Re: CFEngine Help: Re: cf-runagent and keys

2012-06-15 Thread Marco Marongiu
On 15/06/12 16:32, Neil Watson wrote: >> It's set to true, in fact. One clarification though: are you suggesting >> >to remove/comment out the directive, or to set it to false? > Remove/comment it. OK, thanks. I'll test it immediately! >> >When I'll put these policies in production, they'll have

Re: CFEngine Help: Re: cf-runagent and keys

2012-06-15 Thread Neil Watson
On Fri, Jun 15, 2012 at 04:26:04PM +0200, Marco Marongiu wrote: >It's set to true, in fact. One clarification though: are you suggesting >to remove/comment out the directive, or to set it to false? Remove/comment it. >When I'll put these policies in production, they'll have the grateful >task to

Re: CFEngine Help: Re: cf-runagent and keys

2012-06-15 Thread Marco Marongiu
On 15/06/12 16:20, Neil Watson wrote: > This is slightly similar to a bug I saw when using IPV6. The trouble > for me was skipidentify. If you have skipidentify => "true"; somewhere > in your policy try removing it. It's set to true, in fact. One clarification though: are you suggesting to remov

Re: CFEngine Help: Re: cf-runagent and keys

2012-06-15 Thread Neil Watson
This is slightly similar to a bug I saw when using IPV6. The trouble for me was skipidentify. If you have skipidentify => "true"; somewhere in your policy try removing it. https://cfengine.com/bugtracker/view.php?id=988 >cf3> -> !! Package "puppet" cannot be verified -- no match >cf3> -> !! P

Re: CFEngine Help: Re: cf-runagent and keys

2012-06-15 Thread Marco Marongiu
On 14/06/12 20:23, no-re...@cfengine.com wrote: > Marco, could you post the verbose output of cf-runagent, maybe we can > get a clue what's going on from there. That happened again, finally, and examining the output I found at least one strangeness. The file in attachment is a copy & paste from a

CFEngine Help: Re: cf-runagent and keys

2012-06-14 Thread no-reply
Forum: CFEngine Help Subject: Re: cf-runagent and keys Author: zzamboni Link to topic: https://cfengine.com/forum/read.php?3,26210,26214#msg-26214 Marco, could you post the verbose output of cf-runagent, maybe we can get a clue what's going on from

[solved] Re: cf-runagent trust suddenly broken

2011-11-15 Thread Michael Stevens
Stopped cf3, moved the workdir to /tmp, created a new workdir, copied in all the bin / library / content files from the old workdir, started server ... back to normal. On Nov 11, 2011, at 3:07 PM, Michael Stevens wrote: > cf-runagent (3.1.4) suddenly started having trust issues this morning.

Re: Cf-runagent

2010-12-22 Thread Mark Burgess
There is a customary "ifelapsed" time for runagent on the server side to protect against DOS (even self-inflicted) etc. On 12/22/2010 09:50 AM, Seva Gluschenko wrote: > Hi, > > you'd better direct such questions to help-cfengine@cfengine.org since > I'm not Cfengine authority. It's not cfrunagen

Re: Cf-runagent

2010-12-22 Thread Seva Gluschenko
Hi, you'd better direct such questions to help-cfengine@cfengine.org since I'm not Cfengine authority. It's not cfrunagent feature but cf-agent feature which doesn't recheck for promises within given interval (defaults to 1 minute). To force immediate execution, add -K to cf-agent invocation strin

Re: cf-runagent question

2010-11-09 Thread Bas van der Vlies
On 9 nov 2010, at 12:17, Seva Gluschenko wrote: > Again, from my experience -H allows for successful run against 300+ > hosts, so it's not a problem, especially when the host list is > provided by a shell script which takes that list from the database. > > Speaking about urgency, you'd better no

Re: cf-runagent question

2010-11-09 Thread Seva Gluschenko
Again, from my experience -H allows for successful run against 300+ hosts, so it's not a problem, especially when the host list is provided by a shell script which takes that list from the database. Speaking about urgency, you'd better not consider Cfengine as the immediate tool (still from my exp

Re: cf-runagent question

2010-11-09 Thread Bas van der Vlies
On 9 nov 2010, at 11:50, Seva Gluschenko wrote: > From my experience, cf-runagent is best invoked with -H. I > tried -s and it failed, AFAIR. > Thanks for the info. we have a lot of hosts so -H is not an option. I will make separate files for each cluster and use -f option. Sometime we must u

