post-apt-reinstall-issues sys-whonix not connecting to tor

56 views
Skip to first unread message

qube...@tutanota.com

unread,
Jan 24, 2019, 8:53:51 AM1/24/19
to Qubes Users
hi, I reinstalled successfully the whonix-ws-14, whonix-gw-14 and debian-9 templates as described here: https://www.qubes-os.org/news/2019/01/23/qsb-46/ <https://www.qubes-os.org/news/2019/01/23/qsb-46/>

With this kind of installation no sys-whonix is created by default. I created therefore a new AppVM named sys-whonix, based on template whonix-gw-14, NetVM set to sys-firewall. After running Connection Wizard it stops at 5% if connecting directly to Tor, or at 10% if connecting with Bridges. It stops in the bootstrap phase connecting to a relay directory. Whonix check say gave up waiting. In the Arm it keeps popping up duplicates hidden.
After few moments it tells me (when using bridges): [WARN] Proxy Client: unable to connect to IP-address:443 "general SOCKS server failure" .

Is there any setting in the original sys-whonix that is missing if the sys-whonix I just created manually?
What is the solution for this issue?
I live in non-censored area, clearnet internet connection is working smoothly.
Thank you!

Andrew David Wong

unread,
Jan 24, 2019, 10:03:26 PM1/24/19
to qube...@tutanota.com, Qubes Users, Marek Marczykowski-Górecki
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
The correct way to (re)create sys-whonix is:

$ sudo qubesctl state.sls qvm.anon-whonix

For details, see: https://www.whonix.org/wiki/Qubes/Install

We neglected to include this in the QSB.

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlxKfF0ACgkQ203TvDlQ
MDCZjQ/+Oa//xX6mwYSo4v7xUEXVkFyMA7UNTOW4mqYa3bf5pUfhFhAu3M2qViJ0
L/wuD/AA1EvlPDw3toVQL+7Zo/irKdwZ0ZkIUcNyggpxqfujqGfIMo9t3Xvsi8n1
axGsRUDuevYLbAaeNyunpSInIzp3pwIE34GyrZ3NpLFrHa8/IFpe7sQLmTj8cnBK
UIcq1MhIQQJQfuWvUyJ76MTvS8Dal72vAqaGTTVIQWDqLXwMPYlyW8/s5eyc7vPi
sYiKS9lh7juknBqpFAstz0zZy8nzEBeZju7yiqEqKrm0ecTNqTv1ZDTGiqMgFjzq
2fMPGg81OSIWfnuudIw4Lmbr5uoqzjDZ0a20kqJ8yeSmKYLFcGkzVlRmF0A1P0TZ
WV6eDH+FSGzrANNHjP2Uuqk3Ce2sFm/gswzXscmIZH/6AgVhS1xJoEbP6/gfsXQ1
dSRL32f64CAxdpckvC9v8f9bugDZsN9NGzpgpMZwtGZHML6gGL88fjGvalH6iNMr
MeB2m3oTSteVPB0kHhmhHaZ8Unt+LvVNoTygUbeaZ053NFS2uFvVFmUlZwW9eS42
0j2PnREhTnfU5vyv4PRbNyEiPJXtW3jh4IJS6LkCoN9utlKwHtJdKJVjsqFusD9F
Lx7SNjjI+l2I8rBwTtEFGeRLmrU3/Ih1OONPwTEM0tNCcYLOON8=
=RY4C
-----END PGP SIGNATURE-----

