[Winedale-l] Re: Winedale-l Digest, Vol 156, Issue 4

2025-03-25 Thread Laura Smith
Happy happy birthday, Doc! Big hugs to you and JoAnn. Love you both... Laura On Tue, Mar 25, 2025, 8:14 AM wrote: > Send Winedale-l mailing list submissions to > winedale-l@lists.wikimedia.org > > To subscribe or unsubscribe, please visit > > https://lists.wikimedia.org/postorius/lis

Bug#1098267: dns-root-data: root.key needs updating

2025-02-18 Thread Laura Smith
Package: dns-root-data Version: 2024041801~deb12u1 Severity: important X-Debbugs-Cc: n5d9xq3ti233xiyif...@pm.me Dear Maintainer, /usr/share/dns/root.key appears to be an old file in need of refresh? This causes various issues being logged such as: [taupd ] you need to update package with trust a

Re: [Pdns-users] PowerDNS, multi-cloud, feedback needed on options I am considering

2025-01-24 Thread Laura Smith via Pdns-users
On Friday, 24 January 2025 at 10:58, Alexis Fidalgo wrote: > > 1. If you loose connection between secondary and primary kafka will hold the > updates (for the time you configure retention time in the topic) so when > connection is restored, secondary site (consumer) will receive from where i

Re: [Pdns-users] PowerDNS, multi-cloud, feedback needed on options I am considering

2025-01-24 Thread Laura Smith via Pdns-users
> Personally I have good experiences with Lightning Stream in a multi-cloud > setup, but again: your "best option" might be different than mine. > I assume you are manually synching the two cloud S3 instances as AFAIK there no built-in mechanism for Lightning Stream to write the same data to

[Pdns-users] PowerDNS, multi-cloud, feedback needed on options I am considering

2025-01-24 Thread Laura Smith via Pdns-users
I am looking at building in some multi-cloud resilience to a deployment, was considering my options and would appreciate any thoughts ! So far, my ideas are: 1) Run both clouds completely independently and have some middleware that pushes the same API command to both PowerDNS instances. I know

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-23 Thread Laura Smith
Sent with Proton Mail secure email. On Monday, 23 December 2024 at 14:00, Kevin P. Fleming wrote: > The simplest fix is to set "DNSSEC=no" That seems to me to be a bit of a "sledgehammer to crack a nut". The man page for resolved.conf says: "It is recommended to set DNSSEC= to true on

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-23 Thread Laura Smith
On Monday, 23 December 2024 at 13:10, Itxaka Serrano Garcia wrote: > Hallo there! > > If using systemd-resolved, cant you just configure the DNS in > /etc/systemd/resolved.conf or /etc/systemd/resolved.conf.d/ directly so it > setups your desired address? My DNS servers are currently manu

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-23 Thread Laura Smith
Sent with Proton Mail secure email. On Monday, 23 December 2024 at 12:23, Adam Nielsen wrote: > But what's the underlying issue? Maybe there's a different fix? Its been a while so I can't remember the exact details, but I know its to do with Postfix. Postfix creates a copy (not symlin

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-23 Thread Laura Smith
On Monday, 23 December 2024 at 07:45, Daniel Foster wrote: > I believe you can just remove the symlink at /etc/resolv.conf and > replace it with a file that points to 127.0.0.54. > Thanks Daniel, that has been my work-around, a systemd timer checking for 127.0.0.53 and doing a sed on /etc/re

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-22 Thread Laura Smith
On Sunday, 22 December 2024 at 22:13, Kevin P. Fleming systemd-resolved does not write or otherwise modify /etc/resolv.conf; your > system may have a symlink at /etc/resolv.conf which points to one of the > files created by systemd-resolved. Whatever tool or method is managing that > is the o

Re: [systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-22 Thread Laura Smith
Sent with [Proton Mail](https://proton.me/mail/home) secure email. On Sunday, 22 December 2024 at 22:13, Kevin P. Fleming wrote: > systemd-resolved does not write or otherwise modify /etc/resolv.conf; So you're saying this statement at the top of /etc/resolv.conf is a lie ? $ cat /etc/resolv.