Re: cf-runagent question

2010-11-09 Thread Seva Gluschenko
>From my experience, cf-runagent is best invoked with -H. I tried -s and it failed, AFAIR. 2010/11/9 Bas van der Vlies : > cfengine cmmunity edition: 3.1.0 > > > config file: > > body runagent control > { >        Lisa:: >                hosts => { >                        "gb-r10n2.irc.sara.nl",

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: kholloway Link to topic: https://cfengine.com/forum/read.php?3,18529,18546#msg-18546 Excellent! :) Here is my solution until -s is implemented/fixed, it's not perfect and could certainly be don

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: Seva Gluschenko Link to topic: https://cfengine.com/forum/read.php?3,18529,18545#msg-18545 Yes, backgrounding is fixed in svn because I took care of it and sent a patch few months ago. And -s doesn't

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: kholloway Link to topic: https://cfengine.com/forum/read.php?3,18529,18544#msg-18544 Same as before, no errors, doesn't contact any hosts at all. I did find a bug report for the backgrounding issue,

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: neilhwatson Link to topic: https://cfengine.com/forum/read.php?3,18529,18543#msg-18543 For kicks can you do -s !test_hosts ? ___ Help-cfengine mailing list Help

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: kholloway Link to topic: https://cfengine.com/forum/read.php?3,18529,18541#msg-18541 Here is my output from enabling debug 3 on cf-runagent. Seems to indicate that my class is not selected. I will submit a

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: neilhwatson Link to topic: https://cfengine.com/forum/read.php?3,18529,18539#msg-18539 I'm out of ideas. Perhaps submit a bug report. Or if you can try a newer svn version

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: kholloway Link to topic: https://cfengine.com/forum/read.php?3,18529,18536#msg-18536 I saw that in another forum posting while searching for ways to resolve my issue but that does not change anything

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: neilhwatson Link to topic: https://cfengine.com/forum/read.php?3,18529,18534#msg-18534 This is a shot in the dark. Try rearranging the command to /opt/cf3/sbin/cf-runagent -v -s test_hosts -D remote_test1

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: kholloway Link to topic: https://cfengine.com/forum/read.php?3,18529,18533#msg-18533 No output from the Test1 run unless I add -v, then it shows that it parses the config, initializes classes and then just

Cfengine Help: Re: cf-runagent unable to background and ignoring -s

2010-09-28 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent unable to background and ignoring -s Author: neilhwatson Link to topic: https://cfengine.com/forum/read.php?3,18529,18531#msg-18531 What is the output from the failed command? Trying running with -I as it might give more information. I think that

Re: Re: cf-runagent

2010-07-28 Thread Seva Gluschenko
Michael, Perhaps, you might run into issue with keys overlapping on server under the heavy load which have been fixed in 3.0.5. We didn't have to regenerate keys on client side after upgrade, but we had to re-upload several public keys from clients on the policy server. Also, if your client authen

Re: cf-runagent

2010-07-28 Thread Mark Burgess
That's odd. Nothing at all has changed in the RSA code, except perhaps the version of openssl you compile with. mega...@gmail.com wrote: > Got the verbose server output, and this seemed to be the error: > > cf3 Received: [SAUTH y 256 37 c] on socket 5 > cf3 Private decrypt failed = block type i

Re: Re: cf-runagent

2010-07-28 Thread megamic
Got the verbose server output, and this seemed to be the error: cf3 Received: [SAUTH y 256 37 c] on socket 5 cf3 Private decrypt failed = block type is not 02 cf3 Auth dialogue error cf3 REFUSAL of request from connecting host: (SAUTH y 256 37 c) I then regenerated the ppkeys for both the server

Re: cf-runagent

2010-07-28 Thread Michael Potter
On Wed, Jul 28, 2010 at 8:47 PM, Mark Burgess wrote: > > It sounds strange. Did you only upgrade half the systems? Nothing should stop > working. Nope - upgraded both cf-serverd and cf-execd, and was running cf-runagent on same host as the cf-serverd I was contacting. I will check the output of

Re: cf-runagent

2010-07-28 Thread Mark Burgess
It sounds strange. Did you only upgrade half the systems? Nothing should stop working. On 07/28/2010 10:11 AM, Michael Potter wrote: > Ill give that a try tomorrow. I just don't know what could have > changed from 3.0.4 to 3.0.5p1 that caused a working configuration to > break. I wonder if I nee

