· 11 years ago · Jul 06, 2015, 08:08 PM
1###################################################################################################
2################################################# SERVIDOR 1 -{
3####################################### NETWORK -{
4
5cd
6
7service network stop
8
9ip addr
10
11vim /etc/sysconfig/network-scripts/ifcfg-eth0
12
13############################# ifcfg-eth0 -{ #############################
14DEVICE=eth0
15NAME=eth0
16TYPE=Ethernet
17NM_CONTROLLED=yes
18ONBOOT=yes
19IPV6INIT=no
20USERCTL=no
21BOOTPROTO=dhcp
22HWADDR=08:00:27:FF:FF:11
23############################# }- ifcfg-eth0 #############################
24
25vim /etc/sysconfig/network-scripts/ifcfg-eth1
26
27############################# ifcfg-eth1 -{ #############################
28DEVICE=eth1
29NAME=eth1
30TYPE=Ethernet
31NM_CONTROLLED=yes
32ONBOOT=yes
33IPV6INIT=no
34USERCTL=no
35BOOTPROTO=dhcp
36HWADDR=08:00:27:FF:FF:12
37############################# }- ifcfg-eth1 #############################
38
39vim /etc/sysconfig/network-scripts/ifcfg-eth2
40
41############################# ifcfg-eth2 -{ #############################
42DEVICE=eth2
43NAME=eth2
44TYPE=Ethernet
45NM_CONTROLLED=yes
46ONBOOT=yes
47IPV6INIT=no
48USERCTL=no
49BOOTPROTO=dhcp
50HWADDR=08:00:27:FF:FF:13
51############################# }- ifcfg-eth2 #############################
52
53vim /etc/sysconfig/network-scripts/ifcfg-eth3
54
55############################# ifcfg-eth3 -{ #############################
56DEVICE=eth3
57NAME=eth3
58TYPE=Ethernet
59NM_CONTROLLED=yes
60ONBOOT=yes
61IPV6INIT=no
62USERCTL=no
63BOOTPROTO=dhcp
64HWADDR=08:00:27:FF:FF:14
65############################# }- ifcfg-eth3 #############################
66
67service network restart
68chkconfig network on
69
70echo "1" > /proc/sys/net/ipv4/ip_forward
71sysctl -w net.ipv4.ip_forward=1
72
73dhclient eth0
74dhclient eth1
75dhclient eth2
76dhclient eth3
77
78vim /etc/selinux/config
79
80############################# config -{ #############################
81# This file controls the state of SELinux on the system.
82# SELINUX= can take one of these three values:
83# enforcing - SELinux security policy is enforced.
84# permissive - SELinux prints warnings instead of enforcing.
85# disabled - No SELinux policy is loaded.
86SELINUX=enforcing
87# SELINUXTYPE= can take one of these two values:
88# targeted - Targeted processes are protected,
89# mls - Multi Level Security protection.
90SELINUXTYPE=targeted
91############################# }- config #############################
92
93vim /etc/resolv.conf
94
95############################# resolv.conf -{ #############################
96; generated by /sbin/dhclient-script
97search alfacorpltda.cl
98nameserver 172.16.8.11
99############################# }- resolv.conf #############################
100
101cd
102
103#system-config-firewall
104
105vim /etc/sysconfig/iptables
106
107############################# iptables -{ #############################
108# Generated by iptables-save v1.4.7 on Thu May 31 00:00:00 2015
109*filter
110:INPUT ACCEPT [0:0]
111:FORWARD ACCEPT [0:0]
112:OUTPUT ACCEPT [0:0]
113-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
114-A INPUT -p icmp -j ACCEPT
115-A INPUT -i lo -j ACCEPT
116-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
117#x# Agregar -{
118-A INPUT -p tcp -m tcp --dport 10000 -j ACCEPT
119-A INPUT -m state --state NEW -m udp -p udp --dport 514 -j ACCEPT
120-A INPUT -m state --state NEW -m tcp -p tcp --dport 514 -j ACCEPT
121-A INPUT -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
122-A INPUT -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
123-A INPUT -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
124-A INPUT -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
125-A INPUT -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
126-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
127-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
128-A INPUT -m state --state NEW -m tcp -p tcp --dport 20 -j ACCEPT
129-A INPUT -m state --state NEW -m tcp -p tcp --dport 21 -j ACCEPT
130-A INPUT -m state --state NEW -m tcp -p tcp --dport 30300:30309 -j ACCEPT
131-A INPUT -p udp -m udp --dport 5060 -j ACCEPT
132-A INPUT -p tcp -m tcp --dport 5060 -j ACCEPT
133-A INPUT -p tcp -m state --state NEW -m tcp --dport 3128 -j ACCEPT
134#x# }- Agregar
135-A INPUT -j REJECT --reject-with icmp-host-prohibited
136-A FORWARD -j REJECT --reject-with icmp-host-prohibited
137COMMIT
138# Completed on Thu May 31 00:00:00 2015
139############################# }- iptables #############################
140
141service iptables restart
142chkconfig iptables on
143
144####################################### }- NETWORK
145####################################### RESPOSITORY -{
146
147cd
148
149mkdir /media/RHEL_6.0\ i386\ Disc\ 1/
150mount -t iso9660 -o ro /dev/cdrom /media/RHEL_6.0\ i386\ Disc\ 1/
151
152rm -rf /etc/yum.repos.d/rhel.repo/*
153
154vim /etc/yum.repos.d/rhel.repo
155
156############################# rhel.repo -{ #############################
157[rhel-repo]
158name=RHEL Repository
159metadata=yum
160baseurl=file:///media/RHEL_6.0\ i386\ Disc\ 1/
161enabled=1
162gpgcheck=1
163gpgkey=file:///media/RHEL_6.0\ i386\ Disc\ 1/RPM-GPG-KEY-redhat-release
164############################# }- rhel.repo #############################
165
166####################################### }- RESPOSITORY
167####################################### WEBMIN -{
168
169cd
170
171yum -y install perl perl-Net-SSLeay openssl perl-IO-*
172rpm -ivhU webmin-1.750-1.noarch.rpm
173
174service webmin start
175chkconfig webmin on
176
177## https://localhost:10000/
178
179####################################### }- WEBMIN
180####################################### SARG -{
181
182cd
183
184rpm -ivhU sarg-2.3.1-1.el6.rft.i686.rpm
185
186vim /etc/sarg/sarg.conf
187
188############################# sarg.conf -{ #############################
189# sarg.conf
190#
191# TAG: access_log file
192# Where is the access.log file
193# sarg -l file
194#
195#access_log /usr/local/squid/var/logs/access.log
196access_log /var/log/squid/access.log
197
198# TAG: graphs yes|no
199# Use graphics where is possible.
200# graph_days_bytes_bar_color blue|green|yellow|orange|brown|red
201#
202#graphs yes
203#graph_days_bytes_bar_color orange
204
205# TAG: graph_font
206# The full path to the TTF font file to use to create the graphs. It is required
207# if graphs is set to yes.
208#
209#graph_font /usr/share/fonts/truetype/ttf-dejavu/DejaVuSans.ttf
210
211# TAG: title
212# Especify the title for html page.
213#
214#title "Squid User Access Reports"
215
216# TAG: font_face
217# Especify the font for html page.
218#
219#font_face Tahoma,Verdana,Arial
220
221# TAG: header_color
222# Especify the header color
223#
224#header_color darkblue
225
226# TAG: header_bgcolor
227# Especify the header bgcolor
228#
229#header_bgcolor blanchedalmond
230
231# TAG: font_size
232# Especify the text font size
233#
234#font_size 9px
235
236# TAG: header_font_size
237# Especify the header font size
238#
239#header_font_size 9px
240
241# TAG: title_font_size
242# Especify the title font size
243#
244#title_font_size 11px
245
246# TAG: background_color
247# TAG: background_color
248# Html page background color
249#
250# background_color white
251
252# TAG: text_color
253# Html page text color
254#
255#text_color #000000
256
257# TAG: text_bgcolor
258# Html page text background color
259#
260#text_bgcolor lavender
261
262# TAG: title_color
263# Html page title color
264#
265#title_color green
266
267# TAG: logo_image
268# Html page logo.
269#
270#logo_image none
271
272# TAG: logo_text
273# Html page logo text.
274#
275#logo_text ""
276
277# TAG: logo_text_color
278# Html page logo texti color.
279#
280#logo_text_color #000000
281
282# TAG: logo_image_size
283# Html page logo image size.
284# width height
285#
286#image_size 80 45
287
288# TAG: background_image
289# Html page background image
290#
291#background_image none
292
293# TAG: password
294# User password file used by Squid authentication scheme
295# If used, generate reports just for that users.
296#
297#password none
298
299# TAG: temporary_dir
300# Temporary directory name for work files
301# sarg -w dir
302#
303#temporary_dir /tmp
304
305# TAG: output_dir
306# The reports will be saved in that directory
307# sarg -o dir
308#
309#output_dir /var/www/html/squid-reports
310output_dir /var/www/sarg/ONE-SHOT
311
312# TAG: output_email
313# Email address to send the reports. If you use this tag, no html reports will be generated.
314# sarg -e email
315#
316#output_email none
317
318# TAG: resolve_ip yes/no
319# Convert ip address to dns name
320# sarg -n
321#resolve_ip no
322resolve_ip yes
323
324# TAG: user_ip yes/no
325# Use Ip Address instead userid in reports.
326# sarg -p
327#user_ip no
328
329# TAG: topuser_sort_field field normal/reverse
330# Sort field for the Topuser Report.
331# Allowed fields: USER CONNECT BYTES TIME
332#
333#topuser_sort_field BYTES reverse
334
335# TAG: user_sort_field field normal/reverse
336# Sort field for the User Report.
337# Allowed fields: SITE CONNECT BYTES TIME
338#
339#user_sort_field BYTES reverse
340
341# TAG: exclude_users file
342# users within the file will be excluded from reports.
343# you can use indexonly to have only index.html file.
344#
345#exclude_users none
346
347# TAG: exclude_hosts file
348# Hosts, domains or subnets will be excluded from reports.
349#
350# Eg.: 192.168.10.10 - exclude ip address only
351# 192.168.10.0/24 - exclude full C class
352# s1.acme.foo - exclude hostname only
353# *.acme.foo - exclude full domain name
354#
355#exclude_hosts none
356
357# TAG: useragent_log file
358# useragent.log file patch to generate useragent report.
359#
360#useragent_log none
361
362# TAG: date_format
363# Date format in reports: e (European=dd/mm/yy), u (American=mm/dd/yy), w (Weekly=yy.ww)
364#
365#date_format u
366
367# TAG: per_user_limit file MB
368# Saves userid on file if download exceed n MB.
369# This option allow you to disable user access if user exceed a download limit.
370#
371#per_user_limit none
372
373# TAG: lastlog n
374# How many reports files must be keept in reports directory.
375# The oldest report file will be automatically removed.
376# 0 - no limit.
377#
378#lastlog 0
379#x#
380lastlog 30
381
382# TAG: remove_temp_files yes
383# Remove temporary files: geral, usuarios, top, periodo from root report directory.
384#
385#remove_temp_files yes
386
387# TAG: index yes|no|only
388# Generate the main index.html.
389# only - generate only the main index.html
390#
391#index yes
392
393# TAG: index_tree date|file
394# How to generate the index.
395#
396#index_tree file
397
398# TAG: overwrite_report yes|no
399# yes - if report date already exist then will be overwrited.
400# no - if report date already exist then will be renamed to filename.n, filename.n+1
401#
402#overwrite_report no
403
404# TAG: records_without_userid ignore|ip|everybody
405# What can I do with records without user id (no authentication) in access.log file ?
406#
407# ignore - This record will be ignored.
408# ip - Use ip address instead. (default)
409# everybody - Use "everybody" instead.
410#
411#records_without_userid ip
412
413# TAG: use_comma no|yes
414# Use comma instead point in reports.
415# Eg.: use_comma yes => 23,450,110
416# use_comma no => 23.450.110
417#
418#use_comma no
419
420# TAG: mail_utility
421# Mail command to use to send reports via SMTP. Sarg calls it like this:
422# mail_utility -s "SARG report, date" "output_email" <"mail_content"
423#
424# Therefore, it is possible to add more arguments to the command by specifying them
425# here.
426#
427# If you need too, you can use a shell script to process the content of /dev/stdin
428# (/dev/stdin is the mail_content passed by sarg to the script) and call whatever
429# command you like. It is not limited to mailing the report via SMTP.
430#
431# Don't forget to quote the command if necessary (i.e. if the path contains
432# characters that must be quoted).
433#
434#mail_utility mailx
435mail_utility mail
436
437# TAG: topsites_num n
438# How many sites in topsites report.
439#
440#topsites_num 100
441
442# TAG: topsites_sort_order CONNECT|BYTES A|D
443# Sort for topsites report, where A=Ascendent, D=Descendent
444#
445#topsites_sort_order CONNECT D
446
447# TAG: index_sort_order A/D
448# Sort for index.html, where A=Ascendent, D=Descendent
449#
450#index_sort_order D
451
452# TAG: exclude_codes file
453# Ignore records with these codes. Eg.: NONE/400
454# Write one code per line. Lines starting with a # are ignored.
455# Only codes matching exactly one of the line is rejected. The
456# comparison is not case sensitive.
457#
458#exclude_codes /usr/local/sarg/exclude_codes
459
460# TAG: replace_index string
461# Replace "index.html" in the main index file with this string
462# If null "index.html" is used
463#
464#replace_index <?php echo str_replace(".", "_", $REMOTE_ADDR); echo ".html"; ?>
465
466# TAG: max_elapsed milliseconds
467# If elapsed time is recorded in log is greater than max_elapsed use 0 for elapsed time.
468# Use 0 for no checking
469#
470#max_elapsed 28800000
471# 8 Hours
472
473# TAG: report_type type
474# What kind of reports to generate.
475# topusers - users, sites, times, bytes, connects, links to accessed sites, etc
476# topsites - site, connect and bytes report
477# sites_users - users and sites report
478# users_sites - accessed sites by the user report
479# date_time - bytes used per day and hour report
480# denied - denied sites with full URL report
481# auth_failures - autentication failures report
482# site_user_time_date - sites, dates, times and bytes report
483# downloads - downloads per user report
484#
485# Eg.: report_type topsites denied
486#
487#report_type topusers topsites sites_users users_sites date_time denied auth_failures site_user_time_date downloads
488
489# TAG: usertab filename
490# You can change the "userid" or the "ip address" to be a real user name on the reports.
491# If resolve_ip is active, the ip address is resolved before being looked up into this
492# file. That is, if you want to map the ip address, be sure to set resolv_ip to no or
493# the resolved name will be looked into the file instead of the ip address. Note that
494# it can be used to resolve any ip address known to the dns and then map the unresolved
495# ip addresses to a name found in the usertab file.
496# Table syntax:
497# userid name or ip address name
498# Eg:
499# SirIsaac Isaac Newton
500# vinci Leonardo da Vinci
501# 192.168.10.1 Karol Wojtyla
502#
503# Each line must be terminated with '\n'
504# If usertab have value "ldap" (case ignoring), user names
505# will be taken from LDAP server. This method as approaches for reception
506# of usernames from Active Didectory
507#
508#usertab none
509
510# TAG: LDAPHost hostname
511# FQDN or IP address of host with LDAP service or AD DC
512# default is '127.0.0.1'
513#LDAPHost 127.0.0.1
514
515# TAG: LDAPPort port
516# LDAP service port number
517# default is '389'
518#LDAPPort 389
519
520# TAG: LDAPBindDN CN=username,OU=group,DC=mydomain,DC=com
521# DN of LDAP user, who is authorized to read user's names from LDAP base
522# default is empty line
523#LDAPBindDN cn=proxy,dc=mydomain,dc=local
524
525# TAG: LDAPBindPW secret
526# Password of DN, who is authorized to read user's names from LDAP base
527# default is empty line
528#LDAPBindPW secret
529
530# TAG: LDAPBaseSearch OU=users,DC=mydomain,DC=com
531# LDAP search base
532# default is empty line
533#LDAPBaseSearch ou=users,dc=mydomain,dc=local
534
535# TAG: LDAPFilterSearch (uid=%s)
536# User search filter by user's logins in LDAP
537# First founded record will be used
538# %s - will be changed to userlogins from access.log file
539# filter string can have up to 5 '%s' tags
540# default value is '(uid=%s)'
541#LDAPFilterSearch (uid=%s)
542
543# TAG: LDAPTargetAttr attributename
544# Name of the attribute containing a name of the user
545# default value is 'cn'
546#LDAPTargetAttr cn
547
548# TAG: long_url yes|no
549# If yes, the full url is showed in report.
550# If no, only the site will be showed
551#
552# YES option generate very big sort files and reports.
553#
554#long_url no
555
556# TAG: date_time_by bytes|elap
557# Date/Time reports show the downloaded volume or the elapsed time or both.
558#
559#date_time_by bytes
560
561# TAG: charset name
562# ISO 8859 is a full series of 10 standardized multilingual single-byte coded (8bit)
563# graphic character sets for writing in alphabetic languages
564# You can use the following charsets:
565# Latin1 - West European
566# Latin2 - East European
567# Latin3 - South European
568# Latin4 - North European
569# Cyrillic
570# Arabic
571# Greek
572# Hebrew
573# Latin5 - Turkish
574# Latin6
575# Windows-1251
576# Japan
577# Koi8-r
578# UTF-8
579#
580#charset Latin1
581
582# TAG: user_invalid_char "&/"
583# Records that contain invalid characters in userid will be ignored by Sarg.
584#
585#user_invalid_char "&/"
586
587# TAG: privacy yes|no
588# privacy_string "***.***.***.***"
589# privacy_string_color blue
590# In some countries the sysadm cannot see the visited sites by a restrictive law.
591# Using privacy yes the visited url will be changes by privacy_string and the link
592# will be removed from reports.
593#
594#privacy no
595#privacy_string "***.***.***.***"
596#privacy_string_color blue
597
598# TAG: include_users "user1:user2:...:usern"
599# Reports will be generated only for listed users.
600#
601#include_users none
602
603# TAG: exclude_string "string1:string2:...:stringn"
604# Records from access.log file that contain one of listed strings will be ignored.
605#
606#exclude_string none
607
608# TAG: show_successful_message yes|no
609# Shows "Successful report generated on dir" at end of process.
610#
611#show_successful_message yes
612show_successful_message no
613
614# TAG: show_read_statistics yes|no
615# Shows some reading statistics.
616#
617#show_read_statistics yes
618
619# TAG: topuser_fields
620# Which fields must be in Topuser report.
621#
622#topuser_fields NUM DATE_TIME USERID CONNECT BYTES %BYTES IN-CACHE-OUT USED_TIME MILISEC %TIME TOTAL AVERAGE
623
624# TAG: user_report_fields
625# Which fields must be in User report.
626#
627#user_report_fields CONNECT BYTES %BYTES IN-CACHE-OUT USED_TIME MILISEC %TIME TOTAL AVERAGE
628
629# TAG: bytes_in_sites_users_report yes|no
630# Bytes field must be in Site & Users Report ?
631#
632#bytes_in_sites_users_report no
633
634# TAG: topuser_num n
635# How many users in topsites report. 0 = no limit
636#
637#topuser_num 0
638
639# TAG: datafile file
640# Save the report results in a file to populate some database
641#
642#datafile none
643
644# TAG: datafile_delimiter ";"
645# ascii character to use as a field separator in datafile
646#
647#datafile_delimiter ";"
648
649# TAG: datafile_fields all
650# Which data fields must be in datafile
651# user;date;time;url;connect;bytes;in_cache;out_cache;elapsed
652#
653#datafile_fields user;date;time;url;connect;bytes;in_cache;out_cache;elapsed
654
655# TAG: datafile_url ip|name
656# Saves the URL as ip or name in datafile
657#
658#datafile_url ip
659
660# TAG: weekdays
661# The weekdays to take into account ( Sunday->0, Saturday->6 )
662# Example:
663#weekdays 1-3,5
664# Default:
665#weekdays 0-6
666
667# TAG: hours
668# The hours to take into account
669# Example:
670#hours 7-12,14,16,18-20
671# Default:
672#hours 0-23
673
674# TAG: dansguardian_conf file
675# DansGuardian.conf file path
676# Generate reports from DansGuardian logs.
677# Use 'none' to disable it.
678# dansguardian_conf /usr/dansguardian/dansguardian.conf
679#
680#dansguardian_conf none
681
682# TAG: dansguardian_filter_out_date on|off
683# This option replaces dansguardian_ignore_date whose name was not appropriate with respect to its action.
684# Note the change of parameter value compared with the old option.
685# 'off' use the record even if its date is outside of the range found in the input log file.
686# 'on' use the record only if its date is in the range found in the input log file.
687#
688#dansguardian_filter_out_date on
689
690# TAG: squidguard_conf file
691# path to squidGuard.conf file
692# Generate reports from SquidGuard logs.
693# Use 'none' to disable.
694# You can use sarg -L filename to use an alternate squidGuard log.
695# squidguard_conf /usr/local/squidGuard/squidGuard.conf
696#
697#squidguard_conf none
698
699# TAG: redirector_log file
700# the location of the web proxy redirector log such as one created by squidGuard or Rejik. The option
701# may be repeated up to 64 times to read multiple files.
702# If this option is specified, it takes precedence over squidguard_conf.
703# The command line option -L override this option.
704#
705#redirector_log /usr/local/squidGuard/var/logs/urls.log
706
707# TAG: redirector_filter_out_date on|off
708# This option replaces squidguard_ignore_date and redirector_ignore_date whose names were not
709# appropriate with respect to their action.
710# Note the change of parameter value compared with the old options.
711# 'off' use the record even if its date is outside of the range found in the input log file.
712# 'on' use the record only if its date is in the range found in the input log file.
713#
714#redirector_filter_out_date on
715
716# TAG: redirector_log_format
717# Format string for web proxy redirector logs.
718# This option was named squidguard_log_format before sarg 2.3.
719# REJIK #year#-#mon#-#day# #hour# #list#:#tmp# #ip# #user# #tmp#/#tmp#/#url#/#end#
720# SQUIDGUARD #year#-#mon#-#day# #hour# #tmp#/#list#/#tmp#/#tmp#/#url#/#tmp# #ip#/#tmp# #user# #end#
721#redirector_log_format #year#-#mon#-#day# #hour# #tmp#/#list#/#tmp#/#tmp#/#url#/#tmp# #ip#/#tmp# #user# #end#
722
723# TAG: show_sarg_info yes|no
724# shows sarg information and site path on each report bottom
725#
726#show_sarg_info yes
727
728# TAG: show_sarg_logo yes|no
729# shows sarg logo
730#
731#show_sarg_logo yes
732
733# TAG: parsed_output_log directory
734# Saves the processed log in a sarg format after parsing the squid log file.
735# This is a way to dump all of the data structures out, after parsing from
736# the logs (presumably this data will be much smaller than the log files themselves),
737# and pull them back in for later processing and merging with data from previous logs.
738#
739#parsed_output_log none
740
741# TAG: parsed_output_log_compress /bin/gzip|/usr/bin/bzip2|nocompress
742# Command to run to compress sarg parsed output log. It may contain
743# options (such as -f to overwrite existing target file). The name of
744# the file to compresse is provided at the end of this
745# command line. Don't forget to quote things appropriately.
746#
747#parsed_output_log_compress /bin/gzip
748
749# TAG: displayed_values bytes|abbreviation
750# how the values will be displayed in reports.
751# eg. bytes - 209.526
752# abbreviation - 210K
753#
754#displayed_values bytes
755
756# Report limits
757# TAG: authfail_report_limit n
758# TAG: denied_report_limit n
759# TAG: siteusers_report_limit n
760# TAG: squidguard_report_limit n
761# TAG: user_report_limit n
762# TAG: dansguardian_report_limit n
763# TAG: download_report_limit n
764# report limits (lines).
765# '0' no limit
766#
767#authfail_report_limit 10
768#denied_report_limit 10
769#siteusers_report_limit 0
770#squidguard_report_limit 10
771#dansguardian_report_limit 10
772#user_report_limit 10
773#user_report_limit 50
774
775# TAG: www_document_root dir
776# Where is your Web DocumentRoot
777# Sarg will create sarg-php directory with some PHP modules:
778# - sarg-squidguard-block.php - add urls from user reports to squidGuard DB
779#
780#www_document_root /var/www/html
781
782# TAG: block_it module_url
783# This tag allow you to pass urls from user reports to a cgi or php module,
784# to be blocked by some Squid acl
785#
786# Eg.: block_it /sarg-php/sarg-block-it.php
787# sarg-block-it is a php that will append a url to a flat file.
788# You must change /var/www/html/sarg-php/sarg-block-it to point to your file
789# in $filename variable, and chown to a httpd owner.
