mount /dev/xvda /mnt mount --bind /dev /mnt/dev mount --bind /dev/pts /mnt/dev/pts mount --bind /proc /mnt/proc mount --bind /sys /mnt/sys chroot /mnt grub-mkdevicemap update-grub exit umount /mnt/dev umount /mnt/dev/pts umount /mnt/proc umount /mnt/sys umount /mnt
Zobrazují se příspěvky se štítkemLinux. Zobrazit všechny příspěvky
Zobrazují se příspěvky se štítkemLinux. Zobrazit všechny příspěvky
neděle 11. května 2014
Oprava bootování virtuálky na Virtualmaster po upgrade kernelu
V rescue režimu
Štítky:
Linux,
Virtualmaster,
XEN
pondělí 27. května 2013
Extract email address from undelivered mails
(find . -type f | xargs sed -nr "s/.*<([A-Z0-9._%-+]+@[A-Z0-9.-]+\.[A-Z]{2,4})>.*/\L\1/pi") > /emails.txt
Štítky:
Linux
středa 22. května 2013
Konfigurace IPsec tunelu Ubuntu vs. Cisco SRP521W
apt-get install openswan ipsec-tools
cat /etc/ipsec-tools.conf
flush;
spdflush;
spdadd 192.168.0.0 192.168.15.0 any -P out ipsec esp/tunnel/77.75.72.3-173.194.35.88/unique;
spdadd 192.168.15.0 192.168.0.0 any -P in ipsec esp/tunnel/173.194.35.88-77.75.72.3/unique;
cat /etc/ipsec-tools.conf
77.75.72.3 173.194.35.88: PSK "Super tajne heslo"
cat /etc/ipsec.conf
version 2.0
config setup
oe=off
protostack=netkey
nat_traversal=no
conn %default
keyingtries=0
authby=secret
conn vpn
pfs=no
keyingtries=3
rekey=no
esp=3des-md5
ike=3des-md5-modp1024
authby=secret
keyexchange=ike
ikelifetime=8h
keylife=1h
left=77.75.72.3
leftnexthop=%defaultroute
leftsubnet=192.168.0.0/24
right=173.194.35.88
rightsubnet=192.168.15.0/24
auto=start
type=tunnel
cat /etc/iptables.conf
iptables -t nat -A POSTROUTING -o eth1 -s 192.168.0.0/24 ! -d 192.168.15.0/24 -j MASQUERADE
iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
iptables -A FORWARD -i eth1 -s 192.168.15.0/24 -o eth0 -j ACCEPT
cat /etc/ipsec-tools.conf
flush;
spdflush;
spdadd 192.168.0.0 192.168.15.0 any -P out ipsec esp/tunnel/77.75.72.3-173.194.35.88/unique;
spdadd 192.168.15.0 192.168.0.0 any -P in ipsec esp/tunnel/173.194.35.88-77.75.72.3/unique;
cat /etc/ipsec-tools.conf
77.75.72.3 173.194.35.88: PSK "Super tajne heslo"
cat /etc/ipsec.conf
version 2.0
config setup
oe=off
protostack=netkey
nat_traversal=no
conn %default
keyingtries=0
authby=secret
conn vpn
pfs=no
keyingtries=3
rekey=no
esp=3des-md5
ike=3des-md5-modp1024
authby=secret
keyexchange=ike
ikelifetime=8h
keylife=1h
left=77.75.72.3
leftnexthop=%defaultroute
leftsubnet=192.168.0.0/24
right=173.194.35.88
rightsubnet=192.168.15.0/24
auto=start
type=tunnel
cat /etc/iptables.conf
iptables -t nat -A POSTROUTING -o eth1 -s 192.168.0.0/24 ! -d 192.168.15.0/24 -j MASQUERADE
iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
iptables -A FORWARD -i eth1 -s 192.168.15.0/24 -o eth0 -j ACCEPT
pátek 5. dubna 2013
Přesun souborů do složek dle datumu
touch -d "00:00:00.01 2013-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2013/ \;
touch -d "00:00:00.01 2012-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2012/ \;
touch -d "00:00:00.01 2011-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2011/ \;
touch -d "00:00:00.01 2010-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2010/ \;
Štítky:
Linux
pátek 17. srpna 2012
čtvrtek 9. června 2011
KVM on Ubuntu
https://help.ubuntu.com/community/KVM/Managing
https://help.ubuntu.com/community/KVM/CreateGuests
http://libvirt.org/formatdomain.html#elementsDevices
virsh --connect qemu:///system
https://help.ubuntu.com/community/KVM/CreateGuests
http://libvirt.org/formatdomain.html#elementsDevices
virsh --connect qemu:///system
neděle 20. února 2011
Nginx With PHP As FastCGI
