November 26, 2013

Managing Partions With RHEL 6

Introduction

Most Linux distrobution, which is also the case with RHEL 6, uses the MBR (Master Boot Record) partitioning format. The MBR is designed to hold up to maximum 4 primary partition. If more is needed, you must use one primary as extended partition. And do not forget to let the extended partition use all remaining disk space. After creating an extended partition, you can create logical partition on the extended partiti

Graphical Tool

In a desktop RHEL, there is the graphical tool for managing our partition - palimpsest.

$ yum install gnome-disk-utility

A never GUI tool that is maybe better is parted. The good thing with this tool is that it also can resize and copy partitions.

$ yum install parted

Command Line

At the command line, you have the fdisk tool. When using the fdisk tool always use the following options:

  • -c Switch off DOS-compatible mode.
  • -u When listing partition tables, give sizes in sectors instead of cylinders.

Lets get started with fdisk and create a new primary partition.

$ fdisk -cu /dev/sda

Command (m for help): m
Command action
   a   toggle a bootable flag
   b   edit bsd disklabel
   c   toggle the dos compatibility flag
   d   delete a partition
   l   list known partition types
   m   print this menu
   n   add a new partition
   o   create a new empty DOS partition table
   p   print the partition table
   q   quit without saving changes
   s   create a new empty Sun disklabel
   t   change a partition's system id
   u   change display/entry units
   v   verify the partition table
   w   write table to disk and exit
   x   extra functionality (experts only)

Command (m for help): p

Disk /dev/sda: 250.1 GB, 250059350016 bytes
255 heads, 63 sectors/track, 30401 cylinders, total 488397168 sectors
Units = sectors of 1 * 512 = 512 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disk identifier: 0x7f3d8c0f

   Device Boot      Start         End      Blocks   Id  System
/dev/sda1   *        2048     1026047      512000   83  Linux
/dev/sda2         1026048   205826047   102400000   8e  Linux LVM

Command (m for help): n
Command action
   e   extended
   p   primary partition (1-4)
p
Partition number (1-4): 3
First sector (205826048-488397167, default 205826048): 
Using default value 205826048
Last sector, +sectors or +size{K,M,G} (205826048-488397167, default 488397167): +500M

Command (m for help): p

Disk /dev/sda: 250.1 GB, 250059350016 bytes
255 heads, 63 sectors/track, 30401 cylinders, total 488397168 sectors
Units = sectors of 1 * 512 = 512 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disk identifier: 0x7f3d8c0f

   Device Boot      Start         End      Blocks   Id  System
/dev/sda1   *        2048     1026047      512000   83  Linux
/dev/sda2         1026048   205826047   102400000   8e  Linux LVM
/dev/sda3       205826048   206850047      512000   83  Linux

Command (m for help): w
The partition table has been altered!

Calling ioctl() to re-read partition table.

WARNING: Re-reading the partition table failed with error 16: Device or resource busy.
The kernel still uses the old table. The new table will be used at
the next reboot or after you run partprobe(8) or kpartx(8)
Syncing disks.

$ reboot

After reboot you can check your new primary partition.

$ fdisk -cul /dev/sda

Disk /dev/sda: 250.1 GB, 250059350016 bytes
255 heads, 63 sectors/track, 30401 cylinders, total 488397168 sectors
Units = sectors of 1 * 512 = 512 bytes
Sector size (logical/physical): 512 bytes / 512 bytes
I/O size (minimum/optimal): 512 bytes / 512 bytes
Disk identifier: 0x7f3d8c0f

   Device Boot      Start         End      Blocks   Id  System
/dev/sda1   *        2048     1026047      512000   83  Linux
/dev/sda2         1026048   205826047   102400000   8e  Linux LVM
/dev/sda3       205826048   206850047      512000   83  Linux

Now lets create an ext4 file system on the new primary partition.

$ mkfs -t ext4 /dev/sda3

And mount it.

