Re: What does this error mean?

Jose M Calhariz <[email protected]> Tue, 23 Jul 2024 03:07:37 +0100
Newsgroups gmane.comp.archivers.amanda.user,gmane.comp.archivers.amanda.devel
Message-ID <[email protected]>
--SJHXA7/WYCXsi1E+
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,

Currently I do not have a setup with S3 at amanda, so this kind of
problems are under my radar. I think it broke with the upgrade to
Debian v12 and some security updates for Debian v11.  Can anyone
confirm or deny?

I am currently working on updating amanda for Debian v13 so later I
can provide non official packages for Debian v12 of an updated amanda,
possibly 3.5.4.


Kind regards
Jose M Calhariz


On Mon, Jul 22, 2024 at 01:49:21PM -0400, Robert Heller wrote:
> I opened an issue: https://github.com/zmanda/amanda/issues/259
>=20
> I uploaded the *working* configs for Amanda 3.3.3 under CentOS 7.  The 3.=
3.3=20
> configuation is not liked by Amanda 3.5.1 under Debian 12 (not supprising=
). I=20
> *think* I updated the configs for 3.5.1 correctly (can anyone check?).
>=20
> I don't know if this is a bug in Amanda 3.5 or if I have something wrong.
>=20
> At Mon, 22 Jul 2024 18:24:28 +0200 Exuvo <[email protected]> wrote:
>=20
> >=20
> > You can try enabling the "device-property VERBOSE" and see if the logs =
show anything useful.
> >=20
> > Anton "exuvo" Olsson
> >     [email protected]
> >=20
> > On 2024-07-22 18:21, Robert Heller wrote:
> > >
> > > At Mon, 22 Jul 2024 18:00:16 +0200 Exuvo <[email protected]> wrote:
> > >
> > >> According to man amanda-changers the device properties can be specif=
ied in
> > >> multiple places so where you have them should also work.
> > > I don't think that is the problem.  According to this:
> > >
> > > https://stackoverflow.com/questions/30518899/amazon-s3-how-to-fix-the=
-request-signature-we-calculated-does-not-match-the-s
> > >
> > > The problem might be the pathname going to Amazon is bad (leading . o=
r leading
> > > /), but *I* am not using either, so I guess Amanda is messing up the
> > > "signature" somehow.  So this might be a bug?  This used to work with=
 Amanda
> > > 3.3, so it might be something broke in 3.4 or 3.5.
> > >
> > > (I've also opened an issue on github.)
> > >
> > > And I think the "tapedev" is indicated by the
> > >      tpchanger "chg-multi:s3:sharky5-backups/slot-{00..40}"
> > > line: it is a changer on an Amazon s3 device with with a Bucket of
> > > sharky5-backups, with slots slot-00 through slot-40.
> > >
> > >> Anton "exuvo" Olsson
> > >>      [email protected]
> > >>
> > >> On 2024-07-22 17:19, Robert Heller wrote:
> > >>> At Mon, 22 Jul 2024 17:10:23 +0200 Exuvo <[email protected]> wrote:
> > >>>
> > >>>> Never used S3 but dont you need to use a "tapdev" line and device =
properties on that instead of on the changer?
> > >>>> See man amanda-devices S3 Device
> > >>> No, that does not work.  Get a config file syntax error...   The do=
cs are
> > >>> somewhat wrong.
> > >>>
> > >>>> Anton "exuvo" Olsson
> > >>>>       [email protected]
> > >>>>
> > >>>> On 2024-07-22 14:24, Robert Heller wrote:
> > >>>>> backup@sharky5:~$ amcheck sharky5
> > >>>>> Amanda Tape Server Host Check
> > >>>>> -----------------------------
> > >>>>> NOTE: tapelist file does not exists
> > >>>>>          it will be created on the next run
> > >>>>> NOTE: Holding disk '/var/lib/amanda/holdings/sharky5': 38816 MB d=
isk space available, using 12000 MB as requested
> > >>>>> slot 1: While creating new S3 bucket: The request signature we ca=
lculated does not match the signature you provided. Check your key and sign=
ing method. (SignatureDoesNotMatch) (HTTP 403)
> > >>>>> slot 2: While creating new S3 bucket: The request signature we ca=
lculated does not match the signature you provided. Check your key and sign=
ing method. (SignatureDoesNotMatch) (HTTP 403)
> > >>>>>
> > >>>>> backup@sharky5:~$ cat /etc/amanda/sharky5/amanda.conf
> > >>>>> org "Deepwoods Software Sharky5"        # your organization name =
for reports
> > >>>>> mailto "[email protected]"    # space separated list of operato=
rs at your site
> > >>>>> dumpcycle 28 days       # the number of days in the normal dump c=
ycle
> > >>>>> runspercycle 28          # the number of amdump runs in dumpcycle=
 days
> > >>>>>                            # (1 week * 5 amdump runs per week -- =
just weekdays)
> > >>>>> tapecycle 40 tapes      # the number of tapes in rotation
> > >>>>>                            # 1 week (dumpcycle) times 5 tapes per=
 week (just
> > >>>>>                            # the weekdays) plus a few to handle e=
rrors that
> > >>>>>                            # need amflush and so we do not overwr=
ite the full
> > >>>>>                            # backups performed at the beginning o=
f the previous
> > >>>>>                            # cycle
> > >>>>> runtapes 3              # number of tapes to be used in a single =
run of amdump
> > >>>>>
> > >>>>> define changer my_s3 {
> > >>>>>        tpchanger "chg-multi:s3:sharky5-backups/slot-{00..40}"
> > >>>>>        device-property "S3_ACCESS_KEY" "XXXXXXXXXXXXXXXXXXXXXX"
> > >>>>>        device-property "S3_SECRET_KEY" 'xxxxxxxxxxxxxxxxxxxxxxxxx=
x"
> > >>>>>        device-property "NB_THREADS_BACKUP" "3"
> > >>>>> #    changerfile "/etc/amanda/sharky5/changer.conf"
> > >>>>> }
> > >>>>> tpchanger "my_s3"
> > >>>>> tapetype S3     # what kind of tape it is (see tapetypes below)
> > >>>>>
> > >>>>>
> > >>>>> I am sure the S3_ACCESS_KEY and S3_SECRET_KEY are correct.
> > >>>>>
> > >>>>                                                                   =
                 =20
> > >>>>
> > >>                                                                     =
              =20
> > >>
> >=20
> >                                                                        =
     =20
> >=20
> >=20
> >=20
>=20

