Streaming replication allows a standby server to stay up-to-date with primary. The standby connects to the primary, which streams WAL records to the standby as they're generated.
Hot standby is the term used to describe the ability to connect to the server and run read-only queries.
This method of replication is completely transparent to the client, it doesn't require any changes to database, allows query information from standby server and requires minimum administrative effort.
Showing posts with label troubleshooting. Show all posts
Showing posts with label troubleshooting. Show all posts
Wednesday, October 23, 2013
Wednesday, August 22, 2012
How to restore vim screen when exiting
When you exit vim it does not restore the terminal screen (particularly in FreeBSD), here is how to fix that (file ~/.vimrc):
" Restore terminal screen when exiting Vim if &term =~ "xterm" let &t_ti = "\<Esc>[?47h" let &t_te = "\<Esc>[?47l" endif
Labels:
freebsd
,
tricks
,
troubleshooting
,
vim
Thursday, June 21, 2012
Troubleshooting slapd error: too many open files
Debian testing comes with openldap (slapd package) version 2.4.28. I noticed that ldap clients start receiving error and cannot contact ldap service any more. While the slapd daemon was running I found a number of errors in syslog (file /var/log/syslog):
... ldap1 slapd[4894]: SASL [conn=1611] Failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Too many open files) ... ldap1 slapd[4894]: warning: cannot open /etc/hosts.allow: Too many open files ... ldap1 slapd[4894]: warning: cannot open /etc/hosts.deny: Too many open files ... ldap1 slapd[4894]: SASL [conn=1611] Failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Too many open files)Take a look at slapd process max open files soft limit:
cat /proc/`pidof slapd`/limitsCheck number of files open by slapd process:
pidof slapd | xargs lsof -a -p | wc -lThe slapd process must not exceed max open files soft limit. Take a look at files opened by slapd process:
pidof slapd | xargs lsof -a -p | tailHere is a sample output that shows there are a number of deleted files... actually one file /var/tmp/ldap_103.
slapd 4894 openldap 117u REG 0,197 3371 705975 /var/tmp/ldap_103 (deleted) slapd 4894 openldap 118u REG 0,197 3371 705975 /var/tmp/ldap_103 (deleted) slapd 4894 openldap 119u REG 0,197 3371 705975 /var/tmp/ldap_103 (deleted)There is definitely a bug in slapd that cause max open files limit exceed.
Recycle Process
We can write a script that does a check and restart daemon if it reaches certain limit (file /usr/local/sbin/slapd-restart).
#!/bin/sh
# Restart slapd daemon if it has open more than 512 files
if [ `pidof slapd | xargs lsof -a -p | wc -l` -gt 512 ]
then
/etc/init.d/slapd restart
fi
Let cron run this script hourly:
ln -s /usr/local/sbin/slapd-restart \ /etc/cron.hourly/slapd-restartIf slapd process exceed max open files soft limit too quickly consider schedule cron job more frequently.
Mount /var/tmp in tmpfs
While slapd process creates small files in /var/tmp quite quickly I found reasonable to mount it with tmpfs (file /etc/fstab):tmpfs /var/tmp tmpfs noatime,nodev,noexec,nosuid,size=1M 0 0Restart slapd daemon so changes take place:
/etc/init.d/slapd stop # Ensure the /var/tmp is empty rm /var/tmp/ldap_103 mount /var/tmp /etc/init.d/slapd start # Ensure the /var/tmp mounted df -h | grep /var/tmpEnsure the /var/tmp mounted:
tmpfs 1.0M 4.0K 1020K 1% /var/tmpRegularly take a look a /var/log/syslog if there are any errors reported.
Labels:
debian
,
kerberos
,
ldap
,
security
,
troubleshooting
Thursday, June 7, 2012
Gnome Keyring: Location
Gnome keyring can automatically unlock passwords stored in the keyring. Gnome keyring include the following components: pkcs11, gpg, secrets, ssh. You can take a look at various passwords and keys stored by running (Alt + F2) seahorse.
Various keyrings are unlocked during user login. You can control which one by reviewing gnome startup application preferences, take a look by running gnome-session-properties.