790#
791# sarg will pass http://module_url?url=url
792#
793#block_it none
794
795# TAG: external_css_file path
796# Provide the path to an external css file to link into the HTML reports instead of
797# the inline css written by sarg when this option is not set.
798#
799# In versions prior to 2.3, this used to be an absolute file name to
800# a file to include verbatim in each HTML page but, as it takes a lot of
801# space, version 2.3 switched to a link to an external css file.
802# Therefore, this option must contain the HTTP server path on which a client
803# browser may find the css file.
804#
805# Sarg use theses style classes:
806# .logo logo class
807# .info sarg information class, align=center
808# .title_c title class, align=center
809# .header_c header class, align:center
810# .header_l header class, align:left
811# .header_r header class, align:right
812# .text text class, align:right
813# .data table text class, align:right
814# .data2 table text class, align:left
815# .data3 table text class, align:center
816# .link link class
817#
818# Sarg can be instructed to output the internal css it inline
819# into the reports with this command:
820#
821# sarg --css
822#
823# You can redirect the output to a file of your choice and edit
824# it to your liking.
825#
826#external_css_file none
827external_css_file /var/www/sarg/sarg.css
828
829# TAG: user_authentication yes|no
830# Allow user authentication in User Reports using .htaccess
831# Parameters:
832# AuthUserTemplateFile - The template to use to create the
833# .htaccess file. In the template, %u is replaced by the
834# user's ID for which the report is generated. The path of the
835# template is relative to the directory containing sarg
836# configuration file.
837#
838# user_authentication no
839# AuthUserTemplateFile sarg_htaccess
840
841# TAG: download_suffix "suffix,suffix,...,suffix"
842# file suffix to be considered as "download" in Download report.
843# Use 'none' to disable.
844#
845#download_suffix "zip,arj,bzip,gz,ace,doc,iso,adt,bin,cab,com,dot,drv$,lha,lzh,mdb,mso,ppt,rtf,src,shs,sys,exe,dll,mp3,avi,mpg,mpeg"
846
847# TAG: ulimit n
848# The maximum number of open file descriptors to avoid "Too many open files" error message.
849# You need to run sarg as root to use ulimit tag.
850# If you run sarg with a low privilege user, set to 'none' to disable ulimit
851#
852#ulimit 20000
853
854# TAG: ntlm_user_format username|domainname+username
855# NTLM users format.
856#
857#ntlm_user_format domainname+username
858
859# TAG: realtime_refresh_time num sec
860# How many time to auto refresh the realtime report
861# 0 = disable
862#
863# realtime_refresh_time 3
864
865# TAG: realtime_access_log_lines num
866# How many last lines to get from access.log file
867#
868# realtime_access_log_lines 1000
869
870# TAG: realtime_types: GET,PUT,CONNECT,ICP_QUERY,POST
871# Which records must be in realtime report.
872#
873# realtime_types GET,PUT,CONNECT
874
875# TAG: realtime_unauthenticated_records: ignore|show
876# What to do with unauthenticated records in realtime report.
877#
878# realtime_unauthenticated_records: show
879
880# TAG: byte_cost value no_cost_limit
881# Cost per byte.
882# Eg. byte_cost 0.01 100000000
883# per byte cost = 0.01
884# bytes with no cost = 100 Mb
885# 0 = disable
886#
887# byte_cost 0.01 50000000
888
889# TAG: squid24 on|off
890# Compatilibity with squid version <= 2.4 when using emulate_http_log on
891#
892# squid24 off
893############################# }- sarg.conf #############################
894
895vim /etc/httpd/conf.d/sarg.conf
896
897############################# sarg.conf -{ #############################
898Alias /sarg /var/www/sarg
899
900<Directory /var/www/sarg>
901 DirectoryIndex index.html
902 Order deny,allow
903 Deny from all
904#x# Allow from 127.0.0.1
905 Allow from 127.0.0.1 172.16.8.0/22
906 Allow from ::1
907 # Allow from your-workstation.com
908#x#
909 Allow from alfacorpltda.cl
910</Directory>
911############################# }- sarg.conf #############################
912
913## http://pxy.alfacorpltda.cl/sarg
914
915####################################### }- SARG
916####################################### SYSLOG -{
917
918cd
919
920vim /etc/rsyslog.conf
921
922############################# rsyslog.conf -{ #############################
923#rsyslog v3 config file
924
925# if you experience problems, check
926# http://www.rsyslog.com/troubleshoot for assistance
927
928#### MODULES ####
929
930$ModLoad imuxsock.so # provides support for local system logging (e.g. via logger command)
931$ModLoad imklog.so # provides kernel logging support (previously done by rklogd)
932#$ModLoad immark.so # provides --MARK-- message capability
933
934# Provides UDP syslog reception
935#$ModLoad imudp.so
936#$UDPServerRun 514
937
938# Provides TCP syslog reception
939#$ModLoad imtcp.so
940#$InputTCPServerRun 514
941
942
943#### GLOBAL DIRECTIVES ####
944
945# Use default timestamp format
946$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
947
948# File syncing capability is disabled by default. This feature is usually not required,
949# not useful and an extreme performance hit
950#$ActionFileEnableSync on
951
952
953#### RULES ####
954
955#x#
956*.* @log.alfacorpltda.cl
957
958# Log all kernel messages to the console.
959# Logging much else clutters up the screen.
960#kern.* /dev/console
961
962# Log anything (except mail) of level info or higher.
963# Don't log private authentication messages!
964*.info;mail.none;authpriv.none;cron.none /var/log/messages
965
966# The authpriv file has restricted access.
967authpriv.* /var/log/secure
968
969# Log all the mail messages in one place.
970mail.* -/var/log/maillog
971
972
973# Log cron stuff
974cron.* /var/log/cron
975
976# Everybody gets emergency messages
977*.emerg *
978
979# Save news errors of level crit and higher in a special file.
980uucp,news.crit /var/log/spooler
981
982# Save boot messages also to boot.log
983local7.* /var/log/boot.log
984
985
986
987# ### begin forwarding rule ###
988# The statement between the begin ... end define a SINGLE forwarding
989# rule. They belong together, do NOT split them. If you create multiple
990# forwarding rules, duplicate the whole block!
991# Remote Logging (we use TCP for reliable delivery)
992#
993# An on-disk queue is created for this action. If the remote host is
994# down, messages are spooled to disk and sent when it is up again.
995#$WorkDirectory /var/spppl/rsyslog # where to place spool files
996#$ActionQueueFileName fwdRule1 # unique name prefix for spool files
997#$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
998#$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
999#$ActionQueueType LinkedList # run asynchronously
1000#$ActionResumeRetryCount -1 # infinite retries if host is down
1001# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
1002#*.* @@remote-host:514
1003# ### end of the forwarding rule ###
1004############################# }- rsyslog.conf #############################
1005
1006service rsyslog restart
1007
1008####################################### }- SYSLOG
1009####################################### USERADD -{
1010useradd webmaster -s /sbin/nologin
1011useradd usuario1d -s /sbin/nologin
1012useradd usuario1r -s /sbin/nologin
1013useradd usuario1v -s /sbin/nologin
1014passwd webmaster
1015passwd usuario1d
1016passwd usuario1r
1017passwd usuario1v
1018####################################### }- USERADD
1019####################################### DNS -{
1020
1021cd
1022
1023yum -y install bind bind-chroot bind-utils
1024yum -y install bind*
1025
1026service named stop
1027
1028vim /etc/named.conf
1029
1030############################# named.conf -{ #############################
1031//
1032// named.conf
1033//
1034// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
1035// server as a caching only nameserver (as a localhost DNS resolver only).
1036//
1037// See /usr/share/doc/bind*/sample/ for example named configuration files.
1038//
1039
1040options {
1041#x# listen-on port 53 { 127.0.0.1; };
1042 listen-on port 53 { any; };
1043 listen-on-v6 port 53 { ::1; };
1044 directory "/var/named";
1045 dump-file "/var/named/data/cache_dump.db";
1046 statistics-file "/var/named/data/named_stats.txt";
1047 memstatistics-file "/var/named/data/named_mem_stats.txt";
1048#x# allow-query { localhost; };
1049 allow-query { any; };
1050#x#
1051 forwarders { 8.8.8.8; 8.8.4.4; };
1052# forwarders { any; };
1053#x#
1054 forward first;
1055 recursion yes;
1056
1057 dnssec-enable yes;
1058 dnssec-validation yes;
1059 dnssec-lookaside auto;
1060
1061 /* Path to ISC DLV key */
1062 bindkeys-file "/etc/named.iscdlv.key";
1063};
1064
1065logging {
1066 channel default_debug {
1067 file "data/named.run";
1068 severity dynamic;
1069 };
1070};
1071
1072zone "." IN {
1073 type hint;
1074 file "named.ca";
1075};
1076
1077include "/etc/named.rfc1912.zones";
1078
1079#x# Agregar -{
1080zone "alfacorpltda.cl" {
1081 type master;
1082 file "alfacorpltda.cl.zone";
1083 notify yes;
1084 allow-query { any; };
1085 allow-update { none; };
1086};
1087
1088zone "8.16.172.in-addr.arpa" {
1089 type master;
1090 file "8.16.172.in-addr.arpa.zone";
1091 notify yes;
1092 allow-query { any; };
1093 allow-update { none; };
1094};
1095#x# }- Agregar
1096############################# }- named.conf #############################
1097
1098vim /var/named/chroot/var/named/alfacorpltda.cl.zone
1099
1100############################# alfacorpltda.cl.zone -{ #############################
1101$TTL 1D
1102@ IN SOA ns1.alfacorpltda.cl. root.ns1.alfacorpltda.cl. (
1103
1104 2015053101 ; serial
1105 3H ; refresh
1106 15M ; retry
1107 1W ; expiry
1108 1D ) ; minimum
1109
1110 IN NS ns1.alfacorpltda.cl.
1111 IN MX 10 mail.alfacorpltda.cl.
1112
1113@ IN A 172.16.8.11
1114ns1 IN A 172.16.8.11
1115dns IN A 172.16.8.11
1116mail IN A 172.16.8.12
1117www IN A 172.16.8.13
1118ftp IN A 172.16.8.14
1119pxy IN A 172.16.8.14
1120sip IN A 172.16.8.15
1121smb IN A 172.16.8.21
1122sql IN A 172.16.8.22
1123log IN A 172.16.8.23
1124############################# }- alfacorpltda.cl.zone #############################
1125
1126vim /var/named/chroot/var/named/8.16.172.in-addr.arpa.zone
1127
1128############################# 8.16.172.in-addr.arpa.zone -{ #############################
1129$TTL 1D
1130@ IN SOA ns1.alfacorpltda.cl. root.ns1.alfacorpltda.cl. (
1131
1132 2015053101 ; serial
1133 3H ; refresh
1134 15M ; retry
1135 1W ; expiry
1136 1D ) ; minimum
1137
1138
1139@ IN NS ns1.alfacorpltda.cl.
114011 IN PTR ns1.alfacorpltda.cl.
114111 IN PTR dns.alfacorpltda.cl.
114212 IN PTR mail.alfacorpltda.cl.
114313 IN PTR www.alfacorpltda.cl.
114414 IN PTR ftp.alfacorpltda.cl.
114514 IN PTR pxy.alfacorpltda.cl.
114615 IN PTR sip.alfacorpltda.cl.
114721 IN PTR smb.alfacorpltda.cl.
114822 IN PTR sql.alfacorpltda.cl.
114923 IN PTR log.alfacorpltda.cl.
1150############################# }- 8.16.172.in-addr.arpa.zone #############################
1151
1152cp -af /var/named/* /var/named/chroot/var/named/
1153
1154chown root:named /etc/named.conf
1155chcon -t named_zone_t /var/named/chroot/var/named/alfacorpltda.cl.zone
1156chcon -t named_zone_t /var/named/chroot/var/named/8.16.172.in-addr.arpa.zone
1157chcon -u system_u -r object_r -t named_conf_t /etc/named.conf
1158
1159setsebool -P named_write_master_zones 1
1160
1161service named restart
1162chkconfig named on
1163
1164dig -x 172.16.8.11
1165
1166####################################### }- DNS
1167####################################### POSTFIX -{
1168
1169cd
1170
1171yum -y install postfix dovecot
1172
1173alternatives --set mta /usr/sbin/sendmail.postfix
1174
1175service postfix stop
1176
1177vim /etc/postfix/main.cf
1178
1179############################# main.cf -{ #############################
1180# Global Postfix configuration file. This file lists only a subset
1181# of all parameters. For the syntax, and for a complete parameter
1182# list, see the postconf(5) manual page (command: "man 5 postconf").
1183#
1184# For common configuration examples, see BASIC_CONFIGURATION_README
1185# and STANDARD_CONFIGURATION_README. To find these documents, use
1186# the command "postconf html_directory readme_directory", or go to
1187# http://www.postfix.org/.
1188#
1189# For best results, change no more than 2-3 parameters at a time,
1190# and test if Postfix still works after every change.
1191
1192# SOFT BOUNCE
1193#
1194# The soft_bounce parameter provides a limited safety net for
1195# testing. When soft_bounce is enabled, mail will remain queued that
1196# would otherwise bounce. This parameter disables locally-generated
1197# bounces, and prevents the SMTP server from rejecting mail permanently
1198# (by changing 5xx replies into 4xx replies). However, soft_bounce
1199# is no cure for address rewriting mistakes or mail routing mistakes.
1200#
1201#soft_bounce = no
1202
1203# LOCAL PATHNAME INFORMATION
1204#
1205# The queue_directory specifies the location of the Postfix queue.
1206# This is also the root directory of Postfix daemons that run chrooted.
1207# See the files in examples/chroot-setup for setting up Postfix chroot
1208# environments on different UNIX systems.
1209#
1210queue_directory = /var/spool/postfix
1211
1212# The command_directory parameter specifies the location of all
1213# postXXX commands.
1214#
1215command_directory = /usr/sbin
1216
1217# The daemon_directory parameter specifies the location of all Postfix
1218# daemon programs (i.e. programs listed in the master.cf file). This
1219# directory must be owned by root.
1220#
1221daemon_directory = /usr/libexec/postfix
1222
1223# The data_directory parameter specifies the location of Postfix-writable
1224# data files (caches, random numbers). This directory must be owned
1225# by the mail_owner account (see below).
1226#
1227data_directory = /var/lib/postfix
1228
1229# QUEUE AND PROCESS OWNERSHIP
1230#
1231# The mail_owner parameter specifies the owner of the Postfix queue
1232# and of most Postfix daemon processes. Specify the name of a user
1233# account THAT DOES NOT SHARE ITS USER OR GROUP ID WITH OTHER ACCOUNTS
1234# AND THAT OWNS NO OTHER FILES OR PROCESSES ON THE SYSTEM. In
1235# particular, don't specify nobody or daemon. PLEASE USE A DEDICATED
1236# USER.
1237#
1238mail_owner = postfix
1239
1240# The default_privs parameter specifies the default rights used by
1241# the local delivery agent for delivery to external file or command.
1242# These rights are used in the absence of a recipient user context.
1243# DO NOT SPECIFY A PRIVILEGED USER OR THE POSTFIX OWNER.
1244#
1245#default_privs = nobody
1246
1247# INTERNET HOST AND DOMAIN NAMES
1248#
1249# The myhostname parameter specifies the internet hostname of this
1250# mail system. The default is to use the fully-qualified domain name
1251# from gethostname(). $myhostname is used as a default value for many
1252# other configuration parameters.
1253#
1254#myhostname = host.domain.tld
1255#myhostname = virtual.domain.tld
1256#x# Agregar
1257myhostname = mail.alfacorpltda.cl
1258
1259# The mydomain parameter specifies the local internet domain name.
1260# The default is to use $myhostname minus the first component.
1261# $mydomain is used as a default value for many other configuration
1262# parameters.
1263#
1264#mydomain = domain.tld
1265#x# Agregar
1266mydomain = alfacorpltda.cl
1267
1268# SENDING MAIL
1269#
1270# The myorigin parameter specifies the domain that locally-posted
1271# mail appears to come from. The default is to append $myhostname,
1272# which is fine for small sites. If you run a domain with multiple
1273# machines, you should (1) change this to $mydomain and (2) set up
1274# a domain-wide alias database that aliases each user to
1275# user@that.users.mailhost.
1276#
1277# For the sake of consistency between sender and recipient addresses,
1278# myorigin also specifies the default domain name that is appended
1279# to recipient addresses that have no @domain part.
1280#
1281#myorigin = $myhostname
1282#x# Descomentar
1283myorigin = $mydomain
1284
1285# RECEIVING MAIL
1286
1287# The inet_interfaces parameter specifies the network interface
1288# addresses that this mail system receives mail on. By default,
1289# the software claims all active interfaces on the machine. The
1290# parameter also controls delivery of mail to user@[ip.address].
1291#
1292# See also the proxy_interfaces parameter, for network addresses that
1293# are forwarded to us via a proxy or network address translator.
1294#
1295# Note: you need to stop/start Postfix when this parameter changes.
1296#
1297#x# Descomentar
1298inet_interfaces = all
1299#inet_interfaces = $myhostname
1300#inet_interfaces = $myhostname, localhost
1301#x# inet_interfaces = localhost
1302
1303# Enable IPv4, and IPv6 if supported
1304inet_protocols = all
1305
1306# The proxy_interfaces parameter specifies the network interface
1307# addresses that this mail system receives mail on by way of a
1308# proxy or network address translation unit. This setting extends
1309# the address list specified with the inet_interfaces parameter.
1310#
1311# You must specify your proxy/NAT addresses when your system is a
1312# backup MX host for other domains, otherwise mail delivery loops
1313# will happen when the primary MX host is down.
1314#
1315#proxy_interfaces =
1316#proxy_interfaces = 1.2.3.4
1317
1318# The mydestination parameter specifies the list of domains that this
1319# machine considers itself the final destination for.
1320#
1321# These domains are routed to the delivery agent specified with the
1322# local_transport parameter setting. By default, that is the UNIX
1323# compatible delivery agent that lookups all recipients in /etc/passwd
1324# and /etc/aliases or their equivalent.
1325#
1326# The default is $myhostname + localhost.$mydomain. On a mail domain
1327# gateway, you should also include $mydomain.
1328#
1329# Do not specify the names of virtual domains - those domains are
1330# specified elsewhere (see VIRTUAL_README).
1331#
1332# Do not specify the names of domains that this machine is backup MX
1333# host for. Specify those names via the relay_domains settings for
1334# the SMTP server, or use permit_mx_backup if you are lazy (see
1335# STANDARD_CONFIGURATION_README).
1336#
1337# The local machine is always the final destination for mail addressed
1338# to user@[the.net.work.address] of an interface that the mail system
1339# receives mail on (see the inet_interfaces parameter).
1340#
1341# Specify a list of host or domain names, /file/name or type:table
1342# patterns, separated by commas and/or whitespace. A /file/name
1343# pattern is replaced by its contents; a type:table is matched when
1344# a name matches a lookup key (the right-hand side is ignored).
1345# Continue long lines by starting the next line with whitespace.
1346#
1347# See also below, section "REJECTING MAIL FOR UNKNOWN LOCAL USERS".
1348#
1349#x# mydestination = $myhostname, localhost.$mydomain, localhost
1350#x# Descomentar
1351mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
1352#mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain,
1353# mail.$mydomain, www.$mydomain, ftp.$mydomain
1354
1355# REJECTING MAIL FOR UNKNOWN LOCAL USERS
1356#
1357# The local_recipient_maps parameter specifies optional lookup tables
1358# with all names or addresses of users that are local with respect
1359# to $mydestination, $inet_interfaces or $proxy_interfaces.
1360#
1361# If this parameter is defined, then the SMTP server will reject
1362# mail for unknown local users. This parameter is defined by default.
1363#
1364# To turn off local recipient checking in the SMTP server, specify
1365# local_recipient_maps = (i.e. empty).
1366#
1367# The default setting assumes that you use the default Postfix local
1368# delivery agent for local delivery. You need to update the
1369# local_recipient_maps setting if:
1370#
1371# - You define $mydestination domain recipients in files other than
1372# /etc/passwd, /etc/aliases, or the $virtual_alias_maps files.
1373# For example, you define $mydestination domain recipients in
1374# the $virtual_mailbox_maps files.
1375#
1376# - You redefine the local delivery agent in master.cf.
1377#
1378# - You redefine the "local_transport" setting in main.cf.
1379#
1380# - You use the "luser_relay", "mailbox_transport", or "fallback_transport"
1381# feature of the Postfix local delivery agent (see local(8)).
1382#
1383# Details are described in the LOCAL_RECIPIENT_README file.
1384#
1385# Beware: if the Postfix SMTP server runs chrooted, you probably have
1386# to access the passwd file via the proxymap service, in order to
1387# overcome chroot restrictions. The alternative, having a copy of
1388# the system passwd file in the chroot jail is just not practical.
1389#
1390# The right-hand side of the lookup tables is conveniently ignored.
1391# In the left-hand side, specify a bare username, an @domain.tld
1392# wild-card, or specify a user@domain.tld address.
1393#
1394#local_recipient_maps = unix:passwd.byname $alias_maps
1395#local_recipient_maps = proxy:unix:passwd.byname $alias_maps
1396#local_recipient_maps =
1397
1398# The unknown_local_recipient_reject_code specifies the SMTP server
1399# response code when a recipient domain matches $mydestination or
1400# ${proxy,inet}_interfaces, while $local_recipient_maps is non-empty
1401# and the recipient address or address local-part is not found.
1402#
1403# The default setting is 550 (reject mail) but it is safer to start
1404# with 450 (try again later) until you are certain that your
1405# local_recipient_maps settings are OK.
1406#
1407unknown_local_recipient_reject_code = 550
1408
1409# TRUST AND RELAY CONTROL
1410
1411# The mynetworks parameter specifies the list of "trusted" SMTP
1412# clients that have more privileges than "strangers".
1413#
1414# In particular, "trusted" SMTP clients are allowed to relay mail
1415# through Postfix. See the smtpd_recipient_restrictions parameter
1416# in postconf(5).
1417#
1418# You can specify the list of "trusted" network addresses by hand
1419# or you can let Postfix do it for you (which is the default).
1420#
1421# By default (mynetworks_style = subnet), Postfix "trusts" SMTP
1422# clients in the same IP subnetworks as the local machine.
1423# On Linux, this does works correctly only with interfaces specified
1424# with the "ifconfig" command.
1425#
1426# Specify "mynetworks_style = class" when Postfix should "trust" SMTP
1427# clients in the same IP class A/B/C networks as the local machine.
1428# Don't do this with a dialup site - it would cause Postfix to "trust"
1429# your entire provider's network. Instead, specify an explicit
1430# mynetworks list by hand, as described below.
1431#
1432# Specify "mynetworks_style = host" when Postfix should "trust"
1433# only the local machine.
1434#
1435#mynetworks_style = class
1436#mynetworks_style = subnet
1437#mynetworks_style = host
1438
1439# Alternatively, you can specify the mynetworks list by hand, in
1440# which case Postfix ignores the mynetworks_style setting.
1441#
1442# Specify an explicit list of network/netmask patterns, where the
1443# mask specifies the number of bits in the network part of a host
1444# address.
1445#
1446# You can also specify the absolute pathname of a pattern file instead
1447# of listing the patterns here. Specify type:table for table-based lookups
1448# (the value on the table right-hand side is not used).
1449#
1450#mynetworks = 168.100.189.0/28, 127.0.0.0/8
1451#mynetworks = $config_directory/mynetworks
1452#mynetworks = hash:/etc/postfix/network_table
1453#x# Agregar
1454mynetworks = 172.16.0.0/16, 127.0.0.0/8
1455
1456# The relay_domains parameter restricts what destinations this system will
1457# relay mail to. See the smtpd_recipient_restrictions description in
1458# postconf(5) for detailed information.
1459#
1460# By default, Postfix relays mail
1461# - from "trusted" clients (IP address matches $mynetworks) to any destination,
1462# - from "untrusted" clients to destinations that match $relay_domains or
1463# subdomains thereof, except addresses with sender-specified routing.
1464# The default relay_domains value is $mydestination.
1465#
1466# In addition to the above, the Postfix SMTP server by default accepts mail
1467# that Postfix is final destination for:
1468# - destinations that match $inet_interfaces or $proxy_interfaces,
1469# - destinations that match $mydestination
1470# - destinations that match $virtual_alias_domains,
1471# - destinations that match $virtual_mailbox_domains.
1472# These destinations do not need to be listed in $relay_domains.
1473#
1474# Specify a list of hosts or domains, /file/name patterns or type:name
1475# lookup tables, separated by commas and/or whitespace. Continue
1476# long lines by starting the next line with whitespace. A file name
1477# is replaced by its contents; a type:name table is matched when a
1478# (parent) domain appears as lookup key.
