DuckCorp Projects: Issues
https://projects.duckcorp.org/
https://projects.duckcorp.org/favicon.ico?1669909042
2022-07-10T10:42:55Z
DuckCorp Projects
Redmine
DuckCorp Infrastructure - Bug #776 (Resolved): Users are unable to register to projects.duckcorp.org
https://projects.duckcorp.org/issues/776
2022-07-10T10:42:55Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>There is an issue related to the captcha:<br /><pre>
Oops, we failed to validate your reCAPTCHA response. Please try again.
</pre><br />I tried with firefox and chromium.</p>
<p><code>/var/log/redmine/dc/production.log</code> from the <code>redmine</code> LXC container:<br /><pre>
Started POST "/account/register" for 185.238.6.46 at 2022-07-10 12:53:52 +0000
Processing by AccountController#register as HTML
Parameters: {"utf8"=>"✓", "authenticity_token"=>"[REDACTED]", "user"=>{"login"=>"pilou_test", "password"=>"[FILTERED]", "password_confirmation"=>"[FILTERED]", "firstname"=>"pilou", "lastname"=>"pilou_test", "mail"=>"pilou_test@ir5.eu", "language"=>"fr"}, "g-recaptcha-response"=>"[REDACTED]", "commit"=>"Soumettre"}
Current user: anonymous
Rendering plugins/recaptcha/app/views/account/register.html.erb within layouts/base
Rendered plugins/recaptcha/app/views/account/register.html.erb within layouts/base (8.8ms)
Completed 200 OK in 3022ms (Views: 14.7ms | ActiveRecord: 1.4ms)
</pre></p>
DuckCorp Infrastructure - Bug #769 (Rejected): Toushirou get stuck randomly at boot
https://projects.duckcorp.org/issues/769
2022-04-15T23:36:48Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Toushirou get stuck randomly at boot.</p>
Another reboot party needs to be planned in order to assess this issue:
<ul>
<li><a href="https://www.askapache.com/linux/linux-debugging/" class="external">kernel parameters</a>: <code>debug ignore_loglevel log_buf_len=10M print_fatal_signals=1 LOGLEVEL=8 earlyprintk=vga,keep sched_debug console=ttyS0,115200 systemd.log_level=debug</code></li>
<li><a href="https://www.suse.com/support/kb/doc/?id=000019461" class="external">step by step systemd boot process</a></li>
<li><a class="external" href="https://wiki.debian.org/systemd#systemd_hangs_on_startup_or_shutdown">https://wiki.debian.org/systemd#systemd_hangs_on_startup_or_shutdown</a></li>
</ul>
<p>Pictures:<br /><img src="https://projects.duckcorp.org/attachments/download/167/2022-04-13-185627_001.jpeg" loading="lazy" style="width: 50%;" alt="" /><br /><img src="https://projects.duckcorp.org/attachments/download/168/2022-04-13-185651_001.jpeg" loading="lazy" style="width: 50%;" alt="" /></p>
DuckCorp Infrastructure - Bug #746 (Rejected): unexpected restart of Toushirou host
https://projects.duckcorp.org/issues/746
2021-12-13T14:16:57Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Today Toushirou was restarted unexpectedly. It seems that this restart wasn't due a command.</p>
<p>The server was restarted after <code>Dec 13 10:07:03</code> (UTC+1). I unlocked the encrypted encryption around 13h15 (UTC+1).</p>
<p><code>syslog</code> contains:<br /><pre>
Dec 13 10:06:52 Toushirou postfix/smtpd[1353160]: disconnect from <redacted> ehlo=2 starttls=1 mail=1 rcpt=1 bdat=1 quit=1 commands=7
Dec 13 10:07:03 Toushirou stunnel: LOG5[8632]: Connection closed: 182 byte(s) sent to TLS, 20 byte(s) sent to socket
@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@
[...]
@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@^@
Dec 13 13:18:38 Toushirou systemd-udevd[631]: Using default interface naming scheme 'v247'.
Dec 13 13:18:38 Toushirou systemd-udevd[630]: Using default interface naming scheme 'v247'.
Dec 13 13:18:38 Toushirou lvm[578]: 3 logical volume(s) in volume group "extra" monitored
</pre></p>
<p>The filesystem journals were recovered:<br /><pre>
Dec 13 13:18:38 Toushirou systemd-fsck[791]: /dev/md0 was not cleanly unmounted, check forced.
Dec 13 13:18:38 Toushirou systemd-fsck[790]: /dev/mapper/main-ldap: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[790]: /dev/mapper/main-ldap: clean, 14/23616 files, 9468/94208 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-ldap.
Dec 13 13:18:38 Toushirou systemd-fsck[787]: /dev/mapper/main-ftp: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[787]: /dev/mapper/main-ftp: clean, 1042/1966080 files, 4094072/7864320 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-ftp.
