Latest Server related questions

Score: 0
Diablo avatar
How to change an expiring CA certificate issued by letsencrypt to a new root CA of other than letsencrypt?
gb flag

I was using a letsencrypt certificate for the https connection, but now the DST root CA X3 is getting expired and they added a new path to the root ISRG X1, which is not a trusted root for the IoT device that I'm using. So I need to change the root certificate in my server to a new one. Can anyone help me with a solution on how the new certificate can be added along with the existing one or without the  ...

Score: 0
0diseus avatar
PHP-FPM - nginx - clear cache in different environments
cn flag

We have an environment with a web server running nginx, this has 4 virtual hosts (2 of them are the ones running in production, and the others 2 are for testing). We run php-fpm and all that nginx cache thing. Now, i have two questions:

  • How do i manage to only have the cache running for production and no for testing virtual hosts?
  • And, every time a new thing is incorporated to production, devs have to ...
Score: 5
inding avatar
Why does WinDRBD become Diskless/StandAlone (both node)
ng flag

I have a question.

Currently, this OS is Windows Server 2019. The volume configuration is Raid-5. The two servers are connected by a heartbeat network Both nodes were mirrored using WinDRBD. Both nodes have the same configuration. I left unformatted G: and set D: to be visible to the primary node.

my resource are below

include "global_common.conf";

resource "foo" {
    protocol    A;

    net {
         ...
Score: 1
Amit avatar
kubernetes pod running on google compute engine not able to access metadata service
vn flag

I am trying to run google cloud python sdk from inside a k8 pod, running on google compute engine. There is a service account attached to the VM, which is giving it access to the secrets manager. I am able to access secrets manager from the host, however running the python sdk from k8 pod complains of not able to access the metadata service

>>> secret_id = 'unskript_test'
>>> name ...
Score: 0
give permissions to a specific group of users in LDAP the same permissions as a specifc group locally in linux
us flag

Here is the problem. I have a Linux server. This server has a lot of people who need to log into it through the web server; currently authenticated by LDAP. However, I would like to allow some of the users to be able to log in locally and, more importantly, some of the users in LDAP that belong to the "administrators" LDAP group to be able to log in through ssh and be able to run commands as if they wer ...

Score: 1
godsmustbcrazy avatar
Browser not prompting for certificate - IIS 10.0
id flag

I have an application that was working fine in IIS 8.5 which used this setting in the web.config file for a client certificate login (smartcard) for a path. I had to migrate this application to IIS 10.0 and everything is working except the application does not prompt for the certificate and just simply throws an error in the code that there is no certificate.

I have double checked and triple chec ...

Score: 0
mahen3d avatar
SELinux Issue - git status fatal: Out of memory? mmap failed: Permission denied
cn flag

I have Centos 7.9 server running with Apache and Git, however if I do a

[root@a]# git status
fatal: Out of memory? mmap failed: Permission denied

But if Disable or Permissive the SE-Linux via below commands it start working fine.

setenforce Permissive

Any idea on how to fix this issue permanently with SELinux enabled?

Audit log says

node=a type=PROCTITLE msg=audit(1630636505.296:37076): proctitle= ...
Score: 2
KKlouzal avatar
Windows Failover Cluster With SQL Server
es flag

We are moving away from using VMWare over to Windows Failover Cluster (version 2019) to host our company services. I have successfully configured WFC and have a few Virtual-Machine roles running along with the File-Server role and DHCP-Server role. Next is to get our SQL server instances (also version 2019) setup and I am posed with an architectural question.

Is it acceptable to install SQL serve ...

Score: 1
jerryrig avatar
Why can I get on <1G on my 10G Network?
us flag

I have 4 CentOS 7 boxes with SuperMico 10000BaseT NICs plugged into a Netgear ProSafe XS712T switch with Cat8 cables. Switch is all default settings, but shows NICs at 10G Full. NICs are configured:

[root@VH11 ~]# ethtool ens1f0
Settings for ens1f0:
        Supported ports: [ TP ]
        Supported link modes:   100baseT/Full
                                1000baseT/Full
                         ...
Score: 0
GCP: Way to get "paged" via the GCP Cloud Console Android app?
ng flag

I'm using GCP and have set up the GCP Cloud Console Android to notify me of errors and alerts. But my phone is on silent/vibrate most of the time and I miss alerts. Is there a way to get the GCP Cloud Console Android app to always notify me at full volume?

