Recent Questions - Server Fault |
- Can ping OPC UA server, but cannot connect to it
- RDS RD Web Access on Windows Server 2012 R2 Essentials
- I'm having trouble accessing my Plesk Panel on the remote server after Node.Js installation [closed]
- Apache VirtualDocumentRoot multiple subdirectories possible
- Google Cloud VM startup-script to change ssh port
- php-fpm not conncecting to mysqld.sock
- why is port 35128 associated with ssh2? [duplicate]
- I Would like to develop a web crawling system. how to get the Web URL List?
- AD domain accounts cannot login Windows workstation
- Not Able to start tomcat-logserver.service
- Wifi Router Internet connection not working with PC, although mobile's hotspot does [closed]
- Aggregate multiple log files in a directory
- How can I setup 2FA on non-interactive SSH connections?
- How to configure a double proxy jump for apt install?
- what's root cause of "A start job is running for Create Volatile Files and Directories"
- How do I forward all invalid incoming mails in exim
- GlusterFS not running on correct port! (peer disconnected / brick not starting)
- Samba login failure: getpwuid failed
- Dovecot Virtual Users Cannot Send/Receive Mail
- Squid proxy behind Haproxy
- Containerized PostgreSQL with data on a distributed file system
- PHP5 unmet dependencies when upgrading
- Convert HTTP request to HTTPS through Apache and Squid
- Failed at step EXEC spawning /usr/libexec/mariadb-prepare-db-dir
- Domino always server fails to send SMTP email at first attempt
- Unable to Access SBS 2011 Backup Drive
- Zabbix agent - high CPU usage
- nginx regex characters that require quoting?
- blank email bodies on exchange 2010 / outlook 2010
Can ping OPC UA server, but cannot connect to it Posted: 27 Apr 2022 12:50 AM PDT I have an OPC UA server running on a PLC from BR Automation and would like to connect to it from UaExpert running on a Windows 10 machine. It has worked previously, but after physical re-placement of the components and installing a new ethernet cable, I cannot connect to the server any more: However, I am still able to ping the OPC UA server. Security and Authentication Settings are unchanged on my side. I have no possibility to access the settings on the server side, but there is no reason why they would have changed. They have never changed in the past. The new ethernet cable has a length of about 40 meters. Maybe that is an issue? Does anyone have a suggestion why I cannot connect to the server, even though I can ping it? |
RDS RD Web Access on Windows Server 2012 R2 Essentials Posted: 27 Apr 2022 12:50 AM PDT I have a single server setup on Windows Server Essentials 2012 R2 and I need to deploy MFA to secure RDP access to some of the office machines. I don't believe the Anywhere Access bundled with 2012 R2 Essentials is capable of this, so I have installed RDS in order to run it through the Application Proxy (1.6, which I know is only supported until August). I am having issues getting access to desktop sessions through RD Web Access and would like some advice please. So far I have de-activated Anywhere Access and have RDS setup on the server, which is also the DC and DNS for the network. The external domain (server.domain.com) is backed by a trusted certificate and points to the gateway router that the server is behind. Port 443 is forwarded to the server and there is an A record resolving internal lookups to server.domain.com to the server There is a CAP and a RAP in place that are assigned a security group of users that are permitted remote access and a security group of computers that should be remotely accessible. The RD Web landing page shows up at server.domain.com/RDWeb and if I try and login there were initially only basic resources (MS Paint, etc.). I unpublished these and published the RDP app, but this was not visible and there are no computers visible on the RDWeb landing page. I found an article that advised changing the value of ShowInPortal in a Terminal Server registry key, and this creates an RDP sessions for what I think is the server that repeatedly asks for credentials, but doesn't authenticate Interestingly, the original Anywhere Access landing page is still served up by IIS and this still provides RDP sessions for the individual computers on the network, but these throw out an error message after providing credentials to say that 1) the user account, or 2) the computer is not authorised to use the RD Gateway or 3) an incompatible authentication method is being used (I have selected password only at this stage). I haven't looked at licensing yet, as I am assuming that the grace period will allow me to test this and shouldn't be a barrier to getting it up and running? I know the above is a lot to pick through, but if anyone has any ideas, I would love to hear them. |
