Zobrazují se příspěvky se štítkemLinux. Zobrazit všechny příspěvky
Zobrazují se příspěvky se štítkemLinux. Zobrazit všechny příspěvky

neděle 11. května 2014

Oprava bootování virtuálky na Virtualmaster po upgrade kernelu

V rescue režimu

mount /dev/xvda /mnt

mount --bind /dev /mnt/dev
mount --bind /dev/pts /mnt/dev/pts
mount --bind /proc /mnt/proc
mount --bind /sys /mnt/sys

chroot /mnt

grub-mkdevicemap

update-grub

exit
umount /mnt/dev
umount /mnt/dev/pts
umount /mnt/proc
umount /mnt/sys
umount /mnt

pondělí 27. května 2013

Extract email address from undelivered mails

(find . -type f | xargs sed -nr "s/.*<([A-Z0-9._%-+]+@[A-Z0-9.-]+\.[A-Z]{2,4})>.*/\L\1/pi") > /emails.txt

středa 22. května 2013

Konfigurace IPsec tunelu Ubuntu vs. Cisco SRP521W

apt-get install openswan ipsec-tools

cat /etc/ipsec-tools.conf
flush;
spdflush;

spdadd 192.168.0.0 192.168.15.0 any -P out ipsec esp/tunnel/77.75.72.3-173.194.35.88/unique;
spdadd 192.168.15.0 192.168.0.0 any -P in  ipsec esp/tunnel/173.194.35.88-77.75.72.3/unique;


cat /etc/ipsec-tools.conf
77.75.72.3 173.194.35.88: PSK "Super tajne heslo"


cat /etc/ipsec.conf
version 2.0

config setup
        oe=off
        protostack=netkey
        nat_traversal=no

conn %default
        keyingtries=0
        authby=secret

conn vpn
        pfs=no
        keyingtries=3
        rekey=no
        esp=3des-md5
        ike=3des-md5-modp1024
        authby=secret
        keyexchange=ike
        ikelifetime=8h
        keylife=1h

        left=77.75.72.3
        leftnexthop=%defaultroute
        leftsubnet=192.168.0.0/24

        right=173.194.35.88
        rightsubnet=192.168.15.0/24

        auto=start
        type=tunnel


cat /etc/iptables.conf
iptables -t nat -A POSTROUTING -o eth1 -s 192.168.0.0/24 ! -d 192.168.15.0/24 -j MASQUERADE
iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
iptables -A FORWARD -i eth1 -s 192.168.15.0/24 -o eth0 -j ACCEPT





pátek 5. dubna 2013

Přesun souborů do složek dle datumu

touch -d "00:00:00.01 2013-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2013/ \;

touch -d "00:00:00.01 2012-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2012/ \;

touch -d "00:00:00.01 2011-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2011/ \;

touch -d "00:00:00.01 2010-01-01" _stamp
find . -type f -newer _stamp -exec mv {} /2010/ \;

čtvrtek 9. června 2011

KVM on Ubuntu

https://help.ubuntu.com/community/KVM/Managing
https://help.ubuntu.com/community/KVM/CreateGuests
http://libvirt.org/formatdomain.html#elementsDevices

virsh --connect qemu:///system

neděle 20. února 2011

Nginx With PHP As FastCGI

Instalace

echo "deb http://ppa.launchpad.net/brianmercer/php/ubuntu lucid main" >> /etc/apt/sources.list
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 8D0DC64F
apt-get update
apt-get install nginx php5-cli php5-common php5-mysql php5-suhosin php5-fpm

Konfigurace

server {
        listen       80;
        server_name  localhost;

        #access_log  logs/host.access.log  main;

        #error_page  404              /404.html;

        # redirect server error pages to the static page /50x.html
        #
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }

        location / {
            root   /opt/nginx/html;
            index  index.php;
        }

        # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
        #
        location ~ \.php$ {
            root           html;
            fastcgi_pass   127.0.0.1:9000;
            fastcgi_index  index.php;
            fastcgi_param  SCRIPT_FILENAME  /opt/nginx/html$fastcgi_script_name;
            include        fastcgi_params;
        }

