Showing posts with label Redhat Linux. Show all posts
Showing posts with label Redhat Linux. Show all posts

Wednesday, 16 February 2011

Red Hat EX300 Objectives and solutions

I. System Configuration and Management

  • Route IP traffic and create static routes

Using a Linux system as a router is nothing new - in fact many routers run some flavor of Linux. To perform this task you need a system with at least 2 interfaces (physical, virtual, or vlans) to route traffic through.

The base of the actions I will be performing are fromhttp://www.linuxhomenetworking.com/wiki/index.php/Quick_HOWTO_:_Ch03_:_Linux_Networking

SCENARIO:
RHEL6 server with 2 interfaces: eth0 and eth1. eth0 is configured with address 192.168.10.1/24, eth1 is configured with address 192.168.20.1/24. Hosts on either segment will use this this server as their default gateway in order to access resources on the other segment.

STEP 1: Enable IP Forwarding
Edit /etc/sysctl.conf and find the line net.ipv4.ip_forward = 0
Change the value of this line to 1, save and exit the file
Execute sysctl -p to reload the file (or simply reboot)

STEP 2: Enable firewall to forward packets
Use the iptables command to enable forwarding of specific packets and traffic type.
example: Enable ICMP by executing iptables -I FORWARD -p icmp -s 192.168.0.0/16 -d 192.168.0.0/16 -j ACCEPT
When things are confirmed to be working, save the firewall rules so they reapply during a reboot by executingiptables-save > /etc/sysconfig/iptables

#netstat -rn
#route -n

#route add -net 10.40.206.0 netmask 255.255.254.0 gw 10.40.204.3 dev eth0
#ip route add 10.40.206.0/23 via 10.40.204.3 dev eth0

to make the route permanent create /etc/sysconfig/network-scripts/route-eth0 with the entries

  • Use iptables to implement packet filtering and configure network address translation (NAT)
Assuming you know basic networking, routing, and firewalling, basic packet filtering in RHEL is fairly easy. While you can get quite complex with solutions, all we are worrying about here is basic filtering.

Packet filtering in RHEL6 is controlled using a program called iptables. You can find the syntax for managing the tables by running iptables -h, or for more detail use man iptables. You can view the currently implemented rules by running iptables -L, or by viewing the file /etc/sysconfig/iptables (these are the rules loaded at startup). Viewing the /etc/sysconfig/iptables file is probably the easiest way to understand the syntax needed to add/modify the rules.

Configuring NAT
NAT'ing is similar to the process of setting up routing, except the firewall rules are different. Here I will be using the information from http://www.revsys.com/writings/quicktips/nat.html as a basis for the below steps.
SCENARIO:  Your server has 2 network cards: eth0 and eth1. The external network (internet) is connected to eth0, and the internal network is connected to eth1. You want all hosts from eth1 to be able to access resources on eth0 via a NAT'ed connection.


STEP 1: Enable IP Forwarding
Edit /etc/sysctl.conf and find the line net.ipv4.ip_forward = 0
Change the value of this line to 1, save and exit the file
Execute sysctl -p to reload the file (or simply reboot)

STEP 2: Enable Masquerading
Execute the following commands to enable Masquerading (NAT'ing)
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT

Execute iptables-save > /etc/sysconfig/iptables to save the rules

  • Use /proc/sys and sysctl to modify and set kernel run-time parameters
cat /etc/sysctl.conf
cat /proc/sys

sysctl -a

sysctl -p

sysctl -w net.ipv4.icmp_echo_ignore_all=1

edit /etc/sysctl.conf and add the line for persistent value

cat /proc/sys/net/ipv4/icmp_echo_ignore_all

echo 0 > /proc/sys/net/ipv4/icmp_echo_ignore_all 


In its simplest form, this is a fairly straight forward task. If you view the file /etc/sysctl.conf, you will see several attributes with their appropriate values, these are the values applied at startup.
This file can be edited directly with a text editor, then the values reloaded by executing sysctl -p

These values can also be changed at runtime by modifying the values under /proc/sys. For instance, in/etc/sysctl.conf there is an attribute named net.ipv4.ip_forward, this attribute can also be viewed or modified as /proc/sys/net/ipv4/ip_forward.
To view the running value, run cat /proc/sys/net/ipv4/ip_forward
To change the running value, run echo 1 > /proc/sys/net/ipv4/ip_forward

The kernel attributes and values available to change can be found by either browsing the /proc/sys folders, or by running sysctl -a
  • Configure system to authenticate using Kerberos

