00:43 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
00:47 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 240 seconds) | |
00:49 | epoptes_user3 has left IRC (epoptes_user3!c9452078@gateway/web/freenode/ip.201.69.32.120, Ping timeout: 240 seconds) | |
01:44 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
01:46 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Read error: No route to host) | |
02:28 | andygraybeal has joined IRC (andygraybeal!~andy@h212.217.213.151.dynamic.ip.windstream.net) | |
02:47 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
02:52 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 276 seconds) | |
03:34 | Ark74 has joined IRC (Ark74!~Ark74@189.214.42.128) | |
03:42 | monkwitdafunk has joined IRC (monkwitdafunk!~AndChat49@24.114.43.17) | |
03:48 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
03:53 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 276 seconds) | |
04:21 | Ark74 has left IRC (Ark74!~Ark74@189.214.42.128, Quit: Saliendo) | |
04:48 | DanSwano has left IRC (DanSwano!~danswano@93.81.234.22, Ping timeout: 240 seconds) | |
04:49 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
04:54 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 276 seconds) | |
05:46 | khildin has joined IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be) | |
05:47 | vmlintu has joined IRC (vmlintu!~vmlintu@nblzone-240-143.nblnetworks.fi) | |
05:50 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
05:54 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 276 seconds) | |
06:12 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.63.163, Ping timeout: 258 seconds) | |
06:16 | monkwitdafunk has left IRC (monkwitdafunk!~AndChat49@24.114.43.17, Ping timeout: 255 seconds) | |
06:21 | adrianorg has left IRC (adrianorg!~adrianorg@177.132.222.20, Ping timeout: 258 seconds) | |
06:23 | adrianorg has joined IRC (adrianorg!~adrianorg@177.132.222.20) | |
06:28 | alexxtasi has joined IRC (alexxtasi!~alex@unaffiliated/alexxtasi) | |
06:31 | flo1546796 has joined IRC (flo1546796!~flo154679@2001:660:5001:156:1401:ed28:9526:fdea) | |
06:31 | flo1546796 has joined IRC (flo1546796!~flo154679@unaffiliated/flo1546796) | |
07:12 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Ping timeout: 265 seconds) | |
07:13 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
07:18 | DanSwano has joined IRC (DanSwano!~danswano@93.81.234.22) | |
07:28 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.71.254) | |
08:00 | bennabiy has left IRC (bennabiy!~Thunderbi@96-37-209-0.dhcp.leds.al.charter.com, Read error: Connection reset by peer) | |
08:03 | bennabiy has joined IRC (bennabiy!~Thunderbi@96-37-209-0.dhcp.leds.al.charter.com) | |
08:30 | gdi2k has left IRC (gdi2k!~gdi2k@222.127.49.42, Ping timeout: 255 seconds) | |
08:42 | gdi2k has joined IRC (gdi2k!~gdi2k@192.161.56.179) | |
08:43 | Grembler has joined IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net) | |
08:55 | lycourgus has joined IRC (lycourgus!c23fefeb@gateway/web/freenode/ip.194.63.239.235) | |
08:56 | <lycourgus> Καλημερα, εχω το εξης προβλημα:
| |
08:58 | | |
09:11 | ακυρη η ερωτηση.. ειχα ξεχασει να περασω τους κανονες στο iptables. Sorry
| |
09:13 | stgraber has left IRC (stgraber!~stgraber@ubuntu/member/stgraber, Ping timeout: 252 seconds) | |
09:20 | stgraber has joined IRC (stgraber!~stgraber@ubuntu/member/stgraber) | |
09:22 | lycourgus has left IRC (lycourgus!c23fefeb@gateway/web/freenode/ip.194.63.239.235, Quit: Page closed) | |
09:48 | <ogra_> thats all greek to me
| |
09:49 | :)
| |
09:58 | <MrV> :)
| |
