Re: [CentOS] how to set a directory to system_u?

2021-10-03 Thread hw
On Sat, 2021-10-02 at 15:12 +0200, Markus Falb wrote: > > > On 02.10.2021, at 13:49, hw wrote: > > > > > > I'm trying to a lable a directory for ejabberd to store files > > that were uploaded with the http_upload module

[CentOS] how to set a directory to system_u?

2021-10-02 Thread hw
Hi, I'm trying to a lable a directory for ejabberd to store files that were uploaded with the http_upload module. Apparently I should set this to 'system_u:object_r:ejabberd_var_lib_t:s0' since all the files in /var/lib/ejabberd are. So: ls -laZ /srv/data/ unconfined_u:object_r:ejabberd_var_

[CentOS] kvm/qemu: USB passthrough

2021-10-01 Thread hw
Hi, I'm trying to pass an USB port (or hub) to a kvm/qemu guest, to no avail. To find out which physical port I can use, I plugged a device into the port, and dmesg on the host says: usb 3-3: new high-speed USB device number 10 using xhci_hcd Which device on the host is that? lspci | grep -i u

Re: [CentOS] how to display/create DUID?

2021-09-30 Thread hw
On Thursday, September 30, 2021 2:31:48 AM CEST Kenneth Porter wrote: > --On Wednesday, September 29, 2021 11:59 PM +0200 hw wrote: > > Is that my lack of understanding or are these DUIDs really a rather > > stupid idea? > > > > And how are we actually supposed t

Re: [CentOS] how to display/create DUID?

2021-09-29 Thread hw
On Wednesday, September 29, 2021 10:22:27 PM CEST hw wrote: > On Sunday, September 19, 2021 6:53:45 PM CEST Kenneth Porter wrote: > > --On Sunday, September 19, 2021 3:02 PM +0200 hw wrote: > > > None of this is working because the server isn't running a DHCPv6 > > &g

Re: [CentOS] how to display/create DUID?

2021-09-29 Thread hw
On Sunday, September 19, 2021 6:53:45 PM CEST Kenneth Porter wrote: > --On Sunday, September 19, 2021 3:02 PM +0200 hw wrote: > > None of this is working because the server isn't running a DHCPv6 server, > > and there seems to be no file in /var/lib/NetworkManager that

Re: [CentOS] how to display/create DUID?

2021-09-19 Thread hw
On 9/19/21 09:06, Kenneth Porter wrote: --On Sunday, September 19, 2021 2:10 AM +0200 hw wrote: So how/where do find I this DUID on my server? <https://redhatlinux.guru/2019/07/01/find-duid-on-rhel-and-centos-servers/> <https://askubuntu.com/questions/712159/how-can-i-find-out-m

[CentOS] how to display/create DUID?

2021-09-18 Thread hw
Hi, I would like to assign an ipv6 address through the DHCPv6 server of pfsense. To configure a static address, I need to tell the DHCPv6 server a DUID. Apparently DUIDs belong to a particular machine and aren't supposed to ever change unless you re-install the operating system. I guess

[CentOS] How to keep audio active?

2021-09-13 Thread hw
Hi, how can I keep audio active --- or at least make it come back right away --- after there was no audio for a few seconds? It takes some seconds for the audio to come back, like when a movie was paused and playback is being resumed. I either have to scroll back or miss out on the audio,

Re: [CentOS] What to do when a selinux policy doesn't work?

2021-04-14 Thread hw
PS: Yes, it finally works, I just saw it in the log file :) On 4/14/21 9:00 AM, hw wrote: On 2/27/21 3:40 AM, Jonathan Billings wrote: On Feb 26, 2021, at 17:16, hw wrote: Ejabberd is supposed to expire files when they are older than desired, and selinux prevents it.  How can I solve this

Re: [CentOS] How to find out what's eating the bandwidth

2021-04-14 Thread hw
On 3/28/21 7:36 PM, Frank Cox wrote: On Sun, 28 Mar 2021 13:14:16 -0400 Matthew Miller wrote: Is this a home network or a business one? It's a really basic setup "routers from Staples" (dlink and tplink brands I think) plugged into the ISP's modems. You're right that you generally can't se

Re: [CentOS] What to do when a selinux policy doesn't work?

2021-04-14 Thread hw
On 2/27/21 3:40 AM, Jonathan Billings wrote: On Feb 26, 2021, at 17:16, hw wrote: Ejabberd is supposed to expire files when they are older than desired, and selinux prevents it. How can I solve this problem other than by disabling selinux or by deleting the files manually? It’s possible

[CentOS] What to do when a selinux policy doesn't work?