        # deny access to .htaccess files, if Apache's document root
        # concurs with nginx's one
        #
        location ~ /\.ht {
            deny  all;
        }
    }

sobota 20. listopadu 2010

Příprava Linuxového serveru pro hosting Ruby on Rails aplikací

Součásti

  • Nginx
  • Passenger

Instalace

apt-get install ruby rdoc ruby1.8-dev build-essential libopenssl-ruby libcurl4-openssl-dev libssl-dev zlib1g-dev libsqlite3-dev
wget http://production.cf.rubygems.org/rubygems/rubygems-1.3.7.tgz
tar -xzf rubygems-1.3.7.tgz
cd rubygems-1.3.7
ruby setup.rb
gem1.8 install rails sqlite3-ruby passenger
passenger-install-nginx-module

Konfigurace

Init skript /etc/init.d/nginx (počítá s instalací do defaultního umístění)
#! /bin/sh

PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
DAEMON=/opt/nginx/sbin/nginx
NAME=nginx
DESC=nginx

test -x $DAEMON || exit 0

set -e

. /lib/lsb/init-functions

test_nginx_config() {
  if $DAEMON -t $DAEMON_OPTS
  then
    return 0
  else
    return $?
  fi
}

case "$1" in
  start)
 echo -n "Starting $DESC: "
        test_nginx_config
 start-stop-daemon --start --quiet --pidfile /opt/nginx/logs/$NAME.pid \
  --exec $DAEMON -- $DAEMON_OPTS || true
 echo "$NAME."
 ;;
  stop)
 echo -n "Stopping $DESC: "
 start-stop-daemon --stop --quiet --pidfile /opt/nginx/logs/$NAME.pid \
  --exec $DAEMON || true
 echo "$NAME."
 ;;
  restart|force-reload)
 echo -n "Restarting $DESC: "
 start-stop-daemon --stop --quiet --pidfile \
  /opt/nginx/logs/$NAME.pid --exec $DAEMON || true
 sleep 1
        test_nginx_config
 start-stop-daemon --start --quiet --pidfile \
  /opt/nginx/logs/$NAME.pid --exec $DAEMON -- $DAEMON_OPTS || true
 echo "$NAME."
 ;;
  reload)
        echo -n "Reloading $DESC configuration: "
        test_nginx_config
        start-stop-daemon --stop --signal HUP --quiet --pidfile /opt/nginx/logs/$NAME.pid \
            --exec $DAEMON || true
        echo "$NAME."
        ;;
  configtest)
        echo -n "Testing $DESC configuration: "
        if test_nginx_config
        then
          echo "$NAME."
        else
          exit $?
        fi
        ;;
  status)
 status_of_proc -p /opt/nginx/logs/$NAME.pid "$DAEMON" nginx && exit 0 || exit $?
 ;;
  *)
 echo "Usage: $NAME {start|stop|restart|reload|force-reload|status|configtest}" >&2
 exit 1
 ;;
esac

exit 0
Passenger
http://www.modrails.com/videos/passenger_nginx.mov

středa 5. května 2010

Configuring Dynamic DNS & DHCP

http://www.debian-administration.org/article/Configuring_Dynamic_DNS__DHCP_on_Debian_Stable

Disable AppArmor

AppArmor is a security extension (similar to SELinux) that should provide extended security. In my opinion you don't need it to configure a secure system, and it usually causes more problems than advantages (think of it after you have done a week of trouble-shooting because some service wasn't working as expected, and then you find out that everything was ok, only AppArmor was causing the problem). Therefore I disable it (this is a must if you want to install ISPConfig later on).

