· 10 years ago · May 23, 2016, 12:21 AM
1<?xml version="1.0"?>
2<book xmlns="http://docbook.org/ns/docbook" xmlns:xl="http://www.w3.org/1999/xlink" version="5.0">
3 <title>Documentation for Thrace.Lan</title>
4 <info>
5 <pubdate></pubdate>
6 <author>
7 <personname><firstname>Erin</firstname><surname>Gibson</surname></personname>
8 <affiliation><address><email>agibson684.com</email></address></affiliation>
9 </author>
10 <abstract>
11 <para>This documentation is in regards to the servers, applications, devices, and networks of Thrace.lan domain.</para>
12 </abstract>
13 <revhistory>
14 <revision>
15 <revnumber>1.x</revnumber>
16 <date></date>
17 <authorinitials>ecg</authorinitials>
18 <revremark>Updated information</revremark>
19 </revision>
20 </revhistory>
21 </info>
22 <chapter><title>Pre-Installation</title>
23 <para>To begin the process of installation of a new workstation by backing up any data you may have on the old workstation if there is such a machine.
24 If you are reinstalling, recovering a system from hardware/software failure etc.
25 If you are creating a completely new system then ignore this portion and continue on to installation it will start you on the road to creating one from scratch.
26 make sure that the hostname and ipaddress are documented and the DNS name is included in the DNS server and host file. All new services must be documented in the Git Repository on services.thrace.lan inside in the associated manual. Create a request ticket at <link xl:href="https://www.thrace.lan/">Thrace.lan</link> with a cfg2html document created for each host, monitoring files for Nagios monitoring service in puppet manifest, puppet manifests for packages, file and configurations, and new documented services in docbook xml format with the proper style file. Please see the docbook section for further details on docbook. Currently we are utilizing Debian Linux stable version for Thrace.Lan, but future projects may use other distributions.</para>
27
28
29 <para>Next backup all the data in <filename class="directory">/etc,/home,/srv and /root</filename>. Backing up virtual OS software can be done by looking at the partitions associated with KVM. Then using the command DD or another tool to backup the partition to another partition, disk, or as a large file. You may backup to a DVD, Hard Drive or Server. Most of these backups are stored in <filename class="directory">/media/Backup</filename> on xena.thrace.lan.</para>
30
31 <para>Run all commands in the crontab for ROOT, ERIN, and any others. While on the old system determine which physical partition <filename> /dev/sda1, /dev/vg/my_lv </filename> belong to which logical directory <filename class="directory">/home, /root, /srv </filename> and write it down
32 </para>
33
34 <para>Once you run the crontab scripts then you will have created the backups in the <filename class="directory">/media/Backup/</filename>dirctory on the xena.thrace.lan physical server. Also the cfg2html file should of been already created in the <filename class="directory"> /home/THRACE/erin/Documents/cfg2html-archive</filename> directory. This will contain all the information about your system that you should need to recreate it.</para>
35
36 <para>Your best bet is to have the cfg2html document and this documentation open on another system while you install the operating system, and during the configuration if you are not using preseeds and puppet to re-create the system. </para>
37
38 <para>Selection of services, tools and other applications to run on the servers should be made prior to building the machine. I will make specific documents for Noteable ones. They are Puppet, Nagios, Apache, Mysql, Git, CIFS/Samba,Winbind, AD, Openssh-Server. These are typically installed VIA Puppet after the initial image of Debian is created or installed. Use the default Debian ISO or image in <filename>/media/files_apps/</filename></para>
39
40 <para>The keys for SSH are in the <filename>~/.ssh</filename> directory and that you can connect to other systems. The pregenerated keys can be found <filename class="directory">/media/private/erin/keys/</filename>. Use ssh-keygen hostname to create your keys, and store the private key in the keys directory under <filename class="directory">/media/private/erin/keys/</filename>.</para>
41
42 <para>The hostname and ipaddress are documented and the DNS name is included in the DNS server and host file. All new services must be documented in the Git Repository on services.thrace.lan inside in the associated manual. Create a request ticket at <link xl:href="https://www.thrace.lan/">Thrace.lan</link> with a cfg2html document created for each host, monitoring files for Nagios monitoring service in puppet manifest, puppet manifests for packages, file and configurations, and new documented services in docbook xml format with the proper style file. Please see the docbook section for further details on docbook. Currently we are utilizing Debian Linux stable version for Thrace.Lan, but future projects may use other distributions.</para>
43 </chapter>
44
45 <chapter><title>Installation of Operating System</title>
46 <itemizedlist mark="opencircle">
47 <listitem><para>Insert the Distribution disc into your CD drive. This can be what ever flavor of Linux you like. The current installations are Debian Stable, but we may be moving to Proxmox for the host machines and then using pre-built generic Debian stable images for guests. Start or restart your computer. The Language screen appears. </para></listitem>
48 <listitem><para>
49 Select Install Debian and press Enter. The Welcome window appears.
50 </para></listitem>
51 <listitem><para>
52 When prompted to select the installation drives use manual.
53 </para></listitem>
54 <listitem><para>
55 Format the root and swap partition while leaving the <filename class="directory">/home</filename> directory intact.
56 </para></listitem>
57 <listitem><para>
58 create what ever raid devices that need to created and also any Logical volumes with LVM2. Also use ZFS for creation of data storage volumes.
59 </para></listitem>
60 <listitem><para>
61 When prompted create the Themis user.
62 </para></listitem>
63 <listitem><para>
64 In the 'Choose a password to keep your account safe' field, enter a password in both text boxes.
65 </para></listitem>
66 <listitem><para>
67 In the What is the name of your computer? Field, enter the domain thrace.lan and the hostname.
68 </para></listitem>
69 <listitem><para>
70 The installation wizard begins. When the installation wizard finishes, the installation complete window appears.
71 </para></listitem>
72 <listitem><para>
73 Use the defaults for setup of Grub2.
74 </para></listitem>
75 <listitem><para>
76 Click Restart now to restart your computer. Debian is now installed.
77 </para></listitem>
78 <listitem><para>
79 Restart the system and login as themis and type the temporary password you specified in the installation.
80 </para></listitem>
81 </itemizedlist>
82 <para> Modify the <emphasis>/etc/network/interfaces</emphasis> file to what is inside the cfg2html files in the cfg2html archive directory in <filename class="directory">/home/THRACE/$USER/DOCUMENTS/cfg2html-archive</filename></para>
83 <programlisting>
84 auto lo
85 iface lo inet loopback
86 # The primary network interface
87 #allow-hotplug eth0
88 auto eth0
89 iface eth0 inet static
90 address 192.168.1.204
91 netmask 255.255.255.0
92 network 192.168.1.1
93 broadcast 192.168.1.255
94 gateway 192.168.1.1
95 #post-up /sbin/route add default gw 192.168.1.1 eth0
96 </programlisting>
97 <para>create the following directories.</para>
98 <screen>
99 mkdir /media/downloads /media/files_movies /media/movies \
100 /media/files_music /media/misc /media/files_apps /media/apps \
101 /media/files_misc /media/private \
102 /media/public /media/misc_vids /media/Backup </screen>
103 <para>Modify the /etc/fstab with the following:</para>
104 <programlisting>
105 //192.168.1.202/public/ /media/public cifs defaults,user=erin 0 0
106 //192.168.1.202/private/ /media/private cifs defaults,user=erin 0 0
107 //192.168.1.202/Backup/ /media/Backup cifs defaults,user=erin 0 0
108 </programlisting>
109 </chapter>
110
111 <chapter><title>Laptop details ASUS X205TA</title>
112 <para>CategoryLaptopComputer CategoryDebianOn </para>
113 <para>
114 <para>
115 Before installing Debian, Secure Boot needs to be disabled. Starting with Jessie d-i RC2, the installer includes all needed modules and core changes to install and boot on this machine. Make sure you use this version or later to install, or you'll have to fight with lots of issues and it's not likely to be fun!
116 The X205TA is a mixed mode EFI system (i.e. a 64-bit CPU combined with a 32-bit EFI) without any legacy BIOS mode. By default, the Jessie i386 installer images should boot on this machine via UEFI and let you install a complete 32-bit (i386) system. If you use the multi-arch amd64/i386 netinst or DVD image, you will also be able to install in 64-bit mode. You might expect slightly better performance that way, but the limited memory on the machine (2 GiB) will become more of an issue.
117 </para>
118 <title>System Freeze Issue</title>
119 <para>There is a well documented system freeze issue -- see <link xl:href="https://bugs.freedesktop.org/show_bug.cgi?id=88012">Freedesktop Bug #88012</link> and <link xl:href=" https://bugzilla.kernel.org/show_bug.cgi?id=109051">Kernel Bug #109051</link>. To correct this, we can add ''intel_idle.max_cstate=1'' to the kernel boot parameters. The easiest way is to edit the file ''/etc/default/grub'' and configure this line :
120 <emphasis>GRUB_CMDLINE_LINUX_DEFAULT="quiet intel_idle.max_cstate=1"</emphasis>.
121 <programlisting>
122 Then you simply need to reconfigure '''grub''' :
123 sudo update-grub
124 </programlisting>
125 </para>
126 <title> Configuration</title>
127 <title>Audio</title>
128 <para>
129 First say what's the Sound adapter model (lspci may help)Then explain how to get it working
130 The built-in card is a '''Realtek RT5648''' (''unverified''). At this moment there isn't any driver for this card (as of Linux Kernel 4.1.3)
131 <link xl:href="https://bugzilla.kernel.org/show_bug.cgi?id=95681">Kernel Bug</link> <link xl:href="http://comments.gmane.org/gmane.linux.alsa.devel/138822">Alsa</link> It may be possible that some models of the X205TA have a different card, a '''Realtek RT5640''' (''unverified'') : <link xl:href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773835">Bugreport</link>
132 </para>
133 <title>Power Management</title>
134 <para>
135 Battery status information is available since kernel '''3.19'''. The X205TA uses some ACPI 5.0 features that are not supported in kernels '''3.19'''.
136 If you add ''relative_sleep_states=1'' to the kernel command line, suspension (a.k.a: Suspend to RAM) will work. After resume, two things won't. First of all, the touchpad won't respond. To fix that, run these commands...
137 </para>
138 <programlisting>
139 sudo rmmod elan_i2c
140 sudo modprobe elan_i2c
141 </programlisting>
142 <para> Secondly, wireless does not work after resume. To permanently fix this, blacklist the ''btsdio'' module with
143 <programlisting>
144 printf "# Blacklist the btsdio module as it breaks suspend\nblacklist btsdio\n" | sudo tee /etc/modprobe.d/btsdio-blacklist.conf
145 </programlisting>
146 Bluetooth does not works for now, so it's okay to blacklist ''btsdio''.
147 Hibernation (usually) triggers a kernel oops+panic combo when thawing the system. After that, if you reboot the machine the hard way, the kernel boots into a clean session.
148 </para>
149 <title>WiFi</title>
150 <para>
151 With kernel 4.0 wifi is working. However, firmware and nvram file need to be installed.
152 Firmware can be found on Google's Android Git:
153 <programlisting>
154 wget <link xl:href="https://android.googlesource.com/platform/hardware/broadcom/wlan/+archive/master/bcmdhd/firmware/bcm43341.tar.gz">Firmware</link>
155 </programlisting>
156 Then we simply need to copy in in the right place the directory <programlisting>/lib/firmware/brcm/</programlisting> might not exist so it may need to be created with the right name.
157 <programlisting>
158 tar xf bcm43341.tar.gz
159 mkdir -p /lib/firmware/brcm/
160 cp fw_bcm43341.bin /lib/firmware/brcm/brcmfmac43340-sdio.bin
161 </programlisting>
162 The nvram file can be found under <programlisting>/sys/firmware/efi/efivars/</programlisting> If the directory is empty, it may need to be (temporarily) mounted first then the nvram-File needs to be copied and renamed:
163 <programlisting>
164 mount -t efivarfs efivarfs /sys/firmware/efi/efivars
165 cp /sys/firmware/efi/efivars/nvram-74b00bd9-805a-4d61-b51f-43268123d113 /lib/firmware/brcm/brcmfmac43340-sdio.txt
166 </programlisting>
167 Note, that ''brcmfmac43340-sdio.txt'' then contains a wrong MAC address. However, this is not a problem and does not need to be changed, as the file is only a template.
168 </para>
169 <title>Conflict between sdhci-acpi and brcmfmac</title>
170 <para>
171 Due to some conflict between ''sdhci-acpi'' and ''brcmfmac'' <link xl:href="https://bugzilla.kernel.org/show_bug.cgi?id=88061">Kernel Bug</link>, a parameter has to be changed for the ''sdhci-acpi'' driver. There are several ways to do this, but a quick fix is to add this line in /etc/sysfs.conf (make sure you have the package ''sysfsutils'' installed), this way the option is passed before the ''brcmfmac'' driver is loaded :Disable SDHCI-ACPI for Wireless, otherwise WLAN doesn't work
172 <programlisting>bus/platform/drivers/sdhci-acpi/INT33BB:00/power/control = on</programlisting>
173 </para>
174 <title>microSD Card Reader</title>
175 As of 4.5.0-2 this isn't necessary anymore!
176 <title>Features</title>
177 <para>
178 Both the Linux kernel and GRUB have gone a long way to get support for X205TA. Originally, GRUB wasn't even able to boot. As of now, the only remaining features are sound (Realtek and Asus appear not to care about this), (all the) hotkeys, proper suspend/hibernation (apparently, the crash occurs when ''resuming'' from suspension), and Bluetooth. You can track the most recent news and experimental support in <link xl:href="http://ubuntuforums.org/showthread.php?t=2254322">Ubuntuforums</link>.
179 </para>
180 </para>
181 </chapter>
182 <chapter><title>Tools, Applications, Custom Commands/Scripts and Services </title>
183 <para>the following pages will contain the details of the the application, services, custom commands/scripts and tools used on the Thrace.Lan network. These lines will probablly be arbitary and can be debated. Each section will begin with a summary of the form and fuction of said application and then contain the installation, configuration and administrative tasks for each.</para>
184
185 <section><title>Network</title>
186 <para>The<link xl:href="https://www.thrace.lan/">Thrace.lan</link> network is a collection of Microsoft, Linux, Routers, Switches, and Raspberry Pi. the future configuration will be a subnetted network based on function of a set of servers. The desktop and user devices will be in one group, the servers and testing equipment in another. The wireless network will also subnetted out as well. The Guest wifi networks will be based on projectMeshnet and Hyperboria.</para>
187
188 <section><title>Alix-Routers</title>
189 <section><title>Firewalls</title><para/>
190
191 </section>
192 <section><title>MeshNet</title>
193 <para/>
194 </section>
195
196 <section><title>Hyperboria</title>
197 <para/>
198 </section>
199
200 </section>
201 </section>
202
203 <section><title>Virtual Machines</title>
204 <section><title>LXC</title>
205 Requirements
206aptitude install bridge-utils
207rsync -avz erin@calisto::files/ .
208proper bridge for network for host
209auto br0
210iface br0 inet static
211 bridge_ports eth0 eth1 eth2
212 bridge_fd 0
213 address 192.168.1.220
214 netmask 255.255.255.0
215 network 192.168.1.0
216 broadcast 192.168.1.255
217 gateway 192.168.1.1
218 # dns-* options are implemented by the resolvconf package, if installed
219 dns-nameservers 192.168.1.216
220 dns-search thrace.lan
221
222Hard dependencies:
223
224 One of glibc, musl libc, uclib or bionic as your C library
225 Linux kernel >= 2.6.32
226
227Extra dependencies for lxc-attach:
228
229 Linux kernel >= 3.8
230
231Extra dependencies for unprivileged containers:
232
233 cgmanager or another CGroup manager configuring your system for unprivileged CGroups operation
234 A recent version of shadow including newuidmap and newgidmap
235 Linux kernel >= 3.12
236
237Recommended libraries:
238
239 libcap (to allow for capability drops)
240 libapparmor (to set a different apparmor profile for the container)
241 libselinux (to set a different selinux context for the container)
242 libseccomp (to set a seccomp policy for the container)
243 libgnutls (for various checksumming)
244 liblua (for the LUA binding)
245 python3-dev (for the python3 binding)
246
247Installation
248
249In most cases, you'll find recent versions of LXC available for your Linux distribution.
250Either directly in the distribution's package repository or through some backport channel.
251
252For your first LXC experience, we recommend you use a recent supported release,
253such as a recent bugfix release of LXC 1.0.
254
255If using Ubuntu, we recommend you use Ubuntu 14.04 LTS as your container host.
256LXC bugfix releases are available directly in the distribution package repository
257shortly after release and those offer a clean (unpatched) upstream experience.
258
259Ubuntu is also one of the few (if not only) Linux distributions to come by default
260with everything that's needed for safe, unprivileged LXC containers.
261
262On such an Ubuntu system, installing LXC is as simple as:
263
264sudo apt-get install lxc
265
266Your system will then have all the LXC commands available, all its templates
267as well as the python3 binding should you want to script LXC.
268Creating unprivileged containers as a user
269
270Unprivileged containers are the safest containers.
