lunes, 30 de enero de 2012

Openldap script backend

Openldap allows you to customize the backend in several ways. The most usefull in order to prepare a prototype is shellbackend.
With this backend you can create a custom shellscript or executable and use it to return a ldap response.


References

Introduction to the slapd backend

Reference guide for slapd configuration

Configuration

############  LDAP SCRIPT  ##################################
database shell
suffix          "o=shell,dc=sia,dc=es"
search          /opt/soft/openldap/libexec/searchSamle.sh
#######################################################################

code

#! /bin/bash
output() {
printf '%s\n' "$*"

}
echo $?>"/opt/soft/openldap/var/log/log.data"
while true
do
read data
if [ $? -eq 0 ]
then
echo $data>>"/opt/soft/openldap/var/log/log.data"
else
break
fi
done
output "dn: cn=Boris Norris,o=shell,dc=sia,dc=es"
output "cn: Boris Norris"
output ""
output "RESULT"
output "code: 0"
exit 0

martes, 20 de diciembre de 2011

Using sqlite from the command line

Show and format the sql expression:
sqlite3 -separator ' ' test.db "select * from users where username='admin'" |awk {'print "username: " $1 "\npassword: " $2 '}

Insert data:
sqlite3 test.db "insert into users values ('user2','user2','test2')"
echo $?

if exit status equals zero means that everything run smoothly

martes, 22 de noviembre de 2011

using shell scripting with mysql
echo "select * from users" |mysql  myride --skip-column-names|awk {'print $1'}

Creating a HashBang wrapper

Some time ago I needed an executable that was able to call SQL sentences with mysql or sqlite. I did a little research to understand how Shebang works, I found out that was very easy to write your custom wrappers

wrapper :: /bin/bmysql
#!/bin/bash
export database=$1
#echo "Database:: $1| SQL: $2"
#echo $1 holds the file where sql data is stored

export sql_data=`cat $2|grep -v \"#!\"`
#echo "DEBUG:: $sql_data "
echo $sql_data|mysql $1
echo $?

and the script file /home/test/demo.sql

#!/bin/bmysql drupal
show databases;
Have fun with your own wrappers!!!

lunes, 4 de julio de 2011

Creating Jail for users

First: directory structure

You have to build your own custom jailed filesystem. Mine was on /var/cage:
./
.script.rc  bin  config  lib64  spool

./bin:
.lsd  bash  cat  init.rc  ls  sqlite3 echo 

./config:
current

./lib64:
ld-linux-x86-64.so.2  libc.so.6        libpthread.so.0   libselinux.so.1
libacl.so.1           libdl.so.2       libreadline.so.5  libsqlite3.so.0
libattr.so.1          libncurses.so.5  librt.so.1

./spool:
commands

Second. Creating a custom console.

This script will force that instead of creating a custom shell, the user will be jailed after login:

cp /usr/bin/chroot /usr/bin/rooted
chmod u+s /usr/bin/rooted

User is created on /home/jailed:
.profile must conatain the following line:
exec /usr/bin/rooted /var/cage /bin/init.rc


Adendum. /bin/init.rc

/bin/bash --init-file /.script.rc

Using sudo without password

Hi all!!!
Do you ever wanted to grant "root" priviledges to a user without having to type the root password?
I needed to have a user capable of performing "admin" tasks at same level as "root". In order to get things done,  I created a user called admin, member of group "users" with password locked (passwd -l admin). This step is important, because it means that no one except root will be able to access the account.
To grant "admin" unlimited access without password, i had to type sudo and include at the end the following line:

admin ALL=(ALL) NOPASSWD: ALL


Have a nice day!!! : )

viernes, 6 de agosto de 2010

Forcing Apache 2.2 to use browser enconding

Hi !!! It's been so long since the last update, but it's been very difficult to find some time during these 2 months.
Anyway here we go again, Apache by default comes configured with the most popular charset encoding : UTF-8.
This setup can cause some problems when you are not born in the countries where the languaje of Shakespeare is used. If you find yourshelf asking why accents, and european signs are being transformed in question marks, then it's time to comment this setting on httpd.conf:
#AddDefaultCharset UTF-8

and add your setting :

AddDefaultCharset ISO-8859-1

Cheers , and happy holidays!!!

jueves, 24 de junio de 2010

martes, 15 de junio de 2010

Stunnel with Linux

This command will create a TCP SSL Proxy from the port 25443 to 2080

stunnel -p /etc/stunnel/stunnel.pem -D 7 -o /var/log/stunnel4/stunnel.log -A /ca/cacert.pem -d 25443 -f -r 2080

To test the server we can issue the following command

openssl s_client -connect 192.168.56.126:25443

Cheerssss


Del.icio.us

jueves, 27 de mayo de 2010

Create a Loopback filesystem from a file. Linux

If you need to have a new filesystem to test some operations on the server or you want a more flexible way of performing snapshots other than volume management, you can use loopback filesystems.