10:04 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.71.254, Ping timeout: 258 seconds) | |
10:11 | work_alkisg is now known as alkisg | |
10:11 | mrdemc has joined IRC (mrdemc!5f61578a@gateway/web/freenode/ip.95.97.87.138) | |
10:11 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.71.254) | |
10:14 | gdi2k has left IRC (gdi2k!~gdi2k@192.161.56.179, Ping timeout: 255 seconds) | |
10:31 | gdi2k has joined IRC (gdi2k!~gdi2k@222.127.49.42) | |
10:48 | mrdemc has left IRC (mrdemc!5f61578a@gateway/web/freenode/ip.95.97.87.138, Ping timeout: 240 seconds) | |
11:03 | alkisg is now known as work_alkisg | |
11:18 | lliurex has joined IRC (lliurex!c3391366@gateway/web/freenode/ip.195.57.19.102) | |
12:11 | work_alkisg has left IRC (work_alkisg!~alkisg@plinet.ioa.sch.gr, Ping timeout: 252 seconds) | |
12:23 | flo1546796 has left IRC (flo1546796!~flo154679@unaffiliated/flo1546796, Quit: Quitte) | |
12:38 | Faith_ has joined IRC (Faith_!~paty@143.107.231.49) | |
12:57 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
13:07 | Grembler has left IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net, Quit: I Leave) | |
13:15 | <bennabiy> alkisg: that is funny
| |
13:20 | telex has left IRC (telex!~telex@freeshell.de, Remote host closed the connection) | |
13:22 | telex has joined IRC (telex!~telex@freeshell.de) | |
13:25 | <bennabiy> alkisg, vagrantc: question for you... what version of glibc are we using in general. I think support for $5$ and $6$ (SHA-2 hashes) came in 2.7 in glibc2
| |
13:25 | otherwise we are limited to DES or MD5
| |
13:56 | Trusty ships 2.19 or something like that...
| |
13:56 | only reason I asked is because the crypt.h looked like it only supported the two options..
| |
14:06 | <Hyperbyte> On client startup, I get: "Negotation: ..Error: Server closed connection" Next it drops to busybox.
| |
14:07 | I have no idea why the nbd server closes the connection.
| |
14:11 | <bennabiy> did you reboot your server recently?
| |
14:11 | <Hyperbyte> Yessir.
| |
14:12 | <bennabiy> I have found that when I reboot, I usually have to give nbd a swift-kick to get it working right
| |
14:12 | usually sudo service nbd-server force-reload works
| |
14:14 | <Hyperbyte> Done that a few times now, doesn't change anything.
| |
14:16 | Tried mounting manually from BusyBox... same error.
| |
14:25 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Remote host closed the connection) | |
14:25 | alexxtasi has left IRC (alexxtasi!~alex@unaffiliated/alexxtasi) | |
14:26 | <Hyperbyte> syslog says "nbd_server[5313]: Negotiation failed/8a: Requested export not found"
| |
14:26 | Which I personally find somewhat troubling, as the config seems to be in order...
| |
14:27 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
14:27 | cyberorg_ has joined IRC (cyberorg_!~cyberorg@opensuse/member/Cyberorg) | |
14:27 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Read error: Connection reset by peer) | |
14:28 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
14:29 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
14:32 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
14:41 | <bennabiy> is this a new install?
| |
14:41 | Hyperbyte: ^
| |
14:41 | Also, which distro / version are you using
| |
14:41 | ?
| |
14:57 | <Hyperbyte> Hrm, seems /etc/nbd-server/conf.d/ltsp_i386.conf had wrong [name] on top of the file. This is an upgrade from 12.04 to 14.04. I've rebooted the server since the upgrade though, not sure why it's acting up now.
| |
14:57 | Anyway... fixed.
| |
15:08 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.71.254, Ping timeout: 252 seconds) | |
15:24 | <bennabiy> great.