2021-02-26 Thread hw
Hi, I'm getting log file entries about ejabberd not being able to remove files that were uploaded by client through the file upload facility of XMPP. With the help of audit2allow, I have already created and installed some selinux modules to solve such issues, and still files can't be expir

Re: [CentOS] Intel RST RAID 1, partition tables and UUIDs

2020-11-18 Thread hw
On Tue, 2020-11-17 at 08:01 -0600, Valeri Galtsev wrote: > > > On Nov 17, 2020, at 1:07 AM, hw wrote: > [...] > > If you don't require Centos, you could go for Fedora instead. Fedora has > > btrfs > > as default file system now which has software raid

Re: [CentOS] Intel RST RAID 1, partition tables and UUIDs

2020-11-16 Thread hw
On Mon, 2020-11-16 at 18:06 -0500, H wrote: > On 11/16/2020 01:23 PM, Jonathan Billings wrote: > > On Sun, Nov 15, 2020 at 07:49:09PM -0500, H wrote: > > > I have been having some problems with hardware RAID 1 on the > > > motherboard that I am running CentOS 7 on. After a BIOS upgrade of > > > the

Re: [CentOS] Apologies - possible hardware problem?

2020-11-16 Thread hw
On Mon, 2020-11-16 at 09:58 +0100, hw wrote: > > [...] > Put a minimal amount of RAM in and go through all of the modules to see if > one or some of them are broken. Replace all RAM or test it in another computer. > Replace the power supply. Replace CPU or test it in an

Re: [CentOS] Apologies - possible hardware problem?

2020-11-16 Thread hw
On Sun, 2020-11-15 at 18:54 +, Jeffrey Layton wrote: > Good afternoon, > > I have a home workstation with an AMD CPU, Titan V GPU, 32 GB of memory, > and a root SSD and /home on spinning disks. > > Right now it has xubuntu 18.04 on it and it would boot fine. I shut it down > and restarted it

Re: [CentOS] mdadm raid-check

2020-11-16 Thread hw
On Sat, 2020-11-14 at 21:55 -0600, Valeri Galtsev wrote: > > On Nov 14, 2020, at 8:20 PM, hw wrote: > > > > > > Hi, > > > > is it required to run /usr/sbin/raid-check once per week? Centos 7 does > > this. Maybe it's sufficient to run it monthly

Re: [CentOS] ssacli start rebuild?

2020-11-14 Thread hw
On Sat, 2020-11-14 at 14:37 -0700, Warren Young wrote: > On Nov 14, 2020, at 5:56 AM, hw wrote: > > On Wed, 2020-11-11 at 16:38 -0700, Warren Young wrote: > > > On Nov 11, 2020, at 2:01 PM, hw wrote: > > > > I have yet to see software RAID that doesn't kill the

Re: [CentOS] ssacli start rebuild?

2020-11-14 Thread hw
On Sat, 2020-11-14 at 18:55 +0100, Simon Matter wrote: > > On Wed, 2020-11-11 at 16:38 -0700, Warren Young wrote: > > > On Nov 11, 2020, at 2:01 PM, hw wrote: > > > > I have yet to see software RAID that doesn't kill the performance. > > > > > >

Re: [CentOS] ssacli start rebuild?

2020-11-14 Thread hw
On Sat, 2020-11-14 at 07:11 -0800, John Pierce wrote: > On Sat, Nov 14, 2020, 4:57 AM hw wrote: > > > On Wed, 2020-11-11 at 16:38 -0700, Warren Young wrote: > > > > > > And where > > > > do you get cost-efficient cards that can do JBOD? > > >

[CentOS] mdadm raid-check

2020-11-14 Thread hw
Hi, is it required to run /usr/sbin/raid-check once per week? Centos 7 does this. Maybe it's sufficient to run it monthly? IIRC Debian did it monthly. I just checked on Fedora 32. It does not run raid-check at all, at least not via a cron entry. /usr/sbin/raid-check is available, though.

Re: [CentOS] ssacli start rebuild?

2020-11-14 Thread hw
On Wed, 2020-11-11 at 16:38 -0700, Warren Young wrote: > On Nov 11, 2020, at 2:01 PM, hw wrote: > > I have yet to see software RAID that doesn't kill the performance. > > When was the last time you tried it? I'm currently using it, and the performance sucks. Perh

Re: [CentOS] ssacli start rebuild?

