is not helpful because the email address changes all the time. The next problem I have is that each email is send through a different mail server. So I cannot block by sender address. What I would like to do is block an email by the ip address. Not that of the sender but of the ip address of the domain used as part of the email. Any suggestions on how this is done in postfix? |
How to redirect from one subfolder to a subsubfolder with htaccess Posted: 31 Oct 2021 05:02 PM PDT I have this folder structure: The URLs one would call look like this:
Now all I want to achieve with an I tried but in this case when I open I tried but this obviously results in an endless redirect spiral to So I figured I need some I tried this because I figured this would replace "/content/page3" with "/content/page3/a", but to no avail, it doesn't do anything. I now went with using and replaced the relative references in the document with absolute ones. This works. But firstly I would still prefer if the references could remain relative, so the document doesn't break in case the How can I achieve this? |
No protocol handler was valid for the URL /url. If you are using a DSO version of mod_proxy Posted: 31 Oct 2021 04:03 PM PDT Trying to set up a load balancer using Apache 2.4.x on Windows. Error: No protocol handler was valid for the URL /path/. If you are using a DSO version of mod_proxy, make sure the proxy submodules are included in the configuration using LoadModule. Accessing webswing with websocket code deployed on jetty server. Same configuration is working on Linux. config file: |
Powershell Exchange Delete old Phone Sync Devices Posted: 31 Oct 2021 09:06 PM PDT I'm trying to run a Powershell Script that will clean up any Phones that haven't synced in at least 110 days with the Exchange 2013 Server. My code will pull the data and export it to CSV but when I try to pipe in the Remove-MobileDevice command to delete the devices the script fails to do so. Nothing I found on the Internet has been of much help so far. Most are using the outdated ActiveSyncDevice cmdlets. Here's my code, I'm new to PowerShell and appreciate any help: |
Turn on Gzip for combined JS or CSS files without file extension Posted: 31 Oct 2021 04:03 PM PDT I'm trying to configure GZip on my nginx server. It works for files with an file-extension.
So when I have a combine css file without a file extension it doesn't know it needs to be gzipped and serves it plain. Is there a way to let nginx know that everything served from a specified location always needs to be gzipped. With or without an file extension? |
Percona XtraDB Cluster 5.6 does not start Posted: 31 Oct 2021 08:06 PM PDT All the good days. I want to run for test purposes Percona XtraDb Cluster on ubuntu 14.04. The basis here took these two articles
I came instead
The daemon does not start The logs several errors. Error one:
Sure I ran
Error two:
All are advised to remove all of the folders My file my.cnf Actually the question: how to start? If there is anyone working configuration, then please share. |
redirect traffic from 127.0.0.1:5003 to external interface Posted: 31 Oct 2021 10:01 PM PDT I have an application that exposes Web Services on the loopback address 127.0.0.1:5003 so they are only available to the localhost. Is it possible to redirect traffic from there to the external interface so I can call the Web Services from other PCs on the network? I'm pretty sure this can be done by playing with the IP tables in Linux but I'm using windows 7. Thanks in advance! |
pgpool2 parallel mode: Non-superusers must provide a password in the connection string Posted: 31 Oct 2021 05:02 PM PDT I have two AWS RDS postgres nodes backing a parallel mode pgpool setup on EC2. After using pgbench to populate test tables, I get odd behavior from test queries. Any query that uses a function produces the error mentioned in the subject line, while other queries work as expected. Three examples showing success, expected failure, and unexpected failure: Success -- Yields the expected record set: Since the backing nodes are on RDS, md5 authentication is required. Authentication appears to be working fine in the case of non-function queries, as can be seen by replacing the correct password above with an incorrect one. Expected authentication failure: Here's the part that has me baffled -- If I put a function like min() or count() into the query, I get authentication problems: As can be seen from this last query, the password is supplied in the connection string (to the fronted, anyway) and it is the correct password as shown in the first query. Why would my first query work fine with no auth problems, but the third one fail? Have I overlooked a setting somewhere? Edit 2014-10-23: Adding more information. I added superuser privileges to user pgpool on the (frontend) system database and no longer get Turning on debugging for pgpool and looking in the log, I see the query being rewritten as the following, which, in the call to dblink, does not contain the password specified in the original connection string: |
