Fórum Ubuntu CZ/SK

Ubuntu pro osobní počítače => Obecná podpora => Téma založeno: HonzaD 07 Května 2016, 18:43:00

Název: Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: HonzaD 07 Května 2016, 18:43:00
Chtěl jsem aby se bezpečnostní aktualizace sami instalovaly.
Povolil jsem to a po nějakých aktualizacích jsem znovu dal dialogové okno a volba tam najednou zmizela..
viz příloha

EDIT: ještě přidám tohle

# deb cdrom:[Lubuntu 16.04 LTS _Xenial Xerus_ - Release i386 (20160420.1)]/ xenial main multiverse restricted universe
# deb cdrom:[Lubuntu 15.10 _Wily Werewolf_ - Release i386 (20151021)]/ wily main multiverse restricted universe

# See http://help.ubuntu.com/community/UpgradeNotes for how to upgrade to
# newer versions of the distribution.
deb http://cz.archive.ubuntu.com/ubuntu/ xenial main restricted

## Major bug fix updates produced after the final release of the
## distribution.
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-updates main restricted

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team. Also, please note that software in universe WILL NOT receive any
## review or updates from the Ubuntu security team.
deb http://cz.archive.ubuntu.com/ubuntu/ xenial universe
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-updates universe

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## multiverse WILL NOT receive any review or updates from the Ubuntu
## security team.
deb http://cz.archive.ubuntu.com/ubuntu/ xenial multiverse
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-updates multiverse

## N.B. software from this repository may not have been tested as
## extensively as that contained in the main release, although it includes
## newer versions of some applications which may provide useful features.
## Also, please note that software in backports WILL NOT receive any review
## or updates from the Ubuntu security team.

deb http://cz.archive.ubuntu.com/ubuntu/ xenial-security main restricted
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-security universe
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-security multiverse

## Uncomment the following two lines to add software from Canonical's
## 'partner' repository.
## This software is not part of Ubuntu, but is offered by Canonical and the
## respective vendors as a service to Ubuntu users.
# deb http://archive.canonical.com/ubuntu wily partner
# deb-src http://archive.canonical.com/ubuntu wily partner
# deb http://www.openprinting.org/download/printdriver/debian/ xenial contrib

# See http://help.ubuntu.com/community/UpgradeNotes for how to upgrade to
# newer versions of the distribution.
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial main restricted

## Major bug fix updates produced after the final release of the
## distribution.
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial-updates main restricted

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## universe WILL NOT receive any review or updates from the Ubuntu security
## team.
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial universe
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial-updates universe

## N.B. software from this repository is ENTIRELY UNSUPPORTED by the Ubuntu
## team, and may not be under a free licence. Please satisfy yourself as to
## your rights to use the software. Also, please note that software in
## multiverse WILL NOT receive any review or updates from the Ubuntu
## security team.
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial multiverse
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial-updates multiverse

## N.B. software from this repository may not have been tested as
## extensively as that contained in the main release, although it includes
## newer versions of some applications which may provide useful features.
## Also, please note that software in backports WILL NOT receive any review
## or updates from the Ubuntu security team.
# deb-src http://cz.archive.ubuntu.com/ubuntu/ xenial-backports main restricted universe multiverse

## Uncomment the following two lines to add software from Canonical's
## 'partner' repository.
## This software is not part of Ubuntu, but is offered by Canonical and the
## respective vendors as a service to Ubuntu users.
# deb http://archive.canonical.com/ubuntu xenial partner
# deb-src http://archive.canonical.com/ubuntu xenial partner

# deb-src http://security.ubuntu.com/ubuntu xenial-security main restricted
# deb-src http://security.ubuntu.com/ubuntu xenial-security universe
deb http://cz.archive.ubuntu.com/ubuntu/ xenial-backports universe multiverse main restricted
# deb-src http://security.ubuntu.com/ubuntu xenial-security multiverse

EDIT:
tejný problém mám v ubuntu mate 16.04.1
Nejdřív to šlo a po aktualizacích ta možnost zmizela :(