This is a new objective to RHEL6, previously the objective was to setup NIS. Apparently they realized that nobody uses NIS any more and updated the requirements.
Personally, I have been using a tool called Likewise Open (http://www.likewise.com/products/likewise_open/) that enables Linux systems to join an AD domain. Since I doubt this is the solution RedHat is looking for, its back to the books for this one.
STEP 1: Ensure all packages are installed
For this to work properly, you need the kerberos and samba package both installed
yum install krb5-server pam_krb5 samba samba-common samba-winbind samba-client samba-winbind-clients

STEP 2: Configure the system to authenticate
Execute system-config-authentication and choose winbind for the account database
For security model, select ads
Under winbind domain, enter the short-name for the domain (i.e. without the .com)
Under ADS Realm, enter the FQDN of the domain
Under Domain Controllers, enter your preferred domain controller
Select a desired shell template
Click Join Domain and enter the credentials

STEP 3: Confirm
Log out of the system and attempt to log in using domain\user as the username

NOTE: This may be all wrong. I cant find any specific details on what redhat is looking for here (i.e. kerberos authentication via winbind)
  • Build a simple RPM that packages a single file
This is an interesting objective - something that I have never had to do before. After looking around at various tutorials and such, the wording of the objective is even more confusing - RPM packages are designed to install programs, not just copy a file. For example, there is a great how-to for creating RPM packages athttp://fedoraproject.org/wiki/PackageMaintainers/CreatingPackageHowTo.

A few days looking and I actually came upon a need to create a package - I want to have a silent install of Linux in our datacenter that copies custom scripts to the systems. The best way to handle this would of course be to build an RPM package that included just the one script. A little Googling and bingo! http://lincgeek.org/blog/?p=303 has just the information I needed on how to package a single file and direct it to install into a specific location.

STEP 1: Install the necessary packages
Each site you go to says something different, but it appears that the rpmdevtools contains all you need -- yum install rpmdevtools

STEP 2: Setup the folder structure
mkdir -pv rpm/{BUILD,RPMS,SOURCES,SPECS,SRPMS,tmp}

STEP 3: GZip the source file
Assuming you have a script named HelloWorld.sh

  1. Move to the rpm/SOURCES folder
  2. Make a temporary directory with a '-1' at the end -- mkdir HelloWorld-1
  3. GZip the source -- tar czvf HelloWorld-1.tar.gz HelloWorld-1/
STEP 4: Create the spec file
This is the hard part - configuring the RPM on what to build, install, and configure. A sample spec file can be created by running rpmdev-newspec SPECS/HelloWorld.spec, but there is still a lot to add and remove to make this work.
Below is a spec file I created using the sample file
Name:           RandomRootPass
Version:        1
Release:        1%{?dist}
Summary:        Random Root Password changer

Group:          Misc
License:        GPL
#URL:            http://localhost
Source0:        RandomRootPass-1.tar.gz
BuildArch:      noarch
BuildRoot:      %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)


#BuildRequires:
#Requires:

%description
Script to reset the root password to a random value

%prep
%setup -q


%build


%install
#rm -rf $RPM_BUILD_ROOT
#make install DESTDIR=$RPM_BUILD_ROOT
install -m 0755 -d $RPM_BUILD_ROOT/opt/RandomRootPass
install -m 0755 RandomRootPass.pl $RPM_BUILD_ROOT/opt/RandomRootPass/RandomRootPass.pl


%clean
#rm -rf $RPM_BUILD_ROOT


%files
%dir /opt/RandomRootPass
/opt/RandomRootPass/RandomRootPass.pl

#%defattr(-,root,root,-)
#%doc



#%changelog


STEP 5: Build the RPM
Once the spec file is complete, build the package with rpmbuild -qa SPECS/HelloWorld.spec. Assuming no errors occurred, your package is under the RPMS folder. Otherwise attempt to decipher the errors and try again.
  • Configure a system as an iSCSI initiator that persistently mounts an iSCSI target
Wonderful iSCSI - the cheap mans method of SAN connectivity. A quick update on terminology - iSCSI initiator is the client who initiates the connection, iSCSI target is the server providing the storage.

The first thing to do is setup an iSCSI target - this is not a role provided by redhat out of the box, and the exam objective doesnt seem to state that it is expected. The easiest method I have seen of setting up a target is to use openfiler (http://www.openfiler.com/) its a quick install and a fairly easy configuration. There is a nice walkthrough at http://www.techhead.co.uk/how-to-configure-openfiler-v23-iscsi-storage-for-use-with-vmware-esxthat details how to setup the filer for iscsi.