1479#
1480# NOTE: Postfix will not automatically forward mail for domains that
1481# list this system as their primary or backup MX host. See the
1482# permit_mx_backup restriction description in postconf(5).
1483#
1484#relay_domains = $mydestination
1485
1486# INTERNET OR INTRANET
1487
1488# The relayhost parameter specifies the default host to send mail to
1489# when no entry is matched in the optional transport(5) table. When
1490# no relayhost is given, mail is routed directly to the destination.
1491#
1492# On an intranet, specify the organizational domain name. If your
1493# internal DNS uses no MX records, specify the name of the intranet
1494# gateway host instead.
1495#
1496# In the case of SMTP, specify a domain, host, host:port, [host]:port,
1497# [address] or [address]:port; the form [host] turns off MX lookups.
1498#
1499# If you're connected via UUCP, see also the default_transport parameter.
1500#
1501#relayhost = $mydomain
1502#relayhost = [gateway.my.domain]
1503#relayhost = [mailserver.isp.tld]
1504#relayhost = uucphost
1505#relayhost = [an.ip.add.ress]
1506
1507# REJECTING UNKNOWN RELAY USERS
1508#
1509# The relay_recipient_maps parameter specifies optional lookup tables
1510# with all addresses in the domains that match $relay_domains.
1511#
1512# If this parameter is defined, then the SMTP server will reject
1513# mail for unknown relay users. This feature is off by default.
1514#
1515# The right-hand side of the lookup tables is conveniently ignored.
1516# In the left-hand side, specify an @domain.tld wild-card, or specify
1517# a user@domain.tld address.
1518#
1519#relay_recipient_maps = hash:/etc/postfix/relay_recipients
1520
1521# INPUT RATE CONTROL
1522#
1523# The in_flow_delay configuration parameter implements mail input
1524# flow control. This feature is turned on by default, although it
1525# still needs further development (it's disabled on SCO UNIX due
1526# to an SCO bug).
1527#
1528# A Postfix process will pause for $in_flow_delay seconds before
1529# accepting a new message, when the message arrival rate exceeds the
1530# message delivery rate. With the default 100 SMTP server process
1531# limit, this limits the mail inflow to 100 messages a second more
1532# than the number of messages delivered per second.
1533#
1534# Specify 0 to disable the feature. Valid delays are 0..10.
1535#
1536#in_flow_delay = 1s
1537
1538# ADDRESS REWRITING
1539#
1540# The ADDRESS_REWRITING_README document gives information about
1541# address masquerading or other forms of address rewriting including
1542# username->Firstname.Lastname mapping.
1543
1544# ADDRESS REDIRECTION (VIRTUAL DOMAIN)
1545#
1546# The VIRTUAL_README document gives information about the many forms
1547# of domain hosting that Postfix supports.
1548
1549# "USER HAS MOVED" BOUNCE MESSAGES
1550#
1551# See the discussion in the ADDRESS_REWRITING_README document.
1552
1553# TRANSPORT MAP
1554#
1555# See the discussion in the ADDRESS_REWRITING_README document.
1556
1557# ALIAS DATABASE
1558#
1559# The alias_maps parameter specifies the list of alias databases used
1560# by the local delivery agent. The default list is system dependent.
1561#
1562# On systems with NIS, the default is to search the local alias
1563# database, then the NIS alias database. See aliases(5) for syntax
1564# details.
1565#
1566# If you change the alias database, run "postalias /etc/aliases" (or
1567# wherever your system stores the mail alias file), or simply run
1568# "newaliases" to build the necessary DBM or DB file.
1569#
1570# It will take a minute or so before changes become visible. Use
1571# "postfix reload" to eliminate the delay.
1572#
1573#alias_maps = dbm:/etc/aliases
1574alias_maps = hash:/etc/aliases
1575#alias_maps = hash:/etc/aliases, nis:mail.aliases
1576#alias_maps = netinfo:/aliases
1577
1578# The alias_database parameter specifies the alias database(s) that
1579# are built with "newaliases" or "sendmail -bi". This is a separate
1580# configuration parameter, because alias_maps (see above) may specify
1581# tables that are not necessarily all under control by Postfix.
1582#
1583#alias_database = dbm:/etc/aliases
1584#alias_database = dbm:/etc/mail/aliases
1585alias_database = hash:/etc/aliases
1586#alias_database = hash:/etc/aliases, hash:/opt/majordomo/aliases
1587
1588# ADDRESS EXTENSIONS (e.g., user+foo)
1589#
1590# The recipient_delimiter parameter specifies the separator between
1591# user names and address extensions (user+foo). See canonical(5),
1592# local(8), relocated(5) and virtual(5) for the effects this has on
1593# aliases, canonical, virtual, relocated and .forward file lookups.
1594# Basically, the software tries user+foo and .forward+foo before
1595# trying user and .forward.
1596#
1597#recipient_delimiter = +
1598
1599# DELIVERY TO MAILBOX
1600#
1601# The home_mailbox parameter specifies the optional pathname of a
1602# mailbox file relative to a user's home directory. The default
1603# mailbox file is /var/spool/mail/user or /var/mail/user. Specify
1604# "Maildir/" for qmail-style delivery (the / is required).
1605#
1606#home_mailbox = Mailbox
1607#x# Descomentar
1608home_mailbox = Maildir/
1609
1610# The mail_spool_directory parameter specifies the directory where
1611# UNIX-style mailboxes are kept. The default setting depends on the
1612# system type.
1613#
1614#mail_spool_directory = /var/mail
1615#mail_spool_directory = /var/spool/mail
1616
1617# The mailbox_command parameter specifies the optional external
1618# command to use instead of mailbox delivery. The command is run as
1619# the recipient with proper HOME, SHELL and LOGNAME environment settings.
1620# Exception: delivery for root is done as $default_user.
1621#
1622# Other environment variables of interest: USER (recipient username),
1623# EXTENSION (address extension), DOMAIN (domain part of address),
1624# and LOCAL (the address localpart).
1625#
1626# Unlike other Postfix configuration parameters, the mailbox_command
1627# parameter is not subjected to $parameter substitutions. This is to
1628# make it easier to specify shell syntax (see example below).
1629#
1630# Avoid shell meta characters because they will force Postfix to run
1631# an expensive shell process. Procmail alone is expensive enough.
1632#
1633# IF YOU USE THIS TO DELIVER MAIL SYSTEM-WIDE, YOU MUST SET UP AN
1634# ALIAS THAT FORWARDS MAIL FOR ROOT TO A REAL USER.
1635#
1636#mailbox_command = /some/where/procmail
1637#mailbox_command = /some/where/procmail -a "$EXTENSION"
1638
1639# The mailbox_transport specifies the optional transport in master.cf
1640# to use after processing aliases and .forward files. This parameter
1641# has precedence over the mailbox_command, fallback_transport and
1642# luser_relay parameters.
1643#
1644# Specify a string of the form transport:nexthop, where transport is
1645# the name of a mail delivery transport defined in master.cf. The
1646# :nexthop part is optional. For more details see the sample transport
1647# configuration file.
1648#
1649# NOTE: if you use this feature for accounts not in the UNIX password
1650# file, then you must update the "local_recipient_maps" setting in
1651# the main.cf file, otherwise the SMTP server will reject mail for
1652# non-UNIX accounts with "User unknown in local recipient table".
1653#
1654#mailbox_transport = lmtp:unix:/var/lib/imap/socket/lmtp
1655
1656# If using the cyrus-imapd IMAP server deliver local mail to the IMAP
1657# server using LMTP (Local Mail Transport Protocol), this is prefered
1658# over the older cyrus deliver program by setting the
1659# mailbox_transport as below:
1660#
1661# mailbox_transport = lmtp:unix:/var/lib/imap/socket/lmtp
1662#
1663# The efficiency of LMTP delivery for cyrus-imapd can be enhanced via
1664# these settings.
1665#
1666# local_destination_recipient_limit = 300
1667# local_destination_concurrency_limit = 5
1668#
1669# Of course you should adjust these settings as appropriate for the
1670# capacity of the hardware you are using. The recipient limit setting
1671# can be used to take advantage of the single instance message store
1672# capability of Cyrus. The concurrency limit can be used to control
1673# how many simultaneous LMTP sessions will be permitted to the Cyrus
1674# message store.
1675#
1676# To use the old cyrus deliver program you have to set:
1677#mailbox_transport = cyrus
1678
1679# The fallback_transport specifies the optional transport in master.cf
1680# to use for recipients that are not found in the UNIX passwd database.
1681# This parameter has precedence over the luser_relay parameter.
1682#
1683# Specify a string of the form transport:nexthop, where transport is
1684# the name of a mail delivery transport defined in master.cf. The
1685# :nexthop part is optional. For more details see the sample transport
1686# configuration file.
1687#
1688# NOTE: if you use this feature for accounts not in the UNIX password
1689# file, then you must update the "local_recipient_maps" setting in
1690# the main.cf file, otherwise the SMTP server will reject mail for
1691# non-UNIX accounts with "User unknown in local recipient table".
1692#
1693#fallback_transport = lmtp:unix:/var/lib/imap/socket/lmtp
1694#fallback_transport =
1695
1696# The luser_relay parameter specifies an optional destination address
1697# for unknown recipients. By default, mail for unknown@$mydestination,
1698# unknown@[$inet_interfaces] or unknown@[$proxy_interfaces] is returned
1699# as undeliverable.
1700#
1701# The following expansions are done on luser_relay: $user (recipient
1702# username), $shell (recipient shell), $home (recipient home directory),
1703# $recipient (full recipient address), $extension (recipient address
1704# extension), $domain (recipient domain), $local (entire recipient
1705# localpart), $recipient_delimiter. Specify ${name?value} or
1706# ${name:value} to expand value only when $name does (does not) exist.
1707#
1708# luser_relay works only for the default Postfix local delivery agent.
1709#
1710# NOTE: if you use this feature for accounts not in the UNIX password
1711# file, then you must specify "local_recipient_maps =" (i.e. empty) in
1712# the main.cf file, otherwise the SMTP server will reject mail for
1713# non-UNIX accounts with "User unknown in local recipient table".
1714#
1715#luser_relay = $user@other.host
1716#luser_relay = $local@other.host
1717#luser_relay = admin+$local
1718
1719# JUNK MAIL CONTROLS
1720#
1721# The controls listed here are only a very small subset. The file
1722# SMTPD_ACCESS_README provides an overview.
1723
1724# The header_checks parameter specifies an optional table with patterns
1725# that each logical message header is matched against, including
1726# headers that span multiple physical lines.
1727#
1728# By default, these patterns also apply to MIME headers and to the
1729# headers of attached messages. With older Postfix versions, MIME and
1730# attached message headers were treated as body text.
1731#
1732# For details, see "man header_checks".
1733#
1734#header_checks = regexp:/etc/postfix/header_checks
1735
1736# FAST ETRN SERVICE
1737#
1738# Postfix maintains per-destination logfiles with information about
1739# deferred mail, so that mail can be flushed quickly with the SMTP
1740# "ETRN domain.tld" command, or by executing "sendmail -qRdomain.tld".
1741# See the ETRN_README document for a detailed description.
1742#
1743# The fast_flush_domains parameter controls what destinations are
1744# eligible for this service. By default, they are all domains that
1745# this server is willing to relay mail to.
1746#
1747#fast_flush_domains = $relay_domains
1748
1749# SHOW SOFTWARE VERSION OR NOT
1750#
1751# The smtpd_banner parameter specifies the text that follows the 220
1752# code in the SMTP server's greeting banner. Some people like to see
1753# the mail version advertised. By default, Postfix shows no version.
1754#
1755# You MUST specify $myhostname at the start of the text. That is an
1756# RFC requirement. Postfix itself does not care.
1757#
1758#smtpd_banner = $myhostname ESMTP $mail_name
1759#smtpd_banner = $myhostname ESMTP $mail_name ($mail_version)
1760
1761# PARALLEL DELIVERY TO THE SAME DESTINATION
1762#
1763# How many parallel deliveries to the same user or domain? With local
1764# delivery, it does not make sense to do massively parallel delivery
1765# to the same user, because mailbox updates must happen sequentially,
1766# and expensive pipelines in .forward files can cause disasters when
1767# too many are run at the same time. With SMTP deliveries, 10
1768# simultaneous connections to the same domain could be sufficient to
1769# raise eyebrows.
1770#
1771# Each message delivery transport has its XXX_destination_concurrency_limit
1772# parameter. The default is $default_destination_concurrency_limit for
1773# most delivery transports. For the local delivery agent the default is 2.
1774
1775#local_destination_concurrency_limit = 2
1776#default_destination_concurrency_limit = 20
1777
1778# DEBUGGING CONTROL
1779#
1780# The debug_peer_level parameter specifies the increment in verbose
1781# logging level when an SMTP client or server host name or address
1782# matches a pattern in the debug_peer_list parameter.
1783#
1784debug_peer_level = 2
1785
1786# The debug_peer_list parameter specifies an optional list of domain
1787# or network patterns, /file/name patterns or type:name tables. When
1788# an SMTP client or server host name or address matches a pattern,
1789# increase the verbose logging level by the amount specified in the
1790# debug_peer_level parameter.
1791#
1792#debug_peer_list = 127.0.0.1
1793#debug_peer_list = some.domain
1794
1795# The debugger_command specifies the external command that is executed
1796# when a Postfix daemon program is run with the -D option.
1797#
1798# Use "command .. & sleep 5" so that the debugger can attach before
1799# the process marches on. If you use an X-based debugger, be sure to
1800# set up your XAUTHORITY environment variable before starting Postfix.
1801#
1802debugger_command =
1803 PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
1804 ddd $daemon_directory/$process_name $process_id & sleep 5
1805
1806# If you can't use X, use this to capture the call stack when a
1807# daemon crashes. The result is in a file in the configuration
1808# directory, and is named after the process name and the process ID.
1809#
1810# debugger_command =
1811# PATH=/bin:/usr/bin:/usr/local/bin; export PATH; (echo cont;
1812# echo where) | gdb $daemon_directory/$process_name $process_id 2>&1
1813# >$config_directory/$process_name.$process_id.log & sleep 5
1814#
1815# Another possibility is to run gdb under a detached screen session.
1816# To attach to the screen sesssion, su root and run "screen -r
1817# <id_string>" where <id_string> uniquely matches one of the detached
1818# sessions (from "screen -list").
1819#
1820# debugger_command =
1821# PATH=/bin:/usr/bin:/sbin:/usr/sbin; export PATH; screen
1822# -dmS $process_name gdb $daemon_directory/$process_name
1823# $process_id & sleep 1
1824
1825# INSTALL-TIME CONFIGURATION INFORMATION
1826#
1827# The following parameters are used when installing a new Postfix version.
1828#
1829# sendmail_path: The full pathname of the Postfix sendmail command.
1830# This is the Sendmail-compatible mail posting interface.
1831#
1832sendmail_path = /usr/sbin/sendmail.postfix
1833
1834# newaliases_path: The full pathname of the Postfix newaliases command.
1835# This is the Sendmail-compatible command to build alias databases.
1836#
1837newaliases_path = /usr/bin/newaliases.postfix
1838
1839# mailq_path: The full pathname of the Postfix mailq command. This
1840# is the Sendmail-compatible mail queue listing command.
1841#
1842mailq_path = /usr/bin/mailq.postfix
1843
1844# setgid_group: The group for mail submission and queue management
1845# commands. This must be a group name with a numerical group ID that
1846# is not shared with other accounts, not even with the Postfix account.
1847#
1848setgid_group = postdrop
1849
1850# html_directory: The location of the Postfix HTML documentation.
1851#
1852html_directory = no
1853
1854# manpage_directory: The location of the Postfix on-line manual pages.
1855#
1856manpage_directory = /usr/share/man
1857
1858# sample_directory: The location of the Postfix sample configuration files.
1859# This parameter is obsolete as of Postfix 2.1.
1860#
1861sample_directory = /usr/share/doc/postfix-2.6.6/samples
1862
1863# readme_directory: The location of the Postfix README files.
1864#
1865readme_directory = /usr/share/doc/postfix-2.6.6/README_FILES
1866############################# }- main.cf #############################
1867
1868vim /etc/dovecot/dovecot.conf
1869
1870############################# dovecot.conf -{ #############################
1871## Dovecot configuration file
1872
1873# If you're in a hurry, see http://wiki.dovecot.org/QuickConfiguration
1874
1875# "doveconf -n" command gives a clean output of the changed settings. Use it
1876# instead of copy&pasting files when posting to the Dovecot mailing list.
1877
1878# '#' character and everything after it is treated as comments. Extra spaces
1879# and tabs are ignored. If you want to use either of these explicitly, put the
1880# value inside quotes, eg.: key = "# char and trailing whitespace "
1881
1882# Default values are shown for each setting, it's not required to uncomment
1883# those. These are exceptions to this though: No sections (e.g. namespace {})
1884# or plugin settings are added by default, they're listed only as examples.
1885# Paths are also just examples with the real defaults being based on configure
1886# options. The paths listed here are for configure --prefix=/usr
1887# --sysconfdir=/etc --localstatedir=/var
1888
1889# Most of the actual configuration gets included below. The filenames are
1890# first sorted by their ASCII value and parsed in that order. The 00-prefixes
1891# in filenames are intended to make it easier to understand the ordering.
1892!include conf.d/*.conf
1893
1894# Protocols we want to be serving.
1895#x# Descomentar
1896protocols = imap pop3 lmtp
1897
1898# A comma separated list of IPs or hosts where to listen in for connections.
1899# "*" listens in all IPv4 interfaces, "::" listens in all IPv6 interfaces.
1900# If you want to specify non-default ports or anything more complex,
1901# edit conf.d/master.conf.
1902#listen = *, ::
1903
1904# Base directory where to store runtime data.
1905#base_dir = /var/run/dovecot/
1906
1907# Greeting message for clients.
1908#login_greeting = Dovecot ready.
1909
1910# Space separated list of trusted network ranges. Connections from these
1911# IPs are allowed to override their IP addresses and ports (for logging and
1912# for authentication checks). disable_plaintext_auth is also ignored for
1913# these networks. Typically you'd specify your IMAP proxy servers here.
1914#login_trusted_networks =
1915
1916# Sepace separated list of login access check sockets (e.g. tcpwrap)
1917#login_access_sockets =
1918
1919# Show more verbose process titles (in ps). Currently shows user name and
1920# IP address. Useful for seeing who are actually using the IMAP processes
1921# (eg. shared mailboxes or if same uid is used for multiple accounts).
1922#verbose_proctitle = no
1923
1924# Should all processes be killed when Dovecot master process shuts down.
1925# Setting this to "no" means that Dovecot can be upgraded without
1926# forcing existing client connections to close (although that could also be
1927# a problem if the upgrade is e.g. because of a security fix).
1928#shutdown_clients = yes
1929
1930##
1931## Dictionary server settings
1932##
1933
1934# Dictionary can be used to store key=value lists. This is used by several
1935# plugins. The dictionary can be accessed either directly or though a
1936# dictionary server. The following dict block maps dictionary names to URIs
1937# when the server is used. These can then be referenced using URIs in format
1938# "proxy::<name>".
1939
1940dict {
1941 #quota = mysql:/etc/dovecot/dovecot-dict-sql.conf.ext
1942 #expire = sqlite:/etc/dovecot/dovecot-dict-sql.conf.ext
1943}
1944
1945# A config file can also tried to be included without giving an error if
1946# it's not found:
1947#!include_try /etc/dovecot/local.conf
1948############################# }- dovecot.conf #############################
1949
1950vim /etc/dovecot/conf.d/10-mail.conf
1951
1952############################# 10-mail.conf -{ #############################
1953##
1954## Mailbox locations and namespaces
1955##
1956
1957# Location for users' mailboxes. The default is empty, which means that Dovecot
1958# tries to find the mailboxes automatically. This won't work if the user
1959# doesn't yet have any mail, so you should explicitly tell Dovecot the full
1960# location.
1961#
1962# If you're using mbox, giving a path to the INBOX file (eg. /var/mail/%u)
1963# isn't enough. You'll also need to tell Dovecot where the other mailboxes are
1964# kept. This is called the "root mail directory", and it must be the first
1965# path given in the mail_location setting.
1966#
1967# There are a few special variables you can use, eg.:
1968#
1969# %u - username
1970# %n - user part in user@domain, same as %u if there's no domain
1971# %d - domain part in user@domain, empty if there's no domain
1972# %h - home directory
1973#
1974# See doc/wiki/Variables.txt for full list. Some examples:
1975#
1976#x# Descomentar
1977mail_location = maildir:~/Maildir
1978# mail_location = mbox:~/mail:INBOX=/var/mail/%u
1979# mail_location = mbox:/var/mail/%d/%1n/%n:INDEX=/var/indexes/%d/%1n/%n
1980#
1981# <doc/wiki/MailLocation.txt>
1982#
1983#mail_location =
1984
1985# If you need to set multiple mailbox locations or want to change default
1986# namespace settings, you can do it by defining namespace sections.
1987#
1988# You can have private, shared and public namespaces. Private namespaces
1989# are for user's personal mails. Shared namespaces are for accessing other
1990# users' mailboxes that have been shared. Public namespaces are for shared
1991# mailboxes that are managed by sysadmin. If you create any shared or public
1992# namespaces you'll typically want to enable ACL plugin also, otherwise all
1993# users can access all the shared mailboxes, assuming they have permissions
1994# on filesystem level to do so.
1995#
1996# REMEMBER: If you add any namespaces, the default namespace must be added
1997# explicitly, ie. mail_location does nothing unless you have a namespace
1998# without a location setting. Default namespace is simply done by having a
1999# namespace with empty prefix.
2000#namespace {
2001 # Namespace type: private, shared or public
2002 #type = private
2003
2004 # Hierarchy separator to use. You should use the same separator for all
2005 # namespaces or some clients get confused. '/' is usually a good one.
2006 # The default however depends on the underlying mail storage format.
2007 #separator =
2008
2009 # Prefix required to access this namespace. This needs to be different for
2010 # all namespaces. For example "Public/".
2011 #prefix =
2012
2013 # Physical location of the mailbox. This is in same format as
2014 # mail_location, which is also the default for it.
2015 #location =
2016
2017 # There can be only one INBOX, and this setting defines which namespace
2018 # has it.
2019 #inbox = no
2020
2021 # If namespace is hidden, it's not advertised to clients via NAMESPACE
2022 # extension. You'll most likely also want to set list=no. This is mostly
2023 # useful when converting from another server with different namespaces which
2024 # you want to deprecate but still keep working. For example you can create
2025 # hidden namespaces with prefixes "~/mail/", "~%u/mail/" and "mail/".
2026 #hidden = no
2027
2028 # Show the mailboxes under this namespace with LIST command. This makes the
2029 # namespace visible for clients that don't support NAMESPACE extension.
2030 # "children" value lists child mailboxes, but hides the namespace prefix.
2031 #list = yes
2032
2033 # Namespace handles its own subscriptions. If set to "no", the parent
2034 # namespace handles them (empty prefix should always have this as "yes")
2035 #subscriptions = yes
2036#}
2037
2038# Example shared namespace configuration
2039#namespace {
2040 #type = shared
2041 #separator = /
2042
2043 # Mailboxes are visible under "shared/user@domain/"
2044 # %%n, %%d and %%u are expanded to the destination user.
2045 #prefix = shared/%%u/
2046
2047 # Mail location for other users' mailboxes. Note that %variables and ~/
2048 # expands to the logged in user's data. %%n, %%d, %%u and %%h expand to the
2049 # destination user's data.
2050 #location = maildir:%%h/Maildir:INDEX=~/Maildir/shared/%%u
2051
2052 # Use the default namespace for saving subscriptions.
2053 #subscriptions = no
2054
2055 # List the shared/ namespace only if there are visible shared mailboxes.
2056 #list = children
2057#}
2058
2059# System user and group used to access mails. If you use multiple, userdb
2060# can override these by returning uid or gid fields. You can use either numbers
2061# or names. <doc/wiki/UserIds.txt>
2062#mail_uid =
2063#mail_gid =
2064
2065# Group to enable temporarily for privileged operations. Currently this is
2066# used only with INBOX when either its initial creation or dotlocking fails.
2067# Typically this is set to "mail" to give access to /var/mail.
2068#mail_privileged_group =
2069
2070# Grant access to these supplementary groups for mail processes. Typically
2071# these are used to set up access to shared mailboxes. Note that it may be
2072# dangerous to set these if users can create symlinks (e.g. if "mail" group is
2073# set here, ln -s /var/mail ~/mail/var could allow a user to delete others'
2074# mailboxes, or ln -s /secret/shared/box ~/mail/mybox would allow reading it).