2020-11-11 Thread hw
On Wed, 2020-11-11 at 11:34 +0100, Thomas Bendler wrote: > Am Mi., 11. Nov. 2020 um 07:28 Uhr schrieb hw : > > > [...] > > With this experience, these controllers are now deprecated. RAID > > controllers > > that can't rebuild an array after a disk has f

Re: [CentOS] ssacli start rebuild?

2020-11-10 Thread hw
On Mon, 2020-11-09 at 16:30 +0100, Thomas Bendler wrote: > Am Fr., 6. Nov. 2020 um 20:38 Uhr schrieb hw : > > > [...] > > Some search results indicate that it's possible that other disks in the > > array have read errors and might prevent rebuilding for RAID 5. I don

Re: [CentOS] ssacli start rebuild?

2020-11-06 Thread hw
On Fri, 2020-11-06 at 12:08 +0100, Thomas Bendler wrote: > Am Fr., 6. Nov. 2020 um 00:52 Uhr schrieb hw : > > > [...] > > logicaldrive 1 (14.55 TB, RAID 1+0, Ready for Rebuild) > > [...] > > Have you checked the rebuild priority: > > ❯ ssacli ctrl slot=

[CentOS] ssacli start rebuild?

2020-11-05 Thread hw
Hi, is there a way to rebuild an array using ssacli with a P410? A failed disk has been replaced and now the array is not rebuilding like it should: Array A (SATA, Unused Space: 1 MB) logicaldrive 1 (14.55 TB, RAID 1+0, Ready for Rebuild) physicaldrive 1I:0:1 (port 1I:box 0:

[CentOS] how to enforce audio device precence?

2020-10-05 Thread hw
Hi, how can I make it so that audio continues to go the monitor connected to the display port when another monitor gets connected to the HDMI port? ___ CentOS mailing list CentOS@centos.org https://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] looking for ideas about how to create a constant data stream

2020-05-30 Thread hw
On Saturday, May 30, 2020 12:46:02 PM CEST you wrote: > On 30/05/2020 12:32, h...@gc-24.de wrote: > > Hi hw, > > > I'm looking for a good way to create a constant data stream that will > > occupy a bandwidth of about 2--5Mbit/sec between two remote hosts over &

[CentOS] looking for ideas about how to create a constant data stream

2020-05-30 Thread hw
Hi, I'm looking for a good way to create a constant data stream that will occupy a bandwidth of about 2--5Mbit/sec between two remote hosts over the internet. I have full access to the hosts involved. My first attempt to use scp to copy data from /dev/null on host A to /dev/null on host B, bu

Re: [CentOS] LibreOffice locking up

2020-05-25 Thread hw
On Sun, 2020-05-24 at 19:56 -0400, H wrote: > I am running LibreOffice 5.3.6.1 under the latest update of CentOS 7 and > the Mate desktop. Not infrequently LibreOffice Calc locks up and I have > to force close the application. Altough the spreadsheet is rather large I > would not consider it comple

Re: [CentOS] LibreOffice locking up

2020-05-25 Thread hw
On Sun, 2020-05-24 at 19:56 -0400, H wrote: > I am running LibreOffice 5.3.6.1 under the latest update of CentOS 7 and > the Mate desktop. Not infrequently LibreOffice Calc locks up and I have > to force close the application. Altough the spreadsheet is rather large I > would not consider it comple

Re: [CentOS] how does autofs deal with stuck NFS mounts and suspending to RAM?

2020-05-20 Thread hw
On Tuesday, May 19, 2020 2:22:48 PM CEST Jonathan Billings wrote: > On Mon, May 18, 2020 at 05:36:03PM -0600, Warren Young wrote: > > On May 18, 2020, at 5:13 AM, hw wrote: > > > Is there a better alternative for mounting remote file systems > > > over unreliable &g

Re: [CentOS] how does autofs deal with stuck NFS mounts and suspending to RAM?

2020-05-20 Thread hw
On Tuesday, May 19, 2020 12:28:59 PM CEST isdtor wrote: > > That's what I thought. Should I make a bug report? Sshfs is clearly > > intended to reconnect automatically when mounted like that, and it > > doesn't do that. > Not so clearly. Look at the sshfs reconnect option, and also ssh/ssfs > Ser

Re: [CentOS] how does autofs deal with stuck NFS mounts and suspending to RAM?

2020-05-19 Thread hw
On Tuesday, May 19, 2020 1:36:03 AM CEST Warren Young wrote: > On May 18, 2020, at 5:13 AM, hw wrote: > > Is there a better alternative for mounting remote file systems over > > unreliable connections? > > I don’t have a good answer for you, because if you’d asked me without

[CentOS] how does autofs deal with stuck NFS mounts and suspending to RAM?