271Those use a map of uid and gid to allocate a range of uids and gids to a container.
272That means that uid 0 (root) in the container is actually something like uid 100000
273outside the container. So should something go very wrong and an attacker manages
274to escape the container, they'll find themselves with about as many rights as a nobody user.
275
276Unfortunately this also means that the following common operations aren't allowed:
277
278 mounting most of filesystems
279 creating device nodes
280 any operation against a uid/gid outside of the mapped set
281
282Because of that, most distribution templates simply won't work with those.
283Instead you should use the "download" template which will provide you with pre-built images
284of the distributions that are known to work in such an environment.
285
286Now, everything below assumes a recent Ubuntu system or another Linux distribution which offers
287a similar experience (recent kernel, recent version of shadow, cgmanager and default uid/gid allocation).
288
289First of all, you need to make sure your user has a uid and gid map defined in /etc/subuid and /etc/subgid.
290On Ubuntu systems, a default allocation of 65536 uids and gids is given to every new user on the system,
291so you should already have one. If not, you'll have to use usermod to give yourself one.
292
293Next up is /etc/lxc/lxc-usernet which is used to set network devices quota for unprivileged users.
294By default, your user isn't allowed to create any network device on the host, to change that, add:
295
296your-username veth lxcbr0 10
297
298This means that "your-username" is allowed to create up to 10 veth devices connected to the lxcbr0 bridge.
299
300With that done, the last step is to create an LXC configuration file.
301
302 Create the ~/.config/lxc directory if it doesn't exist.
303 Copy /etc/lxc/default.conf to ~/.config/lxc/default.conf
304 Append the following two lines to it:
305 lxc.id_map = u 0 100000 65536
306 lxc.id_map = g 0 100000 65536
307
308Those values should match those found in /etc/subuid and /etc/subgid, the values above are those expected
309for the first user on a standard Ubuntu system.
310
311Just before you create your first container, you probably should logout and login again,
312or even reboot your machine to make sure that your user is placed in the right cgroups.
313(This is only required if cgmanager wasn't installed on your machine prior to you installing LXC.)
314
315And now, create your first container with:
316
317lxc-create -t download -n my-container
318use this link is you got troubles with mac address in guest, use an event number if you get weird startup errors,
319http://www.miniwebtool.com/mac-address-generator/
320The download template will show you a list of distributions, versions and architectures to choose from.
321A good example would be "ubuntu", "trusty" (14.04 LTS) and "i386".
322
323A few seconds later your container will be created and you can start it with:
324
325lxc-start -n my-container -d
326
327You can then confirm its status with either of:
328
329lxc-info -n my-container
330lxc-ls -f
331
332And get a shell inside it with:
333
334lxc-attach -n my-container
335
336Stopping it can be done with:
337
338lxc-stop -n my-container
339
340And finally removing it with:
341
342lxc-destroy -n my-container
343
344Creating unprivileged containers as root
345
346To run a system-wide unprivileged container (that is, an unprivileged container started by root)
347you'll need to follow only a subset of the steps above.
348
349Specifically, you need to manually allocate a uid and gid range to root in /etc/subuid and /etc/subgid.
350And then set that range in /etc/lxc/default.conf using lxc.id_map entries similar to those above.
351
352And that's it. Root doesn't need network devices quota and uses the
353global configuration file so the other steps don't apply.
354
355Any container you create as root from that point on will be running unprivileged.
356Creating privileged containers
357
358Privileged containers are containers created by root and running as root.
359
360Depending on the Linux distribution, they may be protected by some capability dropping, apparmor profiles,
361selinux context or seccomp policies but ultimately, the processes still run as root and so you should never
362give access to root inside a privileged container to an untrusted party.
363
364If you still have to create privileged containers, it's quite simple. Simply don't do any of the configuration
365described above and LXC will create privileged containers.
366
367So:
368
369sudo lxc-create -t download -n privileged-container
370
371Will create a new "privileged-container" privileged container on your system using an image from the download template.
372 #language en
373 ~-[[DebianWiki/EditorGuide#translation|Translation(s)]]: English - [[fr/LXC/SimpleBridge|Français]]-~
374 ----
375 This page includes examples of a
376 bridged or routed network provided by the host.
377
378 Alternatives to this network setup for containers can be found on the [[LXC]] main page.
379
380 == Host device as bridge ==
381 Features:
382 * persisted in host's {{{/etc/network/interfaces}}}
383 * the container's {{{veth}}} virtual ethernet interface can share the network link on the physical interface of the host (eth0). So the container resides on the same ethernet segment and talks to the same dhcp server as the host does.
384
385 Requires {{{bridge-utils}}} package.
386
387 Edit the host's {{{/etc/network/interfaces}}} in this form:
388 {{{
389 # Comment out the following:
390 # The primary network interface
391 #allow-hotplug eth0
392 #iface eth0 inet dhcp
393
394 auto br0
395 iface br0 inet dhcp
396 bridge_ports eth0
397 bridge_fd 0
398 bridge_maxwait 0
399 <![CDATA[
400 # uncomment the below and comment the above for static ip setup on the host
401 #auto br0
402 #iface br0 inet static
403 # bridge_ports eth0
404 # bridge_fd 0
405 # address <host IP here, e.g. 192.168.1.20>
406 # netmask 255.255.255.0
407 # network <network IP here, e.g. 192.168.1.0>
408 # broadcast <broadcast IP here, e.g. 192.168.1.255>
409 # gateway <gateway IP address here, e.g. 192.168.1.1>
410 # # dns-* options are implemented by the resolvconf package, if installed
411 # dns-nameservers <name server IP address here, e.g. 192.168.1.1>
412 # dns-search your.search.domain.here
413 ]]>
414 Restart networking:
415 {{{
416 <programlisting>
417 /etc/init.d/networking restart
418 </programlisting>
419
420 }}}
421
422 * The network section in the container's config (stored on the host in {{{/var/lib/lxc/containername/config}}}) may look like this
423 {{{
424 ## Network
425 lxc.utsname = containershostname
426 lxc.network.type = veth
427 lxc.network.flags = up
428
429 # that's the interface defined above in host's interfaces file
430 lxc.network.link = br0
431
432 # name of network device inside the container,
433 # defaults to eth0, you could choose a name freely
434 # lxc.network.name = lxcnet0
435
436 lxc.network.hwaddr = 00:FF:AA:00:00:01
437
438 # the ip may be set to 0.0.0.0/24 or skip this line
439 # if you like to use a dhcp client inside the container
440 lxc.network.ipv4 = 192.168.1.110/24
441
442 # define a gateway to have access to the internet
443 lxc.network.ipv4.gateway = 192.168.1.1
444
445 }}}
446
447 * Completing the example above, the container's {{{/etc/network/interfaces}}} may be edited to look like this
448 <![CDATA[
449 auto eth0
450 iface eth0 inet dhcp
451 #iface eth0 inet static
452 # address <container IP here, e.g. 192.168.1.110>
453 # all other settings like those for the host
454
455 ]]>
456 == Additonal bridge device instead of changing a host device to br0 ==
457 Features:
458 * setup manually with brctl
459 * the container's {{{veth}}} virtual ethernet interface accesses the network via the bridge device created on the host. By default, the container is not visable from outside the host.
460
461 {{{
462 # script to setup a natted network for lxc guests
463 CMD_BRCTL=/usr/sbin/brctl
464 CMD_IFCONFIG=/sbin/ifconfig
465 CMD_IPTABLES=/sbin/iptables
466 CMD_ROUTE=/sbin/route
467 NETWORK_BRIDGE_DEVICE_NAT=lxc-bridge-nat
468 HOST_NETDEVICE=wlan0
469 PRIVATE_GW_NAT=192.168.100.1
470 PRIVATE_NETMASK=255.255.255.0
471
472 ${CMD_BRCTL} addbr ${NETWORK_BRIDGE_DEVICE_NAT}
473 ${CMD_BRCTL} setfd ${NETWORK_BRIDGE_DEVICE_NAT} 0
474 ${CMD_IFCONFIG} ${NETWORK_BRIDGE_DEVICE_NAT} ${PRIVATE_GW_NAT} netmask ${PRIVATE_NETMASK} promisc up
475 ${CMD_IPTABLES} -t nat -A POSTROUTING -o ${HOST_NETDEVICE} -j MASQUERADE
476 echo 1 > /proc/sys/net/ipv4/ip_forward
477
478 }}}
479
480 == Alternative: ==
481 Features:
482 * persisted in sysctl.conf {{{/etc/sysctl.conf}}}
483 * persisted in interfaces {{{/etc/network/interfaces}}}
484
485 Uncomment the following in {{{/etc/sysctl.conf}}}:
486 {{{
487 # Uncomment the next line to enable packet forwarding for IPv4
488 net.ipv4.ip_forward=1
489 }}}
490
491 Insert the following in {{{/etc/network/interfaces}}}:
492
493 {{{
494 auto lxc-bridge-nat
495 iface lxc-bridge-nat inet static
496 bridge_ports none
497 bridge_fd 0
498 bridge_maxwait 0
499 address 192.168.100.1
500 netmask 255.255.255.0
501 up iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE
502 }}}
503
504 * Give this command to enable forwarding
505 {{{
506 echo 1 > /proc/sys/net/ipv4/ip_forward
507 }}}
508
509 * The containers {{{/etc/network/interfaces}}} is equal to the one proposed in "Host device as bridge"; if you don't put a dhcp server on the {{{lxc-bridge-nat}}}, the container should now use the static ip configuration
510 * The containers config file now uses {{{lxc-bridge-nat}}} as link, another ip and gateway
511 {{{
512 lxc.network.link = lxc-bridge-nat
513 lxc.network.ipv4 = 192.168.100.10/24
514 lxc.network.ipv4.gateway = 192.168.100.1
515 }}}
516 * The host can connect easily from his original network 192.168.1.0 to the natted one 192.168.100.0
517 * if you want to access a containers port (e.g. putting an apache inside a container) from outside the host, you have to forward that port from the host to the containers IP
518
519
520 == References ==
521 * http://www.vislab.uq.edu.au/howto/lxc/lxcnetwork.html -> useful resource which shows how to setup bridged and natted networking for your containers
522 * http://box.matto.nl/lxconlaptop.html -> another example for natted networking also applicable for wlan connectivity on laptops
523stuff for recovery or swapping hosts
524make a tar of the dir and extract it in place on the other host using the -C option to change dir in tar no cp or mv
525tar --numeric-owner -xzvf lxc.tgz -C /
526tar --numeric-owner -xzvf lxc.tgz -C /var/lib/lxc/
527tar --numeric-owner -czvf lxc.tgz /var/lib/lxc/lyceus/
528
529</section>
530
531 <section><title>KVM and Libvirt</title>
532
533 <section><title>Virtmanager</title>
534 <para/>
535 </section>
536
537 <section><title>Proxmox</title>
538 <programlisting>
539 After reading OpenVZ manual then I found the solution:
540 Open /etc/vz/vz.conf
541 Code:
542 VZFASTBOOT=no
543 Change to:
544 Code:
545 VZFASTBOOT=yes
546 Code:
547 # /etc/init.d/vz restart
548 used to mount devices for proxmox guests in vz containers
549 mount --bind /media/Backup/ /var/lib/vz/root/101/media/Backup
550 </programlisting>
551
552 </section>
553 </section>
554 </section>
555
556 <section><title>AD and DNS</title>
557 <para> Active directory is an authorization service that assigns security policies to users and systems.
558 It is currently being ran on the windows 2008 server livia and bkdc. it allows for SSO on the linux systems via Samba, winbind, pam, and nss.
559 An ordinary domain user can join 10 members to the domain.</para>
560 <para>NOTE: See How do I change the default 10 computer limit that Windows 2000 uses to allow authenticated users to join computers to a domain?</para>
561<screen>
562To allow an ordinary user, or group, to add a computer to a domain, you can use either of the following:
563
564 Assign rights using the Default Domain Group policy.
565 Delegate rights using Active Directory Users and Computers.
566
567Assign rights using the Default Domain Group policy:
5681. Open the Default Domain Group policy.
569
5702. Navigate through Computer Configuration / Windows Settings / Security Settings / Local Policies / User Rights Assignment.
571
5723. Expand User Rights Assignment.
573
5744. Double-click Add workstations to Domain.
575
5765. Check the Define these policy settings box.
577
5786. Press the Add User or Group button.
579
5807. Complete the dialog to add the user or group.
581
5828. Press Apply and OK.
583Delegate rights using Active Directory Users and Computers:
5841. Open the Active Directory Users and Computers snap-in.
585
5862. Right-click the container under which you want the computers added, and press Delegate Control.
587
5883. Press Next.
589
5904. Press Add.
591
5925. After adding all the users and/or groups, press Next.
593
5946. Select Create custom task to delegate and press Next.
595
5967. Select Only the following objects in the folder, check Computer objects, check the Create selected objects in this folder box, and press Next.
597
5988. Check the Create all child object box and press Next.
599
6009. Press Finish.</screen></section>
601<section><title>Kerberos</title>
602<para> this was taken from here <link xl:href="https://www.debian-administration.org/article/570/MIT_Kerberos_installation_on_Debian">www.debian-administration.org/article/570/MIT_Kerberos_installation_on_Debian</link> I haven't had a chance to write something better than this.</para>
603<screen>
604
605
606MIT Kerberos installation on Debian
607
608Posted by docelic on Wed 5 Dec 2007 at 10:15
609Tags: infrastructure, kerberos, mit, pam
610
611The purpose of this Guide is to give you a straight-forward, Debian-friendly way of installing and configuring Kerberos. We will go through introduction to Kerberos, installation, configuration, PAM config and setting up of encrypted telnet/ftp session to the server. We will show how to use Kerberos logins as a replacement for SSH keys, and how to use standard (optionally encrypted) telnet/ftp connections instead of SSH.
612
613The newest version of this article can be found at http://techpubs.spinlocksolutions.com/dklar/kerberos.html.
614
615Table of Contents
616
617Introduction
618Conventions
619Kerberos
620
621 Installation
622 Initial Test
623 Access Rights
624 Kadmin Test
625 Adding a User
626 Obtaining a Kerberos Ticket
627 Installing Kerberized Services
628 Connecting to a Kerberized Service
629 Troubleshooting the Connection
630 PAM Configuration
631
632Introduction
633
634Kerberos is a service that has traditionally been captivating system administrators' and advanced users' interest, but its (seemingly or not) high entry barrier and infrastructure requirements prevented many of them from ever using it.
635
636A lot of theory and introductory material has been written on it. We will present a summary here that will be enough for you to put everything in context and form a mental map of the whole problem domain.
637
638Kerberos is a sophisticated authentication technology for securing access to network applications. Passwords are never transmitted over the network. Instead, cryptographic tokens (called "tickets") are used to provide the identity of the user to services. These tickets are acquired by users from a security server, call a Key Distribution Centre (KDC). Furthermore, Kerberos requires mutual authentication of both parties (user and server); this prevents a malicious service from masquerading as an authorised service and stealing information from the user.
639
640Kerberos is a Single Sign-On (SSO) technology. This means that the user only has to authenticate once against the KDC to acquire as many tickets as required by the user in the course of his session. Kerberos is application agnostic. Kerberos is not tied to any particular application, and has been implemented for all common network services (ssh, HTTP, FTP, SMTP, IMAP, etc).
641
642In most simple scenarios, Kerberos can be used as a functional equivalent of SSH keys that you use for passwordless login. Also, it is geared towards infrastructure-based Unix/Linux setups (as opposed to ad-hoc installations), and that's where its true effectiveness lies.
643
644 MIT Kerberos, an implementation of Kerberos, will be used to authenticate users.
645
646 User account names and passwords will be defined in the Kerberos database. When they type in their login name and password, their input will be verified against the Kerberos database.
647
648 Kerberos will only hold this "account information", name/password pairs called principals (along with their expiration time and related options). It will NOT (it can't) hold any other user information (such as IDs, GIDs, real names etc.); this makes Kerberos well-defined and easy to place in your mental map.
649
650 When users authenticate with their credentials (username/password pair), Kerberos issues them a ticket that they use to access all kinds of services without having to retype their login name and/or password. In fact, to be precise, each service requires it's own ticket, but the initial ticket issued by Kerberos is a Ticket-granting Ticket (TGT) which is automatically used to produce further tickets for individual services.
651
652 Note also that with Kerberos, thanks to the design of the protocol, passwords never go over the wire.
653
654 You can find the proper introduction (and complete documentation) on the MIT Kerberos website. I find their documentation (generated in multi-page format from texinfo sources) extremely irritating. To help this, you can download their full Kerberos software release (just pick the lastest stable) which includes the documentation in other formats, such as PostScript.
655
656The "glue layer":
657
658 Linux-PAM, an implementation of PAM (Pluggable Authentication Modules), will be used to tune the behavior of individual programs' functions related to authentication and authorization.
659
660 All kinds of services need to be configured to work properly in the local environment. Just think of daemons (system services) that need to authenticate or authorize users before allowing them access or use of privileged functions. Primarily, this system must be able to prompt users for additional information, such as passwords, interactively.
