Server Chit Chats, Troubleshooting issues and Tutorials :)
Wednesday, July 22, 2009
Securing /tmp and /dev/shm
#df -h |grep tmp
If that displays nothing then go below to create a tmp partition. If you do have a tmp partition you need to see if it mounted with noexec.
#cat /etc/fstab |grep tmp
If there is a line that includes /tmp and noexec then it is already mounted as non-executable. If not follow the instructions below to create one without having to physically format your disk. Idealy you would make a real partition when the disk was originally formated, that being said I have not had any trouble create a /tmp partition using the following method.
Create a ~1000Mb partition
#cd /dev/; dd if=/dev/zero of=tmpMnt bs=1024 count=1000000
Format the partion
#mkfs.ext2 /dev/tmpMnt
When it asks about not being a block special device press Y
Make a backup of the old data
#cp -Rp /tmp /tmp_backup
Mount the temp filesystem
#mount -o loop,noexec,nosuid,rw /dev/tmpMnt /tmp
Set the permissions
#chmod 0777 /tmp
Copy the old files back
#cp -Rp /tmp_backup/* /tmp/
Once you do that go ahead and restart mysql and make sure it works ok. We do this because mysql places the mysql.sock in /tmp which neeeds to be moved. If not it migth have trouble starting. If it does you can add this line to the bottom of the /etc/fstab to automatically have it mounted:
Open the file in vi:
#vi /etc/fstab
Now add this single line at the bottom:
/dev/tmpMnt /tmp ext2 loop,noexec,nosuid,rw 0 0
While we are at it we are going to secure /dev/shm. Look for the mount line for /dev/shm and change it to the following:
none /dev/shm tmpfs noexec,nosuid 0 0
Umount and remount /dev/shm for the changes to take effect.
#umount /dev/shm
#mount /dev/shm
Next delete the old /var/tmp and create a link to /tmp
#rm -rf /var/tmp/
#ln -s /tmp/ /var/
If everything still works fine you can go ahead and delete the /tmp_backup directory.
#rm -rf /tmp_backup
You /tmp, /var/tmp, and /dev/shm are now mounted in a way that no program can be directly run from these directories. Like I have said in other articles there are still ways in but this is one of the many layers of security you should have on your system.
Change mysql data directory
You can change mysql data directory by adding the following entries in /etc/my.cnf file
datadir=newlocation/path
save the file, move the necessary database files from /var/lib/mysql to the new location and restart mysql.
To check if the new location is added correctly, login to mysql as root and create a test database and check the new location if the new database files are added or not.
If mysql doesnt start after restarting then check the logs for an error
# tail -f /var/log/mysqld.log
If there are no specific errors mentioned check if selinux is enabled or not. If its enabled then you may disable it and try starting mysql.
commands to check if selinux is enabled
#getenforce
the result will be like enabled, permissive or targeted You can disable it by editing the configuration file /etc/selinux/config (RHEL/centos)
How to add a range of IP's
For instance, if you want to add 10 IP addresses, you'll have to create 10 files in that directory, starting with ifcfg-eth0:0 and ending
with ifcfg-eth0:10. Each file will contain:
CODE
DEVICE=eth0:0
ONBOOT=yes
BOOTPROTO=static
IPADDR=192.168.0.2
NETMASK=255.255.255.0
NETWORK=192.168.0.0
BROADCAST=192.168.0.255
TYPE=Ethernet
The IPADDR will increase from 192.168.0.2 to 192.168.0.12.
But what if you have to add 100 IP addresses? It could be physically possible to manually add a file for each of them. But how about
1000 IP addresses? Or 10,000? Fortunately, RedHat based systems offer a quick and easy way to bind a range of IPs, eliminating the
need to create a lot of files and saving a lot of your time.
Create a file called ifcfg-eth0-range0 in the /etc/sysconfig/network-scripts directory. This file must contain the following strings:
CODE
IPADDR_START=192.168.0.10
IPADDR_END=192.168.0.110
CLONENUM_START=0
Let's see what each of them does:
IPADDR_START: This is the first IP from the address range you want to bind to your ethernet device.
IPADDR_END: This is, of course, the last IP from that address range.
CLONENUM_START: This is the number that will be assigned to the first IP alias interface. For instance, if your Internet interface is eth0 and CLONENUM_START is 0, then this config file will create 100 interfaces starting with eth0:0 (eth0:0, eth0:1, eth0:2 etc) and ending with eth0:100.
NOTE! Be careful if you need to add more ranges of IPs. You'll have to use a proper value for CLONENUM_START. For instance, if you need to add a second range with 100 IPs besides the one above, create a new file called ifcfg-eth0-range1 and set the CLONENUM_START to 101 so an overwrite will be avoided.