Andrew David Wong

unread,
Jan 24, 2019, 10:36:29 PM1/24/19
to Qubes Users, qube...@tutanota.com, Marek Marczykowski-Górecki
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 24/01/2019 9.03 PM, Andrew David Wong wrote:
> On 24/01/2019 7.53 AM, qube...@tutanota.com wrote:
>> hi, I reinstalled successfully the whonix-ws-14, whonix-gw-14 and debian-9 templates as described here: https://www.qubes-os.org/news/2019/01/23/qsb-46/ <https://www.qubes-os.org/news/2019/01/23/qsb-46/>
>
>> With this kind of installation no sys-whonix is created by default. I created therefore a new AppVM named sys-whonix, based on template whonix-gw-14, NetVM set to sys-firewall. After running Connection Wizard it stops at 5% if connecting directly to Tor, or at 10% if connecting with Bridges. It stops in the bootstrap phase connecting to a relay directory. Whonix check say gave up waiting. In the Arm it keeps popping up duplicates hidden.
>> After few moments it tells me (when using bridges): [WARN] Proxy Client: unable to connect to IP-address:443 "general SOCKS server failure" .
>
>> Is there any setting in the original sys-whonix that is missing if the sys-whonix I just created manually?
>> What is the solution for this issue?
>> I live in non-censored area, clearnet internet connection is working smoothly.
>> Thank you!
>
>
> The correct way to (re)create sys-whonix is:
>
> $ sudo qubesctl state.sls qvm.anon-whonix
>
> For details, see: https://www.whonix.org/wiki/Qubes/Install
>
> We neglected to include this in the QSB.
>

PR: https://github.com/QubesOS/qubes-secpack/pull/26

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlxKhCkACgkQ203TvDlQ
MDAH0g/9EeSTQHx5WqS99WEbtAay4G1oYoyA/ES0VZG0BRdzWCNvQRsYgsytT6pR
0jPUXHopUZ9I+CBxc4FBq+UjcjsqdYkUEmU9tahbCXAcFGfSatc66k/kY94Z5G3Y
VZJUlxuDqLqYC+LqFdAcgmBy9a47hdmnoLWo6FzBR4uynyuK8CBV10cF8n3HSS78
tpqeH4TYEFwqAp11QBmIdo+k7D8zjO0T1S0FyJl9yxQx62igwjC5LbredCSQ34mp
MogR4ci4RPDEn2iRyNSFDDJHvQ4nqR9DMe/LXDCJhy56WBL+ynpySCdGnrKx764s
pK5Z+yC25VWXeJzkhmu2Lo3M2DYdLmd/9Qrkn8gCmIaloKRui5Y20X70RYTwvvdw
k2CBShPJtqAEcmOY3fKfpwa42re26eFXNp+flPnWAYxxdUOTZE2p534poZwp4h7x
KMM5+rofC0r7YP2QKY5+iZ3us7uUTCDUataZUQXWJ4iq3b8ZwckFCt+LleP3VD74
686Hes0iYVTuP2UdnTQGGbDNIgSE6J7CSMdr95DK5iDZjdefG+jgnd+rWPS3b8FQ
SY5bwDYefS3Sv7tL8InldAMgkrkxmJv3naaHpVvlJZ0/d3TxPEuXYgWylDpeTAzG
ZRoPV2ArLHQameUdIhwTELNAvjMeWw9CDEdMaxCcjidrzWgbgqE=
=c2zv
-----END PGP SIGNATURE-----

qube...@tutanota.com

unread,
Jan 25, 2019, 10:04:06 AM1/25/19
to Andrew David Wong, Qubes Users, Marek Marczykowski-Górecki
Thank you. Will the existing anon-whonix be recreated together with sys-whonix as well? I have an anon-whonix AppVM already existing. Should I back it up or chenge its name to prevent data loss?