Once setup, we now need to configure the iSCSI initiator. There is a great article on doing this athttp://www.cyberciti.biz/tips/rhel-centos-fedora-linux-iscsi-howto.html

STEP 1: Install necessary packages
yum install iscsi-initiator-utils
service start iscsi

STEP 2: Configure initiator
Execute iscsiadm -m discoverydb -t sendtargets -p 192.168.10.1 -D to perform the discovery
Use fdisk to view all partitions and identify the new disk fdisk -l (should be something like /dev/sdb)
Use fdisk to create a partition, then execute mkfs.ext4 /dev/sdb1 to format it as ext4

STEP 3: Make the disk mount persistent
Execute chkconfig iscsi on
Because the device name can change between reboots, redhat suggests to mount the partition by using the UUID, execute ls -l /dev/disk/by-uuid, to find the uuid of the new disk
Edit /etc/fstab to configure the disk to mount on startup (should already be an example for /boot)
  • Produce and deliver reports on system utilization (processor, memory, disk, and network)
sar appears to be the tool to save the day here. Installed and running by default, the sysstat package contains tools that capture system performance throughout the day, and automatically summarizes it for you. Generating utilization reports is then a simple matter of knowing the right sar command to execute. If all else fails, simply try man sar

  • Processor
    • Basic processor report: sar or sar -u
    • Basic report every second for the next 10 seconds: sar 1 10
    • Load average: sar -q
    • Per processor statistics: sar -P ALL
    • Power management (not enabled by default): sar -m
  • Memory
    • Kernel paging: sar -B
    • Unused memory: sar -r
    • Swap space: sar -S
  • Disk
    • Disk IO stats (avg): sar -b
    • Disk IO stats: sar -d (-p to use pretty names)
  • Network
    • Network statistics: sar -n DEV
    • Network errors: sar -n EDEV
  • Everything
    • All reports simultaneously: sar -A
  • Use shell scripting to automate system maintenance tasks
This objective is quite a bit more ethereal than the others - with no clear end game, this could mean almost anything. With that in mind, here are a few of the very basic scripts that I have found to assist in automating management. A good place to find help is the man bash page


  • Doing something to each file in a directory
    •  for i in [`ls`]; do echo $i; done
  • Doing something for each line in a file
    •  while read i; do echo $i; done < anaconda-ks.cfg
  • Repeating a task every 10 seconds
    • while true; do echo Hello World; sleep 10; done
  • Create a task that occurs the same time every day
    • crontab -e
    • Enter 1 22 * * * echo Hello World
  • Create a task that occurs once at a specific time/day
    • at 10pm Dec 31 [return]
    • echo Hello World [return]
    • [CTRL]+z
  • Creating an executable script
    • Identify a working set of bash commands and save them to a file
    • Add a #!/bin/bash as the first line (not required, but good form)
    • Execute chmod +x foo.sh to make it executable
http://www.linuxconfig.org/Bash_scripting_Tutorial is a great basic overview of bash scripting. Note that all these commands may work differently in a different shell.

  • Configure a system to log to a remote system
  • Configure a system to accept logging from a remote system
In prior releases of redhat, remote logging was configured via syslogd. In RHEL6, this is replaced with rsyslog.

The first step is to setup a remote server to receive the logging messages, http://www.rsyslog.com/receiving-messages-from-a-remote-system/ has a great walkthrough on setting this up.

  1. Edit /etc/rsyslog.conf an clear the # before the lines allowing syslog reception
    1. $ModLoad imudp.so
    2. $UDPServerRun 514
    3. $ModLoad imtcp.so
    4. $InputTCPServerRUN 514
  2. Restart the rsyslog daemon - service rsyslog restart
  3. Open the firewall to allow syslog connections
    1. iptables -I INPUT -p tcp --dport 514 -j ACCEPT
    2. iptables -I INPUT -p udp --dport 514 -j ACCEPT
    3. iptables-save > /etc/sysconfig/iptables
The next step is to configure the local system to send messages, http://www.rsyslog.com/sending-messages-to-a-remote-syslog-server/ has a great walkthrough on setting this up
  1. Edit /etc/rsyslog.conf and enter the below line (using the appropriate IP or DNS name)
    1. *.*   @@192.168.10.1:514
  2. Restart the rsyslog daemon - service rsyslog restart
Test the configuration by running logger -p warn foo. This will log a message in the local /var/log/messagesand should log a similar message at the same location on the remote server

Network Services

Network services are an important subset of the exam objectives. RHCE candidates should be capable of meeting the following objectives for each of the network services listed below:
  • Install the packages needed to provide the service
  • Configure SELinux to support the service
  • Configure the service to start when the system is booted
  • Configure the service for basic operation
  •  Configure host-based and user-based security for the service
RHCE candidates should also be capable of meeting the following objectives associated with specific services:


HTTP/HTTPS


apachectl start
apachectl stop

  • Configure a virtual host
HTTP virtual hosts allow a single web server to act like multiple web servers, either by publishing to multiple IPs and ports, or by publishing multiple sites and identifying them by name. This feature allows you to publish http://foo.example.com and http://bar.example.com from the same host with a single address, and the server returns the appropriate information based on the site name the customer has typed in.