Can windows credentials be stored for 'All Users'? Posted: 31 Oct 2021 09:06 PM PDT I am looking for a way to store windows credentials for 'All Users' as opposed to individually-named Users in Win7. Issue - we have a company server that is being accessed by multiple users. Each user logs on to the server with their unique user credentials. While working on the server, each user has need to access paid-for-services via a state (as in ND) web site. When they click on the web site link for these services, they are presented with a Windows Security challenge. All unique users enter a common set of credentials (same username & password) for access to the state server. The user only has to enter the state credentials once and they are good the rest of the day even as they log off and log back on to our company server. The kicker is that all individual user profiles are auto-deleted every night for business reasons. The users are wondering if there was some way the state credentials can be stored so that no matter what user logs on to the company server, the state credentials will always be available when they try to access the state's paid-for-services, without having to type them in every day. |
How to restore Ubuntu server on a VMWare image after disk failure? Posted: 31 Oct 2021 08:06 PM PDT After a disk failure on a VMWare GSX I was able to start the raid with one disk and copy the VMWare image to my ESXi server. After repairing the image with and converting it to ESXi with I am not able to boot the image an just get and the cursor does not even blink. What are my options now? Is it possible to recover somehow with a rescue CD? What are the steps? UPDATE: I followed the advice to create a new Ubuntu server and add the VMWare image as new disk. However I get the following. I was trying to restore the superblock but had no luck with the following commands. The above printed several numbers (as described in http://linuxexpresso.wordpress.com/2010/03/31/repair-a-broken-ext4-superblock-in-ubuntu/). I just keep getting "The superblock could not be read...". Do I have any chance to get the data on this ext3 file system back? |
MS SQL 2008 - Can I use Windows Authentication to connect from a Mac Posted: 31 Oct 2021 06:00 PM PDT I have been using Navicat SQL on Mac (Snow Leopard) to connect to MS 2005 via "Basic Auth" and all is good. However the DB is now being migrated to MS 2008 and try as I might I cant get on via Windows Auth. I get the message... [FreeTDS][SQL Server]Login failed. The login is from an untrusted domain and cannot be used with Windows authentication. [FreeTDS][SQL Server]Unable to connect to data source Any Ideas would be v greatfuly accepted. Many Thanks. |
Posted: 31 Oct 2021 10:01 PM PDT I get this error when running Start/Stop/Restart-CacheCluster commands in Caching Administration Windows PowerShell console:
What am I missing here? Microsoft help does not list this error code here. Running v.1.1 of AppFabric on Windows7 x64 machine. EDIT: I have a single host, but am running in cache cluster. Also this set-up used to work a couple of days before, but unfortunately can't tell what actions exactly led to it stopping working. |
how to find out the valid store names for certutil Posted: 31 Oct 2021 05:34 PM PDT I'm trying to find a way to script installing a certificate. Going "right-click->install certificate" works, and shows the certificate under 'subordinate certification authorities' in IE's certificate view If found the certutil.exe command, My question is how do you list/find out the valid storenames? |
Why is the chroot_local_user of vsftpd insecure? Posted: 31 Oct 2021 06:15 PM PDT I'm setting up on my VPS a vsftpd, and i don't want users be allowed to leave they're ftp home directory. I'm using local_user ftp, not anonymous, so I added:
I've read in a lot of forum post, that this is unsecure.
|
Using Gentoo's `ebegin`, `eend` etc under Ubuntu Posted: 31 Oct 2021 07:06 PM PDT We're quite fond of the style of the Producing output similar to: As a result we're using these commands in some of our common shell scripts, which is a problem for the people using Ubuntu and other linuxes. (linuces? linuxen? linucae? other distros) On Gentoo these functions are provided by OpenRC, and imported with In theory we could replace them all with dull |
You are subscribed to email updates from Recent Questions - Server Fault. To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States |
No comments:
Post a Comment