· 11 years ago · Jul 30, 2015, 08:55 PM
1* RHSA :RHCSA:
2** Meta .
3Time Target: 80 Hours
4- Common links ::
5 [[File Folder Diagram]]
6
7RHEL Course website with videos:
8https://role.rhu.redhat.com
9lufimtse@redhat.com
10 / !1..
11
12student/student
13root/redhat << includes bootvm
14
15Exam prep list:
16http://www.redhat.com/en/services/training/ex200-red-hat-certified-system-administrator-rhcsa-exam
17
18*** Links to stuff
19**** Certification :noa:
20:PROPERTIES:
21:CREATED: <2015-04-01 Wed 10:55>
22:EXPIRY: <2020-04-01>
23:END:
24- Exam Certification preperation ::
25 https://mojo.redhat.com/docs/DOC-155671#jive_content_id_Red_Hat_Certified_Engineer__RHCE
26
27- Online Learning links ::
28 https://mojo.redhat.com/docs/DOC-176952
29
30- Red Hat Online Learning center ::
31 https://role.rhu.redhat.com/
32
33- Oracle learning center :: (courses are here)
34 https://rsaebs.corp.redhat.com/
35** Introduction
36:LOGBOOK:
37CLOCK: [2015-03-25 Wed 09:48]--[2015-03-25 Wed 09:49] => 0:01
38CLOCK: [2015-03-24 Tue 17:11]--[2015-03-24 Tue 17:23] => 0:12
39:END:
40*** Red Hat VM config RHEL
41**** Downloading Iso images (img sources)
42REHL 7 WS:
43http://download.devel.redhat.com/released/RHEL-7/7.0/Workstation/x86_64/iso/
44(but Server edditions are available.)
45
46REHL 6 WS:
47http://download.devel.redhat.com/released/RHEL-6/6.6/Workstation/x86_64/iso/
48
49http://download.devel.redhat.com/released/RHEL-7/7.0/Server/x86_64/iso/
50
51or mount vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive2
52
53**** Vm config
54 1) mkdir: /mnt/engarchive2
55 2) sudo edit : /etc/fstab and add:
56 vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive2 /mnt/engarchive2 nfs ro,soft,intr,bg,noatime,nodiratime 0 0
57
58 3) refresh mount:
59 sudo mount -a
60 now you can browse the mount with ls.
61
62 4) make dir: ~/images
63 4.2) copy desired images from mnt ~/iso
64
65 5) make script like: my-makevirtmachine_REHL6_6 and put inside:
66 #+BEGIN_SRC sh
67 #! /bin/bash
68 name=$1 #First agument names the VM
69 imgDir="/home/lufimtse/images" #note, this path should be absolute. ~/images wont work.
70 loc='/home/lufimtse/iso/RHEL-6.6-20140926.0-Workstation-x86_64-dvd1.iso'
71
72 if [ $# != 1 ]; then
73 echo "Usage : $0 [Image Name]"
74 exit 1
75 elif [ -e ${imgDir}/${name}.img ]; then
76 echo "Image already exists."
77 exit 1
78 fi
79
80 virt-install \
81 --connect="qemu:///system" \
82 --name="${name}" \
83 --disk path="${imgDir}/${name}.img",size=20 \
84 --ram=1500 \
85 --vcpu=4 \
86 --cdrom="${loc}" \
87 --network network=default
88 #+END_SRC
89
90 6) Edit the 'loc' variable of script to point to latest iso.
91
92 7) Make sure virt-manager and virt-install are installed.
93 sudo yum install virt-manager virt-install
94
95 8) Run script. It should fire up vms.
96**** Vm user/passwords (RHEL/Fedora)
97RHEL vms:
98lufimtse with usual !1.. password.
99
100Fedora vm:
101lufimtse with usual !1.. pass
102*** International Language Support
103**** Stuff
104- system :: export LANG=fr_FR.utf8
105- per app :: exprot LANG=fr_FR.utf8 date
106- Configure system wide :: localect1 set-locale LANG=fr_FR.utf8
107
108
109Mnemonic :: man localect1 > 'set-local' show info. can use list-locales param to list all langs
110/etc/locale.conf
111
112- List available Languages on Yum :: yum langavailable
113- List installed packages :: yum langlist
114
115- to install a package :: yum langinstall [code] //[code] = e.g [de] [ru] etc..
116**** Configure Colemak from command line
117- Configure colemak from cmd :: localectl set-keymap us-colemak
118
119**** Uni Code Input
120 ctrl+shift+u followed by unicode
121 e.g lambda = U+03bb
122 type combo + 03bb to get lambda.
123 //This doesn't work in all apps. But works in terminal and others.
124** DONE 1 Local/Remote Logins, Man Pages, Getting Help from Red Hat
125CLOSED: [2015-07-30 Thu 15:09]
126:LOGBOOK:
127- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
128CLOCK: [2015-03-26 Thu 11:13]--[2015-03-26 Thu 11:26] => 0:13
129CLOCK: [2015-03-26 Thu 09:52]--[2015-03-26 Thu 10:02] => 0:10
130CLOCK: [2015-03-25 Wed 10:34]--[2015-03-25 Wed 11:04] => 0:30
131CLOCK: [2015-03-25 Wed 09:49]--[2015-03-25 Wed 10:18] => 0:29
132CLOCK: [2015-03-27 Fri 09:32]--[2015-03-27 Fri 10:02] => 0:30
133CLOCK: [2015-03-26 Thu 11:26]--[2015-03-26 Thu 11:50] => 0:24
134:END:
135:PROPERTIES:
136:Effort: 2:00
137:END:
138*** Local Login, man pages
139**** Bash Shell basics
140***** '$' vs '#'
141$ - regular user
142'# - root
143
144Display means 'output'
145***** Terminologies
146Display (output sent to a ..) TERM__
147rc = runcom = run commands TERM__ [[http://unix.stackexchange.com/questions/3467/what-does-rc-in-bashrc-stand-for][src]]
148***** Exiting a shell
149Ctrl+D BKEY__
150exit BCMD__
151***** Environmental Variables (HOME PATH ...)
152:PROPERTIES:
153:ID: 66456bb5-8521-4270-8aaf-fec9b0febc61
154:END:
155$HOME - home directory. /home/mike
156$PATH - Colon seperated list of paths recognized by system. /path1:/path2
157**** Consoles
158Additional Consles:
159 RHEL runs on first console.
160 5 consoles are available.
161 Ctrl+Alt+F1 - Gui environment BKEY__
162 Ctrl+Alt+[F2..F6] Additional consoles BCMD__
163 /Note/ linux 5's gui ran on console 7.
164**** References
165man 1 intro
166man 1 bash
167man 4 console
168man 4 pts
169man 7 man-pages << man of man-pages.
170
171General convention:
172pts(4) == man 4 pts
173
174*** @ SSH login & operations
175**** Summary
176So you don't have to type password:
1771) ssh-keygen
1782) ssh-copy-id user@host
179**** SSH Key-based authentication
180***** SSH key based authentication :BCMD__:
181- SUMMARY ::
182 ssh-keygen //Make your key.
183 ssh-copy-id -i your.pdb <USER>@server.com
184
185- ABOUT ::
186 Login without having to use a password.
187- THEORY ::
188 'private-key' kept secure on your machine. Your password.
189 'public-key' copied to server . Does not have to be secret.
190- GENERATE KEY ::
191 ssh-keygen Location for generated key:
192 ~/.ssh/id_rsa Private Key (is kept local)
193 ~/.ssh/id_rsa.pub Public Key (is copied to server)
194- PASSPHASE ::
195 Makes it more secure, but need to type password.
196
197 Note:
198 If you want to use a passphase, but not type the password,
199 you can use
200 *ssh-agent*. You give your PASSPHASE once via 'ssh-add'
201
202 // Permission:
203 600 on private key
204 644 on public key
205
206- COPYING KEY TO SERVER ::
207 ssh-copy-id <USER>@serverXYZ
208 # this copies '~/.ssh/id_rsa.pub'
209 ssh-copy-id -i ~/.ssh/id_rsa.pub <USER>@server.y
210
211- ADDING KEY LOCALLY ::
212 ssh-add
213ssh-keygen
214ssh-copy-id
215***** References
216ssh-keygen(1)
217ssh-copy-id(1)
218ssh-agent(1)
219ssh-add(1)
220**** SSH Moving / Copying files in SSH via SCP BCMD__
221scp == secure copy
222
223scp user@host:/folder/file /localHome/
224Once in ssh, you cannot access local files.
225Instead, you need to open a 2nd terminal and
226use scp to move things around.
227http://www.hypexr.org/linux_scp_help.php
228**** SSH Server
229: sudo systemctl (enable|start) sshd
230*** Getting help from Red Hat
231**** Customer Portal
232***** My Username / password and Login Credentials (Customer portal)
233USER: lufimtse1@redhat.com *note the '1' in addr*
234PASS: !1..
235EMAIl: lufimtse@redhat.com
236
237***** Web sites/Links
238https://access.redhat.com
239https://access.redhat.com/help
240***** Support phone
241814 4931 (works from internal phone) PHONENUMBER__
242**** RH Support tool case management and kb search.
243For support case management and kb search.
244***** Running:
245redhat-support-tool //goes into interactive mode
246redhat-support-tool <COMMAND> //EXECUTE any command that could have been run in intr.mode.
247***** Configure
248- config file ::
249 ~/.redhat-support-tool/redhat-support-tool.conf
250 This is where the tool stores credentials also.
251
252- '--global' option stores credentials here ::
253 /etc/.redhat-support-tool/redhat-support-tool.conf
254
255***** kb, search and open by id
256- Keyword searching ::
257 search <STRRING>
258
259- open kb article by id
260 kb id
261
262 e.g from command line with less
263 redhat-support-tool kb 253273 | less
264***** Opening a new case
265- Command ::
266opencase
267
268- Flags ::
269You can run with flags:
270Specify: product, version, summary, description, severity,
271 opencase --product="Red Hat Enterprise Linux" --version="7.0"
272
273- Support case urgency ::
274 1 - urgent //business down
275 2 - high //functioning, but system is limited
276 3 - medium //workaround available
277 4 - low // feature requset / very low impact
278***** Gathering support data
279****** Things to gather (overview)
280~sosreport~ //Diagnostic report
281~kdump~ //kernal stack trace for kernal problems
282
283Screenshot/picture of the issue if kernal crashed.
284****** sosreport
2851. Login as root:
286 : su -
2872. Run report:
288 : sosreport
2893. It will run, ask you some questions, then produce something like:
290 /var/tmp/sosreport-lUfimtsev.123456-20150327094918.tar.xz
291***** Attaching files
292Attach a file to a case by case-ID:
293~addattachment -c 01034421 <path to sosreport>~
294***** meh
295** DONE 2 File system Navigation
296CLOSED: [2015-07-30 Thu 15:09]
297:LOGBOOK:
298- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
299CLOCK: [2015-04-01 Wed 09:23]--[2015-04-01 Wed 09:40] => 0:17
300CLOCK: [2015-03-31 Tue 10:16]--[2015-03-31 Tue 10:47] => 0:31
301CLOCK: [2015-03-31 Tue 09:41]--[2015-03-31 Tue 10:07] => 0:26
302CLOCK: [2015-03-30 Mon 10:38]--[2015-03-30 Mon 11:08] => 0:30
303CLOCK: [2015-03-30 Mon 09:47]--[2015-03-30 Mon 10:17] => 0:30
304CLOCK: [2015-03-27 Fri 10:11]--[2015-03-27 Fri 10:41] => 0:30
305:END:
306:PROPERTIES:
307:Effort: 3:00
308:END:
309*** The Linux File System Hierarchy
310**** System Hierarchy Diagram FILE__ FOLDER__ DIAGRAM__
311<<File Folder Diagram>>
312#+BEGIN_SRC dot :file ./img/img_2015_03_27__10_13_02.png :cmdline -Kdot -Tpng
313digraph {
314size="8.5";
315node [shape=folder width=.6 style=filled fillcolor=gold2]
316nodesep=.1
317
318slash [label="/"]
319
320subgraph layoutNodes {
321 node [shape=none, width=0, height=0, label=""]
322 edge [dir=none,style=invis] //ivisible edges
323 slash -> lvl0 -> lvl1 -> lvl2 ->lvl3
324}
325slash -> {rank=same; {bin;boot;dev;etc;home;root;run;sbin;tmp;usr;var}}
326
327ubin[label=bin]
328ulocal[label=local]
329usbin[label=sbin]
330utmp[label=tmp]
331
332vtmp[label=tmp]
333{rank=same; {vtmp;ubin;ulocal;usbin;utmp;lufimtse;lina;oksana;lvl1}}
334lufimtse,lina,oksana [fillcolor=yellow]
335home -> {lufimtse;lina;oksana}
336usr -> {ubin;ulocal;usbin;utmp}
337var -> vtmp
338
339bin -> ubin [style=dotted]
340sbin -> usbin [style=dotted]
341
342utmp -> vtmp [style=dotted]
343
344//Files
345subgraph files {
346 node [shape=record,fillcolor=lightblue]
347 sudoers, group , shadow
348 logindefs [label="login.defs"]
349 etc -> {rank=same; {sudoers;group;shadow;logindefs;passwd}}
350 {rank=same; {sudoers;group;shadow;logindefs;passwd;lvl2}}
351}
352
353//Executables
354subgraph execs {
355 node [shape=record, fillcolor=blue, fontcolor=white]
356 nologin [label="nologin\n (shell)"]
357 sbin -> nologin
358{rank=same; {nologin;lvl2}}
359}
360
361}
362#+END_SRC
363
364#+results:
365[[file:./img/img_2015_03_27__10_13_02.png]]
366
367**** Important Linux files
368:PROPERTIES:
369:ID: d98768f7-c32a-4b62-a2c3-65969999e449
370:END:
371These are tagged #FILE__ across the system.
372
373[[id:95ea3b79-47d7-41b6-899a-f3e5cea8055c][/etc/passwd and /etc/shadow]] - User's group/home dir/shell info and encryped password.
374[[id:5c05a2e1-5930-41be-9aac-00f8598f806c][/egc/group]] - Groups are defined here.
375[[id:0c85f259-0fc9-4ebc-bff2-2fe7688c0f80][/etc/sudoers]] - Admin rights are defined here.
376
377Other:
378[[id:310430c3-bea4-430f-a4cf-627a2f2e2c56][/etc/login.defs]] - defaults for useradd and addgroup commands.
379**** Special Linux files
380***** /dev/zero
381/dev/zero provides unlimited zero's. useful for storage init.
382***** /dev/null
383Place that can sink anything you give it. Useful for squelching outputt.
384**** About file system & terminology
385Sorted by type & purpose.
386e.g /boot for boot files.
387- Terminology ::
388 - staic :: Unchanged
389 - dynamic or varible :: changed by running process
390 - persistent :: config remain static after reboot
391 - runtime :: proc or sys content cleared during reboot.
392**** Common Linux Folders
393- /usr ::
394 Installed software, shared libraries, include files,
395 static read-only program data.
396 - /usr/bin :: /User Commands/
397 - /usr/sbin :: /System admin commands/
398 - /usr/local :: Locally customized software
399- /etc :: Configuration files specific to this system.
400- /var :: *Variable data* that should persist between reboots. (e.g Logs).
401- /run ::
402 *run time data* for procs started since last reboot.
403 Proc id's & lock files.
404 Content is re-created on reboot.
405 Consolidates /var/run and /var/lock from older REHL versions.
406- /home :: User's data & config
407- /root :: home dir for admin.
408- /tmp ::
409 Global writable for temp files.
410 Files *older* than 10 days are deleted automatically.
411 /var/tmp keeps files for 30 days that are not *modified*
412- /boot :: ...
413- /dev :: special /device files/ used by system to access hardware.
414
415Rehl 7 Note:
416In previous versions, the below were /distinct/ directories. Now
417the '/' dirs are sym linked to /usr/*
418/bin -> /usr/bin
419/sbin -> /usr/sbin
420/lib -> /usr/lib
421/lib64 -> /usr/lib64
422
423**** References
424hier (7) MAN__ File system hierarchy
425*** Managing Files Using Command-Line Tools
426**** Usage
427create, copy, link, move, remove files & subdirs.
428
429Reference : cp mv rm mkdir cp mv rm BCMD__
430
431| Activity | Single source | Multiple sources (note) |
432|-------------+-----------------+------------------------------------|
433| Copy file | cp file1 file2 | cp f1 f2 f3 dir (1) |
434| Move file | mv f1 f2 | mv f1 f2 f3 dir (1) |
435| Remove file | rm f1 | rm -f f1 f2 f3 dir (1) |
436| create dir | mkdir dir | mkdir -p part1/par2/dir (3) |
437| copy dir | cp -r dir1 dir2 | cp -r dir1 dir2 dir3 dirL (2) |
438| move dir | mv dir1 dir2 | mv dir1 dir2 dir3 dir4 (2) |
439| Remove dir | rm -r dir1 | rm -rf dir1 dir2 dir3 |
440| | | |
441|-------------+-----------------+------------------------------------|
442| Note | 1 | 'dir' has to be a folder |
443| | 2 | last arg must be a dir. |
444| | 3 | use '-p' wiht caution. (see below) |
445
446- mkdir ::
447 the '-p' auto generate missing folders. This can create undesired folders if
448 something is miss-typed. e.g you have ~/tmp/notes/ and you type:
449 : mkdir ~/tmp/note/uni/CSC309
450 It will not catch that 'note' was miss-spelled and will create a new folder 'note' for you
451
452 multiple creation:
453 : mkdir ~/tmp/CSC309 ~/tmp/CS369 ~/tmp/CSC410
454
455- cp ::
456 When copying multiple files to a directory:
457 : cp a b c dir
458 files retain their names and are just copied into that dir.
