Today we received a new storage array : a Dell PowerVault MD3600f with two MD1200 expension units. In order to use those new disks, we had a bit of home work todo. Here's how we did it.
But you must be warned : this ain't my best blog post.
Ideas and solutions on IT architecture, UNIX, Linux, Oracle, Telecommunication, storage and virtualization in order to help other systems administrators and DBAs.
Saturday, January 25, 2014
Wednesday, January 22, 2014
HOWTO : Replace a failed disk drive in a FreeBSD ZFS pool
In this blog post, we will repair a broken ZFS pool from a FreeBSD server. The machine is running FreeBSD 9.2, but so long as your FreeBSD machine runs a ZFS enabled FreeBSD, all the commands in this article should work.
A little background on this machine. It's been in production for about four years now. It was originally installed with four 750 GB disk drives as a raidz2 pool. The OS has been upgraded several times and so is the disk drives (because that's what fails of course, hence this post). This is a ZFS-only machine built by following the ZFS only FreeBSD installation wiki with GPT formated disks.
A little background on this machine. It's been in production for about four years now. It was originally installed with four 750 GB disk drives as a raidz2 pool. The OS has been upgraded several times and so is the disk drives (because that's what fails of course, hence this post). This is a ZFS-only machine built by following the ZFS only FreeBSD installation wiki with GPT formated disks.
Monday, November 4, 2013
HOWTO : Configure OpenSSH to Fetch Public Keys from OpenLDAP for Authentication on CentOS
Today we will configure our OpenLDAP server to store SSH public keys so that the OpenSSH daemon can fetch them and thus authenticate our users.
To do this, we first need two CentOS machines. This is easy to achieve via a KickStart. If you need help building a KickStart server, follow my previous blog post. Then we need a working OpenLDAP server. If you don't have one, then follow my previous blog posts to set one up.
To do this, we first need two CentOS machines. This is easy to achieve via a KickStart. If you need help building a KickStart server, follow my previous blog post. Then we need a working OpenLDAP server. If you don't have one, then follow my previous blog posts to set one up.
Thursday, October 17, 2013
HOWTO : CentOS 6 KickStart Server
This blog post will explain how to build a Kickstart server which is used to automatically perform untattended OS installation and configuration of both RedHat 6 and CentOS 6 machines.
Kickstart is basically a copy of the Solaris Jumpstart. If you manage IBM AIX machines, it's the equivalent of NIM. Or Ignite in the HP-UX world.
Kickstart is basically a copy of the Solaris Jumpstart. If you manage IBM AIX machines, it's the equivalent of NIM. Or Ignite in the HP-UX world.
Labels:
linux
Wednesday, October 16, 2013
RCS and sudo log names
If you're tired of always seeing the root user in the RCS $Id$ tags, then follow this short and to the point blog post to switch this to the real author.
Labels:
sudo
Friday, April 12, 2013
Map Apple Keyboard on Windows 7 and Restore Apple Function Keys
This is a short post just to redirect all Apple Keyboard users on Windows 7 machines to a great blog that explains how to get the full functions of the keyboard.
Check the Map Apple Keyboard on Windows 7 and Restore Apple Function Keys for more info.
Check the Map Apple Keyboard on Windows 7 and Restore Apple Function Keys for more info.
Tuesday, March 12, 2013
CentOS yum(8) Error « No module named cElementTree » Fixed
I've been having problems with yum(8) on one of the CentOS 6 x86_64 machines. After looking at many different forums and bug reports, I now found the solution.
Friday, February 22, 2013
Oracle Solaris 10 Kerberized SSH Configuration
If you manage Oracle Solaris 10 machines, you might want to configure your servers to accept Kerberos principals via SSH. The SSH that comes with Solaris 10 does not understand the same configurations as the OpenSSH one does. And Solaris has a little quirk that Linux and BSD don't.
If you don't already have a Kerberos infrastrucutre in place, then the first thing to do is to set one up. Read my other article HOWTO : Kerberos KDC with OpenLDAP 2.4 Back-End and SASL GSSAPI Authentication on CentOS 6.2 to learn how to create a Kerberos realm.
If you don't already have a Kerberos infrastrucutre in place, then the first thing to do is to set one up. Read my other article HOWTO : Kerberos KDC with OpenLDAP 2.4 Back-End and SASL GSSAPI Authentication on CentOS 6.2 to learn how to create a Kerberos realm.
MySQL Backup and Recovery
If your site manages it's data with MySQL, then you obviously need to make sure the data is safe. In this blog post, I will show how to create a daily backup automatically. I will also show a continuous data protection plan for MySQL databases. This blog post uses the previous backup server configured in my Secure Backup & Recovery with rsnapshot, rssh and OpenSSH article.
Tuesday, January 29, 2013
Oracle Data Pump
Today I'm going to show how I use Oracle Data Pump utilities. Starting with Oracle 10gR1, Oracle replaced both the export and import utilities by their new Data Pump counterpart : expdp and impdp respectively. The official documentation on these utilities is found in the Oracle Database Utilities10g Release 2 (10.2)
The steps outlined in this blog post are part of a database consolidation effort in which several databases from two different machines will be merged into a new Linux x86_64 server running RedHat Enterprise Linux 5.9 and Oracle RDBMS 10gR2.
The steps outlined in this blog post are part of a database consolidation effort in which several databases from two different machines will be merged into a new Linux x86_64 server running RedHat Enterprise Linux 5.9 and Oracle RDBMS 10gR2.