[systemd-devel] systemd-resolved : How to change permanently to 127.0.0.54

2024-12-22 Thread Laura Smith
At present systemd-resolved inserts 127.0.0.53 into /etc/resolv.conf Certain applications on my system have problems with this, relating to DNSSEC and they work perfectly with the "proxy-only" 127.0.0.54 instead. What is the permanent way to ensure that systemd-resolved inserts .54 and not .53

[pfx] Re: postfix "system library:BIO_connect:Connection refused" following Debian Bookworm update

2024-12-22 Thread Laura Smith via Postfix-users
> Note that after the above you're allowing TLS 1.0 by default, where you > insisted on TLS 1.2 or higher before. Postfix parsing of the legacy > protocol negations has not changed. But you should be using the > preferred min/max forms. I know you're saying nothing changed, but I'm telling yo

[pfx] Re: postfix "system library:BIO_connect:Connection refused" following Debian Bookworm update

2024-12-22 Thread Laura Smith via Postfix-users
> Perhaps Postfix does not "listen" on the IPv6 address? You can use nc or lsof > to find out. > See above where I said "worked fine before the update". "Worked fine" includes external validation, i.e. direct email delivery and ipv6 test websites such as internet.nl For the records, I *th

[pfx] postfix "system library:BIO_connect:Connection refused" following Debian Bookworm update

2024-12-22 Thread Laura Smith via Postfix-users
Following a Debian Bookworm update I am now seeing connectivity issues that were not present before (everything was working perfectly before) Postfix on the instance starts up fine, i.e. indicating no configuration errors. The error is: $ openssl s_client -connect [IPV6_ADDRESS_REDACTED]:25 -sta

[pfx] Re: Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-09-02 Thread Laura Smith via Postfix-users
> $ postqueue; echo $? > postqueue: fatal: usage: postqueue -f | postqueue -i queueid | postqueue -j | > postqueue -p | postqueue -s site > 69 > > With an empty mail queue: > > $ postqueue -p; echo $? > Mail queue is empty > 0 > > $ postqueue -j; echo $? > 0 > > $ postqueue -f; echo $? > 0

[pfx] Re: Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-31 Thread Laura Smith via Postfix-users
> They should instead read output from "postqueue -j" which provides > information in JSON format. JSON support was added in Postfix 3.1 > (i.e. in 2015). > What are the minimum permissions required for postqueue ? postqueue run as an unprivileged user returns : - no output - 0 exit code Bo

[pfx] Re: Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-29 Thread Laura Smith via Postfix-users
> > Data collecting programs should use supported interfaces such as > postqueue output. If the supported interfaces are not sufficient, > people can ask for or contribute what's missing. > > Wietse Thanks Wietse. The only reason I was planning to use it is because, e.g. postfix-exporter for

[systemd-devel] DynamicUser access to a Linux socket

2024-08-28 Thread Laura Smith
Could someone point me into the right systemd service file hardening parameters to give a DynamicUser access to a Linux socket operated by another process ?

[pfx] Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-28 Thread Laura Smith via Postfix-users
In its default configuration, Postfix makes /var/spool/postfix/public/qmgr world accessible whilst the parent directory /var/spool/postfix/public is not. This means that metric gathering is not able to connect to  /var/spool/postfix/public/qmgr. I'm guessing the wrong answer is to make the met

Re: OpenBSD equivalent to FreeBSD hw.uart.console boot setting

2024-08-16 Thread Laura Smith
Sent with Proton Mail secure email. On Friday, 16 August 2024 at 12:41, Stuart Henderson wrote: > On 2024-08-16, Laura Smith n5d9xq3ti233xiyif...@protonmail.ch wrote: > > > On Friday, 16 August 2024 at 09:52, Peter N. M. Hansteen pe...@bsdly.net > > wrote: > &g

Re: OpenBSD equivalent to FreeBSD hw.uart.console boot setting

2024-08-16 Thread Laura Smith
On Friday, 16 August 2024 at 09:52, Peter N. M. Hansteen wrote: > On Fri, Aug 16, 2024 at 08:31:50AM +0000, Laura Smith wrote: > > > Is there an OpenBSD equivalent to the below flag which is set in > > /boot/loader.conf.local on FreeBSD ? > > > > hw.ua

OpenBSD equivalent to FreeBSD hw.uart.console boot setting

2024-08-16 Thread Laura Smith
Is there an OpenBSD equivalent to the below flag which is set in  /boot/loader.conf.local on FreeBSD ? hw.uart.console="mm:0xfedc9000,rs:2"

Re: Any ideas how long gmail cache DNS records ?

2024-08-13 Thread Laura Smith via NANOG
> > For the benefit of the list, was that https://dns.google/cache rather > than the previously mentioned > https://developers.google.com/speed/public-dns/cache ? > Yes, my bad Niels ! The one you mention is indeed the one that worked, the other one (and the other other one) just captcha

Re: Any ideas how long gmail cache DNS records ?

