00:33 | <gdi2k_> ege, if you're still around, LTSP is best suited for the LAN. Try NX-based stuff for WAN. I use X2Go personally and it's easy to set up and works really well over LAN. You can google it
| |
00:38 | gadi has joined IRC (gadi!~gadi@pool-108-21-187-8.nycmny.fios.verizon.net) | |
00:41 | <gdi2k_> *works well over WAN I meant to say
| |
00:52 | andygraybeal has left IRC (andygraybeal!~andy@li613-146.members.linode.com, Read error: Operation timed out) | |
01:00 | Phantomas has joined IRC (Phantomas!~Phantomas@ubuntu/member/phantomas) | |
01:05 | PhoenixSTF has joined IRC (PhoenixSTF!~rudiservo@bl11-152-72.dsl.telepac.pt) | |
01:09 | andygraybeal has joined IRC (andygraybeal!~andy@h51.204.130.174.dynamic.ip.windstream.net) | |
01:31 | Phantomas has left IRC (Phantomas!~Phantomas@ubuntu/member/phantomas, Ping timeout: 240 seconds) | |
02:23 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Ping timeout: 240 seconds) | |
02:25 | vagrantc has left IRC (vagrantc!~vagrant@freegeek/vagrantc, Quit: leaving) | |
02:43 | monkeydiver has left IRC (monkeydiver!~de3legged@pool-71-187-57-101.nwrknj.fios.verizon.net, Quit: This computer has gone to sleep) | |
02:44 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
03:11 | ltsp` has joined IRC (ltsp`!bot@ltsp.org) | |
03:11 | -holmes.freenode.net- [freenode-info] channel flooding and no channel staff around to help? Please check with freenode support: http://freenode.net/faq.shtml#gettinghelp | |
04:05 | |Paradox| has joined IRC (|Paradox|!iamparadox@c-24-125-247-216.hsd1.va.comcast.net) | |
04:16 | ltsp has joined IRC (ltsp!bot@ltsp.org) | |
05:06 | adrianorg has left IRC (adrianorg!~adrianorg@179.187.26.157.dynamic.adsl.gvt.net.br, Ping timeout: 252 seconds) | |
05:07 | adrianorg has joined IRC (adrianorg!~adrianorg@179.187.26.157.dynamic.adsl.gvt.net.br) | |
06:02 | Ark74 has joined IRC (Ark74!~Ark74@189.214.42.128.cable.dyn.cableonline.com.mx) | |
07:10 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.63.163, Ping timeout: 240 seconds) | |
07:16 | Ark74 has left IRC (Ark74!~Ark74@189.214.42.128.cable.dyn.cableonline.com.mx, Quit: Saliendo) | |
07:41 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.21.12) | |
08:03 | bennabiy has left IRC (bennabiy!~Thunderbi@75-138-124-168.dhcp.ahvl.nc.charter.com, Ping timeout: 240 seconds) | |
08:04 | bennabiy has joined IRC (bennabiy!~Thunderbi@75-138-124-168.dhcp.ahvl.nc.charter.com) | |
08:05 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Ping timeout: 268 seconds) | |
08:17 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
08:22 | Phantomas has joined IRC (Phantomas!~Phantomas@ubuntu/member/phantomas) | |
09:13 | freedomrun has left IRC (freedomrun!~freedomru@unaffiliated/freedomrun, Ping timeout: 268 seconds) | |
09:26 | freedomrun has joined IRC (freedomrun!~freedomru@unaffiliated/freedomrun) | |
09:39 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.21.12, Ping timeout: 240 seconds) | |
10:02 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Ping timeout: 255 seconds) | |
10:04 | khildin has joined IRC (khildin!~khildin@ip-213-49-116-139.dsl.scarlet.be) | |
10:05 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
10:28 | freedomrun has left IRC (freedomrun!~freedomru@unaffiliated/freedomrun, Quit: So long and thanks for all the fish.) | |
11:36 | <ege> Hi gdi2k_, thanks for your answer.