The problem I faced with was related to the fact that keyring daemon place it runtime data into $HOME/.cache/keyring-* directory and over time there are quite a lot of them there. So while these data are session specific I would think it is most appropriate to store this information somewhere in temporary storage (e.g. /tmp) so it cleaned up. Fortunately you can define environment variable $XDG_RUNTIME_DIR that points to /tmp and that get it solved.
Various keyrings are unlocked during user login. You can control which one by reviewing gnome startup application preferences, take a look by running gnome-session-properties.
The problem I faced with was related to the fact that keyring daemon place it runtime data into $HOME/.cache/keyring-* directory and over time there are quite a lot of them there. So while these data are session specific I would think it is most appropriate to store this information somewhere in temporary storage (e.g. /tmp) so it cleaned up. Fortunately you can define environment variable $XDG_RUNTIME_DIR that points to /tmp and that get it solved.
echo "export XDG_RUNTIME_DIR=/tmp" > \
/etc/profile.d/gnome-keyring.sh
The keyring daemon properly manage file permission so it owned and readable by user only. Once you reboot your computer the system level profile will setup environment variable for you so keyring cache will be created out there.
Labels:
debian
,
gnome
,
security
,
troubleshooting
Tuesday, February 28, 2012
How to Renew Certificate with OpenSSL
SSL certificates are valid for certain period of time, usually 365 days. If you are using self signed certificates at some point of time you will need renew them, otherwise services that utilize them "unexpectedly" stop working. That actually greatly depends on client configuration, so if client demand valid server certificate it will not proceed any further.
Suppose your certificate private key (original request) is in file my-key.pem and signed certificate in my-cert.pem.
Suppose your certificate private key (original request) is in file my-key.pem and signed certificate in my-cert.pem.
Validate Certificate
Validate certificate by issuing the following command:openssl verify my-cert.pemHere is a sample output of checking valid cerificate:
my-cert.pem: OKExpired:
my-cert.pem: ... error 10 at 0 depth lookup:certificate has expired OKIf verification of certificate shows it expired, you need renew it.
Renew Certificate
Renewal of expired certificate consists of two steps: revoke old one, sign certificate request.- Revoke expired certificate (you will be asked for Certificate Authority password):
ca1:~/ca# openssl ca -revoke my-cert.pem Using configuration from /usr/lib/ssl/openssl.cnf Enter pass phrase for ./demoCA/private/cakey.pem: Revoking Certificate EFDAF4493BC3D5BB. Data Base Updated
- Rename you certificate key (request) file to newreq.pem.
ca1:~/ca# mv my-key.pem newreq.pem ca1:~/ca# /usr/lib/ssl/misc/CA.sh -sign ... Signed certificate is in newcert.pem
Troubleshooting
If you get error like this one below:failed to update database TXT_DB error number 2You must revoke previous certificate from CA database.
Labels:
openssl
,
troubleshooting
Wednesday, February 15, 2012
How to Revert Broken Package in Debian
You just made upgrade of your Debian testing box and noticed something went wrong, some daemon not starting and you have no idea what to do until the bug will be fixed. Fortunately, you are able to revert broken package in Debian. Here we are going revert broken bind9 package version 1:9.8.1.dfsg.P1-2 and replace it with last known to work.
- We need to find last known to work version of the broken package. Take a look at
/var/log/apt/history.log. You should be able to find information about the package failed to install/configure:
Upgrade: ..., bind9:i386 (9.7.3.dfsg-1+b1, 9.8.1.dfsg.P1-2)...
So here version 9.7.3.dfsg-1+b1 is replaced by 9.8.1.dfsg.P1-2. Thus we found last working version. - Since we know version (9.7.3.dfsg-1+b1) of the bind9 package we can install it from snapshot.debian.org. Go to that site and search for your package. You will get a list of various versions available.
Follow link for with version that you found previously. You will get a list of various options, including source, architecture specific files, etc.
bind9_9.7.3.dfsg-1+b1_i386.deb Seen in debian on 2011-04-20 22:16:02 in /pool/main/b/bind9.
Follow link /pool/main/b/bind9. In my case it was:http://snapshot.debian.org/archive/debian/20110420T221602Z/pool/main/b/bind9/
- Add snapshot url to file /etc/apt/sources.list:
deb http://snapshot.debian.org/archive/debian/20110420T221602Z testing main
- Update your apt repository with the following command:
apt-get -o Acquire::Check-Valid-Until=false update
- Have a look at updated package information:
apt-cache showpkg bind9
You should be able to see something like this:Versions: 1:9.8.1.dfsg.P1-2 ... 1:9.7.3.dfsg-1 ...