Podle návodu: wiki.ubuntu.cz/bezpečnost/automatické_bezpečnostní_aktualizace
/etc/apt/apt.conf.d/10periodic jsem měl na 1
Ale soubor /etc/apt/apt.conf.d/50unattended-upgrades jsem měl prázdný.
Krom toho že jsem neměl gedit takže jsem dal pluma to už je asi zastaralé celkově. Chtělo by to tu wiki aktualizovat..
Název: Re:Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: HonzaD 11 Června 2017, 11:35:14
Stejný problém v Lubuntu 17.04
Název: Re:Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: TIBOR 11 Června 2017, 12:27:04
U mna ubuntu mate 16.04.2 LTS vsetko v poriadku. V subore /etc/apt/apt.conf.d/50unattended-upgrades mam
Kód: [Vybrat]
// Automatically upgrade packages from these (origin:archive) pairs
Unattended-Upgrade::Allowed-Origins {
"${distro_id}:${distro_codename}";
"${distro_id}:${distro_codename}-security";
// Extended Security Maintenance; doesn't necessarily exist for
// every release and this system may not have it installed, but if
// available, the policy for updates is such that unattended-upgrades
// should also install from here by default.
"${distro_id}ESM:${distro_codename}";
// "${distro_id}:${distro_codename}-updates";
// "${distro_id}:${distro_codename}-proposed";
// "${distro_id}:${distro_codename}-backports";
};

// List of packages to not update (regexp are supported)
Unattended-Upgrade::Package-Blacklist {
// "vim";
// "libc6";
// "libc6-dev";
// "libc6-i686";
};

// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
//   dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "false";

// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGUSR1. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";

// Install all unattended-upgrades when the machine is shuting down
// instead of doing it in the background while the machine is running
// This will (obviously) make shutdown slower
//Unattended-Upgrade::InstallOnShutdown "true";

// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "root";

// Set this value to "true" to get emails only on errors. Default
// is to always send a mail if Unattended-Upgrade::Mail is set
//Unattended-Upgrade::MailOnlyOnError "true";

// Do automatic removal of new unused dependencies after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";

// Automatically reboot *WITHOUT CONFIRMATION*
//  if the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";

// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
//  Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";

// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";


Odkial stahujes obrazy distribucii? Z oficialnej stranky?
Název: Re:Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: HonzaD 11 Června 2017, 12:43:16
Jo a dělá mi to skoro všude :)

Nemůže to dělat nějaký přidaný repozitář? Například TOX?:
echo "deb https://pkg.tox.chat/debian stable $(lsb_release -cs)" | sudo tee /etc/apt/sources.list.d/tox.list
wget -qO - https://pkg.tox.chat/debian/pkg.gpg.key | sudo apt-key add -
sudo apt-get install apt-transport-https
sudo apt-get update

Nekazí to třeba ten apt-transport-https ?
Jen co napadá mě..
Název: Re:Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: HonzaD 07 Října 2017, 22:21:27
Přišel jsem na to :)
Pokud doinstalujete balíček "unattended-upgrades"
Tak se v Software & Aktualizace (takto se to jmenuje v Lubuntu) zobrazí možnost instalovat automaticky na pozadí bezpečnostní aktualizace. Takže ten cfg /etc/apt/apt.conf.d/50unattended-upgrades bude pro to GUI společný - nevím jak se to chová a jak se to vzájemně přepisuje).

Víc k tomu tedy tady:
https://help.ubuntu.com/lts/serverguide/automatic-updates.html
https://wiki.debian.org/UnattendedUpgrades

Momentálně jsem zaseklý že nevím jak posílat e-maily s přehledemem SW změn a logy a nevím jak přidat automatickou aktualizaci PPA repozitářů.
Osobně bych ocenil lepší klikátko v češtině s možností importu a exportu cfg :) (ta možnost cfg zkopírovat tu je..) s nějakou možností si naklikat možnost posílání mailů (tak aby to mohlo využít cizí smtp server a bylo to odolné proti spamu)..
Název: Re:Bezpečnostní aktualizace - lubuntu 16.04
Přispěvatel: HonzaD 30 Dubna 2018, 14:50:33
Jak přidám další repozitáře (resp všechny) do Unattended-Upgrade::Allowed-Origins?
Stačí tam zadat třeba

Jak se dají přidat další ručně přidané repo nebo PPA