Monday, July 4, 2011

VMWare ESXi Server Implementation


What is VMWare ESXi and Features?

- VMware ESXi is the latest hypervisor architecture from VMware.
- ESXi can be Consolidate all the servers to one physical Machine.
- Not relying on Host’s Operating System (Pure Virtualization OS).
- Start from ESX Vsphere 4.x (Support Only 64 Bit Hardware)
- Support up to 2 TB of Physical Memory.
- Support up to 256 guests machines.
- Can support 32 bit or 64 bit Guest OS (i.e Windows, Linux, Unix)
- ESXi can be run from Server’s SD RAM (Do not need to waste Host’s Storage Space)
- With VMWare Converter, we can convert all the physical machines to VMware ESXi.
- With VSphere Client, we can manage all our virtual machines from one host.
- ESXi’s thin provision technology, can eliminate unnecessary disk usage.
- Can be backup and restore all the virtual machines while servers are still running.
- Can attach with iSCSI and Fiber Channel (External Storage)
- Can add or remove RAM while the virtual servers still running.
- No more hardware cost for New Development Servers.
- We can test new software and patches on Virtual machines.
- Reduce of Electrical Power usage.

Further more information http://www.vmware.com/go/esxi

Monday, March 14, 2011

General System Administration Overview

Classification of Systems:
Small sites have 1 - 10 machines, all running the same OS. Usually the administrator of a small site has only about 20 users. Usually there is only one administrator for a small site.

Medium sites have up to 100 machines, and may be running up to 3 different OSs. The administrator usually has about 100 users. Medium sites may have more that one administrator, either specializing in different operating systems or sharing general system administrator duties.

Large sites have over 100 computers, multiple operating systems, and over 100 users. At a large site, there will be a hierarchy of administration, with the lead or senior System Administrator responsible for all of the systems and assigning duties to one or more assistant administrators.

System Administration Skills:
System administration skills can be classified in four general levels. The links below discuss the required skills, desired skills, and responsibilities of each of those levels. Following the levels are some general thoughts on system administration in general.

Novice Junior Intermediate/advanced Senior Some thoughts on System Administration.
Novice System Administrator:
Required skills:
Has strong inter-personal and communication skills: is capable of explaining simple procedures in writing or verbally; has good phone skills.
Is familiar with Unix and its commands/utilities at the user level. Can edit files using more than one editor. Uses at least two shells one of them being the Bourne shell.
Can perform standard file processing tasks; find, move, remove, redirection.


Required background:
Two years of college or equivalent post-high school education or experience.


Desirable:
A degree or certificat in computer science or related field.
Previous experience in customer support, computer operations, system administration, or another related area.
Motivated to advance in the profession.

Appropriate responsibilities:
Perform routine tasks under the direct supervision of a more experienced administrator.
Be the front-line interface for users; accepting problem reports and passing them to the appropriate system administrators.
Performs some security functions, especially monitoring the system

Junior System Administrator:
Required skills:
Has strong inter-personal and communication skills: capable of training users in applications and Unix fundamentals. Able to write basic system and user documentation.
High skill level with most Unix commands and utilities.
Familiar with most basic system administration tools and tasks. For example, can cleanly boot and shutdown the system, add and remove user accounts, use backup programs, perform fsck and maintain system database files (groups, hosts, aliases, etc.)
Fundamental understanding of the functioning of the Unix operating system: for example understands job control, hard and soft linking, the difference between shell programs and kernel programs.
Basic understanding of Unix security procedures


Required background:
One to three years of system administration experience.


Desirable:
Degree in CS or a related field.
Familiarity with networked/ distributed computing environments. For example: can use the route command, add a workstation to a network, or mount a remote filesystem.
Ability to write functional scripts in an administrative language (shell, Perl, Tk).
Some programming experience in an applicable language like C.


Appropriate Responsibilities:
Administer a small site alone, or assist in the administration of a larger site.
Work under the general supervision of a more senior system administrator or computer systems manager.
Perform normal security procedures, able to advise users on standard security protocol.
Intermediate/Advanced System Administrator
Required Skills
Has strong inter-personal and communication skills: capable of training users in complex topics, making presentations to internal groups. Able to write intricate system and user documentation. Capable of writing and explaining purchase justifications.
Independent problem solving; self-directed, self-starting.
Very comfortable with most aspects of the Unix operating system: paging/swapping, inter-process communication, devices and device driver fundamentals, file system concepts like inode and superblock.
Familiar with fundamental networking/distributed computing environments and concepts. Can configure NFS and NIS, use nslookup or research to check information in the DNS.
Ability to write detailed scripts in at least one, preferably two administrative lnaguages, (shell scripts, Perl, Tk).
Ability to perform at least minimal debugging and modification of C programs.
Ability to perform most security audits, and protect the system against intrusion.


