#arpnetworks 2015-04-30,Thu

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)

WhoWhatWhen
up_the_ironslol [01:14]
...... (idle for 26mn)
brycecAnd suddenly you're back. What, were you off with your /other/ family again? Ugh. /s [01:40]
....... (idle for 30mn)
up_the_ironslol
yes
[02:10]
...................................... (idle for 3h7mn)
***mnathani_ has quit IRC () [05:17]
mnathani_ has joined #arpnetworks [05:22]
.............................. (idle for 2h27mn)
carvite has quit IRC (Ping timeout: 252 seconds) [07:49]
carvite has joined #arpnetworks [07:55]
sorresseanHas anyone had problems with IPMI? when I click on cd-rom image, it just says I don't have priviledges to perform this action, then my session times out and I have to log in again. [08:05]
brycecI don't remember having any issues with the virtual CD. sorressean: I trust that you logged back in and tried it again with the same result? [08:06]
sorresseaneah.
yes*
[08:07]
........ (idle for 35mn)
Meh. this IPMI java interface is not accessible.
Is there a serial console?
[08:42]
brycecWelcome to the nature of most IPMI web interfaces on the market :( But fortunately it's your standard IPMI interface so tools like ipmitool will work too
(And just to clarify - The vast majority of server BMC/IPMI web interfaces suck, terribly and horribly. Just know that it's not ARP's fault.)
[08:51]
staticsafeindeed [08:53]
sorresseanYeah, I figured it was'bnt. [08:53]
staticsafesubmitted the needed paperwork to ARIN, now we wait o/ [08:53]
sorresseanthanks, going to try ipmitool [08:53]
brycecHooray staticsafe
I want an ASN of my own... just to have, not for any real purpose.
[08:54]
staticsafeheh
unfortunately ARIN frowns upon that
[08:56]
brycecYeeeaaaah
That they do.
I just want to feel important.
[08:56]
....... (idle for 30mn)
RandalSchwartzFor many months after I was abruptly terminated from Intel, the ASN for intel corp was still in my name
might have even been years... I forget.
it was some amazingly low number. :)
[09:26]
bryceclol
AS99?
[09:28]
RandalSchwartzYeah, that was it [09:29]
brycecRegDate: 1987-02-19
Seems like it's no longer used
[09:29]
RandalSchwartzyeah - I don't even remember why we got it, or why my name ended up attached to it.
oh - it's because we had an internal net, and two connections to the world
[09:30]
twobithackerdoesn't appear to be in the routing table [09:35]
brycecBecause it's not announcing anything [09:35]
RandalSchwartzYeah, not sure how they're doing it now [09:35]
twobithackerhuh, bgp.he.net says it was seen as recently as Oct 2014 [09:36]
RandalSchwartzweird [09:36]
brycecI thought Intel had a /8 but I don't see it now so I'm guessing they gave that back too. [09:37]
RandalSchwartzfor a while, they used 128.215 inside the company, but it didn't belong to them. :) [09:39]
bryceclol. I wonder who it does belong to... [09:39]
RandalSchwartzOh wait... that was the right number
one part of the company was using a routable number, but just made it up
eventually became a problem when we got "the net"
[09:39]
brycecYou stay classy, Intel! [09:39]
RandalSchwartzso they had to do a great renumbering
eventually joining 128.215
[09:40]
............. (idle for 1h2mn)
***acf___ has joined #arpnetworks
SpaceDum1 has joined #arpnetworks
[10:43]
anis has joined #arpnetworks
acf__ has quit IRC (*.net *.split)
CaZe has quit IRC (*.net *.split)
SpaceDump has quit IRC (*.net *.split)
anisfarhana has quit IRC (*.net *.split)
ix33 has quit IRC (*.net *.split)
ix33 has joined #arpnetworks
[10:48]
staticsafehm ARIN needs an invoice, I guess I'll have to wait for billing to run today [11:01]
brycecstaticsafe: What's wrong with last month's invoice? [11:01]
staticsafemy last ARP invoice was in April 2014 :P [11:02]
brycecOh I see, returning to the fold then [11:02]
................... (idle for 1h33mn)
***hive-mind has quit IRC (Ping timeout: 256 seconds)
hive-mind has joined #arpnetworks
[12:35]
mercutiostatic: with 32bit asn's you'd think they wouldn't see the need for such things?
or are requeusting a short ASN?
