Re: [CentOS] One approach to dealing with SSH brute force attacks.

2008-02-04 Thread John Horne
e use swatch for general log monitoring, and have it report back anything unusual to our central monitoring system (Big Brother). John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)175

Re: [CentOS] mdadm exim mysql

2007-10-19 Thread John Horne
has been built such that mysql is required - although Exim can use CDB, DB4, postgresql (I think) and so on. John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)1752 233914 E-mail: [EMAIL PROTECTED] Fax: +44 (0)1752

[CentOS] How can I set NIC duplex before installation?

2007-06-25 Thread John Horne
nstall which has 2 x gigabit NICs and 2 x 100MB NIC's. My concern is that anaconda will again use wrong NIC parameters, and the installation will again be very slow. Surely it is possible to set the NIC options? John. -- -------

Re: [CentOS] How can I set NIC duplex before installation?

2007-06-25 Thread John Horne
0_ethtool="autoneg=off speed=100 duplex=full" > Okay, that seems easy enough :-) Thanks. However, is the anaconda NIC ordering the same as those listed by the bios? For a mixed NIC server it could be important. John. -- -------

Re: [CentOS] How can I set NIC duplex before installation?

2007-06-25 Thread John Horne
On Mon, 2007-06-25 at 16:51 -0700, John R Pierce wrote: > John Horne wrote: > > Okay, that seems easy enough :-) Thanks. > > However, is the anaconda NIC ordering the same as those listed by the > > bios? For a mixed NIC server it could be important. > > > >

Re: [CentOS] nic bonding

2011-01-17 Thread John Horne
out on the 'net relating to bonded interfaces is out of date. I suspect some of the 'howtos' you have looked at are examples of that. John. -- John Horne Tel: +44 (0)1752 587287 University of Plymouth, UK Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] EL8 / certwatch missing

2020-06-17 Thread John Horne
' package for several years now to see when certificates are about to expire. John. -- John Horne | Senior Operations Analyst | Technology and Information Services University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK [http://www.plymouth.ac.

Re: [CentOS] AIDE or OSSEC on CentOS 5.4 x86_64?

2009-11-29 Thread John Horne
#x27;t be flagged as having changed unless someone has deliberately changed it. Another alternative is Samhain. As far as I remember it can handle prelinking, but will report updated files as having been changed. John. -- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287Fax: +44

Re: [CentOS] Exim installation on CentOS

2010-02-08 Thread John Horne
manual'. Exim is cited as being one of the better MTA projects because of its extensive documentation - over 400 pages in the specification, of varying formats, as well as two (as far as I remember) printed books. John. -- John Horne Tel: +44 (0)1752

Re: [CentOS] yum-updatesd not working on CentOS 5.2

2008-07-11 Thread John Horne
s anything obvious as to why it doesn't do the updates. I could see nothing about this on the RedHat bugzilla (no bugs reported for yum-updatesd at all under Fedora 9). I may test that tonight at home. John. -- --- John Horne, Univers

Re: [CentOS] yum-updatesd not working on CentOS 5.2

2008-07-14 Thread John Horne
On Fri, 2008-07-11 at 17:42 +0100, John Horne wrote: > On Tue, 2008-07-08 at 12:12 +0200, Santi Saez wrote: > > > > So, appears that yum-updatesd can download, notify and install > > updates.. but none of this works on a fresh CentOS 5.2 :-( > > Well I tested thi

Re: [CentOS] crontab for nobody

2008-07-20 Thread John Horne
ar/spool/cron/crontabs/nobody'. What if you try to remove > > it by running 'crontab -l nobody -r'? > > > I can't get that to run, Chris. > > crontab: usage error: only one operation permitted > I think what was meant was: ls -l /var/spool/cron/nobody t

Re: [CentOS] crontab for nobody

2008-07-20 Thread John Horne
hich could indicate if something was automatically installed. John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287 E-mail: [EMAIL PROTECTED] Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] crontab for nobody

2008-07-20 Thread John Horne
pe in 'cat /etc/issue' to see what it says. John. -- ------- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287 E-mail: [EMAIL PROTECTED] Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] anyone doing automatic yum updates via yum-updatesd on production servers?