STEP 1: Create directories to hold the content
cd /var/www
mkdir foo
mkdir bar
echo foo > foo/index.html
echo bar > bar/index.html

STEP 2: Create virtual directories
vi /etc/http/conf/httpd.conf
uncomment the line NameVirtualHost *:80
copy the last 7 lines twice, remove the # at the beginning
edit the DocumentRoot and ServerName lines to match your new directories
Save the file and execute service httpd restart
Test

  • Configure private directories
At first glance, this objective can mean 2 things: allowing users to setup public_html directories, or securing directories with configuration files or .htaccess. A great page detailing the setup of HTTP can be found athttp://www.brennan.id.au/13-Apache_Web_Server.html

public_html
edit the /etc/httpd/conf/httpd.conf and find the line UserDir disabled. Comment out this line, and uncomment the line UserDir public_html.
Restart the web server - service httpd restart
NOTE: There may be multiple layers of security blocking access including folder, file and selinux restrictions.
Specifically, ensure the apache user has access to the home and public_html directories, as well as all files under the public_html directory. Additionally, run setsebool -P httpd_enable_homedirs true

Securing directories
edit the /etc/httpd/conf/httpd.conf file


        AuthType Basic
        AuthName "Private area - authorization required"
        AuthUserFile /etc/httpd/conf/authusers
        Require valid-user
Add users to the authusers file - htpasswd /etc/httpd/conf/authusers username
Restart the web server - service httpd restart
Access should now be restricted to username

.htaccess
This is traditionally used to restrict access to public_html directories since the average user doesnt have access to edit the httpd.conf file.
In the target folder, touch 2 files: .htaccess and .htauthusers
Edit .htaccess and enter the following (note the AuthUserFile appears to need a fully qualified path)
AuthType Basic
AuthName "Private Area"
AuthUserFile /home/username/public_html/private/.htauthusers
Require valid-user
Execute htpasswd .htauthusers username
Access should now be restricted to user username
  • Deploy a basic CGI application
The default apache configuration allows execution of CGI scripts in the /var/www/cgi-bin/ directory. This is controlled by the ExecCGI option for a specified directory. A good reference for this is athttp://www.brennan.id.au/13-Apache_Web_Server.html#cgi

An example of this is below



    Options ExecCGI
    SetHandler cgi-script

Once a script is included in the target directory, it will begin to respond as an executable. A sample cgi script is below to test with, more can be found online with a simple search
helloworld.cgi
#!/usr/bin/perl
print "Content-Type: text/plain", "\n\n";
print "Hello World in Perl", "\n";
  • Configure group-managed content


  • Install the packages needed to provide the service
use :

yum install httpd

or

rpm -ivh httd*x
  • Configure SELinux to support the service
#sestatus -b | grep httpd

to change the selinux boolean use

#setsebool httpd_use_cifs=1

add the following line to /etc/sysconfig/iptables file to allow the http traffic
-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
  • Configure the service to start when the system is booted
chkconfig httpd on
  • Configure the service for basic operation

  • Configure host-based and user-based security for the service

DNS

  • Configure a caching-only name server
  • Configure a caching-only name server to forward DNS queries
There is a good walkthrough of setting up a chaching nameserver athttp://www.redhat.com/magazine/025nov06/features/dns/

Install the needed components yum install bind bind-utils bind-libs bind-chroot caching-nameserver

copy /etc/named.conf to /var/named/chroot/etc/
edit /var/named/chroot/etc/named.conf

  • Change listen-on port from 127.0.0.1; to any;
  • Change allow-query from localhost; to any;
  • Add forwarders { 1.2.3.4; 5.6.7.8; }; and forward only; to the options section
Restart dns - service named restart
Edit /etc/resolve.conf to use the local DNS server
  • Note: Candidates are not expected to configure master or slave name servers

FTP

  • Configure anonymous-only download
Enabling anonymous-only download appears to be enabled by default, so I am not sure why this is an objective. Below are the steps needed in case it isnt in the future.