661
662 Modern Unix systems follow the PAM approach. Instead of hard-coding decision methods and the decision interfaces in the programs themselves, they invoke PAM through a unified, pre-defined interface. Exactly how the PAM then carries out the tests (such as asking the user for a password and verifying its correctness) is none of their business.
663
664 For example, this way, you could easily authenticate user by a retina scan, instead of the usual /etc/passwd file approach. And all, of course, without any recompilation or a change in system software.
665
666 You can find the proper introduction (and complete documentation) on the Linux-PAM website. Pay special attention to the PAM Configuration File Syntax page. Also take a look at the Linux-PAM(7) and pam(7) manual pages.
667
668Conventions
669
670It's quite disappointing when you are not able to follow the instructions found in the documentation. So let's agree on a few points:
671
672 Install and configure sudo. It will allow you to carry out system administrator tasks from your normal user account. All my examples requireing root privileges will use sudo so you will be able to copy-paste them to your shell:
673
674 su -c 'aptitude install sudo'
675 su -c 'echo "$USERNAME ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers'
676
677 (In the example above, it is not necessary to replace $USERNAME with your user name. It is a shell environment variable that will expand to your current username by itself.)
678
679 This way, you will be able to execute any administrative commands by simply typing sudo COMMAND_NAME COMMAND_ARGUMENTS. Try sudo nano /etc/sudoers just to verify it works.
680
681 The Debian GNU packages that we will install as part of the whole procedure, will ask us a series of questions through the debconf interface. Run sudo dpkg-reconfigure debconf and set interface to "Dialog" and priority to "low". This will bring Debconf itself into a known configuration state.
682
683 Monitoring log files is crucial in detecting problems. The catch-all, straight-forward routine to this is to open a terminal and type cd /var/log; sudo tail -f daemon.log sulog user.log auth.log debug kern.log syslog dmesg messages kerberos/*.
684
685 This command will, as the log messages arrive, keep printing them out to the screen for your inspection.
686
687 Finally, a word on font styles:
688
689 Strong-white-on-black signifies the system commands you need to run, or the answers you need to type in.
690
691 Italic, signifies parts of system commands or answers that you should adjust to match your environment. For example, you will probably want to always replace say, SPINLOCK.HR, with your own domain name in uppercase.
692
693 Normal text on gray background,
694 presents output of a real shell session, or the contents of
695 a file. Parts of the input carrying special meaning are depicted using the
696 rules above, such as SPINLOCK.HR.
697
698Kerberos
699
700Well. Here we come to MIT Kerberos.
701Installation
702
703sudo apt-get install krb5-{admin-server,kdc}
704
705During installation, Kerberos' Debconf interface will ask you a few questions. Here's the list of questions and realistic answers to them:
706
707Default Kerberos version 5 realm? SPINLOCK.HR
708# (Your Internet domain name in uppercase - a standard for naming Kerberos realms)
709
710Kerberos4 compatibility mode to use? none
711# (No krb4 compatibility needed in our setup)
712
713What are the Kerberos servers for your realm? krb.spinlock.hr
714# (Make sure your DNS resolves krb.spinlock.hr to
715# the NETWORK IP of the server, NOT 127.0.0.1!). If you do not use
716# the DNS server, adjust an entry in /etc/hosts like this:
717#
718# 127.0.0.1 localhost.localdomain localhost
719# 192.168.7.12 monarch.spinlock.hr monarch krb.spinlock.hr
720
721What is the administrative server for your realm? krb.spinlock.hr
722# (Make sure your DNS resolves krb.spinlock.hr to
723# the NETWORK IP of the server, NOT 127.0.0.1!). If not, same hint as above.
724
725Once we do the above, both the admin-server (kadmind) and the KDC will try to start. Kadmind will fail since we haven't created any realms yet.
726
727To actually create the realm, invoke krb5_newrealm. The command will ask about the master password (write it down since it's very important but also very rarely used) and create the realm using the name as defined in the Debconf step (SPINLOCK.HR).
728
729We now need to tune the Kerberos config file, /etc/krb5.conf. It is split into sections. Look for [realms] and notice the listed famous realms in there that don't belong to your configuration (ATHENA.MIT.EDU, GNU.ORG, ANDREW.CMU.EDU etc.). You can leave them there and at the end add:
730
731SPINLOCK.HR = {
732 kdc = krb
733 admin_server = krb
734 default_domain = spinlock.hr
735}
736
737
738Then search further below for [domain_realm] and add your realm definitions:
739
740.spinlock.hr = SPINLOCK.HR
741spinlock.hr = SPINLOCK.HR
742
743Then, at the end of the file add this logging section:
744
745[logging]
746 kdc = FILE:/var/log/kerberos/krb5kdc.log
747 admin_server = FILE:/var/log/kerberos/kadmin.log
748 default = FILE:/var/log/kerberos/krb5lib.log
749
750(Kerberos logs to syslog by default, but I like separate files, as you see. Run sudo mkdir /var/log/kerberos to create the log directory.)
751
752Run sudo invoke-rc.d krb5-admin-server restart.
753Run sudo invoke-rc.d krb5-kdc restart.
754
755Re-start the log monitoring command (see the section called "Conventions") so that the tail program can pick up new log files from the kerberos/ directory.
756Initial Test
757
758It's already the time to test the installation. We assume that both the admin server and the KDC can be restarted with no errors. (Again, you are watching the log files, right?).
759
760To just quickly test the installation, we will use the kadmin.local database administration program.
761
762Start kadmin.local, then type listprincs. That command should print out the list of principals (user, host and/or service accounts). The whole session should look like this:
763
764sudo kadmin.local
765Authenticating as principal root/admin@SPINLOCK.HR with password.
766
767kadmin.local: listprincs
768
769K/M@SPINLOCK.HR
770kadmin/admin@SPINLOCK.HR
771kadmin/changepw@SPINLOCK.HR
772kadmin/history@SPINLOCK.HR
773krbtgt/SPINLOCK.HR@SPINLOCK.HR
774
775kadmin.local: quit
776
777You may have a few questions now. First of all, how did kadmin.local authenticate as principal root/admin without asking for a password or anything? And second, what's the difference between kadmin and kadmin.local?
778
779There's one common answer to both questions. kadmin.local is a command intended to be ran only on the administration server. It does not connect using the Kerberos protocol; instead, it directly opens the Kerberos database on the local filesystem and authenticates as any user it desires. This can only work for the system administrator who has sufficient privileges to open the database files on the local Unix filesystem, as one would guess. kadmin is the same thing, but it works over the network. It means it uses the Kerberos protocol to connect, and it requires the account password as part of the routine.
780Access Rights
781
782Take a look at the /etc/krb5kdc/kadm5.acl file. It defines user access rights in Kerberos. For users with no special privileges, no action is required. To admin users, however, we want to grant all privileges. To do this, make sure the following line is present in the file and enabled (that is, without the comment '#' character at the beginning):
783
784*/admin *
785
786Also, a word or two on principal names is in order here. In the test step above, you might have noticed principal names like kadmin/admin@SPINLOCK.HR. The general naming syntax for principals is SPEC@REALM, where SPEC, by convention, consists of components separated by "/". In the case of user names, the first component identifies the user name, and the second component, when present, identifies user role. This is a nice separation of privileges; System administrators will authenticate to Kerberos like any other user during off-hours (for example, as NAME). Only when the duty calls will they authenticate as NAME/admin and obtain administrative privileges on the Kerberos database.
787
788Knowing all this, let's create principal root/admin.
789
790sudo kadmin.local
791Authenticating as principal root/admin@SPINLOCK.HR with password.
792
793kadmin.local: addprinc root/admin
794
795WARNING: no policy specified for root/admin@SPINLOCK.HR; defaulting to no policy
796Enter password for principal "root/admin@SPINLOCK.HR": PASSWORD
797Re-enter password for principal "root/admin@SPINLOCK.HR": PASSWORD
798Principal "root/admin@SPINLOCK.HR" created.
799
800kadmin.local: quit
801
802Kadmin Test
803
804Now that we've created the root/admin user, double-check that all the permissions are granted to admin roles in the /etc/krb5kdc/kadm5.acl (instructions given in the previous section); then restart the admin server (sudo invoke-rc.d krb5-admin-server restart).
805
806At this point, we should be able to use the kadmin just as we used kadmin.local. (With the exception, of course, that kadmin will prompt for a password to connect using the Kerberos protocol, as already explained).
807
808sudo kadmin
809Authenticating as principal root/admin@SPINLOCK.HR with password.
810
811Password for root/admin@SPINLOCK.HR: PASSWORD
812
813kadmin: listprincs
814
815K/M@SPINLOCK.HR
816kadmin/admin@SPINLOCK.HR
817kadmin/changepw@SPINLOCK.HR
818kadmin/history@SPINLOCK.HR
819krbtgt/SPINLOCK.HR@SPINLOCK.HR
820root/admin@SPINLOCK.HR
821
822kadmin: quit
823
824Adding a User
825
826Assuming that you've got everything right up to this step, let's now add a new user account (a "principal") to Kerberos. We've already done this above for root/admin, but let's now to it for your regular, unprivileged account.
827
828NOTE: Before creating the Kerberos principal, make sure your intended user already exists as a regular system user (in /etc/passwd most likely). Why it has to be an existing user will be explained later.
829
830Supposing your account name is "mirko", do the following:
831
832sudo kadmin.local
833Authenticating as principal root/admin@SPINLOCK.HR with password.
834
835kadmin: addprinc mirko
836
837WARNING: no policy specified for mirko@SPINLOCK.HR; defaulting to no policy
838Enter password for principal "mirko@SPINLOCK.HR": PASSWORD
839Re-enter password for principal "mirko@SPINLOCK.HR": PASSWORD
840Principal "mirko@SPINLOCK.HR" created.
841kadmin: quit
842
843(It would be wise to pick a password that is different from your system password. That way, in the Kerberos test phase, you will easily be able to see whether the password was authenticated against the normal Unix passwd file, or against the Kerberos database.)
844Obtaining a Kerberos Ticket
845
846Now, you remember we said Kerberos would issue us a ticket once we authenticate. Let's try running klist to see the list of tickets:
847
848klist -5
849
850klist: No credentials cache found (ticket cache FILE:/tmp/krb5cc_1000)
851
852Fine. This is okay. There are no tickets and there's no credentials cache created, since we didn't authenticate yet :) So let's run kinit to do so:
853
854kinit
855
856Password for mirko@SPINLOCK.HR: PASSWORD
857
858Well, well! We should have a ticket now!
859
860klist -5
861
862Ticket cache: FILE:/tmp/krb5cc_1000
863Default principal: mirko@SPINLOCK.HR
864
865Valid starting Expires Service principal
86611/22/06 22:30:36 11/23/06 08:30:33 krbtgt/SPINLOCK.HR@SPINLOCK.HR
867
868If you remember the story from the beginning, you will recognize "krbtgt" to be the Ticket-granting Ticket.
869
870This is enough for now. Run kdestroy to terminate the ticket.
871Installing Kerberized Services
872
873Once you have Kerberos working, you need to Kerberize the services to which you want to authenticate using Kerberos.
874
875It is important to realize that each service may support Kerberos (or any other functionality, for that matter) in two ways:
876
877 The service may be configured at compile time to use Kerberos. This is application-specific; it can only be done if Kerberos support was explicitly included into the application source. The Kerberos binding gets compiled directly into the application and there are usually two versions of the service: one with Kerberos, and one without.
878
879 The service may be configured at compile time to use PAM. Again, this is application-specific, but instead of supporting each authentication mechanism individually, services can just support PAM and delegate all the rest of the authentication work to it. Practically all Unix daemons now have PAM support.
880
881In your Debian GNU repository, you will see packages like krb-ftpd, krb5-telnetd and krb5-rsh-server. Those are replacement services for ftp, telnet and rsh with direct Kerberos support (they also offer encryption support, replacing ssh in every way). When using Kerberized ftp, telnet or rsh, I like to install those packages with direct Kerberos support. Other services, less important or without explicit Kerberos support, can be configured through PAM and will work equally fine.
882
883For the moment, let's just install the krb5-rsh-server. Care must also be taken to actually enable the rsh server; it is started from Inetd (see /etc/inetd.conf), so Inetd must be running as well.
884
885sudo apt-get install krb5-rsh-server
886sudo update-rc.d openbsd-inetd defaults
887sudo invoke-rc.d openbsd-inetd restart
888
889Connecting to a Kerberized Service
890
891Now that we have a Kerberos principal, it would be a real waste if we didn't do anything with it :)
892
893Let's install Kerberized versions of the client programs:
894
895sudo apt-get install krb5-clients
896
897Create yourself a ticket again:
898
899kinit
900
901Password for mirko@SPINLOCK.HR: PASSWORD
902
903There's just one boulder on our way now -- namely, testing the connection on the krb5-rsh-server service we've installed!
904
905It is vital to understand that your first attempt to connect to a Kerberized service WILL LIKELY NOT SUCCEED (but we will not be far away from it succeeding). The example below will show a valid connection, even though you will most probably encounter an error. In the next section, there is a good list of exact errors and their solutions. Each time you get an error in this test step, try to match it with errors listed in the section called "Troubleshooting the Connection" and fix accordingly, moving closer to a working setup.
906
907In fact, the "errors" you'll get aren't exactly errors. They're normal consequences of the fact that we used the "keep adjusting until it works" approach instead of a "do this, do that, and it'll work" method.
908
909Again, remember, what follows is a transcript of a WORKING SYSTEM (you'll have to go through a few steps below to get it working for yourself):
910
911krb5-rsh -x krb.spinlock.hr
912
913This rlogin session is encrypting all data transmissions.
914Last login: Mon Nov 27 16:49:49 from monarch
915Linux monarch 2.4.27-2-686 #1 Mon May 16 17:03:22 JST 2005 i686 GNU/Linux
916
917The programs included with the Debian GNU/Linux system are free software;
918the exact distribution terms for each program are described in the
919individual files in /usr/share/doc/*/copyright.
920
921Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
922permitted by applicable law.
923You have new mail.
924
925logout
926Connection closed.
927
928Troubleshooting the Connection
929
930Consult this list for solutions to the possible Kerberos connection problems.
931
932When you get rsh login working, skip below to the section called "PAM Configuration".
933Error: Connection Refused
934
935krb5-rsh -PN krb.spinlock.hr
936
937
938connect to address 192.168.7.12: Connection refused
939Trying krb4 rlogin...
940connect to address 192.168.7.12: Connection refused
941trying normal rlogin (/usr/bin/netkit-rlogin)
942exec: No such file or directory
943
944Let's take a look at this. First of all, you can see that krb5-rsh has some fallbacks built-in. It first tries to connect using the Kerberos 5 protocol, then Kerberos 4, and then using the normal, non-kerberized rsh. We are only interested in the krb5 result. If any of the other two methods succeed (the krb4 or plain rsh, but they shouldn't!), it's still not what we want.
945
946So where's the problem? Assuming that you did everything right (installed krb5-rsh-server and restarted inetd), the problem is very simple. Namely, by default, Kerberized servers in Debian do not accept unencrypted connections! So, on next attempt, add -x on the command line.
947
948krb5-rsh -PN -x krb.spinlock.hr
949
950Error: Server not found in Kerberos database
951
952krb5-rsh -PN -x krb.spinlock.hr
953
954
955error getting credentials: Server not found in Kerberos database
956
957As you might know, both the users and the services they use must have an appropriate principal entry in the Kerberos database (we're authenticating both the service and the user who wishes to use it). While users are in form of NAME/ROLE (/role is optional), services are in form SERVICE-TYPE/HOST. So we need to add an entry for service "host" (common name for telnet-like services), on host monarch.spinlock.hr:
958
959sudo kadmin.local
960Authenticating as principal root/admin@SPINLOCK.HR with password.
961
962kadmin.local: addprinc -randkey host/monarch.spinlock.hr
963
964WARNING: no policy specified for host/monarch.spinlock.hr@SPINLOCK.HR; defaulting to no policy
965Principal "host/monarch.spinlock.hr@SPINLOCK.HR" created.
966
967kadmin.local: quit
968
969Error: No such file or directory
970
971krb5-rsh -PN -x krb.spinlock.hr
972
973
974Couldn't authenticate to server: Server rejected authentication (during sendauth exchange)
975Server returned error code 60 (Generic error (see e-text))
976Error text sent from server: No such file or directory
977
978The above error indicates that we should pay attention to the "e-text" (error text returned to the client). The error text tells us, in kind of a confusing way (since, you see, there is no filename reported), that the /etc/krb5.keytab file is missing altogether. This is not very likely to happen on Debian GNU since the file is created as part of the automatic package configuration routine. In any case, to create the file, we need to use the kadmin.local command and populate the file with two default entries, kadmin/admin and kadmin/changepw:
979
980sudo kadmin.local
981Authenticating as principal root/admin@SPINLOCK.HR with password.
982
983kadmin.local: ktadd -k /etc/krb5.keytab kadmin/admin kadmin/changepw
984
985Entry for principal kadmin/admin with kvno 4, encryption type Triple DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
986Entry for principal kadmin/admin with kvno 4, encryption type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.
