Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #209997 > unrolled thread

An Ounce of Prevention

Started byBob Bernstein <poobah@ruptured-duck.com>
First post2019-06-17 20:30 +0200
Last post2019-07-02 11:20 +0200
Articles 18 — 9 participants

Back to article view | Back to linux.debian.user


Contents

  An Ounce of Prevention Bob Bernstein <poobah@ruptured-duck.com> - 2019-06-17 20:30 +0200
    Re: An Ounce of Prevention Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-17 20:40 +0200
      Re: An Ounce of Prevention Tixy <tixy@yxit.co.uk> - 2019-06-17 20:50 +0200
        Re: An Ounce of Prevention Tixy <tixy@yxit.co.uk> - 2019-06-17 21:00 +0200
          Re: An Ounce of Prevention Tixy <tixy@yxit.co.uk> - 2019-06-17 21:00 +0200
      Re: An Ounce of Prevention Bob Bernstein <bob@fanatick.org> - 2019-06-17 22:00 +0200
        Re: An Ounce of Prevention Bob Bernstein <poobah@ruptured-duck.com> - 2019-06-18 02:50 +0200
          Re: An Ounce of Prevention Andy Smith <andy@strugglers.net> - 2019-06-18 03:00 +0200
            Re: An Ounce of Prevention Bob Bernstein <bob@fanatick.org> - 2019-06-18 03:50 +0200
              Re: An Ounce of Prevention Andy Smith <andy@strugglers.net> - 2019-06-18 04:40 +0200
                Re: An Ounce of Prevention Bob Bernstein <bob@fanatick.org> - 2019-06-18 06:30 +0200
                  Re: An Ounce of Prevention <tomas@tuxteam.de> - 2019-06-18 10:20 +0200
                  Re: An Ounce of Prevention Richard Hector <richard@walnut.gen.nz> - 2019-06-18 10:40 +0200
                  Re: An Ounce of Prevention Andy Smith <andy@strugglers.net> - 2019-06-18 13:20 +0200
                    Re: An Ounce of Prevention <tomas@tuxteam.de> - 2019-06-18 13:40 +0200
                    Re: An Ounce of Prevention Bob Bernstein <bob@fanatick.org> - 2019-06-18 17:40 +0200
    Re: An Ounce of Prevention Joe <joe@jretrading.com> - 2019-06-17 21:50 +0200
    Re: An Ounce of Prevention andreimpopescu@gmail.com - 2019-07-02 11:20 +0200

#209997 — An Ounce of Prevention

FromBob Bernstein <poobah@ruptured-duck.com>
Date2019-06-17 20:30 +0200
SubjectAn Ounce of Prevention
Message-ID<ya4ye-2TV-7@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

For a change, I want to proceed with a tad of caution 
rather than follow Don't RTFM - Wing That Sucker.

I have an old Jessie running:

Linux debian.localdomain 3.16.0-7-amd64 #1 SMP Debian 3.16.59-1 (2018-10-03) x86_64 GNU/Linux

...and it has been borne in on me that my kernel needs to 
be retired. This old Jessie dates back to the Bad Old Days 
of the systemd wars and has no systemd onboard. I am of a 
mood though to take a Great Leap Forward and install 
Stretch -- systemd 'n all.

My untutored instinct is to go through my apt sources.list 
and replace every instance of 'jessie' with 'stretch,' and 
leave the rest up to apt-get, but I thought YOU SHOULD ASK 
ON THE LIST FIRST BOB.

Full disclosure: I have not kept up. Are there resources, 
wikis, etc, dedicated to Upgrading Debian For Dummies?

All input will be graciously accepted.

Thank you

-- 
"In our age there is no such thing as ‘keeping out of 
politics’. All issues are political issues, and politics 
itself is a mass of lies, evasions, folly, hatred, and 
schizophrenia."