2024-08-13 Thread Laura Smith via NANOG
On Monday, 12 August 2024 at 16:11, Christopher Morrow wrote: > > you MIGHT try just using the 'clear the google-public-dns cache' page: > https://developers.google.com/speed/public-dns/cache > > I think we try really hard to NOT do what you think we're doing... Thanks Christopher. For th

Extra listener for client cert ?

2024-08-13 Thread Laura Smith via dovecot
Is it possible to, and (if yes) has anyone had experience with setting up an extra listener that requires client certs. The problem I've got is I still need to support Outlook clients.  Fortunately these are located in fixed locations on desktop computers. Meanwhile, I would like to harden the

[pfx] dovecot_destination_recipient_limit not mentioned in postconf.5

2024-08-11 Thread Laura Smith via Postfix-users
Why doesn't dovecot_destination_recipient_limit get a mention in the postconf docs (https://www.postfix.org/postconf.5.html) I discovered I needed it today because of an obscure error in my logs affecting only certain mails. Those mails worked again after dovecot_destination_recipient_limit=1

Re: Any ideas how long gmail cache DNS records ?

2024-08-10 Thread Laura Smith via NANOG
L you set.  The recommendation therefore > is to lower the TTL for a few days BEFORE you change your DNS records. > > --srs > > From: NANOG on behalf of Laura > Smith via NANOG > Sent: Saturday, August 10, 2024 7:46:31 PM > To: nanog@nanog.org > Subject: Any ideas how long

Any ideas how long gmail cache DNS records ?

2024-08-10 Thread Laura Smith via NANOG
In typical "Google knows best" style they appear to be ignoring SOA and TTL and doing their own thing. Changed DNS severs and MX records, other public mail services have picked it up no problem. Gmail however appear to be insisting on continuing to deliver to the old mail servers for god knows

[pfx] Re: postfix cleanup_service question

2024-08-08 Thread Laura Smith via Postfix-users
> I guess we are talking about your auth-user relay instance. We are indeed. I am not touching the other instances. > > If that one does not get mail via smtp on port 25, or only gets mail from > authenticated users via that port, you can move configuration to main.cf. Indeed that is the

[pfx] Re: postfix cleanup_service question

2024-08-08 Thread Laura Smith via Postfix-users
> in such case, it should also not be added into "smtp" service, unless Laura > (OP) uses different instance for incoming mail (or has more services in > master.cf) > Basically a derived version of https://www.postfix.org/MULTI_INSTANCE_README.html I have : - Null instance - Inbound instan

[pfx] Re: postfix cleanup_service question

2024-08-07 Thread Laura Smith via Postfix-users
Sent with Proton Mail secure email. On Wednesday, 7 August 2024 at 11:20, Viktor Dukhovni via Postfix-users wrote: > On Wed, Aug 07, 2024 at 09:29:35AM +0000, Laura Smith via Postfix-users wrote: > > > > You may want to check that with > > > > > >

[pfx] Re: postfix cleanup_service question

2024-08-07 Thread Laura Smith via Postfix-users
> > 3/ Referenced it under > > submissions inet n - y - - smtpd > > submission inet n - y - - smtpd > > smtp inet n - y - - smtpd > > > > using the same options setting for all three: > > -o cleanup_service_name=myheadercleanup > > > You may want to check that with > > postmulti -i postfix-my

[pfx] postfix cleanup_service question

2024-08-06 Thread Laura Smith via Postfix-users
I am running an instance of Postfix that is an authenticated relay. Overall it is working great except user IPs are leaking through Received headers. I thought I configured it right, but obviously not. Here's what I've done: 1/ Create header_checks file with the following: /^Received:/ IGNORE

Re: Contact mail for Weekly Global Routing Table Report has ended up on Spamhaus HBL

2024-08-05 Thread Laura Smith via NANOG
> > You could go to Spamhaus' web site and put in a ticket telling them that it's > a mistake. > > There's always one smart alec. I wonder why that didn't occur to me. Oh yeah, that's right, because ITS NOT MY EMAIL ADDRESS. I don't know if it got listed because of the Routing Table Repor

Contact mail for Weekly Global Routing Table Report has ended up on Spamhaus HBL

2024-08-04 Thread Laura Smith via NANOG
Just as an FYI, it appears the pfsinoz -at- gmail.com address given in the Weekly Global Routing Table Report has sended up on the Spamhaus HBL list. You might want to fix this to ensure visibility of the reports are maintained. :)

[pfx] Re: [OT] Null MX or not?

2024-08-01 Thread Laura Smith via Postfix-users
> My doubt is that since the outgoing email server identifies itself as > host1.example.com in the EHLO, is there a requirement or even an > expectation that postmas...@example.com will be able to receive email. I think the reality is that we are in 2024, and the chances of a human reading p

[pfx] Re: Do you reject DMARC failures?