Jan 25, 2019, 4:36 AM by a...@qubes-os.org:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> On 24/01/2019 9.03 PM, Andrew David Wong wrote:
>
>> On 24/01/2019 7.53 AM, >> qube...@tutanota.com <mailto:qube...@tutanota.com>>> wrote:
>>
>>> hi, I reinstalled successfully the whonix-ws-14, whonix-gw-14 and debian-9 templates as described here: >>> https://www.qubes-os.org/news/2019/01/23/qsb-46 <https://www.qubes-os.org/news/2019/01/23/qsb-46/>>>> <>>> https://www.qubes-os.org/news/2019/01/23/qsb-46 <https://www.qubes-os.org/news/2019/01/23/qsb-46/>>>> >
>>>
>>> With this kind of installation no sys-whonix is created by default. I created therefore a new AppVM named sys-whonix, based on template whonix-gw-14, NetVM set to sys-firewall. After running Connection Wizard it stops at 5% if connecting directly to Tor, or at 10% if connecting with Bridges. It stops in the bootstrap phase connecting to a relay directory. Whonix check say gave up waiting. In the Arm it keeps popping up duplicates hidden.
>>> After few moments it tells me (when using bridges): [WARN] Proxy Client: unable to connect to IP-address:443 "general SOCKS server failure" .
>>>
>>> Is there any setting in the original sys-whonix that is missing if the sys-whonix I just created manually?
>>> What is the solution for this issue?
>>> I live in non-censored area, clearnet internet connection is working smoothly.
>>> Thank you!
>>>
>>
>>
>> The correct way to (re)create sys-whonix is:
>>
>> $ sudo qubesctl state.sls qvm.anon-whonix
>>
>> For details, see: >> https://www.whonix.org/wiki/Qubes/Install <https://www.whonix.org/wiki/Qubes/Install>
>>
>> We neglected to include this in the QSB.
>>
>
> PR: > https://github.com/QubesOS/qubes-secpack/pull/26 <https://github.com/QubesOS/qubes-secpack/pull/26>
>
> - --
> Andrew David Wong (Axon)
> Community Manager, Qubes OS
> https://www.qubes-os.org <https://www.qubes-os.org>

Marek Marczykowski-Górecki

unread,
Jan 25, 2019, 10:14:03 AM1/25/19
to qube...@tutanota.com, Andrew David Wong, Qubes Users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Fri, Jan 25, 2019 at 04:04:02PM +0100, qube...@tutanota.com wrote:
> Thank you. Will the existing anon-whonix be recreated together with sys-whonix as well? I have an anon-whonix AppVM already existing. Should I back it up or chenge its name to prevent data loss?

No, if anon-whonix already exists, it will not be recreated.
But note anon-whonix is based on whonix-ws-14 template, which is also
affected. You should update it to unaffected version using one of the
methods described in the QSB.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlxLJ7MACgkQ24/THMrX
1yyaCgf/c6fzqF6MahYzCVd0F+KxHiTrG9mtkCDti/HnFWh+uMkwHiROMDibnrZg
0Zqy4N00vqV4fiH5UhlvAvHPS8R+naVoJ5X/9lMxrjJSBNPmMNsMW03qFFBjbBVp
OPyfKPk+pfZOW6Cmo5FsU3/qYQ3z3g6b3t8S59CRGuCEFub7wBBdTEB+2E2PM8Cg
dLYVTaKU3gP6XLkIM1i/F3DWrRl7LE1/xQ1qatUQQMCEt7ydT54m3LSOgqfmA/e2
VK2q8TTKCYj+gDI7SvJ53T4ndb6CQ+9u0deQ0Akmiq8ZgdsmO/avc5uCF6VOu0Mq
e3R8bktGFlm8wu/pCkSq474xKEMMaA==
=ttQ8
-----END PGP SIGNATURE-----