 George Orwell "Politics and the English Language" (1946) 

[toc] | [next] | [standalone]


#209998

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-06-17 20:40 +0200
Message-ID<ya4HT-2X3-5@gated-at.bofh.it>
In reply to#209997
On Mon, Jun 17, 2019 at 02:20:33PM -0400, Bob Bernstein wrote:
> Full disclosure: I have not kept up. Are there resources, 
> wikis, etc, dedicated to Upgrading Debian For Dummies?

https://www.debian.org/releases/stretch/amd64/release-notes/ch-upgrading.html

[toc] | [prev] | [next] | [standalone]


#210000

FromTixy <tixy@yxit.co.uk>
Date2019-06-17 20:50 +0200
Message-ID<ya4RA-31f-3@gated-at.bofh.it>
In reply to#209998
On Mon, 2019-06-17 at 14:37 -0400, Greg Wooledge wrote:
> On Mon, Jun 17, 2019 at 02:20:33PM -0400, Bob Bernstein wrote:
> > Full disclosure: I have not kept up. Are there resources, 
> > wikis, etc, dedicated to Upgrading Debian For Dummies?
> 
> https://www.debian.org/releases/stretch/amd64/release-notes/ch-upgrading.html

And the following chapter in the release notes may be worth skimming as
well to see if there's any changes that may affect you:

https://www.debian.org/releases/stretch/amd64/release-notes/ch-information.en.html

Note, both the above links are for the amd64 CPU architecture, there
are differend notes for other architectures, so if you use another,
look at the top level page:

https://www.debian.org/releases/stretch/ 

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#210001

FromTixy <tixy@yxit.co.uk>
Date2019-06-17 21:00 +0200
Message-ID<ya51f-34H-1@gated-at.bofh.it>
In reply to#210000
On Mon, 2019-06-17 at 19:46 +0100, Tixy wrote:
[...]
> Note, both the above links are for the amd64 CPU architecture, there
> are differend notes for other architectures, so if you use another,
> look at the top level page:
> 
> https://www.debian.org/releases/stretch/ 

Correction, for the Installation Guide:
https://www.debian.org/releases/stretch/installmanual

[toc] | [prev] | [next] | [standalone]


#210002

FromTixy <tixy@yxit.co.uk>
Date2019-06-17 21:00 +0200
Message-ID<ya51g-34H-5@gated-at.bofh.it>
In reply to#210001
On Mon, 2019-06-17 at 19:52 +0100, Tixy wrote:
> On Mon, 2019-06-17 at 19:46 +0100, Tixy wrote:
> [...]
> > Note, both the above links are for the amd64 CPU architecture,
> > there
> > are differend notes for other architectures, so if you use another,
> > look at the top level page:
> > 
> > https://www.debian.org/releases/stretch/ 
> 
> Correction, for the Installation Guide:
> https://www.debian.org/releases/stretch/installmanual

Doh! Third time lucky? I really meant Release Notes at...
https://www.debian.org/releases/stretch/releasenotes

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#210004

FromBob Bernstein <bob@fanatick.org>
Date2019-06-17 22:00 +0200
Message-ID<ya5Xk-3El-9@gated-at.bofh.it>
In reply to#209998
On Mon, 17 Jun 2019, Greg Wooledge wrote:

> On Mon, Jun 17, 2019 at 02:20:33PM -0400, Bob Bernstein wrote:

>> Full disclosure: I have not kept up. Are there resources, 
>> wikis, etc, dedicated to Upgrading Debian For Dummies?

> https://www.debian.org/releases/stretch/amd64/release-notes/ch-upgrading.html

Bingo! Exactly what I needed. We are underway with the upgrade 
as I type this. Fingers crossed.

Thank you

-- 
These are not the droids you are looking for.

[toc] | [prev] | [next] | [standalone]


#210018

FromBob Bernstein <poobah@ruptured-duck.com>
Date2019-06-18 02:50 +0200
Message-ID<yaatX-6qv-1@gated-at.bofh.it>
In reply to#210004
Stretch is installed with a shiny new kernel. Stretch doesn't know 
how to boot up while turning networking "on" in the process. X 
doesn't work now either.

So, any hints about networking?

-- 
What can be asserted without evidence can be 
dismissed without evidence.
                             Hitchens' Razor

[toc] | [prev] | [next] | [standalone]


#210019

FromAndy Smith <andy@strugglers.net>
Date2019-06-18 03:00 +0200
Message-ID<yaaDD-6tM-1@gated-at.bofh.it>
In reply to#210018
Hello,

On Mon, Jun 17, 2019 at 08:39:32PM -0400, Bob Bernstein wrote:
> So, any hints about networking?

Possibly your network interface has changed name due to persistent
naming? In any case, please can we see the contents of your
/etc/network/interfaces file, and the output of:

$ ip link
$ ip address show

Or do you generally have no networking until X starts and gives you
NetworkManager, etc?

