<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Michael,<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>I did what you indicated, but got "no such file or directory" on both find commands.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>After the httpd start, I got a bunch of these:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>[Sun Apr 10 07:59:01 2011] [warn] NameVirtualHost 69.65.36.46:80 has no VirtualHosts<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Is this OK?<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>-Mark<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> blueonyx-bounces@blueonyx.it [mailto:blueonyx-bounces@blueonyx.it] <b>On Behalf Of </b>Michael Stauber<br><b>Sent:</b> Sunday, April 10, 2011 5:45 AM<br><b>To:</b> BlueOnyx General Mailing List<br><b>Subject:</b> [BlueOnyx:06956] IMPORTANT: Last nights YUM updates - official fix<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><p style='margin:0in;margin-bottom:.0001pt'><span style='font-family:"Arial","sans-serif"'>Hi all,<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>As mentioned in [BlueOnyx:06936], last nights YUM updates contained a nasty surprise. The problem is with CentOS-5.6's mod_nss-1.0.8-3.el5 RPM.<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>Here is the official fix:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>===============<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>1.) Login to the box by SSH as "admin".<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>2.) Type "su -" to gain root access. <o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>3.) Run the following commands:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>/etc/init.d/httpd stop<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>find /etc/httpd/alias -user root -name "*.db" -exec /bin/chgrp apache {} \;<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>find /etc/httpd/alias -user root -name "*.db" -exec /bin/chmod g+r {} \;<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>/etc/init.d/httpd start<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>That should fix the issues.<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>There are also reports of BlueOnyx's GUI defaulting back to the initial setup wizard after these updates, which I cannot confirm yet. If you run into that, please perform the setup wizard again.<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>--------------------------------------------------------------------------------------<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>Why it happened:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>=============<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>The guys at RedHat (and CentOS) who rolled up the new "mod_nss" addressed some security issues with "mod_nss", which also changed around the required ownerships and permissions of the /etc/httpd/alias/ databases. <o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>In the past the files in /etc/httpd/alias/ were all root owned and had these ownerships and permissions:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>OLD:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>====<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>[root@derelik alias]# ls -la /etc/httpd/alias/*.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw------- 1 root root 65536 Sep 23 2010 /etc/httpd/alias/cert8.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw------- 1 root root 16384 Sep 23 2010 /etc/httpd/alias/key3.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw------- 1 root root 16384 Sep 23 2010 /etc/httpd/alias/secmod.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>Now they're supposed to be this way:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>NEW:<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>====<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>[root@cbq alias]# ls -la /etc/httpd/alias/*.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw-r----- 1 root apache 65536 Sep 23 2010 /etc/httpd/alias/cert8.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw-r----- 1 root apache 16384 Sep 23 2010 /etc/httpd/alias/key3.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-rw-r----- 1 root apache 16384 Sep 23 2010 /etc/httpd/alias/secmod.db<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>As you can see: The group ownership got changed from "root" to "apache" and the databases are now also group readable, which they weren't in the past.<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>CentOS-5.6's new mod_nss-1.0.8-3.el5 RPM (which owns these files) was supposed to fix the ownerships and permissions, but didn't. Hence the problems.<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>I'll release an update to the BlueOnyx YUM repository which will automatically take care of this problem. But first I need to fix www.blueonyx.it and the mirrors as well. \o/<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>Thanks to Rodrigo and the others who helped to address the issue in the meantime!<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>-- <o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>With best regards<o:p></o:p></span></p><p style='margin:0in;margin-bottom:.0001pt;-qt-paragraph-type:empty;-qt-block-indent:0;-qt-user-state:0'><span style='font-family:"Arial","sans-serif"'>Michael Stauber<o:p></o:p></span></p></div></body></html>