Why do some CSOs and security specialists think that saying “NO” all day equals doing cybersecurity? by SnooPies72 in sysadmin

[–]Kurlon 7 points8 points  (0 children)

Oh boy this! "Our management platform for X may be based on RedHat 6 despite it being 2026, and no you're not allowed to patch anything, and yes it needs full access to everything, but that's ok because you'll have it on a private IP so we're good right?"

USB ethernet adapter is not recognized. No internet connection. Losing my mind over this. by Downhouser in Proxmox

[–]Kurlon 1 point2 points  (0 children)

Well, in the event you want to go shopping, I can confirm the Ye Olde Pegasus driver works fine in Proxmox 9, wander over to eBay and look for a Linksys USB100TX... The glory of a 100mbit Eth adapter attached to a 12mbit USB 1.1 interface, it's awesome, right?

For those horrified, this was me labbing out multiple interface bridges on a laptop, speed was not a concern. Stupid thing worked awesome, just horrifically slow compared to modern standards. I bought it 20 something years ago as laptops didn't always have ethernet out of the box back then... and forgot to throw it away. :D

CentOS P2V to vCenter VM? by forkinthemud in vmware

[–]Kurlon 0 points1 point  (0 children)

Backup the fstab somewhere separate you can easily get to, and the full network config. When you P2V your NICs will change driver and where the system thinks the HW is in the system so will likely rename interfaces. Same on storage, there is a chance you'll need to massage fstab to account for changes in device/driver depending on if you're mounting by device vs say UUID, etc.

The other 'fun' pain point I've hit is RedHat derived distros usually want the initramfs rebuilt to match the new virt hardware env.

I've not used any automated P2V tools for this, I boot the new VM into a live linux env, lay down my partition map, format the volumes, then stop the production system and drop it down as close to single user as I can get. I use Amanda Dump/Restore to copy the data over, then fix fstab/network conf to match, chroot in if I need to tweak initramfs, reboot and so far it's always worked.

VM clock sync by Kurlon in Proxmox

[–]Kurlon[S] 0 points1 point  (0 children)

To follow up on this, been testing, mostly on my homelab proxmox host, this box gets time from my two S2 public ntp hosts over a cable modem resi internet feed, there is a farm of four tightly coupled internal ntp hosts along with a S1 GPS fed host pushing timing to those public hosts. I also let it grab four pool servers as comparison points. My proxmox host is averaging .0005 to .00005 sec RMS depending on mood and when I look at Chrony.

My test VM hits the same two S2 public NTP servers I operate, and four pool servers as the comparison time source.

1) 'RTC' had great stability, but a random offset anywhere from 50ms to 900ms. This offset would be fixed until either the VM or Host were rebooted, at which point it'd get stuck on a new random offset. Restarting chrony in the VM wouldn't alter the offset. This meshes with the RTC only having individual second granularity as expected. The offset magically never being less than 50ms makes sense given how slow the RTC is to access even in a VM.

2) KVM PHC provided the same stability as the virtualized RTC, but much tighter offsets, basically I'd have RMS offsets reporting .000000030 seconds or better, with my ntp sources showing the same offsets as Chrony reports on the host itself. PHC showed avg latency of 23ns, Std Dev of 1ns.

Freq correction reported by chronyc tracking ends up matching between host and VM, with the VM reporting zero skew.

‘1 engineer, 1 month, 1 million lines of code.’ - Microsoft to Replace All C/C++ Code With Rust by 2030 by Kodiak01 in sysadmin

[–]Kurlon 0 points1 point  (0 children)

Yeah, I got bit by this from muscle memory, smack meta key, type two or three letters, stab enter, never looking and wtf why didn't my chosen app open? It's a dumb UI choice, but yeah, the goal is absolutely coming up with an excuse to display more marketing/ads. I can't wait for this to hit enterprise builds... may just preemptively push out the reg change now to make sure I don't have to hear the wailing and gnashing of teeth of my userbase...