987Entry for principal kadmin/changepw with kvno 4, encryption type Triple DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
988Entry for principal kadmin/changepw with kvno 4, encryption type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.
989
990kadmin.local: quit
991
992Error: Key table entry not found
993
994krb5-rsh -PN -x krb.spinlock.hr
995
996
997Couldn't authenticate to server: Server rejected authentication (during sendauth exchange)
998Server returned error code 60 (Generic error (see e-text))
999Error text sent from server: Key table entry not found
1000
1001Ok. So we now see that the krb5 server did accept the connection, but there's still something preventing the thing from working. The e-text "Key table entry not found" indicates that the host/service principal (created earlier) is not listed in the keytab file. (While for users a principal entry is enough, services need to be listed in the keytab file as well). So we invoke kadmin.local very similarly to the other ktadd example from above:
1002
1003sudo kadmin.local
1004Authenticating as principal root/admin@SPINLOCK.HR with password.
1005
1006kadmin.local: ktadd -k /etc/krb5.keytab host/monarch.spinlock.hr
1007
1008Entry for principal host/monarch.spinlock.hr with kvno 8, encryption type Triple DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
1009Entry for principal host/monarch.spinlock.hr with kvno 8, encryption type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.
1010
1011kadmin.local: quit
1012
1013Error: Decrypt integrity check failed
1014
1015krb5-rsh -PN -x krb.spinlock.hr
1016
1017
1018Couldn't authenticate to server: Server rejected authentication (during sendauth exchange)
1019Server returned error code 31 (Decrypt integrity check failed)
1020Error text sent from server: Decrypt integrity check failed
1021
1022Typically, this can happen when you delete the service and add it again, after the ticket was already obtained. If you remember, the principal for the service was created with the -randkey switch, and so as the key changes randomly on each invocation, it broke the decryption integrity check. Your ticket is not expired, but it can't be used any more -- the encryption keys have changed. The solution to this is to simply destroy the ticket and obtain a new one. To do so, just run kdestroy; kinit.
1023Error: Key version number for principal in key table is incorrect
1024
1025krb5-rsh -PN -x krb.spinlock.hr
1026
1027
1028Couldn't authenticate to server: Server rejected authentication (during sendauth exchange)
1029Server returned error code 60 (Generic error (see e-text))
1030Error text sent from server: Key version number for principal in key table is incorrect
1031
1032This means that the encryption key did not change, but the Key Version Number ("KVNO") did. This usually happens when you change the keytab file after obtaining the ticket. Luckily, the solution, can't be simpler: kdestroy; kinit.
1033
1034That was a pretty extensive list of problems you might encounter. Supposing you got Kerberos login working, let's move onto PAM configuration.
1035PAM Configuration
1036
1037Our PAM setup will work out of the box, and it would be very wise that you get familiar with the PAM Configuration File Syntax before introducing any changes.
1038
1039Long story short, PAM has four management groups. We need to add pam_krb5.so to all of them. See pam_krb5(5) for a description why. (Just keep one thing in mind; session management group isn't as useless as one would conclude from the manual page -- it actually initializes the Kerberos Ticket Granting Ticket for you, so you don't have to invoke kinit manually.)
1040
1041Anyway, here's the show. (PAM configuration has its quirks, so don't try to be smart too early; just copy-paste this to your files and avoid the trouble.)
1042/etc/pam.d/common-account
1043
1044Adjust the file as show below. Either traditional Unix or Kerberos account will be enough to pass this step. If both fail, user will be denied access.
1045
1046account sufficient pam_unix.so
1047account sufficient pam_krb5.so
1048account required pam_deny.so
1049
1050/etc/pam.d/common-auth
1051
1052The following configuration requires a valid password from either Kerberos or the traditional password file. For users that will only authenticate through Kerberos, putting a "*K*" in the password field in /etc/shadow (or /etc/passwd if no shadow passwords are used) is common to both prevent shadow-based authentication and to informally signify a Kerberos login. If both the Kerberos password and the shadow password exist, then the user will be able to type in ANY OF THEM to gain access. If the passwords are the same, then the order of the auth lines will determine which method will take precendence (first match wins).
1053
1054auth sufficient pam_unix.so nullok_secure
1055auth sufficient pam_krb5.so use_first_pass
1056auth required pam_deny.so
1057
1058/etc/pam.d/common-password
1059
1060The following configuration is used for changing the password, and it only operates on the password in the Kerberos database.
1061
1062password sufficient pam_unix.so nullok obscure md5
1063password sufficient pam_krb5.so use_first_pass
1064password required pam_deny.so
1065
1066/etc/pam.d/common-session
1067
1068The following configuration invokes the usual pam_limits.so module, then initializes the TGT (if the user authenticated with a Kerberos password), and then logs session open to the system log files. (It will also log session closedown when a user disconnects).
1069
1070session optional pam_unix.so
1071
1072session optional pam_krb5.so
1073
1074
1075Conclusion
1076
1077At this point, you should have a working Kerberos installation. You can create an account ("principal") in Kerberos, and then use it to log in into the system and/or access services.
1078
1079Note that Kerberos does not keep user information in its database (user ID, group ID, real name etc.). So, in the above setup as shown, you first have to create a normal Unix user (with /etc/passwd entry), and then create it also in Kerberos. Note that the traditional authentication method (from /etc/password and friends) is listed first in the PAM configuration. This means, if you set an identical password for Unix and Kerberos, pam_unix authentication will succeed, skipping the Kerberos part and failing to automatically initialize your Kerberos ticket. Therefore, choose a different Kerberos password for a user than what you've set in /etc/passwd or shadow. Then, by typing Kerberos password, you'll make sure the right thing happens -- authentication will be performed by Kerberos, and Kerberos will initialize users' Kerberos ticket and allow them to access Kerberizes services without typing in any credentials (similar to SSH keys).
1080
1081To completely eliminate /etc/passwd (and related files), you will have to install LDAP or something like libnss-ptdb, but this will be covered in other articles.
1082
1083The newest version of this article can always be found at http://techpubs.spinlocksolutions.com/dklar/kerberos.html.
1084</screen></section>
1085
1086
1087<section><title>Domain Service with Bind</title>
1088<para> this was taken from here <link xl:href="https://wiki.debian.org/Bind9">wiki.debian.org/Bind9</link> I haven't had a chance to write something better than this.</para>
1089<screen>
1090= Introduction =
1091Putting a DNS server on a network allows for the replacement of IP addresses of individual machines by a name. As a result, it's even possible to associate multiple names to the same machine to update the different available services. For example, www.example.com and pop.example.com, could both point to the primary server where the mail server and the business intranet reside, and the domain could be example.com. It's easy to remember that these two services are running on the same machine whose IP address is 192.168.0.1.
1092
1093Now imagine that our network administrator decides for some reason or another to move the mail server to the machine 192.168.0.11. The only thing that has to be changed is the DNS server configuration file. You could always go and modify the host configuration for all the users, but that would be time consuming and inconvenient.
1094
1095= Definitions =
1096 * '''DNS''' : Domain Name System or Domain Name Server
1097 * '''Primary Server''' :
1098 * '''Secondary server''' :
1099 * '''Server cache''' :
1100= Network Layout =
1101We get internet access through an xxxbox (192.168.1.1), two DNS servers provided by our ISP (80.10.249.2, 80.10.246.129). In fact, these two latter servers will ever be referred to in the configuration because the xxxbox will be in charge of resolving names if the packet destination isn't known. Consequently, I consider the xxxbox like a primary server outside of our domain. The “sid†server (192.168.1.10) is connected to the xxxbox via its primary network card. It's also connected to the LAN (192.168.0.0/24) by its secondary network interface(192.168.0.1). It's on this that we are going to install the primary DNS server for our domain example.com
1102([[http://www.ietf.org/rfc/rfc2606.txt|RFC 2606]]) All the computers on the LAN are automatically assigned a single address by the DHCP service. The DHCP also provides the primary DNS server's address for our domain, and updatees the host names for the zone example.com so they can be associated with an ip address.
1103
1104= Server Management =
1105== Installation ==
1106The package bind9 will be used for installation.
1107
1108{{{
1109# apt-get install bind9 }}}
1110and then if you want to also install the documentation (very useful):
1111
1112{{{
1113# apt-get install bind9-doc
1114}}}
1115== Configuration ==
1116After installation, you might want to get familiar with some of the configuration files. They are in the directory /etc/bind/
1117
1118=== TSIG Signature ===
1119The purpose of this signature is to authenticate transactions with BIND. Thus, the DHCP server cannot update the example.com domain if it loses this key. Copy and paste an existing key
1120
1121{{{
1122# cd /etc/bind/
1123# cat rndc.key
1124key "rndc-key" {
1125 algorithm hmac-md5;
1126 secret "QJc08cnP1xkoF4a/eSZZbw==";
1127};
1128
1129# cp rndc.key ns-example-com_rndc-key
1130}}}
1131You can generate a new key with the following options:
1132
1133 * '''algorithm HMAC-MD5''' - identifies 157 (required for a TSIG signature and only algorithm supported by BIND)
1134 * '''length of 512 octets''' (multiple of 64 with a maximum length of 512 for the above algorithm)
1135 * '''name''' : ns-example-com_rndc-key
1136{{{
1137dnssec-keygen -a HMAC-MD5 -b 512 -n USER ns-example-com_rndc-key
1138Kns-example-com_rndc-key.+157+53334
1139}}}
1140The footprint associated with the key is 53334. We get two files, one with an extension key and the other with a private extension. This substitutes the key in the file ns-example-com_rndc-key with the one in one of these two files.
1141
1142{{{
1143# cat Kns-example-com_rndc-key.+157+53334.private
1144Private-key-format: v1.2
1145Algorithm: 157 (HMAC_MD5)
1146Key: LZ5m+L/HAmtc9rs9OU2RGstsg+Ud0TMXOT+C4rK7+YNUo3vNxKx/197o2Z80t6gA34AEaAf3F+hEodV4K+SWvA==
1147Bits: AAA=
1148
1149# cat ns-example-com_rndc-key
1150key "ns-example-com_rndc-key" {
1151 algorithm hmac-md5;
1152 secret "LZ5m+L/HAmtc9rs9OU2RGstsg+Ud0TMXOT+C4rK7+YNUo3vNxKx/197o2Z80t6gA34AEaAf3F+hEodV4K+SWvA==";
1153};
1154}}}
1155The file ns-example-com_rndc-key should not be made world readable for security reasons. This should be inserted into the bind configuration by an include because the bind configuration itself is world-readable. Also, it's a good idea to delete the key and private files generated before.
1156
1157=== named.conf File ===
1158This file is the main configuration file for the DNS file.
1159
1160{{{
1161// Managing acls
1162acl internals { 127.0.0.0/8; 192.168.0.0/24; };
1163
1164// Load options
1165include "/etc/bind/named.conf.options";
1166
1167// TSIG key used for the dynamic update
1168include "/etc/bind/ns-example-com_rndc-key";
1169
1170// Configure the communication channel for Administrative BIND9 with rndc
1171// By default, they key is in the rndc.key file and is used by rndc and bind9
1172// on the localhost
1173controls {
1174 inet 127.0.0.1 port 953 allow { 127.0.0.1; };
1175};
1176
1177// prime the server with knowledge of the root servers
1178zone "." {
1179 type hint;
1180 file "/etc/bind/db.root";
1181};
1182
1183include "/etc/bind/named.conf.default-zones";
1184include "/etc/bind/named.conf.local";
1185}}}
1186
1187=== File named.conf.default-zones ===
1188Note: as of Debian 7 "Wheezy" bind9 ships with a file containing default forward, reverse, and broadcast zones.
1189{{{
1190// be authoritative for the localhost forward and reverse zones, and for
1191// broadcast zones as per RFC 1912
1192zone "localhost" {
1193 type master;
1194 file "/etc/bind/db.local";
1195};
1196zone "127.in-addr.arpa" {
1197 type master;
1198 file "/etc/bind/db.127";
1199};
1200zone "0.in-addr.arpa" {
1201 type master;
1202 file "/etc/bind/db.0";
1203};
1204zone "255.in-addr.arpa" {
1205 type master;
1206 file "/etc/bind/db.255";
1207};
1208}}}
1209
1210=== File named.conf.options ===
1211This file contains all the configuration options for the DNS server
1212
1213{{{
1214options {
1215 directory "/var/cache/bind";
1216
1217 // Exchange port between DNS servers
1218 query-source address * port *;
1219
1220 // Transmit requests to 192.168.1.1 if
1221 // this server doesn't know how to resolve them
1222 forward only;
1223 forwarders { 192.168.1.1; };
1224
1225 auth-nxdomain no; # conform to RFC1035
1226
1227 // Listen on local interfaces only(IPV4)
1228 listen-on-v6 { none; };
1229 listen-on { 127.0.0.1; 192.168.0.1; };
1230
1231 // Do not transfer the zone information to the secondary DNS
1232 allow-transfer { none; };
1233
1234 // Accept requests for internal network only
1235 allow-query { internals; };
1236
1237 // Allow recursive queries to the local hosts
1238 allow-recursion { internals; };
1239
1240 // Do not make public version of BIND
1241 version none;
1242};
1243}}}
1244The port associated with the '''query-source''' option must not in any case be frozen because it jeopardizes the DNS transactions in the case of a resolver.
1245
1246
1247 * [[http://www.kb.cert.org/vuls/id/800113|Vulnerability Note VU#800113]]
1248 * [[http://www.trusteer.com/bind9dns|Bind9 DNS Cache Poisoning]]
1249M. Rash wrote an interesting article about this and how to force the source port randomly via the iptables:
1250[[http://www.cipherdyne.org/blog/2008/07/mitigating-dns-cache-poisoning-attacks-with-iptables.html|Mitigating DNS Cache Poisoning Attacks with iptables]]
1251
1252To reduce the delay timeout for UDP connections, and thus highlight the randomization, which by default is 30s by tuple, simply update the parameter net.netfilter.nf_conntrack_udp_timeout
1253
1254{{{
1255# sysctl -w net.netfilter.nf_conntrack_udp_timeout=10
1256}}}
1257to get timeout of 10s.
1258
1259=== named.conf.local File ===
1260This file contains the local DNS server configuration, and this is where you declare the zones associated with this server's domain(s).
1261
1262
1263{{{
1264// Manage the file logs
1265include "/etc/bind/named.conf.log";
1266
1267// Domain Management example.com
1268// ------------------------------
1269// - The server is defined as the master on the domain.
1270// - There are no forwarders for this domain.
1271// - Entries in the domain can be added dynamically
1272// with the key ns-example-com_rndc-key
1273zone "example.com" {
1274 type master;
1275 file "/var/lib/bind/db.example.com";
1276 //forwarders {};
1277 // If we do not comment the ''forwarders'' "empty" clients of the local subnet in my case don't have access to the upstream DNS ?
1278 //allow-update { key ns-example-com_rndc-key; };
1279 allow-update { key rndc-key; };
1280 //confusion between the file name to import (ns-example-com_rndc-key) and the key label (rndc-key) ?
1281};
1282zone "0.168.192.in-addr.arpa" {
1283 type master;
1284 file "/var/lib/bind/db.example.com.inv";
1285 //see comment below (zone "example.com")
1286 //forwarders {};
1287 //allow-update { key ns-example-com_rndc-key; };
1288 allow-update { key rndc-key; };
1289};
1290
1291// Consider adding the 1918 zones here, if they are not used in your
1292// organization
1293include "/etc/bind/zones.rfc1918";
1294}}}
1295=== named.conf.log File ===
1296{{{
1297logging {
1298 channel update_debug {
1299 file "/var/log/update_debug.log" versions 3 size 100k;
1300 severity debug;
1301 print-severity yes;
1302 print-time yes;
1303 };
1304 channel security_info {
1305 file "/var/log/security_info.log" versions 1 size 100k;
1306 severity info;
1307 print-severity yes;
1308 print-time yes;
1309 };
1310 channel bind_log {
1311 file "/var/log/bind.log" versions 3 size 1m;
1312 severity info;
1313 print-category yes;
1314 print-severity yes;
1315 print-time yes;
1316 };
1317
1318 category default { bind_log; };
1319 category lame-servers { null; };
1320 category update { update_debug; };
1321 category update-security { update_debug; };
1322 category security { security_info; };
1323};
1324}}}
1325Here we define different log methods for the different categories. The first category is, as its name indicates the default category that is usually assigned to syslog. All categories not mentioned, are similar to the default category. For a list of the different categories, see [[http://www.bind9.net/manual/bind/9.3.2/Bv9ARM| the bind9 administrator reference manual]]. In terms of blade-servers, it ignores all the logs associated with them.
1326
1327== Resource Records (RR) ==
1328DNS is made up of several registrations, RR or Resource Records, defining the various domain information. The first is dedicated to name resolution, in our case, it is the file db.example.com. The second will be used for reverse name resolution, it is the file db.example.com.inv.