459
460- mv ::
461 On same file system, re-links. (quick)
462 Between file system, does a copy & delete. (takes longer).
463
464- rm ::
465 - Needs '-r' (recursive) for directories.
466 - There is no trash/bin notions in cmd.
467 - '-i' = interactive ~rm -ri meh~
468 ~rmdir~ only removes directories if they are empty.
469**** References
470cp(1)
471ln(1)
472mkdir(1)
473mv(1)
474rm(1)
475rmdir(1)
476*** ln : Making Links Between Files BCMD__ (1)
477**** Hard links Theory
478- Each file has 1 hard link by default.
479- POINT TO SAME FILE :: files have same permission/link count/user & group ownership/time stamp/file content.
480- Same file system ::
481 - Must be on the same file-system.
482 - After creation, no way to tell which is link is the original.
483- REMOVAL :: to remove a file, remove all it's hard links. LNOTE
484- List Reference Count ::
485 - ~ls -l~ can show how many references there are to the file. E.g.
486 : ls -l
487 : -rw-rw-r--. 3 lufimtse lufimtse 3 Mar 31 10:12 MultiReferencedFile
488 : ^ Number of references = 3.
489**** Soft Links Theory
490~ln -s~
491- A file :: file that points to another file.
492- To any file system :: Can point to a file that exists on another file system.
493- Dangling soft link ::
494 If you delete the file that the softlink points to, the softlinks remains as a ...
495- Directories OK :: Softlinks can point to directories.
496**** Ln syntax
497ln [OPTION]... [-T] TARGET LINK_NAME (1st form) //Target being what to link to.
498ln [OPTION]... TARGET (2nd form) //link created in curr folder.
499ln [OPTION]... TARGET... DIRECTORY (3rd form)
500ln [OPTION]... -t DIRECTORY TARGET... (4th form)
501[OPTIONS]
502 -s symbolic
503 -r make sym links relative.
504
505- Mnemonic ::
506<LiNk (chain)> to <TARGET>, and the name of the chain is:
507[[./img/img_2015_04_01__09_31_23.png]]
508[[shell:kolourpaint ./img/img_2015_04_01__09_31_23.png][edit img]]
509**** Ln examples
510- Examples of forms ::
511 1st: Example: make a '.emacs' link that points to 'mydotemacs.el'
512 : cd ~/
513 : ln -s ~/git/ldts/mydotemacs.el ~/.emacs
514
515 2nd: Example: Make a .emacs.d folder link in my working dir. (link name is same)
516 : cd ~/
517 : ln -s ~/git/ldts/.emacs.d
518
519 3rd: example, create links in current folder to all files in other-dir:
520 : ln -s ../other-dir/* ./
521
522 4th: same as 3rd, but other way around:
523 : ln -s -t ./ ../other-dir/*
524
525- Further Examples ::
526 - Link two directories ::
527 : ln -s [existing_folder] [name of new link]
528 e.g create a symbolic 'g' shortcut pointing to ~/git:
529 : cd ~/
530 : ln -s ~/git g
531
532**** References
533[[man:ln(1)]]
534** DONE 3 Users and Groups
535CLOSED: [2015-07-30 Thu 15:09]
536:LOGBOOK:
537- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
538- State "DONE" from "OPEN" [2015-07-14 Tue 13:38]
539- State "DONE" from "OPEN" [2015-05-25 Mon 10:39]
540CLOCK: [2015-05-25 Mon 10:06]--[2015-05-25 Mon 10:40] => 0:34
541CLOCK: [2015-05-25 Mon 09:28]--[2015-05-25 Mon 10:04] => 0:36
542CLOCK: [2015-04-21 Tue 09:26]--[2015-04-21 Tue 09:56] => 0:30
543CLOCK: [2015-04-14 Tue 10:15]--[2015-04-14 Tue 10:35] => 0:20
544CLOCK: [2015-04-14 Tue 09:57]--[2015-04-14 Tue 10:08] => 0:11
545CLOCK: [2015-04-14 Tue 09:14]--[2015-04-14 Tue 09:44] => 0:30
546CLOCK: [2015-04-13 Mon 10:09]--[2015-04-13 Mon 10:39] => 0:30
547CLOCK: [2015-04-13 Mon 09:33]--[2015-04-13 Mon 10:03] => 0:30
548CLOCK: [2015-04-10 Fri 09:55]--[2015-04-10 Fri 10:25] => 0:30
549CLOCK: [2015-04-09 Thu 10:24]--[2015-04-09 Thu 10:54] => 0:30
550CLOCK: [2015-04-09 Thu 09:28]--[2015-04-09 Thu 10:16] => 0:48
551CLOCK: [2015-04-08 Wed 11:06]--[2015-04-08 Wed 11:36] => 0:30
552CLOCK: [2015-04-08 Wed 09:38]--[2015-04-08 Wed 10:08] => 0:30
553CLOCK: [2015-04-07 Tue 10:30]--[2015-04-07 Tue 11:00] => 0:30
554CLOCK: [2015-04-07 Tue 09:53]--[2015-04-07 Tue 10:23] => 0:30
555CLOCK: [2015-04-06 Mon 11:28]--[2015-04-06 Mon 11:58] => 0:30
556CLOCK: [2015-04-06 Mon 10:39]--[2015-04-06 Mon 11:09] => 0:30
557CLOCK: [2015-04-06 Mon 10:01]--[2015-04-06 Mon 10:31] => 0:30
558CLOCK: [2015-04-02 Thu 10:00]--[2015-04-02 Thu 10:30] => 0:30
559CLOCK: [2015-04-02 Thu 09:24]--[2015-04-02 Thu 09:54] => 0:30
560CLOCK: [2015-04-01 Wed 10:02]--[2015-04-01 Wed 10:29] => 0:27
561CLOCK: [2015-04-01 Wed 09:40]--[2015-04-01 Wed 09:53] => 0:13
562:END:
563:PROPERTIES:
564:Effort: 4:00
565:END:
566*** Overview diagram
567#+BEGIN_SRC dot :file ./img/img_2015_04_21__09_34_28.png :cmdline -Kdot -Tpng
568digraph {
569size="9,5"
570ratio="compress"
571subgraph cmds {
572 node [shape=rect style=filled fillcolor=lightblue]
573 id
574 ps
575 su
576 sudash [label="su -"]
577 sudo
578 useradd
579 usermod
580 userdel
581 passwd
582
583 authconfig -> {authconfigtui [label="authconfig-tui"];
584 authconfiggtk[label="authconfig-gtk"]}
585}
586 Domain -> authconfig
587 Users -> {id ps su sudash sudo}
588 Users -> UserManagement [weight=3]
589 UserManagement -> {useradd usermod userdel passwd}
590}
591#+END_SRC
592
593#+results:
594[[file:./img/img_2015_04_21__09_34_28.png]]
595
596*** About
597- Manage users and groups.
598- Administer local password polocies.
599 (password aging policy..)
600- Centralized identity management.
601*** Users and Groups
602**** Theory
603- Every proccess runs under a certain user.
604- Proc has only access to user's files/dirs.
605**** Users
606:PROPERTIES:
607:ID: 95ea3b79-47d7-41b6-899a-f3e5cea8055c
608:END:
609***** Id Command :BCMD__:
610:PROPERTIES:
611:ID: a590fc9b-0ebf-43ae-ad66-e9aaf1233826
612:END:
613Displays info about current user.
614 man:id
615 : id #Print info of current user, inc UID
616 : id [USER] #Print info for USER
617***** Files belonging to user [[id:2b6fa67c-ec39-4f47-ade0-7cfd9b569e76][Long listing (ln -l)]] shows user info for file in 3rd column
618 : ls -l
619 : drwxrwxr-x. 4 lufimtse lufimtse 4096 Mar 31 14:12 bundles
620 : ^-- User info.
621***** Proccess belonging to user : ps au
622 see [[id:f3c38fc6-5b64-41ab-a79a-721647038df1][ps]]
623***** passwd file
624 Os stores UID in /etc/passwd, e.g: #FILE__
625 username: password : UID : GID : GECOS : home dir : shell
626 lufimtse: x :1000:1000:Leo Ufimtsev:/ home/lufimtse :/bin/bash
627
628 - Passwords now moved to /etc/shadow
629 - UID = User Id
630 - GID = Group ID
631 - GECOS = arbitrary text, usually includes user name.
632**** Group Info
633:PROPERTIES:
634:ID: 5c05a2e1-5930-41be-9aac-00f8598f806c
635:END:
636- Defined in: /etc/group #FILE__
637
638- Primary groups ::
639 - every user has one primary group.
640 - for users, p.g. defined in GID (above)
641 - normally, primary group owns file created by user.
642 - normally, primary group of newly created user is a newly created group with
643 same name as user. User is only member of that UPG (User private Group)
644- Supplementary Groups ::
645 - User can be in zero or more sup.groups.
646 - Users that are supplentary to a group, are listed in /etc/group at the end, e.g:
647 wheel:x:10:lufimtse
648 General syntax is:
649 : groupname:password:GID:(list of users in group)
650**** References
651man:id(1)
652man:passwd(5)
653man:group(5)
654man:info
655man:libc
656*** Managing Local User Accounts
657**** USERADD (create/add users) :BCMD__:
658:PROPERTIES:
659:ID: 310430c3-bea4-430f-a4cf-627a2f2e2c56
660:END:
661Note : this command is not listed with 'tab'. But exists.
662
663- Default ::
664 : useradd <UserName>
665 - Sets resonable defaults for all fields in /etc/passwd.
666 - No password by default.
667 - User cannot login till password is set.
668
669- Add user and join group ::
670 : sudo useradd -G <group> <username>
671- make su2
672
673- list help ::
674 : useradd --help
675**** default file for new users (/etc/login.defs)
676- Defaults read from ::
677 : /etc/login.defs #FILE__
678 Change in this file does not impact existing users.
679**** usermod (lock unlock user, move home dir) :BCMD__:
680See:
681: usermod --help
682man:usermod
683
684Commonly used:
685 -d, --home HOME_DIR change home dir
686 -m, --move-home move user home dir to new location. Used with-d.
687 -L, --lock
688 -U, --unlock
689
690
691 -p Change password. But use passwd instead as you can't see password there.
692e.g, change home-dir:
693: usermod -d /home/exampleusernew exampleuser
694
695See also: [[id:d78a482f-b6be-480c-ba64-3a8188bd376a][usermod (alters group membership)]]
696See also: [[nid:6df049e8-814e-421d-ad49-7764856d1004][Account locking]]
697See also: [[id:f3fef8ce-4e43-4e0b-985e-3b8ca86b7400][nologin shell]]
698**** userdel :BCMD__:
699:PROPERTIES:
700:ID: bd7f89b8-5c02-428d-857b-27b8f7b8b9ac
701:END:
702man:userdel
703- removes user from /etc/passwd, but leaves home dir ::
704 : userdel <username>
705- remove user + home dir ::
706 : userdel -r <username>
707
708(!) Warning:
709 ~userdel~ can leave behind 'unowned' files.
710 New users get assigned first available UID, which can be that of old user.
711 So new user could have access to files of old user. (Security issue).
712 Solutions:
713 - Delete all left overs, as root, find unowned files via:
714 : find / -nouser -o -nogroup 2> /dev/null.
715 - Manually assign new UID's: -u UID
716**** id
717See [[id:a590fc9b-0ebf-43ae-ad66-e9aaf1233826][Id command]]
718**** passwd (set & change password)
719Set initial password or change user's password:
720: passwd <username>
721Then password is prompetd on next line.
722Root can set any password. But has to re-type it.
723 :EG:
724 #+begin_src sh
725 [root@serverX ~]# passwd student
726 Changing password for user student.
727 New password: redhat123
728 BAD PASSWORD: The password fails the dictionary check - it is based on a dictionary
729 word
730 Retype new password: redhat123
731 #+end_src
732 :END:
733man:passwd
734**** UID ranges
735RHEL uses some UID's for special purposes.
736
737| UID | puropse |
738|---------+-------------------------------------------------------|
739| 0 | root |
740| 1-200 | system users, static asssigned |
741| 201-999 | system users, do not own files, assigned dynamically. |
742| 1000+ | regular users. |
743
744Note:
745- Prior to REHL 7, UID 1-499 was for system users, 500+ for regular users.
746- Default ranges can be changed in /etc/login.defs
747**** References
748man:useradd(8)
749man:usermod(8)
750man:userdel(8)
751*** Managing Local Group Acounts
752**** groupadd (creates group) :BCMD__:
753- Add group ::
754 : groupadd <groupname>
755 Uses next available GID from range specified in /etc/login.defs
756- Options ::
757 -g GID = custom GID
758 -r = system group. Mnemonic: '_Root group'
759:EG:
760: sudo groupadd -r appusers #System group.
761: sudo groupadd -g 5000 ateam
762:END:
763man:groupadd(8)
764**** groupmod (modifies existing groups) :BCMD__:
765Change group name to a GID mapping.
766
767Syntax:
768: groupmod [options] GROUP
769
770
771Options:
772- name '-n' ::
773: sudo groupmod -n javaapp appusers
774
775- GID with '-g' ::
776: sudo groupmod -g 6000 team
777man:groupmod(8)
778**** groupdel (deletes a group) :BCMD__:
779: sudo groupdel javaapp
780
781Note:
782 - One cannot delete a group if it's the primary group of an existing user.
783 - As with [[id:bd7f89b8-5c02-428d-857b-27b8f7b8b9ac][userdel]] one should remove any remaining files.
784**** usermod (alters group membership) :BCMD__:
785- Change user's primary group ::
786 usermod -g groupname
787 : sudo usermod -g newGroup user
788
789- Add user to supplementary group ::
790 : sudo usermod -aG wheel elvis
791
792(!) '-a' is append mode. Without it, user is 'moved' to another group.
793
794man:usermod(8)
795:PROPERTIES:
796:ID: d78a482f-b6be-480c-ba64-3a8188bd376a
797:END:
798**** List available groups
799See the /etc/group var.
800e.g
801: tail -5 /etc/group
802**** List groups user is in
803Use the id command. See: [[id:a590fc9b-0ebf-43ae-ad66-e9aaf1233826][Id Command]]
804: id user
805**** References
806man:group(5)
807man:groupadd(8)
808man:groudel(8)
809man:usermod(8)
810
811*** Gaining Superuser Access
812**** The root user
813- overrides permissions.
814- Most devices controlled by root.
815 With few exceptionse, .g usb devices, removable devices.
816
817(!) In general, it is not reccomended to log in as 'root'.
818 Better log in as normal user and use su,sudo or PolicyKit (like UAC for linux)
819 This way only the user account would get compromised and not the whole system.
820**** @ su :Switch users BCMD__
821*su* (switch user) allows you to switch to another account.
822if <username> is not specified, root is used as defaulti
823
824Syntax:
825: su [-] <username>
826
827Example:
828: su -
829
830- *su* vs *su -*
831 su = non-login shell. I.e, keep current [[id:66456bb5-8521-4270-8aaf-fec9b0febc61][Environmental Variables...]]
832 su - = login-shell. I.e new env as if it's that user. *normally prefered*
833*** Managing User Passwords
834**** Shadow passwords and password policy
835***** History of password files
836 Encrypted passwords used to be stored in
837 : /etc/passwd.
838 But due to dictionary attacks, they were moved to
839 : /etc/shadow
840
841***** password has 3 components
842 $1$gCjLa2/Z$6Pu0EK0AzfCjxjv2hoLOB/
843 ^1 ^2 ^3
844
845 1. '$1$' Algorithm. 1=MD5, 6=SHA-512 (see man:crypt(3))
846 2. gCjLa2/Z = the *salt* to encrypt password. Salt + password get combined. salt is random.
847 Prevents identical entries for users in /etc/shadow
848 3. 6Pu0../ = the encrypted hash
849
850 Note: * RHEL 6 & 7 support algo 5 (SHA-256) and algo 6 (SHA-512). Longer salt.
851 root can change via: authconfig --passalgo [md5|sha256|sha512]
852 * RHEL 7 defaults to 5 (sha-256)
853
854***** /etc/shadow format/syntax
855 name:password:lastchange ...
856
857 password = encrypted. If starts with '!', it is locked.
858
859 for details, see man:shadow(3)
860**** Password aging (chage) :BCMD__:
861man:chage
862Command is: chage as in with ommited 'n' 'Change-Age' (not 'change')
863Diagram:
864[[./img/img_2015_04_09__09_30_24.png]]
865
866E.g
867: chage -m 0 -M 90 -W 7 -I 14 <Username>
8680 minimum days
86990 Maximumd days
8707 Warning days
87114 Inactive days, then lock-out. When account is locked, it needs admin attention to fix it.
872
873- Force password change ::
874 Set last change date to be '0'.
875 : chage -d 0
876- List current user's password details ::
877 : chage -l
878- Expire password on specific date ::
879 : chage yyyy-mm-dd
880
881Note:
882 Date command can be used to calculate days in the future:
883 : date -d "+45 days"
884**** Restricting access
885***** Account locking [[elisp:(my/goto-parent)][(g2 link)]]
886:PROPERTIES:
887:ID: 6df049e8-814e-421d-ad49-7764856d1004
888:END:
889man:usermod
890- ~usermod~ can lock an account with '-L' option ::
891 : usermod -L jhon
892 Note, if you try to log into a locked account from a non-root user,
893 you get an 'authentication failure'. Which might be miss-leading.
