Skip to main content

Posts

Ubuntu 16.04 - Remove Unity and Install Gnome

So for my private workstation and laptop I'm using Ubuntu. Even though I spent most of my time in a fully tweaked out terminal (terminator, I'd recommend it), I still do not really like the way Unity 'feels' and 'handles'. So, for reverting to gnome there are not much steps to do. First install the gdm-package. You can do so by running [archy@castle-bravo ~]$ sudo apt-get -y install gdm gnome-shell-extensions This might take a while, depending on your internet-connection. After that, you can remove the ubuntu-desktop packages. This is done by [archy@castle-bravo ~]$ sudo apt-get -y remove unity lightdm After that, let the machine reboot. [archy@castle-bravo ~]$ sudo reboot After the machine booted up, you should be greeted by the gnome login screen. Feel free to comment and / or suggest a topic.

FreeIPA - HBAC-Rules Cheatsheet

Host Based Access Control (short hbac) is a good way to limit access to specific hosts from specific users / groups using specifig services. A small example can be seen at the end of my blogpost about spacewalk and freeipa as authentication source ( link ). Add a hbac-rule: [archy@ipa01 ~]$ ipa hbacrule-add nfs-access Add a user: [archy@ipa01 ~]$ ipa hbacrule-add-user --users=archy nfs-access Add a group: [archy@ipa01 ~]$ ipa hbacrule-add-user --groups=admins nfs-access Add a host: [archy@ipa01 ~]$ ipa hbacrule-add-host --hosts=stor01.archyslife.lan nfs-access Add a group of hosts [archy@ipa01 ~]$ ipa hbacrule-add-host --hostgroups=storage-servers nfs-access Add a service: [archy@ipa01 ~]$ ipa hbacrule-add-service --hbacsvcs=nfs nfs-access Add a servicegroup: [archy@ipa01 ~]$ ipa hbacrule-add-service --hbacsvcgroups=storage nfs-access Removing a hbac-rule: [archy@ipa01 ~]$ ipa hbacrule-del nfs-access Removing a user: [archy@ipa01 ~]$ ipa ...

Setting up Spacewalk to use FreeIPA as authentication source

This post is about setting up Spacewalk to integrate to FreeIPA'sauthentication (ldap/kerberos). First of all, why should you integrate Spacewalk to FreeIPA? FreeIPA gives you the option to control the access policies using keytabs and you can manage your users centrally.  So let's get started. I assume you have a functional Spacewalk and FreeIPA-Server set up and the Spacewalk-Server added as client to your domain. Log in to your FreeIPA-Server and add the http-keytab to your Spacewalk-Server: [archy@ipa01 ~]$ ipa service-add HTTP/spacewalk01.archyslife.lan Next run the script provided by the spacewalk-project / red hat to set up the spacewalk-services [archy@spacewalk ~]$ sudo spacewalk-setup-ipa-autchentication When that's finished, sign in to your IPA-Server again and add the H ost B ased A ccess C ontrol Service. I've named it 'spacewalk' [archy@ipa01 ~]$ ipa hbacsvcs-add spacewalk Next add a hbac-rule for allowing defined users t...

FreeIPA - Basic DNS-Management Cheatsheet

FreeIPA DNS-Management Cheatsheet show ipa's dns-configuration on your local server [archy@ipa01 ~]$ ipa dnsconfig-show modify dns-configuration on your local server [archy@ipa01 ~]$ ipa dnsconfig-mod --forwarder=208.67.222.222 --forwarder=208.67.220.220 --forward-policy=[only|first|none] show all dns servers in an ipa domain [archy@ipa01 ~]$ ipa dnsserver-find show one specific ipa-dnsserver that was found by 'ipa dnsserver-find' [archy@ipa01 ~]$ ipa dnsserver-show ipa02.archyslife.lan modify a remote ipa-dns' configuration [archy@ipa01 ~]$ ipa dnsserver-mod --forwarder=208.67.222.222 --forwarder=208.67.220.220 --forward-policy=[only|first|none] ipa02.archyslife.lan a quick note on forward-policies: only: The dns will search the local database first and if an authoritative answer can be found, return it. Otherwise it will forward and query its forwarders. If the forwarders did not reply, the dns will return a SERVFAIL. first: The dns ...

