Hi,
As a member of the BCS-OSSG committee I thought people here might be
interested in our free Open for Business Conference on Monday 5th September.
http://ossg.bcs.org/ofb2016/
This is the second time that we have run this event and builds on a very
successful event last year. Once again we have a fantastic speaker
line-up to provide many unique insights, including Mike Little,
co-founder of WordPress, and Maarten Ectors, Vice President IoT at
Canonical, with more to be confirmed.
The conference aims to explore key themes in open source software as
they relate to service providers and consumers across both the private
and public sectors.
The conference will once again run as part of the Wuthering Bytes
technology festival, which takes place over the course of 10 days and
features events covering a broad range of open hardware, software and
data topics.
For more information see the websites at http://ossg.bcs.org/ofb2016/ or
http://wutheringbytes.com/ Alternatively, feel free to contact me
directly by replying to this eMail.
Open for Business 2016 is sponsored by the BCS and Embecosm and is free
to attend.
Regards,
@ndy
--
andyjpb(a)ashurst.eu.org
http://www.ashurst.eu.org/
0290 DA75 E982 7D99 A51F E46A 387A 7695 7EBA 75FF
Hi,
By now all customers should have received notification of scheduled
maintenance that will be required due to a serious security flaw in
the hypervisor software that we use (Xen).
If you have not seen an email regarding this then please check your
spam folders etc.
The full details¹ are in the email you've already received and I'm
only sending this so as to have a public notification I can link to
when people raise support tickets to ask what is going on. :)
Anyway, the hosts have all been patched and the maintenance consists
of merely rebooting them to boot into the new hypervisor. This will
happen across three nights.
In previous non-SSD days this used to take around 30 minutes to shut
down all VPSes, reboot and boot them all again. These days I expect
it to be much shorter, maybe 5 minutes. So, you should see a clean
shut down followed by a boot a few minutes later.
It is important that you ensure that your VPS boots cleanly with all
services you expect running to be running. We offer free Nagios
monitoring which can be useful for assuring yourself that everything
you expect to be running really is running. Also if I see Nagios
looks more broken afterwards than it was to start with then I will
have a quick investigate. If interested in having that set up then
please contact support(a)bitfolk.com.
Cheers,
Andy
¹ Well, not any details about the bug itself. These are under
embargo until mid day Tuesday 26 July.
--
http://bitfolk.com/ -- No-nonsense VPS hosting
_______________________________________________
announce mailing list
announce(a)lists.bitfolk.com
https://lists.bitfolk.com/mailman/listinfo/announce
Hi,
For about the 5th time in the last 6 months, Spamhaus has listed the
IPv6 address of our support ticket mail host as a spam source.
I have checked every outbound port 25 connection from that host and
verified that the only thing it sends is replies to support tickets.
The previous times this happened I was able to de-list the host, but
this time:
https://www.spamhaus.org/query/ip/2600%253A3c03%253A%253A31%253A2000
just says "invalid input.", so I can't de-list it this time.
Last time this happened I attempted to contact Spamhaus both by
their web contact form and by twitter to ask for more info as to why
they keep listing this host. I have not received a response.
So, all I can conclude is that Spamhaus are wrong. Possibly someone
is automatically reporting ticket responses to them as spam. I can
only recommend not using their "zen" DNSBL for binary blocking
decisions.
If anyone has any contacts at Spamhaus that do actually respond then
I would appreciate you putting me in touch.
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
_______________________________________________
announce mailing list
announce(a)lists.bitfolk.com
https://lists.bitfolk.com/mailman/listinfo/announce
Hi,
I've been working on a really long-requested feature, which is to
allow an address book of multiple contact details:
https://tools.bitfolk.com/redmine/issues/22
I've now done most of the work on the part that lets you store and
manage contacts, but I both hate and am not very good at web work,
so I'm bound to have made some mistakes. Please could you have a
look at it and see if you can break it?
It's at:
https://testpanel.bitfolk.com/account/contacts/#toc-address-book
Log in with your usual credentials, and your multi-factor auth code
if enabled.