  1. Install packages - yum install vsftpd ftp
  2. Edit /etc/vsftpd/vsftpd.conf
    1. Find the line anonymous_enabled and set it to YES
    2. Ensure anon_upload_enabled is set to NO
  3. Restart ftp - service vsftpd restart

NFS

  • Provide network shares to specific clients
estricting access to NFS shares can be done by restricting firewall access (iptables), or by configuring the/etc/exports file. The /etc/exports file can restrict access to a single machine, a wildcard, or an IP network.
It all starts with installing and starting NFS

  • yum install nfs-utils rpcbind
  • service nfs start
  • service rpcbind start
Restricting to a single machine (can be exported to an IP or hostname)
  • Edit /etc/exports
  • Configure the export command like the following
    • /media 192.168.10.10(rw,no_root_squash)
  • Restart the service - service nfs restart
Restricting to a wildcard -- this allows exporting to a name or IP address with wildcards
  • Edit /etc/exports
  • Configure the export command like the following
    • /media *.example.com(rw,no_root_squash)
    • or /media 192.168.*10(rw,no_root_squash)
  • Restart the service - service nfs restart
 Restricting to an IP network -- this allows exporting to an entire subnet, or group of addresses
  • Edit /etc/exports
  • Configure the export command like the following
    • /media 192.168.10.0/24(rw,no_root_squash)
  • Restart the service - service nfs restart
  • Provide network shares suitable for group collaboration
Restricting access to NFS shares can be done by restricting firewall access (iptables), or by configuring the/etc/exports file. The /etc/exports file can restrict access to a single machine, a wildcard, or an IP network.
It all starts with installing and starting NFS

  • yum install nfs-utils rpcbind
  • service nfs start
  • service rpcbind start
Restricting to a single machine (can be exported to an IP or hostname)
  • Edit /etc/exports
  • Configure the export command like the following
    • /media 192.168.10.10(rw,no_root_squash)
  • Restart the service - service nfs restart
Restricting to a wildcard -- this allows exporting to a name or IP address with wildcards
  • Edit /etc/exports
  • Configure the export command like the following
    • /media *.example.com(rw,no_root_squash)
    • or /media 192.168.*10(rw,no_root_squash)
  • Restart the service - service nfs restart
 Restricting to an IP network -- this allows exporting to an entire subnet, or group of addresses
  • Edit /etc/exports
  • Configure the export command like the following
    • /media 192.168.10.0/24(rw,no_root_squash)
  • Restart the service - service nfs restart

SMB

  • Provide network shares to specific clients
Setting up samba is always fun. Laden with landmines between the Windows and Linux world, everytime you think you have a working solution, it flakes out on you. Here are the steps needed to add an SMB share to specific clients.

  1. Install samba 
    1. yum install samba-client samba-common samba
  2. Configure the /etc/samba/samba.conf file
    1. Find the line workgroup and set the correct workgroup name
    2. At the end of the file, create a new directory block using the same syntax as the others. This example will create a share named "foo" that is only accessible by user "foo"
      1. # foo
      2. [foo]
      3. path = /foo
      4. writeable = yes
      5. browseable = yes
      6. valid users = foo
  3. Save the file and restart the services -- service smb restart, service nmb restart
  4. Make sure the user "foo" exists, and set the samba password - smbpasswd -a foo
  • Provide network shares suitable for group collaboration
Configuring SMB shares for groups is very similar to sharing for an individual. The only gotcha here is making sure security on the folder are set properly.
Scenario: You have a group named group1, users foo and bar are members of this group. You need to share a directory named /group1 to these users only.


  1. Install samba
    1. yum install samba-client samba-common samba
  2. Configure the /etc/samba/samba.conf file
  3. Find the line workgroup and set the correct workgroup name
  4. At the end of the file, create a new directory block using the same syntax as the others. Note the use of the +group1 for valid users, this identifies it as a group instead of a user
    1.  #group1
    2. [group1]
    3. path = /group1
    4. writeable = yes
    5. browseable = yes
    6. valid users = +group1
  5. Save the file and restart the services -- service smb restart, service nmb restart
  6. Ensure the folder being shared is owned by the group
    1. chown root:group1 /group1
  7. Ensure the file permissions allow the group to read/write
    1. chmod 775 /group1 -R

SMTP

  • Configure a mail transfer agent (MTA) to accept inbound email from other systems
This is a simple one, by default postfix will accept only mail originating locally, and all it takes is updating a config file to change that.

  1. Install the necessary packages
    1. yum install postfix 
  2. Edit the /etc/postfix/main.cf file
    1. Find the line inet_interfaces = localhost and change it to inet_interfaces = all
  3. Restart the service
    1. service postfix restart
  4. Open the firewall
    1. iptables -I INPUT -p tcp --dport 25 -j ACCEPT
You should be able to test this by telnetting from a remote computer. If you receive a connection, your good to go.
  • Configure an MTA to forward (relay) email through a smart host
This is a simple one, similar to defaulting to accept mail locally, by default postfix will only send mail to local recipients.