Required Background:
Three to five years of system administration experience.


Desirable:
At least a BS in Computer Science or a related field.
Significant programming background in any applicable language.


Appropriate Responsibilities:
Receive general instructions for new duties from supervisor.
Administers a mid-size site alone, or assists in administration of a larger site.
Initiates some new responsibilities and helps plan for the future of the site and network.
Manages novice system administrators or operators.
Evaluates and/or recommends purchases; has strong influence on the purchasing process.
Serves as the first line of defense against intrusion and inadvertent system damage.
Senior System Administrator:
Required Skills
Strong inter-personal and communication skills; capable of writing proposals and papers, acting as a vendor liaison, making presentations to customer/client audiences or making professional presentations, work closely with upper management.
Ability to solve problems quickly and completely.
Ability to identify tasks which should be automated and then write tools to automate them.
Solid understanding of the Unix based operations system: understands paging and swapping, interprocess communication, devices and device drivers, can perform system analysis and tuning.
Ability to program in at least one, preferably two administrative languages, (shell, Perl, Tk) and port C programs from one platform to another, write small C programs.
Solid understanding of networking/distributed computing environments, understanding the principals of routing, client/server programming, and the design of consistent network-wide filesystems.


Required Background:
More than 5 years of previous system administration experience.


Desirable:
A degree in CS or a related field. Advanced degree preferred.
Extensive programming experience in an applicable language.
Publications within the field of system administration.


Appropriate Responsibilities:
Design/implement complex local and wide-area networks of machines.
Manages a large site or network.
Works under general direction of senior management.
Establishes/recommends policies and procedures for system use and services.
Provides the technical lead and/or supervision for system administrators, system programmers, or others.
Has purchasing authority and responsibility for purchase justification.

Finally, some important thoughts for system Administrators:
Never do something you can't undo.
Always check the backups, never assume they are working. Make sure you can restore from them, too.
Write down what you did, even if you know you will never forget it, you will.
If you do it more than once, write a script.
Get to know your users before there is a problem, then when there is, they will know who you are and maybe have a little understanding.
Remember you are performing a service for your users, you don't own the system, you just get to play with it.
Check your backups.
Never stop learning, there is always something you should know to make your job easier and your system more stable and secure.
Check your backups, again.

Friday, April 30, 2010

RHCE OpenLDAP Server / Client Setup (30/04/2010)

OpenLDAP Server

compat-openldap.i386 0:2.1.30-6.4E
openldap-clients.i386 0:2.2.13-6.4E
openldap-devel.i386 0:2.2.13-6.4E
openldap-servers.i386 0:2.2.13-6.4E
openldap-servers-sql.i386 0:2.2.13-6.4E
ou can install them using the command:
yum install *openldap* -y

-----------------------------------------------------------
vi /etc/openldap/sldap.conf

openssl passwd

add in /etc/openldap/sldap.conf

suffix "dc=example,dc=com"
rootdn "cn=Manager,dc=example,dc=com"
rootpw {crypt}BreLcru48OqmA
-------------------------------------------------------------------------
service ldap restart
tail -f /var/log/messages


useradd -d /home/users/system1-user01 system1-user01
useradd -d /home/users/system2-user02 system2-user02
useradd -d /home/users/system3-user03 system3-user03
useradd -d /home/users/system4-user04 system4-user04
useradd -d /home/users/system5-user05 system5-user05
useradd -d /home/users/system6-user06 system6-user06
useradd -d /home/users/system7-user07 system7-user07
useradd -d /home/users/system8-user08 system8-user08
useradd -d /home/users/system9-user09 system9-user09
useradd -d /home/users/system10-user10 system10-user10

passwd system1-user01

passwd system2-user02

passwd system3-user03

passwd system4-user04

passwd system5-user05

passwd system6-user06

passwd system7-user07

passwd system8-user08

passwd system9-user09

passwd system10-user10

groupadd -g 10000 system01

groupadd -g 10001 system02

usermod -G 10000 system1-user01

usermod -G 10000 system2-user02

usermod -G 10001 system3-user03

--------------------------------------------------------------------------------------

vi /etc/exports

/home/users 192.168.0.0/255.255.255.0(rw,sync)