894
895- Lock and expire account ::
896 : sudo usermod -L -e 1 jhon
897 This is the reccomended way to prevent access to an employee who left the company.
898 When he returns, you can unlock his account once again:
899 : usermod -U jhon
900***** No login shell [[elisp:(my/goto-parent)][(g2 link)]]
901:PROPERTIES:
902:ID: f3fef8ce-4e43-4e0b-985e-3b8ca86b7400
903:END:
904Some users don't need access to the login shell.
905You can set login shell to '/sbin/nologin' for that.
906: usermod -s /sbin/nologin jhon
907
908Nologin simply closes the connection.
909
910(!) nologin does not prevent interactive use of system. Some apps (webaps etc.. )
911 could still gain access.
912**** References
913man:change(1)
914man:usermod(8)
915man:shadow(5)
916man:crypt(3)
917*** Using Itentity Management Services
918**** User information and authentication services
919SSO (Single Sign-on) TERM__
920(like domain).
921With SSO, you login once, then you get a token/cookie that you use to login to other places.
922
923<<C.I.M>>
924A *Centralized identity managment system* needs to provide two things:
9251. /Account Inforamtion/
926 username/homedir location/UID/GID/group member ship.
927 Popular:
928 - LDAP (light weight Directory Access Protocol) [Active directory]
929 - IPA Server and Network Information Services (NIS)
930
9312. /Authentication Information/
932 Validate pass/account. cryptographic password.
933 Kerberos only provides SSO auth.services, typically used alongside LDAP user info.
934
935See also: [[id:bd6076d5-7aff-4e51-b3d0-f55685dd2415][Kerberos]]
936**** Attaching a system to centralized LDAP and Kerbos servers
937***** Authconfig :BCMD__:
938****** Raw files
939To make RHEL 7 join [[C.I.M]], you need to edit various files and configure some daemons.
940
941#+BEGIN_SRC dot :file ./img/img_2015_04_10__10_25_40.png :cmdline -Kdot -Tpng
942 digraph {
943 node [style=filled]
944
945 subgraph Folders {
946 node [shape=folder, width=.6, fillcolor=gold2]
947 nodesep=.1
948 pamd [label="pam.d"]
949 etc -> {sssd;pamd;openldap}
950
951 }
952
953 subgraph Files {
954 node [shape=record,fillcolor=lightblue]
955 ldap [label="{ldap.conf | LDAP settings}"]
956 krb5 [label="{krb5.conf|Kerberos}"]
957 sssdconf [label="{sssd.conf|Security daemon}"]
958 nsswitch [label="{nsswitch.conf|Auth. selection}"]
959 o [label="{*|auth. handling}"]
960 cacerts [label="{cacerts|CA to validate SSL cert.}"]
961
962 nsswitch -> o [label="(Auth selection)" arrowhead=nul style=dotted]
963 }
964
965 etc -> {ldap;krb5;nsswitch}
966 sssd -> sssdconf
967 pamd -> o
968 openldap -> cacerts
969 }
970#+END_SRC
971
972#+results:
973[[file:./img/img_2015_04_10__10_25_40.png]]
974
975- /etc/ldap.conf ::
976 Info on central LDAP server and it's settings.
977- /etc/krb5.conf ::
978 Info on central Kerbos infrastructure
979- /etc/sssd/sssd.conf ::
980 To configure the system securtiy services.
981 Deamon retrieves and chaches user info and auth. info.
982- /etc/nsswitch.conf ::
983 To indicate to system which user info and auth. should be used.
984- /etc/pam.d/* ::
985 Configure how authentication should be handled for var. services.
986- /etc/openldap/cacerts ::
987 Store the root /certificate authoritiec (CA)/ that can validate the SSL certificates
988 used by identity LDAP servers.
989
990*sssd* deamon needs to be enabled before it can be used.
991****** Authentication configuration tools
992It's easy to confuse which file does what. RHEL 7 has tools:
993#+BEGIN_SRC dot :file ./img/img_2015_04_13__10_26_55.png :cmdline -Kdot -Tpng
994 digraph {
995 authconfig -> {authconfigtui [label="authconfig-tui\n(Interactive meuu)"];
996 authconfiggtk[label="authconfig-gtk\n(gui)"]}
997
998 }
999#+END_SRC
1000
1001#+results:
1002[[file:./img/img_2015_04_13__10_26_55.png]]
1003
1004- authconfig :: BCMD__
1005 cmd tool to automate configuration across many systems.
1006 Commands tend to be very long with multiple options.
1007 ∈ /authconfig/ package
1008
1009- authconfig-tui ::
1010 Interactive version. Can be used over ssh.
1011 ∈ /authconfig/ package.
1012
1013- authconfig-gtk ::
1014 Gui version.
1015 ∈ authconfig-gtk package.
1016***** LDAP parms
1017authconfig needs a number of settings to connect:
1018- host name of LDAP server(s)
1019- base DN (Distinguished Name) of the part of the LDAP tree where the system should
1020 look for users.
1021 e.g dc=example, dc=com
1022 ou=People, o=PonyCorp
1023- if SSL/TLS used, a root CA.
1024
1025*Note*: Also need sssd package (it will handle all dependencies)
1026***** Kerbos paramaters
1027For centralized authentication, authconfig will need:
1028 - Name of kerberos /realm/ to use.
1029 - (key distribution centers (KDC))+ host name of kerberos servers
1030 - (host name of admin server)+ machine to talk to for changing passwords/user settings.
1031DNS optional.
1032
1033*krb5-workstation* = tool to troubleshoot kerberos issues.
1034***** Using authconfig-gtk
10351. Install necessary packages:
1036: sudo yum -y install authconfig-gtk sssd krb5-workstation
10372. launch authconfig-gtk
10383. Configure
1039***** Testing a configuration
1040To test LDAP+Kerberos configuration, admin can try to login over ssh using
1041credentials of one of the users.
1042~getent~ cmd can be used to get info about user. (get entry?)
1043: getent passwd <USERNAME>
1044
1045*Important* In def.config, sssd will *not* enumerate network users when no username
1046is specified to the getent cmd. (Remove clutter)
1047**** Attaching a System to an IPA Server
1048For LDAP & Kerberos config, RHEL provides: IPA (Identity Poliy and audit)
1049
1050IPA can centralize
1051- *sudo* rules.
1052- SSH public keys
1053- SSH host keys
1054- TLS Certificates
1055- automounter
1056
1057- Using ipa-client ::
1058 authconfig can be used to make RHEL use IPA server.
1059 But a specialized tool also exists: *ipa-client-install*
1060 ∈ ipa-client package.
1061
1062
1063 Benifits of ipa-client-install is that it uses DNS mostly.
1064
1065 ipa-client-install w/o args tries to use DNS, then prompts admin for info.
1066 (e.g domain name/realm)
1067
1068e.g:
1069 : sudo ipa-client-install --domain=serverX.example.com --no-ntp --mkhomedir
1070
1071 #+name: Example ipa- client install
1072 #+begin_src sh
1073 [student@desktop ~]$ sudo ipa-client-install
1074 Discovery was successful!
1075 Hostname: desktop.domain0.example.com
1076 Realm: DOMAIN0.EXAMPLE.COM
1077 DNS Domain: server.domain0.example.com
1078 IPA Server: server.domain0.example.com
1079 BaseDN: dc=server,dc=domain0,dc=example,dc=com
1080 Continue to configure the system with these values? [no]: yes
1081 User authorized to enroll computers: admin
1082 Synchronizing time with KDC...
1083 Password for admin@DOMAIN0.EXAMPLE.COM: redhat123
1084 Successfully retrieved CA cert
1085 Subject:
1086 CN=Certificate Authority,O=DOMAIN0.EXAMPLE.COM
1087 Issuer:
1088 CN=Certificate Authority,O=DOMAIN0.EXAMPLE.COM
1089 Valid From: Thu Feb 27 13:31:04 2014 UTC
1090 Valid Until: Mon Feb 27 13:31:04 2034 UTC
1091 Enrolled in IPA realm DOMAIN0.EXAMPLE.COM
1092 Created /etc/ipa/default.conf
1093 New SSSD config will be created
1094 Configured /etc/sssd/sssd.conf
1095 Configured /etc/krb5.conf for IPA realm DOMAIN0.EXAMPLE.COM
1096 Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
1097 Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
1098 SSSD enabled
1099 Configured /etc/openldap/ldap.conf
1100 Configured /etc/ssh/ssh_config
1101 Configured /etc/ssh/sshd_config
1102 Client configuration complete.
1103 #+end_src
1104***** Q: What does IPA stand for? :drill:
1105:PROPERTIES:
1106:ID: c36442ee-e892-4945-ad97-50d3d61744ad
1107:DRILL_LAST_INTERVAL: 0.0
1108:DRILL_REPEATS_SINCE_FAIL: 1
1109:DRILL_TOTAL_REPEATS: 3
1110:DRILL_FAILURE_COUNT: 2
1111:DRILL_AVERAGE_QUALITY: 1.0
1112:DRILL_EASE: 2.36
1113:DRILL_LAST_QUALITY: 0
1114:DRILL_LAST_REVIEWED: [2015-05-05 Tue 10:27]
1115:END:
1116[Identity Policy and Auditing]
1117**** Joining a system to Active Directory
1118Multiple methods:
1119
1120 - samba-windbind ::
1121 Install package & configure through authconfig family of tools.
1122 - sssd and realmd ::
1123 Install packages & use sssd/realm cmd's.
1124
1125#+BEGIN_SRC sh
1126 #disscover settings for domain:
1127 sudo realm discover domain.example.com
1128
1129 #join:
1130 sudo realm join domain.example.com
1131
1132 #Logins to A.D are dissabled, to enable:
1133 sudo realm permit --realm domain.example.com --all
1134
1135 #to allow only some users to login, replace --all with users:
1136 sudo realm permit --realm domain.example.com DOMAIN\\Itchy DOMAIN\\Scratchy
1137
1138 #by default, users need to use full login. user@domain.com. to dissable,
1139 #chagne use_fully_qualified_names settings in /etc/sssd/sssd.conf to false & restart sssd.
1140
1141#+END_SRC
1142
1143NOTE:
1144**** References
1145man:ipa-client-install(1)
1146man:authconfig(8)
1147man:authconfig-tui(8)
1148man:authconfig-gtk(8)
1149man:sssd(8)
1150man:sssd-ipa(8)
1151man:sssd-conf(5)
1152man:ssd-ad
1153man:realm(8)
1154** DONE 4 File Permissions
1155CLOSED: [2015-07-30 Thu 15:09]
1156:LOGBOOK:
1157- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
1158- State "DONE" from "OPEN" [2015-06-05 Fri 10:44]
1159CLOCK: [2015-06-05 Fri 10:32]--[2015-06-05 Fri 10:44] => 0:12
1160CLOCK: [2015-06-05 Fri 09:55]--[2015-06-05 Fri 10:20] => 0:25
1161CLOCK: [2015-06-03 Wed 11:25]--[2015-06-03 Wed 11:50] => 0:25
1162CLOCK: [2015-06-02 Tue 10:14]--[2015-06-02 Tue 10:39] => 0:25
1163CLOCK: [2015-06-02 Tue 09:37]--[2015-06-02 Tue 10:02] => 0:25
1164CLOCK: [2015-06-01 Mon 11:50]--[2015-06-01 Mon 12:15] => 0:25
1165CLOCK: [2015-06-01 Mon 11:14]--[2015-06-01 Mon 11:39] => 0:25
1166CLOCK: [2015-05-29 Fri 11:44]--[2015-05-29 Fri 12:09] => 0:25
1167CLOCK: [2015-05-29 Fri 11:09]--[2015-05-29 Fri 11:37] => 0:28
1168CLOCK: [2015-05-28 Thu 10:03]--[2015-05-28 Thu 10:44] => 0:41
1169CLOCK: [2015-05-28 Thu 09:34]--[2015-05-28 Thu 09:59] => 0:25
1170CLOCK: [2015-05-28 Thu 09:23]--[2015-05-28 Thu 09:33] => 0:10
1171CLOCK: [2015-05-27 Wed 09:58]--[2015-05-27 Wed 10:23] => 0:25
1172CLOCK: [2015-05-27 Wed 09:30]--[2015-05-27 Wed 09:55] => 0:25
1173CLOCK: [2015-05-26 Tue 09:48]--[2015-05-26 Tue 10:24] => 0:36
1174CLOCK: [2015-05-26 Tue 09:08]--[2015-05-26 Tue 09:33] => 0:25
1175:END:
1176*** Managing File System Permissions from the command line
1177**** @ chmod (change mode) BCMD__
1178:PROPERTIES:
1179:ID: 088d0576-0ee1-47cd-aef5-ad4155e848a9
1180:END:
1181Change Mod.
1182: chmod [Option]... mode,[Mode]... <FILE|DIRECTORY> ...
1183
1184e.g s
1185: chmod u+x hello.txt //give user execute rights:
1186: chmod ugo=rwx hello.txt //give user group other all rights.
1187: chmod u+x,g+r hello.txt goodbye.txt //set multiple modes to multiple files.
1188
1189- Options ::
1190 -R recursive (use with X below)
1191 -c print only changes
1192 -f silent.
1193
1194- Mode ::
1195 [ugo..][+-=][rwxXst]
1196
1197 ugo - user group other ('s' explained below)
1198 +-= - add, remove, set
1199 rwx - read write execute
1200 X - execute only if file is a directory. Used with -R option.
1201 i.e, not on regular files. e.g
1202 : chmod -R g+rwX demodir
1203See also: [[id:97b90610-24e8-4eb6-988a-5357b8d96a14][Managing default Permissions and file access]] (for 's' permission and sticky)
1204
1205
1206
1207- Numeric method / Octal mode ::
1208 You can give a numeric instead.
1209 u,g,o can have be a combination of:
1210 r - 4
1211 w - 2
1212 x - 1
1213 E.g 761 means u has all rights, group has r(4)+w(2) rights, o has only e(1) rights.
1214 See also: [[id:14358f78-adad-4daa-b3b9-80931740a30e][Numerical setting of special permissions]]
1215man:chmod(1)
1216**** ls -l (ll) (Show/see file permissions) BCMD__
1217You can:
1218: ls -l
1219to see file permissions.
1220
1221- Permissions string ::
1222
1223 : -rw-rw-r--. 1 lufimtse mail 65943 Sep 17 2014 dead.letter
1224 ' | | | | |
1225 User | other user group
1226 group
1227
1228- Directories ::
1229 Directories have a 'd' prefix:
1230 : drwxrwxr-x
1231 : ^-- directory
1232
1233man:ls(1)
1234**** chown (change ownership) BCMD__
1235By default, when a user creates a file, it is owned by that user and the group is
1236the primary group of the user.
1237
1238Give a file a new owner:
1239: chown <new owner> <file>
1240
1241Give a file a new owner and set a new group:
1242: chown <new owner>:<new group> file
1243
1244Set only a new group for the file:
1245: chown :<new group> file
1246Limitation is that the current user can only set the file to a group that the user is in.
1247
1248e.g: . .
1249: chown leo:wheel file
1250
1251Note:
1252- only root can change owner. But user can change group they belong to.
1253- some users use ~chgrp~ which is same as ~chown~ with -R command.
1254
1255man:chown(1)
1256man:chgrp(1)
1257*** Managing default Permissions and file access
1258:PROPERTIES:
1259:ID: 97b90610-24e8-4eb6-988a-5357b8d96a14
1260:END:
1261**** Special File Permissions
1262***** setuid
1263- about ::
1264 ~setuid~ (or ~setgid~) permissions on an executable means that that file will be launched under the owner (or group) of the file, and not by the user who is launching this file.
1265
1266 E.g passwd, it is ran by users, by executed as root who owns the file.
1267 : [student@desktopX ~]$ ls -l /usr/bin/passwd
1268 : -rwsr-xr-x. 1 root root 35504 Jul 16 2010 /usr/bin/passwd
1269 : ^--'setuid' bit
1270 Instead of an 'x', there is an 's'. 'S' if ower does not have exec permissions.
1271 Note, proccess handles security in this case.
1272***** setgid
1273 On folder, makes it so that files created in that folder inherit the group of the folder
1274 and not that of the user.
1275***** sticky bit
1276 Normally, one user can delete files from another user. With the sticky bit, you must own the file to delete it. (or be root).
1277
1278 : drwxrwxrwt.
1279 : ^ 't' indicates sticky.
1280 t = sticky.
1281 T = owner does not have execute perm.
1282***** Effects of special permissions on files & directories.