[12:37]
brycecI think they just realized that there's no point in being reckless, that's how we end up with /8's used by a single company.
brycec should upgrade zeit.arpnetworks.com to Jessie...
[12:38]
mercutioi don't that was a bad thing in the first place.
i just don't think anybody expected the internet to last so long
without changes
[12:40]
brycecWell sure nobody planned ahead/expected it.
But I still don't think Ford Motor Company needs 16.8 million public IP addresses.
[12:40]
mercutiothat could have been fixed 18 years ago or something though [12:41]
brycecPractically everything could have been fixed in the past... hindsight and whatnot [12:42]
mercutioyeah [12:42]
brycecI have less of an issue with /8s that are assigned to computer companies (Apple, HP, DEC) or whole governments and transit providers, but COME ON why does an car company need 17 million IP's?!? Or an oil company? Or financial services?
brycec rages
[12:44]
m0undsgotta put those PLCs on the public internet brycec [12:44]
brycec(That being said, I still don't think the United States Dept. of Defense needs 201 million public IP's, especially when they run their own non-Internet networks)
lol m0unds
[12:44]
mercutioyeah well we know ipv4 is a mess [12:45]
brycec(And MIT's /8 is just MIT holding out to be dicks. True story.) [12:45]
mercutioso now we're trying to screw up ipv6
the ip address side of ipv6 is fine..
but how the hell do you multihome?
[12:45]
brycecheh [12:47]
mercutiodo you need a /48? do you need a /32? [12:47]
sorresseanAnyone done any installs with IPMI using ipmitool? trying to install BSD over SoL. it's just hanging, not sure if there was anything special I needed to do. [12:54]
mkbI usually spend an enormous amount of time and effort trying to make it work and eventually give up and try to get someone else to do it [12:56]
mercutiothe sol is configured normally, but you need to make sure whatever you're using is outputting to serial
java works
[12:58]
sorresseanawshit. [12:58]
mercutioi think i did java [12:58]
sorresseanokay, maybe I can do that from FreeBSD installer [12:58]
brycecmercutio++ [12:58]
sorresseanYeah, the java one isn't accessible with a reader.
There is literally no way for me to do this.
[13:00]
brycecSome installers start a serial terminal by default alongside VGA.
I think Debian does, for instance.
[13:01]
staticsafemultihoming with /48 works just fine [13:01]
mercutiostatic: yeh i think it generally does atm
but if everyone wanted to do it, there might be a push to become more restrictive
[13:03]
sorresseanHrm. wonder if I can get arp to deploy bsd for me, given my issues [13:04]
mercutioand it goes back to the way of doing things that happened in ipv4 [13:04]
sorresseanThis is fun learning, but I need this working so I can start the switch [13:04]
mercutiowith people using "provider" space to multihome
sorressean: you can't get java wokring?
oh right
[13:04]
brycecsorressean: Which BSD? if it's OpenBSD, I'll do it for you. [13:05]
sorresseanmercutio: applet is not accessible
brycec: it's FreeBSD
[13:05]
brycecblech :P [13:05]
sorresseanI'm not cool enough for OpenBSD. :p
I like my jails.
[13:06]
mercutiojails aren't necessarily secure [13:06]
sorresseanNo, they're not.
But they make my life a lot easier sometimes.