Instalace
echo "deb http://ppa.launchpad.net/brianmercer/php/ubuntu lucid main" >> /etc/apt/sources.list sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 8D0DC64F apt-get update apt-get install nginx php5-cli php5-common php5-mysql php5-suhosin php5-fpm
Konfigurace
server {
listen 80;
server_name localhost;
#access_log logs/host.access.log main;
#error_page 404 /404.html;
# redirect server error pages to the static page /50x.html
#
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root html;
}
location / {
root /opt/nginx/html;
index index.php;
}
# pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
#
location ~ \.php$ {
root html;
fastcgi_pass 127.0.0.1:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME /opt/nginx/html$fastcgi_script_name;
include fastcgi_params;
}
# deny access to .htaccess files, if Apache's document root
# concurs with nginx's one
#
location ~ /\.ht {
deny all;
}
}
sobota 20. listopadu 2010
Příprava Linuxového serveru pro hosting Ruby on Rails aplikací
Součásti
- Nginx
- Passenger
Instalace
apt-get install ruby rdoc ruby1.8-dev build-essential libopenssl-ruby libcurl4-openssl-dev libssl-dev zlib1g-dev libsqlite3-dev wget http://production.cf.rubygems.org/rubygems/rubygems-1.3.7.tgz tar -xzf rubygems-1.3.7.tgz cd rubygems-1.3.7 ruby setup.rb gem1.8 install rails sqlite3-ruby passenger passenger-install-nginx-module
Konfigurace
Init skript /etc/init.d/nginx (počítá s instalací do defaultního umístění)#! /bin/sh
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
DAEMON=/opt/nginx/sbin/nginx
NAME=nginx
DESC=nginx
test -x $DAEMON || exit 0
set -e
. /lib/lsb/init-functions
test_nginx_config() {
if $DAEMON -t $DAEMON_OPTS
then
return 0
else
return $?
fi
}
case "$1" in
start)
echo -n "Starting $DESC: "
test_nginx_config
start-stop-daemon --start --quiet --pidfile /opt/nginx/logs/$NAME.pid \
--exec $DAEMON -- $DAEMON_OPTS || true
echo "$NAME."
;;
stop)
echo -n "Stopping $DESC: "
start-stop-daemon --stop --quiet --pidfile /opt/nginx/logs/$NAME.pid \
--exec $DAEMON || true
echo "$NAME."
;;
restart|force-reload)
echo -n "Restarting $DESC: "
start-stop-daemon --stop --quiet --pidfile \
/opt/nginx/logs/$NAME.pid --exec $DAEMON || true
sleep 1
test_nginx_config
start-stop-daemon --start --quiet --pidfile \
/opt/nginx/logs/$NAME.pid --exec $DAEMON -- $DAEMON_OPTS || true
echo "$NAME."
;;
reload)
echo -n "Reloading $DESC configuration: "
test_nginx_config
start-stop-daemon --stop --signal HUP --quiet --pidfile /opt/nginx/logs/$NAME.pid \
--exec $DAEMON || true
echo "$NAME."
;;
configtest)
echo -n "Testing $DESC configuration: "
if test_nginx_config
then
echo "$NAME."
else
exit $?
fi
;;
status)
status_of_proc -p /opt/nginx/logs/$NAME.pid "$DAEMON" nginx && exit 0 || exit $?
;;
*)
echo "Usage: $NAME {start|stop|restart|reload|force-reload|status|configtest}" >&2
exit 1
;;
esac
exit 0
Passengerhttp://www.modrails.com/videos/passenger_nginx.mov
středa 5. května 2010
Configuring Dynamic DNS & DHCP
http://www.debian-administration.org/article/Configuring_Dynamic_DNS__DHCP_on_Debian_Stable
Disable AppArmor
AppArmor is a security extension (similar to SELinux) that should provide extended security. In my opinion you don't need it to configure a secure system, and it usually causes more problems than advantages (think of it after you have done a week of trouble-shooting because some service wasn't working as expected, and then you find out that everything was ok, only AppArmor was causing the problem). Therefore I disable it (this is a must if you want to install ISPConfig later on).