----------------------------------------------------------------------------------

vi /etc/openldap/init.ldif

dn: dc=example,dc=com

objectClass: dcObject

objectClass: organization

o: example

dc: example

dn: cn=Manager,dc=example,dc=com

objectClass: organizationalRole

cn: Manager

dn: ou=Account,dc=example,dc=com

objectClass: organizationalUnit

ou: Account

dn: ou=Group,dc=example,dc=com

objectClass: organizationalUnit

ou: Group

#ldapadd -x -D "cn=Manager,dc=example,dc=com" -W -f init.ldif

#ldapsearch -x -LLL -b "dc=example, dc=com" "(objectClass=*)"

----------------------------------------------------------------------------------------

vi /etc/openldap/group.ldif

dn: cn=system01,ou=Group,dc=example,dc=com

objectClass: posixGroup

objectClass: top

cn: system01

gidNumber: 10000

dn: cn=system02,ou=Group,dc=example,dc=com

objectClass: posixGroup

objectClass: top

cn: system02

gidNumber: 10001

ldapadd -x -D "cn=Manager, dc=example, dc=com" -W -f group.ldif

before create user.ldif

su - system1-user01

id <-- check user id

openssl passwd

copy and paste on

---------------------------------------------------------------

vi /etc/openldap/user.ldif

dn: uid=system1-user01,ou=Account,dc=example,dc=com

uid: system1-user01

cn: test user 01

objectClass: account

objectClass: posixAccount

objectClass: top

userPassword: {crypt}FLVvKA5gz4RUk

loginShell: /bin/bash

uidNumber: 511

gidNumber: 10000

homeDirectory: /home/users/system1-user01


dn: uid=system2-user02,ou=Account,dc=example,dc=com

uid: system2-user02

cn: test user 02

objectClass: account

objectClass: posixAccount

objectClass: top

userPassword: {crypt}9oB/59btUGpGM

loginShell: /bin/bash

uidNumber: 512

gidNumber: 10000

homeDirectory: /home/users/system2-user02

dn: uid=system3-user03,ou=Account,dc=example,dc=com

uid: system3-user03

cn: test user 03

objectClass: account

objectClass: posixAccount

objectClass: top

userPassword: {crypt}xopW7X41D.w/6

loginShell: /bin/bash

uidNumber: 513

gidNumber: 10001

homeDirectory: /home/users/system3-user03

ldapadd -x -D "cn=Manager, dc=example, dc=com" -W -f user.ldif

---------------------------------------------------------------------

export home directory on server1.example.com

/home/users 192.168.0.0/255.255.255.0(rw,sync)

--------------------------------------------------------------------

### LDAP Clients ###

authconfig-tui

- Use LDAP

- Use LDAP Authentication

ldap://server1.example.com

dc=example,dc=com

---------------------------------------------------------------------

vi /etc/auto.master

/home/users /etc/auto.users --timeout=60

vi /etc/auto.users

* -fstype=nfs,rw,soft,intr server1.example.com:/home/users/&


Thursday, April 29, 2010

Linux DNS Server - RHCE Notes (29/04/2010)

Linux Bind DNS Name Server Configuration

#rpm –qi bind / bind-chroot / caching-nameserver
#yum grouplist check group name
#yum groupinstall "DNS Name Server"
# that will install bind / bind-chroot
----------------------------------------------------------------------------------------------------------
Selinux for named
# setsebool -P named_write_master_zones 1
----------------------------------------------------------------------------------------------------------
Install Caching only Name Server
#yum -y install caching-nameserver
# cd /var/named/chroot/etc
#cp named.caching-nameserver.conf named.conf
#chgrp -R named named.conf
#vi named.conf
Change
listen-on port 53 { 127.0.0.1; 192.168.0.254; };
allow-query { 192.168.0.0/24; };
# vi /etc/resolv.conf
nameserver 127.0.0.1
Creating RNDC (Remote Name Daemon Control)
/etc/rndc.key
#rhdc-confgen
#rndc-confgen -a -b 512

Bind Commands to troubleshoot name resolution

#service named restart/reload/stop/start
#rndc start/stop/reload/status
#host –l example.com
#dig www.redhat.com