2024-07-30 Thread Laura Smith via Postfix-users
I too am interested in experiences with rspamd and LLMs, so if there is anything people don't want to share on-list, please loop me in. :) Thanks ! Laura On Tuesday, 30 July 2024 at 18:51, Walt E via Postfix-users wrote: > Can you share your experience on LLM for rspamd? Any links/resources

Re: SV: [chrony-users] Certain NTS servers not synching, how to best troubleshoot ?

2024-07-29 Thread Laura Smith
ning > > -----Oprindelig meddelelse- > Fra: Laura Smith n5d9xq3ti233xiyif...@protonmail.ch > > Sendt: 29. juli 2024 22:28 > Til: chrony-users@chrony.tuxfamily.org > Emne: [chrony-users] Certain NTS servers not synching, how to best > troubleshoot ? > > I have

[chrony-users] Certain NTS servers not synching, how to best troubleshoot ?

2024-07-29 Thread Laura Smith
I have a weird situation where I cannot get NTS working to the netnod.se series of servers (e.g. gbg1-ts.nts.netnod.se ) Other NTS server are working without issue (e.g. ntppool1.time.nl) so its not 4460 being blocked on a firewall. What steps can I take to troubleshoot it ? I've tried "tcpdum

[pfx] Re: connect to pgsql server could not translate host name

2024-07-28 Thread Laura Smith via Postfix-users
> > > I know you're desperately trying to finger point elsewhere but I'm > > pretty sure you are barking up the wrong tree. Everything else > > works, apart from postfix. > > > At the risk of demonstrating my level of thick I have seen similar > messages about "Temporary failure in name reso

[pfx] Re: connect to pgsql server could not translate host name

2024-07-28 Thread Laura Smith via Postfix-users
> On Sun, Jul 28, 2024 at 09:45:45AM +0000, Laura Smith via Postfix-users wrote: > > > The reporting program is postfix/smtpd > > > > postconf output: > > > > smtp inet n - y - - smtpd > > > It runs in a chroot jail, where likely /etc/resolv.c

[pfx] Re: connect to pgsql server could not translate host name

2024-07-28 Thread Laura Smith via Postfix-users
> > But I cannot understand why. Running, e.g. "dig foo.example.com" > > returns instantly with the IP address, no problems with resolution? > > > Are you typing that command as root? Most Postfix daemons don't. > Yes, of course ! dig is a simple command that doesn't require root privilege

[pfx] Re: connect to pgsql server could not translate host name

2024-07-27 Thread Laura Smith via Postfix-users
Note that my copy/paste messed up the formatting, of course my user= line is on a seperate line: hosts=foo.example.com user=myuser password=mypass dbname=mydb query=select foo from bar('%s') ___ Postfix-users mailing list -- postfix-users@postfix.org To

[pfx] connect to pgsql server could not translate host name

2024-07-27 Thread Laura Smith via Postfix-users
I'm getting the following in my logs: " warning: connect to pgsql server foo.example.com: could not translate host name "foo.example.com" to address: Temporary failure in name resolution?" But I cannot understand why.  Running, e.g. "dig foo.example.com" returns instantly with the IP address,

Re: Debian Bookworm packages, please !

2024-06-27 Thread Laura Smith via dovecot
are not needed to buy pro licenses. Aki > On 27/06/2024 11:03 EEST Laura Smith via dovecot wrote: > > > Perhaps try reading my last post Scott. > > Perhaps especially the bit where I said OX were offered money but they were > not interested without megabucks being spent. &g

Re: Debian Bookworm packages, please !

2024-06-27 Thread Laura Smith via dovecot
Perhaps try reading my last post Scott. Perhaps especially the bit where I said OX were offered money but they were not interested without megabucks being spent. As others have said, take your cheap, unsubstatiated, attacks elsewhere chum. On Wednesday, 26 June 2024 at 21:24, Scott Q. via d

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
> Why do you care about the repo then ? Use the patch locally, > publish it, etc. You care about OpenSSL 3.0 compatibility right ? What > do you care if it's in the public tree or not. Because Aki has been shouting from the rooftops here that "beware, its not that easy, Dovecot crashes with Open

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
I do maintain a few open source projects > and am accustomed to people's expectations to get commercial grade > software...for free. > > Cheers > > On Wednesday, 26/06/2024 at 08:34 Laura Smith via dovecot wrote: > > > You are conflating OS with packages.  I don'