FreeIPA - Basic User- and Group-Management Cheatsheet

I've decided to write a small cheatsheet for user- and group-.management in FreeIPA. User-management Add user: [archy@ipa01 ~]$ ipa user-add $username --first=user --last=name --shell=/bin/bash --homedir=/home/username --email=username@archyslife.lan --password Modify user: [archy@ipa01 ~]$ ipa user-mod $username --help The options for user-mod and user-add are exactly the same. Change user's password: [archy@ipa01 ~]$ ipa user-mod $username --password Delete user: [archy@ipa01 ~]$ ipa user-del $username Add user to group: [archy@ipa01 ~]$ ipa group-add-member group --users=$username Remove user from group: [archy@ipa01 ~]$ ipa group-remove-member group --users=$username List users: [archy@ipa01 ~]$ ipa user-find Show information to a specific user: [archy@ipa01 ~]$ ipa user-show $username Disable a user-account: [archy@ipa01 ~]$ ipa user-disable $username Enable a user-account: [archy@ipa01 ~]$ ipa user-enable $username ...

Spacewalk and CentOS 7.4

CentOS 7.4 (1708) was released recently and I've updated the Spacewalk-Server in my testing environment and discovered that a small issue was affecting the services ability to start. First I was getting a blank screen, then the osa-dispatcher.service was not able to start. So here is what I did to fix it: First update your running CentOS-Installation [archy@spacewalk ~]$ sudo yum -y update This might take a while. After it has finished, downgrade the c3p0 package to fix the osa-dispatcher not starting issue and reboot to let your machine start with the updated kernel. [archy@spacewalk ~]$ sudo yum -y downgrade c3p0 && reboot When it's started up again, check the spacewalk-services. [archy@spacewalk ~]$ sudo spacewalk-service status In my case, the taskomatic did not start successfully. This can be fixed by running [archy@spacewalk ~]$ sudo spacewalk-service stop && sleep 5 && spacewalk-service start The services should now be in r...

iSCSI Server and client in CentOS 7

iSCSI (internet Small Computer System Interface) is common way to export storage to a client in enterprise environments (e.g. Clustering with DRBD). In this example, I'll show how to install the iscsi-server and map the exportet LUN to the client. I'm assuming you have a clean and updated version of CentOS 7.3 installed both on client the client and the server. My server's ip: 172.31.10.34 My client's ip: 172.31.10.35 We'll start by configuring the server. First we have to install the package 'targetcli'. This utility is used for all the configuration done. [archy@storage01 ~]$ sudo yum -y install targetcli Enable the service to start on boot and start it now. [archy@storage01 ~]$ sudo systemctl enable target.service && sudo systemctl start target.service Start the configuration by running [archy@storage01 ~]$ sudo targetcli Before configuring the iSCSI-Target I want to mention that there are two options to allocate the stor...

Getting started with Puppet

What is Puppet? Puppet is a config management tool that helps automating, provisioning and mange the infrastructure using the puppet agent to connect to the server (master). The Files used by puppet to configure are saved in manifests. What you will need is fully configured private DNS for your infrastructure providing forward and reverse zones. Otherwise you will have to resolv all names using entries in /etc/hosts which gets very hard to manage really fast. You will also need to have port 8140/tcp open in your server's firewall. In my case, I'll be using the hostnames puppetmaster.archyslife.lan - 172.31.10.40 and client01.archyslife.lan - 172.31.10.50 . Important: There needs to be a dns-record (A) named puppet.yourdomain.tld which points to your master server. If you are using FreeIPA and the integrated DNS, you can simply run: [archy@ipa01 ~]$ ipa dnsrecord-add archyslife.lan puppet --a-ip-address=172.31.10.40 With that said, let's get started. First we...