Skip to content
View in the app

A better way to browse. Learn more.

Unraid

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

tr0910

Members
  • Joined

  • Last visited

Everything posted by tr0910

  1. Re: 80% improvement in context switching. I run win10 vm's on my Intel 2670 dual cpu server and they seem more laggy recently. Am I one who will really notice the benefits of this plugin? Sent from my chisel, carved into granite
  2. Thanks for the tips. I wasn't expecting help from the expert, but only if others had tips. It seems that most have continued to use it as you recommended. I will use a VPN to get access securely for now. If the need escalates, I will revisit, thanks.
  3. Seems no one else is wondering about secure ftp??
  4. I have just updated to 6.7 and the latest proFTPd and am wondering about secure ftp configuration. Does anyone have this working? Up until now, only local access was required, there was no need to provide internet access, but now I might need to forward port 21 on my router and I am worried that this isn't secure with the default settings.
  5. Yeah, I'm sure many folks will be delighted when Cloudberry has a bulletproof way to backup to another unRaid server. Share your server with some friends with no risk of exposing each others files. At $139 per 8tb drive, you would need $1000 in drives. That sounds better than $216 per month
  6. We await your fix at your convenience. The docker is ok, but Peter's plugin is better. His works even if the array is stopped. If Peters Open-vpn plugin is important to you wait on installing 6.7 for a bit. It will get fixed.
  7. I was just about to reboot my server after upgrading to 6.7rc2 when I saw this. OpenVPN is required for me. I will postpone this reboot now, possibly for a long time........
  8. You'll find it in the status of encryption thread. It's done from the command line, so no you won't see it in the web GUI. And the good news is that it doesn't result in any data loss.
  9. Microsoft RDP does this real well with Windows VM's Note FAQ is reserved and wasn't meant for support. Mods feel free to clean this up.
  10. There are many exploring what might be useful from a security standpoint. At one end you have the Snowden approved solutions like Qubes, but we all don't have Snowden's problems. @jonp is suggesting that some additional features may be added to unRaid that I would love to use for increased security in the blog Maybe
  11. My dual 2670 report AES enabled repeating the following 32 times. But when I change pfSense to support Cryptographic Hardware I get the following on pfSense 2.4.3-RELEASE (amd64) on noVNC: pfsense padlock0 no ace support root@Tower:~# grep flags /proc/cpuinfo flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology nonstop_tsc cpuid aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2 ssse3 cx16 xtpr pdcm pcid dca sse4_1 sse4_2 x2apic popcnt tsc_deadline_timer aes xsave avx lahf_lm epb pti ibrs ibpb stibp tpr_shadow vnmi flexpriority ept vpid xsaveopt dtherm ida arat pln pts I changed it back to disabled for now pending advice on this error. Is AES enabled in spite of this error?
  12. Or you can have it located offsite at somebody else's house and connect over the internet for the key. I wouldn't suggest wifi as that is only one more thing to go wrong. But I don't see this as being an increased level of security for determined folks. If they really want you data, they will find the rpi. The only thing in you favor, is you may be able to destroy the rpi before they find it. If this is good enough for you, see @gridrunner and @bonienl approach using your cell phone as the rpi. Fundamentally the rpi doesn't add more security than your cell would. You can create your encrypted array by converting one disk at a time. Thankfully @dlandon has updated unassigned devices plugin to support encrypted disks. What you cannot do is format the disks via unassigned devices. And you cannot covert a disk in-place without having a spare disk to copy to. It really is the same process as converting your disks from ReiserFS to XFS or BTRFS file system.
  13. Yep, I want to make sure that if by some strange bit of fate that the key is compromised, that the 2fa keeps them locked out. The timing you suggest would do it. And there could be a ramping up of the timing, after 3 sets of 3 failures, the server is locked for a few hours. This logic would have to be baked in very tightly, as you wouldn't want someone just changing the server bootup "go" file and defeating the security.
  14. We would never want the 6 digit code being treated as a password. Of course it's not secure. But having it combined with an approved key file in classic 2fa way would be better than just the key file with no 2fa.