Friday, September 28, 2012
VoIP QoS on Cisco 3560 Switches with Polycom and Cisco IP Phones
Today we are going to setup network Quality of Service (QoS) for Voice over IP (VoIP) traffic generated by Polycom and Cisco IP phones. Our goal here is to tag the VoIP packets so that they are placed in a priority outgoing queue so that if the available bandwith is saturated, then the VoIP packets will be the last ones to be dropped by the switch. VoIP is a delay-sensitive application while bulk data transfers are not. When a switch port gets more data that it can handle, the switch will start dropping packets. If a VoIP packet is dropped, people having a conversation will hear a glitch. We don't want that and this is why we must treat the VoIP packets differently than other data packets.
Thursday, September 27, 2012
IOS Upgrade on Cisco WS-C4507R Chassis with Dual Supervisor V Engines
Today we will upgrade the IOS version on both WS-X4516 supervisor engines V in a WS-C4507R chassis. This blog post assumes that your 4507R chassis's supervisor engine already has network support for you to SSH into it.
First, go to the Cisco support site and download the latest IOS version (you need a Cisco support contract to have access to new IOS images). Place this image on your TFTP server. In this example, the TFTP server is a CentOS Linux machine called alice.company.com.
First, go to the Cisco support site and download the latest IOS version (you need a Cisco support contract to have access to new IOS images). Place this image on your TFTP server. In this example, the TFTP server is a CentOS Linux machine called alice.company.com.
Labels:
cisco
Wednesday, August 22, 2012
Oracle Database 11.2.0.3 Install and Setup on RedHat Linux 6 x86_64
In this post we will install a new server with the latest Oracle Database 11gR2 software (as of this writing, it is version 11.2.0.3). In this example, the new machine is called opus.company.com and the new database instance is called meta.
Tuesday, August 21, 2012
Howto Recover Lost Cisco Enable Password
In this blog post, we will recover from a lost Cisco switch enable password.
Thursday, August 16, 2012
How to remove an FC LUN from a running RedHat 6 server.
This quick howto document shows how to remove a fibre channel LUN under multipathd(8) control from a running RedHat Enterprise Linux 6 machine. Be careful when performing online storage modifications. Make sure you have a valid backup. And of course I can't be held resonsible for any problems if you follow these steps ;)
Thursday, June 28, 2012
PC-BSD / FreeBSD Kerberos GNOME Graphical Login
A quick post just to show how to configure a PC-BSD or a FreeBSD workstation to run kinit(1) right when you login. In this example, the desktop machine is running PC-BSD 9.0 with the GNOME desktop.
Tuesday, June 12, 2012
Secure Backup & Recovery with rsnapshot, rssh and OpenSSH
Overview
Wee all need to backup our machines. But we also need to keep the data private and the backup procedure secured. In UNIX and Linux machines, we need to run the backup operation as root in order to read everything on the machines. But allowing remote connections as the root user is not exactly a good idea. So how to we proceed? We use rsnapshot(1) and rssh(1) together with OpenSSH to secure the whole process. Here's how to do it on CentOS 6.
In case you're running a heterogeneous network, please note that I've successfully configured this process on FreeBSD, PC-BSD, RedHat, Ubuntu, AIX and Solaris servers.
In this example, our backup server is called backup.company.com and is running CentOS 6 while the clients are :
Friday, June 8, 2012
HOWTO : OpenLDAP 2.4 Replication on CentOS 6.2
We continue our OpenLDAP 2.4 on CentOS 6.2 with a description on how to setup between two OpenLDAP 2.4 servers. This happens to be the final bullet point in our list of goals :
Install OpenLDAP 2.4.Configure Transport Layer Security (TLS).Manage users and groups in OpenLDAP.Configure pam_ldap to authenticate users via OpenLDAP.Use OpenLDAP as sudo's configuration repository.Use OpenLDAP as automount map repository for autofs.Use OpenLDAP as NFS netgroup repository again for autofs.Use OpenLDAP as the Kerberos principal repository.Setup OpenLDAP backup and recovery.- Setup OpenLDAP replication.
- provider : alice.company.com (a.k.a. master server)
- consumer : bob.company.com (a.k.a. replica server)
Labels:
consumer,
ldap,
linux,
provider,
replication
Thursday, May 31, 2012
CentOS Serial Console Server with Digi AccelePort Xem Module
In order to effectively manage UNIX, Linux and Cisco machines from a remote location, one needs to redirect the console to the serial port and hook this to a serial console server. It is also good on a security stand point because all the messages sent to the console are logged on the console server, thus serving in forensic investigations. Ideally, to have even the BIOS at the serial ports, you need to run Oracle/Sun Microsystems or IBM pServers machines. Most newer x86 servers can redirect their BIOS to the serial port. Do it, it's great! With the console server, you have access to everything the server has to offer from the comfort of your office.
Tuesday, May 15, 2012
HOWTO : OpenLDAP 2.4 Backup & Recovery on CentOS 6.2
This blog post will explain how to backup and restore our OpenLDAP 2.4 server. This is goal number nine.
Install OpenLDAP 2.4.Configure Transport Layer Security (TLS).Manage users and groups in OpenLDAP.Configure pam_ldap to authenticate users via OpenLDAP.Use OpenLDAP as sudo's configuration repository.Use OpenLDAP as automount map repository for autofs.Use OpenLDAP as NFS netgroup repository again for autofs.Use OpenLDAP as the Kerberos principal repository.- Setup OpenLDAP backup and recovery.
- Setup OpenLDAP replication.
Subscribe to:
Posts (Atom)