We can disable it like this:
Disable AppArmor
AppArmor is a security extension (similar to SELinux) that should provide extended security. In my opinion you don't need it to configure a secure system, and it usually causes more problems than advantages (think of it after you have done a week of trouble-shooting because some service wasn't working as expected, and then you find out that everything was ok, only AppArmor was causing the problem). Therefore I disable it (this is a must if you want to install ISPConfig later on).
We can disable it like this:
/etc/init.d/apparmor stop update-rc.d -f apparmor remove aptitude remove apparmor apparmor-utils
Štítky:
Linux
středa 18. listopadu 2009
Squirrelmail česky na Ubuntu
apt-get install squirrelmail-locales locale-gen cs_CZ squirrelmail-configure * 10 Languages * 1 cs_CZ * 2 utf-8
Převod locales do utf-8: http://www.utf-8.sk/squirrelmail.txt
Štítky:
Linux
Removing SSL passphrases
openssl rsa -in server.key.bak -out server.keyhttps://support.railsmachine.com/index.php?pg=kb.page&id=144
pondělí 9. listopadu 2009
středa 19. srpna 2009
Mapování skupin
groupadd DomainAdmins net groupmap add rid=512 type=domain ntgroup="Domain Admins" unixgroup=DomainAdmins groupadd DomainUsers net groupmap add rid=513 type=domain ntgroup="Domain Users" unixgroup=DomainUsers groupadd DomainGuests net groupmap add rid=514 type=domain ntgroup="Domain Guests" unixgroup=DomainGuests groupadd DomainComputers net groupmap add rid=515 type=domain ntgroup="Domain Computers" unixgroup=DomainComputers
pondělí 3. srpna 2009
Postfix monitoring
Mailgraph
apt-get install rrdtool mailgraph
pflogsumm
apt-get install pflogsumm mailx vi /etc/cron.daily/postfix_report.sh
#!/bin/sh PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin pflogsumm /var/log/mail.log.0 | head -c 10M - | mail -s "Mail Statistics" vas@email.cz exit 0
chmod 755 /etc/cron.daily/postfix_report.sh
zdroj: http://www.howtoforge.com/mail_statistics_mailgraph_pflogsumm
čtvrtek 16. července 2009
Přihlášení Samby do win domény
http://developer.novell.com/wiki/index.php/HOWTO:_Configure_Ubuntu_for_Active_Directory_Authentication
1) /etc/resolv.conf
search domena.local
nameserver IPA.DRE.SAP.DC
2) /etc/smb.conf
[global]
server string =
encrypt passwords = Yes
netbios name = LINUX
security = domain
workgroup = SKUPINA
password server = Název serveru
realm = DNS název domény
winbind use default domain = Yes
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users=yes
winbind enum groups=yes
winbind nested groups = Yes
winbind separator = +
interfaces = eth1
bind interfaces only = yes
log level = 3
log file = /var/log/samba/log.%m
store dos attributes = yes
create mask = 770
force create mode = 770
directory mask = 770
3)
[libdefaults]
clockskew = 600
default_realm = DOMENA.LOCAL
[realms]
DNS NÁZEV DOMÉNY = {
kdc = PDC
default_domain = DOMENA
kpasswd_server = PDC.DOMENA.LOCAL
}
[domain_realm]
.domena.local = DOMENA.LOCAL
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[appdefaults]
pam = {
ticket_lifetime = 1d
renew_lifetime = 1d
forwardable = true
proxiable = false
retain_after_close = false
minimum_uid = 0
debug = false
}
4) /etc/pam.d/samba
//pridat na zacatek
auth required /lib/security/pam_winbind.so
account required /lib/security/pam_winbind.so
5) prihlaseni do domeny
net rpc join -S PDC -U administrator
net rpc join -W DOMENA -U administrator
6) /etc/nsswitch.conf
passwd: files winbind
group: files winbind
hosts: files dns winbind
7) wbinfo
wbinfo --set-auth-user=administrator%'bigsecret'
8) test
nmbd; smbd; winbindd;
wbinfo -u //uzivatele
wbinfo -g //skupiny
9) problemy
-debug mod winbodd
+/etc/init.d/winbindd stop
winbindd -d 3 -i
-pripoji se ale nenacte uzivatele (wbinfo -u) (~win 2000)
+do smb.conf pridat client schannel = no