  15. I''ve seen some very well thought out ideas here for starting encrypted arrays, but I haven't seen any discussion of some very strongly supported and well reputed 2 factor authentication systems like Google Authenticator, or Authy. Two factor authentication was first implemented by sending an unlock code via cell text message, but spoofing cell text messages have not proven as unhackable as hoped. I'll focus on Authy as it is my current solution but you might also want to look at Starling and Duo Security too. Authy is 2 factor authentication supporting Android, iOS, Chrome apps, as well as Win32, Win64 and MacOS desktop solutions. Authy creates a 6 digit random ever changing number for each service you link to it. The 6 digit number changes every 60 seconds. To use, you tell google that you want to set up 2 factor authentication, and then create an Authy secure entry that matches the google account. Then you can have Google force you to enter the random 6 digit number every time you login, along with your password, or more infrequently such as every time you reboot. (this is configurable based on your paranoia level). The nice thing about Authy, is that it works without needing cell phone coverage as it is fully offline once set up. I have changed stuff I want more secure over to Authy. Facebook, gMail, hotmail, Amazon, Digital Ocean, twitter, AWS, Teamviewer etc now all support this approach. Why Bank of America, Chase etc still don't support a system like this is beyond me. I have the Authy app on my phone protected by my fingerprint. If you are wanting more flexibility, you can have Authy replicate to another device (say a Chrome browser or desktop) so that if you lose a device, you can still manage the account and unregister the lost device. Could we lock down the unRaid encryption keyfile for encrypted array startup and only have it divulged based on a successful Authy 2 factor authentication challenge?
  16. I use the same keyfile/passphrase on the backup server so that I can mount on the primary server. The problem is very puzzling and may simply be USB3 related. Formatting XFS-Encrypted on a backup server is the only convenient way today to add an encrypted drive to UD.
  17. I have taken another 4tb drive that has been previously connected to this server when it was XFS formatted and converted it to an empty XFS-Encrypted disk on another server. I am getting the same problem with my server not recognizing that it has been previously formatted XFS-Encrypted and wanting to format it again. This is now 2 drives with this same issue. To troubleshoot, I did a new config on the intended destination server and formatted them xfs-encrypted there as a way to prove beyond a shadow of a doubt what might be wrong. I then restored the server to its previous configuration and these 2 4tb drives were attached via UD. This time they worked without issue. In conclusion, sometimes you can format xfs-encrypted on another machine and then mount on the intended server via UD, and sometimes you cannot. The 2 drives that I was able to do this with were both 2tb. The 2 that wouldn't work were 4tb drives. The other thing that might have been a factor was that there were formatted via a USB3 external device. I did also try and plug the USB3 device into the intended destination server and see if we could mount them that way. Surprisingly one of the drives showed up as crypto formatted on the USB3 connection, but it still would not mount.
  18. Actually the hardware failures are me hot-plugging the drive in and out hoping for it to be properly recognized. Since that never worked, I rebooted cleanly, and still the xfs-encrypted disk ST4000DM000-1F2168_S30030A6 is not showing up as mountable. Notice that the SAMSUNG_HD203WI_S1UYJ1YZ601695 is also xfs-encrypted and has no problems mounting via UD. Something is weird with the 4tb Seagate. I hoped a reboot would clean up the problems, but it still is stuck with only a format option showing. What should I try next? (see diagnostics attached for both server conditions, before and after reboot) drchina1-diagnostics-20180506-1442.zip drchina1-diagnostics-20180506-2047.zip
  19. I have had many single sector issues and since I have a hot spare, I yank the offending drive and rebuild to the spare. I them start a pre clear on the offending drive, and most of the time the offending sector returns good. False alarm?? Sent from my Nexus 6 using Tapatalk
  20. Don't think it's connection as I can format via UD then use without problem. However if I reformat as xfs encrypted and reconnect it won't mount. Sent from my Nexus 6 using Tapatalk
  21. Strange behavior for a 4tb disk converted to xfs-encrypted on a different machine and then plugged in and attempted to mount with UD. No option to rename the device is given and format is the only option available. It should present a mount option. This drive was previously formatted xfs and attached via UD so there is some history that may be confusing things. However after I have forgotten the historical record of it, still no luck mounting it. I have done this exact same process with other drives and had no issue mounting xfs-encrypted. What might be wrong with this one? Relevant logs below? May 5 11:14:08 drChina1 kernel: ata7: hard resetting link May 5 11:14:09 drChina1 kernel: ata7: SATA link down (SStatus 0 SControl 300) May 5 11:14:09 drChina1 kernel: ata7: limiting SATA link speed to 1.5 Gbps May 5 11:14:14 drChina1 kernel: ata7: hard resetting link May 5 11:14:14 drChina1 kernel: ata7: SATA link down (SStatus 0 SControl 310) May 5 11:14:14 drChina1 kernel: ata7.00: disabled May 5 11:14:14 drChina1 kernel: ata7: EH complete May 5 11:14:14 drChina1 kernel: ata7.00: detaching (SCSI 7:0:0:0) May 5 11:14:14 drChina1 kernel: sd 7:0:0:0: [sdh] Synchronizing SCSI cache May 5 11:14:14 