$ mkdir /extra
$ mount /dev/sda3 /extra

If you want RHEL to automatically mount your new partition at boot, you need to add that to /etc/fstab. And the recommended way to identify the partition is with it's UUID.

$ blkid /dev/sda3

$ vi /etc/fstab

UUID=b2b97c2f-f0cb-4b41-b297-7f7d36d2efd0 /extra                   ext4    defaults        1 2

And finally save and reboot.

November 25, 2013

How to Mount an USB Device in Linux

Short Version

1. Before inserting the USB, check which disks you already have.

$ ll /dev/sd*
brw-rw----. 1 root disk 8, 0 Nov 24 19:41 /dev/sda
brw-rw----. 1 root disk 8, 1 Nov 24 19:41 /dev/sda1
brw-rw----. 1 root disk 8, 2 Nov 24 19:41 /dev/sda2

2. Create a new directory under /mnt to which you will mount your USB.

$ mkdir /mnt/usb

3. Now insert the USB and mount it.

$ mount /dev/sdb <hit tab>
sdb sdb1

$ mount /dev/sdb1 /mnt/usb

4. Now you are ready to read and write to your USB.

5. To unmount.

$ umount /mnt/usb

Longer Version

In Linux a storage device is represented by a device file in /dev/.

The three letter naming convention for storage devices in Linux are:

  1. s - storage
  2. d - disc (such as SCSI, USB, SATA), cd - cd or dvd
  3. litteral order character, starting with a, then b, c, etc

Example: /dev/sda (SCSI, USB, SATA), /dev/sdb (SCSI, USB, SATA), /dev/scd (CD/DVD)

These device files represent the whole drive. Each drive is partitioned into partition. The first partition receives order number one, the next one two, etc

When a new storage device is added it will receive the last character order literal, here it is b (/dev/sdb). Another way to find out the device file is to tail the dmesg log file.

$ less /var/log/dmesg <hit enter>

...
<press shift+f (follow)>
Waiting for data... (interrupt to abort)

<Now insert USB>

sd ... [sdb] Assuming drive cache: write through
<press ctrl+c (quite)>

Here we see that the USB was allocated device name sdb. But when you mount you mount to a partition that contains a file system. And in general, most USB only have one partition, hence sdb1.

November 24, 2013

Securing SSH with Public/Private Key Authentication

The motive for using public/private key authentication are:

  1. Firstly for convinience, you no longer need to enter password (unless you encrypt your keys with password protected).
  2. Secondly, ones setup, you can remove password protection, which is a big cracking hole.

Prerequisite

The remote user needs to exist on the remote server. If it does not. Create it. And at least LOGIN ONES, so that it's home directory is created. Otherwise you can eagerly created the home directory when you add the user.

Here I will use the existing user root, for simplicity.

Client Side

Generate public and private keys, with NO password protection. I will here use the RSA algorithm and key length 2048 bits.

$ ssh-keygen -b 2048 -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/home/magnus/.ssh/id_rsa): <Enter>
Enter passphrase (empty for no passphrase): <Enter>
Enter same passphrase again: <Enter>
Your identification has been saved in /home/magnus/.ssh/id_rsa.
Your public key has been saved in /home/magnus/.ssh/id_rsa.pub.
The key fingerprint is:
90:da:b5:5a:db:59:be:34:04:6a:99:81:c3:d5:5d:25 magnus@tester1.example.com
The key's randomart image is:
+--[ RSA 2048]----+
|        .. . .E..|
|     . +  . .  . |
|      * o .      |
|     o + * .     |
|    . . S   o    |
|       + o =     |
|      . . o +    |
|           . o   |
|            .    |
+-----------------+

Next make sure that the ssh key directory and private key has proper file permission

$ chmod 700 ~/.ssh
$ chmod 600 ~/.ssh/id_rsa

The last step is to copy the client public key to the server. You can either do that manually, or with the ssh-copy-id tool. Here I will use the tool.