2012-01-18 Thread John Horne
e' command then that could be applied automatically. But updates, for example, to postfix/sendmail/exim etc on a mail server, would not be applied by using 'exclude' in the yum.conf file. These can then be checked and applied manually. John. -- John Horne Tel:

Re: [CentOS] resolving names it is really slow slow with CentOS5.x using named

2009-05-25 Thread John Horne
show you what queries it is receiving and how it is handling them. John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287 E-mail: john.ho...@plymouth.ac.uk Fax: +44 (0)1752 587001 ___

Re: [CentOS] Security Guide for CentOS/RHEL

2008-09-18 Thread John Horne
rce tarball if you want (the source includes an RPM spec file). Latest version is 1.3.2. John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287 E-mail: [EMAIL PROTECTED]

Re: [CentOS] Security Guide for CentOS/RHEL

2008-09-18 Thread John Horne
On Thu, 2008-09-18 at 15:31 +, Josh Donovan wrote: > John Horne wrote: > > > For rkhunter, as far as I can remember, the Fedora 8/9 packages are upto > > date, so you could download one of those from a mirror and install it. > > Personally, I install rkhunter from sour

[CentOS] How to create a virtual bonded interface?

2008-09-18 Thread John Horne
== Shouldn't 'bond0:1' appear there somewhere? Anyone notice if I missed anything? Thanks, John. -- --- John Horne, University o

Re: [CentOS] How to create a virtual bonded interface?

2008-09-18 Thread John Horne
On Thu, 2008-09-18 at 10:36 -0700, nate wrote: > John Horne wrote: > > Hello, > > > > I have a server with 4 NICS running CentOS 5.2. I have bonded the > > interfaces together such that 'bond0' consists of eth0-3. This is not a > > problem, and works f

Re: [CentOS] Nightly yum update did an "upgrade"

2008-10-02 Thread John Horne
h as exim (MTA), freeradius (RADIUS), squid (web cache), etc are likewise disabled on the relevant servers. Again, if they are to be upgraded, then I will do them when it is convenient and without disrupting the current service. John. -- --

Re: [CentOS] Squid Number of hits

2008-10-14 Thread John Horne
ary: http://cord.de/tools/squid/calamaris/ John. -- --- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287 E-mail: [EMAIL PROTECTED] Fax: +44 (0)1752 587001 ___ Cen

Re: [CentOS] Problem detecting HP Tape Drive

2009-01-03 Thread John Horne
used for this, you may well need to do something similar: test -f /proc/driver/cciss/cciss2 && \ echo 'engage scsi' >/proc/driver/cciss/cciss2 2>/dev/null John. -- --- John Horne, University of P

Re: [CentOS] Apparent BIND problem doing RBL lookups for Postfix

2010-04-15 Thread John Horne
assume you have no local ratelimiting (via iptables etc)? John. -- John Horne, University of Plymouth, UK Tel: +44 (0)1752 587287Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

[CentOS] CentOS 7 - not using latest installed kernel

2014-12-03 Thread John Horne
noticed this? Any ideas as to why it might be happening? Thanks, John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] CentOS 7 - not using latest installed kernel

2014-12-03 Thread John Horne
lem has already been reported as a bug to CentOS and up to RedHat: https://bugs.centos.org/view.php?id=7651 John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK ___ CentOS mailing list CentOS@centos.org http://l

Re: [CentOS] Fail2Ban Centos 7 is there a trick to making it work?