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
ithout premium access. Since that's > what the OS has committed to, unless they pull a redhat and deprecate an OS > before initial EOL date. > > Sent from Outlook for iOS > > From: Laura Smith > Sent: Wednesday, June 26, 2024 2:06:44 PM > To: Lucas Rolff > Cc: Aki Tu

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
ke other operating > systems, should probably be brought up with the Debian release and security > teams. > > Sent from Outlook for iOShttps://aka.ms/o0ukef > > ____ > From: Laura Smith via dovecot dovecot@dovecot.org > > Sent: Wednesday, Ju

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
ught up with the Debian release and security > teams. > > Sent from Outlook for iOS > > From: Laura Smith via dovecot > Sent: Wednesday, June 26, 2024 1:31:48 PM > To: Aki Tuomi > Cc: Laura Smith via dovecot ; Michael > Subject: Re: Debian Bookworm packages, please ! >

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
The fundamental problem here is that this turns into a security problem, which in 2024 is not a nice thing to have. Yes, theoretically I could run the previous Debian release, 11 Bullseye which is now EOL but in LTS until 2026. However, the OpenSSL delivered with Bullseye is 1.1.1. Any LTS pat

Re: Debian Bookworm packages, please !

2024-06-26 Thread Laura Smith via dovecot
> > could you please elaborate on this? are there any security issues with > > using the debian version? what are the problems you are implicating with > > your above statement, that it's 'not fully working either'? > > > > greetings... > > > It can sometimes crash. > > Aki Does Dovecot eve

Re: Debian Bookworm packages, please !

2024-06-25 Thread Laura Smith via dovecot
> > We can already see that the Debian/RedHat patched 2.3 which is offered is > broken because there is more than just "making it compile" with things like > OpenSSL3, and yes, I can appreciate that it's not fully broken, but it's not > fully working either. Yeah, that's sort of what's hold

Re: Debian Bookworm packages, please !

2024-06-25 Thread Laura Smith via dovecot
On Tuesday, 25 June 2024 at 15:06, Aki Tuomi via dovecot wrote: > > On 25/06/2024 16:58 EEST Laura Smith via dovecot dovecot@dovecot.org wrote: > > > > Debian Bookworm (12) was released June 2023. > > > > It is therefore somewhat disappointing to see no B

Debian Bookworm packages, please !

2024-06-25 Thread Laura Smith via dovecot
Debian Bookworm (12) was released June 2023. It is therefore somewhat disappointing to see no Bookworm packages in  https://repo.dovecot.org/ce-2.3-latest/debian/ ___ dovecot mailing list -- dovecot@dovecot.org To unsubscribe send an email to dovecot-le.

Re: How to update upper-bound of tstzrange ?

2024-05-21 Thread Laura Smith
Thanks all for your answers ! Much appreciated. Sent with Proton Mail secure email. On Tuesday, 21 May 2024 at 11:02, Laurenz Albe wrote: > On Mon, 2024-05-20 at 13:56 +0200, Erik Wienhold wrote: > > > On 2024-05-20 12:30 +0200, Laura Smith wrote: > > > > > C

How to update upper-bound of tstzrange ?

2024-05-20 Thread Laura Smith
Could someone kindly help me out with the correct syntax ? My first thought was the below but that doesn't work: update foo set upper(bar_times)=upper(bar_times)+interval '1' hour where bar_id='abc'; ERROR: syntax error at or near "(" LINE 1: update event_sessions set upper(bar_times)=upper(bar

Bug#1030119: release-notes: openssh-server: fills the log with "deprecated reading of user environment enabled"

2024-05-18 Thread Laura Smith
You wanted to "track down an actual reason for this change" ? Try this: CVE-2011-3148 CVE-2011-3149 As summarised by Redhat (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/6.4_technical_notes/pam): If an application's PAM configuration contained user_readenv=1, a

Bug#1030119: release-notes: openssh-server: fills the log with "deprecated reading of user environment enabled"

2024-05-18 Thread Laura Smith
You wanted to "track down an actual reason for this change" ? Try this: CVE-2011-3148 CVE-2011-3149 As summarised by Redhat (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/6.4_technical_notes/pam): If an application's PAM configuration contained user_readenv=1, a

Bug#1018260: openssh-server: fills the log with "deprecated reading of user environment enabled"

2024-05-18 Thread Laura Smith
You wanted to "track down an actual reason for this change" ? Try this: CVE-2011-3148 CVE-2011-3149 As summarised by Redhat (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/6.4_technical_notes/pam): If an application's PAM configuration contained user_readenv=1, a

Bug#1018260: openssh-server: fills the log with "deprecated reading of user environment enabled"