Dec 13 13:18:38 Toushirou systemd-fsck[794]: /dev/mapper/main-logs: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[794]: /dev/mapper/main-logs: Clearing orphaned inode 524490 (uid=0, gid=4, mode=0100640, size=186)
Dec 13 13:18:38 Toushirou systemd-fsck[794]: /dev/mapper/main-logs: Clearing orphaned inode 525136 (uid=0, gid=4, mode=0100640, size=2261619)
[...]
Dec 13 13:18:38 Toushirou systemd-fsck[794]: /dev/mapper/main-logs: clean, 3025/915712 files, 701679/3661824 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-logs.
Dec 13 13:18:38 Toushirou systemd-fsck[797]: /dev/mapper/main-mysql: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[797]: /dev/mapper/main-mysql: clean, 1706/305216 files, 302945/1220608 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-mysql.
Dec 13 13:18:38 Toushirou systemd-fsck[801]: /dev/mapper/main-projects: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[801]: /dev/mapper/main-projects: clean, 15384/977280 files, 2501362/3932160 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-projects.
Dec 13 13:18:38 Toushirou systemd-fsck[805]: /dev/mapper/main-stuffcloud: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[805]: /dev/mapper/main-stuffcloud: clean, 184647/8519680 files, 22560629/34078720 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-stuffcloud.
Dec 13 13:18:38 Toushirou systemd-fsck[810]: /dev/mapper/main-var: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[810]: /dev/mapper/main-var: Clearing orphaned inode 136445 (uid=0, gid=0, mode=0100664, size=11567160)
Dec 13 13:18:38 Toushirou systemd-fsck[810]: /dev/mapper/main-var: Clearing orphaned inode 136045 (uid=0, gid=0, mode=0100664, size=9253600)
[...]
Dec 13 13:18:38 Toushirou systemd-fsck[810]: /dev/mapper/main-var: clean, 43941/305216 files, 677459/1220608 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-var.
Dec 13 13:18:38 Toushirou systemd-fsck[811]: /dev/mapper/main-tmp: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[811]: /dev/mapper/main-tmp: Clearing orphaned inode 20 (uid=0, gid=0, mode=0100666, size=0)
Dec 13 13:18:38 Toushirou systemd-fsck[811]: /dev/mapper/main-tmp: Clearing orphaned inode 50 (uid=128, gid=136, mode=0100600, size=0)
[...]
Dec 13 13:18:38 Toushirou systemd-fsck[811]: /dev/mapper/main-tmp: clean, 3380/121920 files, 20791/487424 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-tmp.
Dec 13 13:18:38 Toushirou systemd-fsck[814]: /dev/mapper/main-vcs: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[814]: /dev/mapper/main-vcs: clean, 62639/183264 files, 334140/732160 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-vcs.
Dec 13 13:18:38 Toushirou systemd-fsck[817]: /dev/mapper/main-vmail: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[817]: /dev/mapper/main-vmail: Clearing orphaned inode 1314229 (uid=5111, gid=5111, mode=0100600, size=2543956)
[...]
Dec 13 13:18:38 Toushirou systemd-fsck[817]: /dev/mapper/main-vmail: clean, 38189/1966080 files, 3862291/7864320 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-vmail.
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/extra-lxd.
Dec 13 13:18:38 Toushirou systemd-fsck[827]: /dev/mapper/extra-home: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[827]: /dev/mapper/extra-home: clean, 576437/19660800 files, 60022856/78643200 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/extra-home.
Dec 13 13:18:38 Toushirou systemd-fsck[791]: /dev/md0: 348/64000 files (23.9% non-contiguous), 63264/255936 blocks
Dec 13 13:18:38 Toushirou systemd-fsck[819]: /dev/mapper/main-www: recovering journal
Dec 13 13:18:38 Toushirou systemd-fsck[819]: /dev/mapper/main-www: clean, 417149/9175040 files, 7579187/36700160 blocks
Dec 13 13:18:38 Toushirou systemd[1]: Finished File System Check on /dev/mapper/main-www.
