วันพุธ, พฤษภาคม 21, 2551
ว่าด้วยเรื่องของ Mac OS X Leopard Firewall
ทีนี้ถ้าสมมุติเราอยากจะเปิดพอร์ท 8080 จะทำไง? สั้นๆ มีสองโซลูชั่น
ถ้ากี๊กหน่อยก็ใช้ command line config ด้วยคำสั่ง ipfw. (cf. man ipfw)
ถ้าไม่กี๊กพอก็ใช้ WaterRoof ( http://www.hanynet.com/waterroof ) เป็น free/opensource ซะด้วย น่าสนใจดี
วันศุกร์, สิงหาคม 24, 2550
Granting privileges to Java RTS Users on Solaris 10
Note that you (may) need to logout and login again for the new priviledges to take effect. The preferred approach might be to create a new administrative role, `rtsj_role', then assign `Java Real-Time System User' right to `rtsj_role', and make the user who want to use Java RTS assumes the rtsj_role.
The following procedures are quoted from /opt/SUNWrtjv/doc/JavaRTSInstallation.html#privileges
Granting Privileges to Java RTS Users
The Java Real-Time System uses a number of Solaris resources, such as the real-time scheduling class, whose usage is restricted to privileged processes. Therefore, the Java RTS Virtual Machine must be run as the superuser (root) or must be explicitly granted additional rights by the system administrator in order to ensure predictable timing of operations.
Solaris supports role-based access control (RBAC), which enforces security policy at a more fine-grained level than the conventional superuser security model. This enables a user to be assigned the precise level of privilege that is necessary to execute the Java RTS.
This is typically achieved by means of a specific rights profile, that is, a collection of commands with security attributes. Rights profiles are usually included in an administrative role, and the role is then assigned to a user. Direct assignment of rights profiles to a user is also possible. In that latter case, this user must use a profile shell such as pfsh(1) or pfcsh(1) for the commands with security attributes to succeed.
Rights profiles can be managed using the Solaris Management Console, smc(1), a graphical user interface that provides access to Solaris system administration tools.
To invoke the Solaris Management Console, type the following command:
# /usr/sbin/smc
The 'Java Real-Time System User' rights profile can also be assigned to an administrative role using the following command:
# /usr/sbin/rolemod -P "Java Real-Time System User"
where
This rights profile can also be directly assigned to a Solaris user by using:
# /usr/sbin/usermod -P "Java Real-Time System User"
where
Alternatively, you can decide not to use the Java RTS profile and assign additional rights directly to the Java RTS users. In that later case, be aware that all the processes created by such Java RTS users (that is, not only the Java RTS Virtual Machine) will be granted these additional rights.
Rights management is implemented on Solaris through privileges, that is, discrete rights required to perform particular operations. Privileges decrease the security risk that is associated with one user or one process having full superuser capabilities on a system.
If you decide to bypass the Java RTS rights profile, then the Java RTS users must be granted at least the following privileges, for them to be able to run properly the Java RTS Virtual Machine:
- sys_res_config: allows a process to create and delete processor sets, assign CPUs to processor sets, and change the operational status of CPUs in the system.
- proc_priocntl: allows a process to elevate its priority above its current level and change its scheduling class to any scheduling class, including the RT class.
- proc_lock_memory: allows a process to lock pages in physical memory.
- proc_clock_highres: allows a process to use high resolution timers.