2015-03-30 Thread John Horne
ee https://bugzilla.redhat.com/show_bug.cgi?id=1114821 John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] semi-OT: rkhunter, fix "broken links"

2015-08-07 Thread John Horne
earching in the > manpage, and I've done an rkhunter --propupd, but it still finds the > broken link. Anyone know how to remove the link from the rkhunter > d/b? > Take a look at the EXCLUDE_USER_FILEPROP_FILES_DIRS option in the config file. Set it to the link pathname, then r

Re: [CentOS] iptables: recent nolonger supported in Centos 5.8?!

2012-11-09 Thread John Horne
th your rule above is that you specify '-p tcp', whereas we have '-m tcp -p tcp'. John. -- John Horne, Plymouth University, UK Tel: +44 (0)1752 587287Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

[CentOS] CentOS 6.3 - KDE login screen configuration problems

2012-11-19 Thread John Horne
still shows the 30 second confirmation timer. I have compared the /etc/kde/kdm/kdmrc file from the CentOS PC to my Fedora PC and they are similar. (I make the same changes to my work PC, and these take effect.) Anyone any ideas about this? Thanks, John. -- John Horne Tel: +

Re: [CentOS] CentOS 6.3 - KDE login screen configuration problems

2012-11-20 Thread John Horne
On Mon, 2012-11-19 at 21:04 -0500, Ted Miller wrote: > On 11/19/2012 07:25 AM, John Horne wrote: > > > > The problem is that we would like to configure the login screen, so that > > it does not show the user list, that it does not allow the shutdown or > > reboot comm

Re: [CentOS] CentOS 6.3 - KDE login screen configuration problems

2012-11-21 Thread John Horne
On Tue, 2012-11-20 at 18:45 +0100, Nicolas Thierry-Mieg wrote: > John Horne wrote: > > > > I basically set the same settings, using the same method, as I did for > > my Fedora PC. As said, that works. So configuring KDE using the 'system > > settings' works in

Re: [CentOS] KDE login screen configuration problems

2012-12-10 Thread John Horne
the '/etc/sysconfig/desktop' file. It works with no problems. John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] - monitoring software

2013-10-19 Thread John Horne
RHEL servers, and some Debian and Fedora devices. John. -- ---- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] rkhunter

2014-01-17 Thread John Horne
On 17/01/14 21:37, m.r...@5-cent.us wrote: > I updated java-1.7.0-openjdk a few hours ago - it *was* listed as a > critical security update, and I don't want yelling from rkhunter. The man > page tells me I can tell it rkhunter --propupd ... but it > doesn't know the name above as a package. Been

Re: [CentOS] Monitor Wireless Networks

2014-02-21 Thread John Horne
I am especially interested in the channel so I can choose a different one. > Not sure about for CentOS (other than iwlist), but I recently found 'wavemon' for my Fedora 20 system: http://eden-feed.erg.abdn.ac.uk/wavemon/ John. -- John Horne Tel: +44 (0)1752 587287 Plym

Re: [CentOS] Does anyone use tcp wrappers (hosts.allow/hosts.deny) anymore?

2014-04-20 Thread John Horne
; No policies as such, but we include its installation as part of our standard server build process. It is part of the security used on our servers, and, as others have mentioned, multiple layers is the way to go rather than relying on just one tool. John. -- --

[CentOS] MySQL - replication - how to restore master?

2014-08-13 Thread John Horne
, so that both the master and slave start with the same data? Thanks, John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

[CentOS] Keepalived - spurious failovers

2014-11-12 Thread John Horne
ion why. Has anyone seen this themselves? Or have any idea why it may be occurring? As said, some nighttime process seems to be the cause, but I cannot think or find anything that would cause it. Thanks, John. -- John Horne Tel: +44 (0)1752 587287 Ply

Re: [CentOS] Keepalived - spurious failovers

2014-11-12 Thread John Horne
On Wed, 2014-11-12 at 10:27 -0500, m.r...@5-cent.us wrote: > John Horne wrote: > > > > We are using CentOS 6.6 and keepalived 1.2.13 on two servers for > > failover, no load-balancing. Failover is governed by the NIC being > > present, and the Apache and Tomcat pr