(http://www.gatago.com/linux/samba/14514734.html,
http://kbase.redhat.com/faq/FAQ_85_5515.shtm)
-zadani skupiny s mezerou v nazvu do valid users
+valid users = "@domain admins"
-windows 7
=upravit nastavení NTLM http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
-------------------------
http://lilly.csoft.net/~vdebaere/handleiding/samba-activedirectory/index_en.html
http://us1.samba.org/samba/docs/man/Samba-Guide/unixclients.html#ch9-adssdm
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/InterdomainTrusts.html#id2587424
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/FastStart.html#id2523211
do smb.conf (http://www.wlug.org.nz/ActiveDirectorySamba)[vubec nevim co sem tim chtel rict]
-------------------------
/etc/resolv.conf
/etc/samba/smb.conf
/etc/pam.d/samba
/etc/nsswitch.conf
/etc/krb5.conf
1) /etc/resolv.conf
search domena.local
nameserver IPA.DRE.SAP.DC
2) /etc/smb.conf
[global]
server string =
encrypt passwords = Yes
netbios name = LINUX
security = domain
workgroup = SKUPINA
password server = Název serveru
realm = DNS název domény
winbind use default domain = Yes
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users=yes
winbind enum groups=yes
winbind nested groups = Yes
winbind separator = +
interfaces = eth1
bind interfaces only = yes
log level = 3
log file = /var/log/samba/log.%m
store dos attributes = yes
create mask = 770
force create mode = 770
directory mask = 770
3)
sudo apt-get install heimdal-clients libpam-heimdal/etc/krb5.conf
[libdefaults]
clockskew = 600
default_realm = DOMENA.LOCAL
[realms]
DNS NÁZEV DOMÉNY = {
kdc = PDC
default_domain = DOMENA
kpasswd_server = PDC.DOMENA.LOCAL
}
[domain_realm]
.domena.local = DOMENA.LOCAL
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[appdefaults]
pam = {
ticket_lifetime = 1d
renew_lifetime = 1d
forwardable = true
proxiable = false
retain_after_close = false
minimum_uid = 0
debug = false
}
4) /etc/pam.d/samba
//pridat na zacatek
auth required /lib/security/pam_winbind.so
account required /lib/security/pam_winbind.so
5) prihlaseni do domeny
net rpc join -S PDC -U administrator
net rpc join -W DOMENA -U administrator
6) /etc/nsswitch.conf
passwd: files winbind
group: files winbind
hosts: files dns winbind
7) wbinfo
wbinfo --set-auth-user=administrator%'bigsecret'
8) test
nmbd; smbd; winbindd;
wbinfo -u //uzivatele
wbinfo -g //skupiny
9) problemy
-debug mod winbodd
+/etc/init.d/winbindd stop
winbindd -d 3 -i
-pripoji se ale nenacte uzivatele (wbinfo -u) (~win 2000)
+do smb.conf pridat client schannel = no
(http://www.gatago.com/linux/samba/14514734.html,
http://kbase.redhat.com/faq/FAQ_85_5515.shtm)
-zadani skupiny s mezerou v nazvu do valid users
+valid users = "@domain admins"
-windows 7
=upravit nastavení NTLM http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746
-------------------------
http://lilly.csoft.net/~vdebaere/handleiding/samba-activedirectory/index_en.html
http://us1.samba.org/samba/docs/man/Samba-Guide/unixclients.html#ch9-adssdm
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/InterdomainTrusts.html#id2587424
http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/FastStart.html#id2523211
do smb.conf (http://www.wlug.org.nz/ActiveDirectorySamba)[vubec nevim co sem tim chtel rict]
-------------------------
/etc/resolv.conf
/etc/samba/smb.conf
/etc/pam.d/samba
/etc/nsswitch.conf
/etc/krb5.conf
pátek 5. prosince 2008
Migrace samba PDC na nový server
Postup
- Přenos konfigurace /etc/samba
- Přenos souborů
- Přenos uživatelských účtů /etc/passwd a skupin /etc/group
- Nastavení mapování skupin net groupmap
- Nastavení SID původního PDC
Přesun SID domény
na původním serverunet getlocalsid net getdomainsidna novém serveru
rm /var/lib/samba/* net setlocalsid net setdomainsid
Odkazy