After making any changes to any of the files created in the network-scripts directory, you have to run the following command so the changes are applied and the address range is activated:
# service network restart
Thursday, July 2, 2009
Adding New repositories to YUM
cd /etc/yum.repos.d/
vi dag.repo // the add the following lines in that file//
[dag]
name=Dag RPM Repository for Red Hat Enterprise Linux
baseurl=http://apt.sw.be/redhat/el$releasever/en/$basearch/dag
gpgcheck=1
rpm --import http://dag.wieers.com/rpm/packages/RPM-GPG-KEY.dag.txt
//save and quit//
for remi repo visit the url below
http://blog.famillecollet.com/pages/Config-en
Thursday, June 4, 2009
Yum
yum localinstall package_name.rpm That will install an RPM, and try to resolve all the dependencies for you using your repositories.
yum update update all rpm packages installed on the system
yum update package_name upgrade a rpm package
yum remove package_name remove a rpm package
yum list list all packages installed on the system
yum search package_name find a package on rpm repository
yum clean packages clean up rpm cache erasing downloaded packages
yum clean headers remove all files headers that the system uses to resolve dependency
yum clean all remove from the cache packages and headers files
Monday, May 25, 2009
Installing FFmpeg and FFmpeg-php
System Configuration/Prerequisites
The server that I had to install on was running:
- Centos 5.x
- cPanel 11 (but of course, you don’t need cPanel to install FFmpeg and ffmpeg-php)
- Yum (or anything of the likes would do)
- And I presume you have root access
Getting the required Files
Firstly, we would have to download all the required files to a folder. For me, I picked /usr/local/src, but it could be just any other folder you’d like.
Move into the directory that you’d like to download the source files to and run the following commands:
wget http://www3.mplayerhq.hu/MPlayer/releases/codecs/essential-20061022.tar.bz2
wget http://www4.mplayerhq.hu/MPlayer/releases/MPlayer-1.0rc2.tar.bz2
wget http://rubyforge.org/frs/download.php/17497/flvtool2-1.0.6.tgz
wget http://downloads.xiph.org/releases/ogg/libogg-1.1.3.tar.gz
wget http://downloads.xiph.org/releases/vorbis/libvorbis-1.1.2.tar.gz
wget http://easynews.dl.sourceforge.net/sourceforge/lame/lame-3.97.tar.gz
wget http://easynews.dl.sourceforge.net/sourceforge/ffmpeg-php/ffmpeg-php-0.5.3.1.tbz2
This is what I used in my setup. Additional libraries should be downloaded if you need them. Also, I wouldn’t say that these are the latest binaries, but they work for me for now - you should check for updates if you wish. You may also want to change the location of the SourceForge downloads.
Now extract all the files you’ve downloaded:
bunzip2 essential-20061022.tar.bz2; tar xvf essential-20061022.tar
bunzip2 MPlayer-1.0rc2.tar.bz2 ; tar -xvf MPlayer-1.0rc2.tar
tar zxvf flvtool2-1.0.6.tgz
tar zxvf libogg-1.1.3.tar.gz
tar zxvf libvorbis-1.1.2.tar.gz
tar zxvf lame-3.97.tar.gz
bunzip2 ffmpeg-php-0.5.3.1.tbz2; tar xvf ffmpeg-php-0.5.3.1.tar
Along with the additional libraries you could have possibly downloaded.
Installation
Now that we’re done downloading the files we need, it’s time to start the installation.
Codecs
Create a folder to store the Codecs that ffmpeg will need:
mkdir /usr/local/lib/codecs/
mv essential-20061022/* /usr/local/lib/codecs/
chmod -Rf 755 /usr/local/lib/codecs/
Subversion/Ruby/
yum install subversion
yum install ruby
yum install ncurses-devel
LAME
cd lame-3.97
export LD_LIBRARY_PATH=/usr/local/lib
./configure
make
make install
libogg
cd libogg-1.1.3
./configure
make
make install
libvorbis
cd libvorbis-1.1.2
./configure
make
make install
flvtool2
cd flvtool2-1.0.6
ruby setup.rb config
ruby setup.rb setup
ruby setup.rb install
MPlayer
cd MPlayer-1.0rc2
./configure
make
make install
Now for the big one, ffmpeg.
Installing FFmpeg
Generally, we would install the latest version of ffmpeg. But as of the date of this post, the latest version of ffmpeg does not wok with ffmpeg-php. We will need to checkout a previous version from the SVN.
Inside your src folder, run the following to checkout this version of ffmpeg which works.
svn checkout svn://svn.mplayerhq.hu/ffmpeg/trunk/ ffmpeg -r15261
Once it is done downloading, go into the ffmpeg folder
Note: If a version of ffmpeg was previously installed, run the following command in the ffmpeg folder first:
make uninstall
make clean
Start the installation. You may need to add/enable additional libraries into ./configure.
cd ffmpeg
./configure --enable-libmp3lame --enable-libvorbis --disable-mmx --enable-shared
make
make install
During installation, you may get an error like:
Unable to create and execute files in /tmp. Set the TMPDIR environment
variable to another directory and make sure that /tmp is not mounted
noexec.