2075#mail_access_groups =
2076
2077# Allow full filesystem access to clients. There's no access checks other than
2078# what the operating system does for the active UID/GID. It works with both
2079# maildir and mboxes, allowing you to prefix mailboxes names with eg. /path/
2080# or ~user/.
2081#mail_full_filesystem_access = no
2082
2083##
2084## Mail processes
2085##
2086
2087# Don't use mmap() at all. This is required if you store indexes to shared
2088# filesystems (NFS or clustered filesystem).
2089#mmap_disable = no
2090
2091# Rely on O_EXCL to work when creating dotlock files. NFS supports O_EXCL
2092# since version 3, so this should be safe to use nowadays by default.
2093#dotlock_use_excl = yes
2094
2095# When to use fsync() or fdatasync() calls:
2096# optimized (default): Whenever necessary to avoid losing important data
2097# always: Useful with e.g. NFS when write()s are delayed
2098# never: Never use it (best performance, but crashes can lose data)
2099#mail_fsync = optimized
2100
2101# Mail storage exists in NFS. Set this to yes to make Dovecot flush NFS caches
2102# whenever needed. If you're using only a single mail server this isn't needed.
2103#mail_nfs_storage = no
2104# Mail index files also exist in NFS. Setting this to yes requires
2105# mmap_disable=yes and fsync_disable=no.
2106#mail_nfs_index = no
2107
2108# Locking method for index files. Alternatives are fcntl, flock and dotlock.
2109# Dotlocking uses some tricks which may create more disk I/O than other locking
2110# methods. NFS users: flock doesn't work, remember to change mmap_disable.
2111#lock_method = fcntl
2112
2113# Valid UID range for users, defaults to 500 and above. This is mostly
2114# to make sure that users can't log in as daemons or other system users.
2115# Note that denying root logins is hardcoded to dovecot binary and can't
2116# be done even if first_valid_uid is set to 0.
2117#first_valid_uid = 500
2118#last_valid_uid = 0
2119
2120# Valid GID range for users, defaults to non-root/wheel. Users having
2121# non-valid GID as primary group ID aren't allowed to log in. If user
2122# belongs to supplementary groups with non-valid GIDs, those groups are
2123# not set.
2124#first_valid_gid = 1
2125#last_valid_gid = 0
2126
2127# Maximum allowed length for mail keyword name. It's only forced when trying
2128# to create new keywords.
2129#mail_max_keyword_length = 50
2130
2131# ':' separated list of directories under which chrooting is allowed for mail
2132# processes (ie. /var/mail will allow chrooting to /var/mail/foo/bar too).
2133# This setting doesn't affect login_chroot, mail_chroot or auth chroot
2134# settings. If this setting is empty, "/./" in home dirs are ignored.
2135# WARNING: Never add directories here which local users can modify, that
2136# may lead to root exploit. Usually this should be done only if you don't
2137# allow shell access for users. <doc/wiki/Chrooting.txt>
2138#valid_chroot_dirs =
2139
2140# Default chroot directory for mail processes. This can be overridden for
2141# specific users in user database by giving /./ in user's home directory
2142# (eg. /home/./user chroots into /home). Note that usually there is no real
2143# need to do chrooting, Dovecot doesn't allow users to access files outside
2144# their mail directory anyway. If your home directories are prefixed with
2145# the chroot directory, append "/." to mail_chroot. <doc/wiki/Chrooting.txt>
2146#mail_chroot =
2147
2148# UNIX socket path to master authentication server to find users.
2149# This is used by imap (for shared users) and lda.
2150#auth_socket_path = /var/run/dovecot/auth-userdb
2151
2152# Directory where to look up mail plugins.
2153#mail_plugin_dir = /usr/lib/dovecot
2154
2155# Space separated list of plugins to load for all services. Plugins specific to
2156# IMAP, LDA, etc. are added to this list in their own .conf files.
2157#mail_plugins =
2158
2159##
2160## Mailbox handling optimizations
2161##
2162
2163# The minimum number of mails in a mailbox before updates are done to cache
2164# file. This allows optimizing Dovecot's behavior to do less disk writes at
2165# the cost of more disk reads.
2166#mail_cache_min_mail_count = 0
2167
2168# When IDLE command is running, mailbox is checked once in a while to see if
2169# there are any new mails or other changes. This setting defines the minimum
2170# time to wait between those checks. Dovecot can also use dnotify, inotify and
2171# kqueue to find out immediately when changes occur.
2172#mailbox_idle_check_interval = 30 secs
2173
2174# Save mails with CR+LF instead of plain LF. This makes sending those mails
2175# take less CPU, especially with sendfile() syscall with Linux and FreeBSD.
2176# But it also creates a bit more disk I/O which may just make it slower.
2177# Also note that if other software reads the mboxes/maildirs, they may handle
2178# the extra CRs wrong and cause problems.
2179#mail_save_crlf = no
2180
2181##
2182## Maildir-specific settings
2183##
2184
2185# By default LIST command returns all entries in maildir beginning with a dot.
2186# Enabling this option makes Dovecot return only entries which are directories.
2187# This is done by stat()ing each entry, so it causes more disk I/O.
2188# (For systems setting struct dirent->d_type, this check is free and it's
2189# done always regardless of this setting)
2190#maildir_stat_dirs = no
2191
2192# When copying a message, do it with hard links whenever possible. This makes
2193# the performance much better, and it's unlikely to have any side effects.
2194#maildir_copy_with_hardlinks = yes
2195
2196# Assume Dovecot is the only MUA accessing Maildir: Scan cur/ directory only
2197# when its mtime changes unexpectedly or when we can't find the mail otherwise.
2198#maildir_very_dirty_syncs = no
2199
2200##
2201## mbox-specific settings
2202##
2203
2204# Which locking methods to use for locking mbox. There are four available:
2205# dotlock: Create <mailbox>.lock file. This is the oldest and most NFS-safe
2206# solution. If you want to use /var/mail/ like directory, the users
2207# will need write access to that directory.
2208# dotlock_try: Same as dotlock, but if it fails because of permissions or
2209# because there isn't enough disk space, just skip it.
2210# fcntl : Use this if possible. Works with NFS too if lockd is used.
2211# flock : May not exist in all systems. Doesn't work with NFS.
2212# lockf : May not exist in all systems. Doesn't work with NFS.
2213#
2214# You can use multiple locking methods; if you do the order they're declared
2215# in is important to avoid deadlocks if other MTAs/MUAs are using multiple
2216# locking methods as well. Some operating systems don't allow using some of
2217# them simultaneously.
2218#mbox_read_locks = fcntl
2219#mbox_write_locks = dotlock fcntl
2220mbox_write_locks = fcntl
2221
2222# Maximum time to wait for lock (all of them) before aborting.
2223#mbox_lock_timeout = 5 mins
2224
2225# If dotlock exists but the mailbox isn't modified in any way, override the
2226# lock file after this much time.
2227#mbox_dotlock_change_timeout = 2 mins
2228
2229# When mbox changes unexpectedly we have to fully read it to find out what
2230# changed. If the mbox is large this can take a long time. Since the change
2231# is usually just a newly appended mail, it'd be faster to simply read the
2232# new mails. If this setting is enabled, Dovecot does this but still safely
2233# fallbacks to re-reading the whole mbox file whenever something in mbox isn't
2234# how it's expected to be. The only real downside to this setting is that if
2235# some other MUA changes message flags, Dovecot doesn't notice it immediately.
2236# Note that a full sync is done with SELECT, EXAMINE, EXPUNGE and CHECK
2237# commands.
2238#mbox_dirty_syncs = yes
2239
2240# Like mbox_dirty_syncs, but don't do full syncs even with SELECT, EXAMINE,
2241# EXPUNGE or CHECK commands. If this is set, mbox_dirty_syncs is ignored.
2242#mbox_very_dirty_syncs = no
2243
2244# Delay writing mbox headers until doing a full write sync (EXPUNGE and CHECK
2245# commands and when closing the mailbox). This is especially useful for POP3
2246# where clients often delete all mails. The downside is that our changes
2247# aren't immediately visible to other MUAs.
2248#mbox_lazy_writes = yes
2249
2250# If mbox size is smaller than this (e.g. 100k), don't write index files.
2251# If an index file already exists it's still read, just not updated.
2252#mbox_min_index_size = 0
2253
2254##
2255## mdbox-specific settings
2256##
2257
2258# Maximum dbox file size until it's rotated.
2259#mdbox_rotate_size = 2M
2260
2261# Maximum dbox file age until it's rotated. Typically in days. Day begins
2262# from midnight, so 1d = today, 2d = yesterday, etc. 0 = check disabled.
2263#mdbox_rotate_interval = 1d
2264############################# }- 10-mail.conf #############################
2265
2266vim /etc/dovecot/conf.d/10-auth.conf
2267
2268############################# 10-auth.conf -{ #############################
2269##
2270## Authentication processes
2271##
2272
2273# Disable LOGIN command and all other plaintext authentications unless
2274# SSL/TLS is used (LOGINDISABLED capability). Note that if the remote IP
2275# matches the local IP (ie. you're connecting from the same computer), the
2276# connection is considered secure and plaintext authentication is allowed.
2277#x# Descomentar
2278disable_plaintext_auth = yes
2279
2280# Authentication cache size (e.g. 10M). 0 means it's disabled. Note that
2281# bsdauth, PAM and vpopmail require cache_key to be set for caching to be used.
2282#auth_cache_size = 0
2283# Time to live for cached data. After TTL expires the cached record is no
2284# longer used, *except* if the main database lookup returns internal failure.
2285# We also try to handle password changes automatically: If user's previous
2286# authentication was successful, but this one wasn't, the cache isn't used.
2287# For now this works only with plaintext authentication.
2288#auth_cache_ttl = 1 hour
2289# TTL for negative hits (user not found, password mismatch).
2290# 0 disables caching them completely.
2291#auth_cache_negative_ttl = 1 hour
2292
2293# Space separated list of realms for SASL authentication mechanisms that need
2294# them. You can leave it empty if you don't want to support multiple realms.
2295# Many clients simply use the first one listed here, so keep the default realm
2296# first.
2297#auth_realms =
2298
2299# Default realm/domain to use if none was specified. This is used for both
2300# SASL realms and appending @domain to username in plaintext logins.
2301#auth_default_realm =
2302
2303# List of allowed characters in username. If the user-given username contains
2304# a character not listed in here, the login automatically fails. This is just
2305# an extra check to make sure user can't exploit any potential quote escaping
2306# vulnerabilities with SQL/LDAP databases. If you want to allow all characters,
2307# set this value to empty.
2308#auth_username_chars = abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ01234567890.-_@
2309
2310# Username character translations before it's looked up from databases. The
2311# value contains series of from -> to characters. For example "#@/@" means
2312# that '#' and '/' characters are translated to '@'.
2313#auth_username_translation =
2314
2315# Username formatting before it's looked up from databases. You can use
2316# the standard variables here, eg. %Lu would lowercase the username, %n would
2317# drop away the domain if it was given, or "%n-AT-%d" would change the '@' into
2318# "-AT-". This translation is done after auth_username_translation changes.
2319#auth_username_format =
2320
2321# If you want to allow master users to log in by specifying the master
2322# username within the normal username string (ie. not using SASL mechanism's
2323# support for it), you can specify the separator character here. The format
2324# is then <username><separator><master username>. UW-IMAP uses "*" as the
2325# separator, so that could be a good choice.
2326#auth_master_user_separator =
2327
2328# Username to use for users logging in with ANONYMOUS SASL mechanism
2329#auth_anonymous_username = anonymous
2330
2331# Maximum number of dovecot-auth worker processes. They're used to execute
2332# blocking passdb and userdb queries (eg. MySQL and PAM). They're
2333# automatically created and destroyed as needed.
2334#auth_worker_max_count = 30
2335
2336# Host name to use in GSSAPI principal names. The default is to use the
2337# name returned by gethostname(). Use "$ALL" to allow all keytab entries.
2338#auth_gssapi_hostname =
2339
2340# Kerberos keytab to use for the GSSAPI mechanism. Will use the system
2341# default (usually /etc/krb5.keytab) if not specified.
2342#auth_krb5_keytab =
2343
2344# Do NTLM and GSS-SPNEGO authentication using Samba's winbind daemon and
2345# ntlm_auth helper. <doc/wiki/Authentication/Mechanisms/Winbind.txt>
2346#auth_use_winbind = no
2347
2348# Path for Samba's ntlm_auth helper binary.
2349#auth_winbind_helper_path = /usr/bin/ntlm_auth
2350
2351# Time to delay before replying to failed authentications.
2352#auth_failure_delay = 2 secs
2353
2354# Require a valid SSL client certificate or the authentication fails.
2355#auth_ssl_require_client_cert = no
2356
2357# Take the username from client's SSL certificate, using
2358# X509_NAME_get_text_by_NID() which returns the subject's DN's
2359# CommonName.
2360#auth_ssl_username_from_cert = no
2361
2362# Space separated list of wanted authentication mechanisms:
2363# plain login digest-md5 cram-md5 ntlm rpa apop anonymous gssapi otp skey
2364# gss-spnego
2365# NOTE: See also disable_plaintext_auth setting.
2366#x# auth_mechanisms = plain
2367auth_mechanisms = plain login
2368
2369##
2370## Password and user databases
2371##
2372
2373#
2374# Password database is used to verify user's password (and nothing more).
2375# You can have multiple passdbs and userdbs. This is useful if you want to
2376# allow both system users (/etc/passwd) and virtual users to login without
2377# duplicating the system users into virtual database.
2378#
2379# <doc/wiki/PasswordDatabase.txt>
2380#
2381# User database specifies where mails are located and what user/group IDs
2382# own them. For single-UID configuration use "static" userdb.
2383#
2384# <doc/wiki/UserDatabase.txt>
2385
2386#!include auth-deny.conf.ext
2387#!include auth-master.conf.ext
2388
2389!include auth-system.conf.ext
2390#!include auth-sql.conf.ext
2391#!include auth-ldap.conf.ext
2392#!include auth-passwdfile.conf.ext
2393#!include auth-checkpassword.conf.ext
2394#!include auth-vpopmail.conf.ext
2395#!include auth-static.conf.ext
2396############################# }- 10-auth.conf #############################
2397
2398vim /etc/dovecot/conf.d/10-master.conf
2399
2400############################# 10-master.conf -{ #############################
2401#default_process_limit = 100
2402#default_client_limit = 1000
2403#default_vsz_limit = 256M
2404
2405# Login user is internally used by login processes. This is the most untrusted
2406# user in Dovecot system. It shouldn't have access to anything at all.
2407#default_login_user = dovenull
2408
2409# Internal user is used by unprivileged processes. It should be separate from
2410# login user, so that login processes can't disturb other processes.
2411#default_internal_user = dovecot
2412
2413service imap-login {
2414 inet_listener imap {
2415 #port = 143
2416 }
2417 inet_listener imaps {
2418 #port = 993
2419 #ssl = yes
2420 }
2421
2422 # Number of connections to handle before starting a new process. Typically
2423 # the only useful values are 0 (unlimited) or 1. 1 is more secure, but 0
2424 # is faster. <doc/wiki/LoginProcess.txt>
2425 #service_count = 1
2426
2427 # Number of processes to always keep waiting for more connections.
2428 #process_min_avail = 0
2429
2430 # If you set service_count=0, you probably need to grow this.
2431 #vsz_limit = 64M
2432}
2433
2434service pop3-login {
2435 inet_listener pop3 {
2436 #port = 110
2437 }
2438 inet_listener pop3s {
2439 #port = 995
2440 #ssl = yes
2441 }
2442}
2443
2444service lmtp {
2445 unix_listener lmtp {
2446 #mode = 0666
2447 }
2448
2449 # Create inet listener only if you can't use the above UNIX socket
2450 #inet_listener lmtp {
2451 # Avoid making LMTP visible for the entire internet
2452 #address =
2453 #port =
2454 #}
2455}
2456
2457service imap {
2458 # Most of the memory goes to mmap()ing files. You may need to increase this
2459 # limit if you have huge mailboxes.
2460 #vsz_limit = 256M
2461
2462 # Max. number of IMAP processes (connections)
2463 #process_limit = 1024
2464}
2465
2466service pop3 {
2467 # Max. number of POP3 processes (connections)
2468 #process_limit = 1024
2469}
2470
2471service auth {
2472 # auth_socket_path points to this userdb socket by default. It's typically
2473 # used by dovecot-lda, doveadm, possibly imap process, etc. Its default
2474 # permissions make it readable only by root, but you may need to relax these
2475 # permissions. Users that have access to this socket are able to get a list
2476 # of all usernames and get results of everyone's userdb lookups.
2477 unix_listener auth-userdb {
2478 #mode = 0600
2479 #user =
2480 #x# Agregar
2481 user = postfix
2482 #group =
2483 #x# Agregar
2484 group = postfix
2485 }
2486
2487 # Postfix smtp-auth
2488 #unix_listener /var/spool/postfix/private/auth {
2489 # mode = 0666
2490 #}
2491
2492 # Auth process is run as this user.
2493 #user = $default_internal_user
2494}
2495
2496service auth-worker {
2497 # Auth worker process is run as root by default, so that it can access
2498 # /etc/shadow. If this isn't necessary, the user should be changed to
2499 # $default_internal_user.
2500 #user = root
2501}
2502############################# }- 10-master.conf #############################
2503
2504setsebool -P allow_postfix_local_write_mail_spool 1
2505
2506service postfix restart
2507chkconfig postfix on
2508service dovecot restart
2509chkconfig dovecot on
2510
2511mail -s "ALFACORP Ltda: Mensaje de prueba " webmaster@alfacorpltda.cl
2512
2513 Estimado WebMaster,
2514 Le he este mensaje para probar el funcionamiento del servicio
2515 Se despide con saludos Root
2516 .
2517
2518####################################### }- POSTFIX
2519####################################### HTTPS -{
2520
2521cd
2522
2523yum -y install httpd mod_ssl
2524
2525service httpd stop
2526
2527mkdir -p /var/www/alfacorpltda.cl
2528mkdir /var/www/alfacorpltda.cl/cgi-bin
2529mkdir /var/www/alfacorpltda.cl/logs
2530mkdir /var/www/alfacorpltda.cl/html
2531mkdir /var/www/alfacorpltda.cl/etc
2532mkdir /var/www/alfacorpltda.cl/icons
2533mkdir /var/www/alfacorpltda.cl/error
2534mkdir /var/www/alfacorpltda.cl/desarollo
2535mkdir /var/www/alfacorpltda.cl/ventas
2536mkdir /var/www/alfacorpltda.cl/recepcion
2537mkdir /var/www/htpasswd
2538
2539vim /etc/httpd/conf/httpd.conf
2540
2541############################# httpd.conf -{ #############################
2542#
2543# This is the main Apache server configuration file. It contains the
2544# configuration directives that give the server its instructions.
2545# See <URL:http://httpd.apache.org/docs/2.2/> for detailed information.
2546# In particular, see
2547# <URL:http://httpd.apache.org/docs/2.2/mod/directives.html>
2548# for a discussion of each configuration directive.
2549#
2550#
2551# Do NOT simply read the instructions in here without understanding
2552# what they do. They're here only as hints or reminders. If you are unsure
2553# consult the online docs. You have been warned.
2554#
2555# The configuration directives are grouped into three basic sections:
2556# 1. Directives that control the operation of the Apache server process as a
2557# whole (the 'global environment').
2558# 2. Directives that define the parameters of the 'main' or 'default' server,
2559# which responds to requests that aren't handled by a virtual host.
2560# These directives also provide default values for the settings
2561# of all virtual hosts.
2562# 3. Settings for virtual hosts, which allow Web requests to be sent to
2563# different IP addresses or hostnames and have them handled by the
2564# same Apache server process.
2565#
2566# Configuration and logfile names: If the filenames you specify for many
2567# of the server's control files begin with "/" (or "drive:/" for Win32), the
2568# server will use that explicit path. If the filenames do *not* begin
2569# with "/", the value of ServerRoot is prepended -- so "logs/foo.log"
2570# with ServerRoot set to "/etc/httpd" will be interpreted by the
2571# server as "/etc/httpd/logs/foo.log".
2572#
2573
2574### Section 1: Global Environment
2575#
2576# The directives in this section affect the overall operation of Apache,
2577# such as the number of concurrent requests it can handle or where it
2578# can find its configuration files.
2579#
2580
2581#
2582# Don't give away too much information about all the subcomponents
2583# we are running. Comment out this line if you don't mind remote sites
2584# finding out what major optional modules you are running
2585ServerTokens OS
2586
2587#
2588# ServerRoot: The top of the directory tree under which the server's
2589# configuration, error, and log files are kept.
2590#
2591# NOTE! If you intend to place this on an NFS (or otherwise network)
2592# mounted filesystem then please read the LockFile documentation
2593# (available at <URL:http://httpd.apache.org/docs/2.2/mod/mpm_common.html#lockfile>);
2594# you will save yourself a lot of trouble.
2595#
2596# Do NOT add a slash at the end of the directory path.
2597#
2598ServerRoot "/etc/httpd"
2599
2600#
2601# PidFile: The file in which the server should record its process
2602# identification number when it starts. Note the PIDFILE variable in
2603# /etc/sysconfig/httpd must be set appropriately if this location is
2604# changed.
2605#
2606PidFile run/httpd.pid
2607
2608#
2609# Timeout: The number of seconds before receives and sends time out.
2610#
2611Timeout 60
2612
2613#
2614# KeepAlive: Whether or not to allow persistent connections (more than
2615# one request per connection). Set to "Off" to deactivate.
2616#
2617KeepAlive Off
2618
2619#
2620# MaxKeepAliveRequests: The maximum number of requests to allow
2621# during a persistent connection. Set to 0 to allow an unlimited amount.
2622# We recommend you leave this number high, for maximum performance.
2623#
2624MaxKeepAliveRequests 100
2625
2626#
2627# KeepAliveTimeout: Number of seconds to wait for the next request from the
2628# same client on the same connection.
2629#
2630KeepAliveTimeout 15
2631
2632##
2633## Server-Pool Size Regulation (MPM specific)
2634##
2635
2636# prefork MPM
2637# StartServers: number of server processes to start
2638# MinSpareServers: minimum number of server processes which are kept spare
2639# MaxSpareServers: maximum number of server processes which are kept spare
2640# ServerLimit: maximum value for MaxClients for the lifetime of the server
2641# MaxClients: maximum number of server processes allowed to start
2642# MaxRequestsPerChild: maximum number of requests a server process serves
2643<IfModule prefork.c>
2644StartServers 8
2645MinSpareServers 5
2646MaxSpareServers 20
2647ServerLimit 256
2648MaxClients 256
2649MaxRequestsPerChild 4000
2650</IfModule>
2651
2652# worker MPM
2653# StartServers: initial number of server processes to start
2654# MaxClients: maximum number of simultaneous client connections
2655# MinSpareThreads: minimum number of worker threads which are kept spare
2656# MaxSpareThreads: maximum number of worker threads which are kept spare
2657# ThreadsPerChild: constant number of worker threads in each server process
2658# MaxRequestsPerChild: maximum number of requests a server process serves
2659<IfModule worker.c>
2660StartServers 4
2661MaxClients 300
2662MinSpareThreads 25
2663MaxSpareThreads 75
2664ThreadsPerChild 25
2665MaxRequestsPerChild 0
2666</IfModule>
2667
2668#
2669# Listen: Allows you to bind Apache to specific IP addresses and/or
2670# ports, in addition to the default. See also the <VirtualHost>
2671# directive.
2672#
2673# Change this to Listen on specific IP addresses as shown below to
2674# prevent Apache from glomming onto all bound IP addresses (0.0.0.0)
2675#
2676#Listen 12.34.56.78:80
2677#x# Listen 80
2678Listen 172.16.8.13:80
2679
2680#
2681# Dynamic Shared Object (DSO) Support
2682#
2683# To be able to use the functionality of a module which was built as a DSO you
2684# have to place corresponding `LoadModule' lines at this location so the
2685# directives contained in it are actually available _before_ they are used.
2686# Statically compiled modules (those listed by `httpd -l') do not need
2687# to be loaded here.