</pre></p>
<p>Thanks to GuiHome and Victor for letting me know that the NextCloud service was unavailable.</p>
<p>Once the server has been restarted there was an error with the hivane network link. Hence some service were unavailable. The nerim link worked. <br /><pre>
root@Toushirou:~# systemctl --failed
UNIT LOAD ACTIVE SUB DESCRIPTION
● apache2.service loaded failed failed The Apache HTTP Server
● ifup@eth\x2dwan\x2dhivane.service loaded failed failed ifup for eth-wan-hivane
● matrix-appservice-irc.service loaded failed failed Matrix AppService IRC
● networking.service loaded failed failed Raise network interfaces
</pre></p>
<pre>
root@Toushirou:~# ifdown --force eth-wan-hivane
RTNETLINK answers: Cannot assign requested address
RTNETLINK answers: Cannot assign requested address
root@Toushirou:~# ifup --force eth-wan-hivane
Waiting for DAD... Timed out
ifup: failed to bring up eth-wan-hivane
</pre>
<p>I remember the timed out issue occurred when the last time the server was moved from a rack to another. I tried the <code>ifdown</code>/<code>ifup</code> commands several times (until the <code>Timed out</code> disappeared).</p>
<p>The logs show that the timed out issue occurred at boot:<br /><pre>
Dec 13 13:18:45 Toushirou sh[1562]: Waiting for DAD... Timed out
Dec 13 13:18:45 Toushirou sh[1496]: ifup: failed to bring up eth-wan-hivane
</pre></p>
<p>Next I restarted <code>apache2.service</code> and <code>matrix-appservice-irc.service</code>, then I updated <code>/lib/systemd/system/lxd.socket</code> in order to fix a typo:<br /><pre>Dec 13 15:48:22 Toushirou systemd[1]: /lib/systemd/system/lxd.socket:8: Unit must be of type service, ignoring: lxd.servcie
</pre><br />After that i ran <code>systemctl daemon-reload</code> and <code>lxc list</code> then the redmine LXC container restarted.</p>
<p>At this time I tried to create this issue using redmine:https://projects.duckcorp.org/ but an issue occurred after i tried to authenticate: the redmine web interface showed an error: <code>"Cannot assign requested address - connect(2) for [2001:67c:1740:9001::c1c8:2ab1]:636"</code>.</p>
<p>The restart of the <code>slapd</code> service (which was listening on IPv6 but not IPv4) fixed this issue.</p>
DuckCorp Infrastructure - Enhancement #719 (Rejected): redmine role depends on unversioned patches
https://projects.duckcorp.org/issues/719
2021-02-12T00:13:40Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p><a href="https://projects.duckcorp.org/projects/dc-admin/repository/ansible-role-redmine/revisions/master/entry/tasks/plugins.yml#L34" class="external">The plugin patches aren't versioned</a> , they are stored on the filesystem where redmine is installed.</p>
<p>The patches should be moved in the repository where the Ansible inventory is located.</p>
DuckCorp Infrastructure - Review #705 (Rejected): ansible-role-httpd_php_fpm: create Unix group u...
https://projects.duckcorp.org/issues/705
2020-07-08T19:49:29Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Repository/branch: <a href="https://vcs-git-viewer.duckcorp.org/?p=duckcorp/ansible-role-httpd_php_fpm" class="external"><code>ansible-role-httpd_php_fpm/create_unix_group_for_pool_workers</code></a></p>
<p>Create Unix group used for pool workers.</p>
<p>Fix this error:</p>
<pre>
TASK [zabbix : Generate Zabbix UI configuration]
task path: duckcorp-infra/ansible/roles/zabbix/tasks/webui.yml:30
fatal: [Orthos]: FAILED! => {
"changed": false,
"owner": "root",
"group": "root",
"mode": "0644",
"msg": "chgrp failed: failed to look up group php_sup.duckcorp.org",
"path": "/etc/zabbix/zabbix.conf.php",
"state": "file",
}
</pre>
DuckCorp Infrastructure - Enhancement #615 (Rejected): new Toushirou: configuration migration
https://projects.duckcorp.org/issues/615
2018-04-23T14:41:26Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>This issue regroups tasks related to Toushirou setup.</p>
DuckCorp Infrastructure - Bug #605 (Rejected): No mail since 2017-10-15 07:00:02
https://projects.duckcorp.org/issues/605
2017-10-16T10:53:44Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>On orfeo, Oct 15 07:00:00 (UTC+2), policyd-weight daemon was unable to restart, then all incoming mail were rejected.</p>
<pre>
# systemctl status policyd-weight.service
● policyd-weight.service - LSB: Start and stop the policyd-weight daemon
Loaded: loaded (/etc/init.d/policyd-weight; generated; vendor preset: enabled)
Active: failed (Result: exit-code) since Sun 2017-10-15 07:00:02 CEST; 1 day 5h ago
Docs: man:systemd-sysv-generator(8)
Process: 28244 ExecStop=/etc/init.d/policyd-weight stop (code=exited, status=0/SUCCESS)
Process: 28291 ExecStart=/etc/init.d/policyd-weight start (code=exited, status=1/FAILURE)
Tasks: 0 (limit: 4915)
Memory: 372.0K
CPU: 389ms
CGroup: /system.slice/policyd-weight.service
</pre>
<pre>
# grep "policyd-weight" /var/log/syslog.1
Oct 15 07:00:00 orfeo systemd[1]: Stopping LSB: Start and stop the policyd-weight daemon...