Sanity test failed.
To fix this, run the following commands to create a temporary tmp directory:
mkdir tmp
chmod 777 tmp
export TMPDIR=./tmp
After installation, remember to change the tmp directory back to your server’s tmp disk by doing the following:
export TMPDIR=/tmp
Check if ffmpeg is working by running the following:
ffmpeg -version
It should return something similar to:
FFmpeg version SVN-r15261, Copyright (c) 2000-2008 Fabrice Bellard, et al.
configuration: --enable-libmp3lame --enable-libvorbis --disable-mmx --enable-shared
libavutil 49.10. 0 / 49.10. 0
libavcodec 51.71. 0 / 51.71. 0
libavformat 52.22. 1 / 52.22. 1
libavdevice 52. 1. 0 / 52. 1. 0
If the version isn’t “SVN-r15261″, then there is something wrong and you may need to reinstall ffmpeg.
If something like the following is returned:
ffmpeg: error while loading shared libraries: libavdevice.so.52: cannot open shared object file: No such file or directory
Search for the missing library (in this case libaddevice.so.52) with the following:
find / -name 'libavdevice.so.*'
The returned results may look something like this. The one that we want is the one in the lib folder and not the src folder.
/usr/local/src/ffmpeg/libavdevice/libavdevice.so.52
/usr/local/lib/libavdevice.so.52
/usr/local/lib/libavdevice.so.52.1.0
With that, since the libraries are in the /usr/local/lib/ folder, we run the following:
export LD_LIBRARY_PATH=/usr/local/lib/
Otherwise, simply change the stuff after “=” to the path where the library is.
Sweet! Now that we’ve got FFmpeg working successfully, time to install ffmpeg-php.
Installing ffmpeg-php
Start the installation by running the following (again, run make clean as necessary):
cd ffmpeg-php-0.5.3.1
phpize
./configure
make
make install
You may meet the following errors during installation:
checking for ffmpeg headers… configure: error: ffmpeg headers not found. Make sure you’ve built ffmpeg as shared libs using the –enable-shared option
Solution: Simply create a ffmpeg folder in /usr/local/include/ and run the following to copy all the header files:
cp /usr/local/include/libavcodec/* /usr/local/include/ffmpeg
cp /usr/local/include/libavdevice/* /usr/local/include/ffmpeg
cp /usr/local/include/libavformat/* /usr/local/include/ffmpeg
cp /usr/local/include/libavutil/* /usr/local/include/ffmpeg
cp /usr/local/include/libswscale/* /usr/local/include/ffmpeg
make: *** [ffmpeg_frame.lo] Error 1
Solution: Execute the following in the ffmpeg-php folder. I’ve no idea why the files are named wrongly too.
cp ffmpeg_frame.loT ffmpeg_frame.lo
Upon successful installation, the installer will give you a very long sting to tell you where the extension was installed to. This is a unique string. The following is what I got:
Installing shared extensions: /usr/local/lib/php/extensions/no-debug-non-zts-20060613/
This has to be added to into php.ini.
In cPanel Servers, the php.ini file is located in /usr/local/lib. Otherwise, it should be in etc/php.ini.
Add the following line into php.ini (at the bottom or wherever you want):
extension=ffmpeg.so
Finalizing Installation
Restart Apache on the server.
service httpd restart
Check that ffmpeg is running on the server:
php -i | grep ffmpeg
The following should be returned:
ffmpeg
ffmpeg support (ffmpeg-php) => enabled
ffmpeg-php version => 0.5.3.1
ffmpeg-php gd support => enabled
ffmpeg.allow_persistent => 0 => 0
If an error like the following appears:
php: symbol lookup error: /usr/local/lib/php/extensions/no-debug-non-zts-20060613/ffmpeg.so: undefined symbol: av_free_static
Simply rebuild ffmpeg-php and it should work again.
And you’re done!
You have just successfully installed FFmpeg and ffmpeg-php on your server!
Tuesday, May 12, 2009
SSH key- passwordless login
ssh-keygen -t dsa -f filename
It will prompt for a passphrace, it is desirable to leave it empty.
Two files will be created
filename
filename.pub
copy the filename.pub file to the destination server to the location /root/.ssh add the public key entry into authorized_keys as follows
cat filename.pub >> authorized_keys
/etc/init.d/sshd restart
Thursday, April 30, 2009
Install cPanel
In order to run the cPanel software you must first be running a supported OS like RedHat or CentOS.
cPanel lists their supported operating systems on their website at http://www.cpanel.net. cPanel also recommends that the server it is being installed on is a clean and fresh install. This means that if you previously had done any configuring or ran another control panel software that they recommend you reinstall the server.