2688#
2689# Example:
2690# LoadModule foo_module modules/mod_foo.so
2691#
2692LoadModule auth_basic_module modules/mod_auth_basic.so
2693LoadModule auth_digest_module modules/mod_auth_digest.so
2694LoadModule authn_file_module modules/mod_authn_file.so
2695LoadModule authn_alias_module modules/mod_authn_alias.so
2696LoadModule authn_anon_module modules/mod_authn_anon.so
2697LoadModule authn_dbm_module modules/mod_authn_dbm.so
2698LoadModule authn_default_module modules/mod_authn_default.so
2699LoadModule authz_host_module modules/mod_authz_host.so
2700LoadModule authz_user_module modules/mod_authz_user.so
2701LoadModule authz_owner_module modules/mod_authz_owner.so
2702LoadModule authz_groupfile_module modules/mod_authz_groupfile.so
2703LoadModule authz_dbm_module modules/mod_authz_dbm.so
2704LoadModule authz_default_module modules/mod_authz_default.so
2705LoadModule ldap_module modules/mod_ldap.so
2706LoadModule authnz_ldap_module modules/mod_authnz_ldap.so
2707LoadModule include_module modules/mod_include.so
2708LoadModule log_config_module modules/mod_log_config.so
2709LoadModule logio_module modules/mod_logio.so
2710LoadModule env_module modules/mod_env.so
2711LoadModule ext_filter_module modules/mod_ext_filter.so
2712LoadModule mime_magic_module modules/mod_mime_magic.so
2713LoadModule expires_module modules/mod_expires.so
2714LoadModule deflate_module modules/mod_deflate.so
2715LoadModule headers_module modules/mod_headers.so
2716LoadModule usertrack_module modules/mod_usertrack.so
2717LoadModule setenvif_module modules/mod_setenvif.so
2718LoadModule mime_module modules/mod_mime.so
2719LoadModule dav_module modules/mod_dav.so
2720LoadModule status_module modules/mod_status.so
2721LoadModule autoindex_module modules/mod_autoindex.so
2722LoadModule info_module modules/mod_info.so
2723LoadModule dav_fs_module modules/mod_dav_fs.so
2724LoadModule vhost_alias_module modules/mod_vhost_alias.so
2725LoadModule negotiation_module modules/mod_negotiation.so
2726LoadModule dir_module modules/mod_dir.so
2727LoadModule actions_module modules/mod_actions.so
2728LoadModule speling_module modules/mod_speling.so
2729LoadModule userdir_module modules/mod_userdir.so
2730LoadModule alias_module modules/mod_alias.so
2731LoadModule substitute_module modules/mod_substitute.so
2732LoadModule rewrite_module modules/mod_rewrite.so
2733LoadModule proxy_module modules/mod_proxy.so
2734LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
2735LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
2736LoadModule proxy_http_module modules/mod_proxy_http.so
2737LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
2738LoadModule proxy_connect_module modules/mod_proxy_connect.so
2739LoadModule cache_module modules/mod_cache.so
2740LoadModule suexec_module modules/mod_suexec.so
2741LoadModule disk_cache_module modules/mod_disk_cache.so
2742LoadModule cgi_module modules/mod_cgi.so
2743LoadModule version_module modules/mod_version.so
2744
2745#
2746# The following modules are not loaded by default:
2747#
2748#LoadModule asis_module modules/mod_asis.so
2749#LoadModule authn_dbd_module modules/mod_authn_dbd.so
2750#LoadModule cern_meta_module modules/mod_cern_meta.so
2751#LoadModule cgid_module modules/mod_cgid.so
2752#LoadModule dbd_module modules/mod_dbd.so
2753#LoadModule dumpio_module modules/mod_dumpio.so
2754#LoadModule filter_module modules/mod_filter.so
2755#LoadModule ident_module modules/mod_ident.so
2756#LoadModule log_forensic_module modules/mod_log_forensic.so
2757#LoadModule unique_id_module modules/mod_unique_id.so
2758#
2759
2760#
2761# Load config files from the config directory "/etc/httpd/conf.d".
2762#
2763Include conf.d/*.conf
2764
2765#
2766# ExtendedStatus controls whether Apache will generate "full" status
2767# information (ExtendedStatus On) or just basic information (ExtendedStatus
2768# Off) when the "server-status" handler is called. The default is Off.
2769#
2770#ExtendedStatus On
2771
2772#
2773# If you wish httpd to run as a different user or group, you must run
2774# httpd as root initially and it will switch.
2775#
2776# User/Group: The name (or #number) of the user/group to run httpd as.
2777# . On SCO (ODT 3) use "User nouser" and "Group nogroup".
2778# . On HPUX you may not be able to use shared memory as nobody, and the
2779# suggested workaround is to create a user www and use that user.
2780# NOTE that some kernels refuse to setgid(Group) or semctl(IPC_SET)
2781# when the value of (unsigned)Group is above 60000;
2782# don't use Group #-1 on these systems!
2783#
2784User apache
2785Group apache
2786
2787### Section 2: 'Main' server configuration
2788#
2789# The directives in this section set up the values used by the 'main'
2790# server, which responds to any requests that aren't handled by a
2791# <VirtualHost> definition. These values also provide defaults for
2792# any <VirtualHost> containers you may define later in the file.
2793#
2794# All of these directives may appear inside <VirtualHost> containers,
2795# in which case these default settings will be overridden for the
2796# virtual host being defined.
2797#
2798
2799#
2800# ServerAdmin: Your address, where problems with the server should be
2801# e-mailed. This address appears on some server-generated pages, such
2802# as error documents. e.g. admin@your-domain.com
2803#
2804#x# ServerAdmin root@localhost
2805ServerAdmin root@alfacorpltda.cl
2806
2807#
2808# ServerName gives the name and port that the server uses to identify itself.
2809# This can often be determined automatically, but we recommend you specify
2810# it explicitly to prevent problems during startup.
2811#
2812# If this is not set to valid DNS name for your host, server-generated
2813# redirections will not work. See also the UseCanonicalName directive.
2814#
2815# If your host doesn't have a registered DNS name, enter its IP address here.
2816# You will have to access it by its address anyway, and this will make
2817# redirections work in a sensible way.
2818#
2819#ServerName www.example.com:80
2820ServerName www.alfacorpltda.cl:80
2821
2822#
2823# UseCanonicalName: Determines how Apache constructs self-referencing
2824# URLs and the SERVER_NAME and SERVER_PORT variables.
2825# When set "Off", Apache will use the Hostname and Port supplied
2826# by the client. When set "On", Apache will use the value of the
2827# ServerName directive.
2828#
2829UseCanonicalName Off
2830
2831#
2832# DocumentRoot: The directory out of which you will serve your
2833# documents. By default, all requests are taken from this directory, but
2834# symbolic links and aliases may be used to point to other locations.
2835#
2836#x# DocumentRoot "/var/www/html"
2837DocumentRoot "/var/www/alfacorpltda.cl"
2838
2839#
2840# Each directory to which Apache has access can be configured with respect
2841# to which services and features are allowed and/or disabled in that
2842# directory (and its subdirectories).
2843#
2844# First, we configure the "default" to be a very restrictive set of
2845# features.
2846#
2847<Directory />
2848 Options FollowSymLinks
2849 AllowOverride None
2850</Directory>
2851
2852#
2853# Note that from this point forward you must specifically allow
2854# particular features to be enabled - so if something's not working as
2855# you might expect, make sure that you have specifically enabled it
2856# below.
2857#
2858
2859#
2860# This should be changed to whatever you set DocumentRoot to.
2861#
2862#x# <Directory "/var/www/html">
2863<Directory "/var/www/alfacorpltda.cl">
2864
2865#
2866# Possible values for the Options directive are "None", "All",
2867# or any combination of:
2868# Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews
2869#
2870# Note that "MultiViews" must be named *explicitly* --- "Options All"
2871# doesn't give it to you.
2872#
2873# The Options directive is both complicated and important. Please see
2874# http://httpd.apache.org/docs/2.2/mod/core.html#options
2875# for more information.
2876#
2877 Options Indexes FollowSymLinks
2878
2879#
2880# AllowOverride controls what directives may be placed in .htaccess files.
2881# It can be "All", "None", or any combination of the keywords:
2882# Options FileInfo AuthConfig Limit
2883#
2884 AllowOverride None
2885
2886#
2887# Controls who can get stuff from this server.
2888#
2889 Order allow,deny
2890 Allow from all
2891
2892</Directory>
2893
2894#
2895# UserDir: The name of the directory that is appended onto a user's home
2896# directory if a ~user request is received.
2897#
2898# The path to the end user account 'public_html' directory must be
2899# accessible to the webserver userid. This usually means that ~userid
2900# must have permissions of 711, ~userid/public_html must have permissions
2901# of 755, and documents contained therein must be world-readable.
2902# Otherwise, the client will only receive a "403 Forbidden" message.
2903#
2904# See also: http://httpd.apache.org/docs/misc/FAQ.html#forbidden
2905#
2906<IfModule mod_userdir.c>
2907 #
2908 # UserDir is disabled by default since it can confirm the presence
2909 # of a username on the system (depending on home directory
2910 # permissions).
2911 #
2912 UserDir disabled
2913
2914 #
2915 # To enable requests to /~user/ to serve the user's public_html
2916 # directory, remove the "UserDir disabled" line above, and uncomment
2917 # the following line instead:
2918 #
2919 #UserDir public_html
2920
2921</IfModule>
2922
2923#
2924# Control access to UserDir directories. The following is an example
2925# for a site where these directories are restricted to read-only.
2926#
2927#<Directory /home/*/public_html>
2928# AllowOverride FileInfo AuthConfig Limit
2929# Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec
2930# <Limit GET POST OPTIONS>
2931# Order allow,deny
2932# Allow from all
2933# </Limit>
2934# <LimitExcept GET POST OPTIONS>
2935# Order deny,allow
2936# Deny from all
2937# </LimitExcept>
2938#</Directory>
2939
2940#
2941# DirectoryIndex: sets the file that Apache will serve if a directory
2942# is requested.
2943#
2944# The index.html.var file (a type-map) is used to deliver content-
2945# negotiated documents. The MultiViews Option can be used for the
2946# same purpose, but it is much slower.
2947#
2948DirectoryIndex index.html index.html.var
2949
2950#
2951# AccessFileName: The name of the file to look for in each directory
2952# for additional configuration directives. See also the AllowOverride
2953# directive.
2954#
2955AccessFileName .htaccess
2956
2957#
2958# The following lines prevent .htaccess and .htpasswd files from being
2959# viewed by Web clients.
2960#
2961<Files ~ "^\.ht">
2962 Order allow,deny
2963 Deny from all
2964 Satisfy All
2965</Files>
2966
2967#
2968# TypesConfig describes where the mime.types file (or equivalent) is
2969# to be found.
2970#
2971TypesConfig /etc/mime.types
2972
2973#
2974# DefaultType is the default MIME type the server will use for a document
2975# if it cannot otherwise determine one, such as from filename extensions.
2976# If your server contains mostly text or HTML documents, "text/plain" is
2977# a good value. If most of your content is binary, such as applications
2978# or images, you may want to use "application/octet-stream" instead to
2979# keep browsers from trying to display binary files as though they are
2980# text.
2981#
2982DefaultType text/plain
2983
2984#
2985# The mod_mime_magic module allows the server to use various hints from the
2986# contents of the file itself to determine its type. The MIMEMagicFile
2987# directive tells the module where the hint definitions are located.
2988#
2989<IfModule mod_mime_magic.c>
2990# MIMEMagicFile /usr/share/magic.mime
2991 MIMEMagicFile conf/magic
2992</IfModule>
2993
2994#
2995# HostnameLookups: Log the names of clients or just their IP addresses
2996# e.g., www.apache.org (on) or 204.62.129.132 (off).
2997# The default is off because it'd be overall better for the net if people
2998# had to knowingly turn this feature on, since enabling it means that
2999# each client request will result in AT LEAST one lookup request to the
3000# nameserver.
3001#
3002HostnameLookups Off
3003
3004#
3005# EnableMMAP: Control whether memory-mapping is used to deliver
3006# files (assuming that the underlying OS supports it).
3007# The default is on; turn this off if you serve from NFS-mounted
3008# filesystems. On some systems, turning it off (regardless of
3009# filesystem) can improve performance; for details, please see
3010# http://httpd.apache.org/docs/2.2/mod/core.html#enablemmap
3011#
3012#EnableMMAP off
3013
3014#
3015# EnableSendfile: Control whether the sendfile kernel support is
3016# used to deliver files (assuming that the OS supports it).
3017# The default is on; turn this off if you serve from NFS-mounted
3018# filesystems. Please see
3019# http://httpd.apache.org/docs/2.2/mod/core.html#enablesendfile
3020#
3021#EnableSendfile off
3022
3023#
3024# ErrorLog: The location of the error log file.
3025# If you do not specify an ErrorLog directive within a <VirtualHost>
3026# container, error messages relating to that virtual host will be
3027# logged here. If you *do* define an error logfile for a <VirtualHost>
3028# container, that host's errors will be logged there and not here.
3029#
3030ErrorLog logs/error_log
3031
3032#
3033# LogLevel: Control the number of messages logged to the error_log.
3034# Possible values include: debug, info, notice, warn, error, crit,
3035# alert, emerg.
3036#
3037LogLevel warn
3038
3039#
3040# The following directives define some format nicknames for use with
3041# a CustomLog directive (see below).
3042#
3043LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
3044LogFormat "%h %l %u %t \"%r\" %>s %b" common
3045LogFormat "%{Referer}i -> %U" referer
3046LogFormat "%{User-agent}i" agent
3047
3048# "combinedio" includes actual counts of actual bytes received (%I) and sent (%O); this
3049# requires the mod_logio module to be loaded.
3050#LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio
3051
3052#
3053# The location and format of the access logfile (Common Logfile Format).
3054# If you do not define any access logfiles within a <VirtualHost>
3055# container, they will be logged here. Contrariwise, if you *do*
3056# define per-<VirtualHost> access logfiles, transactions will be
3057# logged therein and *not* in this file.
3058#
3059#CustomLog logs/access_log common
3060
3061#
3062# If you would like to have separate agent and referer logfiles, uncomment
3063# the following directives.
3064#
3065#CustomLog logs/referer_log referer
3066#CustomLog logs/agent_log agent
3067
3068#
3069# For a single logfile with access, agent, and referer information
3070# (Combined Logfile Format), use the following directive:
3071#
3072CustomLog logs/access_log combined
3073
3074#
3075# Optionally add a line containing the server version and virtual host
3076# name to server-generated pages (internal error documents, FTP directory
3077# listings, mod_status and mod_info output etc., but not CGI generated
3078# documents or custom error documents).
3079# Set to "EMail" to also include a mailto: link to the ServerAdmin.
3080# Set to one of: On | Off | EMail
3081#
3082ServerSignature On
3083
3084#
3085# Aliases: Add here as many aliases as you need (with no limit). The format is
3086# Alias fakename realname
3087#
3088# Note that if you include a trailing / on fakename then the server will
3089# require it to be present in the URL. So "/icons" isn't aliased in this
3090# example, only "/icons/". If the fakename is slash-terminated, then the
3091# realname must also be slash terminated, and if the fakename omits the
3092# trailing slash, the realname must also omit it.
3093#
3094# We include the /icons/ alias for FancyIndexed directory listings. If you
3095# do not use FancyIndexing, you may comment this out.
3096#
3097#x# Alias /icons/ "/var/www/icons/"
3098Alias /icons/ "/var/www/alfacorpltda.cl/icons/"
3099
3100#x# <Directory "/var/www/icons">
3101<Directory "/var/www/alfacorpltda.cl/icons">
3102 Options Indexes MultiViews FollowSymLinks
3103 AllowOverride None
3104 Order allow,deny
3105 Allow from all
3106</Directory>
3107
3108#
3109# WebDAV module configuration section.
3110#
3111<IfModule mod_dav_fs.c>
3112 # Location of the WebDAV lock database.
3113 DAVLockDB /var/lib/dav/lockdb
3114</IfModule>
3115
3116#
3117# ScriptAlias: This controls which directories contain server scripts.
3118# ScriptAliases are essentially the same as Aliases, except that
3119# documents in the realname directory are treated as applications and
3120# run by the server when requested rather than as documents sent to the client.
3121# The same rules about trailing "/" apply to ScriptAlias directives as to
3122# Alias.
3123#
3124#x# ScriptAlias /cgi-bin/ "/var/www/cgi-bin/"
3125ScriptAlias /cgi-bin/ "/var/www/alfacorpltda.cl/cgi-bin/"
3126
3127#
3128# "/var/www/cgi-bin" should be changed to whatever your ScriptAliased
3129# CGI directory exists, if you have that configured.
3130#
3131#x# <Directory "/var/www/cgi-bin">
3132<Directory "/var/www/alfacorpltda.cl/cgi-bin">
3133 AllowOverride None
3134 Options None
3135 Order allow,deny
3136 Allow from all
3137</Directory>
3138
3139#
3140# Redirect allows you to tell clients about documents which used to exist in
3141# your server's namespace, but do not anymore. This allows you to tell the
3142# clients where to look for the relocated document.
3143# Example:
3144# Redirect permanent /foo http://www.example.com/bar
3145
3146#
3147# Directives controlling the display of server-generated directory listings.
3148#
3149
3150#
3151# IndexOptions: Controls the appearance of server-generated directory
3152# listings.
3153#
3154IndexOptions FancyIndexing VersionSort NameWidth=* HTMLTable Charset=UTF-8
3155
3156#
3157# AddIcon* directives tell the server which icon to show for different
3158# files or filename extensions. These are only displayed for
3159# FancyIndexed directories.
3160#
3161AddIconByEncoding (CMP,/icons/compressed.gif) x-compress x-gzip
3162
3163AddIconByType (TXT,/icons/text.gif) text/*
3164AddIconByType (IMG,/icons/image2.gif) image/*
3165AddIconByType (SND,/icons/sound2.gif) audio/*
3166AddIconByType (VID,/icons/movie.gif) video/*
3167
3168AddIcon /icons/binary.gif .bin .exe
3169AddIcon /icons/binhex.gif .hqx
3170AddIcon /icons/tar.gif .tar
3171AddIcon /icons/world2.gif .wrl .wrl.gz .vrml .vrm .iv
3172AddIcon /icons/compressed.gif .Z .z .tgz .gz .zip
3173AddIcon /icons/a.gif .ps .ai .eps
3174AddIcon /icons/layout.gif .html .shtml .htm .pdf
3175AddIcon /icons/text.gif .txt
3176AddIcon /icons/c.gif .c
3177AddIcon /icons/p.gif .pl .py
3178AddIcon /icons/f.gif .for
3179AddIcon /icons/dvi.gif .dvi
3180AddIcon /icons/uuencoded.gif .uu
3181AddIcon /icons/script.gif .conf .sh .shar .csh .ksh .tcl
3182AddIcon /icons/tex.gif .tex
3183AddIcon /icons/bomb.gif core
3184
3185AddIcon /icons/back.gif ..
3186AddIcon /icons/hand.right.gif README
3187AddIcon /icons/folder.gif ^^DIRECTORY^^
3188AddIcon /icons/blank.gif ^^BLANKICON^^
3189
3190#
3191# DefaultIcon is which icon to show for files which do not have an icon
3192# explicitly set.
3193#
3194DefaultIcon /icons/unknown.gif
3195
3196#
3197# AddDescription allows you to place a short description after a file in
3198# server-generated indexes. These are only displayed for FancyIndexed
3199# directories.
3200# Format: AddDescription "description" filename
3201#
3202#AddDescription "GZIP compressed document" .gz
3203#AddDescription "tar archive" .tar
3204#AddDescription "GZIP compressed tar archive" .tgz
3205
3206#
3207# ReadmeName is the name of the README file the server will look for by
3208# default, and append to directory listings.
3209#
3210# HeaderName is the name of a file which should be prepended to
3211# directory indexes.
3212ReadmeName README.html
3213HeaderName HEADER.html
3214
3215#
3216# IndexIgnore is a set of filenames which directory indexing should ignore
3217# and not include in the listing. Shell-style wildcarding is permitted.
3218#
3219IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t
3220
3221#
3222# DefaultLanguage and AddLanguage allows you to specify the language of
3223# a document. You can then use content negotiation to give a browser a
3224# file in a language the user can understand.
3225#
3226# Specify a default language. This means that all data
3227# going out without a specific language tag (see below) will
3228# be marked with this one. You probably do NOT want to set
3229# this unless you are sure it is correct for all cases.
3230#
3231# * It is generally better to not mark a page as
3232# * being a certain language than marking it with the wrong
3233# * language!
3234#
3235# DefaultLanguage nl
3236#
3237# Note 1: The suffix does not have to be the same as the language
3238# keyword --- those with documents in Polish (whose net-standard
3239# language code is pl) may wish to use "AddLanguage pl .po" to
3240# avoid the ambiguity with the common suffix for perl scripts.
3241#
3242# Note 2: The example entries below illustrate that in some cases
3243# the two character 'Language' abbreviation is not identical to
3244# the two character 'Country' code for its country,
3245# E.g. 'Danmark/dk' versus 'Danish/da'.
3246#
3247# Note 3: In the case of 'ltz' we violate the RFC by using a three char
3248# specifier. There is 'work in progress' to fix this and get
3249# the reference data for rfc1766 cleaned up.
3250#
3251# Catalan (ca) - Croatian (hr) - Czech (cs) - Danish (da) - Dutch (nl)
3252# English (en) - Esperanto (eo) - Estonian (et) - French (fr) - German (de)
3253# Greek-Modern (el) - Hebrew (he) - Italian (it) - Japanese (ja)
3254# Korean (ko) - Luxembourgeois* (ltz) - Norwegian Nynorsk (nn)
3255# Norwegian (no) - Polish (pl) - Portugese (pt)
3256# Brazilian Portuguese (pt-BR) - Russian (ru) - Swedish (sv)
3257# Simplified Chinese (zh-CN) - Spanish (es) - Traditional Chinese (zh-TW)
3258#
3259AddLanguage ca .ca
3260AddLanguage cs .cz .cs
3261AddLanguage da .dk
3262AddLanguage de .de
3263AddLanguage el .el
3264AddLanguage en .en
3265AddLanguage eo .eo
3266AddLanguage es .es
3267AddLanguage et .et
3268AddLanguage fr .fr
3269AddLanguage he .he
3270AddLanguage hr .hr
3271AddLanguage it .it
3272AddLanguage ja .ja
3273AddLanguage ko .ko
3274AddLanguage ltz .ltz
3275AddLanguage nl .nl
3276AddLanguage nn .nn
3277AddLanguage no .no
3278AddLanguage pl .po
3279AddLanguage pt .pt
3280AddLanguage pt-BR .pt-br
3281AddLanguage ru .ru
3282AddLanguage sv .sv
3283AddLanguage zh-CN .zh-cn
3284AddLanguage zh-TW .zh-tw
3285
3286#
3287# LanguagePriority allows you to give precedence to some languages
3288# in case of a tie during content negotiation.
3289#
3290# Just list the languages in decreasing order of preference. We have
3291# more or less alphabetized them here. You probably want to change this.
3292#
3293LanguagePriority en ca cs da de el eo es et fr he hr it ja ko ltz nl nn no pl pt pt-BR ru sv zh-CN zh-TW
3294
3295#
3296# ForceLanguagePriority allows you to serve a result page rather than
3297# MULTIPLE CHOICES (Prefer) [in case of a tie] or NOT ACCEPTABLE (Fallback)
3298# [in case no accepted languages matched the available variants]
3299#
3300ForceLanguagePriority Prefer Fallback
3301
3302#
3303# Specify a default charset for all content served; this enables
3304# interpretation of all content as UTF-8 by default. To use the
3305# default browser choice (ISO-8859-1), or to allow the META tags
3306# in HTML content to override this choice, comment out this
3307# directive:
3308#
3309#x# AddDefaultCharset UTF-8
3310AddDefaultCharset Off
3311
3312#
3313# AddType allows you to add to or override the MIME configuration
3314# file mime.types for specific file types.
3315#
3316#AddType application/x-tar .tgz
3317
3318#
3319# AddEncoding allows you to have certain browsers uncompress
3320# information on the fly. Note: Not all browsers support this.
3321# Despite the name similarity, the following Add* directives have nothing
3322# to do with the FancyIndexing customization directives above.
3323#
3324#AddEncoding x-compress .Z
3325#AddEncoding x-gzip .gz .tgz
3326
3327# If the AddEncoding directives above are commented-out, then you
3328# probably should define those extensions to indicate media types:
3329#
3330AddType application/x-compress .Z
3331AddType application/x-gzip .gz .tgz
3332
3333#
3334# MIME-types for downloading Certificates and CRLs
3335#
3336AddType application/x-x509-ca-cert .crt
3337AddType application/x-pkcs7-crl .crl
3338
3339#
3340# AddHandler allows you to map certain file extensions to "handlers":
3341# actions unrelated to filetype. These can be either built into the server
3342# or added with the Action directive (see below)
3343#
3344# To use CGI scripts outside of ScriptAliased directories:
3345# (You will also need to add "ExecCGI" to the "Options" directive.)