Oct 15 07:00:02 orfeo policyd-weight[28244]: Stopping policyd-weight (incl. cache): policyd-weight.
Oct 15 07:00:02 orfeo systemd[1]: Stopped LSB: Start and stop the policyd-weight daemon.
Oct 15 07:00:02 orfeo systemd[1]: Starting LSB: Start and stop the policyd-weight daemon...
Oct 15 07:00:03 orfeo policyd-weight[28291]: Starting policyd-weight: policyd-weightmaster: bind 12525: IO::Socket::INET: Address already in use Address already in use at /usr/sbin/policyd-weight line 1052.
Oct 15 07:00:03 orfeo postfix/policyd-weight[28294]: warning: err: init: master: bind 12525: IO::Socket::INET: Address already in use Address already in use at /usr/sbin/policyd-weight line 1052.
Oct 15 07:00:03 orfeo policyd-weight[28291]: failed!
Oct 15 07:00:04 orfeo systemd[1]: policyd-weight.service: Control process exited, code=exited status=1
Oct 15 07:00:04 orfeo systemd[1]: Failed to start LSB: Start and stop the policyd-weight daemon.
Oct 15 07:00:04 orfeo systemd[1]: policyd-weight.service: Unit entered failed state.
Oct 15 07:00:04 orfeo systemd[1]: policyd-weight.service: Failed with result 'exit-code'.
Oct 15 07:00:05 orfeo postfix/policyd-weight[16253]: cache killed
</pre>
<pre>
# /var/log/syslog.1 extract
Oct 15 07:00:39 orfeo postfix/smtpd[28403]: warning: connect to 127.0.0.1:12525: Connection refused
Oct 15 07:00:39 orfeo postfix/smtpd[28403]: warning: problem talking to server 127.0.0.1:12525: Connection refused
Oct 15 07:00:40 orfeo postfix/smtpd[28403]: warning: connect to 127.0.0.1:12525: Connection refused
Oct 15 07:00:40 orfeo postfix/smtpd[28403]: warning: problem talking to server 127.0.0.1:12525: Connection refused
Oct 15 07:00:40 orfeo postfix/smtpd[28403]: NOQUEUE: reject: RCPT from XXX: 451 4.3.5 <XXXX@milkypond.org>: Recipient address rejected: Server configuration problem; from=<XXX@outlook.com> to=<XXX@milkypond.org> proto=ESMTP helo=<XXX>
</pre>
<p>Thanks to rtp for pointing that.</p>
DuckCorp Infrastructure - Review #562 (Rejected): Fix "Invalid SCRIPTWHITELIST configuration opti...
https://projects.duckcorp.org/issues/562
2017-06-19T12:27:16Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Could you review <code>rkhunter_lwp_request_isnt_a_dependency</code> branch ?</p>
<p><code>lwp-request</code> belongs to <code>libwww-perl</code> but <code>libwww-perl</code> isn't a dependency of <code>rkhunter</code>.</p>
DuckCorp Infrastructure - Bug #504 (Rejected): Backups are failing due to an expired certificate
https://projects.duckcorp.org/issues/504
2017-02-01T10:02:10Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<pre>
[root@Korutopi ~]# openssl x509 -in /etc/bacula/certs/duckcorp-backup_bacula_korutopi.crt -text | grep After
Not After : Jul 29 15:14:44 2016 GMT
</pre>
<pre>
01-Feb 10:00 Korutopi-dir JobId 18455: sql_get.c:391 No volumes found for JobId=18452
01-Feb 10:00 Korutopi-dir JobId 18455: No prior or suitable Full backup found in catalog. Doing FULL backup.