1283| S.Perm | Effect on files | Effect on directories |
1284|--------+--------------------------+----------------------------------------------------|
1285| u+s | file exec as owner | --- |
1286| g+s | file exec as group owner | new files assigned group of directory |
1287| o+t | --- | Users with *write* can only remove files they own, |
1288| | | cannot remove/save files owned by others. |
1289|--------+--------------------------+----------------------------------------------------|
1290***** Numerical setting of special permissions
1291:PROPERTIES:
1292:ID: 14358f78-adad-4daa-b3b9-80931740a30e
1293:END:
1294setuid=4
1295setgid=2
1296sticky=1
1297combined can be the prefix.
1298e.g concat(setuid+setgid[2+4], all permissions[ 777]) -> 6777
1299**** Default file permissions (umask BCMD__)
1300umask *removes* permissions.
1301
1302: umask //how current umask of the shell.
1303: umask [0-7]+ //set mask to something new.
1304
1305E.g
1306: umask 0002 //remove write from 'other'.
1307: umask 0077 //remove all permissions from 'group' and 'other'.
1308: umask 77 //same as above, '0's are assumed for ommited numbers.
1309
1310Notes:
1311 - system defaults are defined in ~/etc/profile~ and ~/etc/bashrc~.
1312 - umask = user file-creation mask.
1313
1314Ref:
1315man:umask(1)
1316*** POSIX: Access Control Lists (ACLs)
1317**** About
1318- About ::
1319 - List of users/groups that have access to a file.
1320 - More granular than standard ls permissions.
1321- Enablement ::
1322 - RHEL7 has ext4 alc enabled. RHEL6 needs enabling first.
1323 - XFS has alc build in.
1324- See if ACL is enabled on file ::
1325 : -rwxrw----+
1326 : ^-- the plus at the end indicates that acl is enabled
1327- Other ::
1328 - Directories can have default acl's
1329 - output of getfacl can be used as input to setfacl.
1330 : getfacl -R /directory > file
1331 : setfalc --set-file=file #mass update.
1332- Precedence ::
1333 - File Owner
1334 - ALC users
1335 - Groups (file or ALC)
1336 - Other in ACL.
1337**** getfacl BCMD__
1338 : getfacl <file>
1339- about ::
1340 i.e, 'get file access control list'
1341- for directory ::
1342 - add '.' at the end. Has default rights:
1343 : getfacl .
1344 : ..
1345 : default:user:rwx #etc...
1346- mask ::
1347 - maximum availalbe permissions
1348 e.g
1349 : user:judie:rwx #effective:rw-
1350 : mask::rw-
1351 User judie has rwx permissions, but mask limits to rw only.
1352 - (mask is)Usually auto-calculated, but can be inherited from folder or set.
1353 auto-calculated on update, acl added/modified/updated.
1354**** References
1355man:acl(5)
1356man:getfacl(1)
1357man:ls(1)
1358*** Securing Files with ACLs
1359**** setfacl BCMD__
1360 : setfacl <Options> <flags> <file>
1361***** Input selector
1362-m modify manually
1363 -M <file> from file
1364 -M- '-' means from stdin
1365***** Adding/modifing an ACL
1366: setfacl -m u:name:rX file #User.
1367 : setfacl -m g:name:rw file #Group.
1368 : setfact -m o::- file #other only accepts permissions
1369 - If name is blank == file owner
1370 - name can be uid/gid.
1371***** multiple options
1372: setfacl -m u::rwx,g:sodor:rX,o::- file
1373***** chomd vs setfacl
1374chomd impacts file owner in the same way as setfacl does.
1375 but chmod on group set's the mask, not the group permissions.
1376 chmod has no effect on named users.
1377 - Using getfacl as input ::
1378 - Piping
1379 : getfacl file-A | setfacl --set-file=- file-B
1380 or
1381 : getfacl -c myfile | setfacl -M- myFile
1382
1383 - To/From file:
1384 : getfacl -c myFile > perm.txt #'-c' strips comments
1385 : setfacl -M perm.txt myFile #capital 'M'
1386***** Setting an explicit ACL ~mask~
1387: setfacl -m m::r file
1388 Limit max perm for named users, group owners and named groups.
1389 Doesn't impact file owner and other users.
1390
1391 getfacl will show '#effective' flag.
1392
1393 (!) ACL mask is recalculated upon changes.
1394 to avoid, use ~-n~ or include mask setting.
1395***** Recursive ACL Mods
1396Use upper ~-R~
1397 : setfacl -R -m u:name:rX directory.
1398***** Deleting an ACL
1399Similar, but not specify 'permissions'.
1400 : setfacl -x u:name,g:name myfile
1401 -x and -m can be used together.
1402 mask needs to be deleted last.
1403***** Controling default ACL
1404 Similar, but use '-d'
1405 : setfacl -m d:u:name:rX directory
1406 - Removing acl ::
1407 : setfacl -k #delete all default acls.
1408 : setfacl -x -d
1409 - Recursivley ::
1410 : setfacl -R //with 'X'
1411 - Note about mask ::
1412 Mask overrides default permissions.
1413***** References
1414man:acl(5)
1415man:setfacl(1)
1416** DONE 5 SELinux Permissions
1417CLOSED: [2015-07-30 Thu 15:09]
1418:LOGBOOK:
1419- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
1420- State "DONE" from "OPEN" [2015-06-18 Thu 10:09]
1421CLOCK: [2015-06-18 Thu 09:41]--[2015-06-18 Thu 10:06] => 0:25
1422CLOCK: [2015-06-17 Wed 10:34]--[2015-06-17 Wed 11:13] => 0:39
1423CLOCK: [2015-06-17 Wed 09:32]--[2015-06-17 Wed 09:57] => 0:25
1424CLOCK: [2015-06-16 Tue 10:02]--[2015-06-16 Tue 10:27] => 0:25
1425CLOCK: [2015-06-16 Tue 09:31]--[2015-06-16 Tue 09:56] => 0:25
1426CLOCK: [2015-06-15 Mon 10:07]--[2015-06-15 Mon 10:36] => 0:29
1427CLOCK: [2015-06-15 Mon 09:35]--[2015-06-15 Mon 10:00] => 0:25
1428CLOCK: [2015-06-12 Fri 10:44]--[2015-06-12 Fri 11:09] => 0:25
1429CLOCK: [2015-06-12 Fri 10:01]--[2015-06-12 Fri 10:26] => 0:25
1430CLOCK: [2015-06-11 Thu 09:56]--[2015-06-11 Thu 10:21] => 0:25
1431CLOCK: [2015-06-11 Thu 09:28]--[2015-06-11 Thu 09:53] => 0:25
1432CLOCK: [2015-06-10 Wed 10:02]--[2015-06-10 Wed 10:27] => 0:25
1433CLOCK: [2015-06-10 Wed 09:28]--[2015-06-10 Wed 09:53] => 0:25
1434CLOCK: [2015-06-08 Mon 10:17]--[2015-06-08 Mon 10:41] => 0:24
1435CLOCK: [2015-06-08 Mon 09:43]--[2015-06-08 Mon 10:08] => 0:25
1436CLOCK: [2015-06-05 Fri 10:44]--[2015-06-05 Fri 10:57] => 0:13
1437:END:
1438*** About
1439 SE Linux is fine grained permission management of files/processes/users/ports
1440 to minimize impact of 'rough/hacked' services.
1441
1442 E.g Apache has access to /tmp and /etc/passwd. If apache is compromised,
1443 hacker could fill /tmp folder or /etc/passwd could be displayed on a webpage.
1444*** Enabling and Monitoring Security Enchanced Linux (SELinux)
1445**** Targeted permissions
1446 Permissions are targeted to induvidual files
1447 - file1
1448 - file2 etc..
1449 The goal is to containe them.
1450
1451 +------------+
1452 | Object | << contain object.
1453 +------------+
1454
1455**** Context : Type enforcing
1456Context determines if something has access to a resource.
1457+----------------+ +-----------------------------------+
1458| Labels/Context | =(applied to)=> |(files/processes/users/ports etc..)|
1459+----------------+ +-----------------------------------+
1460
1461labels have several contexts:
1462 - user
1463 - role
1464 - type_t << targeted policy aims here.
1465 - sensitivity
1466
1467- types ::
1468 Typically end with _t
1469 e.g web-server == httpd_t
1470 /var/www/html == httpd_sys_content_t
1471 /tmp and /var/tmp == tmp_t
1472 web-server ports == http_port_t
1473**** Displaying context "-Z"
1474Many commands have a "-Z" at the end to display context.
1475
1476E.g
1477 - Kernel processes
1478 : ps axZ | grep kernel_t
1479 : system_u:system_r:kernel_t:s0 2 ? S 0:00 [kthreadd]
1480 : system_u:system_r:kernel_t:s0 3 ? S 0:09 [ksoftirqd/0]
1481 ^ kernel type.
1482
1483 - home directory
1484 : ls -Z /home
1485 : drwx------. root root system_u:object_r:lost_found_t:s0 lost+found
1486 : drwx--x---+ lufimtse lufimtse unconfined_u:object_r:user_home_dir_t:s0 lufimtse
1487 ^- user_home_dir_t type
1488
1489**** Policy
1490 There is a policy how two objects can interact with one another.
1491 +--------+ +---------+
1492 | Object1+ <-- Policy -->| Object_2|
1493 +--------+ +---------+
1494**** Modes
1495 - 1 Enforcing mode ::
1496 Limits permissions. Logs intrusions. By default, all is blocked unless it's permitted.
1497 - 2 Permissive ::
1498 Allows all, but logs in-correct access. Useful to see what perm services need.
1499 No reboot required.
1500 - 3 Dissabled ::
1501 For those days...
1502 Reboot required with kernel paramaters.
1503
1504To display current mode, use:
1505: getenforce
1506**** Booleans
1507Switches to control behaviour of SELinux policy.
1508
1509Listing all booleans :
1510: getsebool -a
1511**** References
1512man:selinux(8)
1513man:getenforce(8)
1514man:getsebool(8)
1515*** Changing SELinux Modes
1516- Objectives ::
1517 - change current SELinux mode
1518 - Set default SELinux mode of a system.
1519
1520- Se config ::
1521 : /etc/selinux/config
1522 Change this to change the mode at boot time.
1523
1524 Has two variables:
1525 SELINUX=enforcing | permissive | disabled
1526 SELINUXTYPE= targeted | minimum | mlsn # default policy
1527
1528 On older RHEL:
1529 /etc/sysconfig/selinux << on older files.
1530
1531- See current mode ::
1532 getenforce << see current mode
1533
1534- Set other mode ::
1535 setenforce 1 #1 = enforcing mode.
1536 setenforce permissive #words work also.
1537
1538- Dissable/ paramas at boot time ::
1539 pass paramater at boot time:
1540 /boot/grub/grub.conf
1541
1542 enforcing=0 #permissive mode
1543 selinux=0 #dissabled.
1544
1545- Ref ::
1546 man:setenforce(1)
1547 man:getenforce(1)
1548 man:selinux_config(5)
1549
1550*** Changing SELinux Ccontexts
1551**** Summary
1552 Moving preserves SELinux types of file moved.
1553 ~chcon~ can change types but is not reccomended as context
1554 can be overwritten on reboot. Use ~restorecon~ instead.
1555
1556 Search types with ~semanage fcontext -l~.
1557
1558**** See types info
1559List type info of files:
1560: ls -Z
1561: ... _u: _r: _t
1562: user role type
1563
1564Find proccess running a certain type:
1565: ps -Z | grep ..._t
1566
1567**** restorecon : Restoring context of moved file BCMD__
1568Normally files get types of parent dir.
1569But if file moved into dir, it preserves it's original permisisons.
1570In this case, you can use ~restorecon~ (restore context) to set it
1571to the context of the partent dir.
1572
1573: restorecon -v <file> #verbose.
1574: restorecon -Rv /dir #recursivley on all files in folder.
1575
1576This actually uses a database of definitions. E.g list http related bits:
1577: semanage fcontext -l | grep http
1578
1579This contains many regexe's e.g '/websites(/.*)?'. Most specific is applied.
1580**** chcon : Manually set context BCMD__
1581Usually avoid, but can be used for troubleshooting.
1582
1583Useful to set it to a context of an existing file:
1584: chcon --reference=FILE
1585: chcon -t newType FILE
1586
1587e.g
1588: chcon -t httpd_sys_content_t /virtual
1589**** semanage : Adding new Context with BCMD__
1590: semanage fcontext -a -f "" -t http_sys_content_t '/websites(/.*)?'
1591: add ? type regex.
1592
1593- Changing the SELinux context of a file ::
1594
1595- Defining SELinux default file context rules ::
1596**** Example
1597Appache server:
1598: yum install -y httpd
1599: mkdir /custom
1600: echo 'This is serverX.' > /custom/index.html
1601
1602edit ~/etc/httpd/conf/httpd.conf~ and set:
1603DocumentRoot "/custom"
1604<Directory "/custom">
1605
1606Try starting:
1607: systemctl start httpd
1608http://localhost/index.html
1609
1610It will fail with persmissions. Now fix perm
1611: semanage fcontext -a -t httpd_sys_content_t '/custom(/.*)?'
1612: restorecon -Rv /custom
1613*** Changing SELinux Booleans
1614**** About
1615These are rules that can be enabled/dissabled.
1616e.g allow users to run FTP from their home dirs.
1617**** Getting help.
1618You need to install man pages
1619: selinux-policy-devel
1620
1621Search man pages. there are many _selinux pages.
1622: man -k '_selinux'
1623 /the selinux man pages didn't seem to show for me :-/
1624
1625e.g:
1626: man ftpd_selinux
1627
1628See also ~semanage boolean -l~ as it shows description.
1629**** getsebool : find out current state
1630e.g list all and grep:
1631: getsebool -a | grep ftpd
1632
1633See current state for after reboot:
1634: semanage boolean -l
1635
1636e.g:
1637: ftp_home_dir (off , off) Determine whether ftpd can read and write files in user home directories.
1638**** setsebool : set boolean policy
1639Persistent change '-P'
1640: setsebool -P httpd_enable_homedirs on
1641
16421=on, 0=off.
1643**** Ref
1644man:booleans(8)
1645man:getsebool(8)
1646man:setsebool(8)
1647man:semanage(8)
1648man:semanage-boolean(8)
1649*** Troubleshooting SELinux
1650**** General guidance
1651- consider it might be a genuine compromise of the system if service asks for more than it needs.
1652- Most often files moved but context was not adjusted. use ~restorecon~.
1653- sebooleans may need adjusted. (e.g ftd_anon_write allow anonomous ftp upload.)
1654- (unlikley), but may be a bug in policy.
1655
1656**** Install package first
1657 sudo dnf install setroubleshoot-server.x86_64
1658**** Location of messages
1659 : /var/log/audit.log
1660 - SELinux violuations
1661 - "avc denied" indicates permission error.
1662
1663
1664 : /var/log/messages
1665 - short summary
1666 - UUID
1667 - command that caused issue
1668 - path to file etc..
1669
1670**** Example messages
1671 [root@serverX ~]# tail /var/log/audit/audit.log
1672 ...
1673 type=AVC msg=audit(1392944135.482:429): *avc: denied* { getattr } for
1674 pid=1609 comm="httpd" path="/var/www/html/file3" dev="vda1" ino=8980981
1675 scontext=system_u:system_r:httpd_t:s0
1676 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file
1677 ...
1678 [root@serverX ~]# tail /var/log/messages
1679 ...
1680 Feb 20 19:55:42 serverX setroubleshoot: SELinux is preventing /usr/sbin/httpd
1681 from getattr access on the file . For complete SELinux messages. run
1682 sealert -l 613ca624-248d-48a2-a7d9-d28f5bbe2763
1683
1684**** Getting more info
1685 log/messages contains command to get more info:
1686 : sealert -l 613ca624-248d-48a2-a7d9-d28f5bbe2763
1687
1688 The "Raw Audit Messages" has more info on context.
1689 See if the context 'belongs' there. E.g if a "admin_home" context is in
1690 a web-server folder, then it may not belong there.
1691
1692Usually ~restorecon -R /var/www~ will fix the issue.
1693
1694**** References
1695 man:sealert(8)
1696** DONE 6 Process Management
1697CLOSED: [2015-07-30 Thu 15:09]
1698:LOGBOOK:
1699- State "DONE" from "OPEN" [2015-07-30 Thu 15:09]
1700- State "DONE" from "OPEN" [2015-06-25 Thu 10:21]
1701CLOCK: [2015-06-25 Thu 10:16]--[2015-06-25 Thu 10:21] => 0:05
1702CLOCK: [2015-06-25 Thu 09:46]--[2015-06-25 Thu 10:11] => 0:25
1703CLOCK: [2015-06-24 Wed 09:56]--[2015-06-24 Wed 10:25] => 0:29
1704CLOCK: [2015-06-24 Wed 09:30]--[2015-06-24 Wed 09:55] => 0:25
1705CLOCK: [2015-06-23 Tue 10:15]--[2015-06-23 Tue 10:45] => 0:30
1706CLOCK: [2015-06-23 Tue 09:36]--[2015-06-23 Tue 10:04] => 0:28
1707CLOCK: [2015-06-22 Mon 11:20]--[2015-06-22 Mon 12:09] => 0:49
1708CLOCK: [2015-06-22 Mon 10:45]--[2015-06-22 Mon 11:16] => 0:31
1709CLOCK: [2015-06-19 Fri 11:10]--[2015-06-19 Fri 11:35] => 0:25
1710CLOCK: [2015-06-19 Fri 09:43]--[2015-06-19 Fri 10:02] => 0:19
1711CLOCK: [2015-06-18 Thu 10:09]--[2015-06-18 Thu 10:34] => 0:25
1712:END:
1713*** Killing Processes
1714**** Signals
1715Better use name instead of number, as number may vary on linux OS's.