We can disable it like this:
/etc/init.d/apparmor stop
update-rc.d -f apparmor remove
aptitude remove apparmor apparmor-utils

středa 18. listopadu 2009

Squirrelmail česky na Ubuntu

apt-get install squirrelmail-locales
locale-gen cs_CZ
squirrelmail-configure
* 10 Languages
* 1 cs_CZ
* 2 utf-8

Převod locales do utf-8: http://www.utf-8.sk/squirrelmail.txt

Removing SSL passphrases

openssl rsa -in server.key.bak -out server.key
https://support.railsmachine.com/index.php?pg=kb.page&id=144

středa 19. srpna 2009

Mapování skupin

groupadd DomainAdmins
net groupmap add rid=512 type=domain ntgroup="Domain Admins" unixgroup=DomainAdmins
groupadd DomainUsers
net groupmap add rid=513 type=domain ntgroup="Domain Users" unixgroup=DomainUsers
groupadd DomainGuests
net groupmap add rid=514 type=domain ntgroup="Domain Guests" unixgroup=DomainGuests
groupadd DomainComputers
net groupmap add rid=515 type=domain ntgroup="Domain Computers" unixgroup=DomainComputers

pondělí 3. srpna 2009

Postfix monitoring

Mailgraph

apt-get install rrdtool mailgraph

pflogsumm

apt-get install pflogsumm mailx
vi /etc/cron.daily/postfix_report.sh
#!/bin/sh
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
pflogsumm /var/log/mail.log.0 | head -c 10M - | mail -s "Mail Statistics" vas@email.cz
exit 0
chmod 755 /etc/cron.daily/postfix_report.sh

zdroj: http://www.howtoforge.com/mail_statistics_mailgraph_pflogsumm

čtvrtek 16. července 2009

Přihlášení Samby do win domény

http://developer.novell.com/wiki/index.php/HOWTO:_Configure_Ubuntu_for_Active_Directory_Authentication


1) /etc/resolv.conf
search domena.local
nameserver IPA.DRE.SAP.DC
2) /etc/smb.conf
[global]
server string =
encrypt passwords = Yes
netbios name = LINUX
security = domain
workgroup = SKUPINA
password server = Název serveru
realm = DNS název domény
winbind use default domain = Yes
idmap uid = 10000-20000
idmap gid = 10000-20000
winbind enum users=yes
winbind enum groups=yes
winbind nested groups = Yes
winbind separator = +
interfaces = eth1
bind interfaces only = yes
log level = 3
log file = /var/log/samba/log.%m
store dos attributes = yes

create mask = 770
force create mode = 770
directory mask = 770
3)
sudo apt-get install heimdal-clients libpam-heimdal
/etc/krb5.conf
[libdefaults]
clockskew = 600
default_realm = DOMENA.LOCAL

[realms]
DNS NÁZEV DOMÉNY = {
kdc = PDC
default_domain = DOMENA
kpasswd_server = PDC.DOMENA.LOCAL
}

[domain_realm]
.domena.local = DOMENA.LOCAL


[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log


[appdefaults]
pam = {
ticket_lifetime = 1d
renew_lifetime = 1d
forwardable = true
proxiable = false
retain_after_close = false
minimum_uid = 0
debug = false
}
4) /etc/pam.d/samba
//pridat na zacatek
auth required /lib/security/pam_winbind.so
account required /lib/security/pam_winbind.so
5) prihlaseni do domeny
net rpc join -S PDC -U administrator
net rpc join -W DOMENA -U administrator
6) /etc/nsswitch.conf
passwd: files winbind
group: files winbind
hosts: files dns winbind
7) wbinfo
wbinfo --set-auth-user=administrator%'bigsecret'
8) test
nmbd; smbd; winbindd;
wbinfo -u //uzivatele
wbinfo -g //skupiny
9) problemy
-debug mod winbodd
+/etc/init.d/winbindd stop
winbindd -d 3 -i
-pripoji se ale nenacte uzivatele (wbinfo -u) (~win 2000)
+do smb.conf pridat client schannel = no
(http://www.gatago.com/linux/samba/14514734.html,
http://kbase.redhat.com/faq/FAQ_85_5515.shtm)
-zadani skupiny s mezerou v nazvu do valid users
+valid users = "@domain admins"
-windows 7
=upravit nastavení NTLM http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270746

