Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread P J P
> On Friday, 21 November 2014 1:24 PM, Florian Weimer wrote: >> On 11/21/2014 08:34 AM, Jan Kratochvil wrote: >> Almost all of my Fedora installations are test VMs where >> any security is irrelevant. Okay. But does enabling root login offer any significant benefit in that? IOW, if it's disab

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Florian Weimer
On 11/21/2014 09:04 AM, P J P wrote: My point is that once we address this (most likely through some configuration generation during VM setup), we can also switch PermitRootLogin on. You mean off? Or that we disable it by default and enable it while setting up a new VM? The latter. We h

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Juan Orti
El 2014-11-21 08:49, Christian Rose escribió: 2014-11-21 8:11 GMT+01:00 P J P : Sshd(8) daemon by default allows remote users to login as root. 1. Is that really necessary? 2. Lot of users use their systems as root, without even creating a non-root user. Such practices need to be discouraged,

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Gerd Hoffmann
On Fr, 2014-11-21 at 09:11 +0100, Florian Weimer wrote: > On 11/21/2014 09:04 AM, P J P wrote: > >> My point is that once we address this (most likely through some > >> configuration generation during VM setup), we can also switch > >> PermitRootLogin on. > > >You mean off? Or that we disable

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Reindl Harald
Am 21.11.2014 um 08:11 schrieb P J P: Sshd(8) daemon by default allows remote users to login as root. 1. Is that really necessary? 2. Lot of users use their systems as root, without even creating a non-root user. Such practices need to be discouraged, not allowing remote root login

Re: Abandoning boinc-client

2014-11-21 Thread Philip Rhoades
Mattia, On 2014-11-21 05:21, Mattia Verga wrote: Hi all, despite my efforts and many wasted hours I'm unable to build recent versions of boinc-client (I'm stuck with errors about gtk-2.0 and gtk-3.0 co-existence). I'm only a co-maintainer, but the primary maintainer has abandoned the package to

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Pierre-Yves Chibon
On Fri, Nov 21, 2014 at 08:52:23AM +0100, Ralf Corsepius wrote: > Hi, > > for unknown reasons, I can't login to the pkgdb anymore. I just tried with success > What am I supposed to do ? Could you maybe described a little more the issue? Are you redirected to FedOAuth? Do you see the login scree

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Tomas Hozza
On 11/21/2014 09:04 AM, P J P wrote: >> On Friday, 21 November 2014 1:24 PM, Florian Weimer wrote: > >>> On 11/21/2014 08:34 AM, Jan Kratochvil wrote: >>> Almost all of my Fedora installations are test VMs where >>> any security is irrelevant. > >Okay. But does enabling root login offer any s

How to stop unneeded services?

2014-11-21 Thread Peter Lemenkov
Hello All! Perhaps a silly question but I'm stuck and need your help, my fellow fedorians. I've got a service foo.service which Requires=bar.socket (which in turn runs bar.service). So if I start foo.service then systemd opens bar.socket, captures first packet and runs bar.service (which isn't int

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Ralf Corsepius
On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: On Fri, Nov 21, 2014 at 08:52:23AM +0100, Ralf Corsepius wrote: Hi, for unknown reasons, I can't login to the pkgdb anymore. I just tried with success What am I supposed to do ? Could you maybe described a little more the issue? I am goi

Re: Mozilla enabled ads in Firefox and they're active in Fedora

2014-11-21 Thread Matěj Cepl
On 2014-11-20, 16:17 GMT, Petr Viktorin wrote: > Every piece of Fedora is like that, and yet I don't see any > other software doing useless-for-me opt-out tracking. > (Also, who am I paying? All authors of Firefox, or only the Mozilla > employees?) How many multizillion LoC end-user applications

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Ralf Corsepius
On 11/21/2014 11:33 AM, Ralf Corsepius wrote: On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: Are you redirected to FedOAuth? I guess that's it. Do you see the login screen (username/password)? Is the problem only with pkgdb? I don't know. All I can say is https://admin.fedoraproject

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Pierre-Yves Chibon
On Fri, Nov 21, 2014 at 11:33:57AM +0100, Ralf Corsepius wrote: > On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: > >On Fri, Nov 21, 2014 at 08:52:23AM +0100, Ralf Corsepius wrote: > >>for unknown reasons, I can't login to the pkgdb anymore. > > > >Could you maybe described a little more the issu