Re: [CentOS] Keepalived - spurious failovers

2014-11-12 Thread John Horne
On Wed, 2014-11-12 at 11:12 -0500, m.r...@5-cent.us wrote: > John Horne wrote: > >> > > They are both virtual servers - so no UPS. Failover communication is > > over the network. > > Um, bingo: are the host systems on UPS's? What happens on the *host* >

Re: [CentOS] Keepalived - spurious failovers

2014-11-12 Thread John Horne
ron jobs I have set up may give a clue. John. -- ---- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] Keepalived - spurious failovers

2014-11-12 Thread John Horne
On Wed, 2014-11-12 at 16:45 -0500, m.r...@5-cent.us wrote: > John Horne wrote: > > > Given that failover only occurs if Apache, Tomcat or the NIC fail, I > > can't find anything in log rotation that could cause this effect. For > > failover to occur the Apache/Tomcat

Re: [CentOS] rkhunter and prelink

2017-09-02 Thread John Horne
to literally 'SHA1' or 'MD5', then RKH will look for the relevant command. John. -- John Horne | Senior Operations Analyst | Technology and Information Services University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK [http://

[CentOS] DNS bind - use of /etc/named directory

2018-12-03 Thread John Horne
that any bind update would create an 'rpmnew' file. I admit I haven't actually tested this, but has anyone used the '/etc/named' directory and not had to modify the main '/etc/named.conf' file? I suspect, if not, then this should be raised as a possible bug si

Re: [CentOS] DNS bind - use of /etc/named directory

2018-12-04 Thread John Horne
ever, we don't use views and the local settings are not for zones. We do currently have a separate zone file, but again that requires an 'include' in the main '/etc/named.conf'. If a local settings file (in '/etc/named') could be used, then we would simply 'incl

Re: [CentOS] DNS bind - use of /etc/named directory

2018-12-07 Thread John Horne
On Tue, 2018-12-04 at 00:51 +, John Horne wrote: > > For many years we have modified the '/etc/named.conf' file to include local > settings. The disadvantage with this is of course that when bind is updated, > it creates an '/etc/named.conf.rpmnew' file. We then

[CentOS] Peculiar process name in /proc

2019-08-05 Thread John Horne
means, but have no idea what the ';5d44410e' part means. Is this some sort of thread reference? The file '/usr/sbin/xymond' does exist and is running as a daemon. Anyone know what the ';5d44410e' is referring to? I have tried Googling about this, but found no me

Re: [CentOS] Peculiar process name in /proc

2019-08-05 Thread John Horne
On Mon, 2019-08-05 at 13:06 +0100, Giles Coochey wrote: > On 05/08/2019 12:56, John Horne wrote: > > Hello, > > > > I was looking at a process through the '/proc' file system, and came across > > a process name which seemed to contain a hex value: > > &

[CentOS] Cron - log when job ends?

2019-11-15 Thread John Horne
, but removed at some time. Thanks, John. -- John Horne | Senior Operations Analyst | Technology and Information Services University of Plymouth | Drake Circus | Plymouth | Devon | PL4 8AA | UK [http://www.plymouth.ac.uk/images/email_footer.gif]<http://www.plymou

Re: [CentOS] Cron - log when job ends?

2019-11-18 Thread John Horne
On Fri, 2019-11-15 at 16:32 -0500, Karl Vogel wrote: > > > On Fri, Nov 15, 2019 at 05:54:07PM +0000, John Horne wrote: > > J> In trying to resolve a problem with a cron job, we can see when the job > J> starts by looking in the /var/log/cron log file. However, I was as

Re: [CentOS] mlocate-updatedb.timer not working?

2020-03-31 Thread John Horne
f daily as expected. > Just going through my mail messages, and as a quick reply, if you run 'systemctl list-timers' it will show you when the timer last ran and when it is next due to run. No idea as to why yours seemed to stop then start. John. -- John Horne | Senior Operations Ana

[CentOS] snmpd not working well with selinux?