2020-05-18 Thread hw
Hi, after trying sshfs to mount a remote file system on a server with the result that sshfs will sooner or later get stuck and require a reboot of the client, I'm fed up with it and am looking for alternatives. So next I would like to use NFS over a VPN connection instead. To minimize the ins

[CentOS] Centos 7: cups-pdf Postprocessing prevented by selinux :(

2020-04-14 Thread hw
Hi, how can I make it so that printing to a cups PDF printer can successfully run the postprocessing script I specified in /etc/cups/cups-pdf.conf? It does work with 'sentenforce permissve', and after creating and installing some selinux modules from audit.log entries, it still doesn't work, an

Re: [CentOS] Switching from lokkit (iptables) to firewalld

2020-02-04 Thread hw
On Tuesday, February 4, 2020 4:13:50 PM CET Stephen John Smoogen wrote: > On Tue, 4 Feb 2020 at 05:37, Pete Biggs wrote: > > On Mon, 2020-02-03 at 19:04 -0500, Jerry Geis wrote: > > > Hi All, > > > > > > Over the last 20 some years I have a file with about 200K worth of > > > > address > > > >

[CentOS] Centos 7: setting DSCP values on bonding interfaces?

2020-02-01 Thread hw
Hi, is it possible to set DSCP values on bonding interfaces? Packets from asterisk do not have their DSCP values set, so apparently it is not setting them despite it is set up for it, and it seems to be using libcap so it should be able to set them. I can see packets from phones having such v

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-30 Thread hw
On Thursday, January 30, 2020 2:01:28 AM CET Nataraj wrote: > On 1/29/20 3:26 PM, hw wrote: > > On Wednesday, January 29, 2020 6:52:50 PM CET Nataraj wrote: > > [...] > > > >> By burst, I mean that you don't have a bandwidth commitment with an SLA > >>

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-29 Thread hw
On Wednesday, January 29, 2020 6:52:50 PM CET Nataraj wrote: [...] > By burst, I mean that you don't have a bandwidth commitment with an SLA > from your provider. A bandwidth commitment means that you are paying a > provider to guarantee you so many MB or GB of bandwidth and this is > guaranteed t

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-29 Thread hw
On Wednesday, January 29, 2020 8:53:50 AM CET Simon Matter via CentOS wrote: > > On Tuesday, January 28, 2020 1:50:57 PM CET Stephen John Smoogen wrote: > >> On Sun, 26 Jan 2020 at 20:45, hw wrote: > >> > > I'm not sure I understand what you are asking. > &

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-29 Thread hw
On Wednesday, January 29, 2020 12:38:32 AM CET Stephen John Smoogen wrote: > On Tue, 28 Jan 2020 at 15:56, hw wrote: > > > For voice, that > > > usually means a drop or other ugliness because it is assumed that if > > > the quality is too bad, the people wo

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-29 Thread hw
On Wednesday, January 29, 2020 10:10:48 AM CET Nataraj wrote: > On 1/28/20 12:39 PM, hw wrote: > > On Tuesday, January 28, 2020 9:00:22 AM CET Nataraj wrote: > >> On 1/26/20 5:44 PM, hw wrote: > >>> On Sunday, January 26, 2020 11:18:36 PM CET Pete Biggs wrote: &g

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-28 Thread hw
On Tuesday, January 28, 2020 1:50:57 PM CET Stephen John Smoogen wrote: > On Sun, 26 Jan 2020 at 20:45, hw wrote: > > > I'm not sure I understand what you are asking. > > > > It is about VOIP calls via SRTP being interrupted at irregular intervals. > > The int

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-28 Thread hw
On Tuesday, January 28, 2020 9:00:22 AM CET Nataraj wrote: > On 1/26/20 5:44 PM, hw wrote: > > On Sunday, January 26, 2020 11:18:36 PM CET Pete Biggs wrote: > >> First of all - disclaimer - I'm no network specialist, I just read and > >> am intereste

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-26 Thread hw
On Sunday, January 26, 2020 11:18:36 PM CET Pete Biggs wrote: > First of all - disclaimer - I'm no network specialist, I just read and > am interested in it. I may get things wrong!! > > > Both physical interfaces show the same. But does this mean it's on as in > > "rx- checksumming: on" or off

Re: [CentOS] Centos 7: UPD packet checksum verification?

2020-01-26 Thread hw
On Sunday, January 26, 2020 3:58:31 PM CET Pete Biggs wrote: > > what does Centos 7 do with UPD packets having invalid checksums? > > By default I assume they are just dropped - that's what should happen. Hm that's what thought. > > Are such packets inevitably dropped? > > Applications can spec

[CentOS] Centos 7: UPD packet checksum verification?