3346#
3347#AddHandler cgi-script .cgi
3348
3349#
3350# For files that include their own HTTP headers:
3351#
3352#AddHandler send-as-is asis
3353
3354#
3355# For type maps (negotiated resources):
3356# (This is enabled by default to allow the Apache "It Worked" page
3357# to be distributed in multiple languages.)
3358#
3359AddHandler type-map var
3360
3361#
3362# Filters allow you to process content before it is sent to the client.
3363#
3364# To parse .shtml files for server-side includes (SSI):
3365# (You will also need to add "Includes" to the "Options" directive.)
3366#
3367AddType text/html .shtml
3368AddOutputFilter INCLUDES .shtml
3369
3370#
3371# Action lets you define media types that will execute a script whenever
3372# a matching file is called. This eliminates the need for repeated URL
3373# pathnames for oft-used CGI file processors.
3374# Format: Action media/type /cgi-script/location
3375# Format: Action handler-name /cgi-script/location
3376#
3377
3378#
3379# Customizable error responses come in three flavors:
3380# 1) plain text 2) local redirects 3) external redirects
3381#
3382# Some examples:
3383#ErrorDocument 500 "The server made a boo boo."
3384#ErrorDocument 404 /missing.html
3385#ErrorDocument 404 "/cgi-bin/missing_handler.pl"
3386#ErrorDocument 402 http://www.example.com/subscription_info.html
3387#
3388
3389#
3390# Putting this all together, we can internationalize error responses.
3391#
3392# We use Alias to redirect any /error/HTTP_<error>.html.var response to
3393# our collection of by-error message multi-language collections. We use
3394# includes to substitute the appropriate text.
3395#
3396# You can modify the messages' appearance without changing any of the
3397# default HTTP_<error>.html.var files by adding the line:
3398#
3399# Alias /error/include/ "/your/include/path/"
3400#
3401# which allows you to create your own set of files by starting with the
3402# /var/www/error/include/ files and
3403# copying them to /your/include/path/, even on a per-VirtualHost basis.
3404#
3405
3406#x# Alias /error/ "/var/www/error/"
3407Alias /error/ "/var/www/alfacorpltda.cl/error/"
3408
3409<IfModule mod_negotiation.c>
3410<IfModule mod_include.c>
3411#x# <Directory "/var/www/error">
3412 <Directory "/var/www/alfacorpltda.cl/error">
3413 AllowOverride None
3414 Options IncludesNoExec
3415 AddOutputFilter Includes html
3416 AddHandler type-map var
3417 Order allow,deny
3418 Allow from all
3419 LanguagePriority en es de fr
3420 ForceLanguagePriority Prefer Fallback
3421 </Directory>
3422
3423# ErrorDocument 400 /error/HTTP_BAD_REQUEST.html.var
3424# ErrorDocument 401 /error/HTTP_UNAUTHORIZED.html.var
3425# ErrorDocument 403 /error/HTTP_FORBIDDEN.html.var
3426# ErrorDocument 404 /error/HTTP_NOT_FOUND.html.var
3427# ErrorDocument 405 /error/HTTP_METHOD_NOT_ALLOWED.html.var
3428# ErrorDocument 408 /error/HTTP_REQUEST_TIME_OUT.html.var
3429# ErrorDocument 410 /error/HTTP_GONE.html.var
3430# ErrorDocument 411 /error/HTTP_LENGTH_REQUIRED.html.var
3431# ErrorDocument 412 /error/HTTP_PRECONDITION_FAILED.html.var
3432# ErrorDocument 413 /error/HTTP_REQUEST_ENTITY_TOO_LARGE.html.var
3433# ErrorDocument 414 /error/HTTP_REQUEST_URI_TOO_LARGE.html.var
3434# ErrorDocument 415 /error/HTTP_UNSUPPORTED_MEDIA_TYPE.html.var
3435# ErrorDocument 500 /error/HTTP_INTERNAL_SERVER_ERROR.html.var
3436# ErrorDocument 501 /error/HTTP_NOT_IMPLEMENTED.html.var
3437# ErrorDocument 502 /error/HTTP_BAD_GATEWAY.html.var
3438# ErrorDocument 503 /error/HTTP_SERVICE_UNAVAILABLE.html.var
3439# ErrorDocument 506 /error/HTTP_VARIANT_ALSO_VARIES.html.var
3440
3441</IfModule>
3442</IfModule>
3443
3444#
3445# The following directives modify normal HTTP response behavior to
3446# handle known problems with browser implementations.
3447#
3448BrowserMatch "Mozilla/2" nokeepalive
3449BrowserMatch "MSIE 4\.0b2;" nokeepalive downgrade-1.0 force-response-1.0
3450BrowserMatch "RealPlayer 4\.0" force-response-1.0
3451BrowserMatch "Java/1\.0" force-response-1.0
3452BrowserMatch "JDK/1\.0" force-response-1.0
3453
3454#
3455# The following directive disables redirects on non-GET requests for
3456# a directory that does not include the trailing slash. This fixes a
3457# problem with Microsoft WebFolders which does not appropriately handle
3458# redirects for folders with DAV methods.
3459# Same deal with Apple's DAV filesystem and Gnome VFS support for DAV.
3460#
3461BrowserMatch "Microsoft Data Access Internet Publishing Provider" redirect-carefully
3462BrowserMatch "MS FrontPage" redirect-carefully
3463BrowserMatch "^WebDrive" redirect-carefully
3464BrowserMatch "^WebDAVFS/1.[0123]" redirect-carefully
3465BrowserMatch "^gnome-vfs/1.0" redirect-carefully
3466BrowserMatch "^XML Spy" redirect-carefully
3467BrowserMatch "^Dreamweaver-WebDAV-SCM1" redirect-carefully
3468
3469#
3470# Allow server status reports generated by mod_status,
3471# with the URL of http://servername/server-status
3472# Change the ".example.com" to match your domain to enable.
3473#
3474#<Location /server-status>
3475# SetHandler server-status
3476# Order deny,allow
3477# Deny from all
3478# Allow from .example.com
3479#</Location>
3480
3481#
3482# Allow remote server configuration reports, with the URL of
3483# http://servername/server-info (requires that mod_info.c be loaded).
3484# Change the ".example.com" to match your domain to enable.
3485#
3486#<Location /server-info>
3487# SetHandler server-info
3488# Order deny,allow
3489# Deny from all
3490# Allow from .example.com
3491#</Location>
3492
3493#
3494# Proxy Server directives. Uncomment the following lines to
3495# enable the proxy server:
3496#
3497#<IfModule mod_proxy.c>
3498#ProxyRequests On
3499#
3500#<Proxy *>
3501# Order deny,allow
3502# Deny from all
3503# Allow from .example.com
3504#</Proxy>
3505
3506#
3507# Enable/disable the handling of HTTP/1.1 "Via:" headers.
3508# ("Full" adds the server version; "Block" removes all outgoing Via: headers)
3509# Set to one of: Off | On | Full | Block
3510#
3511#ProxyVia On
3512
3513#
3514# To enable a cache of proxied content, uncomment the following lines.
3515# See http://httpd.apache.org/docs/2.2/mod/mod_cache.html for more details.
3516#
3517#<IfModule mod_disk_cache.c>
3518# CacheEnable disk /
3519# CacheRoot "/var/cache/mod_proxy"
3520#</IfModule>
3521#
3522
3523#</IfModule>
3524# End of proxy directives.
3525
3526### Section 3: Virtual Hosts
3527#
3528# VirtualHost: If you want to maintain multiple domains/hostnames on your
3529# machine you can setup VirtualHost containers for them. Most configurations
3530# use only name-based virtual hosts so the server doesn't need to worry about
3531# IP addresses. This is indicated by the asterisks in the directives below.
3532#
3533# Please see the documentation at
3534# <URL:http://httpd.apache.org/docs/2.2/vhosts/>
3535# for further details before you try to setup virtual hosts.
3536#
3537# You may use the command line option '-S' to verify your virtual host
3538# configuration.
3539
3540#
3541# Use name-based virtual hosting.
3542#
3543#NameVirtualHost *:80
3544#
3545# NOTE: NameVirtualHost cannot be used without a port specifier
3546# (e.g. :80) if mod_ssl is being used, due to the nature of the
3547# SSL protocol.
3548#
3549
3550#
3551# VirtualHost example:
3552# Almost any Apache directive may go into a VirtualHost container.
3553# The first VirtualHost section is used for requests without a known
3554# server name.
3555#
3556#<VirtualHost *:80>
3557# ServerAdmin webmaster@dummy-host.example.com
3558# DocumentRoot /www/docs/dummy-host.example.com
3559# ServerName dummy-host.example.com
3560# ErrorLog logs/dummy-host.example.com-error_log
3561# CustomLog logs/dummy-host.example.com-access_log common
3562#</VirtualHost>
3563############################# }- httpd.conf #############################
3564
3565vim /etc/httpd/conf.d/serversignature.conf
3566
3567############################# serversignature.conf -{ #############################
3568ServerSignature Off
3569ServerTokens Prod
3570############################# }- serversignature.conf #############################
3571
3572vim /etc/httpd/conf.d/ssl.conf
3573
3574############################# ssl.conf -{ #############################
3575#
3576# This is the Apache server configuration file providing SSL support.
3577# It contains the configuration directives to instruct the server how to
3578# serve pages over an https connection. For detailing information about these
3579# directives see <URL:http://httpd.apache.org/docs/2.2/mod/mod_ssl.html>
3580#
3581# Do NOT simply read the instructions in here without understanding
3582# what they do. They're here only as hints or reminders. If you are unsure
3583# consult the online docs. You have been warned.
3584#
3585
3586LoadModule ssl_module modules/mod_ssl.so
3587
3588#
3589# When we also provide SSL we have to listen to the
3590# the HTTPS port in addition.
3591#
3592#x# Listen 443
3593Listen 172.16.8.13:443
3594
3595##
3596## SSL Global Context
3597##
3598## All SSL configuration in this context applies both to
3599## the main server and all SSL-enabled virtual hosts.
3600##
3601
3602# Pass Phrase Dialog:
3603# Configure the pass phrase gathering process.
3604# The filtering dialog program (`builtin' is a internal
3605# terminal dialog) has to provide the pass phrase on stdout.
3606SSLPassPhraseDialog builtin
3607
3608# Inter-Process Session Cache:
3609# Configure the SSL Session Cache: First the mechanism
3610# to use and second the expiring timeout (in seconds).
3611SSLSessionCache shmcb:/var/cache/mod_ssl/scache(512000)
3612SSLSessionCacheTimeout 300
3613
3614# Semaphore:
3615# Configure the path to the mutual exclusion semaphore the
3616# SSL engine uses internally for inter-process synchronization.
3617SSLMutex default
3618
3619# Pseudo Random Number Generator (PRNG):
3620# Configure one or more sources to seed the PRNG of the
3621# SSL library. The seed data should be of good random quality.
3622# WARNING! On some platforms /dev/random blocks if not enough entropy
3623# is available. This means you then cannot use the /dev/random device
3624# because it would lead to very long connection times (as long as
3625# it requires to make more entropy available). But usually those
3626# platforms additionally provide a /dev/urandom device which doesn't
3627# block. So, if available, use this one instead. Read the mod_ssl User
3628# Manual for more details.
3629SSLRandomSeed startup file:/dev/urandom 256
3630SSLRandomSeed connect builtin
3631#SSLRandomSeed startup file:/dev/random 512
3632#SSLRandomSeed connect file:/dev/random 512
3633#SSLRandomSeed connect file:/dev/urandom 512
3634
3635#
3636# Use "SSLCryptoDevice" to enable any supported hardware
3637# accelerators. Use "openssl engine -v" to list supported
3638# engine names. NOTE: If you enable an accelerator and the
3639# server does not start, consult the error logs and ensure
3640# your accelerator is functioning properly.
3641#
3642SSLCryptoDevice builtin
3643#SSLCryptoDevice ubsec
3644
3645##
3646## SSL Virtual Host Context
3647##
3648
3649<VirtualHost _default_:443>
3650
3651# General setup for the virtual host, inherited from global configuration
3652#DocumentRoot "/var/www/html"
3653#x#
3654DocumentRoot "/var/www/alfacorpltda.cl/"
3655#ServerName www.example.com:443
3656#x#
3657ServerName www.alfacorpltda.cl:443
3658
3659# Use separate log files for the SSL virtual host; note that LogLevel
3660# is not inherited from httpd.conf.
3661ErrorLog logs/ssl_error_log
3662TransferLog logs/ssl_access_log
3663LogLevel warn
3664
3665# SSL Engine Switch:
3666# Enable/Disable SSL for this virtual host.
3667SSLEngine on
3668
3669# SSL Protocol support:
3670# List the enable protocol levels with which clients will be able to
3671# connect. Disable SSLv2 access by default:
3672#x# SSLProtocol all -SSLv2
3673SSLProtocol all -SSLv2 -SSLv3
3674
3675# SSL Cipher Suite:
3676# List the ciphers that the client is permitted to negotiate.
3677# See the mod_ssl documentation for a complete list.
3678SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW
3679
3680# Server Certificate:
3681# Point SSLCertificateFile at a PEM encoded certificate. If
3682# the certificate is encrypted, then you will be prompted for a
3683# pass phrase. Note that a kill -HUP will prompt again. A new
3684# certificate can be generated using the genkey(1) command.
3685#x# SSLCertificateFile /etc/pki/tls/certs/localhost.crt
3686SSLCertificateFile /etc/pki/tls/certs/www.alfacorpltda.cl.crt
3687
3688# Server Private Key:
3689# If the key is not combined with the certificate, use this
3690# directive to point at the key file. Keep in mind that if
3691# you've both a RSA and a DSA private key you can configure
3692# both in parallel (to also allow the use of DSA ciphers, etc.)
3693#x# SSLCertificateKeyFile /etc/pki/tls/private/localhost.key
3694SSLCertificateKeyFile /etc/pki/tls/private/www.alfacorpltda.cl.key
3695
3696# Server Certificate Chain:
3697# Point SSLCertificateChainFile at a file containing the
3698# concatenation of PEM encoded CA certificates which form the
3699# certificate chain for the server certificate. Alternatively
3700# the referenced file can be the same as SSLCertificateFile
3701# when the CA certificates are directly appended to the server
3702# certificate for convinience.
3703#SSLCertificateChainFile /etc/pki/tls/certs/server-chain.crt
3704
3705# Certificate Authority (CA):
3706# Set the CA certificate verification path where to find CA
3707# certificates for client authentication or alternatively one
3708# huge file containing all of them (file must be PEM encoded)
3709#SSLCACertificateFile /etc/pki/tls/certs/ca-bundle.crt
3710
3711# Client Authentication (Type):
3712# Client certificate verification type and depth. Types are
3713# none, optional, require and optional_no_ca. Depth is a
3714# number which specifies how deeply to verify the certificate
3715# issuer chain before deciding the certificate is not valid.
3716#SSLVerifyClient require
3717#SSLVerifyDepth 10
3718
3719# Access Control:
3720# With SSLRequire you can do per-directory access control based
3721# on arbitrary complex boolean expressions containing server
3722# variable checks and other lookup directives. The syntax is a
3723# mixture between C and Perl. See the mod_ssl documentation
3724# for more details.
3725#<Location />
3726#SSLRequire ( %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
3727# and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
3728# and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
3729# and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
3730# and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20 ) \
3731# or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
3732#</Location>
3733
3734# SSL Engine Options:
3735# Set various options for the SSL engine.
3736# o FakeBasicAuth:
3737# Translate the client X.509 into a Basic Authorisation. This means that
3738# the standard Auth/DBMAuth methods can be used for access control. The
3739# user name is the `one line' version of the client's X.509 certificate.
3740# Note that no password is obtained from the user. Every entry in the user
3741# file needs this password: `xxj31ZMTZzkVA'.
3742# o ExportCertData:
3743# This exports two additional environment variables: SSL_CLIENT_CERT and
3744# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
3745# server (always existing) and the client (only existing when client
3746# authentication is used). This can be used to import the certificates
3747# into CGI scripts.
3748# o StdEnvVars:
3749# This exports the standard SSL/TLS related `SSL_*' environment variables.
3750# Per default this exportation is switched off for performance reasons,
3751# because the extraction step is an expensive operation and is usually
3752# useless for serving static content. So one usually enables the
3753# exportation for CGI and SSI requests only.
3754# o StrictRequire:
3755# This denies access when "SSLRequireSSL" or "SSLRequire" applied even
3756# under a "Satisfy any" situation, i.e. when it applies access is denied
3757# and no other module can change it.
3758# o OptRenegotiate:
3759# This enables optimized SSL connection renegotiation handling when SSL
3760# directives are used in per-directory context.
3761#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
3762<Files ~ "\.(cgi|shtml|phtml|php3?)$">
3763 SSLOptions +StdEnvVars
3764</Files>
3765#x# <Directory "/var/www/cgi-bin">
3766<Directory "/var/www/alfacorpltda.cl/cgi-bin">
3767 SSLOptions +StdEnvVars
3768</Directory>
3769
3770# SSL Protocol Adjustments:
3771# The safe and default but still SSL/TLS standard compliant shutdown
3772# approach is that mod_ssl sends the close notify alert but doesn't wait for
3773# the close notify alert from client. When you need a different shutdown
3774# approach you can use one of the following variables:
3775# o ssl-unclean-shutdown:
3776# This forces an unclean shutdown when the connection is closed, i.e. no
3777# SSL close notify alert is send or allowed to received. This violates
3778# the SSL/TLS standard but is needed for some brain-dead browsers. Use
3779# this when you receive I/O errors because of the standard approach where
3780# mod_ssl sends the close notify alert.
3781# o ssl-accurate-shutdown:
3782# This forces an accurate shutdown when the connection is closed, i.e. a
3783# SSL close notify alert is send and mod_ssl waits for the close notify
3784# alert of the client. This is 100% SSL/TLS standard compliant, but in
3785# practice often causes hanging connections with brain-dead browsers. Use
3786# this only for browsers where you know that their SSL implementation
3787# works correctly.
3788# Notice: Most problems of broken clients are also related to the HTTP
3789# keep-alive facility, so you usually additionally want to disable
3790# keep-alive for those clients, too. Use variable "nokeepalive" for this.
3791# Similarly, one has to force some clients to use HTTP/1.0 to workaround
3792# their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
3793# "force-response-1.0" for this.
3794SetEnvIf User-Agent ".*MSIE.*" \
3795 nokeepalive ssl-unclean-shutdown \
3796 downgrade-1.0 force-response-1.0
3797
3798# Per-Server Logging:
3799# The home of a custom SSL log file. Use this when you want a
3800# compact non-error SSL logfile on a virtual host basis.
3801CustomLog logs/ssl_request_log \
3802 "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
3803
3804</VirtualHost>
3805############################# }- ssl.conf #############################
3806
3807vim /etc/httpd/conf.d/alfacorpltda.cl.conf
3808
3809############################# alfacorpltda.cl.conf -{ #############################
3810NameVirtualHost 172.16.8.13:80
3811 <VirtualHost 172.16.8.13:80>
3812 ServerAdmin webmaster@alfacorpltda.cl
3813 DocumentRoot /var/www/alfacorpltda.cl
3814 ServerName www.alfacorpltda.cl
3815 ServerAlias alfacorpltda.cl
3816 Redirect 301 / https://www.alfacorpltda.cl/
3817 CustomLog logs/alfacorpltda.cl-access_log combined
3818 Errorlog logs/alfacorpltda.cl-error_log
3819 </VirtualHost>
3820
3821NameVirtualHost 172.16.8.13:443
3822 <VirtualHost 172.16.8.13:443>
3823 ServerAdmin webmaster@alfacorpltda.cl
3824 DocumentRoot /var/www/alfacorpltda.cl
3825 ServerName www.alfacorpltda.cl
3826 ScriptAlias /cgi-bin/ /var/www/alfacorpltda.cl/cgi-bin/
3827 <Directory "/var/www/alfacorpltda.cl/cgi-bin">
3828 SSLOptions +StdEnvVars
3829 </Directory>
3830 SSLEngine on
3831 SSLProtocol all -SSLv2
3832 SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW
3833 SSLCertificateFile /etc/pki/tls/certs/www.alfacorpltda.cl.crt
3834 SSLCertificateKeyFile /etc/pki/tls/private/www.alfacorpltda.cl.pem
3835 SetEnvIf User-Agent ".*MSIE.*" \
3836 nokeepalive ssl-unclean-shutdown \
3837 downgrade-1.0 force-response-1.0
3838 CustomLog logs/alfacorpltda.cl-ssl_request_log \
3839 "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
3840 Errorlog logs/alfacorpltda.cl-ssl_error_log
3841 TransferLog logs/alfacorpltda.cl-ssl_access_log
3842 LogLevel warn
3843 </VirtualHost>
3844############################# }- alfacorpltda.cl.conf #############################
3845
3846vim /etc/httpd/conf.d/desarollo.conf
3847
3848############################# desarollo.conf -{ #############################
3849Alias /desarrollo /var/www/alfacorpltda.cl/desarrollo
3850 <Directory "/var/www/alfacorpltda.cl/desarrollo">
3851 Order deny,allow
3852 Deny from all
3853 Allow from 127.0.0.0/8 172.16.8.0/22
3854 Options Indexes Includes SymLinksIfOwnerMatch
3855 AllowOverride All
3856 AuthName "ALDACORP Ltda: Solo usuarios autorizados"
3857 AuthType Basic
3858 Require valid-user
3859 AuthUserFile /var/www/htpasswd/.htpasswd_desarollo
3860 </Directory>
3861############################# }- desarollo.conf #############################
3862
3863vim /etc/httpd/conf.d/ventas.conf
3864
3865############################# ventas.conf -{ #############################
3866Alias /ventas /var/www/alfacorpltda.cl/ventas
3867 <Directory "/var/www/alfacorpltda.cl/ventas">
3868 Order deny,allow
3869 Deny from all
3870 Allow from 127.0.0.0/8 172.16.4.0/22
3871 Options Indexes Includes SymLinksIfOwnerMatch
3872 AllowOverride All
3873 AuthName "ALFACORP Ltda: Solo usuarios autorizados"
3874 AuthType Basic
3875 Require valid-user
3876 AuthUserFile /var/www/htpasswd/.htpasswd_ventas
3877 </Directory>
3878############################# }- ventas.conf #############################
3879
3880vim /etc/httpd/conf.d/recepcion.conf
3881
3882############################# recepcion.conf -{ #############################
3883Alias /recepcion /var/www/alfacorpltda.cl/recepcion
3884 <Directory "/var/www/alfacorpltda.cl/recepcion">
3885 Order deny,allow
3886 Deny from all
3887 Allow from 127.0.0.0/8 172.16.0.0/22
3888 Options Indexes Includes SymLinksIfOwnerMatch
3889 AllowOverride All
3890 AuthName "ALFACORP Ltda: Solo usuarios autorizados"
3891 AuthType Basic
3892 Require valid-user
3893 AuthUserFile /var/www/htpasswd/.htpasswd_recepcion
3894 </Directory>
3895############################# }- recepcion.conf #############################
3896
3897vim /var/www/alfacorpltda.cl/index.html
3898
3899############################# index.html -{ #############################
3900<!DOCTYPE html>
3901<html lang="es">
3902 <head>
3903 <meta charset="UTF-8">
3904 <title>ALFACORP Ltda - Index</title>
3905 </head>
3906 <body>
3907 <table width="800" border="0" align="center">
3908 <tr><td align="center">
3909 <!-- <img src="./alfacorp_2.png" alt="Oops"> -->
3910 <font face="Arial Black"; color="#FFBF00"; size=70; >ALFACORP</font><font face="Arial Black"; color="#0B0B61"; size=70; >LTDA</font>
3911 <h1><font face="Arial Narrow"; size=4; >"Implementacion y optimizacion de los servicios de red para una PYME"</font></h1>
3912 <hr>
3913 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3914 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3915 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3916 <hr>
3917 <h1>Oops!</h1>
3918 <h3>Sitio en Mantenimiento.</h3>
3919 <p>
3920En ALFA Corp Ltda trabajamos para usted ahora y siempre.
3921 </p>
3922 <hr>
3923 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3924 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3925 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3926 <hr>
3927 </td></tr>
3928 </body>
3929</html>
3930
3931############################# }- index.html #############################
3932
3933vim /var/www/alfacorpltda.cl/ventas/index.html
3934
3935############################# index.html -{ #############################
3936<!DOCTYPE html>
3937<html lang="es">
3938 <head>
3939 <meta charset="UTF-8">
3940 <title>ALFACORP Ltda - Ventas</title>
3941 </head>
3942 <body>
3943 <table width="800" border="0" align="center">
3944 <tr><td align="center">
3945 <!-- <img src="./alfacorp_2.png" alt="Oops"> -->
3946 <font face="Arial Black"; color="#FFBF00"; size=70; >ALFACORP</font><font face="Arial Black"; color="#0B0B61"; size=70; >LTDA</font>
3947 <h1><font face="Arial Narrow"; size=4; >"Implementacion y optimizacion de los servicios de red para una PYME"</font></h1>
3948 <hr>
3949 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3950 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3951 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3952 <hr>
3953 <h1>Oops!</h1>
3954 <h3>Sitio en Mantenimiento.</h3>
3955 <p>
3956En ALFA Corp Ltda trabajamos para usted ahora y siempre.