1:9.7.3.dfsg-1 is the version we need. - Remove broken package and related dependencies:
apt-get remove bind9 apt-get autoremove
- Install version we need:
apt-get install bind9=1:9.7.3.dfsg-1
Since it complains:The following packages have unmet dependencies: bind9 : Depends: bind9utils (= 1:9.7.3.dfsg-1) but 1:9.8.1.dfsg.P1-2 is to be installed
... let add that one dependency for bind9utils as well.apt-get install bind9=1:9.7.3.dfsg-1 bind9utils=1:9.7.3.dfsg-1
Package pinning
We will use apt pinning feature to prevent packages from being upgraded. Just create a file /etc/apt/preferences.d/bind9 and add the following:
Package: bind9
Pin: version 1:9.7.3*
Pin-Priority: 1001
Package: bind9utils
Pin: version 1:9.7.3*
Pin-Priority: 1001
The next time you run upgrade these two packages remain untouched.
Labels:
apt
,
debian
,
troubleshooting
Wednesday, December 21, 2011
How to Convert APE+CUE to MP3
There is no a single tool to convert a APE file to a number of mp3 tracks. We are going to convert ape file to wav first, than wav to mp3 (a single file) and finally cut a single mp3 file into several (per CUE file). We need several packages. Two of them (libmac2 monkey-audio) are from debian-multimedia, choose mirror from the following list. You need to install debian-multimedia-keyring package. In my case I have obtained it from here:
http://mirror.yandex.ru/debian-multimedia/pool/main/d/deb-multimedia-keyring/Download debian-multimedia-keyring_2010.12.26_all.deb file (in your case the file can be newer) and install:
dpkg -i debian-multimedia-keyring_2010.12.26_all.debOnce above is done we need to add debian-multimedia repository location to apt source list and update it:
echo "deb http://mirror.yandex.ru/debian-multimedia/ testing main non-free" \
>> /etc/apt/sources.list
apt-get update
Install required packages:
apt-get -y install libmac2 monkeys-audio shntool \
lame mp3splt
Here is a script that does the rest (file ape-mp3.sh):
#!/bin/sh
# Convert APE to WAV
shnconv -o wav CDImage.ape
# Convert WAV to MP3 VBR
lame -h -v --preset cd CDImage.wav CDImage.mp3
rm CDImage.wav
# Split file
mp3splt -a -d mp3 -c CDImage.ape.cue -o \
@a/@b/@n-@a-@t CDImage.mp3
rm CDImage.mp3
Drop that file into a directory that has two files input CDImage.ape and CDImage.ape.cue. Run the script and in few minutes you will get a mp3 directory with your tracks.
Troubleshooting: mp3splt does not set ID3 tags
As of this writing Debian testing comes with mp3splt version 2.2.5-1. The problem has been fixed since version 2.3. So in order to install latest version you need to add the following to /etc/apt/sources.list:
echo "deb http://mp3splt.sourceforge.net/repository wheezy main" \
>> /etc/apt/sources.list
apt-get update
Note that you need remove previously installed packages related to mp3splt:
apt-get remove libmp3splt-mp3 libmp3splt-ogg \
libmp3splt0 mp3splt
Install latest:
apt-get install libmp3splt0-mp3 libmp3splt0-ogg \
libmp3splt0 mp3splt
Labels:
audio
,
debian
,
troubleshooting
Monday, September 5, 2011
How to Compile Python from Source
Here we are going compile python from source. I assume you have a clean installation of Debian testing. Here are few packages required for compilation.
apt-get -y install build-essential zlib1g-dev libbz2-dev \
libncurses5-dev libreadline-gplv2-dev libsqlite3-dev \
libssl-dev libgdbm-dev
Once above installation is complete, download python source code from here: http://www.python.org/ftp/python/.
