Re: [lopsa-tech] Server disk encryption

2013-05-23 Thread Steven Kurylo
scussed, however as I think about it more, I'm not sure if it's worth it either. There were a couple off-list emails also saying they don't use encryption on the servers - while it's a small sample size - that seems to be the consensus. Thank you everyo

Re: [lopsa-tech] Server disk encryption

2013-05-22 Thread Steven Kurylo
ut it's not mandatory yet.But it sounds like I would want to encrypt my servers, unless the process is too onerous. Cheers -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org https://lists.lopsa.org/cgi-bin/mailman/listinfo/tech This

[lopsa-tech] Server disk encryption

2013-05-22 Thread Steven Kurylo
How are you encrypting your server's disks, when they contain sensitive information? Are you doing full disk? With auto boot? Or do you use Mandos, or similar? Or enter the password manually for each machine? Or are you not bothering with encryption, and relying on your physical security instea

Re: [lopsa-tech] nagios / cacti / spiceworks / zabbix / munin / zenoss

2013-03-23 Thread Steven Kurylo
5% for 10 minutes, or the system begins thrashing swap, etc, so I can > hopefully avoid system down.) etc. > > > > Thanks for suggestions. > > > ___ > Tech mailing list > Tech@lists.lopsa.org >

Re: [lopsa-tech] AD Replication Convergence time

2013-03-12 Thread Steven Kurylo
org/cgi-bin/mailman/listinfo/tech > This list provided by the League of Professional System Administrators > http://lopsa.org/ > > -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org https://lists.lopsa.org/cgi-bin/mailman/listinfo/tech This list provided by the League of Professional System Administrators http://lopsa.org/

Re: [lopsa-tech] AD / GPO / security templates

2013-02-20 Thread Steven Kurylo
included >> things like the default security policy out of the box, and the securedc >> policy >> ... but these seem to be missing on 2012... I'm still googling, but haven't >> found it yet. >> -- Steven Kurylo ___

Re: [lopsa-tech] AD Migration

2013-01-21 Thread Steven Kurylo
On Sun, Jan 20, 2013 at 8:39 AM, Edward Ned Harvey (lopser) wrote: > > > Based on my understanding, in Option 1, there is no graceful way to change > from one domain to another while preserving the user id and profile. Yes, > you can script something to make new user accounts in a new domain, bas

Re: [lopsa-tech] Google wants images of my passport, driver's license, bank statement, etc.

2012-08-20 Thread Steven Kurylo
On Mon, Aug 20, 2012 at 12:05 PM, lopser wrote: > > This is going way too far. Nobody in their right mind > should give any credit card payment processing center their driver's > license, passport, bank statement, etc. > > > > Foolish. Baaah!!! I want to play my stupid video game!;-) Too

Re: [lopsa-tech] Home/small business KVMs?

2012-08-16 Thread Steven Kurylo
On Thu, Aug 16, 2012 at 6:14 PM, Robert Hajime Lanning wrote: > > I believe he is talking about the actual console manager. Like we were > talking about KVM to ethernet (single port IP KVM), he is looking for the > same, but in serial, not KVM. > > Something like this: > http://store.digi.com/ind

Re: [lopsa-tech] How to find files in use by NFS or SAMBA (CIFS)?

2012-04-05 Thread Steven Kurylo
On Thu, Apr 5, 2012 at 1:17 PM, Will Dennis wrote: > Should have qualified myself... I'm mainly a Windows guy on the OS > side...  What I'm looking for is something > like (in Windows Server) Computer Management > Shared Folders > Sessions > / Open Files ("Sessions" show each remote machine & use

Re: [lopsa-tech] how to handle 'vacation' coverage for a small shop?

2012-03-16 Thread Steven Kurylo
On Fri, Mar 16, 2012 at 5:49 AM, Edward Ned Harvey wrote: >> From: tech-boun...@lists.lopsa.org [mailto:tech-boun...@lists.lopsa.org] >> On Behalf Of Paul Heinlein >> >> 6. An off-site contractor with mad skillz who's on retainer in case > > One big problem with this is --- They got mad skillz but

Re: [lopsa-tech] Loop detection/prevention.