qube...@tutanota.com

unread,
Jan 25, 2019, 10:20:53 AM1/25/19
to Marek Marczykowski-Górecki, Andrew David Wong, Qubes Users
Jan 25, 2019, 4:13 PM by marm...@invisiblethingslab.com:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> On Fri, Jan 25, 2019 at 04:04:02PM +0100, > qube...@tutanota.com <mailto:qube...@tutanota.com>> wrote:
>
>> Thank you. Will the existing anon-whonix be recreated together with sys-whonix as well? I have an anon-whonix AppVM already existing. Should I back it up or chenge its name to prevent data loss?
>>
>
> No, if anon-whonix already exists, it will not be recreated.
> But note anon-whonix is based on whonix-ws-14 template, which is also
> affected. You should update it to unaffected version using one of the
> methods described in the QSB.
>
> - --
> Best Regards,
> Marek Marczykowski-Górecki
> Invisible Things Lab
> A: Because it messes up the order in which people normally read text.
> Q: Why is top-posting such a bad thing?
> -----BEGIN PGP SIGNATURE-----
>
> iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlxLJ7MACgkQ24/THMrX
> 1yyaCgf/c6fzqF6MahYzCVd0F+KxHiTrG9mtkCDti/HnFWh+uMkwHiROMDibnrZg
> 0Zqy4N00vqV4fiH5UhlvAvHPS8R+naVoJ5X/9lMxrjJSBNPmMNsMW03qFFBjbBVp
> OPyfKPk+pfZOW6Cmo5FsU3/qYQ3z3g6b3t8S59CRGuCEFub7wBBdTEB+2E2PM8Cg
> dLYVTaKU3gP6XLkIM1i/F3DWrRl7LE1/xQ1qatUQQMCEt7ydT54m3LSOgqfmA/e2
> VK2q8TTKCYj+gDI7SvJ53T4ndb6CQ+9u0deQ0Akmiq8ZgdsmO/avc5uCF6VOu0Mq
> e3R8bktGFlm8wu/pCkSq474xKEMMaA==
> =ttQ8
> -----END PGP SIGNATURE-----
>
Hi, I updated the whonix-gw-14 and whonix-ws-14 as well. I am planning to use the pre-update AppVMs as a backup and transfer necessary data to the newly created post-update AppVMs. Than delete them.
In this case, I can just rename the anon-whonix AppVM and the new anon-whonix will be created, right?


> --
> You received this message because you are subscribed to the Google Groups "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to > qubes-users...@googlegroups.com <mailto:qubes-users...@googlegroups.com>> .
> To post to this group, send email to > qubes...@googlegroups.com <mailto:qubes...@googlegroups.com>> .
> To view this discussion on the web visit > https://groups.google.com/d/msgid/qubes-users/20190125151356.GI1429@mail-itl <https://groups.google.com/d/msgid/qubes-users/20190125151356.GI1429%40mail-itl>> .
> For more options, visit > https://groups.google.com/d/optout <https://groups.google.com/d/optout>> .
>

Marek Marczykowski-Górecki

unread,
Jan 25, 2019, 10:26:38 AM1/25/19
to qube...@tutanota.com, Andrew David Wong, Qubes Users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Fri, Jan 25, 2019 at 04:20:50PM +0100, qube...@tutanota.com wrote:
> Jan 25, 2019, 4:13 PM by marm...@invisiblethingslab.com:
>
> > On Fri, Jan 25, 2019 at 04:04:02PM +0100, > qube...@tutanota.com <mailto:qube...@tutanota.com>> wrote:
> >
> >> Thank you. Will the existing anon-whonix be recreated together with sys-whonix as well? I have an anon-whonix AppVM already existing. Should I back it up or chenge its name to prevent data loss?
> >>
> >
> > No, if anon-whonix already exists, it will not be recreated.
> > But note anon-whonix is based on whonix-ws-14 template, which is also
> > affected. You should update it to unaffected version using one of the
> > methods described in the QSB.
>
> Hi, I updated the whonix-gw-14 and whonix-ws-14 as well. I am planning to use the pre-update AppVMs as a backup and transfer necessary data to the newly created post-update AppVMs. Than delete them.
> In this case, I can just rename the anon-whonix AppVM and the new anon-whonix will be created, right?