2024-05-18 Thread Laura Smith
You wanted to "track down an actual reason for this change" ? Try this: CVE-2011-3148 CVE-2011-3149 As summarised by Redhat (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/6.4_technical_notes/pam): If an application's PAM configuration contained user_readenv=1, a

[Pdns-users] default-soa-edit and SOA-EDIT-API

2024-05-17 Thread Laura Smith via Pdns-users
Hi Could someone kindly clarify that if I have default-soa-edit set in my conf file, I don't need to worry about SOA-EDIT-API ? The docs for the default-soa-edit setting only metion SOA-EDIT but are silent on SOA-EDIT-API. Thanks Laura ___ Pdns-us

No output on com3 post-install

2024-04-21 Thread Laura Smith
I cannot understand why I am getting no output on com3 post-install of 7.5. I connect to the USB-serial port, and I can see 7.5 boot of USB, and I can go through the install. No problem. During install, I say "yes" to, do you want to default to com3. But after the reboot, I see no output after

Re: [systemd-devel] Unclear as to why "exec" works but "oneshot" does not

2024-04-14 Thread Laura Smith
On Sunday, 14 April 2024 at 15:21, Andrei Borzenkov wrote: > If whatever your script does involves (re-)starting of sshd service, you > have deadlock with "oneshot" - sshd service cannot proceed until your > service startup completes and your service apparently waits on something > that waits

[systemd-devel] Unclear as to why "exec" works but "oneshot" does not

2024-04-14 Thread Laura Smith
I am running a simple service to tweak SSHD on first boot (the script is at the bottom of this mail). This is on Debian Bookworm incase it makes any difference. If I configure my service as: [Unit] Description=ITS Generate SSH Server Keys Wants=ssh.service Before=ssh.service [Service] ExecStart=

Obsolete Linux downloads (Debian) instructions

2024-04-12 Thread Laura Smith
Hi Who do I have to badger to get the obsolete and frankly dangerous Debian repo instructions fixed @ https://www.postgresql.org/download/linux/debian/ ?  The manner proposed is really "not the done thing" in 2024 and it has been explicitly obsoleted by Debian so the project really should not b

UEFI boot dropping to startup.nsh prompt

2024-04-10 Thread Laura Smith via linux-fai
Diese Nachricht wurde eingewickelt um DMARC-kompatibel zu sein. Die eigentliche Nachricht steht dadurch in einem Anhang. This message was wrapped to be DMARC compliant. The actual message text is therefore in an attachment.--- Begin Message --- I'm building a UEFI image for Debian Bookworkm, but w

Re: Adding options for qcow2 output ?

2024-04-09 Thread Laura Smith via linux-fai
raw image > and converts this to qcow2 using > > qemu-img convert -f raw $rawname -O -c -o compression_type=zstd qcow2 > $qcowname > > > > > > > On Tue, 09 Apr 2024 15:14:07 +, Laura Smith via linux-fai > > > > > > linux-fai@uni-koeln.de sa

Adding options for qcow2 output ?

2024-04-09 Thread Laura Smith via linux-fai
Diese Nachricht wurde eingewickelt um DMARC-kompatibel zu sein. Die eigentliche Nachricht steht dadurch in einem Anhang. This message was wrapped to be DMARC compliant. The actual message text is therefore in an attachment.--- Begin Message --- Hi How do I set the "preallocation=off" qcow2 option

Fix the wording on the 7.5 upgrade page

2024-04-05 Thread Laura Smith
Could someone kindly fix the wording on the 7.5 upgrade page. It says "There were several configuration changes and changes in packages that may require planning before starting the upgrade." But the notes say "nothing of note this release", "nothing to remove this release", Thanks!

Re: dmesg hangs 7.4

2024-03-10 Thread Laura Smith
On Sunday, 10 March 2024 at 11:09, Tobias Fiebig wrote: > > Would still give it a try, esp. given that a large text file cat also > shows this MTU-y behavior. ;-) > > Still, I acknowledge that I do have a very MTU-hammer-view of network > things a lot. > > In any case, the issue sounds inte

Re: dmesg hangs 7.4

2024-03-10 Thread Laura Smith
nything special with the network setup? > > Anything odd in dmesg on the box you're ssh'ing from? > > On 2024-03-09, Laura Smith n5d9xq3ti233xiyif...@protonmail.ch wrote: > > > Hi > > > > I've got a fresh install of 7.4 on a new box and am seein