[13:07]
brycecIt's nice to have logical machines :) [13:07]
sorressean(I can easily just wipe them out and rebuild if I need. So I have a development jail) [13:07]
mercutiocool [13:07]
brycecit's not a hatred of FreeBSD or anything, just that I have far less experience installing it (and there are more questions involved, etc)
(oh and it takes longer)
[13:08]
BryceBotThat's what she said!! [13:08]
mercutioyeah as long as you're not overvalueing security from them, they're probably pretty useful [13:08]
brycecToo often people think of VM's and containers and jails as magical security cures. Gotta correct those people before they do damage. [13:08]
mercutiobrycec: i think vm's are introducing less security in general :)
it's a complex problem though
[13:09]
sorresseanYeah, it's useful in a sense, but it's not really the base of my security [13:09]
brycecGood. [13:09]
mercutiolike 4 vm's are more likely to have a hole than 1 server. [13:10]
brycec(all my jails communicate over lo - now THERE's some network security :D)
*lo0
(er, lo1 actually)
[13:10]
mercutiolo1 [13:10]
sorresseanbrycec: I do that too. [13:10]
staticsafe100ge7-2.core1.lon2.he.net thats a lot of bits [13:10]
sorresseanIt's cool because you can limit what connects where and resource usage of groups of services [13:10]
mercutioit's only ge
* 100 :)
[13:11]
staticsafeheh [13:12]
mercutioyouu can get 100 gigabit ethernet cards for pc now i thnk
like connectx-4 does 100ge i thikn
[13:12]
mnathani_@exch 56.49 usd to cad [13:13]
BryceBot56.49 USD -> 68.20224117 CAD (as of Thu, 30 Apr 2015 13:01:02 -0700) [13:13]
staticsafethe GBP to CAD exchange rate is painful
@exch 72.50 gbp to cad
[13:14]
BryceBot72.50 GBP -> 111.26679936831 USD -> 134.33607868174 CAD (as of Thu, 30 Apr 2015 13:01:02 -0700) [13:15]
staticsafeyeah [13:15]
mercutiodamnit have to request quote to get price for 100gbe card :/ [13:17]
brycecheh [13:19]
mercutioi wonder what rouuting performance would be like on linux near 100gbe :/ [13:20]
http://arstechnica.com/security/2015/04/30/spam-blasting-malware-infects-thousands-of-linux-and-freebsd-servers/
this souunds like they've put some effort into doing a good job.
[13:32]
what openbsd has a bug
with mailformed executables.
[13:43]
brycecIt happens sometimes [13:46]
BryceBotThat's what she said!! [13:46]
brycecAnd specifically, maliciously-formed ELFs [13:46]
mercutioyeah
hmm hammer2 may be getting ported to openbsd :)
gsoc project
[13:46]
brycec<-- not holding his breath [13:47]
mercutioneither
that's why i said may
may overload whoever is doing it
[13:48]
.................................... (idle for 2h55mn)
oh openbsd 5.7 is out already [16:43]
.......... (idle for 48mn)
m0undsgah, one of my fans sounds sick
sounds like an old garage door opener
[17:31]
mercutioat least fans are cheap [17:39]
......... (idle for 42mn)
mkbbut nobody has received it in the mail yet [18:21]
mercutiooh?
it's usually early :(
isn't it?
i don't like cd's
[18:22]
mkbit used to be
the new shipper is in England, that won't help us in North America
[18:22]
mercutioi don't even have a cdrom drive :/
the idea mostly is for support
and to make it easier to write it off as a business expense
rather than to actually use
i think most people who buy cd's still download it
i'm starting to even use usb sticks less now
[18:23]
mkbeh.. it'll arrive by the time I have a chance to install it and I only need it on my thinkpad locally at least [18:24]
mercutioi can just do pxe boot over network [18:24]
mkbnow I'll download it a million times to install on servers
why in the world do they do this?
https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/
[18:24]
mercutiowhat
just title :)
what i want is in between http and https
i want validation of content, cacheable
and validation of where something's coming from-
having keys etc on packgaes etc gives a reasonable certainty
[18:29]
mkband doesn't require https [18:31]
mercutioi'd actually like extended attribute stuff to be done more on unix
like when you download a file it stores where it came from
but yeah i'm kind of irrate at the way that caching is going out hte window
if you have 20 cellphones in an office you can't have a local proxy it cache updates
s/it/to/
[18:32]
BryceBot<mercutio> if you have 20 cellphones in an office you can't have a local proxy to cache updates [18:33]
mkbhttp was supposed to do that [18:33]
mercutiowell not on android, as all the updates go via https. [18:33]
mkbthe rfc describes all sorts of caches and proxies [18:33]
mercutioyeah i haev a local proxy [18:33]
mkbhttps screws it up [18:33]
mercutioit's even on ssd's :)
it's very noticable with things like updating packages on two hosts.