To assign the above set of privileges directly to a Java RTS user, use the Solaris Management Console, smc(1), or type the following command:
# /usr/sbin/usermod -K \
defaultpriv=basic,sys_res_config,proc_priocntl,proc_lock_memory,proc_clock_highres
where
Note that the usermod(1M) command does not allow privileges to be assigned to non-local users (that is, to users who do not appear in the local /etc/passwd file). To assign privileges to a non-local user, add the following line to the /etc/user_attr file:
::::type=normal;profiles=Basic Solaris User;defaultpriv=basic,
sys_res_config,proc_priocntl,proc_lock_memory,proc_clock_highres
where
วันพฤหัสบดี, สิงหาคม 16, 2550
การย้ายรูปที่เก็บด้วย Picasa ไปยังคอมเครื่องใหม่, migrating picasa photo library to a new computer
อย่างไรก็ดี อัลบั้มที่เราสร้างไว้ใน Picasa มันไม่ได้เก็บเป็นโฟลเดอร์ต่างหาก แต่เก็บเป็น XML แต่ใช้นามสกุล .pal (Picasa ALbum) อยู่ที่ $USER\Local Settings\Application Data\Google\Picasa2Albums
ซึ่งในไดเรคทอรี่นี้ จะมี
- watchedfolders.txt เป็นเท็กส์ไฟล์ ที่เก็บว่า Picasa มัน watch ไดเรคทอรี่ไหนอยู่ และ
- ซับไดเรคทอรี่ที่มีชื่อเป็น HEX ยาวๆ ex. b8ce842...2d2 ซึ่งในไดเรคทอรี่นี้จะมีไฟล์ .pal ที่เก็บ Picasa Album อยู่
ให้เราก๊อปไฟล์นั้นไปไว้แล้วเปิด Picasa ขึ้นมาใหม่ก็น่าจะเรียบร้อย
ถ้าเปลี่ยนโลเคชั่นของโฟโต้ไลบรารี่ก็แก้ไขไฟล์ .pal ให้เป็นที่ใหม่ซะด้วย เช่นใน
[D]\Photos\20000229\PIC001.JPG
[D] คือ drive D: [E] ก็คือ drive E:
+ เพิ่มเติม +
หากเราเคยอัพอัลบั้มนั้นขึ้นใน Picasa Web โดยใช้,2 มันจะมีเอ็นทรี่ คล้ายๆอย่างงี้ >_lh" type="num64" value="0"/> >_lh" type="num64" value="0"/>
<< >> เป็น place holder
ในไฟล์ .pal ทำให้ก๊อปไปแล้วกลับไม่ปรากฎอัลบั้มนั้นขึ้นใน Picasa
การแก้ไขก็ทำได้โดยลบสองบรรทัดนั้นออกไป ลบแล้วพอก๊อปไปก็จะได้ดังเดิม
ติดตั้ง Webmin ใน Solaris 10 เพื่อความสะดวกในการคอนฟิก Samba
สรุปก็คือใช้ Webmin ง่ายดี ใช้แอ๊ดมินได้หลายๆอย่างด้วย
บันทึกการติดตั้ง
ref: http://www.webmin.com/solaris.html
- ดาวน์โหลดแพคเกจของ Solaris มาซะ
- #
pkgadd -d webmin-1.360.pkg - แล้วก็คอนฟิกอีกเล็กน้อย โดยเพิ่ม user หรือ sync มันมาจาก unix account ซะ
- แล้วก็เพิ่มไดเรคทอรี่ที่จะแชร์ลงไป
- คอนฟิก อื่นๆ ตามสมควร อาจดูที่ smb.conf เพื่อความชัวร์
- คลิก รีสตาร์ท Samba server
วันพฤหัสบดี, กรกฎาคม 12, 2550
Solaris 10 : Changing password policy, root login policy
The file specify password complexity and so on.
see /etc/default/login
When CONSOLE is set root can only login on the specified device.
Comment to unset the CONSOLE to allow remote root login.
เครื่องเซิฟเวอร์ Sunfire 880 กับ StorEdge A1000
ก็เลยได้โอกาสที่จะใช้ประโยชน์ให้เต็มที่
เริ่มจากการสร้างไฟล์ซิสเต็มซะก่อน บันทึกเล็กๆน้อย เปิดดูจาก Solaris Administration document ในเว๊บของ Sun น่ะแหละ
ใช้คำสั่ง format
และใน format ให้เลือก partition
แล้วเลือก modify
ใช้ All free hogs
แล้วก็ accept table ไปก่อน กำหนดพื้นที่ตามความเหมาะสม
แล้ว label เพื่อwrite change ลงไป
แล้วก็ newfs /dev/..../c4t0d0
แล้วก็ลอง mount ดู
ถ้าโอเคก็แก้ /ets/vfstab เพื่อให้มัน mount โดยอัตโตมัติ
วันศุกร์, เมษายน 13, 2550
ว่าด้วยเรื่อง Samba บน OpenSolaris or Solaris 10
สรุปสั้นๆ ดังนี้
- Solaris 10 and opensolaris already include Samba. No need to get it from sunfreeware.
- The init process has been changed from Solaris 9 and previous versions. Sun introduced SMF (Service Management Facility) which is believed that, once mastered, it'll be better than the old one. I havn't mastered that so I can't tell anything about it.
- Samba's binaries are in /usr/sfw/bin
- Samba's config is in /etc/sfw/smb.conf
- What you need is create smbpasswd for user(s) and edit smb.conf for your needs.
- Use inetconv -i /etc/inet/inetd.conf to convert the inetd configuation to SMF service manifest, and import them to smf repository
- svcs -vx can be used to check the status of a service
- svcconfig import
.xml : to import a manifest for a service - svcadm enable
: to enable a service
- You can view installed files of a package by : less /var/sadm/pkg/SMCsamba/.......