First Step. Create the Loopback file
dd if=/dev/zero of=/apps/test/loop db=1024 count=30720
This will create a 30 Mb file.

Second Step. Create a Loopback device.
First of all we will type
losetup -a
to list the current used devices.
losetup /dev/loop0 /apps/test/loop

Third Step. Create and mount a device.
mkfs -t ext3 -m 1 -v /dev/loop0
mkdir /virt_drive
mount /dev/loop0 /virt_drive



miércoles, 26 de mayo de 2010

Using NTP for time sync

What is NTP?
It's a time sync protocol that allows IT infrastructures to be one in time.
Why i need it?
When time sync it's a critical factor for the services to work. One clear example is Kerberos and Active Directory. SSO Web infrastructures like Oracle Access Manager require exact time sync in all components, all over the servers.
How does it work?
There are two actors in every ntp scenario:
- Client: is the final consumer of the service, which adecuates it's internal clock to the time set on the server
- Server: It's the reference for the time corrections and synchronization. But also it can act as a client for other servers which are authoritative sources for time sync, like NASA atomic time servers, etc

First of all: Let's configure it.
Configuration is quite simple:
- Server side:
+ Authoritative source: the server will be the main NTP server. No other servers will be requested for time sync.
+ Slave model : server will act as server for the client infrastructure, but also will contact
other time servers in order to have a more accurate referal.

Files for a basic configuration on a Linux NTP server:
+ ntp.conf:
# Undisciplined Local Clock. This is a fake driver intended for backup
# and when no outside source of synchronized time is available.
server 127.127.1.0
# local clock
#fudge
127.127.1.0 stratum 10

# Drift file. Put this in a directory which the daemon can write to.
# No symbolic links allowed, either, since the daemon updates the file
# by creating a temporary in the same directory and then rename()'ing
# it to the file.
driftfile /var/lib/ntp/drift

After that we will start the daemon server.

On a Windows 2003 Server with AD acting as NTP server:
Please check the following registry key setting:
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/W32Time/
TimeProviders/NTPserver/Enabled=1


Next step with Linux

To test the service we will use
ntpdate -d 132.236.56.250
After that we will need to perform an initial sync , with the command:  
ntpdate 192.168.56.101
Once we have both machines synchronized we will start a new task on cron with the command
crontab -e
* * * * * /usr/sbin/ntpdate -s -b -p 8 -u 192.168.56.101


Next step with Windows
Please follow this procedure
Some final words.
This tip is an entry point for NTP configuration, if you need further info, please consider reading other
resources like the following ones:
- http://www.akadia.com/services/ntp_synchronize.html
- http://tldp.org/LDP/sag/html/index.html
- http://www.meinberg.de/english/sw/ntp.htm


viernes, 30 de abril de 2010

A script for counting

This is very easy but, just in case:
for aa in `seq 1 10`; do echo $aa; done

Generic script for managing a Unix service

Create a file with the following contents:


#!/bin/bash
export user_name="root"

export srv_name="serv"
export exec_dir_stop="/home/$user_name/bin/stop_serv.sh"
export exec_dir_start="/home/$user_name/bin/start_serv.sh"


case "$1" in
start)
echo -n "Starting $srv_name Service Daemon"

/usr/bin/sudo -u $user_name $exec_dir_start
;;
stop)
echo -n "Shutting $srv_name Service Daemon"
/usr/bin/sudo -u $user_name $exec_dir_stop
;;
restart)
$0 stop
$0 start
;;
*)
echo "Usage: $0 {start|stop|restart}"
exit 1
;;
esac


Save it with a descriptive name on /etc/init.d (or /etc/rc.d) , for instance http_filter . Change the access rights to the user in charge of managing the service, and create a softlink on the run level you want the service to be started.