Suppose you choose to download python 2.5.2.
cd /usr/local/src wget http://www.python.org/ftp/python/2.5.2/Python-2.5.2.tar.bz2 tar xjf Python-2.5.2.tar.bz2 cd Python-2.5.2Since most of libraries in Debian moved from /usr/lib to /usr/lib/i386-linux-gnu we need create symbolic links in old location so the build scripts can find them all. This is far easier than specify a valid library location for each case. Here are links:
ln -s /usr/lib/i386-linux-gnu/libssl.so \
/usr/lib/libssl.so
ln -s /usr/lib/i386-linux-gnu/libcrypt.so \
/usr/lib/libcrypt.so
ln -s /usr/lib/i386-linux-gnu/libcrypto.so \
/usr/lib/libcrypto.so
ln -s /usr/lib/i386-linux-gnu/libbz2.so \
/usr/lib/libbz2.so
ln -s /usr/lib/i386-linux-gnu/libgdbm.so \
/usr/lib/libgdbm.so
ln -s /usr/lib/i386-linux-gnu/libcurses.so \
/usr/lib/libcurses.so
ln -s /usr/lib/i386-linux-gnu/libz.so \
/usr/lib/libz.so
ln -s /usr/lib/i386-linux-gnu/libsqlite3.so \
/usr/lib/libsqlite3.so
Compilation
Before we start compile we need to configure it first. You can run it with all defaults (this will install python to /usr/local/)../configureOr you can specify some other location:
./configure --prefix=/usr/localThe configuration process take few seconds. Next issue make command to actually compile it (this may take few minutes). The -s option prints warning only and -j 2 utilizes 2 CPU cores during the compilation).
make -s -j 2You can optionally test it before installing with:
make testor run specific tests of your interest:
./python Lib/test/test_hashlib.py
Install
make installPython executable should be located at /usr/local/bin/python2.5.
Extra Packages
While python is perfectly working at this moment you might need install some extra packages (e.g. virtualenv) with easy_install.wget -O - -q http://python-distribute.org/distribute_setup.py | python2.5 easy_install-2.5 virtualenvThis way you can install as many python versions as you like.
Troubleshooting
While working with some third party package (e.g. django) you got the following error:ImportError: ...undefined symbol: PyUnicodeUCS2_ReplaceThere reason is described here. You have to re-configure the python:
./configure --enable-unicode=ucs4and build/install it again.
Labels:
debian
,
python
,
troubleshooting
Saturday, June 4, 2011
Troubleshooting: Could not update .ICEauthority file
Here is the error message that might encounter duing gnome desktop startup.
Could not update .ICEauthority file /var/lib/gdm3/.ICEauthorityI have resolved this problem by simply removing that file and let gdm3 daemon re-create it. The commands below must be executed with root privileges.
/etc/init.d/gdm3 stop rm /var/lib/gdm3/.ICEauthority* /etc/init.d/gdm3 startNote, restarting gdm not helps all the time, so try reboot computer instead.
Labels:
debian
,
troubleshooting
Thursday, April 14, 2011
Troubleshooting: Windows Guest on KVM
While migrating windows virtual machine from virtualbox to kvm you might experience an issue related to significant virtual hardware changes, in other words you get BSoD (bluescreen).
Here are few findings that can help you:
- Windows 2003, BSoD. STOP: 0x0000007B. Here is a description. You need apply this before you convert image to kvm.
- Error message that computer does not have a parallel port: "The Parallel port driver service failed to start". Read more here.
- If your Windows host was configured in KVM configuration first choose IDE drive as disk bus, add SCSI controller. When guest starts let it scan for hardware changes, that might take few minutes, when it finds SCSI controller shutdown guest and change disk bus to use SCSI controller, you can remove IDE controller.
- Uninstall virtualbox guest tools, so windows doesn't complain (see system event log).
Labels:
kvm
,
troubleshooting
,
virtualbox
,
windows
Tuesday, March 15, 2011
Debian Diskless Setup and Configuration
Here we are going setup a server that serves over network to pxe clients a diskless debian. We will be using the following:
- DHCP server: dh1 (see how to install here)
- TFTP server: tftp1 (IP: 192.168.10.35)
- NFS server: nfs1 (IP: 192.168.10.30)
- PXE image location on NFS server: /srv/diskless/c1
Saturday, February 5, 2011
Troubleshooting: dbus-daemon nss_ldap failed to bind to LDAP server
While installing Debian OpenLDAP client with Kerberos (see here) on Gnome desktop you might experience the following errors in auth.log.