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Roberto Ragusa
On 11/21/2014 09:42 AM, Reindl Harald wrote: > why? because they are servers for specific tasks and *any* non-root login > would be followed by "su - root" anyways and for automated rsync scripts > backing up data only root has access you need it also For rsync-as-root use cases my usual approa

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Pierre-Yves Chibon
On Fri, Nov 21, 2014 at 11:46:03AM +0100, Ralf Corsepius wrote: > On 11/21/2014 11:33 AM, Ralf Corsepius wrote: > >On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: > > >>Are you redirected to FedOAuth? > >I guess that's it. > > > >>Do you see the login screen (username/password)? > > >>Is the pr

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Reindl Harald
Am 21.11.2014 um 11:55 schrieb Roberto Ragusa: On 11/21/2014 09:42 AM, Reindl Harald wrote: why? because they are servers for specific tasks and *any* non-root login would be followed by "su - root" anyways and for automated rsync scripts backing up data only root has access you need it also

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Reindl Harald
Am 21.11.2014 um 12:05 schrieb Reindl Harald: Am 21.11.2014 um 11:55 schrieb Roberto Ragusa: On 11/21/2014 09:42 AM, Reindl Harald wrote: why? because they are servers for specific tasks and *any* non-root login would be followed by "su - root" anyways and for automated rsync scripts backing

rawhide report: 20141121 changes

2014-11-21 Thread Fedora Rawhide Report
allow it explicitly for legacy clients) * Tue Oct 21 2014 Tomáš Mráz 1.0.1j-2 - update the FIPS RSA keygen to be FIPS 186-4 compliant Size change: 719 bytes paratype-pt-sans-fonts-20141121-1.fc22 -- * Fri Nov 21 2014 Parag Nemade - 20141121-1 - Change the

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Ralf Corsepius
On 11/21/2014 11:52 AM, Pierre-Yves Chibon wrote: On Fri, Nov 21, 2014 at 11:33:57AM +0100, Ralf Corsepius wrote: On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: On Fri, Nov 21, 2014 at 08:52:23AM +0100, Ralf Corsepius wrote: for unknown reasons, I can't login to the pkgdb anymore. Could y

F-21 Branched report: 20141121 changes

2014-11-21 Thread Fedora Branched Report
Compose started at Fri Nov 21 07:15:02 UTC 2014 Broken deps for armhfp -- [avro] avro-mapred-1.7.5-9.fc21.noarch requires hadoop-mapreduce avro-mapred-1.7.5-9.fc21.noarch requires hadoop-client [gearbox] gearbox-10.11-8

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Mikolaj Izdebski
On 11/21/2014 11:56 AM, Pierre-Yves Chibon wrote: > On Fri, Nov 21, 2014 at 11:46:03AM +0100, Ralf Corsepius wrote: >> On 11/21/2014 11:33 AM, Ralf Corsepius wrote: >>> On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: >> Are you redirected to FedOAuth? >>> I guess that's it. >>> Do you s

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Pierre-Yves Chibon
On Fri, Nov 21, 2014 at 12:23:29PM +0100, Ralf Corsepius wrote: > On 11/21/2014 11:52 AM, Pierre-Yves Chibon wrote: > >On Fri, Nov 21, 2014 at 11:33:57AM +0100, Ralf Corsepius wrote: > >>On 11/21/2014 10:30 AM, Pierre-Yves Chibon wrote: > >>>On Fri, Nov 21, 2014 at 08:52:23AM +0100, Ralf Corsepius

Really making fonts awesome in Fedora 21

2014-11-21 Thread Pádraig Brady
I was surprised at the blurriness of the _default_ font (Cantarell) on my new F21 install. There were noticeable artefacts as well as general blurriness with no noticeable difference between grayscale and rgba antialiasing. Even worse was different text heights for bold and normal which was immed

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Matěj Cepl
On 2014-11-21, 10:55 GMT, Roberto Ragusa wrote: > For rsync-as-root use cases my usual approach is to create > another account with userid=0 and login with ssh on this > account. Proper way is actually to use command parameter in authorized_keys on server and for example https://ftp.samba.org/