1716
17171 HUP Hangup
17182 INT Keyboard interrupt Ctrl-c
17193 QUIT Keyboard quit Ctrl-\
17209 KILL Kill, unblockable
172115 TERM Terminate (polite way to kill)
172218 CONT Continue (if stopped)
172319 STOP Stop, unblockable (suspends proc).
172420 TSTP Keyboard stop Ctrl-z suspend.
1725
1726Send SIGTERM first, then SIGKILL if that fails.
1727
1728see: man:signals(7)
1729also:
1730: kill -l
1731**** pkill : Kill user's proccesses administrivley, BCMD__
1732Kill all his proccesses:
1733: pgrep -l -u bob
1734: pkill -SIGKILL -u bob
1735
1736
1737: pkill -u bob
1738 kills all his processes but not his top lvl shell.
1739**** @ w who is logged in BCMD__
1740pty = pseudo terimnal, emulated (e.g xterm/ssh).
1741 pts is slave part of pty. (see man:pty)
1742tty = native terminal. Hardware/kernel.
1743
1744-f shows 'FROM' to see remote users.
1745**** References
1746kill(1), killall(1), pgrep(1), pkill(1), pstree(1), signal(7), and w(1) man pages
1747*** Job management
1748**** jobs : listing tasks BCMD__
1749: jobs
1750**** killing jobs
1751use kill with '%id' e.g %1
1752: kill %2
1753**** disown BCMD__
1754Removes jobs from job list.
1755**** fg / bg
1756Switch job into foreground
1757: fg
1758
1759Restarts a suspended job and runns it in background
1760: bg
1761
1762If no job id provided, the above act on current job.
1763**** wait
1764Useful in scripts that do things in the background.
1765
1766Eg.
1767Make as script wait until all it's background tasks are finished.
1768
1769See ref for example.
1770**** Ref
1771http://www.tldp.org/LDP/abs/html/x9644.html
1772*** Monitoring Process Activity
1773**** Load average
1774active request = ready for IO (inc those waiting for disk).
1775load number = number of active requests, 5 second average
1776exponential moving average = math formula to smoothen out high/low.
1777
1778load average = calculation of load.
1779- exponential
1780- 0-1 per CPU. Can be above 1 if there are too many requests.
1781- e.g 0-2 if there are 2 cpu's.
1782
1783- notes ::
1784 Threads counted induvidually.
1785**** @ top : list top processes BCMD__
1786***** main keys
1787h - help
1788s - set refresh rate
17891 - toggle induvidual cpus
1790H - toggles threads
1791u - filter by user
1792M - sort by memory usage
1793P - sort by process utilization
1794r - renice process
1795k - kill proc. (top in list is selected)
1796W - write (save display for later re-use)
1797***** Fields
1798VIRT = virtual memory (VSZ in ps)
1799RES = physical memory (resident and shared)
1800SHR = sharable memory (libraries etc... )
1801- Process state (s) ::
1802 D - uninterruptable sleeping (e.g waiting for disk)
1803 R runinng
1804 S sleeping
1805 T stopped/traced
1806 Z zombie
1807***** Column management
1808 F - sort order
1809 up/down to select item.
1810 s set to sort according to that field.
1811 right = highlight item, up/down to move column.
1812 SPC add/remove column from view.
1813***** Searching
1814o , then COLUMN=VALUE
1815 e.g COMMAND=foo
1816**** Determine number of CPU's on the system
1817: grep "model name" /proc/cpuinfo | wc -l
1818**** References
1819Load average explained:
1820http://blog.scoutapp.com/articles/2009/07/31/understanding-load-averages
1821
1822yelp help:gnome-system-monitor
1823ps(1), top(1), uptime(1), and w(1) man pages
1824*** Using nice and renice to Influence Process Priority
1825**** About
1826- Linux Priorties range from 0-139.
1827- 0 is higest.
1828- 0 - 99 is real time, 100 to 139 is user space.
1829- User can increase nice, but only root can lower.
1830- nice is inherited from parent proc.
1831
1832Niceness is an influence in priority
1833**** Mapping of nice to cpu priority
1834 Priory Nice PRIORITY
1835 High -20 100
1836 default 0 120
1837 Low 19 139
1838**** Commands
1839: nice -n 5 <CMD> #start command with lower priority
1840: nice <CMD> #default nice = 10.
1841
1842: renice -n 10 <PID> #renice an existing process.
1843
1844top -> select proccess, 'r' (renice).
1845
1846List all prcosses according to their nice value:
1847: ps axo pid,com,nice,pcpu sort=nice
1848**** References
1849nice(1), renice(1), and top(1) man pages
1850*** 100% cpu usage/utilization command, busy BCMD__
1851: sha1sum /dev/zero
1852: cat /dev/zero > /dev/null & #I like this.
1853** DONE 7 Updating Software Packages
1854CLOSED: [2015-07-30 Thu 15:33]
1855:LOGBOOK:
1856- State "DONE" from "OPEN" [2015-07-30 Thu 15:33]
1857- State "DONE" from "OPEN" [2015-06-29 Mon 09:50]
1858CLOCK: [2015-06-29 Mon 09:30]--[2015-06-29 Mon 09:50] => 0:20
1859CLOCK: [2015-06-25 Thu 18:53]--[2015-06-25 Thu 19:18] => 0:25
1860CLOCK: [2015-06-25 Thu 18:17]--[2015-06-25 Thu 18:46] => 0:29
1861:END:
1862*** Attaching Systems to subscriptions for Software Updates
1863- gui ::
1864 : subscription-manager-gui
1865
1866- cmds ::
1867 : subscription-manager --help
1868 per cmd help:
1869 : subscription-manager remove --help
1870
1871: subscription-manager register --username=yourusername --password=yourpassword
1872: subscription-manager list --available | less
1873: subscription-manager attach --auto
1874: subscription-manager list --consumed
1875: subscription-manager unregister
1876
1877**** References
1878subscription-manager-gui(8), subscription-manager(8), and rct(8) man pages
1879
1880Get Started with Red Hat Subscription Management - Red Hat Customer Portal
1881https://access.redhat.com/articles/433903
1882
1883Red Hat Customer Portal
1884https://access.redhat.com/documentation/en-US/Red_Hat_Subscription_Management/1/html-single/MigratingRHN/
1885*** dnf (yum) BCMD__
1886**** help
1887**** list
1888***** about
1889- Show what's installed, then what's available.
1890- press tab to see info.
1891- can be used with wild cards:
1892: yum list vim*
1893***** available - on remote repos
1894***** installed - on your system
1895***** kernels on your system (seeing)
1896: yum list kernel
1897**** info
1898: dnf info packagename
1899**** provides FILE/Library
1900Useful to see which packages provide certain files or libraries.
1901e.g
1902: dnf provides /etc/eclipse.ini
1903
1904Works with wild cards:
1905: E.g msg: No package 'foo-2.0' found ->>
1906: yum provides "*/foo-2.0.pc"
1907**** search KEYWORD
1908**** search all KEYWORD #in description
1909**** install
1910-y : to agree
1911**** update
1912: dnf update PACKAGENAME
1913: dnf update #update all packages.
1914
1915Kernel updates leave old kernel in boot menu.
1916See also [[id:f0c04bef-f80c-4dfe-8df8-2659b86829c1][uname]] for kernel version info.
1917**** remove
1918**** builddep #get build dependencies
1919:PROPERTIES:
1920:ID: 9bee127b-2fb7-49bf-8f13-0cf62251a69d
1921:END:
1922To build packages you often need a bunch of development packages.
1923This command can automatically pull the neccessary sources.
1924
1925e.g
1926: dnf builddep emacs
1927**** enable/dissable repositories temporarily
1928: --enablerepo=PATTERN
1929: --disablerepo=PATTERN
1930See also [[id:b1b4a13c-d3e8-4fcf-9449-edcc79a9b0ab][List repositories]]
1931**** *group*
1932***** list
1933***** list hidden
1934***** info
1935Marker Meaning
1936= Package is installed, was installed as part of the group
1937+ Package isn't installed, will be if the group is installed or updated
1938- Package isn't installed, will not be if the group is installed or updated
1939no marker Package is installed, but was not installed through the group.
1940***** install
1941**** *Transaction history*
1942***** log location: /var/log/yum.log
1943***** history
1944: dnf history
1945Provides a list of actions recently carried out.
1946***** history undo
1947undo an previos action. ID is provided by history command.
1948: dnf history undo ID
1949***** history info ID
1950**** Reference
1951yum(1) and yum.conf(5) man pages
1952http://docs.redhat.com/
1953*** Software Repositories
1954**** about
1955url's that contain a folder *repodata* are classed as repositories.
1956**** List repositories
1957:PROPERTIES:
1958:ID: b1b4a13c-d3e8-4fcf-9449-edcc79a9b0ab
1959:END:
1960yum repolist all
1961**** Location of repositories
1962: /etc/yum.repos.d/redhat.repo
1963Repos end with .repo
1964**** Enable repositories
1965: yum-config-manager --enable rhel-7-public-beta-debug-rpms
1966**** Add repos
1967: yum-config-manager --add-repo="http://dl.fedoraproject.org/pub/epel/beta/7/x86_64/"
1968**** References
1969Additional information may be available in the section on configuring yum and yum repositories in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
1970yum(1), yum.conf(5), and yum-config-manager(1) man pages
1971** DONE 8 Creating and Mounting File Systems
1972CLOSED: [2015-07-30 Thu 16:14]
1973:LOGBOOK:
1974- State "DONE" from "OPEN" [2015-07-30 Thu 16:14]
1975- State "DONE" from "OPEN" [2015-07-02 Thu 12:10]
1976CLOCK: [2015-07-02 Thu 11:55]--[2015-07-02 Thu 12:10] => 0:15
1977CLOCK: [2015-07-02 Thu 11:26]--[2015-07-02 Thu 11:51] => 0:25
1978CLOCK: [2015-07-02 Thu 10:55]--[2015-07-02 Thu 11:21] => 0:26
1979CLOCK: [2015-07-02 Thu 10:30]--[2015-07-02 Thu 10:55] => 0:25
1980CLOCK: [2015-07-02 Thu 09:54]--[2015-07-02 Thu 10:19] => 0:25
1981CLOCK: [2015-06-30 Tue 12:54]--[2015-06-30 Tue 13:08] => 0:14
1982CLOCK: [2015-06-30 Tue 12:15]--[2015-06-30 Tue 12:46] => 0:31
1983CLOCK: [2015-06-30 Tue 11:30]--[2015-06-30 Tue 12:12] => 0:42
1984CLOCK: [2015-06-30 Tue 10:58]--[2015-06-30 Tue 11:23] => 0:25
1985CLOCK: [2015-06-30 Tue 10:30]--[2015-06-30 Tue 10:55] => 0:25
1986CLOCK: [2015-06-29 Mon 11:22]--[2015-06-29 Mon 11:47] => 0:25
1987CLOCK: [2015-06-29 Mon 10:36]--[2015-06-29 Mon 11:01] => 0:25
1988CLOCK: [2015-06-29 Mon 10:01]--[2015-06-29 Mon 10:26] => 0:25
1989CLOCK: [2015-06-29 Mon 09:50]--[2015-06-29 Mon 09:55] => 0:05
1990:END:
1991*** Theory
1992**** Overview
1993To make a new disk accessible, you need to go through a bunch of steps:
19941) Make partition (fdisk)
1995 -> 2) Assign file system. (mkfs)
1996 -> 3) Mount (mount) & make persistent (/etc/fstab)
1997**** MBR / GPT Partitioning
1998- MBR has limit ::
1999 BIOS. Max: 15 partitions, 2 TiB storage.
2000
2001- GPT ::
2002 EFII. Max: 128 partitions, 8 ZiB.
2003 Redundancy parittion table. (Start & end of disk).
2004 128 bits GUID to uniqley identify sections.
2005
2006(!) MBR to GPT can cause data loss. (it is not sure why..)
2007**** Data Storage Unit Terminology (KiB, MiB, GiB etc..)
2008KiB vs KB notion.
2009
2010KB is decimal storage.
2011KiB is binary storage.
2012
2013e.g
2014 kilobyte KB = 10^3 bytes.
2015 kibibyte KiB = 2^10 bytes. (ki-po-bytes).
2016
2017 megabyte MB = 10^6
2018 mebibyte MiB = 2^10 bytes.
2019*** Adding Partitions, File Systems
2020**** 1) fdisk / gdisk : partitioning commands BCMD__
2021***** fdisk vs gdisk
2022fdisk for MBR volumes.
2023gdisk is for GPT volumes.
2024
2025#(fdisk has some GPT support, but it's experimental. Not reccomended).
2026***** Adding disk
2027Often used in conjunction with ~lsblk~ and ~blkid~ to see partitions.
2028
2029fdisk & gdisk can be used interchangingly.
2030: # fdisk /dev/vdb
2031: n (new)
2032: p|e (primary/extended. P usually does the job).
2033: first/last sectors. (e.g +512M. or -512M means leave that space at end).
2034: (optional) t (type -> 'L' to list types).
2035: w (write).
2036:
2037: # partprobe /dev/vdb #update kernel.
2038***** Removing a disk
2039fdisk & gdisk can be used interchangingly.
2040: lsblk
2041: ..
2042: fdisk /dev/vdb
2043: d #delete.
2044: w #write.
2045:
2046: partprobe /dev/vdb #update kernel.
2047**** 2) mkfs : Creating/Making a File System. BCMD__
2048Once partition is created, need to make a file system.
2049
2050: mkfs -t xfs /dev/vdb
2051
2052types:
2053 - xfs (RHEL) > ext4.
2054 - default is ext2.
2055**** 3) mount
2056See below.
2057**** References
2058fdisk(8), gdisk(8), mkfs(8), mount(8), fstab(5) man pages
2059*** Mounting and Unmounting File Systems
2060**** mount : BCMD__
2061***** Temporary mount
2062: mount #list all mounted devices.
2063
2064: mount FS Target_Dir #mount a specific
2065- Args ::
2066 - FS ::
2067 Can be either
2068 - "/dev/*" (partition directly).
2069 - "UUID" Universal Unique id of device.
2070 use blkid to find id's for devices.
2071 - Target_Dir ::
2072 - Reccomended to put into /mnt/YourDir
2073 - Make a dir first, then mount into it.
2074
2075- Example ::
2076 : mkdir /mnt/myDisk
2077 : mount /dev/vdb1 /mnt/myDisk
2078 or
2079 : blkid
2080 : #make note of UUID
2081 : mount UUID="xyz...." /mnt/myDisk
2082***** Persistent mount
2083mount info stored in:
2084: /etc/fstab #file system table.
2085
2086e.g
2087UUID=7a20315d-ed8b-4e75-a5b6-24ff9e1f9838 / xfs defaults 1 1
20881 2 3 4 5/6
20891 = id
20902 = mount point
20913 = file system
20924 = options. (see man:mount)
20935 = dump flag (e.g 0)
20946 = fsck flag. (increment to set order of.) (e.g 2)
2095
2096*(!) messing with this can make machine unbootable.*
2097 After changing, verify with:
2098 : mount -a
2099
2100
2101E.g:
2102: blkid /dev/vdb1 #find UUID
2103
2104: vi /etc/fstab
2105: #add:
2106: UUID=5fcb234a-cf18-4d0d-96ab-66a4d1ad08f5 /archive ext4 defaults 0 2
2107
2108: mount -a
2109**** umount : (Unmount a fs) BCMD__
2110: umount MOUNT_POINT
2111
2112- Can only unmount directory that are not in use.
2113- Use ~lsof~ to find out which proc's are using dir.
2114- Often your shell is in mount point, causing unmount issues.
2115
2116e.g
2117: umount /mnt/myDisk
2118**** blkid : (block id, lists UUID) BCMD__
2119- lists UUID for devices in the system.
2120- lists type of fs
2121**** lsblk : (list block devices) BCMD__
2122Like ~blkid~ but more human-friendly.
2123**** df : (space/usage on disk file system) BCMD__
2124- Reports disk file system usage.
2125- Size available on each on disk.
2126: df -h #h = human redale.
2127**** lsof (List open files) BCMD__
2128: lsof /yourDir
2129: lsof #list all open files by system.
2130**** Removable Media (flash usb sticks) note
2131Flash sticks are usually mounted in:
2132: /run/media/<user>/<label>
2133It is best to unmount them prior to ejection.
2134**** References
2135mount(8), umount(8), and lsof(8) man pages
2136*** Managing Swap Space
2137Virtual memory = real + swap.
2138**** Summary
2139Create a swap partition. Set type as swap.
2140Mark as swap. Turn swap on. Make swap persistent.
2141
2142 lsblk
2143 fdisk , t 82
2144 mkswap /dev/dbv
2145 swapon -a
2146 blkid #make note of UUID
2147 sudo vi /etc/fstab -> add UUID="..." swap swap 0 0
2148 mount -a #test.
2149**** create swap space
2150 - create partition (see fdisk)
2151 - set type : 82 Linux swap
2152 - Format a swap signature on the device.