1329
1330=== Files ===
1331 * RR for name reso (db.example.com file)
1332
1333{{{
1334$TTL 3600
1335@ IN SOA sid.example.com. root.example.com. (
1336 2007010401 ; Serial
1337 3600 ; Refresh [1h]
1338 600 ; Retry [10m]
1339 86400 ; Expire [1d]
1340 600 ) ; Negative Cache TTL [1h]
1341;
1342@ IN NS sid.example.com.
1343@ IN MX 10 sid.example.com.
1344
1345sid IN A 192.168.0.1
1346etch IN A 192.168.0.2
1347
1348pop IN CNAME sid
1349www IN CNAME sid
1350mail IN CNAME sid
1351}}}
1352 * RR for inverse name resol ( db.example.com.inv file)
1353
1354{{{
1355@ IN SOA sid.example.com. root.example.com. (
1356 2007010401 ; Serial
1357 3600 ; Refresh [1h]
1358 600 ; Retry [10m]
1359 86400 ; Expire [1d]
1360 600 ) ; Negative Cache TTL [1h]
1361;
1362@ IN NS sid.example.com.
1363
13641 IN PTR sid.example.com.
13652 IN PTR etch.example.com.
1366}}}
1367=== Some Explanations : ===
1368$TTL : (Time To Live) expresses the duration (in seconds) validity, by default, of the information contained in the RRs. Once this time expires, it is necessary to recheck the data. Types :
1369
1370 * '''SOA''' : Show romanization
1371to define information about the area. In this case the name of the primary DNS server "sid.example.com." and the email address of technical contact (root.example.com.; the @ is replaced by a dot). It is composed of several fields:
1372 * 1. ''Serial'' : is the whole non-signed 32 bits. This is the serial number to increment with each change of file. It allows the secondary server to reload the information they have. The general purpose is to format it this way YYYYMMDDXX, either for the first amendment 01/04/2007 -> 2007040101, for the second 2007040102.
1373 * 2. ''Refresh'' : defines the data refresh period.
1374 * 3. ''Retry '': if an error occurs during the last refresh, it will be repeated at the end of time Retry.
1375 * 4. Expires'''': the server is considered unavailable after the time expires.
1376 * 5. Negative cache TTL'''': set the lifetime of a NXDOMAIN response from us.
1377 *'' 'NS''': information on behalf of nameservers for the domain.
1378 *'' 'X.''': information on the mail server. Many can be defined. Thus, it is possible to give them a priority, assigning a number. The lower the number, the higher the priority.
1379 *'' 'A''': associates a host name to an IPv4 address (32 bits)
1380 *'' 'YYYY''': associates a host name to an IPv6 address (128 bits)
1381 *'' 'CNAME''': identifies the canonical name of an alias (a name that points to another name)
1382 *'' 'PTR''': This is simply the inverse resolution (the opposite of type A).
1383The classes in the association determines the Internet class. Other classes are available (CH and HS). For more information please consult the [[http://www.ietf.org/rfc/rfc1035.txt|RFC 1035]]
1384
1385== /etc/resolv.conf File ==
1386{{{
1387search example.com
1388}}}
1389It's no more complicated than that !
1390
1391= Bind Chroot =
1392The named daemon is started using the bind user by default.
1393
1394This option is found in the bind service config file''' /etc/default/bind9''' (NOTE: this is not valid for jessie who used systemd):
1395
1396{{{
1397OPTIONS="-u bind"
1398}}}
1399
1400The bind start script '''/etc/init.d/bind9''' reads this config file when the service is started.
1401
1402Starting bind as a non root user is good practice but to run the daemon in a chroot environment we also need specify the chroot directory. This is done using the same OPTIONS variable in /etc/default/bind9.
1403
1404To begin, start by stopping the bind service:
1405
1406{{{
1407/etc/init.d/bind9 stop
1408}}}
1409
1410Then edit /etc/default/bind9 (not for jessie):
1411
1412{{{
1413OPTIONS="-u bind -t /var/bind9/chroot"
1414}}}
1415
1416For Jessie, edit /etc/systemd/system/multi-user.target.wants/bind9.service to add options "-t /var/bind9/chroot":
1417
1418{{{
1419[Unit]
1420Description=BIND Domain Name Server
1421Documentation=man:named(8)
1422After=network.target
1423
1424[Service]
1425ExecStart=/usr/sbin/named -f -u bind -t /var/bind9/chroot
1426ExecReload=/usr/sbin/rndc reload
1427ExecStop=/usr/sbin/rndc stop
1428
1429[Install]
1430WantedBy=multi-user.target
1431}}}
1432
1433For Jessie, after changing the above unit file, reload it with:
1434
1435{{{
1436systemctl daemon-reload
1437}}}
1438
1439Now create the chroot directory structure:
1440
1441{{{
1442mkdir -p /var/bind9/chroot/{etc,dev,var/cache/bind,var/run/named}
1443}}}
1444
1445Create the required device special files and set the correct permissions:
1446
1447{{{
1448mknod /var/bind9/chroot/dev/null c 1 3
1449mknod /var/bind9/chroot/dev/random c 1 8
1450chmod 660 /var/bind9/chroot/dev/{null,random}
1451}}}
1452
1453Move the current config directory into the new chroot directory:
1454
1455{{{
1456mv /etc/bind /var/bind9/chroot/etc
1457}}}
1458
1459Now create a symbolic link in /etc for compatibility:
1460
1461{{{
1462ln -s /var/bind9/chroot/etc/bind /etc/bind
1463}}}
1464
1465If you want to use the local timezone in the chroot (e.g. for syslog):
1466
1467{{{
1468cp /etc/localtime /var/bind9/chroot/etc/
1469}}}
1470
1471Change the ownership on the files you've just moved over and the rest of the newly created chroot directory structure:
1472
1473{{{
1474chown -R bind:bind /etc/bind/*
1475chmod 775 /var/bind9/chroot/var/{cache/bind,run/named}
1476chgrp bind /var/bind9/chroot/var/{cache/bind,run/named}
1477}}}
1478
1479Edit the PIDFILE variable in /etc/init.d/bind9 to the correct path:
1480
1481{{{
1482PIDFILE=/var/bind9/chroot/var/run/named/named.pid
1483}}}
1484
1485Finally tell rsyslog to listen to the bind logs in the correct place:
1486
1487{{{
1488echo "\$AddUnixListenSocket /var/bind9/chroot/dev/log" > /etc/rsyslog.d/bind-chroot.conf
1489}}}
1490
1491Restart rsyslog and start bind:
1492
1493{{{
1494/etc/init.d/rsyslog restart; /etc/init.d/bind9 start
1495}}}
1496
1497= Client Manage =
1498As I mentioned at the beginning, the assignment of IP addresses on the LAN is performed by the DHCP server. Thus, to set our DNS server to different clients, it is necessary to add the DHCP configuration file the following two lines:
1499
1500option domain-name "example.com"
1501
1502option domain-name-server sid.example.com
1503
1504It must be added to the file (I think) the areas for which DHCP should automatically perform updates.
1505
1506Syntax (everything after "=>" is my comments) :
1507
1508zone [name.of.the.zone.] {
1509 primary 127.0.0.1; => the primary DNS server is on the same machine as the DHCP
1510
1511 key rndc-key; => it's necessary to provide the security key (via an ''include'') in the beginning of the DHCP server configuration file,
1512
1513 this must be the same key that secures the allow-update for the zone in the ''named.conf.local'' of Bind9.
1514}
1515
1516Examples de [name.of.the.zone.] (with the "." at the end) :
1517
1518- example.com. : for the direct zone of this article,
1519
1520- 0.168.192.in-addr.arpa. : for the inverse zone of this article.
1521
1522
1523For more information on the implementation of dynamic update of DNS records through DHCP is [[http://www.dthconnex.com/dhcp_server.html|here]]
1524= Testing tools =
1525 * '''Dig Command''' : this can directly search the DNS server of your choice and get a lot of information in addition to name resolution and contrast resolution.
1526 {{{
1527 <![CDATA[
1528$ dig nomade-frjo.stones.lan
1529; <<>> DiG 9.4.2 <<>> nomade-frjo.stones.lan
1530;; global options: printcmd
1531;; Got answer:
1532;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15760
1533;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
1534
1535;; QUESTION SECTION:
1536;nomade-frjo.stones.lan. IN A
1537
1538;; ANSWER SECTION:
1539nomade-frjo.stones.lan. 900 IN A 192.168.0.242
1540
1541;; AUTHORITY SECTION:
1542stones.lan. 604800 IN NS emerald.stones.lan.
1543stones.lan. 604800 IN NS diamond.stones.lan.
1544
1545;; ADDITIONAL SECTION:
1546diamond.stones.lan. 604800 IN A 192.168.0.1
1547emerald.stones.lan. 604800 IN A 192.168.0.2
1548
1549;; Query time: 20 msec
1550;; SERVER: 127.0.0.1#53(127.0.0.1)
1551;; WHEN: Fri Mar 28 20:53:09 2008
1552;; MSG SIZE rcvd: 131
1553
1554$ dig -x 192.168.0.242
1555; <<>> DiG 9.4.2 <<>> -x 192.168.0.242
1556;; global options: printcmd
1557;; Got answer:
1558;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37702
1559;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
1560
1561
1562;; QUESTION SECTION:
1563;242.0.168.192.in-addr.arpa. IN PTR
1564
1565;; ANSWER SECTION:
1566242.0.168.192.in-addr.arpa. 900 IN PTR nomade-frjo.stones.lan.
1567
1568;; AUTHORITY SECTION:
15690.168.192.in-addr.arpa. 604800 IN NS diamond.stones.lan.
15700.168.192.in-addr.arpa. 604800 IN NS emerald.stones.lan.
1571
1572;; ADDITIONAL SECTION:
1573diamond.stones.lan. 604800 IN A 192.168.0.1
1574emerald.stones.lan. 604800 IN A 192.168.0.2
1575
1576;; Query time: 19 msec
1577;; SERVER: 127.0.0.1#53(127.0.0.1)
1578;; WHEN: Fri Mar 28 20:53:31 2008
1579;; MSG SIZE rcvd: 155
1580}}}
1581 * '''nslookup''' : Kind of slow but still useful.
1582 {{{
1583$ nslookup etch
1584Server: 192.168.0.1
1585Address: 192.168.0.1#53
1586Name: etch.example.com
1587Address: 192.168.0.2
1588
1589$ nslookup 192.168.0.2
1590Server: 192.168.0.1
1591Address: 192.168.0.1#53
15922.0.168.192.in-addr.arpa name = etch.example.com.
1593}}}
1594 * '''named-checkconf''' : Verifies the syntax of the configuration files for Bind9.
1595 {{{
1596# named-checkconf -z
1597zone localhost/IN: loaded serial 1
1598zone 127.in-addr.arpa/IN: loaded serial 1
1599zone 0.in-addr.arpa/IN: loaded serial 1
1600zone 255.in-addr.arpa/IN: loaded serial 1
1601zone estar.lan/IN: loaded serial 20080315
1602zone 0.168.192.in-addr.arpa/IN: loaded serial 20080315
1603zone 10.in-addr.arpa/IN: loaded serial 1
1604zone 16.172.in-addr.arpa/IN: loaded serial 1
1605zone 17.172.in-addr.arpa/IN: loaded serial 1
1606zone 18.172.in-addr.arpa/IN: loaded serial 1
1607zone 19.172.in-addr.arpa/IN: loaded serial 1
1608zone 20.172.in-addr.arpa/IN: loaded serial 1
1609zone 21.172.in-addr.arpa/IN: loaded serial 1
1610zone 22.172.in-addr.arpa/IN: loaded serial 1
1611zone 23.172.in-addr.arpa/IN: loaded serial 1
1612zone 24.172.in-addr.arpa/IN: loaded serial 1
1613zone 25.172.in-addr.arpa/IN: loaded serial 1
1614zone 26.172.in-addr.arpa/IN: loaded serial 1
1615zone 27.172.in-addr.arpa/IN: loaded serial 1
1616zone 28.172.in-addr.arpa/IN: loaded serial 1
1617zone 29.172.in-addr.arpa/IN: loaded serial 1
1618zone 30.172.in-addr.arpa/IN: loaded serial 1
1619zone 31.172.in-addr.arpa/IN: loaded serial 1
1620zone 168.192.in-addr.arpa/IN: loaded serial 1
1621}}}
1622 * '''named-checkzone''' : Verifies the validity of zone files before resetting the configuration.
1623 {{{
1624# named-checkzone example.com /var/lib/bind/db.example.com
1625zone example.com/IN: loaded serial 20080315
1626OK
1627}}}
1628 {{{
1629# named-checkzone 0.168.192.in-addr.arpa /var/lib/bind/db.example.com.inv
1630zone 0.168.192.in-addr.arpa/IN: loaded serial 20080315
1631OK
1632}}}
1633= Links and Resources =
1634 * [[RFC:1035|rfc1035]] - Implementation ans specifications
1635 * [[RFC:1591|rfc1591]] - Domain Name System Structure and Delegation
1636 * [[RFC:2606|rfc2606]] - Reserved Top Level DNS Names
1637 * [[http://www.bind9.net/manual/bind/9.3.2/Bv9ARM]] - Bind 9 Administrator Manual
1638 * Services Whois :
1639 * [[http://www.gandi.net/whois?l=FR|Gandhi]]
1640 * [[http://www.afnic.fr/outils/whois/|AFNIC]]
1641
1642----
1643/!\ ToDos
1644 * End of
1645 * To add DNSSEC
1646]]>
1647</screen>
1648</section>
1649 <section><title>AD->LDAP</title>
1650 <section><title>LDAP</title>
1651 <para>Light weight Directory Access protocol maintains a distributed directory database of user data over the network. It can contains a collection of user data for the network. It is typically used for single sign on scenarios in corporate enviroments. It is currently being used in Thrace.Lan to allow for SSO of administrators on the network. you can request your own login via the <link xl:href="https://www.thrace.lan">Thrace.lan</link> webpage.</para>
1652 <para>Expermimental at this point. We will generally proceeed with a testing phase in the raspberry testing enviroment and verify that all configurations work as they are intended with the production configuration.</para>
1653 <section><title>Installation</title></section>
1654 <section><title>Configuration</title></section>
1655 <section><title>Administration</title></section>
1656 </section></section>
1657
1658 <section><title>File-Sharing</title>
1659 <para> The File sharing for THRACE.Lan refers to CIFS, Formerly Samba. Samba is a free software re-implementation of the SMB/CIFS networking protocol, originally developed by Andrew Tridgell. As of version 3, Samba provides file and print services for various Microsoft Windows clients and can integrate with a Windows Server domain, either as a Primary Domain Controller (PDC) or as a domain member. It can also be part of an Active Directory domain. The Main file sharing server is on xena.thrace.lan and gabrielle.thrace.lan is to be recommissioned as another samba host soon. The current file-sharing directories can be found on <link xl:href="https://www.thrace.lan/">Thrace.lan </link>. They contain documents, pictures, videos, and music. They can be movies, books, or backgrounds for your desktop. The organization is as follows. /media/downloads contains current downloads that have not be sorted. /media/movies contains movies and videos. /media/misc contain miscellaneous items that don't fit else where. /media/apps contains applications and games for your use. The contra to these are the /media/files_* an example would be /media/files_misc which contains older miscellaneous items.</para></section>
1660 <section><title>Transmission</title></section>
1661 <para>Transmissions is a cross platform bittorrent client with several different interfaces. These include command line, web server, GTK, QT, and remote. It is a modern feature rich services like encryption, a web interface, peer exchange, magnet links, DHT, µTP, UPnP and NAT-PMP port forwarding, web-seed support, watch directories, tracker editing, global and per-torrent speed limits, and more. It has a lower memory foot print than the other clients out there.</para>
1662 <section><title>Installation</title></section>
1663 <section><title>Configuration</title></section>
1664<screen>Configuring Firefox to use Transmission for Magnet links in GNOME:
1665 gconftool-2 -t string -s /desktop/gnome/url-handlers/magnet/command "/usr/bin/transmission '%s'"
1666 gconftool-2 -t bool -s /desktop/gnome/url-handlers/magnet/needs_terminal false
1667 gconftool-2 -t bool -s /desktop/gnome/url-handlers/magnet/enabled true
1668<![CDATA[
1669 When you start Transmission's GTK+ client version 1.80 or newer, it will make these three calls for you if you don't already have a magnet handler set up.