dbus-daemon: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Credentials cache file '/tmp/krb5cc_101' not found) dbus-daemon: nss_ldap: failed to bind to LDAP server ldap://ldapk1.dev.local/: Local error dbus-daemon: nss_ldap: could not search LDAP server - Server is unavailableAt the same time you will might see a number of errors reported by slapd:
slapd: conn=2806 op=0 UNBIND slapd: conn=2806 fd=27 closed slapd: conn=2807 fd=27 ACCEPT from IP=192.168.XX.XXX:XXXXX (IP=0.0.0.0:XXX)The problem is related to parallel boot of your system. By default dbus and nscd are started in parallel, the problem appears when dbus is launched before nscd daemon. In order to fix that you need to change boot sequence. Make sure you have the following in /etc/init.d/dbus (notice line Should-Start):
# Provides: dbus # Should-Start: nscd # Required-Start: $remote_fs $syslogOnce above is done simple re-enable dbus service so it updates everything necessary:
rcconf --off dbus ; rcconf --on dbusNotice changes in /etc/rc2.d:
# ls /etc/rc2.d/ S17nscd ... S18dbusYou need restart your computer (or at least restart dbus daemon) in order changes take place.
Labels:
debian
,
kerberos
,
ldap
,
troubleshooting
Debian OpenLDAP client with Kerberos
Before we proceed with client setup (let assume our client machine name is deby01.dev.local) you need to setup the following:
- Kerberos Client (look here).
- We need install few packages:
apt-get -y install ldap-utils libpam-ldap \ libsasl2-modules-gssapi-mit nscd libnss-ldap kstart
During installation you will be prompted for few questions:- libnss-ldap
LDAP server URI: ldap://ldapk1.dev.local/ Distinguished name of the search base: dc=dev,dc=local LDAP version to use: 3 cn=admin,ou=people,dc=dev,dc=local LDAP account for root: cn=admin,ou=people,dc=dev,dc=local LDAP root account password: <just hit enter>
- libpam-ldap
Allow LDAP admin account to behave like local root? No Does the LDAP database require login? No
- libnss-ldap
- Reconfigure libpam-runtime and disable LDAP Authentication:
dpkg-reconfigure libpam-runtime
- Configure kstart, add the following to /etc/inittab (It will check every 10 minutes of the Kerberos ticket needs to be renewed and set the ticket lifetime to 24 hours:
KS:2345:respawn:/usr/bin/k5start -U -f /etc/krb5.keytab -K 10 -l 24h
Force init to reload configuration:kill -HUP 1
Ensure /tmp/krb5cc_0 file is created:ls -lh /tmp/krb5cc_0
- Kerberise libnss-ldap (file /etc/libnss-ldap.conf), ensure the following:
base dc=dev,dc=local uri ldap://ldapk1.dev.local/ ldap_version 3 rootbinddn cn=admin,ou=people,dc=dev,dc=local # Use SASL and GSSAPI and where to find the # Kerberos ticket cache. use_sasl on sasl_mech gssapi krb5_ccname FILE:/tmp/krb5cc_0
- Set defaults for LDAP clients (file /etc/ldap/ldap.conf). Note client configuration changes if ldap is configured via SSL (see here).
BASE dc=dev,dc=local URI ldap://ldapk1.dev.local/ SASL_MECH GSSAPI
- Add LDAP support for login process by nscd (file /etc/nsswitch.conf):
passwd: compat ldap group: compat ldap shadow: compat ldap
- Restart Name Service Cache daemon:
/etc/init.d/nscd restart
- Configure PAM to automatically create a user home directory (file /etc/pam.d/common-session):
session required pam_mkhomedir.so
Troubleshooting
- You might experience the following error while initializing kerberos ticket in Debian Gnome desktop:
Cannot resolve network address for KDC in realm DEV.LOCAL
This somehow conflicts with avahi-daemon, you will need disable it:rcconf --off avahi-daemon
- If you are using Debian Gnome desktop, have a look at Troubleshooting: dbus-daemon nss_ldap failed to bind to LDAP server, that you can find here.