$ ssh-copy-id -i ~/.ssh/id_rsa.pub root@remoteserver

If you were setting up public/private key authentication for a different user, please replace root in above command with you user.

Server Side

On the server side, open /etc/ssh/sshd_config and enable public/private key authentication

PubkeyAuthentication yes

Then restart the ssh daemon service.

$ service sshd restart

And finally verify that the keys directory and files have the proper file permission and SELinux type for your user.

$ chmod 700 ~/.ssh
$ chmod 600 ~/.ssh/id_rsa

$ restorecon -Rv ~/.ssh

Test

Finally you need to test, to verify the installation. On the client machine switch to the user you had setup for and

$ ssh <your_user>@remoteserver

RHEL: How to Switch Users in Multiuser Runlevels

Switching User

To switch to a different user, e.g. student, run

$ su - student

To switch to root

$ su -

Runlevels

Most Linux distribution can be ran in 5 different runlevels. Runlevel 0 and 6 are special, which you can see below.

  • 0 - Shutdown
  • 1 - Single user mode, without network
  • 2 - Multiuser, without NFS (The same as 3, if you do not have networking)
  • 3 - Full multiuser mode, with network.
  • 4 - Unused
  • 5 - X11, graphical mode with network
  • 6 - Reboot

To see the current runlevel, type:

$ runlevel

The default runlevel is set in /etc/inittab.

How to Switch Runlevels

You can switch the runlevel with init, e.g. init 3. But from the graphical mode, there is also a keyboard shortcut.

ctrl + alt + F1 - for init 1, ctrl + alt + F2 - for init 2, etc.

November 23, 2013

Accessing Network Files via NFS and CIFS in Linux

Working with remote file system under Linux is not hard. Below I will show how to use the two most common remote file system used:

  • NFS - Network File System
  • CIFS - Common Internet File System

NFS

Show the NFS server’s export list.

$ showmount -e nfsserver.domain.com

Mount. Note that the directory /remote must exist before mount, if not create it with mkdir /remotenfs.

$ mount nfsserver.domain.com:/c/media /remotenfs

Unmount file systems

$ umount /remotenfs

CIFS

CIFS is the underlying remote file protocol used for samba server and which is the most common file server when having a mixed client environment with Windows and Linux.

Install client library

$ yum install samba-client

Show the CIFS server’s sharenames.

$ smbclient -L nfsserver.domain.com

Mount. Note that the directory /remote must exist before mount, if not create it with mkdir /remotecifs.

$ mount //cifsserver.domain.com/media /remotecifs

Unmount file systems

$ umount /remotecifs

Common vi commands

Most Linux server runs without a graphical interface and the most sure installed editor for file is the vi editor. But getting used with vi can be a little challenging. Below I will show you the most common vi commands.

Openvi file.txt
Close without saving:q!
Inserti
Quite editingESC
Write and close:wq
Copy line and paste lineyy + p
Delete line and paste linedd + P (capital)
Change wordcw
Browse to next workw
Browse to previous workb
Go to first line1G
Go to last lineG

Linux File and Special Permission

File Permission

The simplest file permission in Linux are the r (read), w (write), x (executable). These file permission yields for u (user), g (group) and o (other). They can be set both:

  • Symbolically: +-r, +-w, +-x
  • Numerically: r=4, w=2, x=1

Special Permission

There are three special permission: setuid, setgid and sticky. They can be both applied to files and directories, but then have different meanings.

Special Permission File Directory
setuid Only meaning for executable file: The executable file be be run as the file owner, not as the user that executes it.

Example /usr/bin/passwd
No effect.
setgid Only meaning for executable file: The executable file be be run as the file group, not as the user that executes it. All newly created file in directory, will inherit the parent directory group permission.
sticky No effect. All files created with a user that have write permission for a specific file can only remove that file, except for root.

Example: /tmp

To set the special permission:

  • Symbolically: setuid=u+s, setgid=g+s, sticky=o+t
  • Numerically: setuid=4, setgid=2, sticky=1