čtvrtek 27. listopadu 2025

Fixing OpenDKIM Signing After Upgrading Ubuntu 18.04 LTS → 24.04 LTS

 (prispevek zformuloval GPT chatbot na zaklade mych velmi strucnych poznamek)

After a long-planned upgrade from Ubuntu 18 LTS straight to Ubuntu 24 LTS, I discovered that outgoing e-mail was no longer being signed with OpenDKIM. What followed was a small adventure involving masked services, silent failures, and a missing package. Here is the full story for anyone who runs into the same issue.

1. First symptoms: DKIM signing stopped working

Right after the upgrade, outgoing mail lost its DKIM signatures.
A look into /var/log/mail.log showed a clear clue:

postfix/smtpd[153304]: warning: connect to Milter service inet:localhost:8892: Connection refused

Port 8892, where OpenDKIM normally listens, was not responding:

# ss -tuln | grep 8892 (no output)

So the DKIM milter was simply not running.

2. Trying to start OpenDKIM — and finding it masked

My next step was obvious: check the service.

# systemctl start opendkim Failed to start opendkim.service: Unit opendkim.service is masked.

Status confirmed it:

# systemctl status opendkim opendkim.service Loaded: masked (Reason: Unit opendkim.service is masked.) Active: inactive (dead)

Why the upgrade masked the service is unclear, but unmasking is straightforward:

# systemctl unmask opendkim # systemctl start opendkim

This time the service started—at least according to systemd.
But DKIM signatures were still missing.

3. Adding debug logging

To see what was going on, I enabled more verbose logging by adding to /etc/opendkim.conf:

SyslogSuccess yes LogWhy yes

After that:

# systemctl restart opendkim

The service looked healthy, no visible errors... but still no signs of DKIM signing.

4. The surprising discovery: OpenDKIM wasn’t installed (!?)

Running locate gave the final hint:

# locate opendkim opendkim:

It essentially returned nothing.
At this point it became clear: the service files were present, but the actual OpenDKIM binary was not installed (a side effect of the distribution jump).

A quick explicit install solved everything:

# apt install opendkim

And — voilà — DKIM signing immediately started working again.

5. Conclusion

Upgrading directly from Ubuntu 18 → 24 can leave some services in a strange state. In my case:

  • opendkim.service was masked after the upgrade

  • The service files survived, but the binary package was missing

  • Postfix failed to talk to the milter (Connection refused)

  • Installing OpenDKIM manually restored full functionality

úterý 29. července 2025

multi-hop gateway in wireguard (hub and spoke)

https://www.procustodibus.com/blog/2022/06/multi-hop-wireguard/#internet-gateway-as-a-spoke 

routovani default routy skrz wireguard mezi peerama:

on the client, 172.20.24.15 set 

wg0.conf
[Interface] ... Address = 172.20.24.15/32
[Peer] ... AllowedIPs = 0.0.0.0/0 

ip route add wg_server_ip via 192.168.122.1 dev eth0
ip route add default via 172.20.24.10 dev wg0 

 

on the gateway, 172.20.24.10 

iptables -t nat -A POSTROUTING -s 172.20.24.0/24 -o vlan2 -j MASQUERADE
(a mozna i neco z toho:
iptables -t nat -A POSTROUTING -o oet1 -j MASQUERADE
iptables -A FORWARD -i oet1 ...? ) 

(list:  iptables -t nat -S POSTROUTING )

on the hub (wg server) 172.20.24.1 

wg:
wg set wg2 peer rdwrtQdE7Z0SqZcJmoydFD74vXLLTnf+gk9go5pDWRw= allowed-ips 0.0.0.0/0 (namisto 172.20.24.10/24) (klic je klienta gateway) 

routing:
echo "123 wgfrompeer" >> /etc/iproute2/rt_tables #tim se nastavi jen jmeno
ip route add default via 172.20.24.10 dev wg2 table 123
ip rule add iif wg2 table 123 priority 100

(list:  ip route show table 123 , ip rule show )

 

firewall:
# neco z tohodle:
sysctl -w net.ipv4.ip_forward=1 (to uz je zrejme jako default)
iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i wg2 -s 172.20.24.0/24 -j ACCEPT
iptables -I FORWARD -i wg2 -o wg2 -j ACCEPT

středa 5. března 2025

File browser and file dialogs take a long time to open

 https://askubuntu.com/questions/1341909/file-browser-and-file-dialogs-take-a-long-time-to-open-or-fail-to-open-in-all-ap

 

Fast solution: 

pkill gvfsd-trash

Brute force permanent solution:

mv /usr/libexec/gvfsd-trash{,.bak}

 

úterý 3. září 2024

override ownership of mounted filesystem

 According to How can I mount a filesystem, mapping userids? :

I need to mount image file and share the content in the samba tree.

The thus, I need to remap original "user" to local user "nobody".

 

 

apt install  bindfs
root# mount -o ro /dev/loop1 /mnt/1 
root# bindfs -u nobody -g nogroup --map=user/nobody /mnt/1 /data/samba/tree/mountpoint

pátek 9. srpna 2024

Ansys 57 on 64-bit Debian 12 Bookworm

1. copy old installation tree

2. try it it runs:

 ~$ /ansys_inc/ansys57/bin/xansys57
bash: /ansys_inc/ansys57/bin/xansys57: cannot execute: required file not found

or:

 ~$ LM_LICENSE_FILE=1057@server /ansys_inc/ansys57/bin/ansys57 < inputfile.inp

If this works, change the variable definition: setenv ANSYSLIC_DIR /ansys_inc/ansys57
in /ansys_inc/ansys57/bin/anscript57.ini
and create the license file

echo SERVER=1057@server > /ansys_inc/ansys57/ansyslmd.ini 

3. add missing binaries

# apt install ncompress tcsh
# dpkg --add-architecture i386
# apt-get update
# apt install libc6-i386

ldd command lists missing libraries:

# ldd /ansys_inc/ansys57/bin/linuxia32/xans.e57
....
# apt-get install   libxi6:i386
# apt-get install   libxt6:i386
# apt-get install   libxpm4:i386
# dpkg -L  libxpm4:i386
# ln -s /usr/lib/i386-linux-gnu/libXpm.so.4.11.0 /usr/lib/i386-linux-gnu/libXp.so.6

# The Motif library libXm.so.2 is included in the original tree in a rpm file: extract libraries from

/ansys_inc/ansys57/syslib/OPENMOTIF/openmotif-2.1.30-2_ICS.i386.rpm
/ansys_inc/ansys57/syslib/MESA/Mesa-3.2-1rh61.i386.rpm

into /ansys_inc/ansys57/syslib/linuxia32 folder and create symlink:

cd /ansys_inc/ansys57/syslib/linuxia32
ln -s libXm.so.2.1 libXm.so.2

goto 2.