Yes, exactly.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlxLKqcACgkQ24/THMrX
1yxYaAgAjuiGQxpY2tyiH62706bMQ7FejCNPdoBXwL5RzM7j6/5hYlA7cUa/L5fn
Z4q/7F2k9olSQFDvobZ/PJw+cvaV8lFfNWUnSiIkgCVQ5VxZxCHmWR/QWoBf4oRE
7CGWOgT89u1jTUO595IQ3LSq7ixT5DhqhwRYc0JuWYHL0vYIMJJ3+e5X2/Y0bnNr
6DbR9EuY9F6PsLTwXLG1/Bf8XdA7MIaKVhkVQvAcvUFHvdjJIXzBT4HigjclXFzI
AMgAvtEYJXiygylwlrC3fMprDYSSMmv2yDyaBMN9oQ1Q3Aw+hnb+X8unLebV5F8X
hzLmEdXJ7KJJCIipvFzriOEckXqWxQ==
=GgX4
-----END PGP SIGNATURE-----

qube...@tutanota.com

unread,
Jan 25, 2019, 10:59:25 AM1/25/19
to Marek Marczykowski-Górecki, Andrew David Wong, Qubes Users
Jan 25, 2019, 4:26 PM by marm...@invisiblethingslab.com:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> On Fri, Jan 25, 2019 at 04:20:50PM +0100, > qube...@tutanota.com <mailto:qube...@tutanota.com>> wrote:
>
>> Jan 25, 2019, 4:13 PM by >> marm...@invisiblethingslab.com <mailto:marm...@invisiblethingslab.com>>> :
>>
>> > On Fri, Jan 25, 2019 at 04:04:02PM +0100, > >> qube...@tutanota.com <mailto:qube...@tutanota.com>>> <mailto:>> qube...@tutanota.com <mailto:qube...@tutanota.com>>> >> wrote:
>> >
>> >> Thank you. Will the existing anon-whonix be recreated together with sys-whonix as well? I have an anon-whonix AppVM already existing. Should I back it up or chenge its name to prevent data loss?
>> >>
>> >
>> > No, if anon-whonix already exists, it will not be recreated.
>> > But note anon-whonix is based on whonix-ws-14 template, which is also
>> > affected. You should update it to unaffected version using one of the
>> > methods described in the QSB.
>>
>> Hi, I updated the whonix-gw-14 and whonix-ws-14 as well. I am planning to use the pre-update AppVMs as a backup and transfer necessary data to the newly created post-update AppVMs. Than delete them.
>> In this case, I can just rename the anon-whonix AppVM and the new anon-whonix will be created, right?
>>
>
> Yes, exactly.
>
> - --
> Best Regards,
> Marek Marczykowski-Górecki
> Invisible Things Lab
> A: Because it messes up the order in which people normally read text.
> Q: Why is top-posting such a bad thing?
> -----BEGIN PGP SIGNATURE-----
>
> iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAlxLKqcACgkQ24/THMrX
> 1yxYaAgAjuiGQxpY2tyiH62706bMQ7FejCNPdoBXwL5RzM7j6/5hYlA7cUa/L5fn
> Z4q/7F2k9olSQFDvobZ/PJw+cvaV8lFfNWUnSiIkgCVQ5VxZxCHmWR/QWoBf4oRE
> 7CGWOgT89u1jTUO595IQ3LSq7ixT5DhqhwRYc0JuWYHL0vYIMJJ3+e5X2/Y0bnNr
> 6DbR9EuY9F6PsLTwXLG1/Bf8XdA7MIaKVhkVQvAcvUFHvdjJIXzBT4HigjclXFzI
> AMgAvtEYJXiygylwlrC3fMprDYSSMmv2yDyaBMN9oQ1Q3Aw+hnb+X8unLebV5F8X
> hzLmEdXJ7KJJCIipvFzriOEckXqWxQ==
> =GgX4
> -----END PGP SIGNATURE-----
>

Thank you, all working well.


> --
> You received this message because you are subscribed to the Google Groups "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to > qubes-users...@googlegroups.com <mailto:qubes-users...@googlegroups.com>> .
> To post to this group, send email to > qubes...@googlegroups.com <mailto:qubes...@googlegroups.com>> .
> To view this discussion on the web visit > https://groups.google.com/d/msgid/qubes-users/20190125152631.GJ1429@mail-itl <https://groups.google.com/d/msgid/qubes-users/20190125152631.GJ1429%40mail-itl>> .
Reply all
Reply to author
Forward
0 new messages