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#210020

FromBob Bernstein <bob@fanatick.org>
Date2019-06-18 03:50 +0200
Message-ID<yabq2-6YZ-1@gated-at.bofh.it>
In reply to#210019
On Tue, 18 Jun 2019, Andy Smith wrote:

> Possibly your network interface has changed name due to 
> persistent naming? In any case, please can we see the contents 
> of your /etc/network/interfaces file...

/etc/network/interfaces

-snip-
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

source /etc/network/interfaces.d/*

auto lo eth0
iface lo inet loopback

iface eth0 inet static
     address 192.168.1.40
     netmask 255.255.255.0
     gateway 192.168.1.1
     dns-nameserver 8.8.8.8
-snip-

*The dns-nameserver line is brandy-new today. I've used the rest 
of that, above, for years.)

> and the output of:
> $ ip link

-snip-
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
     link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
     link/ether 00:24:21:87:09:c2 brd ff:ff:ff:ff:ff:ff
3: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN mode DEFAULT group default qlen 100
     link/none 
-snip

> $ ip address show

-snip-
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
     link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
     inet 127.0.0.1/8 scope host lo
        valid_lft forever preferred_lft forever
     inet6 ::1/128 scope host
        valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
     link/ether 00:24:21:87:09:c2 brd ff:ff:ff:ff:ff:ff
     inet 192.168.1.40/24 brd 192.168.1.255 scope global eth0
        valid_lft forever preferred_lft forever
     inet6 2600:8805:8900:120:224:21ff:fe87:9c2/64 scope global mngtmpaddr dynamic
        valid_lft 83116sec preferred_lft 83116sec
     inet6 fe80::224:21ff:fe87:9c2/64 scope link
        valid_lft forever preferred_lft forever
3: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 100
     link/none
     inet 10.17.15.15/24 brd 10.17.15.255 scope global tun0
        valid_lft forever preferred_lft forever
     inet6 fc00::99:0:0:1:d/64 scope global
        valid_lft forever preferred_lft forever
     inet6 fe80::f2a5:610d:5659:9512/64 scope link flags 800
        valid_lft forever preferred_lft forever
-snip-

(The tun0 somehow survived some openvpn experimentation I was 
doing last night. I have no idea what that IP is. It survived my 
Jessie -> Stretch upgrade done this afternoon.)

> Or do you generally have no networking until X starts and gives you
> NetworkManager, etc?

No. I didn't mean to imply that the X failure was at all 
connected to my networking puzzles. I like to boot to a CLI and 
then type "startx". I don't even know where to go to find 
NetworkManager. Absolute systemd noobie here.

Thank you

-- 
These are not the droids you are looking for.

[toc] | [prev] | [next] | [standalone]


#210022

FromAndy Smith <andy@strugglers.net>
Date2019-06-18 04:40 +0200
Message-ID<yaccq-7yu-3@gated-at.bofh.it>
In reply to#210020
Hi Bob,

On Mon, Jun 17, 2019 at 09:21:57PM -0400, Bob Bernstein wrote:
> iface eth0 inet static
>     address 192.168.1.40
>     netmask 255.255.255.0
>     gateway 192.168.1.1
>     dns-nameserver 8.8.8.8

[…]

> 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
>     link/ether 00:24:21:87:09:c2 brd ff:ff:ff:ff:ff:ff

So you configure eth0 and you do actually have an eth0, so that's
alright.

> 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
>     link/ether 00:24:21:87:09:c2 brd ff:ff:ff:ff:ff:ff
>     inet 192.168.1.40/24 brd 192.168.1.255 scope global eth0
>        valid_lft forever preferred_lft forever

…and your eth0 is currently up and has the IP address you
configured, so that's okay.

So I do wonder why it's not working. What does this say?

$ ip route show

Just wondering what your default route is.

And how are you determining that networking doesn't work? i.e. what
are the symptoms?

What happens if you try to ping something? Like:

$ ping 8.8.8.8

I am ignoring the tun0 stuff right now but that could possibly be
related.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#210023

FromBob Bernstein <bob@fanatick.org>
Date2019-06-18 06:30 +0200
Message-ID<yadUR-dA-1@gated-at.bofh.it>
In reply to#210022
On Tue, 18 Jun 2019, Andy Smith wrote:

> What happens if you try to ping something? Like:

It is the ping failures that give me the most angst, since I am 
one of those people who, almost the first thing they'll do, if 
you sit them down at a computer keyboard, is try to ping 
somebody. I noticed that linode.com returned pings in a fairly 
decent fashion, but godaddy.com and jtan.com returned none.