1670 Configuring Firefox to use Transmission-Daemon for Magnet links:
1671
1672 Create a shell script /usr/local/bin/magnet containing:
1673
1674 #!/bin/sh
1675 /usr/bin/transmission-remote --add "$1"
1676
1677 chmod +x /usr/local/bin/magnet
1678
1679 In Firefox go to about:config
1680
1681 Right-click on any link and select "New->String".
1682
1683 String name: network.protocol-handler.app.magnet
1684 String value: /usr/local/bin/magnet
1685
1686 Right-click on any link and select "New->Boolean"
1687
1688 Enter name: network.protocol-handler.handler.external.magnet
1689 Enter value: true
1690
1691 Restart Firefox
1692]]>
1693 <para>secondary possible solution</para>
1694 Firefox
1695 about:config
1696 enter handler.expose
1697 Right click - New - Boolean
1698 Enter the preference name network.protocol-handler.expose.magnet
1699 Set its value to false
1700 Click on the magnet link and you should see Firefox’s Launch Application Choose Dialog
1701 Select your torrent client.
1702 </screen>
1703 <section><title>Administration</title></section>
1704 <section><title>Flexget</title>
1705 <para>FlexGet is a multipurpose automation tool for content like torrents, nzbs, podcasts, comics, series, movies, etc. It can use different kinds of sources like RSS-feeds, html pages, csv files, search engines and there are even plug-ins for sites that do not provide any kind of useful feeds.</para>
1706 <para>There are numerous plug-ins that allow utilizing FlexGet in interesting ways and more are being added continuously.
1707 FlexGet is extremely useful in conjunction with applications which have watch directory support or provide interface for external utilities like FlexGet.</para></section>
1708 <section><title>Installation</title></section>
1709 <![CDATA[
1710 if you get this error you need to the install below
1711 Traceback (most recent call last):
1712 File "/usr/local/bin/flexget", line 5, in <module>
1713 from pkg_resources import load_entry_point
1714 File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 2876, in <module>
1715 working_set = WorkingSet._build_master()
1716 File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 451, in _build_master
1717 return cls._build_from_requirements(__requires__)
1718 File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 464, in _build_from_requirements
1719 dists = ws.resolve(reqs, Environment())
1720 File "/usr/lib/python2.7/dist-packages/pkg_resources.py", line 644, in resolve
1721 raise VersionConflict(dist, req)
1722 pkg_resources.VersionConflict: (six 1.8.0 (/usr/lib/python2.7/dist-packages), Requirement.parse('six>=1.9.0'))
1723 Transmissionrpc module version 0.11 or higher required.]]>
1724 <para>same with this error upgrade below
1725 this is how i had to install flexget this time, special python2.x in a special dir..</para>
1726 <screen>
1727 aptitude install virtualenv
1728 aptitude install python-transmissionrpc
1729 virtualenv -p python2.7 /usr/local/etc/pip/
1730 #how to install apps
1731 /usr/local/etc/pip/bin/pip install flexget
1732 /usr/local/etc/pip/bin/pip install python-transmissionrpc --upgrade
1733 /usr/local/etc/pip/bin/pip install transmissionrpc --upgrade
1734 /usr/local/etc/pip/bin/pip install six --upgrade
1735 </screen>
1736 <section><title>Configuration</title></section>
1737 <section><title>Administration</title></section>
1738
1739 <section><title>Tahoe-lafs</title>
1740 <section><title>Installation</title></section>
1741 <section><title>Configuration</title></section>
1742 <section><title>Administration</title></section>
1743 </section>
1744<section><title>Rundeck</title>
1745 <para>
1746 dpkg -i /media/private/rundeck-2.3.2-1-GA.deb
1747 aptitude install java7-runtime-headless
1748 mkdir /var/rundeck/projects/thrace.lan/etc/
1749 cp /media/private/resources.xml /var/rundeck/projects/thrace.lan/etc/resources.xml
1750 cp /media/private/rundeck/ /etc/ -R
1751 adduser rundeck
1752 addgroup rundeck
1753 chown rundeck /var/rundeck/ -R
1754 cp /media/private/erin/Repository/keys/rundeck /var/lib/rundeck/.ssh/id_rs
1755 chown rundeck /var/lib/rundeck/.ssh -R
1756 service rundeckd restart
1757 </para>
1758</section>
1759<section><title>Puppet</title>
1760 <para> Puppet is a centralized configuration management server. it serves the configuration, package name, and files to many different servers. It uses a ruby like syntax to create multiple files for multiples of servers, that can be identical or unique in some areas. It works with many different distributions of linux and windows!</para>
1761
1762 <para>Puppet includes a basic puppet master web server based on Ruby's WEBrick library. (This is what Puppet uses if you run puppet master on the command line or use most puppetmaster init scripts.)
1763 You cannot use this default server for real-life loads, as it can’t handle concurrent connections; it is only suitable for small tests with ten nodes or fewer. You must configure a production quality web server before you start managing your nodes with Puppet.
1764
1765 Any Rack-based application server stack will work with a puppet master, but if you don’t have any particular preference, you should use Passenger combined with Apache. This guide shows how to configure Puppet with this software.
1766 </para>
1767 <section><title>What is Passenger?</title>
1768 <para>Passenger (AKA mod_rails or mod_rack) is an Apache 2.x module which lets you run Rails or Rack applications inside a general purpose web server,
1769 like Apache httpd or nginx.
1770 </para></section>
1771 <section><title>Relevant Pages in the Passenger Docs</title>
1772 <para>The Apache version of the Passenger user’s guide covers the Passenger-specific configuration directives we use below in much greater detail.</para></section>
1773 <section><title>Install Apache and Passenger</title>
1774 <para>Make sure puppet master has been run at least once (or puppet agent, if this master is not the CA), so that all required SSL certificates are in place.</para>
1775 <section><title>Install Apache 2</title>
1776 <subtitle>Debian/Ubuntu:</subtitle>
1777 <screen>
1778 $ sudo apt-get install apache2 ruby1.8-dev rubygems
1779 $ sudo a2enmod ssl
1780 $ sudo a2enmod headers
1781 </screen>
1782 </section>
1783
1784 <section><title>RedHat/Centos</title>
1785 <screen>
1786 RHEL/CentOS (needs the Puppet Labs repository enabled, or the EPEL repository):
1787 $sudo yum install httpd httpd-devel mod_ssl ruby-devel rubygems gcc
1788 </screen></section>
1789 <section>
1790 <title>Install Rack/Passenger</title>
1791 <screen>
1792$ sudo gem install rack passenger
1793$ sudo passenger-install-apache2-module
1794 </screen>
1795 </section>
1796<section><title>Configure Apache</title>
1797<para>
1798 To configure Apache to run the puppet master application, you must:
1799
1800 <screen>Install the puppet master Rack application, by creating a directory for it and copying the config.ru file from the Puppet source.
1801 Create a virtual host config file for the puppet master application, and install/enable it. </screen>
1802</para>
1803 <para>Global Configuration
1804 Keepalive Timeout</para>
1805<para>
1806 Make sure Apache’s KeepAliveTimeout setting is set to at least 5. (5 is the default value, but your global Apache config may have set a different value, in which case you'll need to change it.)
1807
1808 Although this setting is valid at virtual host scope, the way Apache reads its value means it's safer to set it globally.
1809 Install the Puppet Master Rack Application
1810
1811 Your copy of Puppet includes a config.ru file, which tells Rack how to spawn puppet master processes. To install this Rack application in a form Passenger can use, you'll need to:
1812
1813 Create three directories for the application (a parent directory, a public directory, and a tmp directory)
1814 Copy the ext/rack/config.ru file from the Puppet source code into the parent directory
1815 Set the ownership of the config.ru file
1816</para>
1817 <screen>Note: The chown step is important asthe owner of this file is the user the puppet master process will run under. This should usually be puppet, but may be different in your deployment.</screen>
1818 <screen>Also, make sure the Apache user (which may vary by platform) can both read and traverse all three directories, can traverse all of its parent directories, and can write to the tmp directory.</screen>
1819 <programlisting>
1820 These steps will look something like this:
1821
1822$ sudo mkdir -p /usr/share/puppet/rack/puppetmasterd
1823$ sudo mkdir /usr/share/puppet/rack/puppetmasterd/public /usr/share/puppet/rack/puppetmasterd/tmp
1824$ sudo cp /usr/share/puppet/ext/rack/config.ru /usr/share/puppet/rack/puppetmasterd/
1825$ sudo chown puppet:puppet /usr/share/puppet/rack/puppetmasterd/config.ru
1826 </programlisting>
1827<para>
1828The location of the Puppet source will vary by OS, and the packages you installed with might have excluded the files from ext/. If so, you can download the config.ru file directly from GitHub.
1829Create and Enable the Puppet Master Vhost</para>
1830<para>See a example Vhost Configuration a below for the contents of this vhost file. Note that the vhost’s DocumentRoot directive refers to the Rack application directory you created above.</para>
1831<screen>
1832Debian/Ubuntu:
1833
1834See “Example Vhost Configuration†below for the contents of the puppetmaster file
1835
1836
1837$ sudo cp puppetmaster /etc/apache2/sites-available/
1838$ sudo a2ensite puppetmaster
1839
1840
1841RHEL/CentOS:
1842
1843See a Example Vhost Configuration below for the contents of the puppetmaster.conf file.
1844
1845
1846$ sudo cp puppetmaster.conf /etc/httpd/conf.d/
1847</screen>
1848<screen>
1849Example Vhost Configuration
1850
1851This Apache Virtual Host configures the puppet master on the default puppetmaster port (8140). You can also see a similar file at ext/rack/example-passenger-vhost.conf in the Puppet source.
1852
1853# You'll need to adjust the paths in the Passenger config depending on which OS
1854# you're using, as well as the installed version of Passenger.
1855I am not sure you have to do this anymore module is already loaded.
1856# Debian/Ubuntu:
1857#LoadModule passenger_module /var/lib/gems/1.8/gems/passenger-4.0.x/ext/apache2/mod_passenger.so
1858#PassengerRoot /var/lib/gems/1.8/gems/passenger-4.0.x
1859#PassengerRuby /usr/bin/ruby1.8
1860
1861# RHEL/CentOS:
1862#LoadModule passenger_module /usr/lib/ruby/gems/1.8/gems/passenger-4.0.x/ext/apache2/mod_passenger.so
1863#PassengerRoot /usr/lib/ruby/gems/1.8/gems/passenger-4.0.x
1864#PassengerRuby /usr/bin/ruby
1865
1866# And the passenger performance tuning settings:
1867# Set this to about 1.5 times the number of CPU cores in your master:
1868PassengerMaxPoolSize 12
1869# Recycle master processes after they service 1000 requests
1870PassengerMaxRequests 1000
1871# Stop processes if they sit idle for 10 minutes
1872PassengerPoolIdleTime 600
1873</screen>
1874<screen>
1875Listen 8140
1876 <![CDATA[
1877<VirtualHost *:8140>
1878 # Make Apache hand off HTTP requests to Puppet earlier, at the cost of
1879 # interfering with mod_proxy, mod_rewrite, etc. See note below.
1880 PassengerHighPerformance On
1881
1882 SSLEngine On
1883
1884 # Only allow high security cryptography. Alter if needed for compatibility.
1885 SSLProtocol ALL -SSLv2 -SSLv3
1886 SSLCipherSuite EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!IDEA:!ECDSA:kEDH:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA
1887 SSLHonorCipherOrder on
1888
1889 SSLCertificateFile /var/lib/puppet/ssl/certs/puppet-server.example.com.pem
1890 SSLCertificateKeyFile /var/lib/puppet/ssl/private_keys/puppet-server.example.pem
1891 SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem
1892 SSLCACertificateFile /var/lib/puppet/ssl/ca/ca_crt.pem
1893 SSLCARevocationFile /var/lib/puppet/ssl/ca/ca_crl.pem
1894 SSLCARevocationCheck chain
1895 SSLVerifyClient optional
1896 SSLVerifyDepth 1
1897 SSLOptions +StdEnvVars +ExportCertData
1898
1899 # Apache 2.4 introduces the SSLCARevocationCheck directive and sets it to none
1900 # which effectively disables CRL checking. If you are using Apache 2.4+ you must
1901 # specify 'SSLCARevocationCheck chain' to actually use the CRL.
1902
1903 # These request headers are used to pass the client certificate
1904 # authentication information on to the puppet master process
1905 RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
1906 RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
1907 RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
1908
1909 DocumentRoot /usr/share/puppet/rack/puppetmasterd/public
1910
1911 <Directory /usr/share/puppet/rack/puppetmasterd/>
1912 Options None
1913 AllowOverride None
1914 # Apply the right behavior depending on Apache version.
1915 <IfVersion < 2.4>
1916 Order allow,deny
1917 Allow from all
1918 </IfVersion>
1919 <IfVersion >= 2.4>
1920 Require all granted
1921 </IfVersion>
1922 </Directory>
1923
1924 ErrorLog /var/log/httpd/puppet-server.example.com_ssl_error.log
1925 CustomLog /var/log/httpd/puppet-server.example.com_ssl_access.log combined
1926</VirtualHost>
1927]]></screen>
1928<para>If this puppet master is not the certificate authority, you will need to use different paths to the CA certificate and CRL:</para>
1929<screen>
1930SSLCertificateChainFile /var/lib/puppet/ssl/certs/ca.pem
1931SSLCACertificateFile /var/lib/puppet/ssl/certs/ca.pem
1932SSLCARevocationFile /var/lib/puppet/ssl/crl.pem
1933</screen>
1934<para>For additional details about enabling and configuring Passenger, see the Passenger install guide and the Apache version of the Passenger user’s guide.</para>
1935</section>
1936<section><title>Notes on PassengerHighPerformance</title>
1937<para>
1938 The example vhost config above sets PassengerHighPerformance On. This setting basically allows Passenger to shortcut some of Apache’s normal layers of request handling, so the Puppet application can respond earlier. Unfortunately, it can also interfere with other Apache modules, including important ones like mod_proxy, mod_rewrite, and mod_authz_core.
1939
1940 In the example, we’ve limited its effect by setting PassengerHighPerformance at the vhost scope, so it won’t interfere with any non-Puppet requests the Apache process is handling. You can also enable or disable it in a <![CDATA[<Location>]]> directive, which may be necessary if you’re proxying traffic to the Puppet CA in a multi-master setup.</para>
1941
1942 <section><title>Notes on DocumentRoot and PassengerAppRoot</title>
1943 <para>Passenger usually uses Apache’s DocumentRoot directive to guess where to find its config.ru file — it assumes config.ru will be right beside the public directory.
1944 This generally works fine, but some users have seen Passenger fail to guess.
1945 If Passenger fails to load the puppet master app and is displaying a generic error message, our first suggestion is to double-check the directory permissions
1946 (remember the Apache user must be able to read and traverse all puppet master application directories),
1947 but you can also try explicitly telling Passenger where to find the config.ru file with the PassengerAppRoot directive:</para>
1948 <screen>PassengerAppRoot /usr/share/puppet/rack/puppetmasterd</screen></section>
1949
1950 <section><title>Notes on SSL Verification</title>
1951 <para>
1952 When an agent node makes a request to the puppet master, Apache’s mod_ssl performs the verification of its certificate, and the puppet master application will trust mod_ssl’s judgment.
1953 The two systems communicate via environment variables — Apache must set two variables containing the client’s subject DN and its verification status,
1954 and the puppet master must know which variables to check when it receives a request.</para>
1955
1956 <para>Puppet uses the ssl_client_header and ssl_client_verify_header settings to find these variables;
1957 the default values are HTTP_X_CLIENT_DN and HTTP_X_CLIENT_VERIFY, respectively.In our example vhost config above,
1958 Apache uses the SSLOptions +StdEnvVars directive to make several SSL-related environment variables available;
1959 a full list of these variables is available here.
1960 It then uses these variables to construct several RequestHeader set directives,
1961 which put the information into the X-Client-DN and X-Client-Verify HTTP headers.
1962 The common gateway interface (CGI) standard converts all HTTP headers to environment variables and munges their names (an HTTP_ prefix is added,
1963 ashes are converted to underscores, and all letters are uppercased),
1964 and Puppet uses these environment variables, which have become the
1965 default names we mentioned above (HTTP_X_CLIENT_DN and HTTP_X_CLIENT_VERIFY).</para>
1966
1967 <para>Alternately, you could leave off the RequestHeader directives and use the SSL_CLIENT_S_DN and SSL_CLIENT_VERIFY variables directly,
1968 but this is a less standard way to do it, is tied specifically to Apache and mod_ssl, and requires changing your puppet.conf.</para></section>
1969
1970<section><title>Start or Restart the Apache service</title>
1971<screen>
1972Ensure that any WEBrick puppet master process is stopped before starting the Apache service; only one can be bound to TCP port 8140.