I'm having trouble accessing my Plesk Panel on the remote server after Node.Js installation [closed] Posted: 27 Apr 2022 12:10 AM PDT I'm having trouble accessing my Plesk Panel on the remote server. I used Apache Web Server in Plesk Panel. But for an application development I had to use Node.Js. So I searched Plesk official website how to do it and just installed Node.Js and NPM server from Plesk admin panel. After confirming the install, I saw the install progress bar and it never went away. I've waited over a few days to finish this process bar. The problem is that I can never access the Plesk login panel again (port 8443/8880 is closed automatically) and I can't even access the login page. HTTP or HTTPS requests return "Unable to connect" message. However, everything except the Plesk Panel login page (i.e. webpages, emails, MySQL database) works fine. I've tried accessing the server to open the port with SSH by the admin account, but it's being rejected by server. (I've tested FTP access from the admin account, but it's also denied). Thus, I cannot restart the server again. I cannot see logs, I cannot edit htaccess files, or stop any process, change firewall setting, etc. I can only access the server using SSH and FTP by standard user accounts, but they don't have the required permission to make any changes. How can I solve this problem? Any help would be greatly appreciated. |
Apache VirtualDocumentRoot multiple subdirectories possible Posted: 26 Apr 2022 11:38 PM PDT I have a local Apache server for developing pages. Therefore, I have a root folder where all the different pages are in subfolders. Those folders then have another subfolders for the public content. This could be - depending on the framework - a different folder (e.g. public, wwwroot, webroot, httpdocs). Now instead of using http://localhost/page/webroot I want to use the http://page.localhost/ URL scheme because it should be like in real world (e.g. links which point to root should work and so on). First I tried with So my second approach was to use mod_rewrite. with something like: (The last 3 lines can be repeated for the other folders - skipped here for readability) That looked quite promising in the beginning, but then I found out that it does not work if the page has a .htaccess file with local mod_rewrite in it which maps all requests to index.php (like some framework do). In this case the mod_rewrite will run into an endless loop as the dynamic part of the path is treated like a subfolder and not like the DocumentRoot. Here is the output from the log: https://pastebin.com/4aNgRahx This repeats until the recursion limit is reached. The .htaccess file looks like this: If I switch it off it will work. So what I should do now? Changing the .htaccess or any files in the project folder is not an option because it will not work anymore in the real server then. |
Google Cloud VM startup-script to change ssh port Posted: 26 Apr 2022 11:34 PM PDT After changing port i'm unable to login SSH Extremely large packet length from remote suggests data stream corruption firewall already open for that port Now i wanted to try revert ssh port to 22 Can I do it with google startup-script and if yes, what command i need for that ? Thanks |
php-fpm not conncecting to mysqld.sock Posted: 26 Apr 2022 11:12 PM PDT i have created a profile using aa-genprof type=AVC msg=audit(1): apparmor="DENIED" operation="connect" info="Failed name lookup - disconnected path" error=-13 profile="/usr/sbin/php-fpm7.4" name="run/mysqld/mysqld.sock" pid=3723 comm="php-fpm7.4" requested_mask="wr" denied_mask="wr" fsuid=33 ouid=113 i manually added /var/run/mysqld/mysqld.sock rw, to apparmor profile still same any solution?? |
why is port 35128 associated with ssh2? [duplicate] Posted: 26 Apr 2022 10:41 PM PDT I failed to login to my root account over ssh, and when doing so I noticed this interesting line in auth.log: "Failed password for root from [ip address] port 35128 ssh2" I'm not so interested in the actual failure to access root (I found a solution to this), I'm more interested in why this is going to/coming from port 35128 since ufw is set to deny incoming traffic on ports that aren't 80 and 22 by default. I'm very new to working with servers, so I'm interested to see what this is. |
I Would like to develop a web crawling system. how to get the Web URL List? Posted: 26 Apr 2022 10:32 PM PDT I Would like to develop a web crawling system. any idea to get Malaysia visited Web URL? or how to get all the world Domain name? like google bot can web crawling for all web site. |