| |
11:36 | I found a lot NX stuff but that was all really old
| |
11:37 | I'll have a look at X2Go
| |
11:45 | thanks, looks promising and had a release last year and not only in 2008 like others :)
| |
12:00 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.63.163) | |
12:16 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.63.163, Ping timeout: 240 seconds) | |
13:34 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.21.12) | |
13:37 | khildin has left IRC (khildin!~khildin@ip-213-49-116-139.dsl.scarlet.be, Remote host closed the connection) | |
13:49 | monkeydiver has joined IRC (monkeydiver!~de3legged@static-71-245-53-226.sctnpa.east.verizon.net) | |
14:01 | telex has left IRC (telex!~telex@freeshell.de, Remote host closed the connection) | |
14:02 | telex has joined IRC (telex!~telex@freeshell.de) | |
14:45 | adrianorg has left IRC (adrianorg!~adrianorg@179.187.26.157.dynamic.adsl.gvt.net.br, Ping timeout: 255 seconds) | |
14:46 | adrianorg has joined IRC (adrianorg!~adrianorg@177.134.57.166) | |
15:17 | BrotherOdd has joined IRC (BrotherOdd!~Brother@173-21-43-27.client.mchsi.com) | |
15:59 | monkeydiver has left IRC (monkeydiver!~de3legged@static-71-245-53-226.sctnpa.east.verizon.net, Quit: Leaving) | |
18:00 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.21.12, Ping timeout: 240 seconds) | |
18:03 | alkisg has joined IRC (alkisg!~alkisg@ubuntu/member/alkisg) | |
18:05 | vagrantc has joined IRC (vagrantc!~vagrant@freegeek/vagrantc) | |
18:20 | alkisg has left IRC (alkisg!~alkisg@ubuntu/member/alkisg, Remote host closed the connection) | |
18:28 | Phantomas has left IRC (Phantomas!~Phantomas@ubuntu/member/phantomas, Quit: Leaving.) | |
18:52 | BrotherOdd has left IRC (BrotherOdd!~Brother@173-21-43-27.client.mchsi.com, Quit: Leaving) | |
19:44 | aruiz has joined IRC (aruiz!~aruiz@ip-94-112-67-211.net.upcbroadband.cz) | |
19:45 | <aruiz> hello there, I want to decouple the main dhcp/tftp LTSP server from the desktop provider, can I run ldm in one machine and the rest of the services in another one?
| |
19:47 | <vagrantc> the short answer is yes
| |
19:47 | * aruiz is afraid of the long answer now | |
19:47 | <vagrantc> on debian/ubuntu you want to install the ldm-server package on the server(s) you want to serve applications
| |
19:48 | <aruiz> vagrantc, how do I tell the clients the server is there?
| |
19:48 | <vagrantc> technically, ldm runs on the thin client :)
| |
19:48 | <aruiz> that's the bit I'm struggling with
| |
19:48 | <vagrantc> aruiz: set LDM_SERVER in lts.conf
| |
19:48 | you'll also need to get the ssh keys from the server moved over
| |
19:48 | <Hyperbyte> aruiz, out of curiosity... why do you want this?
| |
19:48 | * vagrantc has used that sort of setup for ages | |
19:49 | <vagrantc> with one LTSP server, you can have numerous application servers.
| |
19:49 | <aruiz> Hyperbyte, I want to split network services from the main desktop provider
| |
19:50 | <vagrantc> it also provides some measure of isolation ... the rootfs not being hosted on the same machine as the GUI apps, which have far more security vulnerabilities
| |
19:50 | <aruiz> Hyperbyte, it's not the first time I need to upgrade the desktop system but I don't want to because it may break the whole setup
| |
19:50 | so say, I need to chose between the latest LibreOffice and a reliable system
| |
19:50 | :-)
| |
19:50 | I don't want to make that choice
| |
19:50 | so for now I want to put all the network services (CUPS, DHCP, tftpboot, LTSP images) in a LXC container
| |
19:51 | it also helps when it comes to backing up the system
| |
19:51 | if the system crashes
| |
19:51 | I reinstall a vanilla ubuntu, deploy that LXC and everything is working and configured again
| |
19:51 | <Hyperbyte> Right, you want to move nbd too... then it makes more sense.