http://www.microsoft.com/technet/sysinternals/Utilities/NewSid.mspxhttp://sarwiki.informatik.hu-berlin.de/Windows_Domain_Migration_--_after-thought_edition
http://www.tek-tips.com/viewthread.cfm?qid=1316498&page=5
http://kb.nitix.com/2567
http://directory.fedora.redhat.com/wiki/Howto:Samba
http://www.linuxcommand.org/man_pages/pdbedit8.html
http://www.linuxcommand.org/man_pages/net8.html
http://www.microsoft.com/technet/sysinternals/Utilities/NewSid.mspx
úterý 9. září 2008
OpenVPN - klient
Konfigurace pro klienta
# klient client # server remote I.P.ADRESA.SERVERU 1194 # certifikat certifikacni autority ca ca.crt # certifikat klienta cert uzivatel.crt # klíč klienta key uzivatel.key # The persist options will try to avoid # accessing certain resources on restart # that may no longer be accessible because # of the privilege downgrade. # Try to preserve some state across restarts. persist-key persist-tun # udrzuje spojeni nazivu, 10 (ping) a 120 (ping-restart) keepalive 10 60 port 1194 proto udp dev tap0 # ukecanost verb 5 mute 10 # komprese prenasenych dat comp-lzo # uzivatel pod kterym bezi klient user nobody # skupina pod kterym bezi klient group nogroup # Verify server certificate by checking # that the certicate has the nsCertType # field set to "server". This is an # important precaution to protect against # a potential attack discussed here: # http://openvpn.net/howto.html#mitm # # To use this feature, you will need to generate # your server certificates with the nsCertType # field set to "server". The build-key-server # script in the easy-rsa folder will do this. ns-cert-type server # Most clients don't need to bind to # a specific local port number. nobind
OpenVPN - server
Instalace
apt-get install openvpn
Generování certifikátů
cd /usr/share/doc/openvpn/examples/easy-rsa/2.0 source ./vars ./clean-all ./build-ca ./build-key-server server ./build-key user ./build-dh cp keys/ca.crt /etc/openvpn/ cp keys/dh1024.pem /etc/openvpn/ cp keys/server.crt /etc/openvpn/ cp keys/server.key /etc/openvpn/ vi /etc/openvpn/server.conf
Konfigurace
server 192.168.5.0 255.255.255.0 client-to-client port 1194 proto udp dev tap0 # ukecanost verb 5 mute 10 # komprese prenasenych dat comp-lzo # uzivatel pod kterym bezi server user nobody # skupina pod kterou bezi server group nogroup dh dh1024.pem # certifikat certifikacni autority ca ca.crt # certifikat serveru cert server.crt # klíč serveru key server.key tls-server # The persist options will try to avoid # accessing certain resources on restart # that may no longer be accessible because # of the privilege downgrade. # Try to preserve some state across restarts. persist-key persist-tun # udrzuje spojeni nazivu, 10 (ping) a 60(ping-restart) keepalive 10 60 # list of current client connections to the file openvpn.status once per minute status /var/log/openvpn.status # logy serveru log-append /var/log/openvpn.log #routovani push "route 192.168.2.0 255.255.255.0" push "dhcp-option DNS 192.168.2.2" push "dhcp-option WINS 192.168.2.2"
Restart OpenVNP
/etc/init.d/openvpn restart
Výjimky v iptables
iptables -A INPUT -i tap0 -j ACCEPT iptables -A OUTPUT -o tap0 -j ACCEPT iptables -A FORWARD -i tap0 -j ACCEPT
Key Files
Now we will find our newly-generated keys and certificates in the keys subdirectory. Here is an explanation of the relevant files:| Filename | Needed By | Purpose | Secret |
| ca.crt | server + all clients | Root CA certificate | NO |
| ca.key | key signing machine only | Root CA key | YES |
| dh{n}.pem | server only | Diffie Hellman parameters | NO |
| server.crt | server only | Server Certificate | NO |
| server.key | server only | Server Key | YES |
| client1.crt | client1 only | Client1 Certificate | NO |
| client1.key | client1 only | Client1 Key | YES |
Přihlásit se k odběru:
Příspěvky (Atom)