| |
15:27 | khildin has left IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be, Ping timeout: 255 seconds) | |
15:43 | vagrantc has joined IRC (vagrantc!~vagrant@freegeek/vagrantc) | |
15:50 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.21.12) | |
15:51 | khildin has joined IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be) | |
15:56 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Remote host closed the connection) | |
16:00 | mealstrom has left IRC (mealstrom!~Thunderbi@46.63.21.12, Read error: Connection reset by peer) | |
16:12 | mgariepy has left IRC (mgariepy!mgariepy@ubuntu/member/mgariepy, Ping timeout: 240 seconds) | |
16:25 | khildin has left IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be, Ping timeout: 240 seconds) | |
16:26 | mgariepy has joined IRC (mgariepy!mgariepy@ubuntu/member/mgariepy) | |
16:27 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
16:28 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Quit: cyberorg) | |
16:31 | vmlintu has left IRC (vmlintu!~vmlintu@nblzone-240-143.nblnetworks.fi, Ping timeout: 265 seconds) | |
16:33 | Grembler has joined IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net) | |
16:33 | Ark74 has joined IRC (Ark74!~Ark74@187.185.66.134) | |
16:35 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Ping timeout: 258 seconds) | |
16:42 | <Ark74> hi!
| |
16:43 | F-GT has left IRC (F-GT!~phantom@ppp59-167-136-109.static.internode.on.net, Ping timeout: 240 seconds) | |
16:43 | <Ark74> guys, do you know if epoptes/vnc can resize the shared screen on clients?
| |
16:44 | let's say i have a bigger resolution on the server and some clients has a lower one
| |
16:45 | when sharing the screen it is bigger than the clients screen
| |
16:45 | (on fullscreen sharing)
| |
16:46 | <vagrantc> the obvious workaround is to resize the sending screen... dunno if something more elegant is possible.
| |
16:47 | shadowwraith has joined IRC (shadowwraith!806e4820@gateway/web/freenode/ip.128.110.72.32) | |
16:47 | <shadowwraith> test
| |
16:48 | any one know if there is a tutorial or read me that explains how to get LTSP working for CentOS 6.5?
| |
16:49 | <Ark74> mmm, i see
| |
16:50 | ok, thanks
| |
16:52 | Grembler has left IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net, Quit: I Leave) | |
16:53 | <shadowwraith> ok, well I'll let that simmer for a bit…I'll be hanging out here in the back ground
| |
16:55 | khildin has joined IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be) | |
16:56 | <Ark74> shadowwraith, good call, sorry im not a centos user :-P
| |
16:56 | F-GT has joined IRC (F-GT!~phantom@ppp59-167-136-109.static.internode.on.net) | |
16:57 | <shadowwraith> no worries, Ark
| |
17:01 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
17:02 | <shadowwraith> <---- looking for CentOS 6.5 users that use LTSP
| |
17:05 | * vagrantc wonders what happened to enslaver | |
17:06 | <vagrantc> enslaver implemented the "recent" redhat variants ... haven't seen em for a while
| |
17:07 | <shadowwraith> hmm..doesn't red hat use some kind of daemon systemd or something like that?
| |
17:09 | I think centos uses xinet so being a novice to regular user, I'm going to need some guidance
| |
17:09 | <ogra_> well, but he did it on some other derivative, no ?
| |
17:09 | EL something ?
| |
17:10 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
17:12 | <shadowwraith> I appreciate the feedback, unfortunately I think I'm drowning in ignorance. EL makes me think RHEL
| |
17:12 | championofcyrodi has joined IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net) | |
17:12 | <shadowwraith> my ignorance, not anyone elses
| |
17:13 | <championofcyrodi> So I've been trying to debug this keyring issue, and I think it may have to do with the way chrome attempts to access the keyring, and not the keyring itself: https://bugs.launchpad.net/ubuntu/+source/ltsp/+bug/1320982
| |
17:14 | The LTSP fat client is configured to use the PAM method for keyring unlocking: https://wiki.archlinux.org/index.php/GNOME_Keyring#PAM_method
| |
17:15 | And it seems to be working, because when doing $ env | grep keyring It seems as though the environment variables are pointing to an active keyring control file created in the /run folder.
| |
17:17 | But for some reason the gnome "Password and Keys" (seahorse?) application does not show a Password Keyring as available. So it is trying to create a new one when Google Chrome tries to access it.