  1. Install the necessary packages
    1. yum install postfix 
  2. Edit the /etc/postfix/main.cf file
    1. Find the relayhost section and add a line relayhost = 192.168.10.1
  3. Restart the service
    1. service postfix restart
You should be able to test this by sending an email to a remote user.

SSH

  • Configure key-based authentication
One of my favorite things to do when managing Linux systems is to configure key-based authentication. This allows me to connect to multiple systems via scripts without have to re-authenticate every time. A decent walkthrough is available at http://linuxproblem.org/art_9.html
Scenario: You are user A on host A, and you want to log onto host B as user B

  1. As user A on host A, execute
    1. ssh-keygen -t rsa
  2. Echo out the contents of ~/.ssh/id_rsa.pub (save to clipboard or copy via ssh to host B)
  3. As user B on host b, make the .ssh directory if it doesnt already exist
    1. mkdir ~/.ssh
  4. Edit the file ~/.ssh/authorized_keys and enter the contents from id_rsa.pub
Your now done. Assuming all went well, user A on host A should be able to run ssh b@b and be automatically logged in
  • Configure additional options described in documentation

NTP

  • Synchronize time using other NTP peers
The easiest way to configure NTP is to use the GUI.

  1. On the top bar, right-click the time and select Preferences
  2. Click Time Settings and the Set System Time
  3. Check the box Synchronize date and time over the network
  4. Edit the list of NTP servers and click OK
Alternatively, you can execute system-config-date to go directly to step 3.

To perform the same via command line:
  1. Edit /etc/ntp.conf
    1. Configure 1 or more server lines like below
      1. server 0.rhel.pool.ntp.org
      2. or server 192.168.10.1
  2. Start the service
    1. service ntpd start
When all finished, make sure ntpd is set to start automatically for next reboot chkconfig ntpd on.
You can also perform a one-off sync by running ntpdate 192.168.10.1 (this only works if ntpd isnt running)

Tuesday, 1 February 2011

Installing Kernel Source Code in Red Hat/Centos Linux

If we want to install the full kernel source tree,

As root, install the packages rpm-build, redhat-rpm-config unifdef


[root@host]# yum install rpm-build redhat-rpm-config unifdef

As an ordinary user, not root, create a directory tree based on ~/rpmbuild:


[user@host]$ cd
[user@host]$ mkdir -p rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
[user@host]$ echo '%_topdir %(echo $HOME)/rpmbuild' > .rpmmacros

packages must not be built using root account

find the kernel source rpm in the repos and download the SRPM  and install the srpm


[user@host]$ rpm -i http://mirror.centos.org/centos/5/updates/SRPMS/kernel-2.6.18-194.32.1.el5.src.rpm 2>&1 | grep -v mockb

Now that the source rpm is installed, unpack and prepare the source files:


[user@host]$ cd ~/rpmbuild/SPECS
[user@host SPECS]$ rpmbuild -bp --target=`uname -m` kernel-2.6.spec 2> prep-err.log | tee prep-out.log

The value of  `uname -m` sets --target to the architecture of your current kernel.

The kernel source tree will now be found in the directory ~/rpmbuild/BUILD/

Using the above procedure we can install source for all the rpms.

References:


1) http://wiki.centos.org/HowTos/I_need_the_Kernel_Source

2) Build Custom Kernel http://wiki.centos.org/HowTos/Custom_Kernel

3) Build custom kernel modules http://wiki.centos.org/HowTos/BuildingKernelModules

4) RHEL 6 source rpms: http://ftp.redhat.com/pub/redhat/linux/enterprise/6Server/en/os/SRPMS/

5) Kernel Howto : http://www.faqs.org/docs/Linux-HOWTO/Kernel-HOWTO.html#AEN307

6) Kernel development guidance : http://jehurst.wordpress.com/2011/01/13/rhel-for-the-clueless-rpm/
                                                      http://www.osdever.net/tutorials/view/brans-kernel-development-tutorial






Thursday, 13 January 2011

Red Hat EX200 Objectives and solutions

I. Understand and Use Essential Tools

  • Access a shell prompt and issue commands with correct syntax
         Applications --> System Tools ---> Terminal
         or
         press function keys to access pseudo consoles to type commands
             shell prompt (command line) refers to the Linux command prompt whre we enter commands for execution.
              $ cal 2011


    • Use input-output redirection (>, >>, |, 2>, etc.)
           The BASH shell allows you to redirect input, output and error messages to allow programs and commands to read input from something other than the keyboard and send output and errors to something other than the terminal window.