01-Feb 10:00 Korutopi-dir JobId 18455: Start Backup JobId 18455, Job=Thorfinn-general-data.2017-02-01_10.00.00_24
01-Feb 10:00 Korutopi-dir JobId 18455: Error: tls.c:92 Error with certificate at depth: 0, issuer = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=DuckCorp Backup CA/emailAddress=admin@duckcorp.org, subject = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=korutopi.duckcorp.org/emailAddress=admin@duckcorp.org, ERR=10:certificate has expired
01-Feb 10:00 Korutopi-dir JobId 18455: Error: openssl.c:86 Connect failure: ERR=error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
01-Feb 10:00 Korutopi-dir JobId 18455: Fatal error: TLS negotiation failed with SD at "korutopi.duckcorp.org:30003"
01-Feb 10:00 Korutopi-dir JobId 18455: Error: Bacula Korutopi-dir 5.2.6 (21Feb12):
Build OS: x86_64-pc-linux-gnu debian jessie/sid
JobId: 18455
Job: Thorfinn-general-data.2017-02-01_10.00.00_24
Backup Level: Full (upgraded from Incremental)
Client: "Thorfinn-fd" 5.2.6 (21Feb12) x86_64-pc-linux-gnu,debian,jessie/sid
FileSet: "GeneralData Set" 2012-06-24 14:00:00
Pool: "GeneralData-Full" (From Job FullPool override)
Catalog: "DcCatalog" (From Client resource)
Storage: "File" (From Pool resource)
Scheduled time: 01-Feb-2017 10:00:00
Start time: 01-Feb-2017 10:00:24
End time: 01-Feb-2017 10:00:35
Elapsed time: 11 secs
Priority: 50
FD Files Written: 0
SD Files Written: 0
FD Bytes Written: 0 (0 B)
SD Bytes Written: 0 (0 B)
Rate: 0.0 KB/s
Software Compression: None
VSS: no
Encryption: no
Accurate: yes
Volume name(s):
Volume Session Id: 0
Volume Session Time: 0
Last Volume Bytes: 0 (0 B)
Non-fatal FD errors: 2
SD Errors: 0
FD termination status:
SD termination status:
Termination: *** Backup Error ***
01-Feb 10:00 Korutopi-dir JobId 18455: Rescheduled Job Thorfinn-general-data.2017-02-01_10.00.00_24 at 01-Feb-2017 10:00 to re-run in 3600 seconds (01-Feb-2017 11:00).
01-Feb 10:00 Korutopi-dir JobId 18455: Job Thorfinn-general-data.2017-02-01_10.00.00_24 waiting 3600 seconds for scheduled start time.
01-Feb 11:00 Korutopi-dir JobId 18455: Start Backup JobId 18455, Job=Thorfinn-general-data.2017-02-01_10.00.00_24
01-Feb 11:00 Korutopi-dir JobId 18455: Error: tls.c:92 Error with certificate at depth: 0, issuer = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=DuckCorp Backup CA/emailAddress=admin@duckcorp.org, subject = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=korutopi.duckcorp.org/emailAddress=admin@duckcorp.org, ERR=10:certificate has expired
01-Feb 11:00 Korutopi-dir JobId 18455: Error: openssl.c:86 Connect failure: ERR=error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
01-Feb 11:00 Korutopi-dir JobId 18455: Fatal error: TLS negotiation failed with SD at "korutopi.duckcorp.org:30003"
01-Feb 11:00 Korutopi-dir JobId 18455: Error: Bacula Korutopi-dir 5.2.6 (21Feb12):
Build OS: x86_64-pc-linux-gnu debian jessie/sid
JobId: 18455
Job: Thorfinn-general-data.2017-02-01_10.00.00_24
Backup Level: Full (upgraded from Incremental)
Client: "Thorfinn-fd" 5.2.6 (21Feb12) x86_64-pc-linux-gnu,debian,jessie/sid
FileSet: "GeneralData Set" 2012-06-24 14:00:00
Pool: "GeneralData-Full" (From Job FullPool override)
Catalog: "DcCatalog" (From Client resource)
Storage: "File" (From Pool resource)
Scheduled time: 01-Feb-2017 10:00:00
Start time: 01-Feb-2017 11:00:40
End time: 01-Feb-2017 11:00:50
Elapsed time: 10 secs
Priority: 50
FD Files Written: 0
SD Files Written: 0
FD Bytes Written: 0 (0 B)
SD Bytes Written: 0 (0 B)
Rate: 0.0 KB/s
Software Compression: None
VSS: no
Encryption: no
Accurate: yes
Volume name(s):
Volume Session Id: 0
Volume Session Time: 0
Last Volume Bytes: 0 (0 B)
Non-fatal FD errors: 2
SD Errors: 0
FD termination status:
SD termination status:
Termination: *** Backup Error ***
01-Feb 11:00 Korutopi-dir JobId 18455: Rescheduled Job Thorfinn-general-data.2017-02-01_10.00.00_24 at 01-Feb-2017 11:00 to re-run in 3600 seconds (01-Feb-2017 12:00).
01-Feb 11:00 Korutopi-dir JobId 18455: Job Thorfinn-general-data.2017-02-01_10.00.00_24 waiting 3600 seconds for scheduled start time.