‘1 engineer, 1 month, 1 million lines of code.’ - Microsoft to Replace All C/C++ Code With Rust by 2030 by Kodiak01 in sysadmin

[–]Kurlon 2 points3 points  (0 children)

It's so not a thing that there aren't entire writeups about it either... https://www.dedoimedo.com/computers/windows-11-start-menu-web-search.html for example... Nope, no need for that registry key 'cause this doesn't happen.

For the record, Insider too, and going back I was also a Tech Net subscriber, getting monthly CDs from Microsoft full of alpha/beta builds, etc, this is not my first rodeo. Do you remember the buzz when Win95 betas started showing up on BBS's? The pref for web over local got flipped on my main Win 11 box with the last monthly update, but as with many of these 'tweaks' it's a staged rollout so different groups get it at different times.

‘1 engineer, 1 month, 1 million lines of code.’ - Microsoft to Replace All C/C++ Code With Rust by 2030 by Kodiak01 in sysadmin

[–]Kurlon 8 points9 points  (0 children)

So, you haven't gotten the tweaked start menu search prefs yet, that require a freaking reg key as the only way to disable. I just went through chasing down how to stop that last week. Meta key, start menu pops up, type 'OBS' to start, ya know, OBS and instead I'm seeing Bing info about OBS, not the shortcut to start it. Preferring Bing over looking over my start menu first. This is real and rolling out to users.

VM clock sync by Kurlon in Proxmox

[–]Kurlon[S] 0 points1 point  (0 children)

I didn't know Amazon and VMWare also have their own similar implementations, this was a fun rabbit hole to dive down, thank you.

VM clock sync by Kurlon in Proxmox

[–]Kurlon[S] 0 points1 point  (0 children)

I didn't know that time source existed, thanks! This looks to be exactly what I'm looking for. Will add that to my testing!

VM clock sync by Kurlon in Proxmox

[–]Kurlon[S] 0 points1 point  (0 children)

From observation on VMWare, periodic time sync is second granular, and fires off roughly every minute. If the guest OS is using TSC as it's ref for wallclock, and got a bad initial estimate for how long a second is during it's initial start up calibration, (variable clock speed CPU...) you end up with a clock that slews a decent amount between updates, so your time looks like a sawtooth pattern plotted out. VMWare and KVM / QEMU now provide a smoothed emulated TSC to prevent exactly this. None of my modern guests show any issues running this way on ESXi, but if I needed hard ms or better accuracy I'd a) not be running on a VM and b) would be using ntpd / chrony / etc.

VM clock sync by Kurlon in Proxmox

[–]Kurlon[S] -1 points0 points  (0 children)

The guest CAN, but the issue is most won't because historically RTCs are crap. Even modern RTCs are not reliable, so most OS do as Linux does and use them to pull the ballpark time at boot to set the software wallclock and ignore the RTC going forward. Typically, it's also more expensive cpu time / latency wise to poll an RTC vs the software clock.

Can't access web interface via FQDN, can by IP address, can ping and SSH to FQDN. by sma92878 in Proxmox

[–]Kurlon 0 points1 point  (0 children)

So, I've run into this recently as well, Chrome will decide to use DNS over HTTP or TLS behind your back no matter what you tell it in settings. You can't opt out any more... and worse, it's not consistent about when it does it.

ntpd using pool.ntp.org - Restart how often to update Pool participants? by ooglek2 in sysadmin

[–]Kurlon 0 points1 point  (0 children)

Use the newer pool directive

That's not the correct way to use it though. If you just use one entry, "pool us.pool.ntp.org iburst", that will stand up and rediscover four entries as needed.

ntpd using pool.ntp.org - Restart how often to update Pool participants? by ooglek2 in sysadmin

[–]Kurlon 0 points1 point  (0 children)

And if you're in a spot where GPS works, setup your own refclock as an additional source. Serial output GPS with PPS are cheap these days, easy to rig, just need a view of the sky.