All I have to do here is click my KVM switch and set the other 
unix system I have to the test. Those last two mentioned hosts 
are commercial for-profit ventures, and are almost always "up," 
as was shown by my *bsd system.

I was also interested to note that linode returned pings in ipv6 
mode. Switching to 'ping -4' ended any return of pings from 
linode. That was the sort of thing that made me think my 
"networking" was "not working."

And it's not lookup issues either, since what I see with Stretch 
is like this:

PING linode.com(2600:3c00::22 (2600:3c00::22)) 56 data bytes
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=1 ttl=51 time=63.4 ms
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=2 ttl=51 time=55.5 ms
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=3 ttl=51 time=56.4 ms
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=4 ttl=51 time=55.6 ms
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=5 ttl=51 time=55.8 ms
64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=6 ttl=51 time=55.9 ms
^C
--- linode.com ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5008ms
rtt min/avg/max/mdev = 55.544/57.151/63.482/2.844 ms

--and--

PING godaddy.com (208.109.192.70) 56(84) bytes of data.

--- godaddy.com ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3051ms

(That dotted four is one of godaddy's mail servers.)

In the middle of all this apparent network confusion, I said to 
myself "Oh, the heck with it..." and started my faithful trusty 
alpine mail system, which certainly requires network services. 
It's been running like a charm here on my new Stretch, which is 
sort of how it always runs, and I am typing on it right now and 
am about to send this overlong excursion.

Thank you

-- 
These are not the droids you are looking for.

[toc] | [prev] | [next] | [standalone]


#210026

From<tomas@tuxteam.de>
Date2019-06-18 10:20 +0200
Message-ID<yahvr-2p7-3@gated-at.bofh.it>
In reply to#210023

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jun 18, 2019 at 12:07:16AM -0400, Bob Bernstein wrote:
> On Tue, 18 Jun 2019, Andy Smith wrote:
> 
> >What happens if you try to ping something? Like:
> 
> It is the ping failures that give me the most angst [...]

> I was also interested to note that linode returned pings in ipv6
> mode. Switching to 'ping -4' ended any return of pings from linode.
> That was the sort of thing that made me think my "networking" was
> "not working."

FWIW, godaddy responds to pings (v4) here. One possible explanation
is that you're sitting behind of a firewall (yours or your ISP's)
which throws away (v4) ICMPs [1] -- so your pings possibly get out
there, but the responses never arrive back.

Cheers
[1] https://en.wikipedia.org/wiki/Internet_Control_Message_Protocol

-- t

[toc] | [prev] | [next] | [standalone]


#210027

FromRichard Hector <richard@walnut.gen.nz>
Date2019-06-18 10:40 +0200
Message-ID<yahON-2vG-7@gated-at.bofh.it>
In reply to#210023

[Multipart message — attachments visible in raw view] — view raw

On 18/06/19 4:07 PM, Bob Bernstein wrote:
> On Tue, 18 Jun 2019, Andy Smith wrote:
> 
>> What happens if you try to ping something? Like:

Sorry, sent my previous reply direct instead of to the list.

How about the "ip route show" that Andy suggested?

If you've been experimenting with openvpn, and have a tun interface,
there's a good chance it's changed your default route.

Richard

[toc] | [prev] | [next] | [standalone]


#210032

FromAndy Smith <andy@strugglers.net>
Date2019-06-18 13:20 +0200
Message-ID<yakjD-465-1@gated-at.bofh.it>
In reply to#210023
Hi Bob,

On Tue, Jun 18, 2019 at 12:07:16AM -0400, Bob Bernstein wrote:
> On Tue, 18 Jun 2019, Andy Smith wrote:
> >What happens if you try to ping something? Like:

[…]

> PING linode.com(2600:3c00::22 (2600:3c00::22)) 56 data bytes
> 64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=1 ttl=51 time=63.4 ms

So it seems you have IPv6 connectivity but not IPv4, although you do
have your v4 address configured on the interface. I'd be interested
in seeing your routing table (the "ip route show" command I
mentioned before).

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#210033

From<tomas@tuxteam.de>
Date2019-06-18 13:40 +0200
Message-ID<yakCZ-4cI-1@gated-at.bofh.it>
In reply to#210032

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jun 18, 2019 at 11:12:40AM +0000, Andy Smith wrote:
> Hi Bob,
> 
> On Tue, Jun 18, 2019 at 12:07:16AM -0400, Bob Bernstein wrote:
> > On Tue, 18 Jun 2019, Andy Smith wrote:
> > >What happens if you try to ping something? Like:
> 
> […]
> 
> > PING linode.com(2600:3c00::22 (2600:3c00::22)) 56 data bytes
> > 64 bytes from 2600:3c00::22 (2600:3c00::22): icmp_seq=1 ttl=51 time=63.4 ms
> 
> So it seems you have IPv6 connectivity but not IPv4, although you do
> have your v4 address configured on the interface.