because it's like 100x the speed :)
[18:33]
mkbI wish I had more than one openbsd machine at work [18:35]
mercutiowhy's that? [18:35]
mkbeverything would work much better if only we'd scrap linux [18:35]
mercutiolike what? [18:35]
mkbno more systemd [18:36]
mercutiosystemd is fine [18:36]
mkbactually that's not a fair complaint because I don't think we're ever going to really upgrade past centos 6 [18:36]
mercutioi find stability and predictability are better with openbsd
but upgrades can be a pita
[18:37]
mkbexactly [18:37]
mercutiolots of people still use centos5
i hate centos
[18:37]
mkbthey go changing crap every six months on linux or else it's one of the old centos 6 machines [18:37]
mercutiowhat's with that fastmirror crap
it doesn't even work reliably
and it takes ages
[18:37]
mkbwe have a mirror but fastmirror can't figure that out
and there's like 5 mirrors on internet2 closer that it can't find either
[18:37]
mercutionew zealand is actually good for mirrors in general
and most mirrors will do 60 to 80mb/sec+
there's no openbsd mirror in new zealand though.
yeah it's 5 mirrors on internet2 that's the issue
i can understand it not finding a local mirror...
if it's just your own mirror
but it seems to be bad even with public mirrors
[18:38]
mkbI think we have a public mirror
It's a university
[18:39]
mercutiooh
oh taht's even worse :)
[18:39]
mkbshould be 1Gbit/s [18:40]
mercutiothe problem with universitys can sometimes be that file storage is non-local and slow [18:40]
mkboh I never considered he might put the files on NFS [18:41]
mercutioso there may be plenty of network capacity and slow disk [18:41]
mkbI hope not [18:41]
mercutioit depends, is nfs everywhere there?
it used to be extremely common in sun days
it's not so common for newer setups, that are more linuxy ;/
[18:42]
mkbwe use it all over the place, but I don't know anything about how it's run [18:42]
mercutiobut it's making a come back with vmware [18:43]
.... (idle for 16mn)
sorressean: did you get sorted ok? [18:59]
.......................... (idle for 2h8mn)
***dj_goku has quit IRC (Remote host closed the connection) [21:07]
............ (idle for 58mn)
mordac has joined #arpnetworks [22:05]
mordachello, can i please request that the OpenBSD 5.7 install CD be added to the list of CD-ROMs available in the control panel? The amd64 URL is http://ftp5.usa.openbsd.org/pub/OpenBSD/5.7/amd64/install57.iso
the i386 url is http://ftp5.usa.openbsd.org/pub/OpenBSD/5.7/amd64/install57.iso
er...http://ftp5.usa.openbsd.org/pub/OpenBSD/5.7/i386/install57.iso
[22:05]
.... (idle for 16mn)
mercutioit'll probably be added shortly mordac
it's less than 24 hours since release.
[22:25]
.... (idle for 15mn)
brycecmkb, mercutio - if you hadn't heard there are manufacturing issues with the CD's so they're late.
(It's still best to send an email so up_the_irons has a todo item to cross off)
[22:41]
mordacmercutio: I make the request because it was my request that got 5.6 up in November. I don't mind making the request and it seems to get the job done. :) [22:53]
mercutioahh ok [22:53]
brycecheh
Oh mordac, typical OpenBSD nerd...
Well up_the_irons tells me my dedicated machine has been upgraded, and indeed it's back up and running... but for whatever reason I cannot SSH in. *sigh*
[22:54]
mercutioipmi? [22:59]
bryceclooks like it. Damn firewall... worked fine before the shutdown, now I'm apparently locked out.
<3 "sol activate"
[23:01]
mercutioyeah it's convenient. what'd you do to it? [23:12]
brycecSecond hard drive and more RAM [23:14]
brycec gets to look forward to an online RAID build in-production, w00t [23:25]
wtf, Linux... "ip route add...." "RTNETLINK answers: No such process" and I have no routes
heh my network configs are apparently totally screwy. Thank goodness for IPMI sol!
[23:35]
mercutiohmm
uubuuuntu trusty?
[23:40]
brycecDebian Wheezy [23:41]
mercutiooops leaning on keys
ahhh
that shouldn't have anything weird about it's setup
[23:41]
brycecSeems like it might be having some odd issues with bridging atop bonded interfaces [23:41]
mercutiosh
oh
[23:41]
brycecpurely script-wise. Technically it works fine.
For whatever reason when Debian's ifup adds the ipv4 to the bridge, it doesn't take. No errors or anything, and I can manually run the ip commands later and get it up.
well here goes nothing...
hooray! everything is just fine
removed the inet6 configuration and everything came up just fine
[23:41]

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)