1973
1974Debian/Ubuntu:
1975
1976$ sudo /etc/init.d/apache2 restart
1977
1978RHEL/CentOS:
1979
1980$ sudo /etc/init.d/httpd restart
1981
1982If all works well, you’ll want to make sure the WEBrick service no longer starts on boot:
1983
1984Debian/Ubuntu:
1985
1986$ sudo update-rc.d -f puppetmaster remove
1987
1988RHEL/CentOS:
1989
1990$ sudo chkconfig puppetmaster off
1991$ sudo chkconfig httpd on
1992</screen>
1993 </section>
1994 </section>
1995 </section>
1996</section>
1997 <section><title>SSMTP</title>
1998 <para>SSMTP is a send only email emulator for sendmail. It does not receieve email. It is useful is you do not have access to a full service email server and wish to forwarded your emails off to another server.</para>
1999 <section><title>Installation</title></section>
2000<section><title>Configuration</title></section>
2001<section><title>Administration</title></section>
2002 </section>
2003
2004 <section><title>OpenSSH</title>
2005 <section><title>Installation</title></section>
2006<section><title>Configuration</title></section>
2007<section><title>Administration</title></section>
2008
2009 <section><title>Server</title><para/>
2010 </section>
2011
2012 <section><title>Client</title>
2013
2014 <section><title>Commands</title><screen>
2015 ssh -Y hostname
2016 ssh -X hostname</screen>
2017 </section>
2018 </section>
2019 </section>
2020
2021 <section><title>OpenVPN</title><para/>
2022 <section><title>Installation</title></section>
2023<section><title>Configuration</title></section>
2024<section><title>Administration</title></section>
2025 </section>
2026
2027 <section><title>Squidproxy</title><para/>
2028 <section><title>Installation</title></section>
2029<section><title>Configuration</title></section>
2030<section><title>Administration</title></section>
2031 </section>
2032
2033 <section><title>WebPages</title>
2034 <para><link xl:href="https://www.thrace.lan">Thrace.lan</link> and <link xl:href="https://erin.homelinux.org/">Thrace.lan</link> are the web urls for the THRACE.LAN webpages. They all use SSL encryption to protect the contents of the webpage and your credentials. They are indeed being written again and the keys will be signed by a global entity so that there is no longer any more errors when your browser goes to it. The webpage does contain links to the warez and other files on the network filesharing on the Xena server.</para>
2035
2036 <screen>here is how you make the ssl cert
2037 openssl req -new -key www.thrace-lan.info.key -out www.thrace-lan.info.csr
2038 openssl req -nodes -newkey rsa:2048 -sha1 -keyout www.thrace-lan.info.key -out www.thrace-lan.info.csr
2039 openssl x509 -req -days 365 -in www.thrace-lan.info.csr -signkey www.thrace-lan.info.key -out www.thrace-lan.info.crt
2040 service apache2 restart
2041 </screen>
2042<section><title>Plexmedia server install/setup</title>
2043<para>
2044
2045Plex Media Server Repo for Debian
2046
2047Hi.
2048We have decided to lock the other Debian thread and start a new one so I can edit the first post since Origin is no longer and has not been maintaing this package for a while.
2049
2050All credits goes to Tobias and the other at Plex for PMS and the init script for Debian were made by Origin. I have just taken all there work and efforts and repacked it for Debian since the ubuntu package is not compatible since the change to upstart.
2051
2052Down here is the instructions for installing PMS from my repo. This packages is for now compatible with Debian Squeeze , Wheezy and OpenMediaVault 0.3 , 0.4
2053
2054First Time install
2055
2056sudo apt-get install curl
2057echo "deb http://shell.ninthgate.se/packages/debian squeeze main" | sudo tee -a /etc/apt/sources.list.d/plexmediaserver.list
2058sudo curl http://shell.ninthgate.se/packages/shell-ninthgate-se-keyring.key | sudo apt-key add -
2059sudo apt-get update
2060sudo apt-get install plexmediaserver
2061
2062
2063
2064Upgrading
2065
2066sudo apt-get update
2067sudo apt-get upgrade
2068
2069
2070
2071
2072The init script Original by Origin with a minor modification by me
2073 <![CDATA[
2074#!/bin/sh
2075### BEGIN INIT INFO
2076# Provides: plexmediaserver
2077# Required-Start: $remote_fs $syslog $networking
2078# Required-Stop:
2079# Default-Start: 2 3 4 5
2080# Default-Stop: 0 1 6
2081# Short-Description: Plex Media Server
2082# Description: Plex Media Server for Linux,
2083# More information at http://www.plexapp.com
2084# Many thanks to the great PlexApp team for their wonderfull job !
2085# Author: Cedric Quillevere / origin@killy.net
2086# Rewamped Christian Svedin / christian.svedin@gmail.com
2087# Version: 1.2
2088### END INIT INFO
2089
2090# Read configuration variable file if it is present
2091[ -r /etc/default/plexmediaserver ] && . /etc/default/plexmediaserver
2092
2093test -f "/usr/lib/plexmediaserver/start.sh" || exit 0
2094
2095plex_running=`ps ax | grep "\./Plex Media Server" | awk '{ print $1 }' | wc -l`
2096
2097case "$1" in
2098 start)
2099 if [ "$plex_running" -gt 1 ]; then
2100 echo "Plex already running..."
2101 exit 0
2102 fi
2103 echo -n "Starting Plex Media Server: "
2104 su -l $PLEX_MEDIA_SERVER_USER -c "/usr/sbin/start_pms &" >/dev/null 2>&1
2105 sleep 1
2106 echo "done"
2107 ;;
2108 stop)
2109 if [ "$plex_running" -eq 1 ]; then
2110 echo "Plex Media Server is not running (no process found)..."
2111 exit 0
2112 fi
2113 echo -n "Killing Plex Media Server: "
2114 # Trying to kill the Plex Media Server itself but also the Plug-ins
2115 ps ax | grep "Plex Media Server" | awk '{ print $1 }' | xargs kill -9 >/dev/null 2>&1
2116 ps ax | grep "Plex DLNA Server" | awk '{ print $1 }' | xargs kill -9 >/dev/null 2>&1
2117 sleep 1
2118 echo "done"
2119 ;;
2120 restart)
2121 sh $0 stop
2122 sh $0 start
2123 ;;
2124 status)
2125 if [ "$plex_running" -gt 1 ]; then
2126 echo "Plex Media Server process running."
2127 else
2128 echo "It seems that Plex Media Server isn't running (no process found)."
2129 fi
2130 ;;
2131 *)
2132 echo "Usage: $0 {start|stop|restart|status}"
2133 exit 1
2134 ;;
2135esac
2136
2137exit 0
2138]]>
2139</para>
2140
2141</section>
2142
2143
2144
2145 <section><title>Apache</title>
2146 <para> Apache is the webserver utilized by the THRACE.LAN network. It is located on the backup services server and the eve server. This webpage will contain the second most up to date documentation on the network besides the git repositiory. It serves the contents of /var/www for the webpages and the contents of /usr/share/nagios3/htdocs for the nagios 3 webpage files. The configs are located in the /etc/apache2 directory and /etc/nagios3. They are managed through puppet and the git repository on the gabrielle. You must make changes in puppt not on the eve or services server!</para>
2147 <section><title>Installation</title></section>
2148<section><title>Configuration</title></section>
2149<section><title>Administration</title></section>
2150 </section>
2151
2152 <section><title>Nagios</title>
2153 <para>Nagios is an active, and passive monitoring service. It can manage filesystems, services, hosts, SNMP and many other things as well. It is fully customizable from the bottom up. This service is located on the eve server and is managed by git & puppet on gabrielle. you can access from <link xl:href="https://erin.homelinux.org/nagios3">Thrace.lan </link> or <link xl:href="https://www.thrace.lan/nagios3"> Thrace.lan</link> from you browser.</para>
2154 <section><title>Installation</title></section>
2155<section><title>Configuration</title></section>
2156<section><title>Administration</title></section>
2157 <section><title>Nagios Graph</title>
2158 <para>This is an addon for Nagios monitoring server for graphing and meteric collection/display. </para>
2159 <section><title>Installation</title></section>
2160<section><title>Configuration</title></section>
2161<section><title>Administration</title></section>
2162 </section>
2163 </section>
2164 <section><title>Zabbix</title><para/>
2165 <section><title>Installation</title></section>
2166<section><title>Configuration</title></section>
2167<section><title>Administration</title></section>
2168 </section>
2169
2170 <section><title>Webmin</title>
2171 <para> Webmin is a web-based system configuration tool for Unix-like systems, although recent versions can also be installed and run on Windows. With it, it is possible to configure operating system internals, such as users, disk quotas, services or configuration files, as well as modify and control open source apps, such as the Apache HTTP Server, PHP or MySQL. This has been discontinued and is no longer used on THRACE.lan.</para>
2172 <section><title>Installation</title></section>
2173<section><title>Configuration</title></section>
2174<section><title>Administration</title></section></section>
2175 </section>
2176
2177 <section><title>Mysql</title>
2178 <para>This is the database used for THRACE.LAN. The Mysql server is located on the Xena server and is used to house the data for xbmc currently. </para>
2179 <para>In order to backup and restore the phpmyadmin mysql servers, i had to backup the databases, and redo the users from the privilages section of each newly importated db. there is also some stuff on the cli we neeed to document justin knows, setting up security prefs,</para>
2180 <section><title>Installation</title></section>
2181<section><title>Configuration</title></section>
2182make sure the grant privilages is set on the userss, make sure you give them permission for global basic stuff for ttrss, and for the local tables, scuttle is ok with just table no global, copy over the config file for phpmyadmin to /etc/apache2/conf.d/ if you want it to get picked up by apache
2183<section><title>Administration</title></section>
2184</section>
2185
2186<section><title>Octopussy log manager</title>
2187
2188<title>Octopussy Installation</title>
2189<![CDATA[
2190Please make sure that SELinux, AppArmor, or other security software like these are well configured in order to work with Octopussy and its software (Apache, MySQL, RSyslog, ...)
2191
2192(cf. Bug Report #3097479)
2193Debian/Ubuntu Installation
2194
2195(tested on Debian 5&6 and Ubuntu 10.04)
2196
2197Get the latest octopussy debian package here.
2198
2199Debian 6 WARNING: On Debian 6, for stupid reason (Debian Free Software Guidelines #6 violation), the package libmail-sender-perl is not in /main/ section anymore but in /non-free/ section. You had to insert these 2 lines in /etc/apt/sources.list file if you want to install Octopussy properly:
2200
2201deb http://ftp.fr.debian.org/debian/ squeeze non-free
2202deb-src http://ftp.fr.debian.org/debian/ squeeze non-free
2203
2204followed by an 'apt update':
2205
2206apt-get update
2207
2208Then install Octopussy:
2209
2210dpkg -i octopussy_<version>_all.deb
2211apt-get -f install
2212
2213Enable syslog reception from other hosts in /etc/rsyslog.conf:
2214
2215$ModLoad imuxsock # provides support for local system logging
2216$ModLoad imklog # provides kernel logging support (previously done by rklogd)
2217#$ModLoad immark # provides --MARK-- message capability
2218
2219# provides UDP syslog reception
2220$ModLoad imudp
2221$UDPServerRun 514
2222
2223# provides TCP syslog reception
2224$ModLoad imtcp
2225$InputTCPServerRun 514
2226
2227and then restart Rsyslog
2228
2229/etc/init.d/rsyslog restart
2230
2231Generate self-signed Certificate for Octopussy Web Server:
2232
2233openssl genrsa > /etc/octopussy/server.key
2234openssl req -new -x509 -nodes -sha1 -days 365 -key /etc/octopussy/server.key > /etc/octopussy/server.crt
2235
2236and then restart Octopussy webserver
2237
2238/etc/init.d/octopussy web-stop
2239/etc/init.d/octopussy web-start
2240]]>
2241</section>
2242
2243 <section><title>Raspberry Pi</title>
2244 <para> This is a future project to create a multi node Rasberry Pi rapid deployment test bed with grub2, busybox, networking, sshfs remote mounting or NFS if required, preseeds, puppet etc. this will require a server for dhcp and sshfs filesystem. In order to get other operating systems we are going to have to be able to boot them from the grub2 install i suspect.
2245 We are going to need at least 5 nodes to start with. The number should be odd since we want one to load-balance for when we create Apache load balancing clusters.</para>
2246 <section><title>Installation</title></section>
2247<section><title>Configuration</title></section>
2248<section><title>Administration</title></section>
2249 </section>
2250
2251 <section><title>mdadm-Raid</title><para/>
2252 <para>Just Don't Do IT</para>
2253 <section><title>Installation</title></section>
2254<section><title>Configuration</title></section>
2255<section><title>Administration</title></section>
2256 </section>
2257 <section><title>Docbook</title>
2258 <para> This document is located in the services git repository and can be cloned from there. The format of the documentation is to add a general picture of the subject and a paragraph of introduction. Then a step by step flow of each task with screen shot pictures. Each section will begin with a summary of the form and fuction of said application and then contain the installation, configuration and administrative tasks for each. </para>
2259
2260 <section><title>Installation of Docbook</title>
2261 <para>The docbook manual can be created by using the xsltproc command to create the docbook html file. the needed packages can be installed as follows
2262 <programlisting>aptitude install xsltproc docbook-xsl-ns docbook5-xml</programlisting></para></section>
2263 <section><title>Oxygen</title>
2264 <para>I wouldn't bother with anything else but Oxygen editor at this time. </para>
2265 </section>
2266 <section><title>Administration of Docbook</title>
2267 <para> Once you have a working Docbook xml file then you can create the outfile with the xlstproc from you xsl-ns files you installed earlier. This command will create a html file for you to view through a webbrowser. The .xsl files are located in /usr/share/xml/docbook/stylesheet/docbook-xsl-ns/. The fo/docbook.xsl creates the .fo file and the html/profile-docbook.xsl creates the html file</para>
2268 <programlisting>xsltproc -o server-manual.docbook.html html/profile-docbook.xsl server-manual.docbook.xml</programlisting>
2269 <para> This command create a .fo file to be used with the fop command following it.</para>
2270 <programlisting>xsltproc -xinclude -o mybook.fo docbook.xsl server-manual.docbook.xml</programlisting>
2271 <programlisting>fop mybook.fo -pdf mybook.pdf</programlisting>
2272 </section>
2273 </section>
2274
2275 <section><title>Desktop</title>
2276 <para>use the command to find what applications are connected to which display. dont forget to export DISPLAY=:2
2277 <programlisting>for file in <![CDATA[ /proc/[0-9]*; do grep -ao 'DISPLAY=[^[:cntrl:]]*' $file/environ 2>/dev/null && grep -ao '(.*)' $file/stat; done | sed 'N;s/\n/\t/' OR find /proc/[0-9]* -maxdepth 1 -name environ -type f | xargs cat | tr '\0' '\n' | \grep '^DISPLAY=' | sort -u ]]></programlisting></para>
2278 <section><title>Stumpwm Window Manager</title><para/>
2279 <section><title>Installation</title></section>
2280<section><title>Configuration</title></section>
2281<section><title>Administration</title></section>
2282 </section>
2283 <section><title>Xmonad Window Manager</title><para/>
2284 <section><title>Installation</title></section>
2285<section><title>Configuration</title></section>
2286<section><title>Administration</title></section>
2287 </section>
2288 <section><title>Netbook Configuration</title><para>
2289 <section><title>Installation</title></section>
2290<section><title>Configuration</title></section>
2291<section><title>Administration</title></section>
2292 </para>
2293 </section>
2294
2295 </section>
2296 <section><title>Git</title>
2297 <para> Git is a distributed revision control system that is utilized in THRACE.lan to control puppet, manage revisions to scripts, lists and other tools including this manual. Please perform a check-out of the latest version on services.thrace.lan.</para>
2298
2299 <section><title>Installation of Git</title>
2300 <para>to install the basic git tool use <programlisting> aptitude install git</programlisting>
2301 Then execute the <programlisting> git config --global user.name "Your Name" </programlisting> command to setup your basic identity in the git config.</para>
2302 </section>
2303
2304 <section><title>git init</title>
2305 <para> To begin create the basic files that you want to manage in the git repositority. Once that is done execute:<programlisting>git init</programlisting> command in the directory to initalize git.</para>
2306 </section>
2307
2308 <section><title>git add and git commit</title>
2309 <para> To add a file or directory to the git repository use: <programlisting> git add somefile</programlisting> this can also be done with a directory like <programlisting> git add some/directory/here/file.txt </programlisting> This is called staging, you can see that there are changes that need to be commited by using: <programlisting> git status</programlisting> command. Once this is complete you need to use the command: <programlisting> git commit -m "some info about the file" </programlisting> to add the file to the repository</para>
2310 </section>
2311
2312 <section><title> git status</title>
2313 <para> To see that status of the repository change to the directory of the repository and execute: <programlisting> git status</programlisting></para>
2314 </section>
2315
2316 <section><title>Git Aliases</title>
2317 <para> Git aliases allow you make short simple abbreviations for long complicated commands. The following is what i use it is just an example.</para>
2318 <programlisting>
2319 [alias]
2320 co = checkout
2321 ci = commit
2322 st = status
2323 br = branch
2324 go = git push --all --repo=origin --repo=tinylan
2325 hist = log --pretty=format:\"%h %ad | %s%d [%an]\" --graph --date=short
2326 type = cat-file -t
2327 dump = cat-file -p
2328 </programlisting>
2329 </section>
2330
2331 <section><title>Git Searching</title>
2332
2333 <section><title>Git reflog </title>
2334 <para>A Git reflog is a list of hashes, which represent where you have been during commits. Each time a branch is updated to point to a new reference, an entry is written in the reflog to say where you were. Since the branch is updated whenever you commit, the git reflog has a nice effect of storing your local developer’s history.</para>
2335 <programlisting>
2336 $git reflog
2337 b921a36 HEAD@{0}: pull origin: Fast-forward
2338 61a6fa8 HEAD@{1}: commit: work but still no background color for programlisting I am uncertain what i have to change in the xsl
2339 cfd2290 HEAD@{2}: pull origin-remote master: Fast-forward
2340 185742b HEAD@{3}: pull origin-remote master: Fast-forward
2341 </programlisting>
2342 </section>
2343 </section>
2344
2345 <section><title>Git Checkout</title>
2346 <para>This command allows you to checkout different versions of your branches of path of tree.
