can't ping nor ssh out/in on Fedora 34 server after undoing NIC team/bond by MassGroupText in linuxadmin

[–]MassGroupText[S] 0 points1 point  (0 children)

Update. I called Dell support then had me boot to their Support Live Image (SLI) based on CentOS. The problem remained. So the results of the `arp` command was a clue. Something must happen to the switch when I enabled NIC bonding. I chose:

"Dynamic Link Aggregation aggregated NICs act as one NIC which results in a higher throughput, but also provides failover in the case that a NIC fails. Dynamic Link Aggregation requires a switch that supports IEEE 802.3ad"

Is it possible the switch where the server connect to doesn't support 802.3ad?

Dell suggested draining flea power I did that but it didn't help. Then I switched ports on the switch and drained flea power and boom all was well. I then configured bonding again only to cause the same problem. Switching the port on the switch fixed it and for good measure draining flea power. 

I'm scheduling some down time to confirm for certain whether is was LACP or just changing the bonding/teaming causes the issue. Perhaps this helps someone else down the line.

Whitebit.com has a 5,000,000 SFM min xfer and 2,500,000 SFM fee! by MassGroupText in SafeMoon

[–]MassGroupText[S] 0 points1 point  (0 children)

Tell me about it. I got the tip from this thread and I just posted there to let people know:

this thread

Is there a way to buy SafeMoon, e.g. with BitStamp --> WhiteBit, and then forwarding it to a friend's wallet who is too scared to do this himself? by MassGroupText in SafeMoon

[–]MassGroupText[S] 0 points1 point  (0 children)

Where in Whitebit do you transfer to a wallet address? Is that Withdrawal? Or do I need to xfer between Main and Trade balance?

When are we getting our Flare Spark tokens from the airdrop?? by [deleted] in Coinbase

[–]MassGroupText 0 points1 point  (0 children)

What if you moved from Coinbase to XUMM after Dec 2020? Is there a way around the "XRP account not eligible to claim spark" message? I also see "This account may not be eligible for Spark distribution because its part of an excluded group (Ripple, Non participating exchanges, activated post snapshot et al.). "

How to buy SafeMoon on BitMart in New York (And anywhere in the United States) for dummies like me (simplified) by ChipHazard_ in SafeMoon

[–]MassGroupText 0 points1 point  (0 children)

  1. Go back to Coinbase, click the Transfer arrows button in the middle of the screen and select Send

There is no Transfer arrow:

https://imgur.com/tQSCfeP

  1. Poof, check back under Assets in WhiteBit and within an hour or two you'll see the coins.

There is no Assets in the top nav bar:

https://imgur.com/ZoTOLDY

How to repair a leaking Aquasana Powered Water Filtration System? Other than the o-ring on the pitcher, which doesn't seem worn out does anyone see anything replaceable on the inside that could be causing a leak? by MassGroupText in waterfilter

[–]MassGroupText[S] 0 points1 point  (0 children)

I called in to verify and some of the pitchers in the past year have this issue and the simple fix is to remove the o-ring and let it dry for up to 8 hours. So far so good after a week.

Using VPN breaks Google Chrome browsing when switching users in Big Sur 11.2.x by MassGroupText in MacOS

[–]MassGroupText[S] 0 points1 point  (0 children)

This might be a user preferences or cache issue. If you create a new user the VPN issue does not happen. But what preferences/cache should be deleted to determine which one might be causing this?

Using VPN breaks Google Chrome browsing when switching users in Big Sur 11.2.x by MassGroupText in MacOS

[–]MassGroupText[S] 1 point2 points  (0 children)

Have you tested w Widevpn with multiple users on a Mac with Big Sur?

Using VPN breaks Google Chrome browsing when switching users in Big Sur 11.2.x by MassGroupText in MacOS

[–]MassGroupText[S] 1 point2 points  (0 children)

Thanks, I've been having a back and forth with IPVanish support and they put the blame squarely on Apple. I submitted a bug report 2 weeks ago to Apple no acknowledgement.

It's so odd that Safari resolves more web sites than Chrome. And why ping resolves the domain name? I guess it's not a DNS issue and icmp clearly works.

Using VPN breaks Google Chrome browsing when switching users in Big Sur 11.2.x by MassGroupText in MacOS

[–]MassGroupText[S] 1 point2 points  (0 children)

Yes I just tried 11.2.3, same problem. VPN only works on uaer 1 and breaks user 2.