| |
17:19 | [GuS] has joined IRC ([GuS]!~gustavo@213-117-16-190.fibertel.com.ar) | |
17:19 | [GuS] has joined IRC ([GuS]!~gustavo@unaffiliated/gus/x-663402) | |
17:19 | <Faith_> shadowwraith, did you see the k12linux project? they say it's for fedora, but in the site it appears to have a guide for centos 6
| |
17:20 | <championofcyrodi> CentOS 6 docs has an install guide for k12linux
| |
17:21 | Faith_: now if only i can find it again
| |
17:23 | <vagrantc> the RHEL stuff worked for centos and scientific linux, if i recall correctly...
| |
17:27 | <championofcyrodi> k12linux on CentOS 6 (From disklessworkstation.com) http://www.youtube.com/watch?v=91fuA0nwXAs
| |
17:33 | vmlintu has joined IRC (vmlintu!~vmlintu@83.145.240.143) | |
17:36 | championofcyrodi has left IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net, Quit: Leaving.) | |
17:42 | championofcyrodi has joined IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net) | |
17:43 | <bennabiy> vagrantc: How secure / paranoid do we want to be with the password hash strength? It is a one time key, reseeded before each use so even if the password is captured over and over, the seed will keep changing as well
| |
17:44 | <championofcyrodi> Interesting. I logged into the LTSP server, Ran 'seahorse' as my user, and was able to create a default keyring. However, now when chrome loads running on the thick client, it recognizing that there is a default keyring, prompts me for the password, but hangs when trying to unlock.
| |
17:46 | also creating thousands of keyring.temp files while the daemon is running.
| |
17:47 | <vagrantc> bennabiy: it's not really a one-time key... it's a hash of a passphrase
| |
17:53 | championofcyrodi has left IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net, Quit: Leaving.) | |
17:57 | Ark74 has left IRC (Ark74!~Ark74@187.185.66.134, Quit: Saliendo) | |
17:58 | championofcyrodi has joined IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net) | |
18:03 | <championofcyrodi> shadowwraith: let me know if you get k12linux working on CentOS 6.5, I may have to end up using it in the future.
| |
18:06 | <bennabiy> vagrantc: True. I more meant that the same phrase would not likely produce the same hash multiple times
| |
18:06 | But since the salt is included in the hash, I guess that does not matter...
| |
18:39 | alkisg has joined IRC (alkisg!~alkisg@ubuntu/member/alkisg) | |
18:48 | <alkisg> championofcyrodi: what are your differences from a default setup? E.g. using lightdm instead of ldm, maybe ldap, maybe nfs...?
| |
19:13 | <championofcyrodi> alkisg: I did not modify the defaults in regard to ldm/lightdm or nfs/sshfs/nbd. The only thing I have done is installed sssd, and created the configuration in /etc/sssd/sssd.conf to support LDAP authentication via PAM modules.
| |
19:14 | <alkisg> championofcyrodi: can you retry without that?
| |
19:14 | <championofcyrodi> I believe that when installing sssd, the sss-pam package updates /etc/nsswitch.conf and /etc/pam.d/ modules.
| |
19:15 | You mean try it with a user account that resides on the LTSP server itself?
| |
19:15 | (Local account)
| |
19:15 | <alkisg> That change is only on the server, right?
| |
19:15 | Yes, please try with a local account
| |
19:16 | <championofcyrodi> actually no. I installed sssd on the chroot as well.
| |
19:16 | <alkisg> I.e. basically I'm interested to see if the bug happens in an out-of-the box installation of ltsp in 14.04, or if it only affects sssd etc
| |
19:16 | <championofcyrodi> gotcha
| |
19:16 | <alkisg> LDM doesn't use PAM
| |
19:17 | <championofcyrodi> Let me try logging it with a local account and see what happens. brb.
| |
19:17 | championofcyrodi has left IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net, Quit: Leaving.) | |
19:23 | championofcyrodi has joined IRC (championofcyrodi!~championo@50-205-35-98-static.hfc.comcastbusiness.net) | |
19:24 | <championofcyrodi> alkisg: same result, http://imgur.com/MV59YEr,aXE23ng#0 http://imgur.com/MV59YEr,aXE23ng#1
| |
19:25 | You can see the spinner on the continue button in the first screen shot (#0)
| |
19:25 | <alkisg> championofcyrodi: the expected result is, that ldm won't unlock the keyring as it's not using PAM, but otherwise keyrings would work
| |
19:25 | I'll try locally with 14.04 in a bit, so we'll see if sssd is to blame.