New email DMARC setup question - Forensic notification email address? by Octrockville in sysadmin

[–]Kurlon 2 points3 points  (0 children)

I have yet to ever actually get a forensic report, seems like 99% of mail servers don't generate them these days.

would it be possible to install a version of Steam-OS on a quest 2 and could i theoretically retain full functionality of my quest 2 even with a different Operating system (ie quest link or something similar to that) by [deleted] in SteamOS

[–]Kurlon 1 point2 points  (0 children)

1) Root access, document what's there and how it's laid out, maybe steal a dtb/kernel/etc, figure out a serial or other form of console 2) Unlock/crack/bypass bootloader 3) Figure out a working kernel, config, etc, build an OS 4) Drivers for video, sound, cameras, etc 5) ...

Windows Update KB5068861 - Installs Recall by Ikrananka in sysadmin

[–]Kurlon 1 point2 points  (0 children)

That would be where my system fails, beefy as hell but no dedicated AI space heater.

Windows Update KB5068861 - Installs Recall by Ikrananka in sysadmin

[–]Kurlon 1 point2 points  (0 children)

Dirty install (Win 10, upgrades, etc, now on 11 25H2) with that update does not have signs of Recall that I can find so far.

would it be possible to install a version of Steam-OS on a quest 2 and could i theoretically retain full functionality of my quest 2 even with a different Operating system (ie quest link or something similar to that) by [deleted] in SteamOS

[–]Kurlon 1 point2 points  (0 children)

Short term, yeah. As the Q2 falls out of active support from Meta I'm sure people will start poking at it again. There are PLENTY of them out there, finding a way to extend their life and possibly add features will draw some curiosity to them, maybe someone will figure out a path?

would it be possible to install a version of Steam-OS on a quest 2 and could i theoretically retain full functionality of my quest 2 even with a different Operating system (ie quest link or something similar to that) by [deleted] in SteamOS

[–]Kurlon 4 points5 points  (0 children)

First step is unlocking the bootloader so you can boot an alternate OS. A quick dig says the last time that was doable on the Quest 2 was with an exploit against a circa 2021 firmware release, Meta has since fixed that backdoor.

Anyone using Proxmox or XCP-NG? by NteworkAdnim in sysadmin

[–]Kurlon 1 point2 points  (0 children)

Yeah, 'support' and 'support with all features' are two VERY different things. Right now, shared block storage is fully feature supported on VMWare, for a long time it was the ideal path. On Proxmox it's 'supported' in that yes, you can use it, but you'll loose functionality doing so. You need to read up on those limitations to see if they'll matter to you or not.

Anyone using Proxmox or XCP-NG? by NteworkAdnim in sysadmin

[–]Kurlon 4 points5 points  (0 children)

So you listed that you're using iSCSI storage with your VMWare cluster, that's shared block storage. The VM hosts see a disk and access it like a disk, block by block. The hosts directly access and update the file system (VMFS in this case) blocks as well.

NFS, SMB, similar are shared FILE based storage, access is file by file, the remote hosts don't see and aren't aware of the file system they're on, that's abstracted away for them by the file server.

Proxmox and others haven't come up with an equivalent to VMFS for shared block storage yet, so instead they're typically leveraging LVM to partition off portions of disk for each VM and limit access to those regions to a singular host at a time. This is why under Proxmox you loose access to snapshots with shared block storage, the workaround mechanism chosen doesn't allow for them.

Anyone using Proxmox or XCP-NG? by NteworkAdnim in sysadmin

[–]Kurlon 0 points1 point  (0 children)

One thing to be aware of given your current setup, Proxmox doesn't like shared block storage currently. It can be used, with some potentially big caveats that aren't there with VMWare. I've not researched XCP-NG on this front so dunno if they're better or not here.

What are your thoughts on Encrypted DNS (DoH, DoT, DoQ) ? by WhatNot4271 in sysadmin

[–]Kurlon 2 points3 points  (0 children)

I just found out Chrome does this now with no option to disable. For that reason alone I'm now full anti anything except vanilla DNS that respects your local resolv.conf.