Joining CentOS and authenticate to ACtive Directory using winbind
- Make sure that you have a working DNS that can resolve the domain you are going to join and authenticate the CentOS server. Check /etc/resolv.conf
Install the ff:
yum install authconfig krb5-workstation pam_krb5 samba-common
Execute the command:
Assuming the domain is MYCOMPANY.COM
authconfig --disablecache --enablewinbind --enablewinbindauth --smbsecurity=ads --smbworkgroup=MYCOMPANY --smbrealm=MYCOMPANY.COM --enablewinbindusedefaultdomain --enablekrb5 --krb5realm=MYCOMPANY.COM --enablekrb5kdcdns --enablekrb5realmdns --enablelocauthorize --enablepamaccess --smbidmapuid=16777216-16777300 --krb5kdc=srv001.mycompany.com --krb5adminserver=srv001.mycompany.com --winbindtemplateshell=/bin/bash --updateall
The command above will change the /etc/samba/smb.conf and /etc/krb5.conf
Once done on the authconfig command, issue the command below:
kinit admin.user@MYCOMPANY.COM #This will ask for your password that you use on your AD domain to login, and will tell you if the server was joined successfully.
Once accepted, you may join to domain.
net join -w MYCOMPANY.COM -U admin.user #Again will ask for a password.
/etc/init.d/winbind restart
chkconfig winbind on
Cisco | Linux | Mandriva | Centos | FreeBSD | GNS3 | Windows 2003 | RedHat | LVM | Rhev 3
Wednesday, November 4, 2015
Thursday, September 3, 2015
Some Backup script for postgresql 9.3 database - using parallel run
#!/bin/bash
#set-x
#Original Script Owner#
# #backuppostgresql.sh
#by #CraigSanders
#this script is public domain. feel free to use or modify as you like.
## Modified by: yongitz and ohbet - 2015 of September
#Note
# to restore database from this backup
# Command is: /usr/pgsql-9.3/bin/pg_restore -j -Fd $DATA
# where data is the path of the backup /db/BACKUP/Date-of-backup/Database_Name-folder
# /usr/pgsql-9.3/bin/pg_restore -j -Fd /db/BACKUP/2015-09-04/database_folder
# See postgresql 9.3 manual page for details
#
PGDUMP="/usr/pgsql-9.3/bin/pg_dump"
PSQL="/usr/pgsql-9.3/bin/psql"
#
# directory to save backups in, must be owned by postgres user
BASE_DIR="/db/BACKUP"
#Make some checking if backup folder is available
#
if ! ls $BASE_DIR > /dev/null 2>&1; then
echo "Backup directory $BASE_DIR does not exist. Backup processes terminated." | mail -s "!!! ALERT - BACKUP PROCESS FAILED @ DBSERVERXYZ !!!" db.admin@mycompany.com
exit 1
fi
#Create the Base Directory
YMD=$(date "+%Y-%m-%d")
DIR="$BASE_DIR/$YMD"
ls -l $BASE_DIR
mkdir -p $DIR
cd $DIR
#
# get list of databases in system , exclude the tempate db and other db not needed, db below are example only
DBS=$($PSQL -l -t | egrep -v 'template[01]|dbxyz|db2|db_warehouse' | awk '{print $1}' | grep -v '|'|grep -v '^$')
#
# now loop through each individual database
for database in $DBS; do
DATA=$DIR/$database
# dump data
if [ $database = db_live_final ]; then
# Remarks: j8 = 8 parallel process to run: at 9.3 and above
# Remarks: -N backup_tables and -N DBX_* are schema that are excluded on backup
$PGDUMP -v -j8 -N backup_tables -N DBX_* -Fd -f $DATA $database
else
$PGDUMP -v -j8 -Fd -f $DATA $database
fi
done
#copy conf files currently used.
cp /db/pgsql/9.3/data/*.conf $DIR/
#
#Create readme for restore
cat < $DIR/Restore_readme.txt
To restore database from this backup
Use Command:
/usr/pgsql-9.3/bin/pg_restore -j -Fd /path/to/backup/folder/per/db/name
where data is the path of the backup /db/BACKUP/Date-of-backup/Database_Name-folder
Sample Below:
/usr/pgsql-9.3/bin/pg_restore -j -Fd /db/BACKUP/2015-09-04/database_folder
See postgresql 9.3 manual page for further details
EOF
#
# delete backup files older than 30 days
OLD=$(find $BASE_DIR -type d -mtime +30)
if [ -n "$OLD" ] ; then
echo deleting old backup files: $OLD
echo $OLD | xargs rm -rf
fi
Then save this as bash script and put on a cron to run daily.
#set-x
#Original Script Owner#
# #backuppostgresql.sh
#by #CraigSanders
#this script is public domain. feel free to use or modify as you like.
