Major Bug: UFW stopped thru logrotate

On Debian Sid i have seen that ufw service is stopped on logrotate!!

Its a bad known bug!

Workaround:

  • Set all Services like Dovecot, Postfix to listen on LOCALHOST (127.0.0.1) if not needed over Internet
  • Enable ONLY encrypted AUTH (Login) to Postfix! (TLS 1.2)
  • Disable unneeded Services ! like Samba, FTP…
  • move config from /etc/logrotate.d/ufw to /root/ to disable ufw logrotate !!
  • edit /etc/ufw/ufw.conf set LOGLEVEL to „off“
  • restart the Server and check open Ports next Days from outside with:

$sudo nmap -PN my.server.com

Openwrt LEDE ath9k bugs fixed

If you use a TP Link Router like 3600, 4300 or a other brand with ATH9K Chipset you should upgrade to OPENWRT 18.06 with Kernel 4.9

Tested: OpenWrt 18.06.0 r7188-b0b5c64c22 / LuCI openwrt-18.06 branch (git-18.210.69179-6df9a57) – Atheros AR9344 rev 2

cause:

  • more stable
  • less load
  • no ath9k Wifi Lookup on high transfers

Same seen on other TP Link Routers like 841 Series, remark last Version 13 not supported

Hope that the Freifunk Software will be updated fast!

More Information go: https://openwrt.org/

Outlook 2016 unsharp Fonts on Laptop Screen

If you asked for help on a new Windows 10 Laptop with Outlook 2016 cause the displayed Fonts unsharp or unclear

check Outlook Settings -> Advanced -> Display -> set „disable Hardware Acceleration“ for the Video Card !

outlook-2016-unsharp-fonts

or check the Subpixel Rendering of windows 10 go:

Search -> Clear Type Settings -> rerun all Dialogs -> select the best readable Window with Texts

Remark:

  • Can be a Linux Problem too! Seen on some OpenOffice Setups!
  • Checkout if installed, the advanced Video Driver Software at System Settings or beside Clock Icons! (seen at ATI)

 

Ubuntu 16.04 Compiz Hang Kernel

After Ubuntu published the latest Kernel Patches for Meltdown and Spectre the Kernel 4.4.0-104/109-generic let Intel Graphics freeze or hang on Compiz with Unity.

Howto fix:

Install the latest Kernel 4.4.0-112-generic

do:
sudo apt-get install linux-image-4.4.0-112-generic
sudo apt-get install linux-image-extra-4.4.0-112-generic

reboot

then:

sudo apt-get autoremove --purge -y

This removes older kernels and save Space! Do test the PC for hanging again!!!

Locale Umloud Problems Cron

If you run scripts to handle text output by cronjobs your perhaps get problems with umlouds „ÖÄÜ“ cause they are displayed by „**“.
This is a problem cause cron uses „C“ setting as locale, you can test it by setting it into root crontab:

open crontab from root with:

$su - root
$crontab -

insert
* * * * * locale

This will mail cron’s locale echo to the mailbox of root! Read root’s mail!
After tests remove the locale entry at crontab!

Howto fix for Scripts:

open crontab from root with:

$su - root
$crontab -e

insert (for German):

LANG=de_DE.UTF-8 
LC_ALL=de_DE.UTF-8

for US:
LANG=en_US.UTF-8 
LC_ALL=en_US.UTF-8

Debian: without sytemd

If you run Debian Servers, you read last weeks about security problems of systemd service manager.

On several tests i have seen much systems having problems on service starts on boot like on debian, raspian ..

This is a result of not clean redesigned scripts of the services by the Maintainers like the Proxy Server „privoxy“ Package…

For Tests i decided to try the new Debian Fork Replacement DEVUAN  for Desktop and a standard Debian Server Setup without systemd!

Howto purge Systemd on a Debian System read this external Wiki:

http://without-systemd.org/wiki/index.php/How_to_remove_systemd_from_a_Debian_jessie/sid_installation

or try Devuan for Server and Desktop:

https://devuan.org/

Remark: Devuan is tested for Desktop usage cause customized scripts and packages like polkit for EASY setup!

Nvidia: Legacy Driver Debian 9.0 Stretch Kernel 4.9 Bug Interface

Current is a UNFIXED Bug on Debian 9.0 Stretch which makes impossible to easy install DKMS Nvidia-Legacy Drivers 304/340 for older Geforce Cards

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852152

To run nouveau on upgrade 8.0 to 9.0 go to /etc/modprobe.d and remove MANUAL all blacklist configs (*.conf) of nvidia cause some glued on upgrade and are not purged automatic by the upgrade. Cause they will block nouveau load at boot (xserver-xorg-video-nouveau)

Then run on Terminal:

$sudo update-initramfs -u -k all
$sudo update-grub
$sudo reboot

Remarks:

  • Older Hardware isn’t supported by Legacy Drivers after Nvidia-375!!
  • If you not forced to upgrade to 9.0, then WAIT! up to 3 Month! and checkout Bug Lists.
  • I tried Nvidia Installer Files too (*.run) they don’t work too, seems a API of the Kernel is changed
  • Nouveau Version on Debian Stretch is able to run Kodi (glx)! seen on Geforce 8400GS 256MB
  • On Onboard Geforce Chips like older Laptops HOLD Debian 8.0