| |
19:27 | <championofcyrodi> thank you. I'm not sure if the keyring is 100% required, but i know a lot of the users want to use google chrome, which prompts for the keyring. If sssd is to blame, I am curious as to my options. 1.) disable keyring or 2.) use alternative to sssd. Ultimately I am hoping to use LTSP with LDAP authentication so users can log in to their account on any thick client.
| |
19:27 | <alkisg> You don't need to modify the chroot for that at all
| |
19:27 | The server can use whatever authentication you want; the chroot will use ldm/ssh
| |
19:28 | <championofcyrodi> Well, I'm also required to have the screens lock.
| |
19:28 | <alkisg> You can do that with remoteapps screensaver
| |
19:29 | <championofcyrodi> for security purposes. So i used xscreensaver which seems to authenticate with PAM
| |
19:29 | I'll try the remoteapps screensaver
| |
19:29 | if that works, I'll disable sssd from the chroot, and see if that resolves the keyring issue
| |
19:40 | <alkisg> championofcyrodi: it seems the problem is that gnome-keyring is using ~/.gnome2/keyrings/*temp* and that doesn't work with sshfs
| |
19:40 | Maybe it's a socket, didn't dig into it
| |
19:41 | If you e.g. create a dir in /run/user/1234/keyrings, with appropriate permissions, and symlink it to .gnome2/keyrings, then keyrings work fine
| |
19:41 | So the bug you filed at launchpad, should be against gnome-keyring or possibly sshfs, not against ltsp
| |
19:41 | Tell them to use a temp file under /run/user/1234
| |
19:42 | <vagrantc> well, /run/user isn't available everywhere...
| |
19:42 | <alkisg> It's their change, they should support it :D
| |
19:42 | <vagrantc> though hopefully will be soon? :)
| |
19:43 | heh
| |
19:43 | <alkisg> I don't think the problem existed before
| |
19:43 | I think they used /tmp/* before
| |
19:48 | <championofcyrodi> sorry, got "drive by" tasking... reading now responses now
| |
19:51 | when you say 'create a dir in /run/user/<uid>/keyrings" I assume you mean on the LTSP server, not the chroot?
| |
19:53 | <alkisg> In the chroot, just for testing that this solves the issue
| |
19:56 | <championofcyrodi> I see, /run/user does not exist, so you want me to create the path /run/user/<uid>/keyrings. Make sure permissions match what is on the LTSP server itself, and the symlink would be something like /run/user/1234/keyrings -> /home/<1234user>/.gnome2/keyrings ?
| |
19:57 | vmlintu has left IRC (vmlintu!~vmlintu@83.145.240.143, Ping timeout: 240 seconds) | |
20:00 | khildin has left IRC (khildin!~khildin@ip-213-49-116-80.dsl.scarlet.be, Ping timeout: 240 seconds) | |
20:03 | <alkisg> /run/user/<uid> should exist when a user has logged in to a fat client
| |
20:05 | xet7 has left IRC (xet7!~xet7@a88-112-147-81.elisa-laajakaista.fi, Quit: Lähdössä) | |
20:07 | <alkisg> Source gkm-transaction.c, line 276
| |
20:10 | There's a logic for "transations" there in gnome-keyring, which obviously fails on sshfs
| |
20:27 | <championofcyrodi> there is some ambiguity going on here with the which /run/user/<uid> path to modify. My understanding is that there are 3 filesystems at play:
| |
20:27 | 1.) The LTSP Server itself, where user home folders reside.
| |
20:27 | 2.) the chroot image, which is accessed with 'sudo chroot /opt/ltsp/amd64' and updated with ltsp-update-image
| |
20:27 | 3.) the unionfs that is created when I log into the thick client itself, which combines the ltsp image with the ltsp server home folder.