Domain example.com configuration

# vi /var/named/chroot/etc/named.conf

# chgrp -R named named.conf ßchange group to named for named.conf

# ln -s /var/named/chroot/etc/named.conf /etc/named.conf

------------------------------------------------------------------------------------------

named.conf (SAMPLE)

options {

listen-on port 53 { 127.0.0.1; 192.168.0.254; };

directory "/var/named";

dump-file "/var/named/data/cache_dump.db";

statistics-file "/var/named/data/named_stats.txt";

memstatistics-file "/var/named/data/named_mem_stats.txt";

allow-query { 192.168.0.0/24; };

forward only;

forwarders {

172.16.1.73;

};

};

zone "." IN {

type hint;

file "named.ca";

};

zone "example.com" IN {

type master;

file "example.com.zone";

allow-update { none; };

};

zone "0.168.192.in-addr.arpa" IN {

type master;

file "192.168.0.zone";

allow-update { none; };

};

include "/etc/rndc.key";

------------------------------------------------------------------------------------------------------------

vi /var/named/chroot/var/named/example.com.zone

chgrp -R named example.com.zone

------------------------------------------------------------------------------------------------------------

example.com.zone (SAMPLE)

$TTL 86400

example.com. IN SOA server1.example.com. root.server1.example.com. (

2010042900 ; serial number

1H ; refresh slave

5M ; retry query

1W ; expire

1M ; negative TTL

)

@ IN NS server1.example.com.

@ IN MX 10 server1.example.com.

example.com. IN A 192.168.0.254

mail.example.com. 3600 IN CNAME server1.example.com.

kerberos.example.com. 3600 IN CNAME server1.example.com.

station1.example.com. IN A 192.168.0.1

station2 IN A 192.168.0.2

station3 IN A 192.168.0.3

station4 IN A 192.168.0.4

station5 IN A 192.168.0.5

station6 IN A 192.168.0.6

station7 IN A 192.168.0.7

station8 IN A 192.168.0.8

station9 IN A 192.168.0.9

station10 IN A 192.168.0.10

www10 IN CNAME station10.example.com.

ssl IN CNAME station10.example.com.

gateway IN A 192.168.0.100

server1 IN A 192.168.0.254

------------------------------------------------------------------------------------------------------------

vi /var/named/chroot/var/named/192.168.0.zone

chgrp –R named 192.168.0.zone

----------------------------------------------------------------------------------------------------------

192.168.0.zone (SAMPLE)

$TTL 86400

0.168.192.IN-ADDR.ARPA. IN SOA server1.example.com. root.server1.example.com.(

2010042900 ; serial number

1H ; refresh slave

5M ; retry query

1W ; expire

1M ; negative TTL

)

@ IN NS server1.example.com.

1.0.168.192.IN-ADDR.ARPA. IN PTR station1.example.com.

2 IN PTR station2.example.com.

3 IN PTR station3.example.com.

4 IN PTR station4.example.com.

5 IN PTR station5.example.com.

6 IN PTR station6.example.com.

7 IN PTR station7.example.com.

8 IN PTR station8.example.com.

9 IN PTR station9.example.com.

10 IN PTR station10.example.com.

---------------------------------------------------------------------------------------------------------

Bind Slave zone Configuration on stationx (SAMPLE)

# vi /var/named/chroot/etc/named.conf

# chgrp -R named named.conf ßchange group to named for named.conf

# ln -s /var/named/chroot/etc/named.conf /etc/named.conf

------------------------------------------------------------------------------------------------------------

options {

listen-on port 53 { 127.0.0.1; 192.168.0.10; };

directory "/var/named";

dump-file "/var/named/data/cache_dump.db";

statistics-file "/var/named/data/named_stats.txt";

memstatistics-file "/var/named/data/named_mem_stats.txt";

allow-query { 192.168.0.0/24; };

};

zone "example.com" IN {

type slave;

file "slaves/example.com.zone";

masters {

192.168.0.254;

};

};

zone "0.168.192.in-addr.arpa" IN {

type slave;

file "slaves/192.168.0.zone";

masters {

192.168.0.254;

};

};

------------------------------------------------------------------------------------------------------------

# service named restart

After restart the server, example.com.zone / 192.168.0.zone files automatically create in

/var/named/chroot/var/named/example.com.zone (forward lookup)

/var/named/chroot/var/named/192.168.0.zone (reversed lookup)

# dig server1.example.com (forward lookup test)

# dig -x 192.168.0.254 (reversed lookup test)



RHCT / RHCE Notes- Apache / Squid (29/04/2010)