--=20
--

Os velhos n=E3o se tornam mais s=E1bios, mas mais prudentes

--Ernest Hemingway

--SJHXA7/WYCXsi1E+
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEERkvHzUOf7l6LQJigNIp3jWiF748FAmafEFsACgkQNIp3jWiF
74+E1A/9HAYfm4qVNi5aJxXY0Zc6wGHSw1rjU3vcdTUsLgQtv+M/sS68tUHq/U3h
Qqciv71Lc2mMHKWzR9G2OK8rP/Z296FjUTNXtSg/RiA+et7ak2Dfscg7iDMU/2xc
sf6EPGNeK+972Min3jK7sGQsD7NkQFI3hARra4a4+V9pgnHBchAih8abXZoHci99
EqAUgY7YVCidhkHEDqGDPy80TZafOEl8ajRRY7zXccDtlRG70tVzR7xQPXSckhhe
m8x/0VsG9qIT0vNGYqFt5JglZH1VPUnGLVRbVtlv1HekzE49VkzaWqB8hgcT0I4v
s+Ba+b9hcy2AkYJCIICqAGon17Fxoe8I6SBvjKtpZHNufYhyCp2tCNrE63A1ab/R
xfh/rqlky1uQtcwtyseX+daLlv+thQ2+HapZv1WMPGnFfrXqkn/JAjIVhngY7SeU
EBxjtjvC1R6N01n3wQ03vsN7KQN4fjTx47fa1kf2sUcDcqRMUJZ6V0+ow4iYm+Ec
XH+0pk/hfM6u3hsGKC5+iRzoqMnNbNdFyVMJUPTUoHZrLQQyxuU3Bq+bViV9wBWz
7ugpGv2G/DmCir9JGnHaqdaWpkXo4niviR3ARytRtrd1ML4tRGEt5IS4gxOfPAke
IFR6zvsf2WSewYNDTuR5Sbhd7Jn+/CQ6yVjLR6Swslv41AWF3b8=
=rVQz
-----END PGP SIGNATURE-----

--SJHXA7/WYCXsi1E+--