AD domain accounts cannot login Windows workstation Posted: 26 Apr 2022 09:01 PM PDT Tried some searching but failed to find helpful answers. I'm currently examining an AD domain user account issues in an enterprise DevOp environment which is utilizing VMware Horizon VDI and the VDI is affected by the issues. The problem is: the existing AD user accounts are able to access Windows 10 desktops(which are domain-joined) but the new created AD user accounts cannot login these desktops. While logging in with the "welcome" word and circle figure appear on the screen, the "new created AD user accounts" will be kicked with no error messages. I did some troubleshooting with the VMware Horizon part and some of the error/log messages from theses VMware Horizon products are listed below: "Sending not authenticated response for set-user-global-preferences request." "Sending not authenticated response for do-logout request." "Invalidating the session marked unauthenticated" "Session : bab3--0c66--72f6-***-7a66 is removed" "Request router channel became inactive" And eventually VMware official support engineer determined that the root cause is from AD domain. Let's back to the topic about AD domain. At the beginning, there's only one Ad domain controller of window server 2016 version 1607 with only the roles "AD domain service" and "DNS" installed. In recent days, I thought the issue was due to first DC system unstable so a second domain controller was created and all 5 FSMO roles were transferred to this second DC. Currently I tried using the new created ad domain users to login the Windows desktops directly(bypass VMware product) - still the same issue! I can see Windows server ID 2089, 2887 on the domain controllers but according to my understanding these do not concern the domain accounts' login issue of my question. From the Windows workstation desktop(that I repeatedly use domain users to try to login and troubleshoot), I discovered lots of id 7001 and 10005 events in the event viewer. This is weird. I enabled LDAP "require signing" policy on DC and workstations but the issue still persist... Can anyone give me some hints please. |
Not Able to start tomcat-logserver.service Posted: 26 Apr 2022 11:24 PM PDT |
Wifi Router Internet connection not working with PC, although mobile's hotspot does [closed] Posted: 26 Apr 2022 10:03 PM PDT I have a PC with windows 11 on it, and I bought this network adapter for allowing me connect the internet through wifi: https://prnt.sc/5ekQQycs6QWl After installing the driver, I tried to connect to my home's wifi network, but it didn't succes. After connecting to it, it says "No Internet, Secure" in the wifi's list. However, when I open hotspot on my phone, it always working and I have internet on my PC. Also, the house's wifi works execlent, as all the devices and TV's are working with it. It tried restart everything, the modem, PC, forget network and connect again but it still not working. Also, I do have ping to the default gateway (192.168.1.1) Any help please ? |
Aggregate multiple log files in a directory Posted: 26 Apr 2022 11:48 PM PDT I have k3s single node cluster running on a machine. I do not have any logging infrastructure set up yet and I'd leave this as a future learning experience for now. On that k3s I run some cron jobs which create logs for each of the jobs into a separate file. I can observe them in I'm unable to find a simple tool that could watch that logs directory, preferably with a file name pattern, and stream/join those small job logs into a single log file, including new files that are being created. I don't mind if file name is lost, I just want the log lines to end up in one file serving as an archive of all the job runs. What I have considered? I could just add a script to cat those files and append into a target file with an interval, but I'd have to keep track which files have already been inserted in case of the jobs get out of sync or the cron interval changes. Also I might like to extend this functionality for pods that are "long-running" and in this case I'd have to start tracking updated lines in logs. All examples I have found deal with real-time tailing on screen, which Is not what I need. I kind of need multi-tailing into a target log file. Any ideas? (I'd also accept some kind of simple Kubernetes logging hook example) |