[Base] Base Design WG agenda meeting 21 November 2014 15:00 UTC on #fedora-meeting

2014-11-21 Thread Harald Hoyer
Agenda: - Status buildrequires cleanup work (davids & nils!) - Docker update - Status rpm mechanisms for multiple config subpackages - Status rpm mechanisms for factory reset files - Base WG ownership of generic network install images (keep it on the agenda, until all WG members are back fr

update on ca-certificates, introducing the ca-legacy utility

2014-11-21 Thread Kai Engert
On Fri, 2014-10-31 at 14:05 +0100, Kai Engert wrote: > All legacy root CA certificates, which seem to be required for full > compatibility with either OpenSSL or GnuTLS, will continue to be > included and enabled in the ca-certificates package. > > For users who are willing to accept the breakage

Re: update on ca-certificates, introducing the ca-legacy utility

2014-11-21 Thread Kai Engert
FYI, I'm documenting the changes that we make on top of the Mozilla CA list at: https://fedoraproject.org/wiki/CA-Certificates Kai -- devel mailing list devel@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/devel Fedora Code of Conduct: http://fedoraproject.org/code-of-

Re: update on ca-certificates, introducing the ca-legacy utility

2014-11-21 Thread Stephen Gallagher
On Fri, 2014-11-21 at 14:03 +0100, Kai Engert wrote: > On Fri, 2014-10-31 at 14:05 +0100, Kai Engert wrote: > > All legacy root CA certificates, which seem to be required for full > > compatibility with either OpenSSL or GnuTLS, will continue to be > > included and enabled in the ca-certificates

Re: Accessing/Logging into the pkgdb

2014-11-21 Thread Ralf Corsepius
On 11/21/2014 12:46 PM, Pierre-Yves Chibon wrote: On Fri, Nov 21, 2014 at 12:23:29PM +0100, Ralf Corsepius wrote: But I don't seem to be able to log-in directly on https://admin.fedoraproject.org/pkgdb This really sounds like a problem on FedOAuth rather than pkgdb itself. Have you tried fe

update on ca-certificates, introducing the ca-legacy utility

2014-11-21 Thread Kai Engert
Resending this as a new thread, for increased visibility. As explained in the older thread, the Mozilla project has started to remove CA certificates that contain weak keys. Those removals cause issues with software based on OpenSSL, and software based on older versions of GnuTLS. (A short descri

Re: update on ca-certificates, introducing the ca-legacy utility

2014-11-21 Thread Kai Engert
On Fri, 2014-11-21 at 10:45 -0500, Stephen Gallagher wrote: > Kai, this is very important information buried at the bottom of a long > email thread; would you mind re-sending this summary in a new thread > (also to devel-announce) so that people are sure to see it? done -- devel mailing list de

Re: iccjpeg.h errors

2014-11-21 Thread Rex Dieter
Antonio Trande wrote: > I don't know how to fix these errors during IceCat compilation. Lately I > tried to adapt Fedora compilations flags but there is wrong something. > > Here the log: > http://koji.fedoraproject.org/koji/getfile?taskID=8044663&name=build.log&offset=-4000 > > This is SPEC fi

Fedora scientific packaging

2014-11-21 Thread Sandro Mani
Hello, Some time ago I started working on packaging Salome, the platform for numerical simulation. As always, time is a limited resource, and things kinda stalled after hitting a few issues here and there, despite most of the work being done. Now, with Jiri Kastner joining the effort, we deci

Re: Fedora scientific packaging

2014-11-21 Thread M. Edward (Ed) Borasky
The two I want most are RStudio (desktop and server) and R Commander. RStudio does exist in RPM form but the packages are made via 'cmake' rather than by Fedora's process, and the server's using the old school /etc/init.d rather than systemd. R Commander's much easier - you just have to package it'

Re: Abotu setting 'PermitRootLogin=no' in sshd_config

2014-11-21 Thread Richard W.M. Jones
On Fri, Nov 21, 2014 at 09:11:51AM +0100, Florian Weimer wrote: > On 11/21/2014 09:04 AM, P J P wrote: > >>My point is that once we address this (most likely through some > >>configuration generation during VM setup), we can also switch > >>PermitRootLogin on. > > > You mean off? Or that we disa

Re: How to stop unneeded services?