2012-05-30 Thread John Horne
x27;t understand why it works with SELinux enabled when started from the command line, but not when started by the 'service' command. That seems very odd. Anyone any ideas about this? Thanks, John. -- John Horne Tel: +44 (0

Re: [CentOS] snmpd not working well with selinux?

2012-05-30 Thread John Horne
On Wed, 2012-05-30 at 16:52 +0100, John Horne wrote: > > I am trying to use SNMP on a CentOS 6.2 server, and am using the > 'pass_persist' configuration command: > Sorry, I should have added that nothing appears to be logged in /var/log/audit/audit.log when snmpd fails to

Re: [CentOS] snmpd not working well with selinux?

2012-05-30 Thread John Horne
On Wed, 2012-05-30 at 12:55 -0400, Daniel J Walsh wrote: > On 05/30/2012 11:58 AM, John Horne wrote: > > On Wed, 2012-05-30 at 16:52 +0100, John Horne wrote: > >> > >> I am trying to use SNMP on a CentOS 6.2 server, and am using the > >> 'pass_persist&#

Re: [CentOS] snmpd not working well with selinux?

2012-05-30 Thread John Horne
after the restorecon. John. -- John Horne, Plymouth University, UK Tel: +44 (0)1752 587287Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] Request for CentOS stats

2012-05-30 Thread John Horne
On Wed, 2012-05-30 at 17:00 -0400, Max Pyziur wrote: > Yes, lol ... > > I know enough about mailman that it's a cinch for the list administrator > to get the headline number of subscribers. > Why would you want to know such numbers? John. -- John Horne, Plymouth Univer

Re: [CentOS] snmpd not working well with selinux?

2012-05-31 Thread John Horne
e of pass_persist works fine. I'll submit this as a bug for your consideration. John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] snmpd not working well with selinux?

2012-05-31 Thread John Horne
qf /var/run/net-snmp net-snmp-5.5-37.el6_2.1.x86_64 = So '/var/run/net-snmpd' must have come in at a later date than F15. John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK

Re: [CentOS] snmpd not working well with selinux?

2012-05-31 Thread John Horne
show_bug.cgi?id=822480 It seems that '/var/lib/net-snmp' should be used. I have tested my use of pass_persist and it does work when using '/var/lib/net-snmp'. John. -- John Horne Tel: +44 (0)1752 587287 Plymouth Universi

[CentOS] Perl - strict.pm not found

2012-10-10 Thread John Horne
on other servers (albeit CentOS 5.8) with no problems. Thanks, John. -- John Horne Tel: +44 (0)1752 587287 Plymouth University, UK Fax: +44 (0)1752 587001 ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] Perl - strict.pm not found

2012-10-10 Thread John Horne
On Wed, 2012-10-10 at 05:44 -0600, Warren Young wrote: > On 10/10/2012 4:38 AM, John Horne wrote: > > > > The problem is that 'strict.pm' is located in /usr/share/perl5 (as it is > > on our other servers), and /usr/share/perl5 is specified in @INC. > > Perl

Re: [CentOS] Perl - strict.pm not found

2012-10-11 Thread John Horne
On Wed, 2012-10-10 at 11:38 +0100, John Horne wrote: > > the /etc/cron.daily/freshclam script runs in the early morning, I get > sent an email error message: > > = > /etc/cron.daily/freshclam: > > Can't locate strict.pm in @INC

Re: [CentOS] Perl - strict.pm not found

2012-10-11 Thread John Horne
On Thu, 2012-10-11 at 11:42 -0400, Daniel J Walsh wrote: > On 10/11/2012 06:34 AM, John Horne wrote: > > On Wed, 2012-10-10 at 11:38 +0100, John Horne wrote: > >> > >> the /etc/cron.daily/freshclam script runs in the early morning, I get >