2153 Appply 'swap signature'.
2154 : mkswap /dev/vdb1
2155 - Turn on swap space :
2156 : swapon /dev/vbd1 #on a device or
2157 : swapon -a #activate all listed in fstab.
2158**** Make Persistent
2159 add to /etc/fstab
2160 e.g
2161 : UUID=fbd7fa60-b781-44a8-961b-37ac3ef572bf swap swap defaults 0 0
2162 - mount point is set to 'swap' as it's not accessible.
2163 - default contains'auto', which auto-mounts swap space.
2164**** Prioritizing swap spaces
2165- Persistent ::
2166 in /etc/fstab, can set pri=1
2167 : UUID=af30cbb0-3866-466a-825a-58889a49ef33 swap swap pri=1 0 0
2168
2169- Temporary ::
2170 : swapon -p 1 /dev/vdb1
2171
2172Note, swapspaces with equal priorities will get round-robin.
2173Otherwise written to highest priority till full, then onto next one.
2174
2175Range: [-1, 32k], default= -1
2176
2177**** turn off swap space
2178 : swapoff
2179**** see available swap space
2180useful to see if you really added swap space.
2181: swapon -s #summary of each swap space
2182: free -h #memory overview in genreal.
2183**** References
2184** 9 Service Managment and Boot Troubleshooting
2185mkswap(8), swapon(8), swapoff(8), mount(8), fdisk(8) man pages
2186CLOSED: [2015-07-07 Tue 15:54]
2187:LOGBOOK:
2188- State "DONE" from "OPEN" [2015-07-07 Tue 15:54]
2189CLOCK: [2015-07-07 Tue 15:53]--[2015-07-07 Tue 15:54] => 0:01
2190CLOCK: [2015-07-07 Tue 15:08]--[2015-07-07 Tue 15:33] => 0:25
2191CLOCK: [2015-07-07 Tue 14:40]--[2015-07-07 Tue 15:05] => 0:25
2192CLOCK: [2015-07-07 Tue 13:04]--[2015-07-07 Tue 13:59] => 0:55
2193CLOCK: [2015-07-07 Tue 12:25]--[2015-07-07 Tue 12:50] => 0:25
2194CLOCK: [2015-07-07 Tue 11:50]--[2015-07-07 Tue 12:15] => 0:25
2195CLOCK: [2015-07-07 Tue 11:21]--[2015-07-07 Tue 11:28] => 0:07
2196CLOCK: [2015-07-06 Mon 15:45]--[2015-07-06 Mon 16:31] => 0:46
2197CLOCK: [2015-07-06 Mon 14:51]--[2015-07-06 Mon 15:16] => 0:25
2198CLOCK: [2015-07-06 Mon 14:21]--[2015-07-06 Mon 14:46] => 0:25
2199CLOCK: [2015-07-06 Mon 13:49]--[2015-07-06 Mon 14:14] => 0:25
2200CLOCK: [2015-07-06 Mon 13:32]--[2015-07-06 Mon 13:48] => 0:16
2201CLOCK: [2015-07-06 Mon 13:00]--[2015-07-06 Mon 13:25] => 0:25
2202CLOCK: [2015-07-06 Mon 12:59]--[2015-07-06 Mon 12:59] => 0:00
2203CLOCK: [2015-07-06 Mon 12:59]--[2015-07-06 Mon 12:59] => 0:00
2204CLOCK: [2015-07-06 Mon 11:30]--[2015-07-06 Mon 12:05] => 0:35
2205CLOCK: [2015-07-06 Mon 10:57]--[2015-07-06 Mon 11:28] => 0:31
2206CLOCK: [2015-07-06 Mon 10:22]--[2015-07-06 Mon 10:47] => 0:25
2207CLOCK: [2015-07-06 Mon 09:51]--[2015-07-06 Mon 10:16] => 0:25
2208CLOCK: [2015-07-03 Fri 11:58]--[2015-07-03 Fri 12:10] => 0:12
2209CLOCK: [2015-07-03 Fri 10:44]--[2015-07-03 Fri 11:22] => 0:38
2210CLOCK: [2015-07-03 Fri 10:03]--[2015-07-03 Fri 10:28] => 0:25
2211CLOCK: [2015-07-03 Fri 09:47]--[2015-07-03 Fri 10:03] => 0:16
2212CLOCK: [2015-07-02 Thu 12:15]--[2015-07-02 Thu 12:20] => 0:05
2213:END:
2214*** View process info (boot time services etc)
2215:LOGBOOK:
2216- State "DONE" from "HOLD" [2015-07-07 Tue 11:58]
2217- State "HOLD" from "OPEN" [2015-07-06 Mon 14:06]
2218:END:
2219Deamon processes by convention end with 'd'. systemd, bluetoothd etc..
2220*service* = one or more daemons.
2221
2222- History ::
2223 Init was pid 1. Now systemd has pid1.
2224 Features:
2225 - parallel launching
2226 - dependency resolution
2227 - proccess groups,
2228 - on-demand starting
2229
2230- meh ::
2231 .service - system service. E.g webserver
2232 .sock - delay startup till socket opened by client
2233 .path - delay startup till file changed. E.g print spooler.
2234
2235- States ::
2236 ... active(exited) : one time config complete
2237 ... static : cannot be enabled, but started by enabled services.
2238
2239- Summary ::
2240 systemctl
2241
2242- Show only socket ::
2243 systemctl --type=socket --all
2244
2245- Boot time services ::
2246 systemctl list-unit-files --type=service
2247
2248- Failed services ::
2249 systemclt --failed type=service
2250
2251- Show status ::
2252 systemctl status rngd.service
2253 systemctl status sshd
2254 systemctl status sshd.socket
2255
2256- active/enabled ::
2257 systemctl is-active sshd
2258 systemctl is-active sshd.socket #more specific.
2259 systemctl is-enabled sshd #.socket
2260**** References
2261systemd(1), systemd.unit(5), systemd.service(5), systemd.socket(5), and systemctl(1) man pages
2262Additional information may be available in the chapter on managing services with systemd in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2263*** Controlling System Services
2264:LOGBOOK:
2265- State "DONE" from "HOLD" [2015-07-07 Tue 11:58]
2266- State "HOLD" from "OPEN" [2015-07-06 Mon 14:06]
2267:END:
2268E.g On config changes, often want to reload a service.
2269**** Starting / Stopping / Restarting a service
2270: systemctl (start|stop|restart|reload*1) name.service
2271 1* reload doesn't stop/start, only loads config.
2272**** Enabling / Dissabling a service
2273En/Dis doesn't start/stop a service, but prevents loading on reboot.
2274: systemctl (enable|disable) UNIT
2275**** Dependencies
2276- Starting ::
2277 Starting .socket or .path starts the .service
2278
2279- Dissabling ::
2280 Dissabling .service dissables dependent .path and .socket.
2281
2282- Stopping ::
2283 All services have to be stopped manually .service .path .socket.
2284 Stopping .service does not stop .socket
2285
2286- List dependencies ::
2287 : systemctrl ... --reserve #not tested.
2288**** Masking
2289To avoid conflict (e.g services that manage a firewall), we mask services.
2290That makes them in-startable.
2291: systemctl (mask|unmask) network
2292**** References
2293systemd(1), systemd.unit(5), systemd.service(5), systemd.socket(5), and systemctl(1) man pages
2294Additional information may be available in the chapter on managing services with systemd in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2295*** The RHEL Boot Process
2296:LOGBOOK:
2297- State "DONE" from "HOLD" [2015-07-07 Tue 12:31]
2298- State "HOLD" from "OPEN" [2015-07-06 Mon 14:06]
2299:END:
2300**** Boot Process
2301> grup2-install
2302> reads:
2303 /etc/grub.d/
2304 /etc/default/grub
2305 /etc/grub2/grub.cfg (not manually)
2306
2307> load (kernel + initramfs)
2308 initramfs is a gzipped archive with kernel modules+init scripts.
2309 configured with /etc/dracut.conf
2310
2311> pass kernel paramas (linux16.. )
2312> start: /sbin/init (which contains systemd) with pid=1.
2313> mounts fs, inc /etc/fstab
2314> loads *default.target*
2315**** System Targets
2316Tree-based structure, that instructs what to load.
2317***** About
2318Target files located in:
2319/usr/lib/systemd/system
2320
2321graphical.target - all services.
2322◠└─multi-user.target - text-based
2323◠├─basic.target
2324...
2325rescue.target - basic prompt
2326emergency.target - read-only
2327
2328***** Show dependency tree
2329 : systemctl list-dependencies graphical.target | grep target
2330***** Show all targets
2331 : systemctl list-units --type=target --all
2332 : systemctl list-unit-files --type=target --all #installed on disk.
2333***** Isolate targets
2334 Select to load only certain services at run time.
2335This also means stopping non-related services.
2336E.g below kills user interface:
2337 : systemctl isolate multi-user.target
2338 Note, only 'AllowIsolate=yes' (in unit file config) can be isolated.
2339**** Setting default target
2340Default is usually a link to other target:
2341: ll /etc/systemd/system/default.target
2342: lrwxrwxrwx. 1 root root 36 May 13 2014 /etc/systemd/system/default.target -> /lib/systemd/system/graphical.target
2343
2344Can be get/set via:
2345: [root@serverX ~]# systemctl get-default
2346: multi-user.target
2347: [root@serverX ~]# systemctl set-default graphical.target
2348: rm '/etc/systemd/system/default.target'
2349: ln -s '/usr/lib/systemd/system/graphical.target' '/etc/systemd/system/default.target'
2350: [root@serverX ~]# systemctl get-default
2351: graphical.target
2352**** Selecting different target at boot time
2353- During boot, (e)dit boot option,
2354- find /linux16/ line,
2355- append: *systemd.unit=rescue.target*
2356 or '1'
2357
2358This config affects only a single boot.
2359**** References
2360bootup(7), dracut.bootup(7), systemd.target(5), systemd.special(7), sulogin(8), and systemctl(1) man pages
2361info grub2 (GNU GRUB Manual)
2362*** Reparing common Boot issues
2363:LOGBOOK:
2364- State "DONE" from "HOLD" [2015-07-07 Tue 13:20]
2365- State "HOLD" from "OPEN" [2015-07-06 Mon 14:06]
2366- State "CANC" from "PERSIST" [2015-07-06 Mon 11:50]
2367- State "WAIT" from "HOLD" [2015-07-06 Mon 11:50]
2368- State "HOLD" from "DONE" [2015-07-06 Mon 11:50]
2369- State "DONE" from "OPEN" [2015-07-06 Mon 11:46]
2370:END:
2371**** Reset root password (@ need to memorize this process).
2372- reboot system`
2373- change boot paramaters (e)dit.
2374- under 'linux16', append: *rd.break* (ram disk break).
2375- Ctrl+x
2376- Type commands ::
2377 : mount -o remount,rw /sysroot
2378 : chroot /sysroot
2379 : #1
2380 : passwd root
2381 : touch /.autorelabel #update SELinux labels.
2382
2383- ctrl+d *2 to continue boot.
2384- SELinux will take a while to re-label things.
2385**** Using journalctl to view boot log
2386- Enable persistent logging ::
2387 : [root@serverX ~]# mkdir -p -m2775 /var/log/journal
2388 : [root@serverX ~]# chown :systemd-journal /var/log/journal
2389 : [root@serverX ~]# killall -USR1 systemd-journald
2390
2391- Show log of previous boot (b-1)
2392 : journalctl -b-1 -p err
2393**** Diagonse and repair system boot issues
2394***** Early debug shell
2395Spawn a new root shell on TTY9
2396: systemctl enable debug-shell.service,
2397Switch to it:
2398 Ctrl+Alt+F9
2399(!) remember to exit it after boot.
2400***** Emergency recsue target,
2401- in boot, edit boot config,
2402- after linux16, append
2403 systemd.unit=rescue.target #basic
2404 systemd.unit=emergency.target #read only
2405***** Stuck jobs
2406List stuck jobs:
2407: systemctl list-jobs
2408seek 'waiting'
2409***** "Failed to load SELinux Policy. Freezing"
2410- Edit boot config, add 'selinux=0' to linux16 param list.
2411- boot into systtem. Reinstall package:
2412 : yum reinstall selinux-policy-targeted
2413
2414**** References
2415dracut.cmdline(7), systemd-journald(8), journalctl(1), sushell(8), and systemctl(1) man pages
2416/usr/lib/systemd/system/debug-shell.service
2417*** Repairing File System Issues at Boot
2418:LOGBOOK:
2419- State "DONE" from "HOLD" [2015-07-07 Tue 15:54]
2420- State "HOLD" from "OPEN" [2015-07-06 Mon 14:06]
2421:END:
2422Common issues that lead to "emergency shell"
2423 - Corrupt fs
2424 systemd will appemt fsck. If too serious, user is prompted.
2425 - non existing device/UUID/mount point/option in /etc/fstab
2426
2427After editing /etc/fstab , reload daemon
2428: systemctl daemon-reload
2429
2430Enabling debug shell might be useful.
2431: sudo systemctl enable debug-shell.service
2432: (Optional) systemctl start debug-shell.service
2433This enables a terminal on Ctrl+Alt+F9.
2434Remember to disable it after.
2435
2436
2437- E.g fix:
2438 - boot, edit param
2439 - linux16 >> systemd.unit=emergency.target
2440 - mount -o remount,rw /
2441 - mount -a #find broken entry
2442 - vi /etc/fstab #remove broken entry
2443
2444- E.g 2 issue
2445 : [FAILED] to mount /extras
2446 : see systemctl status extras.mount for details
2447 : # systemctl status -l extras.mount
2448 : ... issue on /dev/vdb1
2449 : blkid
2450 : edit /etc/fstab to find issues
2451 : systemctl daemon-reload
2452**** References
2453systemd-fsck(8), systemd-fstab-generator(3), and systemd.mount(5) man pages
2454*** Repairing Boot Loader Issues
2455:LOGBOOK:
2456- State "DONE" from "OPEN" [2015-07-06 Mon 16:14]
2457:END:
2458grub2 = grand unified boot loader.
2459**** Edit grub config
2460 ----- (readt from) - /etc/default/grub.cfg (config file)
2461 .
2462 grub2-mkconfig
2463 . .
2464 . .... (Writte to) /boot/grub2/grub.cfg (auto-generated)
2465 .
2466 .
2467 (uses scripts from /etc/grub.d/)
2468
2469- After editing cfg, run ::
2470 : grub2-mkconfig > /boot/grub2/grub.cfg
2471**** (re) install grub / bootloader
2472Useful when grub was wiped from the system.
2473: grub2-install
2474**** References
2475info grub2 (GNU GRUB Manual)
2476Chapter 28: "Invoking grub2-install"q
2477info grub2-install (GNU GRUB Manual)
2478** 10 Network Configuration
2479:LOGBOOK:
2480- State "DONE" from "OPEN" [2015-07-08 Wed 12:09]
2481CLOCK: [2015-07-08 Wed 11:40]--[2015-07-08 Wed 12:09] => 0:29
2482CLOCK: [2015-07-08 Wed 11:05]--[2015-07-08 Wed 11:38] => 0:33
2483CLOCK: [2015-07-08 Wed 10:21]--[2015-07-08 Wed 10:46] => 0:25
2484CLOCK: [2015-07-08 Wed 09:50]--[2015-07-08 Wed 10:15] => 0:25
2485CLOCK: [2015-07-07 Tue 16:38]--[2015-07-07 Tue 17:03] => 0:25
2486CLOCK: [2015-07-07 Tue 15:54]--[2015-07-07 Tue 16:29] => 0:35
2487CLOCK: [2015-07-06 Mon 16:43]--[2015-07-06 Mon 17:08] => 0:25
2488:END:
2489*** Validating Network Configuration
2490**** Show ip address
2491: ip addr
2492: ip addr show eth0
2493**** Show gateway
2494: route -n
2495**** Show usage
2496: ip -s link show eth0
2497**** Diagnostics
2498: ping
2499: traceroute / tracepath
2500
2501- socket ::
2502See which are in use, which are listed.
2503: ss
2504: ss -ta #shows stats
2505: ss -lt #listening TCP addresses.
2506
2507-n Show numbers instead of names for interfaces and ports.
2508-t Show TCP sockets.
2509-u Show UDP sockets.
2510-l Show only listening sockets.
2511-a Show all (listening and established) sockets.
2512-p Show the process using the sockets.
2513*** Configuring Networking with ~nmcli~
2514*device* = eth port
2515*connection* = named settings.
2516
25171 device can have many connections, but only 1 connection can be active at a time.
2518
2519~nmcli~ is a command line interface.
2520~nm-connection-editor~ is a gui for this.
2521
2522Command Use
2523nmcli dev status List all devices.
2524nmcli con show List all connections.
2525nmcli con up "<ID>" Activate a connection.
2526nmcli con down "<ID>" Deactivate a connection. The connection will restart if autoconnect is yes.
2527nmcli dev dis <DEV> Bring down an interface and temporarily disable autoconnect.
2528nmcli net off Disable all managed interfaces.
2529nmcli con add ... Add a new connection.
2530nmcli con mod "<ID>" ... Modify a connection.
2531nmcli con del "<ID>" Delete a connection.
2532
2533e.g
2534Add a connection.