| |
20:28 | <alkisg> championofcyrodi: forget about ltsp
| |
20:29 | Use whatever local installation you want, e.g. an ubuntu live cd
| |
20:29 | killall gnome-keyring-daemon
| |
20:29 | cd .gnome2
| |
20:29 | mv keyrings keyrings.old
| |
20:29 | mkdir keyrings keyrings.new
| |
20:29 | <championofcyrodi> I'll stop you there... ~/.gnome2 does not exist
| |
20:29 | <alkisg> chmod 700 keyrings keyrings.new
| |
20:30 | ~/.gnome2 doesn't exist where? In the system where you run seahorse?
| |
20:30 | That's where the keyrings go, in /home/username/.gnome2/keyrings...
| |
20:30 | sshfs localhost:/home/username/.gnome2/keyrings.new keyrings
| |
20:31 | gnome-keyring-daemon -s -f
| |
20:31 | With those commands, you're running gnome-keyring-daemon using sshfs for keyrings
| |
20:31 | And, it reproduces the issue you're having
| |
20:31 | Those commands are enough to report the issue to gnome... it's not at all ltsp related
| |
20:35 | <championofcyrodi> the keyrings are ending up in /run/user/<pid> for the thick clients. not ~/.gnome2
| |
20:35 | i'm sorry... the keyrings are ending up in ~/.local/share/keyrings for the thick client. not ~/.gnome2/keyrings
| |
20:37 | <alkisg> Maybe it's using different directories for new users, the users I've tested were old ones, having keyrings of at least 2 years old... let me try with a new one
| |
20:38 | <championofcyrodi> SSSD is using pam_mkhomedir for users who log in for the first time (authenticating against directory server via ldap), which uses /etc/skel as a skeleton directory.
| |
20:41 | i just checked on a standard 14.04 desktop install i did yesterday. Keyring works fine, keys are stored in ~/.local/share/keyrings
| |
20:43 | <alkisg> championofcyrodi: yup, for new users they go there
| |
20:43 | Other than the folder location, it's like I wrote above
| |
20:43 | The bug isn't related to LTSP or SSSD
| |
20:44 | With what I wrote above, you can reproduce it without LTSP
| |
20:44 | <championofcyrodi> aha... i see what you're saying now.
| |
20:44 | that the gnome-keyring-daemon is failing over sshfs
| |
20:44 | <alkisg> Yup
| |
20:45 | <championofcyrodi> lol, sorry.
| |
20:45 | and those steps will duplicate the issue, with out needing to test in the LTSP environment
| |
20:45 | <alkisg> Right, to make it easier for gnome developers to reproduce
| |
20:46 | <championofcyrodi> gotcha
| |
20:46 | <alkisg> And if you want to "bypass" the problem in ltsp, you'd have to use a .local/share/keyrings folder that's not in sshfs
| |
20:46 | It could be a symlink to /run or to /tmp
| |
20:46 | (/run/user/<pid>/keyrings, some folder inside there which isn't sshfs)
| |
20:47 | But of course that's not a solution, it's just proof that it works with ltsp if you're not using sshfs,
| |
20:47 | ...you don't want to have to sync between sshfs and some other file system just for that...
| |
20:47 | <championofcyrodi> right
| |
20:48 | <alkisg> LTSP also easily supports NFS for /home, you might want to try there too
| |
20:48 | Maybe it works there, until the bug is solved...
| |
20:54 | <championofcyrodi> alkisg: did you see tons of temp files get generated when you used an sshfs localhost mount for keyrings, while the keyring daemon was hanging?
| |
20:54 | in ~/.local/share/keyrings
| |
20:59 | i reported it here: https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1321922 I'll go ahead and close the one i opened for ltsp
| |
20:59 | and link to the new one
| |
21:01 | <alkisg> championofcyrodi: yes, I did see the temp files
| |
21:01 | championofcyrodi: Don't use launchpad to report gnome bugs, they never get fixed there
| |
21:01 | <championofcyrodi> oh?