Re: dmesg hangs 7.4

2024-03-09 Thread Laura Smith
ignaled. This only hits as soon as the packets > get a size larger than the MTU, e.g., when typing dmesg (or find /). > > With best regards, > Tobias > > On Sat, 2024-03-09 at 16:07 +, Laura Smith wrote: > > > Hi > > > > I've got a fresh inst

Re: dmesg hangs 7.4

2024-03-09 Thread Laura Smith
Same thing, it hangs : # cat /dev/urandom | openssl enc -base64 -out foo ^C # ls -lah foo 1.5G Mar 9 17:17 foo # cat foo Bunch of text, then hang, then dropped "Timeout, server not responding." Sent with Proton Mail secure email. On Saturday, 9 March 2024 at 16:55, Mihai Popes

dmesg hangs 7.4

2024-03-09 Thread Laura Smith
Hi I've got a fresh install of 7.4 on a new box and am seeing a very weird problem. If I enter "dmesg" I get a few lines of output and then it hangs and my ssh connection gets dropped. I ran syspatch, rebooted and the problem persists. Example: # dmesg MX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PC

Re: array_to_json/array_agg question

2024-02-20 Thread Laura Smith
> You almost got the subrecord ("value_1" and "value_2") right. You need > to use json_build_object() (or even the new json_object() function added > in pg16) instead of row_to_json() to just include "value_1" and > "value_2". Then GROUP BY "key" and aggregate the subrecords with > json_agg(). T

array_to_json/array_agg question

2024-02-20 Thread Laura Smith
Hi Before I go down the road of taking care of this in the front-end through iterations, I thought I would ask the pgsql if there was a clever query I could do on postgres that would take care of it for me instead. In essence, I would like to consolidate values from the same key as a json arra

Re: Function inserting into tstzrange ? (syntax error at or near...)

2024-02-18 Thread Laura Smith
> > There's not bespoke SQL syntax for constructing a range. You must > use a function, something like > > VALUES(p_event_id, tstzrange(p_start_time,p_end_time,'[)')) ... Thanks all for your swift replies. Serves me right for assuming I could use variable substitution where text would norma

Function inserting into tstzrange ? (syntax error at or near...)

2024-02-18 Thread Laura Smith
I'm sure I'm doing something stupid here, but I think I've got the syntax right ? The error I'm seeing: psql:event_session_funcs.sql:26: ERROR:  syntax error at or near "[" LINE 11:         VALUES(p_event_id,[p_start_time,p_end_time)) RETURNI... The function: CREATE OR REPLACE FUNCTION new_even

Re: Scriptable way to validate a pg_dump restore ?

2024-01-29 Thread Laura Smith
On Monday, 29 January 2024 at 09:06, Ron Johnson wrote: > > That's kinda like being asked to prove that rocks always fall when you drop > them. Either you trust physics, because physics has always worked, or you > must watch every rock, because next time it might not fall. The analogy is >

Scriptable way to validate a pg_dump restore ?

2024-01-29 Thread Laura Smith
Hi Let's say I've got a scenario where I'm doing a pg_dump replication rather than online streaming, e.g. due to air-gap or whatever. Is there a scriptable way to validate the restore ?  e.g. using doing something clever with ctid or something to ensure both the schema and all its rows were re

[Pdns-users] Any chance of an actual PowerDNS upgrade guide ?

2024-01-12 Thread Laura Smith via Pdns-users
Hi The release notes for PowerDNS Recursor 5.0.1 link to what is claimed to be an "upgrade guide", however the "guide" reads more like a version change log. Is there any chance we can actually be provided with an actual guide ? For example: I am on Debian, using the PowerDNS repo. Beyond the o

Re: Replicator service in Dovecot 2.4 CE

2023-10-18 Thread Laura Smith via dovecot
> Are you completely removing support for 'replication-with-dsync' starting > from version 2.4? > Are there any plans for built-in tools to implement an active/active or > active/passive cluster in the community edition? kv See the long discussion "the future of SIS" (https://dovecot.org/m

Re: Run PHP on NGINX

2023-10-17 Thread Laura Smith via nginx
--- Original Message --- On Tuesday, October 17th, 2023 at 16:50, Jeff wrote: > Can PHP code be run using NGINX? > > Yes of course. There are surely thousands of how-to's on Google already ? Its not difficult, only about 5 lines in the config file. ___

Re: The future of SIS

2023-10-17 Thread Laura Smith via dovecot
--- Original Message --- On Tuesday, October 17th, 2023 at 15:27, Filip Hanes via dovecot wrote: > Other S3 implementation is Minio on top of any posix filesystem - you can > choose which fills your needs. Minio is great in general, the only thing I would say it its a little bit wei