IMPORTANT: If the server you plan to install cPanel on is a live production server, STOP. cPanel's installer may overwrite your previous configurations and cause downtime for you or your customers!
cPanel has made the installation process a simple one and only takes a few commands to get the install going. Below are the steps:
1. Log into your server as root via the console or SSH.
3. Change directory into your /home (cmd: cd /home).2.1. If nslookup does not work, giving a 'command not found' error, you can use yum to install the necessary packages (cmd: yum install bind-utils.i386).
2.2. If you get an error about not being able to resolve the host, you need to edit your /etc/resolv.conf and add proper resolvers ( eg; 8.8.8.8 )
4. Download cPanel's installer (cmd: wget -N http://httpupdate.cpanel.net/latest ).
4.1. If you get a 'command not found' error, you need to install wget. (cmd: yum install -y wget).5. Now run the installer using sh or bash (cmd: sh latest).
5.1. If you get another 'command not found' error, you need to install Perl. (cmd: yum install perl).The installer is now running and may take a hour to two depending on your servers hardware, OS, connection speed, etc.
Once the installation is complete it's not time to log into the WebHostManager (WHM) and go through the wizard. Point your browser to http://your_ip_here
Once complete your system is ready to use! Good Luck ;)
Sunday, March 15, 2009
How can I configure multiple Web sites using Host Headers?
Configure Web Sites by Using Host Header Names
To configure Web sites by using the Host Header Names feature, follow these steps:
1. Click Start, point to Administrative Tools, and then click Internet Information Services.
2. Expand * server name (where server name is the name of the server), and then expand Web Sites.
3. Right-click the Web site that you want, and then click Properties.
The Web site name Properties dialog box appears (where Web site name is the name of the Web site that you selected).
4. Click the Web Site tab, and then in the IP Address list, select the IP address that you want assigned to this Web site.
5. Click Advanced.
6. Under Multiple identities for this Web Site, click the IP address, and then click Edit.
The Advanced Web Site Identification dialog box appears.
7. In the Host Header Name box, type the host header that you want. For example, type www.example1.com. Add the port number, select the IP address in the list, and then click OK.
NOTE: If you want to configure this Web site with additional identities, click Add. Use the same IP address and TCP port, but enter a unique Host Header Name, and then click OK. For example, if you want to access the same Web site from both the Internet and a local intranet, you can configure the Web site identity in the manner shown in the following example:
IP Address TCP Port Host Header Name
192.168.0.100 80 www.example1.com
192.168.0.100 80 example1.com
8. In the Advanced Multiple Web Site Configuration dialog box, click OK.
9. In the Web site name Properties dialog box, click OK.
You return to the IIS window.
10. Right-click the next Web site that you want, and then click Properties.
11. In the IP Address list, select the same IP address that you selected in step 4, and then click Advanced.
12. Under Multiple identities for this Web Site, click the IP address, and then click Edit.
The Advanced Web Site Identification dialog box appears.
13. In the Host Header Name box, type a unique host header for this Web site. For example, type www.example2.com, add the port number, select the IP address in the list, and then click OK.
14. In the Advanced Multiple Web Site Configuration dialog box, click OK.
15. In the Web site name Properties dialog box, click OK.
You return to the IIS window.
16. Repeat steps 10 through 15 for each Web site that you want hosted on this IP address.
17. Register the host header names with the appropriate name resolution system -- for example, a Domain Name System (DNS) server or, in the case of a small network, a Hosts file.
The Web sites are now configured to accept incoming Web requests, based on their host header names.
More Information
Do not assign a host header name to the Default Web Site. Many programs expect the Default Web Site to use an IP address of (All Unassigned), TCP Port 80, and no host header name.
Troubleshooting
• Clients cannot connect to the Web sites by using the IP address:
Because there is more than one Web site configured to the IP address, you must connect to the Web site by using the host header name. When you try to connect to the Web site by using the IP address, you receive the following error message:
The page cannot be found.
The page you are looking for might have been removed, had its name changed, or is temporarily unavailable.
• Clients cannot connect to the Web sites by using host header names:
Multiple host names must be mapped to the single IP address by using a DNS server or a Hosts file.
How to Connect to the Console Session
Connecting to the Console Session
When you connect to the console session of a Windows Server 2003-based server, no other user has to be already logged on to the console session. Even if no one is logged on to the console, you are logged on just as if you were sitting at the physical console.
To connect from the remote Windows Server 2003-based computer, open a command prompt, and then type the following command:
mstsc -v:servername /F -console
where mstsc is the Remote Desktop connection executable file, -v indicates a server to connect to, /F indicates full screen mode, and -console is the instruction to connect to the console session.