2020-01-26 Thread hw
Hi, what does Centos 7 do with UPD packets having invalid checksums? Are such packets inevitably dropped? Does a network card drop them when it does checksum verification in hardware even before the packets go anywhere? In general, if someone were to send me UPD packets with invalid checksums

Re: [CentOS] Replacing sendmail with postfix

2019-09-23 Thread hw
On Saturday, September 21, 2019 3:14:12 PM CEST MAILIST wrote: > exim should also be considered. We have been using exim with CentOS > for at least 10 years. Right. I've been using exim for over 20 years and haven't had any issues with it. Exims documentation is outstanding and the mailing lis

Re: [CentOS] Increase logging verbosity of saslauthd?

2019-09-11 Thread hw
On Wednesday, 11 September 2019 05:34:27 CEST Jobst Schmalenbach wrote: > Hi > > CentOS 7.X, sendmail.x86_64 8.14.7-5.el7, cyrus-sasl.x86_64 2.1.26-23.el7 > > There are conflicting message on how to increase the logging of saslauthd. > > I know I can do this: >/usr/sbin/saslauthd -d -n0 -m /

Re: [CentOS] NFS Server on Centos 7.6.1810 dying without reason

2019-09-07 Thread hw
On Fri, 30 Aug 2019 16:25:40 -0500 Erick Perez - Quadrian Enterprises wrote: > I managed to get NFS statistics just before server rebooted. > I can reproduce this every time. > Question: Am I saturating the SATA bus on the NFS server so violently > with the SSDs that the server hard reboots? > Pe

Re: [CentOS] CUPS job handling

2019-09-06 Thread hw
On Sun, 1 Sep 2019 11:04:02 -0600 Frank Cox wrote: > On Sun, 1 Sep 2019 14:19:58 +0200 > hw wrote: > > > Yet if a printer doesn't print anymore, it is desirable to divert jobs > > to another printer, preferably a designated fallback. It is of no use > > when

Re: [CentOS] CUPS job handling

2019-09-01 Thread hw
On Thu, 22 Aug 2019 11:48:37 -0500 (CDT) Michael Hennebry wrote: > On Tue, 20 Aug 2019, hw wrote: > > > is it somehow possible to make CUPS automatically redirect jobs, and > > following jobs, away from printers which can not print them to other > > printers that

[CentOS] CUPS job handling

2019-08-20 Thread hw
Hi, is it somehow possible to make CUPS automatically redirect jobs, and following jobs, away from printers which can not print them to other printers that can print them until the printers that couldn't print them are again able to print them? Like I have a bunch of label printers which are all

Re: [CentOS] virsh: howto convert storage type of VMs?

2019-08-01 Thread hw
On 8/1/19 10:19 PM, Jon Pruente wrote: On Thu, Aug 1, 2019 at 2:50 PM hw wrote: Hi, how can I convert the storage type of VMs from being stored in individual qcow2 files to being stored in a storage pool? The VMs may be shut down during the conversion. qemu-img convert -O {output_type

[CentOS] virsh: howto convert storage type of VMs?

2019-08-01 Thread hw
Hi, how can I convert the storage type of VMs from being stored in individual qcow2 files to being stored in a storage pool? The VMs may be shut down during the conversion. ___ CentOS mailing list CentOS@centos.org https://lists.centos.org/mailman/

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 7:10 PM, Nataraj wrote: [...] I meant to say: Configure all dns servers as secondary/slaves (one should be the primary master) for your own domains. Thos means that all of your servers are authoritative for your own domains, so they cannot fail on local dns lookups due to Interne

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 9:39 PM, John Pierce wrote: On Thu, Jul 25, 2019 at 10:32 AM hw wrote: I can't help it when the primary name server goes down because the UPS fails the self test and tells the server it has 2 minutes or so left in wich case the server figures it needs to shut down. I wanted b

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 9:11 PM, mark wrote: hw wrote: On 7/25/19 4:07 PM, Giles Coochey wrote: Sounds like you're performing maintenance on your servers (a) too often (b) during office / peak hours I can't help it when the primary name server goes down because the UPS fails the self test

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 7:58 PM, Paul Heinlein wrote: On Thu, 25 Jul 2019, hw wrote: On 7/25/19 3:28 PM, Leroy Tennison wrote: If you don't want multiple DNS server entries on the client I'm ok with them, only the problem is that the clients take their timeouts when a server is unreachable,