drChina1 kernel: sd 7:0:0:0: [sdh] Synchronize Cache(10) failed: Result: hostbyte=0x04 driverbyte=0x00 May 5 11:14:14 drChina1 kernel: sd 7:0:0:0: [sdh] Stopping disk May 5 11:14:14 drChina1 kernel: sd 7:0:0:0: [sdh] Start/Stop Unit failed: Result: hostbyte=0x04 driverbyte=0x00 May 5 11:14:14 drChina1 rc.diskinfo[9417]: SIGHUP received, forcing refresh of disks info. May 5 11:14:14 drChina1 rc.diskinfo[9417]: SIGHUP received, forcing refresh of disks info. May 5 11:18:48 drChina1 kernel: ata7: exception Emask 0x10 SAct 0x0 SErr 0x4040000 action 0xe frozen May 5 11:18:48 drChina1 kernel: ata7: irq_stat 0x00000040, connection status changed May 5 11:18:48 drChina1 kernel: ata7: SError: { CommWake DevExch } May 5 11:18:48 drChina1 kernel: ata7: hard resetting link May 5 11:18:58 drChina1 kernel: ata7: softreset failed (1st FIS failed) May 5 11:18:58 drChina1 kernel: ata7: hard resetting link May 5 11:19:01 drChina1 kernel: ata7: SATA link up 3.0 Gbps (SStatus 123 SControl 300) May 5 11:19:01 drChina1 kernel: ata7.00: ATA-8: ST4000DM000-1F2168, S30030A6, CC52, max UDMA/133 May 5 11:19:01 drChina1 kernel: ata7.00: 7814037168 sectors, multi 0: LBA48 NCQ (depth 31/32), AA May 5 11:19:01 drChina1 kernel: ata7.00: configured for UDMA/133 May 5 11:19:01 drChina1 kernel: ata7: EH complete May 5 11:19:01 drChina1 kernel: scsi 7:0:0:0: Direct-Access ATA ST4000DM000-1F21 CC52 PQ: 0 ANSI: 5 May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: Attached scsi generic sg7 type 0 May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] 7814037168 512-byte logical blocks: (4.00 TB/3.64 TiB) May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] 4096-byte physical blocks May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] Write Protect is off May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] Mode Sense: 00 3a 00 00 May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA May 5 11:19:01 drChina1 kernel: sd 7:0:0:0: [sdh] Attached SCSI disk May 5 11:19:01 drChina1 rc.diskinfo[9417]: SIGHUP received, forcing refresh of disks info. May 5 11:19:01 drChina1 rc.diskinfo[9417]: PHP Warning: Use of undefined constant ID_MODEL - assumed 'ID_MODEL' (this will throw an Error in a future version of PHP) in /etc/rc.d/rc.diskinfo on line 470 May 5 11:19:01 drChina1 rc.diskinfo[9417]: PHP Warning: Use of undefined constant SERIAL_SHORT - assumed 'SERIAL_SHORT' (this will throw an Error in a future version of PHP) in /etc/rc.d/rc.diskinfo on line 470 Here the result of a successful xfs-encrypted mount May 5 11:37:36 drChina1 unassigned.devices: Adding disk '/dev/mapper/SS_1695'... May 5 11:37:39 drChina1 unassigned.devices: Mount drive command: /sbin/mount '/dev/mapper/SS_1695' '/mnt/disks/SS_1695' May 5 11:37:39 drChina1 kernel: XFS (dm-3): Mounting V5 Filesystem May 5 11:37:39 drChina1 kernel: XFS (dm-3): Ending clean mount May 5 11:37:39 drChina1 unassigned.devices: Successfully mounted '/dev/mapper/SS_1695' on '/mnt/disks/SS_1695'. May 5 11:37:39 drChina1 unassigned.devices: Defining share 'SS_1695' with file '/etc/samba/unassigned-shares/SS_1695.conf' May 5 11:37:39 drChina1 unassigned.devices: Adding share 'SS_1695' to '/boot/config/smb-extra.conf' May 5 11:37:39 drChina1 unassigned.devices: Reloading Samba configuration... May 5 11:37:39 drChina1 unassigned.devices: Directory '/mnt/disks/SS_1695' shared successfully. May 5 11:37:39 drChina1 unassigned.devices: Device '/dev/mapper/SS_1695' script file not found. 'ADD' script not executed.
  22. I have started using unassigned devices for mounting xfs-encrypted drives. I am needing to take backups of the Luks Header, as this is recommended for disaster recovery. If the drive is array mounted I would: cryptsetup luksHeaderBackup /dev/md1 --header-backup-file /boot/LuksHeaderBackup/SS_2T_1695 But with unassiged devices I get the following: May 2 08:55:39 drChina1 unassigned.devices: Adding disk '/dev/mapper/SS_1695'... May 2 08:55:41 drChina1 unassigned.devices: Mount drive command: /sbin/mount '/dev/mapper/SS_1695' '/mnt/disks/SS_1695' May 2 08:55:41 drChina1 kernel: XFS (dm-2): Mounting V5 Filesystem May 2 08:55:41 drChina1 kernel: XFS (dm-2): Ending clean mount May 2 08:55:42 drChina1 unassigned.devices: Successfully mounted '/dev/mapper/SS_1695' on '/mnt/disks/SS_1695'. and referencing as /dev/mapper/SS_1695 just errors out with "Device /dev/mapper/SS_1695 is not a valid LUKS device." Is this not the correct way to reference this drive?
  23. UD does not support formatting to the encrypted file systems that unRaid now supports. I would be interested in XFS encrypted formatting specifically. Thanks for making UD support mounting encrypted devices. Is there any way to format a drive as encrypted in UD?
  24. This issue seems to persist on 6.5 too. Once I trigger a false alarm with the plugin by deleting a file in the monitored shares, the server shuts SMB down and resetting the plugin does not reset the SMB access. It is totally gone and only a stop of the array and a restart of the array restores access. I seem to recall the SMB shares would go to read only before on 6.3 They didn't completely go off-line. I am only using bait shares and not using bait files.
  25. My China IP address changes every 48 hours like clockwork

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.