    File Descriptor   
    Symbol
    Associated Digit   
    Descriptor     
     stdin
     <
     0
     Standard input   
     stdout
     >
     1
     Standard output   
     stderr
     >
     2
     Standard error
             Table: I/O/E Redirection Symbols
       
          Redirecting Standard Input
        
          $ mailx user2 < file1    ( Get input to mailx command from file1 file)

          Redirecting Standard Output

          $ sort file1 > sort.out   ( Redirect the output to sort.out file)     
          $ sort file1 >> sort.out  ( appent to output to sort.out file) 

         Redirecting Standard Error

         Error redirection sends any error messages generated to an alternate destination such as a file, instead of sending them to the terminal window. 

         $ find / -name core -print 2> /dev/null 

         Redirecting both Standard Output and Error

          $ ls /etc/ /cdr 1> testfile1 2>&1
          $ ls /etc/ /cdr &> testfile1
    • Use grep and regular expressions to analyze text
         grep (global regular expression print) searches contents of one or more specified files for a regular expression. If found, it prints every line containing the expression on the screen without changing the original file contents.


       
          for example, to search for the pattern "user1" in the /etc/passwd file:

           $ grep user1 /etc/passwd
            user1:x:501:501::/home/user1:/bin/bash
        
         to search for all the users beginning with user:


           $ grep "user*" /etc/passwd
           usbmuxd:x:113:113:usbmuxd user:/:/sbin/nologin
           saslauth:x:497:495:"Saslauthd user":/var/empty/saslauth:/sbin/nologin
           user1:x:501:501::/home/user1:/bin/bash
           user2:x:502:502::/home/user2:/bin/bash
         To search for all occurrences of the pattern "user1" in both the /etc/passwd and /etc/group files:

         $ grep user1 /etc/passwd /etc/group
        /etc/passwd:user1:x:501:501::/home/user1:/bin/bash
        /etc/group:user1:x:501:
        To display only the names of those files that contain the pattern "user1" from the specified file list use :

        $ grep -l  
       

    • Access remote systems using ssh and VNC
     check whether the required packages are installed. then we can use ssh and vnc as follows:

    $ ssh user@remotesystem

    we can either use vncviewer  in commandline and X windows session to connect to the vnc server running on remote systems.
    • Log in and switch users in multi-user runlevels
    log in using the username and passwords in runlevel 3 (in text mode) and graphically in run level 5
    • Archive, compress, unpack and uncompress files using tar, star, gzip, and bzip2

    star -xattr -H=exustar -c -f all_web.star public_html/ web_files/
    tar xvzf file.tar.gz
    tar cvzf file.tar.gz files
    
    
    gunzip patch-2.5.28.gz
    • Create and edit text files
    Use vi, nano, emacs, gedit etc  text editors
    • Create, delete, copy and move files and directories
    touch, mv, rm , mv , cp

    for directories use -r for recursive option
    • Create hard and soft links
    ln hardlink1 file1

    ln -s softlink1 file1
    • List, set and change standard ugo/rwx permissions
    ls -l or ll

    chmod

    numerics -- symbolic

    1 -- execute-- x

    2 -- write-- w

    4 -- read-- r
    • Locate, read and use system documentation including man, info, and files in /usr/share/doc .
      [Note: Red Hat may use applications during the exam that are not included in Red Hat Enterprise Linux for the purpose of evaluating candidate's abilities to meet this objective.]
    read the documentation accordingly using:

    man command
    info commnad
    and files in /usr/share/doc

    II. Operate Running Systems

    • Boot, reboot, and shut down a system normally
    power on the machine to boot it

    reboot command can be used to reboot the machine

    shutdown command with -h option to halt or -r option to reboot with time mostly 'now'

    • Boot systems into different runlevels manually
    init runlevel
    • Use single-user mode to gain access to a system
    init 1 or telinit 1

    at the boot time edit the grub menu and at the end of the kernel entry append 1 or S to boot into single user mode
    • Identify CPU/memory intensive processes, adjust process priority with renice, and kill processes
    ps aux

    ps -ef

    top

    kill 

    nice

    renice 
    • Locate and interpret system log files
    /var/log/messages

    /var/log/*


    • Access a virtual machine's console
    xm console

    virsh console

    virt-viewer
    • Start and stop virtual machines
    xm create < vm >

    xm destroy

    xm shutdown

    xm restart

    virsh option
    • Start, stop and check the status of network services
    /sbin/service status/start/stop/restart

    /etc/init.d/service status/start/stop/restart

    III. Configure Local Storage

    • List, create, delete and set partition type for primary, extended, and logical partitions 
    Use fdisk diskname and type m for help on the commands and use the neccesssary command

    for listing the partitions in fdisk: type p

    for creating a new partition: type n , select whether it should be primary/extended and  specify the required amount of space

    for creating the system id of a partition  in fdisk:  type t, and for help type L then select the required id such as 83 for linux  and 8e for Linux LVM etc. Then type w to save the changes to the partition table.