01-Feb 12:01 Korutopi-dir JobId 18455: Start Backup JobId 18455, Job=Thorfinn-general-data.2017-02-01_10.00.00_24
01-Feb 12:01 Korutopi-dir JobId 18455: Error: tls.c:92 Error with certificate at depth: 0, issuer = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=DuckCorp Backup CA/emailAddress=admin@duckcorp.org, subject = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=korutopi.duckcorp.org/emailAddress=admin@duckcorp.org, ERR=10:certificate has expired
01-Feb 12:01 Korutopi-dir JobId 18455: Error: openssl.c:86 Connect failure: ERR=error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
01-Feb 12:01 Korutopi-dir JobId 18455: Fatal error: TLS negotiation failed with SD at "korutopi.duckcorp.org:30003"
01-Feb 12:01 Korutopi-dir JobId 18455: Error: Bacula Korutopi-dir 5.2.6 (21Feb12):
Build OS: x86_64-pc-linux-gnu debian jessie/sid
JobId: 18455
Job: Thorfinn-general-data.2017-02-01_10.00.00_24
Backup Level: Full (upgraded from Incremental)
Client: "Thorfinn-fd" 5.2.6 (21Feb12) x86_64-pc-linux-gnu,debian,jessie/sid
FileSet: "GeneralData Set" 2012-06-24 14:00:00
Pool: "GeneralData-Full" (From Job FullPool override)
Catalog: "DcCatalog" (From Client resource)
Storage: "File" (From Pool resource)
Scheduled time: 01-Feb-2017 10:00:00
Start time: 01-Feb-2017 12:01:07
End time: 01-Feb-2017 12:01:19
Elapsed time: 12 secs
Priority: 50
FD Files Written: 0
SD Files Written: 0
FD Bytes Written: 0 (0 B)
SD Bytes Written: 0 (0 B)
Rate: 0.0 KB/s
Software Compression: None
VSS: no
Encryption: no
Accurate: yes
Volume name(s):
Volume Session Id: 0
Volume Session Time: 0
Last Volume Bytes: 0 (0 B)
Non-fatal FD errors: 2
SD Errors: 0
FD termination status:
SD termination status:
Termination: *** Backup Error ***
01-Feb 12:01 Korutopi-dir JobId 18455: Rescheduled Job Thorfinn-general-data.2017-02-01_10.00.00_24 at 01-Feb-2017 12:01 to re-run in 3600 seconds (01-Feb-2017 13:01).
01-Feb 12:01 Korutopi-dir JobId 18455: Job Thorfinn-general-data.2017-02-01_10.00.00_24 waiting 3600 seconds for scheduled start time.
01-Feb 13:01 Korutopi-dir JobId 18455: Start Backup JobId 18455, Job=Thorfinn-general-data.2017-02-01_10.00.00_24
01-Feb 13:01 Korutopi-dir JobId 18455: Error: tls.c:92 Error with certificate at depth: 0, issuer = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=DuckCorp Backup CA/emailAddress=admin@duckcorp.org, subject = /C=DL/ST=DuckLand/L=DuckCity/O=DuckCorp/OU=DuckCorp Backup Department/CN=korutopi.duckcorp.org/emailAddress=admin@duckcorp.org, ERR=10:certificate has expired
01-Feb 13:01 Korutopi-dir JobId 18455: Error: openssl.c:86 Connect failure: ERR=error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
01-Feb 13:01 Korutopi-dir JobId 18455: Fatal error: TLS negotiation failed with SD at "korutopi.duckcorp.org:30003"
01-Feb 13:01 Korutopi-dir JobId 18455: Error: Bacula Korutopi-dir 5.2.6 (21Feb12):
Build OS: x86_64-pc-linux-gnu debian jessie/sid
JobId: 18455
Job: Thorfinn-general-data.2017-02-01_10.00.00_24
Backup Level: Full (upgraded from Incremental)
Client: "Thorfinn-fd" 5.2.6 (21Feb12) x86_64-pc-linux-gnu,debian,jessie/sid
FileSet: "GeneralData Set" 2012-06-24 14:00:00
Pool: "GeneralData-Full" (From Job FullPool override)
Catalog: "DcCatalog" (From Client resource)
Storage: "File" (From Pool resource)
Scheduled time: 01-Feb-2017 10:00:00
Start time: 01-Feb-2017 13:01:21
End time: 01-Feb-2017 13:01:31
Elapsed time: 10 secs
Priority: 50
FD Files Written: 0
SD Files Written: 0
FD Bytes Written: 0 (0 B)
SD Bytes Written: 0 (0 B)
Rate: 0.0 KB/s
Software Compression: None
VSS: no
Encryption: no
Accurate: yes
Volume name(s):
Volume Session Id: 0
Volume Session Time: 0
Last Volume Bytes: 0 (0 B)
Non-fatal FD errors: 2
SD Errors: 0
FD termination status:
SD termination status:
Termination: *** Backup Error ***
</pre>
DuckCorp Infrastructure - Enhancement #460 (Resolved): SSL/TLS: check ciphers
https://projects.duckcorp.org/issues/460
2015-07-09T00:02:15Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
Checks:
<ul>
<li>NULL,EXPORT,LOW,3DES,aNULL must be disabled</li>