-------------------------
http://lilly.csoft.net/~vdebaere/handleiding/samba-activedirectory/index_en.html

http://us1.samba.org/samba/docs/man/Samba-Guide/unixclients.html#ch9-adssdm

http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/domain-member.html


http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/InterdomainTrusts.html#id2587424

http://us1.samba.org/samba/docs/man/Samba-HOWTO-Collection/FastStart.html#id2523211


do smb.conf (http://www.wlug.org.nz/ActiveDirectorySamba)[vubec nevim co sem tim chtel rict]



-------------------------
/etc/resolv.conf
/etc/samba/smb.conf
/etc/pam.d/samba
/etc/nsswitch.conf
/etc/krb5.conf

pátek 5. prosince 2008

úterý 9. září 2008

OpenVPN - klient

Konfigurace pro klienta

# klient
client

# server
remote I.P.ADRESA.SERVERU 1194

# certifikat certifikacni autority
ca ca.crt

# certifikat klienta
cert uzivatel.crt

# klíč klienta
key uzivatel.key

# The persist options will try to avoid
# accessing certain resources on restart
# that may no longer be accessible because
# of the privilege downgrade.
# Try to preserve some state across restarts.
persist-key
persist-tun

# udrzuje spojeni nazivu, 10 (ping) a 120 (ping-restart)
keepalive 10 60
port 1194
proto udp
dev tap0

# ukecanost
verb 5
mute 10

# komprese prenasenych dat
comp-lzo

# uzivatel pod kterym bezi klient
user nobody

# skupina pod kterym bezi klient
group nogroup

# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server".  This is an
# important precaution to protect against
# a potential attack discussed here:
#  http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server".  The build-key-server
# script in the easy-rsa folder will do this.
ns-cert-type server

# Most clients don't need to bind to
# a specific local port number.
nobind

OpenVPN - server

Instalace

apt-get install openvpn

Generování certifikátů

cd /usr/share/doc/openvpn/examples/easy-rsa/2.0

source ./vars

./clean-all
./build-ca
./build-key-server server
./build-key user
./build-dh

cp keys/ca.crt /etc/openvpn/
cp keys/dh1024.pem /etc/openvpn/
cp keys/server.crt /etc/openvpn/
cp keys/server.key /etc/openvpn/

vi /etc/openvpn/server.conf

Konfigurace

server 192.168.5.0 255.255.255.0
client-to-client
port 1194
proto udp
dev tap0

# ukecanost
verb 5
mute 10

# komprese prenasenych dat
comp-lzo

# uzivatel pod kterym bezi server
user nobody

# skupina pod kterou bezi server
group nogroup

dh dh1024.pem

# certifikat certifikacni autority
ca ca.crt

# certifikat serveru
cert server.crt

# klíč serveru
key server.key

tls-server

# The persist options will try to avoid
# accessing certain resources on restart
# that may no longer be accessible because
# of the privilege downgrade.
# Try to preserve some state across restarts.
persist-key
persist-tun

# udrzuje spojeni nazivu, 10 (ping) a 60(ping-restart)
keepalive 10 60

# list of current client connections to the file openvpn.status once per minute
status /var/log/openvpn.status

# logy serveru
log-append /var/log/openvpn.log
#routovani
push "route 192.168.2.0 255.255.255.0"
push "dhcp-option DNS 192.168.2.2"
push "dhcp-option WINS 192.168.2.2"

Restart OpenVNP

/etc/init.d/openvpn restart

Výjimky v iptables

iptables -A INPUT -i tap0 -j ACCEPT
iptables -A OUTPUT -o tap0 -j ACCEPT
iptables -A FORWARD -i tap0 -j ACCEPT

Key Files

Now we will find our newly-generated keys and certificates in the keys subdirectory. Here is an explanation of the relevant files:
Filename Needed By Purpose Secret
ca.crt server + all clients Root CA certificate NO
ca.key key signing machine only Root CA key YES
dh{n}.pem server only Diffie Hellman parameters NO
server.crt server only Server Certificate NO
server.key server only Server Key YES
client1.crt client1 only Client1 Certificate NO
client1.key client1 only Client1 Key YES