2014-11-21 Thread Stephen Gallagher
On Fri, 2014-11-21 at 13:52 +0400, Peter Lemenkov wrote: > Hello All! > Perhaps a silly question but I'm stuck and need your help, my fellow > fedorians. > > I've got a service foo.service which Requires=bar.socket (which in > turn runs bar.service). So if I start foo.service then systemd open

Re: How to stop unneeded services?

2014-11-21 Thread Lennart Poettering
On Fri, 21.11.14 13:52, Peter Lemenkov (lemen...@gmail.com) wrote: > Hello All! > Perhaps a silly question but I'm stuck and need your help, my fellow > fedorians. > > I've got a service foo.service which Requires=bar.socket (which in > turn runs bar.service). So if I start foo.service then syst

Re: [Scitech] Fedora scientific packaging

2014-11-21 Thread Dave Love
Sandro Mani writes: > That said, there is now a github repo which contains the > work-in-progress stuff for packaging Salome (and some initial OpenFOAM > work) here [2]. People interested in joining these efforts or sharing > initial work on other scientific packages are very welcome to join the

Re: Fedora scientific packaging

2014-11-21 Thread Pete Travis
On Nov 21, 2014 12:48 PM, "M. Edward (Ed) Borasky" wrote: > > The two I want most are RStudio (desktop and server) and R Commander. RStudio does exist in RPM form but the packages are made via 'cmake' rather than by Fedora's process, and the server's using the old school /etc/init.d rather than sy

Self Introduction: Colin Macdonald

2014-11-21 Thread Colin Macdonald
Hi all, I've been a Fedora user since 2008 and long-time GNU/Linux user on other distros before that. I'm currently working on packaging "Biber" (#1165620) which is a LaTeX bibliography tool, with the kind help of @psabata and @mef. I've maintained a copr of this for six months or so. @psabata

Re: references to "Makefiles" in the wiki's Packaging: namespace

2014-11-21 Thread Adam Williamson
On Fri, 2014-11-14 at 16:31 -0700, Ken Dreyer wrote: > I was talking with someone today about > https://fedoraproject.org/wiki/Packaging:DistTag , and they were > confused about the references to the Makefiles. > > Can I have access to edit that particular page to clean that up? > > Or how does o

Re: Taskatron depcheck broken/incomplete (was: Re: Removing packages that have broken dependencies in F21 tree)

2014-11-21 Thread Adam Williamson
On Sun, 2014-11-16 at 01:21 +0100, Kevin Kofler wrote: > Kalev Lember wrote: > > 2) juffed was broken by > > https://admin.fedoraproject.org/updates/FEDORA-2014-14301/ . Interestingly > > enough the update passed the Taskatron depcheck test there, even though it > > created a new broken dependency

Re: Fedora scientific packaging

2014-11-21 Thread Suchakra
Hi, > What do you say, Ed? If I get the package review done, will you help with > bugs and maintenance? > > --Pete I am using RStudio actively on Fedora using the rpm they provide. Though it works just about satisfactorily for me standalone, it would really be nice to have it in our repos. I ca

Fedora 21 Final blocker bug status report #1

2014-11-21 Thread Adam Williamson
Hi folks! We're now into the Fedora 21 Final freeze period, and we really need to address blocker bugs promptly to try and make the scheduled release date. On the current schedule Go/No-Go will happen on 2014-12-04, which means we really need the final release candidate built by 2014-12-02, so even

Re: Fedora scientific packaging

2014-11-21 Thread M. Edward (Ed) Borasky
I think the Fedora policy requires more of a commitment from maintainers than I can offer. In any event, I know RStudio Server can be built from source on Fedora and that it works but it needs a lot of detailed attention to turn it into something that will make it into a release. It has a few depen

Re: Fedora 21 Final blocker bug status report #1

2014-11-21 Thread M. Edward (Ed) Borasky
I'll volunteer to test https://bugzilla.redhat.com/show_bug.cgi?id=1146232 "f21 workstation ships 'default' network, so loses connectivity when run in a VM" - libvirt / gnome-boxes - when do we expect TC3? On Fri, Nov 21, 2014 at 9:15 PM, Adam Williamson wrote: > Hi folks! We're now into the Fed