Re: Slow relink in 7.4

2023-10-17 Thread Laura Smith
--- Original Message --- On Tuesday, October 17th, 2023 at 10:07, David Higgs wrote: > I have an underpowered amd64 VPS and attempted to (auto)upgrade it to 7.4. Just how underpowered is your VPS ? I've got a few underpowered VPS's (1 or 2 vCPU, 512MB RAM) and they went through the

Re: The future of SIS

2023-10-17 Thread Laura Smith via dovecot
--- Original Message --- On Tuesday, October 17th, 2023 at 06:46, Jean-Daniel Dupas wrote: > > If you are using Ubuntu, OpenZFS is readily available, and support > deduplication natively. I thought nobody sane actually used ZFS dedup because it eats RAM for breakfast, lunch and d

RE: The future of SIS

2023-10-16 Thread Laura Smith via dovecot
> Is s3 not to slow for this? > I think the clue is in the name "s3-compatible". Clearly calling out to "real" (AWS) S3 would be a non-starter. But a local installation of something like CEPH, MinIO or whatever on the same LAN ? I'd think that should be workable, no ? ___

RE: The future of SIS

2023-10-16 Thread Laura Smith via dovecot
> > Interesting, nice they use this rust, I am curious how they define this > scaling. What I don't get is why are they messing with smtp. I always get a > bad feeling when a company is trying to do everything. Good they are using rust and even better they've had an independent security audi

Re: The future of SIS

2023-10-16 Thread Laura Smith via dovecot
> > Well, so Laura is absolutely right ... > > > "Things like dsync will be GONE in the community version." > > That's not right, dsync is still there. Replicator is not, so dsync can't be > triggered automatically by dovecot after changes to the mailbox Well, to be fair : 1. I said what I

Re: The future of SIS

2023-10-16 Thread Laura Smith via dovecot
> > If that is the case, well then I have to find another way to keep mails in > sync between 2 mailservers. Hope the community will find a new solution! > I have been keeping one eye on Stalwart (https://stalw.art/) for a while now. I haven't tested it as yet, but I'm very much tempted to g

Re: Low voltage server for bird.

2023-10-15 Thread Laura Smith via Bird-users
2x PSU heavily limits your options.   There are tons of interesting 1x PSU options, but really once you're looking at 2x PSU then you're really looking at a proper 1U server, and so your best bet is to make sure you buy one that has high-efficiency PSUs ("gold" or whatever they call it these da

Re: The future of SIS

2023-10-13 Thread Laura Smith via dovecot
spread FUD that you made up. > > Dsync is not going anywhere, and we are not close-sourcing Dovecot Core. > There is not a trove of code going into Dovecot 3.0 that "never sees the > daylight". > > Thank you, > Aki > > > On 13/10/2023 21:10 EEST Laura Sm

Re: Postgresql HA cluster

2023-10-13 Thread Laura Smith
--- Original Message --- On Friday, October 13th, 2023 at 14:10, Jehan-Guillaume de Rorthais wrote: > But really, double check first why a simple primary-standby architecture > doesn't > meet your needs. The simpler the architecture is, the better. Even from the > application point of

Re: The future of SIS

2023-10-13 Thread Laura Smith via dovecot
TL;DR If you are a Dovecot Community user, don't waste your time reading the Dovecot Pro release notes. To expand: I think you have to understand that lots of things that are going into Dovecot 3 (Pro) will never see the light of day in the community edition. In addition, Dovecot have publicly

Re: ARIN whois contact abuse from ipv4depot aka Silicon Desert International Inc

2023-10-13 Thread Laura Smith via NANOG
--- Original Message --- On Thursday, October 12th, 2023 at 18:59, Niels Bakker wrote: > RIPE have a policy that states Which is exactly what I said Neils. When I asked about it, they pointed me at a policy. Well hell, theoretically my company has a policy that describes zero-tol

Re: OpenBSD 7.4

2023-10-13 Thread Laura Smith
> I usually track the following file. > > https://cvsweb.openbsd.org/src/etc/root/root.mail > Ironically, that file seems to support the earlier statement made by Peter Hansteen that he got shot down for (i.e. "The exact date will not be generally known until it happens if recent releases a

Re: ARIN whois contact abuse from ipv4depot aka Silicon Desert International Inc

2023-10-12 Thread Laura Smith via NANOG
Honestly Mike I don't think they care. I mean, most (all ?) of the registries still can't be bothered to validate the information the resource holders post to the database.  Last time I asked, e.g. RIPE about it, they basically said "not my problem guv" , pointed me to some policy document that

  1   2   3   4   5   >