All it does right now is let you add and change contact records. It
won't actually make any of your alerts and bills etc go anywhere
different (changing the main contact will, though, as usual). That's
for later.
So, I'm interested to see if you can break it. If you can, an update
at the above redmine page would be appreciated (log in with your
usual BitFolk credentials). Or just mail me off-list if you don't
feel like logging in to redmine.
Complaints about how it *looks* will not be that useful, since I
already know I suck at HTML. If you do have suggestions about how to
improve the aesthetics they should come with example HTML/CSS that
implements your look. :)
After this is working how we want then I intend to disable all of
the roles except alerting, as each role will require a lot of work
elsewhere at BitFolk. I need to also push out some updated
monitoring so I will make it use the alerting role at the same time.
Next will most likely be adding back the billing role, as the main
driver for issue #22 in the first place was for people who want
their billing notifications to go to a different place. They've been
waiting 6 years…
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi all,
I just thought I'd report that I recently did a successful
"do-release-upgrade -d" to upgrade my Ubuntu 14.04 vps to 16.04. There
were a few snags but they were of my own making (e.g. failed mysql
reconfigure due to me moving the data directory and apparmor
complaining).
Then tonight I decided to migrate from i386 to amd64 using this guide:
http://www.ewan.cc/?q=node/132
It worked fine.
The main reason for changing architecture was wanting to use repos
provided by powerdns and some other projects which only have 64 bit
packages.
Cheers,
Roger
I never saw a (fairly important) email sent earlier this month so
decided to check my postfix logs. Surprised to discover that
they only go back a week and appear to being rotated daily.
/etc/cron.daily/sysklogd contains the line:
logs=$(syslogd-listfiles)
and the output of syslogd-listfiles is:
/var/log/syslog
...only.
But the equivalent in cron.weekly calls "syslogd-listfiles --weekly"
which *does* list the mail.* log files.
So it's like the cron.daily is taking the '--weekly' output.
Any pointers?
No references to 'mail' in logrotate.d or logrotate.conf.
It's Debian 6.0.10.
This might be more support-related, but has anyone set up delegated
reverse DNS for IPv6 with "all-knowing-dns"?
It handles PTR and AAAA records on the fly and lets me avoid doing the
whole zone-file thingy. But I'm uncertain about this bit :
"Please bear in mind that the zone
e.f.2.f.1.f.1.0.8.a.b.0.1.0.0.2.ip6.arpa should already exist on all the
nameservers you list."
Can I use "all-knowing-dns" as an easy fix?
$ apt-cache show all-knowing-dns
Package: all-knowing-dns
Version: 1.7-1
Installed-Size: 38
Maintainer: Debian Perl Group <pkg-perl-maintainers(a)lists.alioth.debian.org>
Architecture: all
Depends: init-system-helpers (>= 1.11), perl, libmouse-perl,
libmousex-nativetraits-perl, libnet-dns-perl, libnetaddr-ip-perl,
libprivileges-drop-perl
Description-en: tiny DNS server for IPv6 Reverse DNS
AllKnowingDNS provides reverse DNS for IPv6 networks which use SLAAC
(autoconf), e.g. for a /64 network.
.
The problem with IPv6 reverse DNS and traditional nameservers is that the
nameserver requires you to provide a zone file. Assuming you want to
provide
RDNS for a /64 network, you have 2**64 = 18446744073709551616
different usable
IP addresses (a little less if you are using SLAAC). Providing a zone
file for
that, even in a very terse notation, would consume a huge amount of
disk space
and could not possibly be held in the memory of the computers available
nowadays.
.
AllKnowingDNS instead generates PTR and AAAA records on the fly. You only
configure which network you want to serve and what your entries should
look
like.