2012-02-25 Thread Steven Kurylo
On Fri, Feb 24, 2012 at 8:34 PM, Anne Cross wrote: > > Or they're sales reps tidying up a conference room, who look at the wires > coming out of the conference table jacks, say, "That looks untidy," loop > them all up and then plug all the ends in to keep them neatly bundled. > I'll double down o

Re: [lopsa-tech] Integrated User and Group Management

2012-01-23 Thread Steven Kurylo
On Mon, Jan 23, 2012 at 12:48 PM, Atom Powers wrote: > > My question for the list: > Are there powerful account management tools for Active Directory that > can support a custom account lifecycle? > > For example, if an applicant becomes a student there are several > account attributes and groups

Re: [lopsa-tech] A strange file related to ssh

2012-01-23 Thread Steven Kurylo
On Mon, Jan 23, 2012 at 10:18 AM, Dan Schlitt wrote: > > It is definitely not a header file. > > I did reinstall the ssh but the number of files that were removed when > removing openssl was a bit daunting so I didn't do it. You'll want to skip dependency checking sudo dpkg --force-all --remove

Re: [lopsa-tech] RAID for windows

2012-01-03 Thread Steven Kurylo
enough for grub, but grub fails to find the kernel, grub can look for the kernel on disk 2 automatically. -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org https://lists.lopsa.org/cgi-bin/mailman/listinfo/tech This list provided by the

Re: [lopsa-tech] Redirection of program output to a file

2011-12-29 Thread Steven Kurylo
On Thu, Dec 29, 2011 at 12:51 PM, John BORIS wrote: > > Just to recap, I tried > sh -iv |& tee /tmp/log with tail -f /tmp/log > run-my-program | tee /tmp/log > run-my-program | tee -a /tmp/log > run-my-program 2>&1 > > None of these worked. > > This is a SCO 5.0.6 system and it is a COBOL program

Re: [lopsa-tech] Asterisk and Nortel cs1000e integration

2011-12-01 Thread Steven Kurylo
experience with telephony? I was thinking maybe I'll have to create a > SIP trunk between the 2, but I am a total noob with VOIP. Thanks in advance > and see you @ LISA '11 -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org

Re: [lopsa-tech] Tracking down a virus

2011-11-10 Thread Steven Kurylo
something there. But that's a lot of work, and doesn't provide any value to > anyone so it's your call. > > -- > Benjamin > > On Nov 8, 2011, at 10:54 AM, Steven Kurylo wrote: > >> Hi, >> >> We had an incident yesterday evening and I'm trying

[lopsa-tech] Tracking down a virus

2011-11-08 Thread Steven Kurylo
Is anyone familiar with this virus? The URLs I've looked at so far are timing out, so I can't check the virus that way. Thank you. -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org https://lists.lopsa.org/cgi-bin/mailman/listinfo/

Re: [lopsa-tech] scp

2011-05-04 Thread Steven Kurylo
On Wed, May 4, 2011 at 3:54 PM, Andrew Hume wrote: > it is time for my annual head-slapping over scp. > is there any plausible alternative to scp? mostly its all fine, > but i am struggling over having to do an additional ssh > afterwards to confirm teh file got there (or to let > the other side k

Re: [lopsa-tech] What's your favorite small/cheap board/box for doing wi-fi stuff?

2011-04-26 Thread Steven Kurylo
s as to what you need. Multiple wifi? Certain CPU requirements? We use Buffalo WHR-HP-G54's with openwrt extensively. We also Pacific Wireless for POE. I'd also recommend Ubiquiti and Mikrotik products, as other people have. -- Steven Kurylo ___

Re: [lopsa-tech] Understanding a system's workload

2011-04-21 Thread Steven Kurylo
On Thu, Apr 21, 2011 at 5:58 PM, Phil Pennock wrote: > On 2011-04-21 at 10:03 -0700, Steven Kurylo wrote: >> However I've never been happy with troubleshooting IO issues.  Often I >> end feelings its IO, but can't point my finger at the specific number. >>  It seems