... or it's just (v4) ICMP being filtered out somewhere. There are
firewall configurations which do that.

>                                                  I'd be interested
> in seeing your routing table (the "ip route show" command I
> mentioned before).

I think traceroute would be more interesting in this context:
it has options explicitly made for such firewall landscapes.

Read the man page or ask here if interested.

Cheers
-- t

[toc] | [prev] | [next] | [standalone]


#210050

FromBob Bernstein <bob@fanatick.org>
Date2019-06-18 17:40 +0200
Message-ID<yaong-6vG-11@gated-at.bofh.it>
In reply to#210032
On Tue, 18 Jun 2019, Andy Smith wrote:

> I'd be interested in seeing your routing table (the "ip route 
> show" command I mentioned before).

You must have your Jedi robes on. "These are the ip show 
commands I mentioned before."

But you didn't mention 'ip route show,' else I would have 
provided it, yes? What it showed was that yes, my default-route 
had been commandeered by the openvpn tun0. As long as there was 
an openvpn conf file in /etc/openvpn I was going to be stuck 
with that tun0. Gone now so I can't show you.

Thank you


-- 
These are not the droids you are looking for.

[toc] | [prev] | [next] | [standalone]


#210003

FromJoe <joe@jretrading.com>
Date2019-06-17 21:50 +0200
Message-ID<ya5NE-3AQ-1@gated-at.bofh.it>
In reply to#209997
On Mon, 17 Jun 2019 14:20:33 -0400
Bob Bernstein <poobah@ruptured-duck.com> wrote:

> For a change, I want to proceed with a tad of caution 
> rather than follow Don't RTFM - Wing That Sucker.
> 
> I have an old Jessie running:
> 
> Linux debian.localdomain 3.16.0-7-amd64 #1 SMP Debian 3.16.59-1
> (2018-10-03) x86_64 GNU/Linux
> 
> ...and it has been borne in on me that my kernel needs to 
> be retired. This old Jessie dates back to the Bad Old Days 
> of the systemd wars and has no systemd onboard. I am of a 
> mood though to take a Great Leap Forward and install 
> Stretch -- systemd 'n all.
> 
> My untutored instinct is to go through my apt sources.list 
> and replace every instance of 'jessie' with 'stretch,' and 
> leave the rest up to apt-get, but I thought YOU SHOULD ASK 
> ON THE LIST FIRST BOB.
> 
> Full disclosure: I have not kept up. Are there resources, 
> wikis, etc, dedicated to Upgrading Debian For Dummies?
> 
> All input will be graciously accepted.
> 
>
Something not mentioned on the Debian pages is that php7 is now
default, and various 'deprecated' features are now gone. If you still
use old php applications, you may find breakage.

Also, having tried a quick two-stage upgrade from wheezy, I found that
FreeRADIUS wouldn't run. I don't know where the changes were made, but
the new version didn't like my old configuration file. I'm not actively
using it at the moment, so I ignored it, and later installed it with
its own configuration file. It runs now, but I suppose I'll have to
spend a week configuring it sometime.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#210591

Fromandreimpopescu@gmail.com
Date2019-07-02 11:20 +0200
Message-ID<yfn7b-7bm-5@gated-at.bofh.it>
In reply to#209997

[Multipart message — attachments visible in raw view] — view raw

On Lu, 17 iun 19, 14:20:33, Bob Bernstein wrote:
> For a change, I want to proceed with a tad of caution 
> rather than follow Don't RTFM - Wing That Sucker.
> 
> I have an old Jessie running:
> 
> Linux debian.localdomain 3.16.0-7-amd64 #1 SMP Debian 3.16.59-1 (2018-10-03) x86_64 GNU/Linux
> 
> ...and it has been borne in on me that my kernel needs to 
> be retired. This old Jessie dates back to the Bad Old Days 
> of the systemd wars and has no systemd onboard. I am of a 
> mood though to take a Great Leap Forward and install 
> Stretch -- systemd 'n all.

Just for the archives, upgrading to stretch (or buster) does not 
necessarily involve switching to systemd.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web