3957 </p>
3958 <hr>
3959 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3960 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3961 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3962 <hr>
3963 </td></tr>
3964 </body>
3965</html>
3966
3967############################# }- index.html #############################
3968
3969vim /var/www/alfacorpltda.cl/desarollo/index.html
3970
3971############################# index.html -{ #############################
3972<!DOCTYPE html>
3973<html lang="es">
3974 <head>
3975 <meta charset="UTF-8">
3976 <title>ALFACORP Ltda - Desarrolo</title>
3977 </head>
3978 <body>
3979 <table width="800" border="0" align="center">
3980 <tr><td align="center">
3981 <!-- <img src="./alfacorp_2.png" alt="Oops"> -->
3982 <font face="Arial Black"; color="#FFBF00"; size=70; >ALFACORP</font><font face="Arial Black"; color="#0B0B61"; size=70; >LTDA</font>
3983 <h1><font face="Arial Narrow"; size=4; >"Implementacion y optimizacion de los servicios de red para una PYME"</font></h1>
3984 <hr>
3985 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3986 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3987 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3988 <hr>
3989 <h1>Oops!</h1>
3990 <h3>Sitio en Mantenimiento.</h3>
3991 <p>
3992En ALFA Corp Ltda trabajamos para usted ahora y siempre.
3993 </p>
3994 <hr>
3995 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
3996 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
3997 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
3998 <hr>
3999 </td></tr>
4000 </body>
4001</html>
4002
4003############################# }- index.html #############################
4004
4005vim /var/www/alfacorpltda.cl/recepcion/index.html
4006
4007############################# index.html -{ #############################
4008<!DOCTYPE html>
4009<html lang="es">
4010 <head>
4011 <meta charset="UTF-8">
4012 <title>ALFACORP Ltda - Recepcion</title>
4013 </head>
4014 <body>
4015 <table width="800" border="0" align="center">
4016 <tr><td align="center">
4017 <!-- <img src="./alfacorp_2.png" alt="Oops"> -->
4018 <font face="Arial Black"; color="#FFBF00"; size=70; >ALFACORP</font><font face="Arial Black"; color="#0B0B61"; size=70; >LTDA</font>
4019 <h1><font face="Arial Narrow"; size=4; >"Implementacion y optimizacion de los servicios de red para una PYME"</font></h1>
4020 <hr>
4021 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
4022 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
4023 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
4024 <hr>
4025 <h1>Oops!</h1>
4026 <h3>Sitio en Mantenimiento.</h3>
4027 <p>
4028En ALFA Corp Ltda trabajamos para usted ahora y siempre.
4029 </p>
4030 <hr>
4031 <a href="http://www.alfacorpltda.cl/desarrollo/">Desarrollo</a>
4032 <a href="http://www.alfacorpltda.cl/ventas/">Ventas</a>
4033 <a href="http://www.alfacorpltda.cl/recepcion/">Recepcion</a>
4034 <hr>
4035 </td></tr>
4036 </body>
4037</html>
4038############################# }- index.html #############################
4039
4040cp -af /var/www/icons/* /var/www/alfacorpltda.cl/icons/
4041cp -af /var/www/error/* /var/www/alfacorpltda.cl/error/
4042
4043touch /var/www/htpasswd/.htpasswd_desarollo
4044touch /var/www/htpasswd/.htpasswd_ventas
4045touch /var/www/htpasswd/.htpasswd_recepcion
4046
4047chcon -t httpd_sys_content_t /var/www/alfacorpltda.cl
4048chcon -t httpd_sys_script_ro_t /var/www/alfacorpltda.cl/desarollo/index.html
4049chcon -t httpd_sys_script_ro_t /var/www/alfacorpltda.cl/ventas/index.html
4050chcon -t httpd_sys_script_ro_t /var/www/alfacorpltda.cl/recepcion/index.html
4051chcon -t httpd_sys_script_ro_t /var/www/alfacorpltda.cl/index.html
4052
4053chmod 600 /var/www/htpasswd/.htpasswd_*
4054chown apache:apache /var/www/htpasswd/.htpasswd_*
4055
4056htpasswd -b -c /var/www/htpasswd/.htpasswd_desarollo usuario1d 123456
4057htpasswd -b -c /var/www/htpasswd/.htpasswd_ventas usuario1v 123456
4058htpasswd -b -c /var/www/htpasswd/.htpasswd_recepcion usuario1r 123456
4059
4060rm -f /etc/pki/tls/*/www.alfacorpltda.cl.*
4061
4062openssl genrsa -des3 -out /etc/pki/tls/private/www.alfacorpltda.cl.key 4096
4063openssl rsa -in /etc/pki/tls/private/www.alfacorpltda.cl.key -out /etc/pki/tls/private/www.alfacorpltda.cl.pem
4064openssl req -sha256 -new -key /etc/pki/tls/private/www.alfacorpltda.cl.key -out /etc/pki/tls/certs/www.alfacorpltda.cl.csr
4065
4066 CL
4067 R Metropolitana
4068 Melipilla
4069 ALFA Corp Ltda
4070 Pyme
4071 www.alfacorpltda.cl
4072 webmaster@alfacorpltda.cl
4073
4074
4075
4076openssl x509 -sha256 -req -days 1825 -in /etc/pki/tls/certs/www.alfacorpltda.cl.csr -signkey /etc/pki/tls/private/www.alfacorpltda.cl.key -out /etc/pki/tls/certs/www.alfacorpltda.cl.crt
4077
4078chmod 400 /etc/pki/tls/*/www.alfacorpltda.cl.*
4079
4080setsebool -P httpd_can_sendmail 1
4081setsebool -P httpd_read_user_content 1
4082setsebool -P httpd_enable_homedirs 1
4083setsebool -P httpd_enable_ftp_server 1
4084setsebool -P httpd_enable_cgi 0
4085setsebool -P httpd_ssi_exec 1
4086setsebool -P httpd_can_network_connect_db 1
4087setsebool -P httpd_can_network_connect 1
4088setsebool -P httpd_builtin_scripting 0
4089
4090service httpd restart
4091chkconfig httpd on
4092
4093## http://wwww.alfacorpltda.cl
4094## https://wwww.alfacorpltda.cl
4095
4096####################################### }- HTTPS
4097####################################### FTP -{
4098
4099cd
4100
4101yum -y install vsftpd
4102
4103service vsftpd stop
4104
4105vim /etc/vsftpd/vsftpd.conf
4106
4107############################# vsftpd.conf -{ #############################
4108# Example config file /etc/vsftpd/vsftpd.conf
4109#
4110# The default compiled in settings are fairly paranoid. This sample file
4111# loosens things up a bit, to make the ftp daemon more usable.
4112# Please see vsftpd.conf.5 for all compiled in defaults.
4113#
4114# READ THIS: This example file is NOT an exhaustive list of vsftpd options.
4115# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's
4116# capabilities.
4117#
4118# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
4119anonymous_enable=YES
4120#
4121# Uncomment this to allow local users to log in.
4122local_enable=YES
4123#
4124# Uncomment this to enable any form of FTP write command.
4125write_enable=YES
4126#
4127# Default umask for local users is 077. You may wish to change this to 022,
4128# if your users expect that (022 is used by most other ftpd's)
4129local_umask=022
4130#
4131# Uncomment this to allow the anonymous FTP user to upload files. This only
4132# has an effect if the above global write enable is activated. Also, you will
4133# obviously need to create a directory writable by the FTP user.
4134#anon_upload_enable=YES
4135#
4136# Uncomment this if you want the anonymous FTP user to be able to create
4137# new directories.
4138#anon_mkdir_write_enable=YES
4139#
4140# Activate directory messages - messages given to remote users when they
4141# go into a certain directory.
4142dirmessage_enable=YES
4143#
4144# Activate logging of uploads/downloads.
4145xferlog_enable=YES
4146#
4147# Make sure PORT transfer connections originate from port 20 (ftp-data).
4148connect_from_port_20=YES
4149#
4150# If you want, you can arrange for uploaded anonymous files to be owned by
4151# a different user. Note! Using "root" for uploaded files is not
4152# recommended!
4153#chown_uploads=YES
4154#chown_username=whoever
4155#
4156# You may override where the log file goes if you like. The default is shown
4157# below.
4158#x# Descomentar
4159xferlog_file=/var/log/vsftpd.log
4160#
4161# If you want, you can have your log file in standard ftpd xferlog format.
4162# Note that the default log file location is /var/log/xferlog in this case.
4163xferlog_std_format=YES
4164#
4165# You may change the default value for timing out an idle session.
4166#idle_session_timeout=600
4167#
4168# You may change the default value for timing out a data connection.
4169#data_connection_timeout=120
4170#
4171# It is recommended that you define on your system a unique user which the
4172# ftp server can use as a totally isolated and unprivileged user.
4173#nopriv_user=ftpsecure
4174#
4175# Enable this and the server will recognise asynchronous ABOR requests. Not
4176# recommended for security (the code is non-trivial). Not enabling it,
4177# however, may confuse older FTP clients.
4178#async_abor_enable=YES
4179#
4180# By default the server will pretend to allow ASCII mode but in fact ignore
4181# the request. Turn on the below options to have the server actually do ASCII
4182# mangling on files when in ASCII mode.
4183# Beware that on some FTP servers, ASCII support allows a denial of service
4184# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd
4185# predicted this attack and has always been safe, reporting the size of the
4186# raw file.
4187# ASCII mangling is a horrible feature of the protocol.
4188#ascii_upload_enable=YES
4189#ascii_download_enable=YES
4190#
4191# You may fully customise the login banner string:
4192#ftpd_banner=Welcome to blah FTP service.
4193#x#
4194ftpd_banner=ALFACORP Ltda: Bienvenido a FTP
4195#
4196# You may specify a file of disallowed anonymous e-mail addresses. Apparently
4197# useful for combatting certain DoS attacks.
4198#deny_email_enable=YES
4199# (default follows)
4200#banned_email_file=/etc/vsftpd/banned_emails
4201#
4202# You may specify an explicit list of local users to chroot() to their home
4203# directory. If chroot_local_user is YES, then this list becomes a list of
4204# users to NOT chroot().
4205#x# Descomentar -{
4206chroot_local_user=YES
4207chroot_list_enable=YES
4208# (default follows)
4209chroot_list_file=/etc/vsftpd/chroot_list
4210#x# }- Descomentar
4211#
4212# You may activate the "-R" option to the builtin ls. This is disabled by
4213# default to avoid remote users being able to cause excessive I/O on large
4214# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
4215# the presence of the "-R" option, so there is a strong case for enabling it.
4216#ls_recurse_enable=YES
4217#
4218# When "listen" directive is enabled, vsftpd runs in standalone mode and
4219# listens on IPv4 sockets. This directive cannot be used in conjunction
4220# with the listen_ipv6 directive.
4221listen=YES
4222#
4223# This directive enables listening on IPv6 sockets. To listen on IPv4 and IPv6
4224# sockets, you must run two copies of vsftpd with two configuration files.
4225# Make sure, that one of the listen options is commented !!
4226#listen_ipv6=YES
4227
4228pam_service_name=vsftpd
4229userlist_enable=YES
4230tcp_wrappers=YES
4231
4232#x# Agregar -{
4233pasv_min_port=30300
4234pasv_max_port=30309
4235anon_max_rate=2097152
4236local_max_rate=52428800
4237max_clients=50
4238max_per_ip=8
4239
4240#xx#anon_world_readable_only=yes
4241#xx#no_anon_password=yes
4242#xx#anon_root=/
4243#xx#local_root=/
4244#xx#download_enable=yes
4245#x# }- Agregar
4246############################# }- vsftpd.conf #############################
4247
4248vim /etc/vsftpd/chroot_list
4249
4250############################# chroot_list -{ #############################
4251usuario1d
4252usuario1r
4253usuario1v
4254############################# }- chroot_list #############################
4255
4256setsebool -P ftp_home_dir 1
4257setsebool -P allow_ftpd_full_access 1
4258
4259service vsftpd restart
4260chkconfig vsftpd on
4261
4262## ftp://ftp.alfacorpltda.cl
4263## ftp://user00d@ftp.alfacorpltda.cl
4264
4265####################################### }- FTP
4266####################################### SQUID -{
4267
4268cd
4269
4270yum -y install squid
4271
4272service squid stop
4273
4274vim /etc/squid/squid.conf
4275
4276############################# -{ #############################
4277#x# Agregar -{
4278visible_hostname pxy.alfacorpltda.cl
4279cache_mgr webmaster@alfacorpltda.cl
4280# auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/squid.auth
4281# acl ncsa_users proxy_auth REQUIRED
4282#x# }- Agregar
4283
4284#
4285# Recommended minimum configuration:
4286#
4287acl manager proto cache_object
4288acl localhost src 127.0.0.1/32
4289#x# acl localhost src ::1/128
4290acl to_localhost dst 127.0.0.0/8 0.0.0.0/32
4291#x# acl to_localhost dst ::1/128
4292
4293# Example rule allowing access from your local networks.
4294# Adapt to list your (internal) IP networks from where browsing
4295# should be allowed
4296#x# Comentar -{
4297# acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
4298# acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
4299# acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
4300# acl localnet src fc00::/7 # RFC 4193 local private network range
4301# acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines
4302#x# }- Comentar
4303#x# Agregar
4304acl localnet src 172.16.0.0/16
4305
4306acl SSL_ports port 443
4307acl Safe_ports port 80 # http
4308acl Safe_ports port 21 # ftp
4309acl Safe_ports port 443 # https
4310acl Safe_ports port 70 # gopher
4311acl Safe_ports port 210 # wais
4312acl Safe_ports port 1025-65535 # unregistered ports
4313acl Safe_ports port 280 # http-mgmt
4314acl Safe_ports port 488 # gss-http
4315acl Safe_ports port 591 # filemaker
4316acl Safe_ports port 777 # multiling http
4317acl CONNECT method CONNECT
4318
4319#x# Agregar -{
4320acl sitesredirect dstdomain "/etc/squid/sitesredirect.lst"
4321acl extensionsdeny urlpath_regex "/etc/squid/extensionsdeny.lst"
4322
4323acl localipallow src "/etc/squid/localipallow.lst"
4324acl localipdeny src "/etc/squid/localipdeny.lst"
4325
4326acl timetable time MTWHF 08:30-18:30
4327acl timetable time SA 08:30-17:30
4328
4329#http_access allow ncsa_users
4330#x# }- Agregar
4331
4332#
4333# Recommended minimum Access Permission configuration:
4334#
4335# Only allow cachemgr access from localhost
4336http_access allow manager localhost
4337http_access deny manager
4338
4339# Deny requests to certain unsafe ports
4340http_access deny !Safe_ports
4341
4342# Deny CONNECT to other than secure SSL ports
4343http_access deny CONNECT !SSL_ports
4344
4345# We strongly recommend the following be uncommented to protect innocent
4346# web applications running on the proxy server who think the only
4347# one who can access services on "localhost" is a local user
4348#http_access deny to_localhost
4349
4350#
4351# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
4352#
4353
4354#x# Agregar -{
4355#http_access allow localallow ncsa_users
4356http_access allow localipallow
4357http_access deny localipdeny
4358
4359deny_info http://www.alfacorpltda.cl localnet
4360http_reply_access deny sitesredirect localnet
4361http_access deny extensionsdeny localnet
4362
4363http_access allow timetable localnet
4364http_access deny localnet
4365#x# }- Agregar
4366
4367# Example rule allowing access from your local networks.
4368# Adapt localnet in the ACL section to list your (internal) IP networks
4369# from where browsing should be allowed
4370#x# http_access allow localnet
4371http_access allow localhost
4372
4373# And finally deny all other access to this proxy
4374http_access deny all
4375
4376# Squid normally listens to port 3128
4377#x# http_port 3128
4378http_port 172.16.8.14:3128
4379
4380# We recommend you to use at least the following line.
4381hierarchy_stoplist cgi-bin ?
4382
4383#x# Agregar -{
4384cache_mem 50 MB
4385maximum_object_size 50 MB
4386memory_pools off
4387## LRU #LFUDA #GDSF
4388cache_replacement_policy heap LFUDA
4389cache_swap_low 90
4390cache_swap_high 95
4391
4392cache_dir aufs /var/spool/squid 512 16 256
4393#x# }- Agregar
4394
4395# Uncomment and adjust the following to add a disk cache directory.
4396#cache_dir ufs /var/spool/squid 100 16 256
4397
4398# Leave coredumps in the first cache dir
4399coredump_dir /var/spool/squid
4400
4401# Add any of your own refresh_pattern entries above these.
4402refresh_pattern ^ftp: 1440 20% 10080
4403refresh_pattern ^gopher: 1440 0% 1440
4404refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
4405refresh_pattern . 0 20% 4320
4406############################# }- #############################
4407
4408vim /etc/squid/localipdeny.lst
4409
4410############################# -{ #############################
4411172.16.8.102
4412172.16.8.103
4413172.16.8.104
4414############################# }- #############################
4415
4416vim /etc/squid/localipallow.lst
4417
4418############################# -{ #############################
4419172.16.8.11
4420172.16.8.12
4421172.16.8.13
4422172.16.8.14
4423172.16.8.15
4424172.16.8.16
4425172.16.8.17
4426172.16.8.18
4427172.16.8.19
4428172.16.8.20
4429172.16.8.21
4430172.16.8.22
4431172.16.8.23
4432172.16.8.24
4433172.16.8.25
4434172.16.8.26
4435172.16.8.27
4436172.16.8.28
4437172.16.8.29
4438172.16.4.10
4439172.16.4.11
4440172.16.4.12
4441172.16.0.10
4442172.16.0.11
4443172.16.0.12
4444############################# }- #############################
4445
4446vim /etc/squid/sitesredirect.lst
4447
4448############################# -{ #############################
4449.facebook.com
4450.net
4451.org
4452.tk
4453.li
4454.info
4455############################# }- #############################
4456
4457vim /etc/squid/extensionsdeny.lst
4458
4459############################# -{ #############################
4460\.[Jj][Pp][Gg]\$
4461\.[Bb][Mm][Pp]\$
4462\.[Gg][Ii][Ff]\$
4463\.[Pp][Nn][Gg]\$
4464\.[Jj][Pp][Ee][Gg]\$
4465\.[Ii][Cc][Oo]\$
4466\.[Mm][Pp]3\$
4467\.[Mm][Pp]4\$
4468\.[Rr][Aa][Rr]\$
4469\.[Ee][Xx][Ee]\$
4470\.[Cc][Mm][Dd]\$
4471\.[Bb][Aa][Tt]\$
4472\.[Vv][Bb][Ss]\$
4473\.[Vv][Bb][Ee]\$
4474############################# }- #############################
4475
4476#chmod 600 /etc/squid/squid.auth
4477#chown squid:squid /etc/squid/squid.auth
4478#htpasswd -b -c /etc/squid/squid.auth usuario1d 123456
4479
4480setsebool -P squid_connect_any 1
4481setsebool -P squid_use_tproxy 1
4482
4483squid -z
4484service squid stop
4485service squid restart
4486chkconfig squid on
4487
4488####################################### }- SQUID
4489################################################# }- SERVIDOR 1
4490###################################################################################################
4491################################################# SERVIDOR 1b -{
4492####################################### NETWORK -{
4493
4494cd
4495
4496service network stop
4497
4498ip addr
4499
4500vim /etc/sysconfig/network-scripts/ifcfg-eth0
4501
4502############################# ifcfg-eth0 -{ #############################
4503DEVICE=eth0
4504NAME=eth0
4505TYPE=Ethernet
4506NM_CONTROLLED=yes
4507ONBOOT=yes
4508IPV6INIT=no
4509USERCTL=no
4510BOOTPROTO=dhcp
4511HWADDR=08:00:27:FF:FF:15
4512############################# }- ifcfg-eth0 #############################
4513
4514service network restart
4515chkconfig network on
4516
4517echo "1" > /proc/sys/net/ipv4/ip_forward
4518sysctl -w net.ipv4.ip_forward=1
4519
4520dhclient eth0
4521
4522vim /etc/selinux/config
4523
4524############################# config -{ #############################
4525# This file controls the state of SELinux on the system.
4526# SELINUX= can take one of these three values:
4527# enforcing - SELinux security policy is enforced.
4528# permissive - SELinux prints warnings instead of enforcing.
4529# disabled - No SELinux policy is loaded.
4530SELINUX=enforcing
4531# SELINUXTYPE= can take one of these two values:
4532# targeted - Targeted processes are protected,
4533# mls - Multi Level Security protection.
4534SELINUXTYPE=targeted
4535############################# }- config #############################
4536
4537vim /etc/resolv.conf
4538
4539############################# resolv.conf -{ #############################
4540; generated by /sbin/dhclient-script
4541search alfacorpltda.cl
4542nameserver 172.16.8.11
4543############################# }- resolv.conf #############################
4544
4545cd
4546
4547#system-config-firewall
4548
4549vim /etc/sysconfig/iptables
4550
4551############################# iptables -{ #############################
4552# Generated by iptables-save v1.4.7 on Thu May 31 00:00:00 2015
4553*filter
4554:INPUT ACCEPT [0:0]
4555:FORWARD ACCEPT [0:0]
4556:OUTPUT ACCEPT [0:0]
4557-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
4558-A INPUT -p icmp -j ACCEPT
4559-A INPUT -i lo -j ACCEPT
4560-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
4561#x# Agregar -{
4562-A INPUT -m state --state NEW -m udp -p udp --dport 514 -j ACCEPT
4563-A INPUT -m state --state NEW -m tcp -p tcp --dport 514 -j ACCEPT
4564-A INPUT -p udp -m udp --dport 5060 -j ACCEPT
4565-A INPUT -p tcp -m tcp --dport 5060 -j ACCEPT
4566#x# }- Agregar
4567-A INPUT -j REJECT --reject-with icmp-host-prohibited
4568-A FORWARD -j REJECT --reject-with icmp-host-prohibited
4569COMMIT
4570# Completed on Thu May 31 00:00:00 2015
4571############################# }- iptables #############################
4572
4573service iptables restart
4574chkconfig iptables on
4575
4576####################################### }- NETWORK
4577####################################### ASTERISK -{
4578## SHMZ 6.