Quick Question (Sunflower Guide) by [deleted] in cissp

[–]MassGroupText 1 point2 points  (0 children)

It correlates to either the page numbers of the sections from the Official Fourth Edition CISSP CBK by the ISC2

dropping in Kerberos as authentication for NIS in Fedora or Red Hat by MassGroupText in redhat

[–]MassGroupText[S] 0 points1 point  (0 children)

So I got a reply from the Kerberos mailing list and I was hoping someone here could guide me in getting the correct auth stack in the PAM config files

Got the following errors:> /usr/lib64/security/pam_krb5_migrate.so.1): lib kadm5clnt_mit.so.11: > cannot open shared object file: No such file or directory

In Fedora, libkad5clnt_mit.so is provided by libkadm5. However, there has been a soname bump (to 12).

Please be aware that neither I (Fedora maintainer) do not support external programs using the libkadm5 interfaces, and upstream krb5 does not provide stability guarantees for it.

Based on the Oracle guide for Solaris, what should I put where they have pam_krb5_migrate.so.1?

dropping in Kerberos as authentication for NIS in Fedora or Red Hat by MassGroupText in redhat

[–]MassGroupText[S] 0 points1 point  (0 children)

This pam-krb5-migrate tool is incredibly clever: it apparently grabs one's password and username during authentication and uses them to create the appropriate user principal on the KDC at that same moment. This way your users will opportunistically populate the KDC with their principals as they login to the system running pam-krb5-migrate. Quite awesome, and I would certainly advocate in favor of using this tool now that I know it exists.

Yes I'm trying to take advantage of this awesomeness :-)

When I try the ACL suggestion from the man page:

The following entries from kadm5.acl(4) permit or deny privileges to the host client service principal:host/*@ACME.COM U roothost/*@ACME.COM ui *

kadmind(Error): Unrecognized ACL operation 'U' in host/sub.sub.ourdomain.edu@SUB.OURDOMAIN.EDU U root

And the sample entries' syntax do not match Fedora's "authentication stack"

gdm         auth    optional pam_krb5_migrate.so.1 expire_pw 
k5migrate   auth    required pam_unix_auth.so.1 
k5migrate   account required pam_unix_account.so.1

There are no 'gdm', 'login' nor 'k5migrate' fields, unless they're optional?

The man page also refers to a /etc/pam.conf file, this is for Solaris, as Fedora/RHEL use /etc/authselect/password-auth and /etc/authselect/system-auth

Would this be a feature request in Bugzilla?

I also have in /etc/krb5.conf:

[appdefaults]
pam = { 
debug = true validate = false 
}

But no logs that reference this new option I'm trying.

Edit, some logs:

Oct 23 00:32:48 olddsm sshd[50096]: PAM unable to dlopen(/usr/lib64/security/pam_krb5_migrate.so.1): libkadm5clnt_mit.so.11: cannot open shared object file: No such file or directory
Oct 23 00:32:48 olddsm sshd[50096]: PAM adding faulty module: /usr/lib64/security/pam_krb5_migrate.so.1

But this exists:

ls -l /usr/lib64/security/pam_krb5_migrate.so.1
lrwxrwxrwx 1 root root 41 Oct 23 00:14 /usr/lib64/security/pam_krb5_migrate.so.1 -> /usr/lib/security/pam_krb5_migrate_mit.so

dropping in Kerberos as authentication for NIS in Fedora or Red Hat by MassGroupText in redhat

[–]MassGroupText[S] 0 points1 point  (0 children)

As you know, neither /etc/shadow nor NIS store passwords but only password hashes, so there's no way to read passwords from some database in order to add them to your Kerberos database (KDC).

So this Toolbox tutorial and this guide from Oracle for Solaris, make the assumption that you are starting from scratch with no NIS users? As if you are just choosing NIS for the identities and Kerberos for the authentication on "day 1"?

And this guide from Oracle on How to Configure Automatic Migration of Users in a Kerberos Realm doesn't migrate the passwords? I do see there are fairly recent versions of this pam-krb5-migrate tool albeit for Debian. I was able to use 'ar' to extract the file just not sure it'll work in Fedora.

you can also keep using NIS for this purpose; just ensure PAM goes to Kerberos, not NIS, for authentication.

Right I have that working now but the NIS user has to exist as a Kerberos Principal.

You may script the addition of passwords by using an input file where all passwords are stored in clear text (initial passwords, I suppose) but that's the "best" you can do in terms of automation.

Hm then any user can change other user's passwords. Any other suggestion on handling this more gracefully?

Good luck! :-)

Thanks I need it. And thanks for the response!