| |
19:51 | <aruiz> Hyperbyte, yeah
| |
19:51 | <Hyperbyte> I actually use virtual machines for this purpose. :)
| |
19:51 | <aruiz> basically the desktop should only serve... the desktop :-) (and ssh too of course)
| |
19:52 | Hyperbyte, I have a Windows VM too, but VMs have a lot of overhead compared to containers
| |
19:52 | <vagrantc> oh yes, i was assuming splitting all the non-desktop stuff to a separate server
| |
19:52 | <aruiz> VirtualBox is not 100% reliable in my experience, and I don't want a hybrid KVM+VBox setup :-)
| |
19:52 | <vagrantc> splitting tftp and rootfs is a pain.
| |
19:53 | <aruiz> vagrantc, na, I basically want everything LTSP in that container, but the desktop
| |
19:53 | <vagrantc> right, that's simple.
| |
19:53 | <Hyperbyte> I disagree actually. With kvm-qemu there's not so much overhead I think. At least I haven't ran into any problems running a full thin client server virtualized.
| |
19:53 | <aruiz> vagrantc, so installing ldm-server and setting LDM_SERVER should do the trick right?
| |
19:53 | <Hyperbyte> Anyway, different discussion... :-)
| |
19:54 | <vagrantc> aruiz: and copying the ssh keys to the LTSP server
| |
19:54 | <aruiz> vagrantc, the public ones?
| |
19:55 | <vagrantc> aruiz: the lazy insecure way is: ltsp-update-sshkeys --export SERVER > /etc/ltsp/ssh_known_hosts.SERVER
| |
19:55 | yes, the public keys
| |
19:55 | and then ltsp-update-sshkeys (and possibly ltsp-update-image, if you use NBD)
| |
19:56 | oh, wait.
| |
19:57 | ltsp-update-sshkeys --export /etc/ltsp/ssh_known_hosts.SERVER SERVER
| |
19:57 | or you could even leave out --export ...
| |
19:57 | i always did it manually
| |
19:58 | <aruiz> so wait... this is the bit I don't understand
| |
19:58 | <vagrantc> aruiz: you need the application server's public ssh host keys
| |
19:58 | <aruiz> I should run ltsp-update-sshkeys on the container (where the ltsp services are, except for the desktop)
| |
19:58 | but what do I do on the ldm-server?
| |
19:58 | right, but are those root ssh keys?
| |
19:58 | <vagrantc> you veryify that ltsp-update-sshkeys grabbed the right keys
| |
19:59 | <aruiz> or is this run by a particular user?
| |
19:59 | <vagrantc> ssh host keys
| |
19:59 | <aruiz> ah the host keys, gotcha
| |
19:59 | <vagrantc> you'll run it as root, yeah.
| |
19:59 | <aruiz> got it,
| |
19:59 | <vagrantc> it basically uses ssh-keyscan to download the keys from the server
| |
20:04 | aruiz: you can manually create them, you just copy the /etc/ssh/ssh_host*.pub into a file, and prepend each line with the server name.
| |
20:07 | you'll also need name resolution to work properly, or use "HOSTS_xx=appserver1 192.168.0.5"
| |
20:13 | * vagrantc waves | |
20:13 | vagrantc has left IRC (vagrantc!~vagrant@freegeek/vagrantc, Quit: leaving) | |
20:44 | riddle has left IRC (riddle!riddle@us.yunix.net, Disconnected by services) | |
20:44 | riddle has joined IRC (riddle!riddle@us.yunix.net) | |
20:48 | Ryan52 has left IRC (Ryan52!~ryan52@freegeek/ryan52, *.net *.split) | |
20:48 | aruiz has left IRC (aruiz!~aruiz@ip-94-112-67-211.net.upcbroadband.cz, *.net *.split) | |
20:48 | Ryan52 has joined IRC (Ryan52!~ryan52@freegeek/ryan52) | |
20:55 | aruiz has joined IRC (aruiz!~aruiz@ip-94-112-67-211.net.upcbroadband.cz) | |
21:12 | aruiz has left IRC (aruiz!~aruiz@ip-94-112-67-211.net.upcbroadband.cz, Ping timeout: 253 seconds) | |
23:53 | mahovkirill has joined IRC (mahovkirill!~mahovkiri@195.74.88.67) | |