## Modified by: yongitz and ohbet - 2015 of September
#Note
# to restore database from this backup
# Command is: /usr/pgsql-9.3/bin/pg_restore -j -Fd $DATA
# where data is the path of the backup /db/BACKUP/Date-of-backup/Database_Name-folder
# /usr/pgsql-9.3/bin/pg_restore -j -Fd /db/BACKUP/2015-09-04/database_folder
# See postgresql 9.3 manual page for details
#
PGDUMP="/usr/pgsql-9.3/bin/pg_dump"
PSQL="/usr/pgsql-9.3/bin/psql"
#
# directory to save backups in, must be owned by postgres user
BASE_DIR="/db/BACKUP"
#Make some checking if backup folder is available
#
if ! ls $BASE_DIR > /dev/null 2>&1; then
echo "Backup directory $BASE_DIR does not exist. Backup processes terminated." | mail -s "!!! ALERT - BACKUP PROCESS FAILED @ DBSERVERXYZ !!!" db.admin@mycompany.com
exit 1
fi
#Create the Base Directory
YMD=$(date "+%Y-%m-%d")
DIR="$BASE_DIR/$YMD"
ls -l $BASE_DIR
mkdir -p $DIR
cd $DIR
#
# get list of databases in system , exclude the tempate db and other db not needed, db below are example only
DBS=$($PSQL -l -t | egrep -v 'template[01]|dbxyz|db2|db_warehouse' | awk '{print $1}' | grep -v '|'|grep -v '^$')
#
# now loop through each individual database
for database in $DBS; do
DATA=$DIR/$database
# dump data
if [ $database = db_live_final ]; then
# Remarks: j8 = 8 parallel process to run: at 9.3 and above
# Remarks: -N backup_tables and -N DBX_* are schema that are excluded on backup
$PGDUMP -v -j8 -N backup_tables -N DBX_* -Fd -f $DATA $database
else
$PGDUMP -v -j8 -Fd -f $DATA $database
fi
done
#copy conf files currently used.
cp /db/pgsql/9.3/data/*.conf $DIR/
#
#Create readme for restore
cat <
To restore database from this backup
Use Command:
/usr/pgsql-9.3/bin/pg_restore -j -Fd /path/to/backup/folder/per/db/name
where data is the path of the backup /db/BACKUP/Date-of-backup/Database_Name-folder
Sample Below:
/usr/pgsql-9.3/bin/pg_restore -j -Fd /db/BACKUP/2015-09-04/database_folder
See postgresql 9.3 manual page for further details
EOF
#
# delete backup files older than 30 days
OLD=$(find $BASE_DIR -type d -mtime +30)
if [ -n "$OLD" ] ; then
echo deleting old backup files: $OLD
echo $OLD | xargs rm -rf
fi
Then save this as bash script and put on a cron to run daily.
Sunday, November 16, 2014
Redirect http to https with multiple VirtualHost on apache
Goal: Redirect all http to https, domain are config.example.com and configure.example.com.
When first try on it, I encountered redirect problem, when you dont place carefully the virtual host, redirection will got problem, so on my example, I need to place carefully, config http then https, and configure http then https. It should also redirect properly when you have a sub folder.
Note: I changed the tags to |
|VirtualHost *:80|
ServerName config.example.com/
RedirectMatch 301 /(.*)$ https://config.example.com/$1
|/VirtualHost|
|VirtualHost *:443|
SSLEngine on
SSLProtocol -ALL -SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM
SSLCertificateFile /etc/pki/example_cert_2017/example.com.crt
SSLCertificateKeyFile /etc/pki/example_cert_2017/example.key
SSLCertificateChainFile /etc/pki/example_cert_2017/gd_bundle.crt
ServerName config.example.com
ServerAlias config.example.com
DocumentRoot "/data/www/config"
ErrorLog logs/ssl-config-error_log
CustomLog logs/ssl-config-access.log common
|/VirtualHost|
|VirtualHost *:80|
ServerName configure.example.com
RedirectMatch 301 /(.*)$ https://configure.example.com/$1
|/VirtualHost|
|VirtualHost *:443|
SSLEngine on
SSLProtocol -ALL -SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM
SSLCertificateFile /etc/pki/example_cert_2017/example.com.crt
SSLCertificateKeyFile /etc/pki/example_cert_2017/example.key
SSLCertificateChainFile /etc/pki/example_cert_2017/gd_bundle.crt
ServerName configure.example.com
ServerAlias configure.example.com
DocumentRoot "/data/www/configure"
ErrorLog logs/ssl-configure-error_log
CustomLog logs/ssl-configure-access.log common
|/VirtualHost|
When first try on it, I encountered redirect problem, when you dont place carefully the virtual host, redirection will got problem, so on my example, I need to place carefully, config http then https, and configure http then https. It should also redirect properly when you have a sub folder.