Debian OpenLDAP with Kerberos Authentication
Before we proceed with ldap kerberization (let assume our server name is ldapk1.dev.local) you need to setup the following:
Once the basic installation of the above is complete, here we go:
Remove Authentication from LDAP
- Since we are going to authenticate users with Kerberos we need to prohibit users access to password stored in ldap. Add the following to file access-passwd.ldif:
dn: olcDatabase={1}hdb,cn=config changetype: modify # # Delete default user access to password delete: olcAccess olcAccess: {0}to attrs=userPassword,shadowLastChange by self write by anonymous auth by dn="cn=admin,dc=dev,dc=local" write by * none - # Prohibit access to password add: olcAccess olcAccess: {0}to attrs=userPassword,shadowLastChange by * none - # Only authenticated users have read access # Anonymous users have no access. add: olcAccess olcAccess: {1}to * by users read by * noneand apply changes:ldapmodify -QY EXTERNAL -H ldapi:/// -f access-passwd.ldif
- Delete admin account:
ldapdelete -cxWD cn=admin,dc=dev,dc=local cn=admin,dc=dev,dc=local
and it access rights in the directory (file access-noadmin.ldif):dn: olcDatabase={1}hdb,cn=config changetype: modify # # Revoke admin write rights to the directory delete: olcAccess olcAccess: {3}to * by self write by dn="cn=admin,dc=dev,dc=local" write by * read - # Move admin account to people unit replace: olcRootDN olcRootDN: uid=admin,ou=people,dc=dev,dc=local - # Remove admin password delete: olcRootPWand apply changes:ldapmodify -QY EXTERNAL -H ldapi:/// -f access-noadmin.ldif
Setup GSSAPI mapping between OpenLDAP and Kerberos
- Install SASL module for Kerberos:
apt-get install libsasl2-modules-gssapi-mit
- Add ldap principal:
kadmin -p admin -q "addprinc -randkey ldap/ldapk1.dev.local" kadmin -p admin -q "ktadd ldap/ldapk1.dev.local"
- Allow openldap group (slapd service is running under openldap account) access kerberos information:
chgrp openldap /etc/krb5.keytab chmod g+r,o= /etc/krb5.keytab ls -lh /etc/krb5.keytab
- Specify authentication mode (file /etc/ldap/ldap.conf):
SASL_MECH GSSAPI
- Setup SASL mapping between Kerberos and LDAP accounts (file auth-kerberos.ldif):
dn: cn=config changetype: modify # # Regular expression that match a simple user name # provided by SASL and map it to ldap entry add: olcAuthzRegexp olcAuthzRegexp: uid=([^,]+),cn=dev.local,cn=gssapi,cn=auth uid=$1,ou=people,dc=dev,dc=local - # Specify SASL Kerberos realm add: olcSaslRealm olcSaslRealm: DEV.LOCAL
and apply changes:ldapmodify -QY EXTERNAL -H ldapi:/// -f auth-kerberos.ldif
- Restart OpenLDAP service:
/etc/init.d/slapd restart
Verify settings
Verify above changes by querying config:ldapsearch -LLLQY EXTERNAL -H ldapi:/// -b \
cn=config "(|(cn=config)(olcDatabase={1}hdb))"
Here it is:
dn: cn=config
objectClass: olcGlobal
cn: config
olcArgsFile: /var/run/slapd/slapd.args
olcLogLevel: stats
olcPidFile: /var/run/slapd/slapd.pid
olcToolThreads: 1
olcAuthzRegexp: {0}uid=([^,]+),cn=dev.local,cn=gssapi,cn=auth uid=$1,ou=people
,dc=dev,dc=local
olcSaslRealm: DEV.LOCAL
dn: olcDatabase={1}hdb,cn=config
objectClass: olcDatabaseConfig
objectClass: olcHdbConfig
olcDatabase: {1}hdb
olcDbDirectory: /var/lib/ldap
olcSuffix: dc=dev,dc=local
olcAccess: {0}to attrs=userPassword,shadowLastChange by * none
olcAccess: {1}to dn.base="" by * read
olcLastMod: TRUE
olcDbCheckpoint: 512 30
olcDbConfig: {0}set_cachesize 0 2097152 0
olcDbConfig: {1}set_lk_max_objects 1500
olcDbConfig: {2}set_lk_max_locks 1500
olcDbConfig: {3}set_lk_max_lockers 1500
olcDbIndex: objectClass eq
olcDbIndex: uid eq
olcDbIndex: cn eq
olcDbIndex: ou eq
olcDbIndex: dc eq
olcRootDN: uid=admin,ou=people,dc=dev,dc=local
Kerberos Authentication Test
- Let ensure anonymous has no access
ldapk1:~/ldap# ldapsearch -xLLL No such object (32)
- Authenticate to Kerberos:
kinit -p admin
- Let make the search as authenticated user (you should be able to see organization units people and groups):
ldapsearch -LLL
Troubleshooting
- Cannot create replay cache: No such file or directory
ldap1:~# ldapsearch -LLL SASL/GSSAPI authentication started ldap_sasl_interactive_bind_s: Other (e.g., implementation specific) error (80) additional info: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Cannot create replay cache: No such file or directory)
The only way recover from this error:- Restart slapd daemon
- Consider add cron job on reboot that restarts slapd (file /etc/cron.d/slapd)
@reboot root /etc/init.d/slapd restart
Labels:
debian
,
kerberos
,
ldap
,
security
,
troubleshooting
Wednesday, December 15, 2010
Debian Slave DNS Server Setup
The setup of Slave (Secondary) DNS Server is pretty easy. You need to follow two previous posts of setting up a simple DNS server and chroot bind9.