How can I setup 2FA on non-interactive SSH connections? Posted: 26 Apr 2022 08:59 PM PDT I would like to add a level of security for logins to an SSH server (Ubuntu), using two factor authentication. One particularity on how the users connect to the SSH server is that sometimes they do it in a non-interactive way: the SSH server is configured in the users' MySQL client to be used as a bastion/proxy to reach a database. As a consequence I'm looking for 2FA setups that don't require the user to type anything in a terminal. One existing solution that sounds promising in theory is Google's phone prompt allowing the user to validate the connection. Every SSH user would be associated with a phone number and this phone number would receive a prompt to validate on each connection. An obvious downside to this idea is that it sounds like it would require the development of a phone app, which would make it way too complicated and expensive. Are there other techniques that I could use to allow users to validate non-interactive SSH logins? |
How to configure a double proxy jump for apt install? Posted: 27 Apr 2022 01:06 AM PDT I need to install packets in a KVM guest (vm) but the KVM host (hypervisor) doesn't have internet. I already know how to configure an ssh+apt proxy to give apt install capabilities to computers in a one jump lenght proxy. I tried setting a bridged interface but I keep getting connexion error after a few seconds of apt install through ssh. I'm now in the need to perform a double jump to work aroung this issue. I tried chaining the proxy like below but I encounter some errors : The first jump work fine, I can apt install on the hypervisor. But when I try it on VM1, the following error apprear : It seems to come from the redirection between the two ssh sessions, the hypervisor seems to fail to redirect the apt install request from VM1 to the ssh1 tunnel. Do you know how to resolve my issue ? Note : The KVM host-guest network interconnexion is done by the default NAT bridge (switch). |
what's root cause of "A start job is running for Create Volatile Files and Directories" Posted: 26 Apr 2022 11:28 PM PDT Stuck at "A start job is running for Create Volatile Files and Directories" after reboot a server(Debian 9.5, 64bit), and solve by this "boot-stuck-at-a-start-job-is-running-for-create-volatile-files-and-directories". I can't figure out what is the root cause of this issue, although search from many questions which are not refer the root cause but just the varied solutions that not meet me. We have not reach the limit of file or (sub) directory, and set the And the are more than 50% capacity of The original Some info: |
How do I forward all invalid incoming mails in exim Posted: 26 Apr 2022 10:30 PM PDT I have to all my invalid incoming to new addresss I have a route like this. virtual_aliases: driver = redirect allow_defer allow_fail domains = lsearch;/etc/userdomains user = "${lookup \ {$domain} \ lsearch{/etc/userdomains} \ {$value} \ }" group = "${lookup \ {$domain} \ lsearch{/etc/userdomains} \ {$value} \ }" address_data = \ "router=$router_name \ redirect=${quote:${lookup \ {$local_part} \ lsearch{${extract{5}{::}{${lookup passwd{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}{$value}}}}/etc/${perl{untaint}{$domain}}/aliases} \ }}" data = ${extract{redirect}{$address_data}} file_transport = address_file router_home_directory = ${extract \ {5} \ {::} \ {${lookup passwd \ {${lookup \ {$domain_data} \ lsearch{/etc/userdomains} \ {$value} \ }} \ {$value} \ }} \ } local_part_suffix = +* local_part_suffix_optional retry_use_local_part unseen userforward: driver = redirect allow_filter allow_fail forbid_filter_run forbid_filter_perl forbid_filter_lookup forbid_filter_readfile forbid_filter_readsocket check_ancestor check_local_user domains = $primary_hostname no_expn require_files = "+$home/.forward" condition = "${extract{size}{${stat:$home/.forward}}}" file = $home/.forward file_transport = address_file reply_transport = address_reply directory_transport = address_directory user = $local_part_data group = $local_part_data no_verify File as user: redirect@domain.com , user *: ::fail:Any Message Here my normal forward works but not this * one |
GlusterFS not running on correct port! (peer disconnected / brick not starting) Posted: 26 Apr 2022 10:01 PM PDT On CentOS 7 witch two bricks on I've upgraded gluster from 313 to 6 by using This is my mount command: I then restarted The error message is on on So it makes sense it cannot mount when the brick is offline. However, I have no clue how to start this brick, even after searching for hours. It would be nice to find a solution. I tried removing the volume to recreate it but it complains not all bricks are connected. I also read that gluster uses ipv6 on default since version 5, but not sure how it affect my setup since srv1 seems to be up and running? EDIT: Glusterd is not running on the right port! It should be what the hell? How do I fix this?? Restarting does nothing than that it assigns a new random port... Why is it not running on 24007? |