Note: I changed the tags to |
ServerName config.example.com/
RedirectMatch 301 /(.*)$ https://config.example.com/$1
SSLProtocol -ALL -SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM
SSLCertificateFile /etc/pki/example_cert_2017/example.com.crt
SSLCertificateKeyFile /etc/pki/example_cert_2017/example.key
SSLCertificateChainFile /etc/pki/example_cert_2017/gd_bundle.crt
ServerName config.example.com
ServerAlias config.example.com
DocumentRoot "/data/www/config"
ErrorLog logs/ssl-config-error_log
CustomLog logs/ssl-config-access.log common
|/VirtualHost|
RedirectMatch 301 /(.*)$ https://configure.example.com/$1
|/VirtualHost|
SSLProtocol -ALL -SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM
SSLCertificateFile /etc/pki/example_cert_2017/example.com.crt
SSLCertificateKeyFile /etc/pki/example_cert_2017/example.key
SSLCertificateChainFile /etc/pki/example_cert_2017/gd_bundle.crt
ServerName configure.example.com
ServerAlias configure.example.com
DocumentRoot "/data/www/configure"
ErrorLog logs/ssl-configure-error_log
CustomLog logs/ssl-configure-access.log common
Wednesday, November 12, 2014
Zimbra email retention under 30 days
Normally, zimbra COS can allocate only at least 30 Days and more of email retention, and if lower than 30 days is required, COS is not capable. (Well, you may correct my if I am wrong)
Below is a sample script to do the Job.
1. Create a zimbra distro list that will become the bases of user list that have a threshold. For example, 7days_users@list.example.com is the distro, member of this will have a retention of 7 days.
2. The script.
#!/bin/bash
#Generate the members of 7days_users and pipe it on a temp file.
zmprov gdlm 7days_users@list.example.com |egrep -v '^#|members' > /tmp/_TMP7days
#
for USER in `cat /tmp/_TMP7days`
do
zmmailbox -z -m $USER s -t message -l 1000 "before:`date +%x --date="7 days ago"`" |grep mess |awk '{print $2}' > /tmp/7days_$USER
done
##delete ID
for UserName in `cat /tmp/_TMP7days`
do
for MAILID in `cat /tmp/7days_$UserName`
do
zmmailbox -z -m $UserName dm $MAILID
done
done
#end of script
Below is a sample script to do the Job.
1. Create a zimbra distro list that will become the bases of user list that have a threshold. For example, 7days_users@list.example.com is the distro, member of this will have a retention of 7 days.
2. The script.
#!/bin/bash
#Generate the members of 7days_users and pipe it on a temp file.
zmprov gdlm 7days_users@list.example.com |egrep -v '^#|members' > /tmp/_TMP7days
#
for USER in `cat /tmp/_TMP7days`
do
zmmailbox -z -m $USER s -t message -l 1000 "before:`date +%x --date="7 days ago"`" |grep mess |awk '{print $2}' > /tmp/7days_$USER
done
##delete ID
for UserName in `cat /tmp/_TMP7days`
do
for MAILID in `cat /tmp/7days_$UserName`
do
zmmailbox -z -m $UserName dm $MAILID
done
done
#end of script
Monday, October 6, 2014
Updating openssl to latest
Updating openssl to latest
Download the latest openssl source, as of this writing, the latest is the one I installed.
https://www.openssl.org/source/
Login to your server as root.
wget https://www.openssl.org/source/openssl-1.0.1i.tar.gz
as root
tar xzvf openssl-1.0.1i.tar.gz
cd openssl-1.0.1i
./config
make
make test
make install
Installation is at /usr/local/ssl/bin/openssl
move old openssl
mv /usr/bin/openssl /root/openssl-old
ln -s /usr/local/ssl/bin/openssl /usr/bin/openssl
check version
openssl version
OpenSSL 1.0.1i 6 Aug 2014
Though its better to recompile it as RPM on your build server so as to follow best practice that your production server particular to the one that facing internet should not contain any compiler.