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 5:14 PM, Nataraj wrote: On 7/25/19 6:48 AM, rai...@ultra-secure.de wrote: Am 2019-07-25 15:41, schrieb hw: On 7/25/19 2:53 PM, rai...@ultra-secure.de wrote: Am 2019-07-25 14:51, schrieb hw: Hi, how can DNS reliability, as experienced by clients on the LAN who are sending queries

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 4:07 PM, Giles Coochey wrote: > > On 25/07/2019 13:51, hw wrote: >> Hi, >> >> how can DNS reliability, as experienced by clients on the LAN who are >> sending queries, be increased? >> >> Would I have to set up some sort of cluster consisti

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 4:49 PM, Nux! wrote: > I'm about to do an overhaul of the DNS service at work and my plan is to use > powerdns recursor + dnsdist + keepalived. I've more or less done the overhaul, only some sort of failover thing is missing ... I'll check those out, thanks! __

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 3:28 PM, Leroy Tennison wrote: > If you don't want multiple DNS server entries on the client I'm ok with them, only the problem is that the clients take their timeouts when a server is unreachable, and users panic. > then a master and (possibly multiple) slave server configuration can

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 3:48 PM, rai...@ultra-secure.de wrote: > Am 2019-07-25 15:41, schrieb hw: >> On 7/25/19 2:53 PM, rai...@ultra-secure.de wrote: >>> Am 2019-07-25 14:51, schrieb hw: >>>> Hi, >>>> >>>> how can DNS reliability, as experienced by clients

Re: [CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
On 7/25/19 2:53 PM, rai...@ultra-secure.de wrote: > Am 2019-07-25 14:51, schrieb hw: >> Hi, >> >> how can DNS reliability, as experienced by clients on the LAN who are >> sending queries, be increased? >> >> Would I have to set up some sort of cluster consist

Re: [CentOS] CentOS 8 partiitioning for reliability

2019-07-25 Thread hw
On 7/19/19 11:57 PM, Kenneth Porter wrote: > I was just given a Dell R720xd with 160 GB memory and 12x 900 GB drives that > I plan to deploy as my home mail/file/backup server to replace an aging > Supermicro server running CentOS 7. Yeah, it's gross overkill for that and I > expect to tuck most

[CentOS] how to increase DNS reliability?

2019-07-25 Thread hw
Hi, how can DNS reliability, as experienced by clients on the LAN who are sending queries, be increased? Would I have to set up some sort of cluster consisting of several servers all providing DNS services which is reachable under a single IP address known to the clients? Just setting up sever

[CentOS] some questions about tuned ...

2019-07-19 Thread hw
Hi, what is the point of running tuned as a daemon when dynamic tuning is disabled? What is the point of enabling dynamic tuning, especially when using the supplied profiles like throughput-performance? I haven't customized those by specifying any thresholds, and I don't see any point i

Re: [CentOS] SELinux settings for directory shared via NFS and samba?

2019-07-19 Thread hw
On 7/19/19 3:43 PM, Monty Shinn wrote: On Jul 19, 2019, at 8:27 AM, Leon Fauster via CentOS wrote: Am 19.07.2019 um 14:51 schrieb hw : Hi, what do I need to do to share the same directory with both NFS and samba? SElinux requires 'samba_share_t' for samba and 'nfs_t'

[CentOS] SELinux settings for directory shared via NFS and samba?

2019-07-19 Thread hw
Hi, what do I need to do to share the same directory with both NFS and samba? SElinux requires 'samba_share_t' for samba and 'nfs_t' for NFS, and AFAIC I can't set both at the same time on a directory. ___ CentOS mailing list CentOS@centos.org https://

[CentOS] exim PAM authentication: all users unknown

2018-03-22 Thread hw
Hi, how come that exim can not authenticate users using PAM? == PLAIN: driver = plaintext server_set_id = $auth2 server_prompts = : server_condition = ${if pam{$auth2:$auth3}{yes}{no}} server_advertise_condition =

Re: [CentOS] selinux: how to allow access?

2018-03-20 Thread hw
On 03/20/2018 01:42 PM, Peter Kjellström wrote: On Tue, 20 Mar 2018 13:07:12 +0100 hw wrote: ... So what do you really gain from selinux, and is that worthwhile all the trouble and the hours spent to fix the problems it creates? What about the impact on performance? The main feature is

Re: [CentOS] selinux: how to allow access?