2535: nmcli con add con-name "default" type ethernet ifname eth0
2536
2537Modify a connectio
2538: nmcli con mod "static" connection.autoconnect no
2539Note, after changing settings, need to activate/reactivate connection:
2540: nmcli con up "static"
2541**** References
2542nmcli(1), nmcli-examples(5), and nm-settings(5) man pages
2543Additional information may be available in the section on using the NetworkManager
2544 command line tool nmcli in the Red Hat Enterprise Linux Networking Guide
2545for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2546*** Editing Network Configuration Files
2547- Config files ::
2548 : /etc/systconfig/network-scripts/ifcfg-name
2549
2550- Configuration Options for ifcfg File ::
2551 Static
2552 BOOTPROTO=none
2553 IPADDR0=172.25.X.10
2554 PREFIX0=24
2555 GATEWAY0=172.25.X.254
2556 DEFROUTE=yes
2557 DNS1=172.25.254.254
2558
2559 Dynamic
2560 BOOTPROTO=dhcp
2561
2562 Etheir
2563 DEVICE=eth0
2564 NAME="System eth0"
2565 ONBOOT=yes
2566 UUID=f3e8dd32-3...
2567 USERCTL=yes
2568
2569- After modifying, need to reload ::
2570 : nmcli con reload
2571 : nmcli con down "eth0"
2572 : nmcli con up "eth0"
2573
2574*** Configure Host Names and Name Resolution
2575**** Hostname
2576View host name:
2577: hostname
2578
2579TMP set hostname:
2580: hostname meh
2581
2582
2583Static host name defined in:
2584: /etc/hostname
2585
2586Modify via :
2587: hostnamectl set-hostname redLeo.localdomain
2588
2589Info:
2590: hostnamectl status
2591**** dnf name resolution
2592Config file:
2593: cat /etc/hosts
2594
2595Get assiged entries: <<more reliable than ~host~
2596: getent hosts localhost
2597This queries dns server if not found locally.
2598Also :
2599: host www.google.com
2600
2601Resolve file, (it is updated by nmcli).
2602: /etc/resolv.conf
2603 domain search nameserver 10.
2604**** References
2605nmcli(1), hostnamectl(1), hosts(5), getent(1), host(1), and resolv.conf(5) man pages
2606Additional information may be available in the chapter on configuring host names in the Red Hat Enterprise Linux Networking Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2607
2608** 11 System Logging and NTP
2609:LOGBOOK:
2610- State "DONE" from "OPEN" [2015-07-09 Thu 18:20]
2611CLOCK: [2015-07-09 Thu 17:56]--[2015-07-09 Thu 18:20] => 0:24
2612CLOCK: [2015-07-09 Thu 17:23]--[2015-07-09 Thu 17:48] => 0:25
2613CLOCK: [2015-07-09 Thu 16:25]--[2015-07-09 Thu 16:50] => 0:25
2614CLOCK: [2015-07-09 Thu 15:51]--[2015-07-09 Thu 16:16] => 0:25
2615CLOCK: [2015-07-09 Thu 15:21]--[2015-07-09 Thu 15:46] => 0:25
2616CLOCK: [2015-07-09 Thu 13:56]--[2015-07-09 Thu 14:21] => 0:25
2617CLOCK: [2015-07-09 Thu 13:29]--[2015-07-09 Thu 13:54] => 0:25
2618CLOCK: [2015-07-09 Thu 12:53]--[2015-07-09 Thu 13:18] => 0:25
2619CLOCK: [2015-07-09 Thu 12:18]--[2015-07-09 Thu 12:43] => 0:25
2620CLOCK: [2015-07-09 Thu 11:20]--[2015-07-09 Thu 11:45] => 0:25
2621CLOCK: [2015-07-09 Thu 10:50]--[2015-07-09 Thu 11:15] => 0:25
2622CLOCK: [2015-07-09 Thu 09:43]--[2015-07-09 Thu 10:08] => 0:25
2623CLOCK: [2015-07-08 Wed 18:31]--[2015-07-08 Wed 18:31] => 0:00
2624CLOCK: [2015-07-08 Wed 18:03]--[2015-07-08 Wed 18:28] => 0:25
2625CLOCK: [2015-07-08 Wed 15:30]--[2015-07-08 Wed 15:55] => 0:25
2626:END:
2627*** Reading system Log files FILE__
2628Location:
2629: /var/log/*
2630
2631- Theory ::
2632 - Behaviour :
2633 ~systemd-journald~ -> passes to -> ~rsyslog~
2634 ~rsyslog~ then writes them to /var/log/messages
2635 and copies them to more specific log files like /debug
2636
2637- Log files, /var/log/... ::
2638 - messages : Most syslog messages, except more specific once.
2639 - secure
2640 - maillog
2641 - cron
2642 - boot.log #not persistent after reboot (but can be set).
2643
2644- Viewing logs ::
2645 Useful for live-tracking.
2646 : tail -f log
2647
2648- Log Priority levels ::
2649 Debugging-level message.
2650 Code Priority Severity
2651 0 emerg System is unusable.
2652 1 alert Action must be taken immediately.
2653 2 crit Critical condition.
2654 3 err Non-critical error condition.
2655 4 warning Warning condition.
2656 5 notice Normal but significant event.
2657 6 info Informational event.
2658 7 debug Debugging-level message.
2659 See man:syslog(3)
2660
2661**** References
2662systemd-journald.service(8), rsyslogd(8), and rsyslog.conf(5) man pages
2663Additional information may be available in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2664*** rsyslog : Configure filters BCMD__ FILE__
2665- Config file ::
2666: /etc/rsyslog.conf
2667
2668- Additional config files ::
2669: /etc/rsyslog.d/*
2670
2671- Rule Syntax ::
2672: (Name).(Level) /var/log/LOG-NAME
2673 Name is :
2674 user / debug/ mail etc..
2675 Level is : emerg / crit / alert etc..
2676 (see logger '-p' option & facilities).
2677
2678Service to reload after adjusting config files:
2679: systemctl restart rsyslog.service
2680
2681- logrotate ::
2682 rotates log (default every 4 weeks)
2683**** References
2684logrotate(8)
2685man:rsyslog.conf(5)
2686Extensive docu:
2687http://www.rsyslog.com/doc/master/index.html
2688
2689logger(1), tail(1), rsyslog.conf(5), and logrotate(8) man pages
2690rsyslog Manual
2691/usr/share/doc/rsyslog-*/manual.html provided by the rsyslog-doc package
2692Additional information may be available in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2693*** logger : Sending log messages manually BCMD__
2694: logger "hello world"
2695: logger -p local7.notice "boot log entry"
2696*** journalctl : Systemd Journal Entries BCMD__
2697- Limit entries ::
2698 : journalctl -n #list only last entries.
2699 : journalctl -n 5
2700
2701- Follow ::
2702 : journalctl -f #follow.
2703
2704- Filter by priority ::
2705 : journalctl -p err #show priority.
2706
2707- Since boot ::
2708 : journalctl -b #all messages since last boot.
2709 : journalctl -b -1 #previous boot with persisetent logs.
2710
2711- Since/until date ::
2712 : journalctl --since (today|yesterday|YYYY-MM-DD HH:MM:SS) --until (...)
2713 If date is ommited = today. Time is optional with date.
2714
2715- Verbose / other fields (e.g pid) ::
2716 : journalctl -o verbose #show details about each event.
2717
2718 We can use any option printed by verbose:
2719 : journalctl --since today -o verbose _PID=1727
2720 see man:systemd.journal-fields(7)
2721**** References
2722journalctl(1) and systemd.journal-fields(7) man pages
2723
2724Additional information may be available in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2725*** Persistent journaling
2726Normally, journald saves things to:
2727: /run/log/journal
2728
2729To make persistent:
27301) Make dir:
2731: /var/log/journal
27322) Make root *owner*, systemd-journal *group owner*.
2733: chown root:systemd-journal /var/log/journal
27343) Make users write, group have all perm, others read and execute
2735: chmod 2755 /var/log/journal
27364) Reboot or send USR1 signal
2737: killall -USR1 systemd-journald
27385) Verify:
2739: ll /var/log/journal
2740*** Maintaining Accurate Time
2741
2742: datetimectl CMD
2743: CMD:
2744: set-timezone
2745: set-time "YYYY-MM-DD HH:MM:SS" #can be either or both.
2746: set-ntp true|false
2747
2748: chronyd
2749
2750Servers listed in
2751: /etc/chrony.conf
2752After adjusting, restart ~systemctrl restart chronyd~
2753
2754Command line interface 'c'
2755: chronyc sources -v
2756**** References
2757timedatectl(1), tzselect(8), chronyd(8), chrony.conf(5), and chronyc(1) man pages
2758Additional information may be available in the Red Hat Enterprise Linux System Administrator's Guide for Red Hat Enterprise Linux 7, which can be found at http://docs.redhat.com/
2759NTP Pool Project
2760Time Zone Database
2761** 12 LVM
2762:LOGBOOK:
2763- State "DONE" from "OPEN" [2015-07-10 Fri 15:04]
2764CLOCK: [2015-07-10 Fri 15:02]--[2015-07-10 Fri 15:04] => 0:02
2765CLOCK: [2015-07-10 Fri 14:21]--[2015-07-10 Fri 14:46] => 0:25
2766CLOCK: [2015-07-10 Fri 13:39]--[2015-07-10 Fri 14:04] => 0:25
2767CLOCK: [2015-07-10 Fri 13:06]--[2015-07-10 Fri 13:31] => 0:25
2768CLOCK: [2015-07-10 Fri 11:55]--[2015-07-10 Fri 12:20] => 0:25
2769CLOCK: [2015-07-10 Fri 11:26]--[2015-07-10 Fri 11:51] => 0:25
2770CLOCK: [2015-07-10 Fri 10:54]--[2015-07-10 Fri 11:19] => 0:25
2771CLOCK: [2015-07-10 Fri 10:29]--[2015-07-10 Fri 10:54] => 0:25
2772CLOCK: [2015-07-09 Thu 19:49]--[2015-07-09 Thu 20:14] => 0:25
2773CLOCK: [2015-07-09 Thu 19:16]--[2015-07-09 Thu 19:41] => 0:25
2774CLOCK: [2015-07-09 Thu 18:42]--[2015-07-09 Thu 19:07] => 0:25
2775CLOCK: [2015-07-09 Thu 18:20]--[2015-07-09 Thu 18:21] => 0:01
2776:END:
2777*** Theory of LVM
2778Used to dynamically resize/move partitions. Live extending of partitions with hot-swap.
2779E.g use 3 hard drives as a single volume.
2780
2781Concepts:
2782- Physical Device :: Hard drive
2783- Physical Volume :: Volume on a hard drive
2784 - Phicial extent :: small strips of 1k/4k/64k bytes on P.V's.
2785
2786- Volume Group :: Made of one or many P.V's. Contains one or more L.V's.
2787- Logical Volume :: a logical volume, host for partitions.
2788
2789Image:
2790[[./img/img_2015_07_09__19_57_55.png]]
2791
2792- Snap shot :: read only image of volume
2793- Device mapper :: kernel module allowing use of LVM2.
2794*** Managing
2795**** Creating
27961) Create Partitions with ~fdisk~.
2797 Then set those partitions to LVM type (8e).
2798 : fdisk /dev/vdb
2799 : n ... p.... t 8e
2800 2) Create *physical volumes*
2801 : pvcreate /dev/vdb1 /dev/vdb2
2802 3) Create a *volume group*
2803 : vgcreate alphagroup /dev/vdb1 /dev/vdb2
2804 4) Create a *Logical Volume*
2805 : lvcreate -n mylv -L 2G alphagroup #n=name, L=size.
2806
2807 Now you can create fs, (note VG/LV path)
2808 : mkfs -t xfs /dev/alphagroup/mylv
2809 And make it persitent
2810 : mkdir /mnt/meh
2811 : vi /etc/fstab
2812 : +: /dev/alphagroup/mylv /mnt/meh xfs defaults 1 2
2813 : mount -a #check.
2814
2815**** Also useful
2816: fdisk -l /dev/vdb #identify if LVM type was used.
2817 : lsblk -f #info on LVM blocks also.
2818 : df -h #info on size on disks.
2819
2820**** Removing
2821: unmount /mnt/mylv
2822 : remove from /etc/fstab & check with 'mount -a'
2823 : lvremove /dev/alphagroup/mylv
2824 : vgremove alphagroup
2825 : pvremove /dev/vdb1 /dev/vdb2
2826**** Displaying
2827(pv|vg|lv)display
2828e.g
2829: pvdisplay [VOLUME]
2830**** References
2831lvm(8), pvcreate(8), vgcreate(8), lvcreate(8), pvremove(8), vgremove(8), lvremove(8), pvdisplay(8), vgdisplay(8), lvdisplay(8), fdisk(8), gdisk(8), parted(8), partprobe(8), and mkfs(8) man pages
2832*** Extending Logical Volumes
2833- Extending Logical Volume ::
2834 1) ~fdisk~ > create a new LVM partition. (8e).
2835 2) ~pvcreate~ > create P.V
2836 3) ~vgextend myvg /dev/vbc1~ Extend your V.G
2837 4) Extend Logical volume
2838 : lvextend /dev/myvg/mylv -l +100%FREE
2839 - notice '+' before 100%FREE.
2840 - '-l' indicate number of extends.
2841 - '-L' indicates size, e.g -L 2G
2842 (!) remember to extend the xfs or ext4.
2843
2844- Extend xFs or ext ::
2845 for fs specify the mount point:
2846 : xfs_growfs /mnt/myMount
2847 for ext4, specify device:
2848 : resize2fs /dev/mygv/mylv
2849
2850- Reduce Volume Group ::
2851 1) Move stuff off the pv. (!) BACKUP FIRST.
2852 : pvmove /dev/vdb2
2853 2) Reduce vg by pv
2854 : vgreduce myvg /dev/vdb2
2855
2856- See which VG P.V's are mounted on ::
2857 : pvdisplay #lists the 'VG Name' property.
2858
2859- See which P.V an L.V is maped to ::
2860 : lvdisplay -m /dev/myvg/mylv #-m = mapped.
2861
2862- Useful ::
2863 : df -h #see sizes of disks.
2864**** References
2865lvm(8), pvcreate(8), pvmove(8), vgdisplay(8), vgextend(8), vgreduce(8), vgdisplay(8), vgextend(8), vgreduce(8), lvextend(8), fdisk(8), gdisk(8), parted(8), partprobe(8), xfs_growfs(8), and resize2fs(8) man pages
2866*** Reference
2867Excellent Presentation:
2868http://www.slideshare.net/gnunify/storage-management-using-lvm
2869** 13 Cron jobs & temp files
2870:LOGBOOK:
2871- State "DONE" from "OPEN" [2015-07-13 Mon 11:07]
2872- State "DONE" from "OPEN" [2015-07-13 Mon 09:28]
2873CLOCK: [2015-07-10 Fri 16:37]--[2015-07-10 Fri 17:23] => 0:46
2874CLOCK: [2015-07-10 Fri 15:32]--[2015-07-10 Fri 15:57] => 0:25
2875CLOCK: [2015-07-10 Fri 15:04]--[2015-07-10 Fri 15:27] => 0:23
2876:END:
2877*** cron : Scheduling Cron Jobs BCMD__
2878- Through config file ::
2879: /etc/crontab
2880E.g run every 2 minutes
2881 m h d m dow usr (day of week).
2882: */2 * * * * root echo "hello" >> /home/lufimtse/tmpf
2883 ^- (!) Observe that there is a user.
2884Note: Cron re-reads the config file every minute.
2885 Thus service doesn't need to be restarted after changes.
2886
2887- By putting your scripts into directories ::
2888 : /etc/cron.* (daily|hourly|weekly|monthly)
2889 Note, your scripts must be executable (+x).
2890
2891 Additional tasks are defined via files in:
2892 : /etc/cron.d/*
2893*** Managing temporary files
2894Can create tmp files/dirs. Empty dirs, re-create files.
2895Re-apply SE permissions, make sym.links etc.
2896
2897- Cmd that creates/removes temp files ::
2898 : systemd-tmpfiles [--create | --remove]
2899 Usually runs 15 mis after boot & 1ce a day.
2900
2901- Config files ::
2902 : /etc/tmpfiles.d/*.conf # highest preceedence, admin configured.
2903 : /run/tmpfiles.d/*.conf # Volotile. Run-time used.
2904 : /usr/lib/tmpfiles.d/*.conf # used by rpm packages. Lowest preceedence.
2905
2906 Upon name conflict, etc/ is used first.
2907
2908 Type path Mode UID GID Age Argument
2909 D /run/systemd/seats 0755 root root 1d
2910 D - wipe & make dir.
2911 d - make if not exist etc..
2912 see man:tmpfiles.d(5)
2913
2914- Tip ::
2915 You often copy things form /usr/lib/tmpfiles.d/*.conf (e.g tmp.conf)
2916 to /etc/tmpfiles.d/*.conf and adjust the values to what you desire.