Re: [lopsa-tech] Understanding a system's workload

2011-04-21 Thread Steven Kurylo
On Thu, Apr 21, 2011 at 6:55 AM, Doug Weimer wrote: > Many comments in the 'amount of swap' thread mentioned the importance of > understanding a system's workload. This is something that I often > struggle with. What tools and techniques do you use to better understand > the expected workload for

Re: [lopsa-tech] Understanding Security Vulnerability

2011-02-09 Thread Steven Kurylo
> I understand that, the problem I have is that there isn't any way for > unauthenticated users to upload files to this server. This makes me > worried that we didn't patch the actual vulnerability and instead just > patched one path to the vulnerability. How is $thisfile created? I don't see the

Re: [lopsa-tech] getting specific netflow analysis

2011-02-07 Thread Steven Kurylo
> 1)  A host on my network is receiving traffic from hundreds of remote hosts > out on the Internet.  I'd like to have some way of noticing that this is > happening so that I can take a closer look at what that host is doing.  For > example, it would be fine if I could see a table of hosts that's s

Re: [lopsa-tech] SCSI hard drive availability

2011-01-25 Thread Steven Kurylo
second hand drives from scsi4me.com before, without any problems. I don't really consider ebay to be reliable though, you never know when they won't have any available. That would be part of my stockpiling strategy; buy several years worth and replenish through

[lopsa-tech] SCSI hard drive availability

2011-01-25 Thread Steven Kurylo
e before. I guess I should double check RAM availability too, though those don't wear out nearly as much. Sadly the new server fairy doesn't come around here often. Thanks. -- Steven Kurylo ___ Tech mailing list Tech@lists.lopsa.org https://l

Re: [lopsa-tech] Is it possible to run an open relay on a different Postfix port

2011-01-18 Thread Steven Kurylo
> I would like to set up another port (e.g. 2525) and have it work as a open > relay for all my internal addresses as this will be harder for the > kiddies to find and exploit. While I can't help you with your specific postfix question, I'd like to point out script kiddies will still find it prett

Re: [lopsa-tech] 82599 10GBit/s intel NIC

2011-01-16 Thread Steven Kurylo
On Sun, Jan 16, 2011 at 11:13 AM, Conrad Wood wrote: > Hi there, > > I have gotten myself into installing some linux boxes as 10GBit/s > internet Gateways. > The internet connection is delivered as 10GBit/s Ethernet-over-Fibre. > The card is in a PCIe 8 Lane slot. > > I gather from [1] that 1 Lane

Re: [lopsa-tech] Server Recommendations

2011-01-14 Thread Steven Kurylo
On Fri, Jan 14, 2011 at 2:45 PM, Charles Jones wrote: > On Fri, Jan 14, 2011 at 3:40 PM, Charles Jones   > wrote: >> >> echo "scsi scan-new-devices" > /proc/scsi/scsi > > Just for fun I googled again and it looks like now the thing to do is: > echo "- - -" > /sys/class/scsi_host/host0/scan > Hopef

Re: [lopsa-tech] Server Recommendations

2011-01-14 Thread Steven Kurylo
> I don't want to have to pay > extortionate prices for hard drives either. I hate that a 6 bay hot swap > machine comes with blanks instead of drive trays. If you want more trays you > have to buy them from Dell with marked up Dell drives. I understand wanting to > only support drives known to wor

Re: [lopsa-tech] Server Recommendations

2011-01-14 Thread Steven Kurylo
On Fri, Jan 14, 2011 at 9:23 AM, Daniel Pittman wrote: > On Jan 14, 2011 9:12 AM, "Roy McMorran" wrote: > >> Apologies in advance if I'm covering old ground here.  I'd swear I'd seen >> a similar discussion recently but I haven't been able to find it in the >> archives.  Anyway... >> >> I'm seeki

Re: [lopsa-tech] Faster than 1G Ether... ESX to ZFS

2010-12-08 Thread Steven Kurylo
> > Also, if you have a NFS datastore, which is not available at the time of ESX > bootup, then the NFS datastore doesn't come online, and there seems to be no > way of telling ESXi to make it come online later. esxcfg-nas -r I assume there is way using the SDK too. So you could have a script wh