| |
21:02 | <alkisg> Yeah it's best to verify that the bug is an upstream one, and then report it upstream to the gnome bugtracker
| |
21:02 | This one is pretty sure an upstream bug, but you'll get better treatment in the gnome bug tracker if you verify the bug using the latest fedora version
| |
21:03 | <championofcyrodi> :-/ I need more time in a day.
| |
21:03 | <alkisg> Don't we all :(
| |
21:05 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Remote host closed the connection) | |
21:05 | <championofcyrodi> I'll work on this a bit more tomorrow. For now I have to put a system on a new UPS and head home. Thanks for your help.
| |
21:05 | <alkisg> https://bugzilla.gnome.org/browse.cgi?product=gnome-keyring
| |
21:05 | championofcyrodi: if you report it there, do mention it in the list so that we keep an eye on when it does get fixed
| |
21:06 | <championofcyrodi> 'the list' ?
| |
21:06 | <alkisg> Once it's fixed upstream, then the fix should go to Ubuntu, then an SRU process is needed to get it backported to 14.04...
| |
21:06 | Ah sorry
| |
21:06 | I was reading the bug mails and I thought you were using the ltsp mailing list
| |
21:06 | OK just mention it here in IRC
| |
21:07 | <championofcyrodi> ah, negative. I can use the mailing list though. I'll subscribe tomorrow, setup the gnome bugzilla account, add the bug, and mention it on the list.
| |
21:08 | <alkisg> Or just mention it when closing the bug report, that's better
| |
21:08 | (the older bug report against ltsp)
| |
21:08 | <championofcyrodi> okay
| |
21:08 | <alkisg> Good luck :)
| |
21:08 | <championofcyrodi> thanks
| |
21:16 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |
21:33 | mealstrom has joined IRC (mealstrom!~Thunderbi@46.63.63.163) | |
21:36 | alkisg has left IRC (alkisg!~alkisg@ubuntu/member/alkisg, Remote host closed the connection) | |
21:52 | Faith_ has left IRC (Faith_!~paty@143.107.231.49, Quit: Bye!) | |
22:28 | zama_ has joined IRC (zama_!zama@2604:180::502b:135a) | |
22:30 | Ark74 has joined IRC (Ark74!~Ark74@189.220.248.68.cable.dyn.cableonline.com.mx) | |
22:33 | zama has left IRC (zama!zama@unaffiliated/stryx/x-3871776, Ping timeout: 265 seconds) | |
22:36 | Lumiere- has joined IRC (Lumiere-!~jstraw@cpe-67-10-129-187.satx.res.rr.com) | |
22:37 | mgariepy_ has joined IRC (mgariepy_!mgariepy@nat/revolutionlinux/x-umyfrqaktkeviofz) | |
22:38 | mgariepy has left IRC (mgariepy!mgariepy@ubuntu/member/mgariepy, Ping timeout: 265 seconds) | |
22:38 | Lumiere has left IRC (Lumiere!~jstraw@unaffiliated/jstraw, Ping timeout: 265 seconds) | |
22:38 | Lumiere- is now known as Lumiere | |
22:38 | Lumiere has joined IRC (Lumiere!~jstraw@unaffiliated/jstraw) | |
22:54 | shadowwraith has left IRC (shadowwraith!806e4820@gateway/web/freenode/ip.128.110.72.32, Ping timeout: 240 seconds) | |
22:55 | Parker955_Away has left IRC (Parker955_Away!~parker@74.112.203.151, Excess Flood) | |
22:56 | Parker955 has joined IRC (Parker955!~parker@74.112.203.151) | |
23:06 | adrianorg has left IRC (adrianorg!~adrianorg@177.132.222.20, Ping timeout: 258 seconds) | |
23:08 | adrianorg has joined IRC (adrianorg!~adrianorg@179.179.79.36) | |
23:15 | gbaman has left IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com, Remote host closed the connection) | |
23:22 | Ark74 has left IRC (Ark74!~Ark74@189.220.248.68.cable.dyn.cableonline.com.mx, Quit: Saliendo) | |
23:59 | gbaman has joined IRC (gbaman!~gbaman@host81-130-112-2.in-addr.btopenworld.com) | |