2917
2918 Often need to refresh:
2919 : sysdemd-tmpfiles --create my.conf
2920 : sysdemd-tmpfiles --clean my.conf
2921**** References
2922systemd-tmpfiles(8), tmpfiles.d(5), stat(1), stat(2), and systemd.timer(5) man pages
2923** 14 Mounting Network File Systems
2924:LOGBOOK:
2925- State "DONE" from "OPEN" [2015-07-13 Mon 20:22]
2926CLOCK: [2015-07-13 Mon 19:50]--[2015-07-13 Mon 20:15] => 0:25
2927CLOCK: [2015-07-13 Mon 18:17]--[2015-07-13 Mon 18:50] => 0:33
2928CLOCK: [2015-07-13 Mon 15:05]--[2015-07-13 Mon 15:30] => 0:25
2929CLOCK: [2015-07-13 Mon 14:27]--[2015-07-13 Mon 14:52] => 0:25
2930CLOCK: [2015-07-13 Mon 13:49]--[2015-07-13 Mon 14:14] => 0:25
2931CLOCK: [2015-07-13 Mon 13:10]--[2015-07-13 Mon 13:35] => 0:25
2932CLOCK: [2015-07-13 Mon 12:24]--[2015-07-13 Mon 12:49] => 0:25
2933CLOCK: [2015-07-13 Mon 11:07]--[2015-07-13 Mon 11:32] => 0:25
2934CLOCK: [2015-07-13 Mon 10:37]--[2015-07-13 Mon 11:02] => 0:25
2935CLOCK: [2015-07-13 Mon 10:08]--[2015-07-13 Mon 10:33] => 0:25
2936CLOCK: [2015-07-13 Mon 09:28]--[2015-07-13 Mon 09:53] => 0:25
2937:END:
2938*** Mounting an NFS share
2939: exportfs -s #show shares on cur system.
2940
2941- One-off mounting ::
2942 : mount server:/share /mnt/MyMountPoint
2943 With security:
2944 : mount -o sec=sys server0:/shares/manual /mnt/manual
2945
2946- Persitent mounting ::
2947 : vi /etc/fstab
2948 : vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive2 /mnt/tmp nfs sync 0 0
2949 Verify:
2950 : mount -a
2951
2952- Security ::
2953 Can enable security, useful for domain auth.
2954 none - 'nfsnobody' GID & UID.
2955 sys - default.
2956 krb5 - kerbos key. (see keytab below)
2957 krb5i - no tampering ensured.
2958 krb5p - encryped, slows performance.
2959
2960- Keytab ::
2961 Authentication key:
2962 : /etc/krb5.keytab
2963 Should contain (host principal [xor|and] nfs principal)
2964
2965- kerbors requires service ::
2966 : sudo systemctl enable nfs-secure
2967 : sudo systemctl start nfs-secure
2968 (nfs-secure is part of default-installed 'nfs-utils package).
2969*** autofs : (auto mount on demand). BCMD__ LR7
2970:PROPERTIES:
2971:ID: 23da2bcc-3135-438d-b54d-5f360fd99f12
2972:END:
2973Automatically map NFS.
2974
2975- Benifits ::
2976 - No root privildges required as for mount.
2977 - reduces resource usage
2978 - auto mounts/unmounts mount points
2979 - wild card support /*
2980
2981- Installation ::
2982 - ~autofs~ needs to be installed first.
2983
2984- Theory ::
2985 - *Relative* mappings : "hello" may refer to /automnt/hello
2986 - *Direct* mapping : may refer to any path, e.g /mnt/hello
2987
2988- Usage ::
2989 - 1) autofs config of configs ::
2990 Can be any file name, but must end with *.autofs*
2991 : vi /etc/auto.master.d/demo.autofs
2992
2993 Entries map mnt points to config files:
2994 : /automnt /etc/auto.demo #relative
2995 : #OR
2996 : /- /etc/auto.direct #direct mappings point to root '/-'
2997
2998 - 2) config files ::
2999 Relative mapping: /etc/auto.demo
3000 : hello -r,sync vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive2
3001
3002 Direct mapping: /etc/auto.direct
3003 : /mnt/isos -r,sync vtap-eng01.storage.rdu2.redhat.com:/vol/engarchive2
3004
3005 - 3) Enable/start/restart autofs service ::
3006 : systemctl (enable|start|restart) autofs.service
3007
3008 - 4) Now you should be able to navigate to mount points and they will be auto-mounted.
3009
3010- Wild-card ::
3011 E.g in auto.demo you can specify * and & to match any share on server:
3012 : * -r,sync serverX:/&
3013**** References
3014autofs(5), automount(8), auto.master(5), and mount.nfs(8) man pages
3015*** smb (windows network)
3016**** Setup
3017- packages ::
3018 : cifs-utils samba-client
3019**** mounting
3020- identify ::
3021 : smbclient -L //serverX
3022
3023- mount ::
3024 : mount -t cifs -o guest //serverX/Share /mountPt
3025
3026- mount with credentials ::
3027 - Ask for password:
3028 : mount -t cifs -o username=watson //serverX/Share /mountPt
3029 - Read credentials from file:
3030 : mount -t cifs -o credentials=/secure/creds.smb //serverX/Share /mntPt
3031 : ..
3032 : cat /secure/creds.smb
3033 : username=meh
3034 : password=mehPass
3035 : domain=mehDomain #see man 8 mount.cifs
3036
3037 Note, password file should be protected:
3038 : chmod 600 /secure/creds.smb
3039
3040- Persistent mounting ::
3041 /etc/fstab
3042 : //serverX/share /mntPt cifs guest 0 0
3043
3044 : //serverX/share /mntPt cifs credentials=/secure/creds 0 0 #NOT TESTED?
3045
3046 - note UID/GID ::
3047 UID / GID numbers should match on server.
3048**** Auto mounting smb with autofs
3049Almost same as regular autofs, except you need to specify
3050- *-fstype=cifs*
3051- credentials file
3052- '://' (colon) in front of server.
3053
3054- Config of config ::
3055 : /etc/auto.master.d/smb.autofs
3056 : cat smb.autofs
3057 : /autosmb/ /etc/auto.smb
3058
3059- Config auto.smb ::
3060 Note the ':' in front of server name:
3061 : myShare -fstype=cifs,credentials=/secure/myCreds ://serverX/myShare
3062 : myShare -fstype=cifs,guest ://serverX/myShare
3063
3064- enable/restart 'autofs' service
3065**** References
3066mount(8), umount(8), fstab(5), mount.cifs(8), smbclient(1), autofs(5), automount(8), and auto.master(5) man pages
3067** 15 Firewall Configuration
3068:LOGBOOK:
3069- State "DONE" from "OPEN" [2015-07-14 Tue 14:02]
3070CLOCK: [2015-07-14 Tue 13:40]--[2015-07-14 Tue 14:02] => 0:22
3071CLOCK: [2015-07-14 Tue 11:19]--[2015-07-14 Tue 11:44] => 0:25
3072CLOCK: [2015-07-14 Tue 10:51]--[2015-07-14 Tue 11:16] => 0:25
3073CLOCK: [2015-07-14 Tue 10:41]--[2015-07-14 Tue 10:41] => 0:00
3074CLOCK: [2015-07-14 Tue 10:12]--[2015-07-14 Tue 10:37] => 0:25
3075CLOCK: [2015-07-14 Tue 09:42]--[2015-07-14 Tue 10:07] => 0:25
3076CLOCK: [2015-07-13 Mon 20:22]--[2015-07-13 Mon 20:47] => 0:25
3077CLOCK: [2015-07-13 Mon 17:25]--[2015-07-13 Mon 18:12] => 0:47
3078:END:
3079*** Zones
3080Default permitted:
3081 - All incomming that were requested by system.
3082 - All outgoing.
3083
3084- 3 Methods to interact with Firewall ::
3085 - Edit config files /etc/firewalld/ (not covered)
3086 - ~firewall-config~ GUI tool.
3087 - ~firewall-cmd~
3088
3089
3090- list of zones ::
3091 man:firewalld.zones(5)
3092 e.g "drop" drops all incomming packets.
3093 "home" permissive..
3094
3095- Services ::
3096 man:firewalld.service(5)
3097 (see for links to xml files)
3098
3099- GUI ::
3100 : firewall-config
3101 If I forget, it's easy to find via man-pages:
3102 apropos -a firewall gui`
3103
3104- firewall-cmd ::
3105 - add '--permenent' to apply to config.
3106 - often have to to specify '--zone=<zone>' to apply to a zone.
3107 man:firewall-cmd
3108 : firewall-cmd --get-services
3109
3110 : --get-default-zone
3111 : --set-default-zone
3112 : --get-zones
3113
3114 : --list-all # list all interfaces with zones applied to them.
3115
3116 : --(add|remove)-(service|port)=(SERVICE|PORT) #add/remove, use default zone if none specified.
3117
3118 : --reload #drop run time, load persistent config.
3119
3120- Example ::
3121 All traffic from 192.. assigned to internal zone. Open port on internal zone.
3122 : firewall-cmd --set-default-zone=dmz
3123 : firewall-cmd --permenent --zone=internal --add-sonurce=192.168.0.0/24
3124 : firewall-cmd --permenent --zone=internal --add-service=mysql
3125 : firewall-cmd --reload
3126** 16 Virtualization and Kickstart
3127:LOGBOOK:
3128- State "DONE" from "OPEN" [2015-07-14 Tue 17:32]
3129CLOCK: [2015-07-14 Tue 16:48]--[2015-07-14 Tue 17:25] => 0:37
3130CLOCK: [2015-07-14 Tue 16:16]--[2015-07-14 Tue 16:41] => 0:25
3131CLOCK: [2015-07-14 Tue 15:46]--[2015-07-14 Tue 16:11] => 0:25
3132CLOCK: [2015-07-14 Tue 15:02]--[2015-07-14 Tue 15:27] => 0:25
3133CLOCK: [2015-07-14 Tue 14:30]--[2015-07-14 Tue 14:55] => 0:25
3134:END:
3135*** Kickstart
3136Kickstart is for automated installs for RHEL.
3137
3138GUI Package:
3139: system-config-kickstart
3140
3141Base config:
3142: /root/anaconda-ks.cfg
3143
3144Validate a ks file :
3145: ksvalidator /tmp/anaconda-ks.cfg
3146
3147Publish config to Anaconda:
3148 - Far: FTP | NFS |HTTP
3149 - Near: DHCP | TFTP
3150 - Local: USB | CD | Local disk.
3151
3152- Point anacondoa to location ::
3153 Need to append ~ks=LOCATION~ to linux kernel.
3154
3155 ks=http://server/dir/file
3156 ks=nfs:server:/dir/file
3157 ks=hd:device:/dir/file
3158*** Virtualization
3159- GUI ::
3160 : virt-manager
3161- CMD tool ::
3162 Does what gui tool does, but through the cmd.
3163 : virsh #enter inteactive prompt.
3164
3165 : virsh list #list turned on/off vm's.
3166 : virsh destory server
3167 : virsh start server
3168** Study Checklist
3169:LOGBOOK:
3170CLOCK: [2015-07-30 Thu 15:33]--[2015-07-30 Thu 15:58] => 0:25
3171CLOCK: [2015-07-30 Thu 14:49]--[2015-07-30 Thu 15:14] => 0:25
3172CLOCK: [2015-07-30 Thu 14:02]--[2015-07-30 Thu 14:27] => 0:25
3173CLOCK: [2015-07-30 Thu 13:20]--[2015-07-30 Thu 13:45] => 0:25
3174CLOCK: [2015-07-30 Thu 12:19]--[2015-07-30 Thu 12:44] => 0:25
3175CLOCK: [2015-07-30 Thu 11:45]--[2015-07-30 Thu 12:10] => 0:25
3176CLOCK: [2015-07-30 Thu 10:58]--[2015-07-30 Thu 11:23] => 0:25
3177CLOCK: [2015-07-30 Thu 09:47]--[2015-07-30 Thu 10:12] => 0:25
3178CLOCK: [2015-07-30 Thu 09:15]--[2015-07-30 Thu 09:40] => 0:25
3179:END:
3180*** DONE Understand and use essential tools
3181CLOSED: [2015-07-29 Wed 21:31]
3182:LOGBOOK:
3183- State "DONE" from "OPEN" [2015-07-29 Wed 21:31]
3184CLOCK: [2015-07-29 Wed 17:57]--[2015-07-29 Wed 18:16] => 0:19
3185CLOCK: [2015-07-27 Mon 21:00]--[2015-07-27 Mon 21:25] => 0:25
3186CLOCK: [2015-07-27 Mon 20:42]--[2015-07-27 Mon 20:52] => 0:10
3187CLOCK: [2015-07-27 Mon 20:10]--[2015-07-27 Mon 20:13] => 0:03
3188CLOCK: [2015-07-27 Mon 19:48]--[2015-07-27 Mon 20:10] => 0:22
3189:END:
3190- [X] Access a shell prompt and issue commands with correct syntax
3191- [X] Use input-output redirection (>, >>, |, 2>, etc.)
3192- [X] Use grep and regular expressions to analyze text
3193- [X] Access remote systems using ssh
3194- [X] Log in and switch users in multiuser targets
3195- [X] Archive, compress, unpack, and uncompress files using tar, star, gzip, and bzip2
3196- [X] Create and edit text files
3197- [X] Create, delete, copy, and move files and directories
3198- [X] Create hard and soft links
3199- [X] List, set, and change standard ugo/rwx permissions
3200- [X] Locate, read, and use system documentation including man, info, and files in /usr/share/doc
3201*** DONE Manage users and groups
3202CLOSED: [2015-07-29 Wed 21:31]
3203:LOGBOOK:
3204- State "DONE" from "OPEN" [2015-07-29 Wed 21:31]
3205CLOCK: [2015-07-29 Wed 20:07]--[2015-07-29 Wed 20:32] => 0:25
3206CLOCK: [2015-07-29 Wed 19:35]--[2015-07-29 Wed 20:00] => 0:25
3207CLOCK: [2015-07-29 Wed 18:16]--[2015-07-29 Wed 18:22] => 0:06
3208:END:
3209- [X] Create, delete, and modify local user accounts
3210- [X] Change passwords and adjust password aging for local user accounts
3211- [X] Create, delete, and modify local groups and group memberships
3212- [X] Configure a system to use an existing authentication service for user and group information
3213*** DONE Manage security
3214CLOSED: [2015-07-30 Thu 15:12]
3215:LOGBOOK:
3216- State "DONE" from "OPEN" [2015-07-30 Thu 15:12]
3217:END:
3218- [X] Configure firewall settings using firewall-config, firewall-cmd, or iptables
3219- [X] Configure key-based authentication for SSH
3220- [X] Set enforcing and permissive modes for SELinux
3221- [X] List and identify SELinux file and process context
3222- [X] Restore default file contexts
3223- [X] Use boolean settings to modify system SELinux settings
3224- [X] Diagnose and address routine SELinux policy violations
3225*** Operate running systems
3226- [X] Boot, reboot, and shut down a system normally
3227- [ ] Boot systems into different targets manually
3228- [ ] Interrupt the boot process in order to gain access to a system
3229- [ ] Identify CPU/memory intensive processes, adjust process priority with renice, and kill processes
3230- [ ] Locate and interpret system log files and journals
3231- [X] Access a virtual machine's console
3232- [X] Start and stop virtual machines
3233- [ ] Start, stop, and check the status of network services
3234- [ ] Securely transfer files between systems
3235*** Configure local storage
3236:LOGBOOK:
3237CLOCK: [2015-07-30 Thu 16:42]
3238:END:
3239- [X] List, create, delete partitions on MBR and GPT disks
3240- [ ] Create and remove physical volumes, assign physical volumes to volume groups, and create and delete logical volumes
3241- [ ] Configure systems to mount file systems at boot by Universally Unique ID (UUID) or label
3242- [ ] Add new partitions and logical volumes, and swap to a system non-destructively
3243*** Create and configure file systems
3244- [X] Create, mount, unmount, and use vfat, ext4, and xfs file systems
3245- [ ] Mount and unmount CIFS and NFS network file systems
3246- [ ] Extend existing logical volumes
3247- [X] Create and configure set-GID directories for collaboration
3248- [X] Create and manage Access Control Lists (ACLs)
3249- [X] Diagnose and correct file permission problems
3250*** Deploy, configure, and maintain systems
3251- [ ] Configure networking and hostname resolution statically or dynamically
3252- [ ] Schedule tasks using at and cron
3253- [ ] Start and stop services and configure services to start automatically at boot
3254- [ ] Configure systems to boot into a specific target automatically
3255- [ ] Install Red Hat Enterprise Linux automatically using Kickstart
3256- [ ] Configure a physical machine to host virtual guests
3257- [ ] Install Red Hat Enterprise Linux systems as virtual guests
3258- [ ] Configure systems to launch virtual machines at boot
3259- [ ] Configure network services to start automatically at boot
3260- [ ] Configure a system to use time services
3261- [ ] Install and update software packages from Red Hat Network, a remote repository, or from the local file system
3262- [ ] Update the kernel package appropriately to ensure a bootable system
3263- [ ] Modify the system bootloader
3264** Appendix
3265*** Various Terms
3266**** Kerberos (protocol) :TERM__:
3267:PROPERTIES:
3268:ID: bd6076d5-7aff-4e51-b3d0-f55685dd2415
3269:END:
3270Kerberos is a protocol with security.
3271
3272- *Protected* with symmetric key cryptography. Optionally with public-key.
3273- Client <-> Server oriented
3274- Protected against
3275 * evesdropping
3276 * replay attacks
3277subscription-manager attach --auto* OS-Specific
3278** References
3279*** All Red Hat Product documentation.
3280https://access.redhat.com/documentation/en-US/