Re: cf-runagent

2010-07-28 Thread Michael Potter
Ill give that a try tomorrow. I just don't know what could have changed from 3.0.4 to 3.0.5p1 that caused a working configuration to break. I wonder if I need to regenerate my ppkeys after an upgrade On Wed, Jul 28, 2010 at 3:22 PM, Seva Gluschenko wrote: > To obtain verbose server output, yo

Re: cf-runagent

2010-07-27 Thread Seva Gluschenko
To obtain verbose server output, you must shut down its daemon and run it from command line with -v option. The cf-serverd then stays in foreground and goes into verbose mode, so that you can try and run cf-runagent on another terminal and see what's going on on the server side. 2010/7/28 : > Hi

Cfengine Help: Re: cf-runagent ignores max_children parameter

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent ignores max_children parameter Author: mark Link to topic: https://cfengine.com/forum/read.php?3,17639,17646#msg-17646 Excellent Seva, thanks for pointing out this omission. I've patched the code. ___

Cfengine Help: Re: cf-runagent strange behaviour with -s option

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent strange behaviour with -s option Author: Seva Gluschenko Link to topic: https://cfengine.com/forum/read.php?3,17638,17645#msg-17645 Neil, the -s option defines classes for local usage, not to be sent remotely. Anyway, it seems to follow the same

Cfengine Help: Re: cf-runagent strange behaviour with -s option

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent strange behaviour with -s option Author: neilhwatson Link to topic: https://cfengine.com/forum/read.php?3,17638,17644#msg-17644 I seem to recall that in cf2 options that were to go to the remote agent were on the right of the hostname. IIRC then

Cfengine Help: Re: cf-runagent strange behaviour with -s option

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent strange behaviour with -s option Author: Seva Gluschenko Link to topic: https://cfengine.com/forum/read.php?3,17638,17643#msg-17643 For those who might be interested, it seems like the arguments parser goes wrong somehow. Reordering command line

Cfengine Help: Re: cf-runagent ignores max_children parameter

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent ignores max_children parameter Author: Seva Gluschenko Link to topic: https://cfengine.com/forum/read.php?3,17639,17642#msg-17642 Well, so that I suggest you the following patch which is proven to be working in my environment: --- src

Cfengine Help: Re: cf-runagent ignores max_children parameter

2010-07-06 Thread no-reply
Forum: Cfengine Help Subject: Re: cf-runagent ignores max_children parameter Author: mark Link to topic: https://cfengine.com/forum/read.php?3,17639,17640#msg-17640 Very little work has gone into cf-runagent because it is mainly used for testing. The bottom line is that if you have 200 machines

Re: cf-runagent adn understanding cfengine work process

2010-05-27 Thread Vasiliy G Tolstov
В Срд, 26/05/2010 в 10:53 +0400, Vasiliy G Tolstov пишет: > Hello. > > I'm try to understand cfengine (manuals already read, but not fully > understand) Hmm. Already found solution (cf-agent -f xxx.cf). Another question - can i provide parameters to agent bundle in command line? For example i ne

Cfengine Help: Re: cf-runagent on a single host

2010-04-24 Thread forum
Forum: Cfengine Help Subject: Re: cf-runagent on a single host Author: Beto Link to topic: https://cfengine.com/forum/read.php?3,16993,16994#msg-16994 cf-runagent -H See man cf-runagent or cf-runagent -h. ___ Help-cfengine mailing list Help-cfengine

Re: cf-runagent and key trust

2010-03-28 Thread Nicolas Charles
Great, thank you ! Nicolas On Sun, Mar 28, 2010 at 1:41 PM, Mark wrote: > I just fixed this so it will work in the patch nextweek > > > Mark > > > On 28 Mar 2010, at 12:41, Nicolas Charles wrote: > >> Hello, >> >> I've been trying this with the Nova version, is it implemented ? >> >> Machine 1

Re: cf-runagent and key trust

2010-03-28 Thread Nicolas Charles
Hello, I've been trying this with the Nova version, is it implemented ? Machine 1 # cf-runagent --interactive -H192.168.0.20 BAD: key could not be accepted on trust !! Authentication dialogue with 192.168.0.20 failed Unable to establish connection with 192.168.0.20 Machine 2 > -> Accepting a c