2347 <programlisting>git checkout SomeBranch</programlisting>
2348 This one one specifies that time frame of one month ago.
2349 <programlisting>git checkout -p @{1.month.ago}</programlisting></para>
2350 </section>
2351 </section>
2352
2353 <section><title>Gitolite-admin</title>
2354 <para> This service is located on the backup linux server services.thrace.lan. it is a fulling functioning git hosting service that works with git. Git can work with out this as a server, but it was just easier to use gitolite-admin to administer. It can also do lots of neat features like mirroring. Please see <link xl:href="https://www.gitolite.com">gitolite-admin</link> for futher documentation.</para>
2355
2356 <section><title>Installation</title>
2357 <para>To install gitolite-admin please use the following to clone the repository from the server, and install it to the server of your choice.<emphasis>This must be done on the gitolite-admin server!</emphasis></para>
2358 <programlisting>
2359 git clone git://github.com/sitaramc/gitolite
2360 gitolite/install -ln
2361 </programlisting>
2362 </section>
2363 <section><title>Configuration</title>
2364 <para>On the gitolite-server use the following command to add your key to the configuration. This should be the case sensative user name for the client user you connect to the server with. Such as erin, eryn, or root.</para>
2365 <programlisting>
2366 gitolite setup -pk your-name.pub
2367 </programlisting>
2368 <para>Now move to the workstation and run the following commands to clone the gitolite config .Replacing the host with the server name you have used.</para>
2369 <programlisting>
2370 git clone git@<emphasis>host</emphasis>:gitolite-admin.git
2371 </programlisting>
2372 </section>
2373 <section><title>Administration</title>
2374 <para>Now that the configuration is completed you can start using the tool.</para>
2375 <section><title>Adding Users</title>
2376 <para> On the client system enter the <command>~/gitolite-admin/keydir/</command> directory of the cloned repository and place your username.pub file into the directory. then execute a <command>git add user.pub</command> command. Commit and push the gitolite-admin repositiory to the gitolite-admin server.
2377 </para></section>
2378 <section><title>Adding Repositiories</title>
2379 <para>Move to the <command>~/gitolite-admin/conf/gitolite.conf</command> file opened in your favorite editor. Then configure the file in the following syntax. Save your changes and commit and push to the server. If you need help contact support.</para>
2380 <programlisting>
2381 @people = erin eryn me
2382 repo gitolite-admin
2383 RW+ = @people
2384 repo myrepo
2385 RW+ = @people
2386 </programlisting>
2387 <para>Now we can clone the new bare repositories into your current working directory and start adding files. Please see the git section for details.</para>
2388 <section><title>Removing Repositiories</title>
2389 <para>The configurations must be removed on the client server cloned directory, and then you must login to the gitolite server and remove the repositories from the <command>/home/git/directory</command>.</para>
2390 </section>
2391<section><title>Recovery and Reinstall</title>
2392 <screen>
2393 adduser git
2394 passwd git
2395 cd /home/git/
2396 cp *.pub /home/git/
2397 chmod 755 /home/git/*.pub
2398 login git
2399 mkdir -p ~/bin
2400 git clone git://github.com/sitaramc/gitolite
2401 gitolite/install -ln /home/git/bin
2402 gitolite setup -pk server-services.pub
2403 login root
2404 ?cp /media/private/erin/Repository/keys/server-services /media/downloads/
2405 ?chmod 755 /media/downloads/server-services
2406 rm /media/downloads/server-services
2407 /media/private/erin/Repository/keys/server-services.pub /home/git/
2408 add keys etc here likke above
2409 git clone --verbose git@git.thrace.lan:gitolite-admin
2410 add in backups from puppet repo here make sure you included tags
2411 git clone --verbose git@git.thrace.lan:puppet
2412 do the same for Repository and then push them up to server
2413 git clone --verbose git@git.thrace.lan:Repository
2414 </screen>
2415</section>
2416
2417
2418<section><title>Reinstall puppet Repository</title>
2419 <screen> mv /etc/puppet /etc/puppet-old
2420 cd /etc/puppet
2421 cp /root-old/.ssh/config /root/.ssh/
2422 cp /media/private/erin/Repository/keys/server-services /root/.ssh/
2423 git clone --verbose git@git.thrace.lan:puppet
2424 </screen>
2425</section>
2426 </section>
2427 </section>
2428 </section>
2429
2430 <section><title>Git-annex</title><para/>
2431 <section><title>Installation</title></section>
2432<section><title>Configuration</title></section>
2433<section><title>Administration</title></section>
2434
2435 </section>
2436
2437 <section><title>Git-flow</title><para/>
2438 <section><title>Installation</title></section>
2439<section><title>Configuration</title></section>
2440<section><title>Administration</title></section>
2441
2442 </section>
2443
2444 <section><title>LVM</title><para/>
2445 <section><title>Installation</title></section>
2446<section><title>Configuration</title></section>
2447<section><title>Administration</title></section>
2448 </section>
2449
2450 <section><title>ZFS</title><para/>
2451 <section><title>Installation</title></section>
2452use package on website
2453wget http://archive.zfsonlinux.org/debian/pool/main/z/zfsonlinux/zfsonlinux_2%7Ewheezy_all.deb
2454# dpkg -i zfsonlinux_2~wheezy_all.deb
2455# apt-get update
2456# apt-get install debian-zfs
2457 sudo zpool create test raidz sdd sde sdf sdg sdh sdi
2458 zpool create pool raidz1 /dev/sda /dev/sdb1 /dev/sdc /dev/sdd /dev/sde3 /dev/sdf
2459zfs create tank/test
2460# zfs list
2461NAME USED AVAIL REFER MOUNTPOINT
2462tank 175K 2.92G 43.4K /tank
2463tank/test 41.9K 2.92G 41.9K /tank/test
2464zfs create pool/COMPLETE
2465zfs create pool/BACKUP
2466zfs create pool/TV_SHOWS
2467zfs create pool/PRIVATE
2468zfs create pool/PUBLIC
2469zfs create pool/APPS
2470zfs create pool/MISC_VIDS
2471zfs create pool/MUSIC
2472zfs create pool/MISC
2473zfs create pool/MOVIES
2474zfs create pool/DOWNLOADS
2475zfs set mountpoint=/mnt/test tank/test
2476zfs rename tank/test3 tank/music
2477<section><title>Configuration</title></section>
2478do not let system fill up completly
2479zfs set reservation=5G tank/home/moore
2480zfs create pool/.reserve
2481zfs set reservation=5G pool/.reserve
2482you should setup on compression like this
2483zfs set compression=lz4 tank/log
2484zfs set compression=lz4 pool/APPS
2485zfs set compression=lz4 pool/BACKUP
2486zfs set compression=lz4 pool/COMPLETE
2487zfs set compression=lz4 pool/DOWNLOADS
2488zfs set compression=lz4 pool/MISC
2489zfs set compression=lz4 pool/MISC_VIDS
2490zfs set compression=lz4 pool/MOVIES
2491zfs set compression=lz4 pool/MUSIC
2492zfs set compression=lz4 pool/PRIVATE
2493zfs set compression=lz4 pool/PUBLIC
2494zfs set compression=lz4 pool/TV_SHOWS
2495zfs set compression=lz4 pool/TV_SHOWS
2496<section><title>Administration</title></section>
2497nice one liner to see all the zfs process a bunch is ok
2498ps axuwwwf | grep '\_ \[z' | wc -l
2499 </section>
2500
2501 <section><title>Grub Version 2</title>
2502 <section><title>Installation</title></section>
2503<section><title>Configuration</title></section>
2504<section><title>Administration</title></section>
2505
2506 <section><title>Configuring Grub V2</title>
2507
2508 <section><title>Raid</title><para/>
2509
2510 </section>
2511
2512 <section><title>LVM</title><para/>
2513
2514 </section>
2515 </section>
2516
2517 <section><title>Troubleshooting Grub V2</title>
2518
2519 <section><title>Raid</title><para/>
2520
2521 </section>
2522
2523 <section><title>LVM</title><para/>
2524
2525 </section>
2526 </section>
2527 <section><title>Recovering Grub</title>
2528 <para>Consult these webpage for further details <link xl:href="http://wiki.debian.org/ GrubRecover">GrubRecover </link>and<link xl:href="http://www.debian.org/releases/stable/i386/ch08s07.html">www.debian.org</link>. you may need to edit /etc/mtab or /boot/grub/device.mapas well.
2529 <programlisting>
2530 Boot a live cd and mount your disk read/write.
2531 mount boot partition into your / partition if applicable
2532 <filename> mount -o bind /dev/ /your/root/dev </filename>
2533 <filename> mount -o bind /usr/your/root/usr</filename>
2534 <filename> chroot /your/root </filename>
2535 <filename> mount -t proc none /proc </filename>
2536 <filename> grub -install /dev/foo </filename>
2537 </programlisting></para>
2538 </section>
2539 </section>
2540 <section><title>Cfg2html</title>
2541 <para> Cfg2html is a collection of scripts that create a html and plain text file with your package selection, configuration details, hardware, and chosen files. The current implementation on Thrace.Lan is invoked by a shell script that subsequently creates the file in /home/THRACE/erin/Documents/ with the date & time stamp at the end. This is then compress and saved for later. Also there is another script that takes the file and puts it on the Thrace.Lan webpage. The following commands are used to generate the file.</para>
2542 <section><title>Installation</title></section>
2543<section><title>Configuration</title></section>
2544<section><title>Administration</title></section>
2545 </section>
2546
2547 <section><title>Credentials</title>
2548 <para> To obtain credentials on THRACE.lan please see Erin Gibson or send an email to agibson684@gmail.com. you may also visit the <link xl:href="https://www.thrace.lan">Thrace.lan</link>or <link xl:href="https://erin.homelinux.org/">Thrace.lan</link> website to create a request to obtain them.
2549 </para></section>
2550
2551 <section><title>Requests</title>
2552 <para> Request can be made to <link xl:href="https://erin.homelinux.org/">Thrace.lan</link> or by send an email to <email>agibson684@gmail.com</email>.</para>
2553 </section>
2554
2555 <section><title>Commandline</title>
2556
2557 <section><title>Dtrx: Replacement for Tar and other compression tools</title><para/>
2558 <section><title>Installation</title></section>
2559<section><title>Configuration</title></section>
2560<section><title>Administration</title></section>
2561 </section>
2562
2563 <section><title>Rar: Commercial compression and archive tool</title><para/>
2564 <section><title>Installation</title></section>
2565<section><title>Configuration</title></section>
2566<section><title>Administration</title></section>
2567 </section>
2568
2569 <section><title>7Zip: Free compression and archive tool</title><para/>
2570 <section><title>Installation</title></section>
2571<section><title>Configuration</title></section>
2572<section><title>Administration</title></section>
2573 </section>
2574
2575 <section><title>Safe-RM</title><para/>
2576 <section><title>Installation</title></section>
2577<section><title>Configuration</title></section>
2578<section><title>Administration</title></section>
2579 </section>
2580
2581 </section>
2582
2583 <section><title>Scripts</title>
2584 <section><title>Backups</title>
2585 <para> Backups are ran by the shell script backup.day.sh, backup.week.sh, or backup.month.sh they create their backups of the content of <filename> /home, /etc, and /root. </filename> They are stored in the Tar Bzip2 compressed files in the CIFS share of <filename>/media/Backup/\$hostname/type/</filename> where type is <emphasis>daily, weekly, or monthly.</emphasis>
2586 They are ran via the root crontab for their specified duration. If the backups abort they create an email to the root account and it gets forwarded to <email>agibson684@gmail.com</email>.
2587 </para></section>
2588 </section>
2589
2590 <section><title>Aliases</title><para/>
2591 </section>
2592
2593 <section><title>Functions</title><para/>
2594 </section>
2595
2596 <section><title>Built-ins</title><para/>
2597 </section>
2598
2599 <section><title>Locations of Files and Documents</title>
2600 <para> Files and Documents are located in the <filename>/media/private/erin/Repository/, /media/files_misc,</filename> git repository on services.thrace.lan or through the web-page at <link xl:href="https://www.thrace.lan">https://www.thrace.lan</link>. As it stand right now most documents and small scripts are stored in the git repository and large binary documents are stored in the <filename>/media/private/erin/Repository</filename> or <filename>/media/files_misc/</filename>. There is also binary files that are in use in the <filename>~/home</filename> directories for /root and erin. The <filename>/media/private/Admin\-*</filename> directories are used as well. It is indeed a big mess.
2601 </para></section>
2602 <section><title>Various Linux Information</title>
2603<![CDATA[
2604 for f in *; do cp $f $f.html; done
2605 system top processes:ps -eo user,pcpu,pid,cmd | sort -r -k2 | head -6
2606
2607 cat /etc/passwd | sort | cut -d":" -f1
2608
2609 cat /etc/passwd | sort | gawk '$3 >= 500 {print $1 }' FS=":"
2610
2611 for f in *.php; do cp $f $f.bkp; done
2612 for f in *.php; do cp $f{,.bkp}; done
2613 tar cf - . | (cd /usr/backups/; tar xfp -)
2614
2615 tar cf - . | ssh smith@remote.server tar xfp - -C /usr/backup/smith
2616
2617 grep '@' incoming_email | gawk '{print $3}' | sort | uniq
2618
2619 ps -eo user,pcpu,pid,cmd | sort -n -r -k2 | head -6
2620
2621 gawk '/@/{print $3}' incoming_email | sort -u
2622
2623 awk '/@/ {print $3}' incoming_email | sort -u
2624
2625 gawk '$3 >= 500 {print $1 }' FS=":" /etc/passwd | sort"
2626
2627 cat mail_list | sort | uniq -c | sort -nr | head -n -5
2628
2629 find . -name '*.wav' -maxdepth 2 | while read FILE; do lame -b 32 "${FILE}" "$
2630 {FILE%.wav}.mp3"; done
2631
2632 alias findtar=' find ./ -name ' *.tar' '
2633 alias bigone=' du | sort -rn | more ']]>
2634
2635One other thing, cat | anything is almost always wrong. Most apps will let you do anything filename, or if that fails you can always use bash redirectionn anything <![CDATA[<]]> filename. Use cat for the intended purpose\; combining multiple input files into a single output.
2636
2637Watch out with the cp php <![CDATA[->]]> .php.bkp example; if you do this in a place where your web-server (with php-module enabled) can access it you could have a code leak! (.php will be interpreted and .bkp will serve the plain text contents of the file!)
2638A possible example; http://server/config.php.bkp would disclose sensitive data(a lot of php applications store their database credentials here, among otherthings...)
2639Also look out when using editors with a backup function; for example the joe editor leaves its backup files with a trailing ~, backup of config.php will be config.php~ causing the same effect.
2640
2641
2642The trick for showing the top 5 processes is pretty handy. Here are a few of my own in scripts I've written:
2643http://www.digitalprognosis.com/opensource/scripts/top-open-files
2644http://www.digitalprognosis.com/opensource/scripts/top-disk-users
2645These scripts might help someone else
2646
2647Sometimes you need uniqueness but also want to preserve order so sorting is out. In those cases you can use awk.
2648Arrays in awk can be indexed by strings. $0 is the entire line and $1, $2, etc.
2649are fields within the line.
2650So...
2651<![CDATA[awk '/@/ && !un[$3]++ {print $3}' incoming_email]]>
2652The ++ increments the element addressed by $3 and only elements numbered zero, the first, are printed. Of course you can print other fields or combinations of fields as well.
2653#
2654
2655If you ever find the need to erase sensitive data from a linux system try this:
2656<![CDATA[$ find -type f -execdir shred -fuzv -n7 '{}' \; rm -rf *]]>
2657Now note that you can leave off the end and erase the empty directories manually. Not trying to get anyone to erase their files!
2658
2659There is also debate on whether the shred command is even useful on journalizing filesystems since the metadata is still left behind. I'm not going
2660to argue this point since I usually use this when I am erasing old floppies I have lying around (yes, I still use them sometimes).
2661#
2662
2663What's the proper way to run a one-liner (with pipe or i/o-redirection) through sudo? normally sudo will only "extend" until the first pipe or re-direction
2664symbol and the rest of the command will often not have the proper permissions e.g. to write a file. Obviously, I want to avoid doing a 'su' first or login as root, which is trivial.
2665#
2666I don't know about "proper", but something like this would work:
2667<![CDATA[sudo bash -c "echo 'test' > ]]> test1.txt && echo 'test' <![CDATA[>]]> test2.txt
2668The -c parameter for bash takes a string and executes it. Since we've sudo'ed the bash, it has root permissions, and therefore, the commands listed in the quoted string will run with root permissions.
2669 </section>
2670</chapter>
2671</book>