<li>RC4 must be disabled</li>
<li>SSLv2,SSLv3 must be disabled</li>
<li>TLSv1.1,TLSv1.2 must be enabled</li>
<li>PFS must be enabled</li>
</ul>
<ul>
<li>SSL Compression must be disabled</li>
</ul>
Configuration updates needed:
<ul>
<li>Postgresql (default conf used <code>HIGH:MEDIUM:+3DES:!aNULL</code>)</li>
<li>Apache (<code>RSA:!EXP:!NULL:+HIGH:+MEDIUM:-LOW</code>)</li>
</ul>
<ul>
<li>References
<ul>
<li><a class="external" href="https://community.openvpn.net/openvpn/wiki/Hardening#Useof--tls-cipher">https://community.openvpn.net/openvpn/wiki/Hardening#Useof--tls-cipher</a></li>
<li><a class="external" href="https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/">https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/</a></li>
<li><a class="external" href="http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-secrecy.html">http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-secrecy.html</a></li>
<li><a class="external" href="https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations">https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations</a></li>
<li><a class="external" href="https://github.com/ioerror/duraconf">https://github.com/ioerror/duraconf</a></li>
</ul>
</li>
<li>Tools:
<ul>
<li><a class="external" href="https://github.com/jvehent/tlsnames/blob/master/convert_openssl_to_gnutls.sh">https://github.com/jvehent/tlsnames/blob/master/convert_openssl_to_gnutls.sh</a></li>
</ul></li>
</ul>
DuckCorp Infrastructure - Bug #451 (Rejected): postfix and LDAP errors: ldap:/etc/postfix/ldap_re...
https://projects.duckcorp.org/issues/451
2015-05-21T10:44:27Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<blockquote>
<p>zgrep -A 1 "dict_ldap_lookup: Search error -5: Timed out" /var/log/syslog* |sort -rn</p>
</blockquote>
<pre>
/var/log/syslog.7.gz:May 15 06:32:49 orfeo postfix/cleanup[25851]: warning: ldap:/etc/postfix/ldap_redirs.cf lookup error for "arnau@duckcorp.dl"
/var/log/syslog.7.gz:May 15 06:32:49 orfeo postfix/cleanup[25851]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.6.gz:May 16 06:42:58 orfeo postfix/cleanup[7985]: warning: ldap:/etc/postfix/ldap_redirs.cf lookup error for "duck@duckcorp.dl"
/var/log/syslog.6.gz:May 16 06:42:58 orfeo postfix/cleanup[7985]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.3.gz:May 19 06:34:24 orfeo postfix/trivial-rewrite[25111]: warning: ldap:/etc/postfix/ldap_virtual_domains.cf: table lookup problem
/var/log/syslog.3.gz:May 19 06:34:24 orfeo postfix/trivial-rewrite[25111]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.2.gz:May 20 06:32:51 orfeo postfix/trivial-rewrite[3709]: warning: ldap:/etc/postfix/ldap_virtual_domains.cf: table lookup problem
/var/log/syslog.2.gz:May 20 06:32:51 orfeo postfix/trivial-rewrite[3709]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.1:May 21 06:42:36 orfeo postfix/trivial-rewrite[21147]: warning: ldap:/etc/postfix/ldap_virtual_domains.cf: table lookup problem
/var/log/syslog.1:May 21 06:42:36 orfeo postfix/trivial-rewrite[21147]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.1:May 21 06:32:21 orfeo postfix/cleanup[16995]: warning: ldap:/etc/postfix/ldap_redirs.cf lookup error for "Duck@duckcorp.org"
/var/log/syslog.1:May 21 06:32:21 orfeo postfix/cleanup[16995]: warning: dict_ldap_lookup: Search error -5: Timed out
/var/log/syslog.1:May 21 06:28:55 orfeo postfix/trivial-rewrite[16155]: warning: ldap:/etc/postfix/ldap_virtual_domains.cf: table lookup problem
/var/log/syslog.1:May 21 06:28:55 orfeo postfix/trivial-rewrite[16155]: warning: dict_ldap_lookup: Search error -5: Timed out
</pre>
<p>All errors occur around 06:30am. LDAP server is on the same host. <code>slapd</code> process is running since <code>Apr06 12:51</code>.</p>
Bip - Bug #431 (New): bip is leaking file descriptors
https://projects.duckcorp.org/issues/431
2015-01-15T02:01:19Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>fran wrote:</p>
<blockquote>