Samba login failure: getpwuid failed Posted: 27 Apr 2022 12:56 AM PDT I cannot access a remote drive using Windows or smbclient; my authentication appears successful according to the samba log file, but Strangely, the SID corresponds to a local user: (ny4010 is my samba server machine) Even though on the client I am logging in using a domain user: Here is my smb.conf file: my nsswitch.conf file looks like: passwd: files winbind I think the smoking gun here is that a local user's SID is showing up in that getpwuid failed line... |
Dovecot Virtual Users Cannot Send/Receive Mail Posted: 26 Apr 2022 10:01 PM PDT I got Dovecot + Postfix running a few days ago in conjunction with Squirrelmail. Soon after, I got tired of "Mail for nuts," and switched to RainLoop. It seems to be working fine however, only with literal users. Virtual users can login, but cannot send OR receive mail. I've looked around, but can't figure anything out. One post indicated that this was caused by having destinations other than "localhost" in the Postfix config, but I still had the same issue. I think I've created all the needed accounts. The userDB is under the vmail account. Postfix (main.cf): # See /usr/share/postfix/main.cf.dist for a commented, more complete version Dovecot (dovecot.conf): Dovecot commands also seems to indicate that some settings such as VirtualUserDB (dovedb): |
Posted: 27 Apr 2022 01:05 AM PDT In my configuration, I use Haproxy mainly for reverse proxy. I installed Squid Proxy in my private lan and I can access it from external with port 3128. But I use the basic authentification ncsa and the headers is not crypted so my login is vulnerable. I want to forward my proxy by haproxy. [Client]->proxy.example.net->[haproxy:443 ssl]->[squid:3128] I added in my haproxy configuration a new backend: My default backend and other works fine but not proxy-squid. I realized a "tcpdump -nX -vv -i lo port 3128" during my request and nothing.. and with the port 443, I see many packets with incorrect checksum. In Wireshark, I do not see the ssl handshake like when I accessing example.com (default backend). I just see the 3-way handshake tcp followed by FIN, ACK. I think Haproxy do not understand my real request when I set the proxy in my browser config. So, is it possible to realize that with a specific configuration? Thanks! |
Containerized PostgreSQL with data on a distributed file system Posted: 27 Apr 2022 01:05 AM PDT I am curious if somebody is actually running PostgreSQL in a container in production on some form of distributed file system - GlusterFS preferably, or anything. I am currently running Mesos/Marathon. In case the PostgreSQL node fails, Marathon simply launches another instance of PostgreSQL on other nodes and if done properly (service discovery and application recovering from database connection loss), the ultimate fault tolerance will be achieved. I know PostgreSQL has its own HA solutions, like log shipping and hot stand-by backup, but then one still need to solve the problem on when to switch from master to slave, how to do it properly and so on. So, how do you run PostgreSQL in production on GlusterFS or similar? If so, is it stable? How about performance? |
PHP5 unmet dependencies when upgrading Posted: 26 Apr 2022 08:06 PM PDT Trying to upgrade PHP from 5.3 to 5.6 using the following: When I try this, I run into this error and not sure how to resolve: If I try to precede the upgrade by doing If I try I tried doing Also tried doing just What is the correct way to resolve these dependencies issues? |
Convert HTTP request to HTTPS through Apache and Squid Posted: 27 Apr 2022 12:01 AM PDT We have a service running internally that needs to upload files to S3 and all outgoing traffic currently routes through a Squid server I manage. The service that sends the files only supports HTTP but we want them encrypted when going from the proxy to S3. It appears that Squid cannot do this natively, so I'm attempting to set up Apache 2.2 on port 80 on the same Ubuntu server to transparently rewrite the URL from http to https and then proxy it through Squid on 3128. I just haven't been able to figure out the right Apache configuration for this. I think it should be something like this (assume local IP is 10.1.2.3): It's that last comment that I haven't been able to figure out. Any suggestions? |
Failed at step EXEC spawning /usr/libexec/mariadb-prepare-db-dir Posted: 27 Apr 2022 12:01 AM PDT a bit of a newbie here so mind my obliviousness. I'm trying to install mariadb on a fresh Centos 7 server, though upon running "systemctl start mariadb.service" I get this malarkey:
"journalctl -xn" outputs:
And "systemctl status mariadb.service" outputs:
I've checked the file permissions and it seems to be in order... Running from sudo also produces the same result. If anyone has any tips, they would be greatly appreciated. Thanks! |
Domino always server fails to send SMTP email at first attempt Posted: 26 Apr 2022 09:05 PM PDT In our logs, we find the below: Which is then followed by: Our messages go out normally, but we see this same issue EVERY connection we make. I beleive there is something wrong with my configuration, probably with a timeout, or something similar, but I have not been able to pinpoint it correctly. |
Unable to Access SBS 2011 Backup Drive Posted: 26 Apr 2022 09:05 PM PDT I have a client running an SBS 2011 server that is configured to make backups to an external hard drive via the built in server backup utility. I am unable to access this drive - It shows up in disk management but there is no drive letter assigned. When I assign a drive letter, the drive shows up but I get an access denied error when attempting to open. Is this normal behavior for an SBS backup drive? |
Posted: 26 Apr 2022 11:06 PM PDT I am monitoring a host with the help of Zabbix and I noticed that Zabbix agent started using quite a lot of CPU cycles: There are about 100 items monitored with the agent. They are also monitored on other identical hosts where Zabbix agent does not consume so much of CPU. Agents send collected data to Zabbix proxy. The agent configuration is default. The host CPU has 8 cores (2.4 Gz). The smallest time value for monitored items is 60 seconds. I use Zabbix server / agent 1.8.11 and I can't upgrade to 2.2 at least now. I checked debug log from all sides: Zabbix server, proxy, agent and can't find any issues there. Just usual checks received and sent all of the time. I don't know how to investigate this issue further and asking for community help. How could I trace why agent is consuming CPU so hard? One more thing that is looking strange for me is stats of the network connections: Thank you. Update 1. 10.128.0.15 - IP of Zabbix server 10.120.0.3 - IP of Zabbix host Update 2. Those TIME_WAIT connections are from web server nginx. Update 3. I attached to the Zabbix agent process with strace and it appeared that 100% is used by agents on the Update 4. Just to get all things clear... I tried to work with the TIME_WAIT connections state. For example, I tried decreasing Conclusion The Zabbix agent CPU load issue appeared to be bound with the network connections number. If we attach to the zabbix_agentd process using strace, we will see how CPU cycles are used (1-st column - CPU time spent running in the kernel): Here most of the CPU time is used on the read system calls. Further investigation showed that these read calls (2 of them are shown below) are continious attempts to read the |
nginx regex characters that require quoting? Posted: 26 Apr 2022 08:06 PM PDT So I was configuring nginx today and I hit a weird problem. I was trying to match a location like this: ...for URLs like "http://my.domain.com/0001/index.html". This rule was never matching, despite the fact that it by all rights should. It took me awhile to figure out, based on this documentation, that some characters in regexes need to be quoted. The problem is, the documentation is for rewrites, and it specifically calls out curly braces, not square brackets. After a fair bit of experimentation that involved a lot of swearing, I discovered that I could fix the problem by quoting the regex like so: Is there a list somewhere of characters that nginx requires quoting regexes with? Or could there be something else going on here that I'm totally missing? This is my first nginx configuration job, so it's very possible I've misunderstood something... |
blank email bodies on exchange 2010 / outlook 2010 Posted: 26 Apr 2022 11:06 PM PDT We are experiencing random blank email bodies on email sent between internal users on Exchange 2010 sp1 rollup pack 3 and clients using outlook 2010 sp 1 on windows 7 with latest patches. The same email sent to different users is correctly received by everyone but one single user (it happens randomly on different users). In outlook the user can see headers (Sender, Receiver, subject, date, etc) but the body is completely blank. We already tried with no luck:
Any suggestion would be welcome. |
You are subscribed to email updates from Recent Questions - Server Fault. To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States |
No comments:
Post a Comment