2018-03-20 Thread hw
On 03/16/2018 10:38 PM, Phil Perry wrote: On 16/03/18 18:37, Alexander Dalloz wrote: Am 16.03.2018 um 13:09 schrieb hw: On 03/16/2018 12:14 PM, Richard Grainger wrote: Yet again I could not find any documentation explaining how to do basic things like this :(  Selinux is more like a curse

Re: [CentOS] cyrus: socket options

2018-03-17 Thread hw
On 03/16/2018 10:21 PM, Alexander Dalloz wrote: Am 16.03.2018 um 13:07 schrieb hw: [...]    # lmtp    cmd="lmtpd -a" listen="lmtp:127.0.0.1" prefork=4    lmtpunix  cmd="lmtpd -a" listen="/var/lib/imap/socket/lmtp" prefork=4 [...] Both

Re: [CentOS] cyrus: socket options

2018-03-17 Thread hw
On 03/16/2018 08:14 PM, Alexander Dalloz wrote: Am 16.03.2018 um 13:07 schrieb hw: Hi, what are the following messages supposed to tell me and does this indicate a problem? # systemctl status cyrus-imapd [...] master[3766]: unable to setsocketopt(IP_TOS): Operation not supported master

Re: [CentOS] selinux: how to allow access?

2018-03-16 Thread hw
On 03/16/2018 12:14 PM, Richard Grainger wrote: Yet again I could not find any documentation explaining how to do basic things like this :( Selinux is more like a curse than anything else :( Why is there not even a good documentation? More trolling? Show me a good documentation and/or name g

[CentOS] cyrus: socket options

2018-03-16 Thread hw
Hi, what are the following messages supposed to tell me and does this indicate a problem? # systemctl status cyrus-imapd [...] master[3766]: unable to setsocketopt(IP_TOS): Operation not supported master[3766]: unable to setsocketopt(IP_TOS): Operation not supported [...] Exim says it can

[CentOS] selinux: how to allow access?

2018-03-16 Thread hw
Hi, how do I allow exim access to a socket in order to be able to do local deliveries to cyrus? type=AVC msg=audit(1521179280.845:1920270): avc: denied { name_connect } for pid=319 comm="exim" dest=24 scontext=system_u:system_r:exim_t:s0 tcontext=system_u:object_r:lmtp_port_t:s0 tclass=

Re: [CentOS] RADIUS

2018-03-09 Thread hw
Steven Tardy wrote: On Wed, Mar 7, 2018 at 11:57 AM hw wrote: Apparently Cisco can do it: https://www.cisco.com/c/en/us/products/collateral/wireless/wireless-location-appliance/product_data_sheet0900aecd80293728.html I was going to mention Cisco WCS which uses wireless “controllers” and

Re: [CentOS] Squid and HTTPS interception on CentOS 7 ?

2018-03-08 Thread hw
Nicolas Kovacs wrote: Le 08/03/2018 à 11:30, hw a écrit : The government says you must use squidguard to filter something? The law in France (Code Pénal, article 227-24) states that a public network is not allowed to broadcast messages containing violence, pornography or any content contrary

Re: [CentOS] Squid and HTTPS interception on CentOS 7 ?

2018-03-08 Thread hw
Nicolas Kovacs wrote: Le 06/03/2018 à 18:48, hw a écrit : And how do you get a list of IPs from which data could be retrieved which the students are not supposed to see? How is this done anyway, does the government give out a list of URLs or IPs which you are required to block?  If not, what

Re: [CentOS] RADIUS

2018-03-07 Thread hw
Gordon Messmer wrote: On 03/01/2018 03:06 AM, hw wrote: It is illogical to lump all network access together into a single category. ... If your device can communicate with a switch, even for the purpose of authenticating, then it has network access. The device has access to the switch

Re: [CentOS] RADIUS

2018-03-07 Thread hw
Gordon Messmer wrote: On 03/01/2018 09:26 AM, hw wrote: I was asking for documentation telling me how RADIUS can be used, not only that it can be used. RADIUS is a backend component of 802.1x and WPA2 Enterprise.  You appear to be looking for information on how to use those two.  If you look

Re: [CentOS] RADIUS

2018-03-07 Thread hw
Pete Biggs wrote: What do you want? I was asking for documentation telling me how RADIUS can be used, not only that it can be used. RADIUS is just an authentication (plus a bit more) protocol - what you are asking is like asking how LDAP can be used. Usually it's treated like a magic black

Re: [CentOS] RADIUS

2018-03-07 Thread hw
Pete Biggs wrote: That´s not my problem to solve, but think about it: You can get a lot more information using CCTV cameras, and those are everywhere. Unfortunately, nobody cares, and it´s not like you have a choice. So why would there be any legal issues? It's called "A Law". Different pl

Re: [CentOS] RADIUS

2018-03-07 Thread hw
Stephen John Smoogen wrote: On 2 March 2018 at 12:07, hw wrote: Oh yeah. Who ever gave you those marching orders needs to talk with all kinds of lawyers... even researching for it might be problematic in some countries due to a multitude of laws. You are walking out of setting up a wireless

Re: [CentOS] Squid and HTTPS interception on CentOS 7 ?