Download the latest openssl source, as of this writing, the latest is the one I installed.
https://www.openssl.org/source/
Bytes Timestamp Filename ________ ____________________ ____________________________ 5149260 Sep 25 22:45:26 2014 openssl-1.0.2-beta3.tar.gz (MD5) (SHA1) (PGP sign) 1404199 Aug 20 12:52:55 2014 openssl-fips-ecp-2.0.8.tar.gz (MD5) (SHA1) (PGP sign) 1424766 Aug 20 12:52:46 2014 openssl-fips-2.0.8.tar.gz (MD5) (SHA1) (PGP sign) 3727934 Aug 6 23:56:45 2014 openssl-0.9.8zb.tar.gz (MD5) (SHA1) (PGP sign) 3994771 Aug 6 23:56:45 2014 openssl-1.0.0n.tar.gz (MD5) (SHA1) (PGP sign) 4422117 Aug 6 23:56:45 2014 openssl-1.0.1i.tar.gz (MD5) (SHA1) (PGP sign) [LATEST] 4872101 Jul 22 22:53:02 2014 openssl-1.0.2-beta2.tar.gz (MD5) (SHA1) (PGP sign) 1438620 Jul 4 01:21:08 2014 openssl-fips-2.0.7.tar.gz (MD5) (SHA1) (PGP sign) 1417674 Jul 4 01:21:08 2014 openssl-fips-ecp-2.0.7.tar.gz (MD5) (SHA1) (PGP sign)
Login to your server as root.
wget https://www.openssl.org/source/openssl-1.0.1i.tar.gz
as root
tar xzvf openssl-1.0.1i.tar.gz
cd openssl-1.0.1i
./config
make
make test
make install
Installation is at /usr/local/ssl/bin/openssl
move old openssl
mv /usr/bin/openssl /root/openssl-old
ln -s /usr/local/ssl/bin/openssl /usr/bin/openssl
check version
openssl version
OpenSSL 1.0.1i 6 Aug 2014
Though its better to recompile it as RPM on your build server so as to follow best practice that your production server particular to the one that facing internet should not contain any compiler.
Tuesday, June 25, 2013
Reversing SVN using good revision number
When updating the codes or code only using svn, below usually is the output:
-bash-3.2$ svn update --force
svn.user@192.168.1.1's password:
U code01.php
Updated to revision 15701.
but if the dev team wants to revert that to previous revision because there was an error on the code, then the possible command is below:
say, the good revision is 15690 as per dev.
-bash-3.2$ svn merge -r HEAD:15690 code01.php
svn.user@192.168.1.1's password:
--- Reverse-merging r15701 through r15691 into 'code01.php':
U code01.php
Now reverted back to a good revision.
-bash-3.2$ svn update --force
svn.user@192.168.1.1's password:
U code01.php
Updated to revision 15701.
but if the dev team wants to revert that to previous revision because there was an error on the code, then the possible command is below:
say, the good revision is 15690 as per dev.
-bash-3.2$ svn merge -r HEAD:15690 code01.php
svn.user@192.168.1.1's password:
--- Reverse-merging r15701 through r15691 into 'code01.php':
U code01.php
Now reverted back to a good revision.
Thursday, June 20, 2013
Monitoring a directory for new file, deleted file, modified file with inotifywait and send thru email
On my setup, I am using CentOS
Add epel repo
yum install inotify-tools
create a bash script at /usr/ocal/bin/inotify_daemon.sh with entry below:
#!/bin/bash
pgrep inotifywait > /dev/null
if [ $? -eq 0 ]
then
exit
else
inotifywait --format '%w%f %e %T' --timefmt '%Y/%m/%d-%H:%M:%S' -e create,delete,modify,move -mrq /path/to/folder/ |while read file;do echo $file | mail -s "activity alert" myuser@mydomain.com; done &
fi
then create a cron entry at crontab or root cron.
* * * * * /usr/ocal/bin/inotify_daemon.sh
The cron will run and if inotify_daemon.sh get accidentally killed, it will run it again. If already running, then it will exit.
I assume that the server has a working smtp and tested to relay email to a ligit and working email system.
Sample email body once it will work is below:
/path/to/folder/test2 DELETE,ISDIR 2013/06/20-05:11:09
the notification that the folder has been deleted.
Add epel repo
yum install inotify-tools
create a bash script at /usr/ocal/bin/inotify_daemon.sh with entry below:
#!/bin/bash
pgrep inotifywait > /dev/null
if [ $? -eq 0 ]
then
exit
else
inotifywait --format '%w%f %e %T' --timefmt '%Y/%m/%d-%H:%M:%S' -e create,delete,modify,move -mrq /path/to/folder/ |while read file;do echo $file | mail -s "activity alert" myuser@mydomain.com; done &
fi
then create a cron entry at crontab or root cron.
* * * * * /usr/ocal/bin/inotify_daemon.sh
The cron will run and if inotify_daemon.sh get accidentally killed, it will run it again. If already running, then it will exit.
I assume that the server has a working smtp and tested to relay email to a ligit and working email system.
Sample email body once it will work is below:
/path/to/folder/test2 DELETE,ISDIR 2013/06/20-05:11:09
the notification that the folder has been deleted.
Subscribe to:
Posts (Atom)