<p>bip is leaking file descriptors on my server, and the fix is pretty easy: on connection.c, on read_socket, whenever read returns <1 and errno is different to EAGAIN and EINTR, the socket MUST be closed <br />because read will not return 0 on the following iterations of select (cause it's not added to the read fd_set after that), plus after read failing with fatal error it keeps returning -1</p>
</blockquote>
Bip - Enhancement #270 (Resolved): GIT: use signed tag
https://projects.duckcorp.org/issues/270
2012-01-10T01:53:49Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Signed tags must be used.</p>
Bip - Bug #269 (Resolved): buffer overflow when number of open file descriptors >= FD_SETSIZE
https://projects.duckcorp.org/issues/269
2012-01-07T10:28:05Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<p>Reported by Julien Tinnes, thanks to him!</p>
<p>Bip doesn't check if fd is equal or larger than FD_SETSIZE.</p>
<p>From select man page:</p>
<blockquote>
<p>Executing FD_CLR() or FD_SET() with a value of fd that is negative or is equal to or larger than FD_SETSIZE will result in undefined behavior.</p>
</blockquote>
Bip - Bug #186 (New): Bip crash after using "/QUOTE BIP TRUST OK" on a new connection
https://projects.duckcorp.org/issues/186
2011-01-18T02:29:38Z
Pierre-Louis Bonicoli
pierre-louis.bonicoli@ir5.eu
<a name="How-to-reproduce"></a>
<h1 >How to reproduce:<a href="#How-to-reproduce" class="wiki-anchor">¶</a></h1>
<ol>
<li>/etc/bip.conf: add a new ssl connection </li>
<li>restart bip (Debian: <em>/etc/init.d/bip restart</em>)</li>
<li>use <em>/QUOTE BIP TRUST OK</em><br /> # all client connections are disconnected</li>
</ol>
<a name="Logs"></a>
<h1 >Logs<a href="#Logs" class="wiki-anchor">¶</a></h1>
<a name="Client-logs"></a>
<h2 >Client logs:<a href="#Client-logs" class="wiki-anchor">¶</a></h2>
<blockquote>
<p>03:12:08 oftc | irc: connecting to server irc-bouncer/7778...<br />03:12:08 oftc | irc: connected to irc-bouncer<br />03:12:08 oftc -- | b.i.p (b.i.p): This server SSL certificate was not accepted because it is not in your store of trusted certificates:<br />03:12:08 oftc -- | b.i.p (b.i.p): Subject: /C=US/ST=Indiana/L=Indianapolis/O=Software in the Public Interest/OU=hostmaster/CN=Certificate Authority/emailAddress=<a class="email" href="mailto:hostmaster@spi-inc.org">hostmaster@spi-inc.org</a><br />03:12:08 oftc -- | b.i.p (b.i.p): Issuer: /C=US/ST=Indiana/L=Indianapolis/O=Software in the Public Interest/OU=hostmaster/CN=Certificate Authority/emailAddress=<a class="email" href="mailto:hostmaster@spi-inc.org">hostmaster@spi-inc.org</a><br />03:12:08 oftc -- | b.i.p (b.i.p): MD5 fingerprint: 2A:47:9F:60:BB:83:74:6F:01:03:D7:0B:0D:F6:0D:78<br />03:12:08 oftc -- | b.i.p (b.i.p): WARNING: if you've already trusted a certificate for this server before, that probably means it has changed.<br />03:12:08 oftc -- | b.i.p (b.i.p): If so, YOU MAY BE SUBJECT OF A MAN-IN-THE-MIDDLE ATTACK! PLEASE DON'T TRUST THIS CERTIFICATE IF YOU'RE NOT SURE THIS IS NOT THE CASE.<br />03:12:08 oftc -- | b.i.p (b.i.p): Type /QUOTE BIP TRUST OK to trust this certificate, /QUOTE BIP TRUST NO to discard it.<br />03:12:20 oftc -- | irc.bip.net (irc.bip.net): ==== Certificate now trusted.<br />03:12:20 oftc -- | irc.bip.net (irc.bip.net): No more certificates waiting awaiting user trust, thanks!<br />03:12:20 oftc -- | irc.bip.net (irc.bip.net): If the certificate is trusted, bip should be able to connect to the server on the next retry. Please wait a while and try connecting your client again.</p>
</blockquote>
<a name="Bip-logs"></a>
<h2 >Bip logs:<a href="#Bip-logs" class="wiki-anchor">¶</a></h2>
<blockquote>
<p>18-01-2011 03:12:12 ERROR: No certificate in SSL write_socket<br />18-01-2011 03:12:12 ERROR: SSL cert check failed at depth=3: certificate rejected (28)<br />18-01-2011 03:12:12 ERROR: Certificate check failed: certificate rejected (28)!<br />18-01-2011 03:12:12 ERROR: Error on fd 31 (state 9)<br />18-01-2011 03:12:12 ERROR: [oftc] read_lines error, closing...<br />18-01-2011 03:12:12 ERROR: [oftc] reconnecting in 240 seconds<br />18-01-2011 03:12:54 ERROR: No certificate in SSL write_socket</p>
</blockquote>