2018-03-06 Thread hw
Valeri Galtsev wrote: On 03/05/18 08:34, Bill Gee wrote: On Monday, March 5, 2018 7:23:53 AM CST Leon Fauster wrote: Am 05.03.2018 um 13:04 schrieb Nicolas Kovacs : Le 28/02/2018 à 22:23, Nicolas Kovacs a écrit : So far, I've only been able to filter HTTP. Do any of you do transparent HTT

Re: [CentOS] Squid and HTTPS interception on CentOS 7 ?

2018-03-06 Thread hw
Leon Fauster wrote: Am 05.03.2018 um 13:04 schrieb Nicolas Kovacs : Le 28/02/2018 à 22:23, Nicolas Kovacs a écrit : So far, I've only been able to filter HTTP. Do any of you do transparent HTTPS filtering ? Any suggestions, advice, caveats, do's and don'ts ? After a week of trial and error,

Re: [CentOS] evince

2018-03-06 Thread hw
ken wrote: On 03/03/2018 11:31 AM, hw wrote: Is there better source to look for answers than these two: What kind of answers are you looking for? Perhaps installing a missing font solves the problem with evince. You could try mupdf, xpdf and qpdfview to see if one of them can display the

Re: [CentOS] evince

2018-03-03 Thread hw
Chris Olson wrote: We have some small networks with connectivity to the Internet through firewall routers.  The smallest has one Windows 7 system and three Linux systems including both CentOS 6 and CentOS 7 machines.  The Windows 7 systems have full Adobe packages that are updated regularly and a

Re: [CentOS] RADIUS

2018-03-02 Thread hw
Stephen John Smoogen wrote: On 1 March 2018 at 12:26, hw wrote: Stephen John Smoogen wrote: On 1 March 2018 at 08:42, hw wrote: I didn´t say I want that, and I don´t know yet what I want. A captive portal may be nice, but I haven´t found a way to set one up yet, and I don´t have an

Re: [CentOS] RADIUS

2018-03-01 Thread hw
Stephen John Smoogen wrote: On 1 March 2018 at 08:42, hw wrote: I didn´t say I want that, and I don´t know yet what I want. A captive portal may be nice, but I haven´t found a way to set one up yet, and I don´t have an access point controller which would provide one, so I can´t tell if that

Re: [CentOS] RADIUS

2018-03-01 Thread hw
John Hodrien wrote: This is really nothing to do with CentOS anymore, if it ever was. right On Thu, 1 Mar 2018, hw wrote: If PXE boot is not possible because it would require to allow network access to unauthorized devices, or if it is not reasonably feasible because switching the device

Re: [CentOS] RADIUS

2018-03-01 Thread hw
Gordon Messmer wrote: On 02/27/2018 08:21 AM, hw wrote: Gordon Messmer wrote: I've never seen anyone actually do this, but there's an article discussing it.  It is noteworthy that this requires enforcement in the client OS, as well as the switch. The article itself says that

Re: [CentOS] pid_max

2018-03-01 Thread hw
Jerry Geis wrote: I have two systems both running CentOS 7.4 one shows pid_max as 32768 the other shows pid_max as 49152 Why might that be ? I would have thought they would be the same. I have not changed them. Where does it come from, tuned profiles? _

Re: [CentOS] RADIUS

2018-02-27 Thread hw
Gordon Messmer wrote: On 02/23/2018 03:22 AM, hw wrote: I´m not sure how to imagine it.  It would be nice if every device connecting to the network, wirelessly or otherwise, had to be authenticated --- and not only the device, but also the user(s) using it. https://www.networkworld.com

Re: [CentOS] RADIUS

2018-02-23 Thread hw
Pete Biggs wrote: A prerequisite for PXE is DHCP - by the time your device does anything with PXE it's already accessed the network and got an IP address and so on. There is absolutely no way to prohibit access to your network without first allowing the device some access to your network in o

Re: [CentOS] RADIUS

2018-02-23 Thread hw
Pete Biggs wrote: Yes, I do it frequently with my phone. You do it once and it remembers it. My phone is more often on wifi than on 4G when I'm in a town. And you need to install certificates or enter a password or something? Yes. Just once, then things are remembered and you can seemlessly

  1   2   3   >