(My previous experience is with PagerDuty. Their Android app will ring loudly even if my phone is on silent/vibrate. I see that GCP has an ...

Score: 3
Setting up sftp on Amazon Linux 2 with ssh keys, user segregation (sftp vs ssh), different ports, and user directory constraints
pk flag

TDLR: I have a Catch 22 where, depending on permissions on the user's home directory, I can get the SSH authentication to work, or the user directory constraints, but not both.

BTW, I really want to roll my own SFTP server. Please don't recommend I try AWS Transfer service or something alternative. Thanks.

Here is relevant (changed from default) content in /etc/ssh/sshd_config:

Subsystem sftp internal-sf ...
Score: 2
roee klinger avatar
How to scale OpenVPN when client-to-client is a must?
bd flag

I am trying to create an OpenVPN server cluster that can autoscale, I have found a lot of information online on how to create such a network.

As far as I understand, you basically use a round-robin DNS, and few OpenVPN servers, the clients simply connect to the DNS and are assigned one of the OpenVPN servers to connect to.

However, my setup requires that all clients will be visible to each other, so ...

Score: 0
Unable to ssh using ProxyJump but it works with ssh -J
cn flag

My question is: How do I set up a bastion host for ssh on AWS using an ubuntu instance?

I can do the following with success:

root@e183d80cdabc# ssh -J ubuntu@63.33.206.201 ubuntu@10.240.0.20
Last login: Sat Sep  4 13:14:17 2021 from 10.240.0.30
==> SUCCESS! ==> ubuntu@ip-10-240-0-20:~$

But it fails when I try the ~/.ssh/config file approach. Commands used:

# ssh 10.240.0.20
# ssh ubuntu@10.240.0. ...
Score: 2
frigo avatar
What is reducing the MSS by 42?
jp flag

I am running multiple VMs in Azure. VMs are running in a subnet with NSG. NICs do not use NSGs, we do not use accelerated networking.

I notice that when a VM talks to another VM of the same subnet using TCP, the MSS value in the SYN packets is reduced by 42. That means if I send a TCP SYN with MSS=876 to another VM of the same network, the other VM will capture a TCP SYN with MSS=834:

Client:

18:49:27.52 ...
Score: -3
dufte avatar
How to implement a uptime-monitoring and forced shutdown after a defined uptime with notifications and countdown
cv flag

Setup:

  • approx. 1000 windows 10 machines in 4 countries (AD)
  • approx. 10% of the users tend to keep PCs running for > 1 week without reboot -> something i consider an issue (i.e. because of Windows Updates for example)

Target:

  • ensure machines gets rebooted after an uptime of > x days
  • ensure user gets notified X hours before forced shutdown
  • ensure user gets notified Y minutes before forced shutdo ...

The Stunning Power of Questions

Much of an executive’s workday is spent asking others for information—requesting status updates from a team leader, for example, or questioning a counterpart in a tense negotiation. Yet unlike professionals such as litigators, journalists, and doctors, who are taught how to ask questions as an essential part of their training, few executives think of questioning as a skill that can be honed—or consider how their own answers to questions could make conversations more productive.

That’s a missed opportunity. Questioning is a uniquely powerful tool for unlocking value in organizations: It spurs learning and the exchange of ideas, it fuels innovation and performance improvement, it builds rapport and trust among team members. And it can mitigate business risk by uncovering unforeseen pitfalls and hazards.

For some people, questioning comes easily. Their natural inquisitiveness, emotional intelligence, and ability to read people put the ideal question on the tip of their tongue. But most of us don’t ask enough questions, nor do we pose our inquiries in an optimal way.

The good news is that by asking questions, we naturally improve our emotional intelligence, which in turn makes us better questioners—a virtuous cycle. In this article, we draw on insights from behavioral science research to explore how the way we frame questions and choose to answer our counterparts can influence the outcome of conversations. We offer guidance for choosing the best type, tone, sequence, and framing of questions and for deciding what and how much information to share to reap the most benefit from our interactions, not just for ourselves but for our organizations.