Master (Primary) DNS Server
- Add the following to /etc/bind/named.conf.options
dnssec-enable yes;
- Generate MD5 hash key:
dnssec-keygen -r /dev/urandom -a hmac-md5 \ -b 256 -n host rndc ; cat Krndc.*.private \ | grep Key ; rm Krndc*
Here is output:Key: 9EKQM+7+EnJzO7TWyayUf0vks4k+SZPf9DAs8fOeREM=
- Add the following (replace md5 key with the one you generated) to a new file /etc/bind/transfer.key
key TRANSFER { algorithm hmac-md5; secret "9EKQM+7+EnJzO7TWyayUf0vks4k+SZPf9DAs8fOeREM="; }; -
Secure key:
chmod o-r /etc/bind/transfer.key
- Add the following to a new file /etc/bind/named.conf.transfer
include "/etc/bind/transfer.key"; // Slave IP Address server 192.168.10.3 { keys { TRANSFER; }; }; - Add the following to file /etc/bind/named.conf
include "/etc/bind/named.conf.transfer";
Slave (Secondary) DNS Server
- Add the following to /etc/bind/named.conf.options
dnssec-enable yes;
- Add the following (replace md5 key with the one you generated) to file /etc/bind/transfer.key
key TRANSFER { algorithm hmac-md5; secret "9EKQM+7+EnJzO7TWyayUf0vks4k+SZPf9DAs8fOeREM="; }; -
Secure key:
chmod o-r /etc/bind/transfer.key
- Add the following to file /etc/bind/named.conf.transfer
include "/etc/bind/transfer.key"; // Master IP Address server 192.168.10.2 { keys { TRANSFER; }; }; - Add the following to file /etc/bind/named.conf
include "/etc/bind/named.conf.transfer";
- Specify slave zones in file /etc/bind/named.conf.local:
zone "dev.local" IN { type slave; file "/etc/bind/db.dev.local"; masters { 192.168.10.2; }; allow-notify { 192.168.10.2; }; }; zone "10.168.192.IN-ADDR.ARPA" IN { type slave; file "/etc/bind/db.10.168.192"; masters { 192.168.10.2; }; allow-notify { 192.168.10.2; }; }; - Copy forwards to slave (file /etc/bind/named.conf.forward):
zone "corp.local" IN { type forward; forwarders { 192.168.11.2; 192.168.11.3; }; }; - Ensure bind:bind is the owner of the configuration so it can update the files received from master.
chown -R bind:bind /var/chroot/bind9/etc/*
root@ns2:/etc/bind# apt-get install ntpdate ... root@ns2:/etc/bind# ntpdate pool.ntp.orgNow you can restart bind9 on both servers and ensure that slave received zone files.
Troubleshooting
Have a look at system log file (/var/log/syslog) for any errors reported by named. If you will see something telling you permission denied while dumping a file, ensure bind:bind is the owner as following:chown -R bind:bind /var/chroot/bind9/etc/* /etc/init.d/bind9 restart ls -l /ent/bind/db.*
Labels:
debian
,
dns
,
network
,
troubleshooting
Subscribe to:
Posts
(
Atom
)