4579## /etc/pbx_first_boot.sh
4580
4581mv /etc/asterisk/sip.conf /etc/asterisk/sip.conf.bk
4582mv /etc/asterisk/extension.conf /etc/asterisk/extension.conf.bk
4583
4584vim /etc/asterisk/sip.conf
4585
4586############################# sip.conf -{ #############################
4587[general]
4588disable=all
4589qualify=yes
4590allow=ulaw
4591allow=alaw
4592allow=gsm
4593canreinvite=no
4594dtmfmode=rfc2833
4595srvlookup=yes
4596allowguest=no
4597bindaddr=0.0.0.0
4598port=5060
4599context=alfacorpltda
4600
4601[5700]
4602username=5700
4603secret=12346
4604callerid="Desarrollo" <5700>
4605context=acltda-desarrollo
4606host=dynamic
4607qualify=yes
4608nat=no
4609canreinvite=yes
4610type=friend
4611
4612[5701]
4613username=5701
4614secret=12346
4615callerid="Usuario1D" <5701>
4616context=acltda-desarrollo
4617host=dynamic
4618qualify=yes
4619nat=no
4620canreinvite=yes
4621type=friend
4622
4623[5400]
4624username=5400
4625secret=12346
4626callerid="Ventas" <5400>
4627context=acltda-ventas
4628host=dynamic
4629qualify=yes
4630nat=no
4631canreinvite=yes
4632type=friend
4633
4634[5401]
4635username=5401
4636secret=12346
4637callerid="Usuario1V" <5401>
4638context=acltda-ventas
4639host=dynamic
4640qualify=yes
4641nat=no
4642canreinvite=yes
4643type=friend
4644
4645[5100]
4646username=5100
4647secret=12346
4648callerid="Recepcion" <5100>
4649context=acltda-recepcion
4650host=dynamic
4651qualify=yes
4652nat=no
4653canreinvite=yes
4654type=friend
4655
4656[5101]
4657username=5101
4658secret=12346
4659callerid="Usuario1R" <5101>
4660context=acltda-recepcion
4661host=dynamic
4662qualify=yes
4663nat=no
4664canreinvite=yes
4665type=friend
4666############################# }- sip.conf #############################
4667
4668vim /etc/asterisk/extension.conf
4669
4670############################# extension.conf -{ #############################
4671[alfacorpltda]
4672
4673[acltda-desarrollo]
4674exten => _5[7-9]XX,1,Answer
4675exten => _5[7-9]XX,n,Dial(SIP/${EXTEN}),10,Tt
4676exten => _5[7-9]XX,n,Verbose("ALFA Corp Ltda")
4677exten => _5[7-9]XX,n,HangUP
4678
4679include => acltda-recepcion
4680include => acltda-ventas
4681
4682[acltda-ventas]
4683exten => _5[4-6]XX,1,Dial(SIP/${EXTEN}),10,Tt
4684exten => _5[4-6]XX,n,Verbose("ALFA Corp Ltda")
4685exten => _5[4-6]XX,n,HangUP
4686
4687include => acltda-desarrollo
4688include => acltda-recepcion
4689
4690[acltda-recepcion]
4691exten => _5[1-3]XX,1,Dial(SIP/${EXTEN}),10,Tt
4692exten => _5[1-3]XX,n,Verbose("ALFA Corp Ltda")
4693exten => _5[1-3]XX,n,HangUP
4694
4695include => acltda-desarrollo
4696include => acltda-ventas
4697############################# }- extension.conf #############################
4698
4699service asterisk restart
4700
4701####################################### }- ASTERISK
4702################################################# }- SERVIDOR 1b
4703###################################################################################################
4704################################################# SERVIDOR 2 -{
4705####################################### NETWORK -{
4706
4707cd
4708
4709service network stop
4710
4711ip addr
4712
4713vim /etc/sysconfig/network-scripts/ifcfg-eth0
4714
4715############################# ifcfg-eth0 -{ #############################
4716DEVICE=eth0
4717NAME=eth0
4718TYPE=Ethernet
4719NM_CONTROLLED=yes
4720ONBOOT=yes
4721IPV6INIT=no
4722USERCTL=no
4723BOOTPROTO=dhcp
4724HWADDR=08:00:27:FF:FF:21
4725############################# }- ifcfg-eth0 #############################
4726
4727vim /etc/sysconfig/network-scripts/ifcfg-eth1
4728
4729############################# ifcfg-eth1 -{ #############################
4730DEVICE=eth1
4731NAME=eth1
4732TYPE=Ethernet
4733NM_CONTROLLED=yes
4734ONBOOT=yes
4735IPV6INIT=no
4736USERCTL=no
4737BOOTPROTO=dhcp
4738HWADDR=08:00:27:FF:FF:22
4739############################# }- ifcfg-eth1 #############################
4740
4741vim /etc/sysconfig/network-scripts/ifcfg-eth2
4742
4743############################# ifcfg-eth2 -{ #############################
4744DEVICE=eth2
4745NAME=eth2
4746TYPE=Ethernet
4747NM_CONTROLLED=yes
4748ONBOOT=yes
4749IPV6INIT=no
4750USERCTL=no
4751BOOTPROTO=dhcp
4752HWADDR=08:00:27:FF:FF:23
4753############################# }- ifcfg-eth2 #############################
4754
4755service network restart
4756chkconfig network on
4757
4758echo "1" > /proc/sys/net/ipv4/ip_forward
4759sysctl -w net.ipv4.ip_forward=1
4760
4761dhclient eth0
4762dhclient eth1
4763dhclient eth2
4764
4765vim /etc/selinux/config
4766
4767############################# config -{ #############################
4768# This file controls the state of SELinux on the system.
4769# SELINUX= can take one of these three values:
4770# enforcing - SELinux security policy is enforced.
4771# permissive - SELinux prints warnings instead of enforcing.
4772# disabled - No SELinux policy is loaded.
4773SELINUX=enforcing
4774# SELINUXTYPE= can take one of these two values:
4775# targeted - Targeted processes are protected,
4776# mls - Multi Level Security protection.
4777SELINUXTYPE=targeted
4778############################# }- config #############################
4779
4780vim /etc/resolv.conf
4781
4782############################# resolv.conf -{ #############################
4783; generated by /sbin/dhclient-script
4784search alfacorpltda.cl
4785nameserver 172.16.8.11
4786############################# }- resolv.conf #############################
4787
4788cd
4789
4790#system-config-firewall
4791
4792vim /etc/sysconfig/iptables
4793
4794############################# iptables -{ #############################
4795# Generated by iptables-save v1.4.7 on Thu May 31 00:00:00 2015
4796*filter
4797:INPUT ACCEPT [0:0]
4798:FORWARD ACCEPT [0:0]
4799:OUTPUT ACCEPT [0:0]
4800-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
4801-A INPUT -p icmp -j ACCEPT
4802-A INPUT -i lo -j ACCEPT
4803-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
4804#x# Agregar -{
4805-A INPUT -p tcp -m tcp --dport 10000 -j ACCEPT
4806-A INPUT -m state --state NEW -m udp -p udp --dport 514 -j ACCEPT
4807-A INPUT -m state --state NEW -m tcp -p tcp --dport 514 -j ACCEPT
4808-A INPUT -m state --state NEW -m tcp -p tcp --dport 135:139 -j ACCEPT
4809-A INPUT -m state --state NEW -m udp -p udp --dport 135:139 -j ACCEPT
4810-A INPUT -m state --state NEW -m tcp -p tcp --dport 445 -j ACCEPT
4811-A INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
4812#x# }- Agregar
4813-A INPUT -j REJECT --reject-with icmp-host-prohibited
4814-A FORWARD -j REJECT --reject-with icmp-host-prohibited
4815COMMIT
4816# Completed on Thu May 31 00:00:00 2015
4817############################# }- iptables #############################
4818
4819service iptables restart
4820chkconfig iptables on
4821
4822####################################### }- NETWORK
4823####################################### RESPOSITORY -{
4824
4825cd
4826
4827mkdir /media/RHEL_6.0\ i386\ Disc\ 1/
4828mount -t iso9660 -o ro /dev/cdrom /media/RHEL_6.0\ i386\ Disc\ 1/
4829
4830rm -rf /etc/yum.repos.d/rhel.repo/*
4831
4832vim /etc/yum.repos.d/rhel.repo
4833
4834############################# rhel.repo -{ #############################
4835[rhel-repo]
4836name=RHEL Repository
4837metadata=yum
4838baseurl=file:///media/RHEL_6.0\ i386\ Disc\ 1/
4839enabled=1
4840gpgcheck=1
4841gpgkey=file:///media/RHEL_6.0\ i386\ Disc\ 1/RPM-GPG-KEY-redhat-release
4842############################# }- rhel.repo #############################
4843
4844####################################### }- RESPOSITORY
4845####################################### WEBMIN -{
4846
4847cd
4848
4849yum -y install perl perl-Net-SSLeay openssl perl-IO-*
4850rpm -ivhU webmin-1.750-1.noarch.rpm
4851
4852service webmin start
4853chkconfig webmin on
4854
4855## https://localhost:10000/
4856
4857####################################### }- WEBMIN
4858####################################### USERADD -{
4859useradd usuario1d -s /sbin/nologin
4860useradd usuario1r -s /sbin/nologin
4861useradd usuario1v -s /sbin/nologin
4862passwd usuario1d
4863passwd usuario1r
4864passwd usuario1v
4865####################################### }- USERADD
4866####################################### SAMBA -{
4867cd
4868
4869yum -y install samba samba-client samba-common
4870
4871service smb start
4872service nmb start
4873
4874vim /etc/samba/smb.conf
4875
4876############################# smb.conf -{ #############################
4877# This is the main Samba configuration file. You should read the
4878# smb.conf(5) manual page in order to understand the options listed
4879# here. Samba has a huge number of configurable options (perhaps too
4880# many!) most of which are not shown in this example
4881#
4882# For a step to step guide on installing, configuring and using samba,
4883# read the Samba-HOWTO-Collection. This may be obtained from:
4884# http://www.samba.org/samba/docs/Samba-HOWTO-Collection.pdf
4885#
4886# Many working examples of smb.conf files can be found in the
4887# Samba-Guide which is generated daily and can be downloaded from:
4888# http://www.samba.org/samba/docs/Samba-Guide.pdf
4889#
4890# Any line which starts with a ; (semi-colon) or a # (hash)
4891# is a comment and is ignored. In this example we will use a #
4892# for commentry and a ; for parts of the config file that you
4893# may wish to enable
4894#
4895# NOTE: Whenever you modify this file you should run the command "testparm"
4896# to check that you have not made any basic syntactic errors.
4897#
4898#---------------
4899# SELINUX NOTES:
4900#
4901# If you want to use the useradd/groupadd family of binaries please run:
4902# setsebool -P samba_domain_controller on
4903#
4904# If you want to share home directories via samba please run:
4905# setsebool -P samba_enable_home_dirs on
4906#
4907# If you create a new directory you want to share you should mark it as
4908# "samba-share_t" so that selinux will let you write into it.
4909# Make sure not to do that on system directories as they may already have
4910# been marked with othe SELinux labels.
4911#
4912# Use ls -ldZ /path to see which context a directory has
4913#
4914# Set labels only on directories you created!
4915# To set a label use the following: chcon -t samba_share_t /path
4916#
4917# If you need to share a system created directory you can use one of the
4918# following (read-only/read-write):
4919# setsebool -P samba_export_all_ro on
4920# or
4921# setsebool -P samba_export_all_rw on
4922#
4923# If you want to run scripts (preexec/root prexec/print command/...) please
4924# put them into the /var/lib/samba/scripts directory so that smbd will be
4925# allowed to run them.
4926# Make sure you COPY them and not MOVE them so that the right SELinux context
4927# is applied, to check all is ok use restorecon -R -v /var/lib/samba/scripts
4928#
4929#--------------
4930#
4931#======================= Global Settings =====================================
4932
4933[global]
4934
4935# ----------------------- Netwrok Related Options -------------------------
4936#
4937# workgroup = NT-Domain-Name or Workgroup-Name, eg: MIDEARTH
4938#
4939# server string is the equivalent of the NT Description field
4940#
4941# netbios name can be used to specify a server name not tied to the hostname
4942#
4943# Interfaces lets you configure Samba to use multiple interfaces
4944# If you have multiple network interfaces then you can list the ones
4945# you want to listen on (never omit localhost)
4946#
4947# Hosts Allow/Hosts Deny lets you restrict who can connect, and you can
4948# specifiy it as a per share option as well
4949#
4950#x# workgroup = MYGROUP
4951 workgroup = ALFACORPLTDA
4952 server string = Samba Server Version %v en %L
4953
4954; netbios name = MYSERVER
4955#x#
4956 netbios name = SMB
4957
4958; interfaces = lo eth0 192.168.12.2/24 192.168.13.2/24
4959#x#
4960 interfaces = lo eth0 172.16.0.0/16 172.16.8.1/22
4961; hosts allow = 127. 192.168.12. 192.168.13.
4962#x#
4963 hosts allow = 127. 172.16.
4964
4965# --------------------------- Logging Options -----------------------------
4966#
4967# Log File let you specify where to put logs and how to split them up.
4968#
4969# Max Log Size let you specify the max size log files should reach
4970
4971 # logs split per machine
4972 log file = /var/log/samba/log.%m
4973 # max 50KB per log file, then rotate
4974 max log size = 50
4975
4976# ----------------------- Standalone Server Options ------------------------
4977#
4978# Scurity can be set to user, share(deprecated) or server(deprecated)
4979#
4980# Backend to store user information in. New installations should
4981# use either tdbsam or ldapsam. smbpasswd is available for backwards
4982# compatibility. tdbsam requires no further configuration.
4983
4984 security = user
4985 passdb backend = tdbsam
4986
4987
4988# ----------------------- Domain Members Options ------------------------
4989#
4990# Security must be set to domain or ads
4991#
4992# Use the realm option only with security = ads
4993# Specifies the Active Directory realm the host is part of
4994#
4995# Backend to store user information in. New installations should
4996# use either tdbsam or ldapsam. smbpasswd is available for backwards
4997# compatibility. tdbsam requires no further configuration.
4998#
4999# Use password server option only with security = server or if you can't
5000# use the DNS to locate Domain Controllers
5001# The argument list may include:
5002# password server = My_PDC_Name [My_BDC_Name] [My_Next_BDC_Name]
5003# or to auto-locate the domain controller/s
5004# password server = *
5005
5006
5007; security = domain
5008; passdb backend = tdbsam
5009; realm = MY_REALM
5010
5011; password server = <NT-Server-Name>
5012
5013# ----------------------- Domain Controller Options ------------------------
5014#
5015# Security must be set to user for domain controllers
5016#
5017# Backend to store user information in. New installations should
5018# use either tdbsam or ldapsam. smbpasswd is available for backwards
5019# compatibility. tdbsam requires no further configuration.
5020#
5021# Domain Master specifies Samba to be the Domain Master Browser. This
5022# allows Samba to collate browse lists between subnets. Don't use this
5023# if you already have a Windows NT domain controller doing this job
5024#
5025# Domain Logons let Samba be a domain logon server for Windows workstations.
5026#
5027# Logon Scrpit let yuou specify a script to be run at login time on the client
5028# You need to provide it in a share called NETLOGON
5029#
5030# Logon Path let you specify where user profiles are stored (UNC path)
5031#
5032# Various scripts can be used on a domain controller or stand-alone
5033# machine to add or delete corresponding unix accounts
5034#
5035; security = user
5036; passdb backend = tdbsam
5037
5038; domain master = yes
5039; domain logons = yes
5040
5041 # the login script name depends on the machine name
5042; logon script = %m.bat
5043 # the login script name depends on the unix user used
5044; logon script = %u.bat
5045; logon path = \\%L\Profiles\%u
5046 # disables profiles support by specifing an empty path
5047; logon path =
5048
5049; add user script = /usr/sbin/useradd "%u" -n -g users
5050; add group script = /usr/sbin/groupadd "%g"
5051; add machine script = /usr/sbin/useradd -n -c "Workstation (%u)" -M -d /nohome -s /bin/false "%u"
5052; delete user script = /usr/sbin/userdel "%u"
5053; delete user from group script = /usr/sbin/userdel "%u" "%g"
5054; delete group script = /usr/sbin/groupdel "%g"
5055
5056
5057# ----------------------- Browser Control Options ----------------------------
5058#
5059# set local master to no if you don't want Samba to become a master
5060# browser on your network. Otherwise the normal election rules apply
5061#
5062# OS Level determines the precedence of this server in master browser
5063# elections. The default value should be reasonable
5064#
5065# Preferred Master causes Samba to force a local browser election on startup
5066# and gives it a slightly higher chance of winning the election
5067; local master = no
5068; os level = 33
5069; preferred master = yes
5070
5071#----------------------------- Name Resolution -------------------------------
5072# Windows Internet Name Serving Support Section:
5073# Note: Samba can be either a WINS Server, or a WINS Client, but NOT both
5074#
5075# - WINS Support: Tells the NMBD component of Samba to enable it's WINS Server
5076#
5077# - WINS Server: Tells the NMBD components of Samba to be a WINS Client
5078#
5079# - WINS Proxy: Tells Samba to answer name resolution queries on
5080# behalf of a non WINS capable client, for this to work there must be
5081# at least one WINS Server on the network. The default is NO.
5082#
5083# DNS Proxy - tells Samba whether or not to try to resolve NetBIOS names
5084# via DNS nslookups.
5085
5086; wins support = yes
5087; wins server = w.x.y.z
5088; wins proxy = yes
5089
5090; dns proxy = yes
5091
5092# --------------------------- Printing Options -----------------------------
5093#
5094# Load Printers let you load automatically the list of printers rather
5095# than setting them up individually
5096#
5097# Cups Options let you pass the cups libs custom options, setting it to raw
5098# for example will let you use drivers on your Windows clients
5099#
5100# Printcap Name let you specify an alternative printcap file
5101#
5102# You can choose a non default printing system using the Printing option
5103
5104 load printers = yes
5105 cups options = raw
5106
5107; printcap name = /etc/printcap
5108 #obtain list of printers automatically on SystemV
5109; printcap name = lpstat
5110; printing = cups
5111
5112# --------------------------- Filesystem Options ---------------------------
5113#
5114# The following options can be uncommented if the filesystem supports
5115# Extended Attributes and they are enabled (usually by the mount option
5116# user_xattr). Thess options will let the admin store the DOS attributes
5117# in an EA and make samba not mess with the permission bits.
5118#
5119# Note: these options can also be set just per share, setting them in global
5120# makes them the default for all shares
5121
5122; map archive = no
5123; map hidden = no
5124; map read only = no
5125; map system = no
5126; store dos attributes = yes
5127
5128
5129#============================ Share Definitions ==============================
5130
5131[homes]
5132 comment = Home Directories
5133 browseable = no
5134 writable = yes
5135; valid users = %S
5136; valid users = MYDOMAIN\%S
5137
5138[printers]
5139 comment = All Printers
5140 path = /var/spool/samba
5141 browseable = no
5142 guest ok = no
5143 writable = no
5144 printable = yes
5145
5146# Un-comment the following and create the netlogon directory for Domain Logons
5147; [netlogon]
5148; comment = Network Logon Service
5149; path = /var/lib/samba/netlogon
5150; guest ok = yes
5151; writable = no
5152; share modes = no
5153
5154
5155# Un-comment the following to provide a specific roving profile share
5156# the default is to use the user's home directory
5157; [Profiles]
5158; path = /var/lib/samba/profiles
5159; browseable = no
5160; guest ok = yes
5161
5162
5163# A publicly accessible directory, but read only, except for people in
5164# the "staff" group
5165; [public]
5166; comment = Public Stuff
5167; path = /home/samba
5168; public = yes
5169; writable = yes
5170; printable = no
5171; write list = +staff
5172
5173#x# Agregar -{
5174 [Recepcion]
5175 comment = SMB Recepcion
5176 hide dot files = yes
5177 public = no
5178 create mode = 0644
5179 path = /smb/recepcion
5180 write list = usuario1d,usuario1r
5181 directory mode = 0755
5182 browseable = no
5183 printable = no
5184
5185 [smb-carpeta]
5186 path = /smb/smb-carpeta/
5187 read only = no
5188 security = share
5189 null password = yes
5190 case sensitive = no
5191 comment = SMB Carpeta
5192 guest ok = yes
5193 browseable = yes
5194 umask = 000
5195#x# }- Agregar
5196############################# }- smb.conf #############################
5197
5198smbpasswd -a root
5199smbpasswd -a usuario1d
5200smbpasswd -a usuario1v
5201smbpasswd -a usuario1r
5202
5203mkdir -p /smb/recepcion
5204mkdir /smb/smb-carpeta
5205chcon -t samba_share_t /smb/recepcion
5206chcon -t samba_share_t /smb/smb-carpeta
5207setfacl -m u:usuario1d:rwX,u:usuario1r:rwX /smb/recepcion/
5208
5209setsebool -P samba_export_all_rw 1
5210setsebool -P use_samba_home_dirs 1
5211setsebool -P samba_create_home_dirs 1
5212setsebool -P samba_domain_controller 1
5213setsebool -P samba_run_unconfined 1
5214
5215service nmb restart
5216service smb restart
5217chkconfig nmb on
5218chkconfig smb on
5219
5220## \\smb.alfacorpltda.cl\recepcion
5221
5222####################################### }- SAMBA
5223####################################### MYSQL -{
5224
5225cd
5226
5227yum -y install mysql mysql-server
5228
5229service mysqld start
5230
5231mysqladmin -u root password '123456'
5232#mysql_secure_installation
5233
5234service mysqld stop
5235
5236vim /etc/my.cnf
5237
5238############################# my.cnf -{ #############################
5239#x# Agregar -{
5240[mysql]
5241default-character-set=utf8
5242#x# }- Agregar
5243
5244[mysqld]
5245datadir=/var/lib/mysql
5246socket=/var/lib/mysql/mysql.sock
5247user=mysql
5248# Disabling symbolic-links is recommended to prevent assorted security risks
5249symbolic-links=0
5250#x# Agregar -{
5251port=3306
5252skip-name-resolve
5253query_cache_type=1
5254query_cache_limit=1M
5255query_cache_size=32M
5256log_queries_not_using_indexes=1
5257slow_query_log=1
5258slow_query_log_file=/var/lib/mysql/mysqld-slow-query.log
5259tmp_table_size=32M
5260max_heap_table_size=32M
5261max_connections=500
5262thread_cache_size=50
5263open_files_limit=65535
5264table_definition_cache=4096
5265table_open_cache=512
5266collation_server=utf8_unicode_ci
5267character-set-server=utf8
5268init_connect='SET collation_connection = utf8_general_ci'
5269init_connect='SET NAMES utf8'
5270#x# }- Agregar
5271
5272[mysqld_safe]
5273log-error=/var/log/mysqld.log
5274pid-file=/var/run/mysqld/mysqld.pid
5275
5276#x# Agregar -{
5277[client]
5278port=3306
5279#x# }- Agregar
5280############################# }- my.cnf #############################
5281
5282setsebool -P allow_user_mysql_connect 1
5283setsebool -P mysql_connect_any 1
5284
5285service mysqld restart
5286chkconfig mysqld on
5287
5288mysqladmin -u root -p create basedatos00
5289
5290####################################### }- MYSQL
5291####################################### SYSLOG-{
5292
5293cd
5294
5295chkconfig rsyslog on
5296
5297vim /etc/rsyslog.conf
5298
5299############################# rsyslog.conf -{ #############################
5300#rsyslog v3 config file
5301
5302# if you experience problems, check
5303# http://www.rsyslog.com/troubleshoot for assistance
5304
5305#### MODULES ####
5306
5307$ModLoad imuxsock.so # provides support for local system logging (e.g. via logger command)
5308$ModLoad imklog.so # provides kernel logging support (previously done by rklogd)
5309#$ModLoad immark.so # provides --MARK-- message capability
5310
5311# Provides UDP syslog reception
5312#x# Descomentar -{
5313$ModLoad imudp.so
5314$UDPServerRun 514
5315#x# }- Descomentar
5316
5317# Provides TCP syslog reception
5318#x# Descomentar -{
5319$ModLoad imtcp.so
5320$InputTCPServerRun 514
5321#x# }- Descomentar
5322
5323#### GLOBAL DIRECTIVES ####
5324
5325# Use default timestamp format
5326$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
5327
5328# File syncing capability is disabled by default. This feature is usually not required,
5329# not useful and an extreme performance hit
5330#$ActionFileEnableSync on
5331
5332
5333#### RULES ####
5334
5335#x# Agregar -{
5336$template TmplAuth, "/var/log/rsyslog/%HOSTNAME%/%PROGRAMNAME%.log"
5337$template TmplMsg, "/var/log/rsyslog/%HOSTNAME%/%PROGRAMNAME%.log"
5338authpriv.* ?TmplAuth
5339*.info,mail.none,authpriv.none,cron.none ?TmplMsg
5340#x# }- Agregar
5341
5342# Log all kernel messages to the console.
5343# Logging much else clutters up the screen.
5344#kern.* /dev/console
5345
5346# Log anything (except mail) of level info or higher.
5347# Don't log private authentication messages!
5348*.info;mail.none;authpriv.none;cron.none /var/log/messages
5349
5350# The authpriv file has restricted access.
5351authpriv.* /var/log/secure
5352
5353# Log all the mail messages in one place.
5354mail.* -/var/log/maillog
5355
5356
5357# Log cron stuff
5358cron.* /var/log/cron
5359
5360# Everybody gets emergency messages
5361*.emerg *
5362
5363# Save news errors of level crit and higher in a special file.
5364uucp,news.crit /var/log/spooler
5365
5366# Save boot messages also to boot.log
5367local7.* /var/log/boot.log
5368
5369
5370
5371# ### begin forwarding rule ###
5372# The statement between the begin ... end define a SINGLE forwarding
5373# rule. They belong together, do NOT split them. If you create multiple
5374# forwarding rules, duplicate the whole block!
5375# Remote Logging (we use TCP for reliable delivery)
5376#
5377# An on-disk queue is created for this action. If the remote host is
5378# down, messages are spooled to disk and sent when it is up again.
5379#$WorkDirectory /var/spppl/rsyslog # where to place spool files
5380#$ActionQueueFileName fwdRule1 # unique name prefix for spool files
5381#$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
5382#$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
5383#$ActionQueueType LinkedList # run asynchronously
5384#$ActionResumeRetryCount -1 # infinite retries if host is down
5385# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
5386#*.* @@remote-host:514
5387# ### end of the forwarding rule ###
5388############################# }- rsyslog.conf #############################
5389
5390mkdir /var/log/rsyslog
5391
5392service rsyslog restart
5393
5394####################################### }- SYSLOG
5395################################################# }- SERVIDOR 2
5396###################################################################################################