Description-md5: 1df6f6c08cc7056f9106168642d482b9
Homepage: https://metacpan.org/release/AllKnowingDNS/
Section: perl
Priority: optional
Filename: pool/main/a/all-knowing-dns/all-knowing-dns_1.7-1_all.deb
Size: 22260
MD5sum: 8f70307d17b1690e293595ecd349c436
SHA1: 5c9002dacf99bd5085d8e7ebfdc3f247d8a2287d
SHA256: 712b360eb1830fa175a8b476276979212dd6405987b4c859e5651c377346aac8
Hi,
Two-factor authentication for the BitFolk Panel and Xen Shell has
long been requested¹, and is finally now implemented. If you wish to
enable it please visit the "Security" section of the Panel to do so:
https://panel.bitfolk.com/account/security/
You should hopefully find the process straightforward. If you don't,
please let us know.
Thanks to the requesters and those who've been helping to test it
over the last ~week. For those who've been testing: I've disabled it
on your live account but left the key data there. If you don't want
to re-use the same key you can just invalidate it and generate
another one.
Cheers,
Andy
¹ https://tools.bitfolk.com/redmine/issues/117
PS It's worth looking over the list of outstanding feature requests
and seeing if there's any you'd like to vote for as it's nice to
know what is important to you.
https://tools.bitfolk.com/redmine/issues?query_id=1 (log in with
your usual BitFolk credentials if you want to vote / update
anything)
--
http://bitfolk.com/ -- No-nonsense VPS hosting
_______________________________________________
announce mailing list
announce(a)lists.bitfolk.com
https://lists.bitfolk.com/mailman/listinfo/announce
Hi,
Implementing two-factor authentication has long been a requested
feature:
https://tools.bitfolk.com/redmine/issues/117
I have implemented it on the panel test site at
https://testpanel.bitfolk.com and would really appreciate if those
who are interested in 2FA would give it a go to see if it works how
you want/expect.
If test site is currently pointed at the real database so changes
you make will be for real, although the real panel site does not
have 2FA deployed so you cannot lock yourself out of anything
important. I will purge all TOTP keys and set everyone back to
having TOTP disabled before it goes live.
If you have any comments then adding them to the feature tracker
(link above) would be appreciated.
Note that 2FA on the web panel is pretty pointless without also
having 2FA or similar on the SSH to Xen Shell. I am as yet undecided
about where to go with that (only that it needs to go somewhere). I
don't know whether it's acceptable to just have an option to restrict
it to SSH key auth only, or if the same 2FA should be used there
(there is a PAM module for TOTP 2FA:
https://packages.debian.org/jessie/libpam-google-authenticator)
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
Anyone else having routing problems? I'm unsure if it's me, as my ISP
has been having issues today so it could very easily be my end, but I
can't get to bitfolk from some locations, my packets seem to be getting
lost somewhere in zayo.com:
mstevens@mstevens-Vostro-460:~ % traceroute etla.org
traceroute to etla.org (85.119.82.193), 30 hops max, 60 byte packets
1 gateway (192.168.1.1) 0.294 ms 0.398 ms 0.510 ms
2 192.168.10.85 (192.168.10.85) 2.576 ms 2.606 ms 2.637 ms
3 172.30.4.135 (172.30.4.135) 10.433 ms 11.886 ms 14.330 ms
4 mai.b2.edge.as200876.rs.uk.evolving.net.uk (82.145.32.89) 16.494 ms 16.926 ms 11.980 ms
5 1717.net1.north.dc5.as20860.net (87.117.210.25) 35.128 ms 34.351 ms 35.158 ms
6 be3.asr01.thn.as20860.net (62.233.127.173) 18.842 ms 19.629 ms 19.581 ms
7 ae6.mpr1.lhr15.uk.zip.zayo.com (94.31.48.85) 19.650 ms 11.177 ms 10.736 ms
8 ae5.mpr2.lhr2.uk.zip.zayo.com (64.125.21.9) 12.184 ms 12.775 ms 13.125 ms
9 ae10.mpr1.lhr1.uk.zip.zayo.com (64.125.31.193) 16.533 ms 16.117 ms 16.703 ms
10 * * *
It works from other places, which is how I'm sending this email...
Michael