Apache configuration

Question:
- implement a web server for the site http://stationX.example.com, then perform the following steps:
- Download ftp://server1.example.com/pub/rhce/station.html
- Rename the download file to index.html
- Copy this index.html to the DocumentRoot of your web server
- Do Not make any modifications to the content of index.html
- Extend your webserver to include a virtual host for the site http://wwwx.example.com/, where x is your station number, then perform the following steps:
- Set the DocumentRoot to /var/www/virtual
- Download ftp://server1.example.com/pub/rhce/www.html
- Rename the download file to index.html
- Copy this index.html in the DocumentRoot of the virtual host
- Do Not make any modifications to the content of index.html
- Ensure that user1 is able to create content in /var/www/virtual
Note: The original web site http://stationx.example.com must still be accessible. DNS resolution for the hostname wwwx.example.com is already provided by the name server on server1.example.com.

Answer:

#netstat –ntlp / netstat –nulp
#check port 80 / 443 listening
# rpm -qi httpd
# yum grouplist | less
# yum groupinstall "Web Server"
# yum install mod_ssl ---- for port 443
# vi /etc/httpd/conf/httpd.conf - Main Webserver config
# vi /etc/httpd/conf.d/ssl.conf - SSL webpage
------------------------------------------------------------------------------------------------------
### Default website config ### (stationx.example.com) x = your station number
ftp://server1.example.com/pub/rhce/station.html
mv station.html /var/www/html/index.html
-------------------------------------------------------------------------------------------------------
#### VirtualHost #### (wwwx.example.com) x= your station number
mkdir /var/www/virtual
ftp://server1.example.com/pub/rhce/www.html
mv www.html /var/www/virtual/index.html
--------------------------------------------------------------------------------------------------------

## Create VirtualHost ##

/NameVirtual ß search in vi

NameVirtualHost 192.168.0.10:80

ServerName station10.example.com

ServerAlias station10

DocumentRoot /var/www/html

ServerName www10.example.com

ServerAlias www10

DocumentRoot /var/www/virtual

ErrorLog logs/www10.example.com-error_log

CustomLog logs/www10.example.com-access_log common

-----------------------------------------------------------------------------------------------------------

### HTTPS VirtualHost port 443 ### https://ssl.example.com

vi /etc/httpd/conf.d/ssl.conf

NameVirtualHost 192.168.0.10:443

ServerName ssl.example.com

ServerAlias ssl

DocumentRoot /var/www/virtual-ssl

----------------------------------------------------------------------------------------

SELinux Permission

chcon -R --reference=/var/www/html /var/www/virtual

OR

chcon -R –u system_u /var/www/virtual

chcon -R -t httpd_sys_content_t /var/www/virtual

---------------------------------------------------------------------------------------------------------

Basic text password Auth for Apache

vi /etc/httpd/conf/httpd.conf

/Directory çsearch in vi

###Default configuration for Apache###

Options Indexes FollowSymLinks

AllowOverride None

Order allow,deny

Allow from all

>

###Create one for Basic text Auth###

Alias /virtual "/var/www/virtual/"

AuthType Basic

AuthName "Text Based Auth"

AuthUserFile /etc/httpd/passwords

Require user user1

>

----------------------------------------------------------------------------------------------------------

###Create user name and password file###

htpasswd -c /etc/httpd/passwords user1

###Next Time don need to add –c ###

htpasswd /etc/httpd/passwords user2

httpd -S (Virtualhost setting check)

httpd –t (Syntax Check) OR service httpd configtest

Question:

- Implement a web proxy server bound to port 8080

- Clients within example.com should have access to your proxy server

- Clients outside of example.com should NOT have access to your proxy server.

Answer:

RHCE squid proxy server configuration

#rpm –qi squid – check squid already install or not

#squid –v – check squid version

#if squid not installed

#yum –y install squid

#cp /etc/squid/squid.conf /tmp

vi /etc/squid/squid.conf

1. http_port 3128 à change to http_port 8080

2. acl our_networks src 192.168.0.0/24

3. http_access allow our_networks

4. visible_hostname stationx.example.com (x = your station name)

5. squid -z

6. service squid start

7. chkconfig squid on

8. chkconfig --list squid

Test on client side !!!

vi /etc/profile.d/proxy.sh

export http_proxy=http://192.168.0.10:8080/

export https_ proxy=http://192.168.0.10:8080/

export ftp_proxy=http://192.168.0.10:8080/

export no_proxy=.example.com