    Further we can create the required filesystem using 'mkfs.ext(x) partition' or use LVM tools for creating logical volumes accordingly then format with neccessary filesystem.

    • Create and remove physical volumes, assign physical volumes to volume groups, create and delete logical volumes
    to create a physical volume create a partition on the disk using fdisk utility as mentioned above and select the system id for the partition as 8e which is Linux LVM

    then use the following commands to create the logical volume groups:

    # pvcreate -v /dev/sda1 /dev/sda2
    # vgcreate -v -s 32 vg-testvm /dev/sda1 /dev/sda2
    # lvcreate -v -L 4g -n lv-home vg-testvm
    # lvcreate -v -L 2g -n lv-var vg-testvm
    to remove 
    # lvremove /dev/vg-testvm/lv-home
    # vgremove /dev/vg-testvm
    # pvremove /dev/sda1
    Use vgdisplay -v and lvdisplay -v to see your new creations and complete details. My own naming convention is to use "vg" to indicate a volume group, and "lv" for a logical volume. So you see the structure here: the volume group is your total LVM storage space, which is comprised of several physical disk partitions, and then you have to divide your volume group into logical groups, or even just one logical group.
    The -v switch turns on verbosity so you know what it's doing, and -s 32 creates physical extents that are 32 megabytes in size. Extents are often shrouded in mystery because no one bothers to explain them, but actually they're not mysterious at all. Physical extents are LVM's individual storage blocks, so the smallest possible size for a logical volume is a single extent. There is a maximum of 65,536 extents available per Linux kernel. The default size is 4 MB, which limits the maximum size of your volume group to about 256 GB. You can calculate a reasonable extent size by dividing the desired size of your volume by 65K. Extent sizes must be a power of 2, so round up to the next one and leave room for growth. Extent size doesn't affect performance, just your storage allocations. Extents are fixed when you create your volume group, so you can't change them later.
    You have to increase or decrease the size of your volumes according to your extents, so here we're limited to 32 MB increments. The maximum possible size of a logical volume for 2.6 kernels is 16 terabytes on 32-bit systems, and 8 exabytes on 64-bit systems.
    Now it's time to put filesystems and mountpoints on your logical volumes. Logical volumes are akin to physical disk partitions, so "lv-home" is going to be /home, and "lv-var" is /var:
    # mkfs.xfs /dev/vg-testvm/lv-home
    # mkfs.ext3 /dev/vg-testvm/lv-var
    You may use any filesystem you want. Now create your mountpoints, adjust permissions and ownership, and then create your /etc/fstab entries. You can use either the /dev names or UUIDs:
    /dev/vg-testvm/lv-home /home xfs defaults 0 2
    /dev/vg-testvm/lv-var /var ext3 defaults 0 2

    UUID=8d566d0e /dev/vg-testvm/lv-home /home xfs defaults 0 2
    UUID=681919d5 /dev/vg-testvm/lv-var /var ext3 defaults 0 2
    The UUIDs are truncated to conserve pixels. vgdisplay -v shows your UUIDs. Now you can reboot or manually mount your new logical volumes, and you're ready to start using them just like physical disk partitions.

    Increasing the Size of a Logical Volume

    Follow these steps to add a physical disk partition to an existing logical volume:
    # pvcreate -v /dev/sdb1
    # vgextend vg-testvm /dev/sdb1
    # lvextend -L+10G
    Then you must resize your filesystem using the resizing command specific to your filesystem. ReiserFS can be safely resized while mounted, and XFS must be mounted. Ext2/3 should be unmounted first:
    # umount /var
    # resize2fs -p /dev/vg-testvm/lv-var
    # mount /var
    The others look like this:
    # resize_reiserfs /dev/volumegroup/logical-volume
    # xfs_growfs /home
    ReiserFS uses the /dev name, and XFS uses the name of the mountpoint. JFS is rather complicated
    • Create and configure LUKS-encrypted partitions and logical volumes to prompt for password and mount a decrypted file system at boot
    The following procedure will reconfigure and format your /home. The procedure is for single-user computers or computers that are shared between trusted users.
    The following procedure will wipe all your existing data, so be sure to have a tested backup before you start. This also requires you to have a separate partition for /home (in my case that is /dev/VG00/LV_home). All the following must be done as root. Any of these steps failing means you must not continue until the step succeeded.

    Step-by-Step Instructions

    1. enter runlevel 1: telinit 1
    2. unmount your existing /home: umount /home
    3. if it fails use fuser to find and kill processes hogging /home: fuser -mvk /home
    4. verify /home is not mounted any longer: cat /proc/mounts | grep home
    5. fill your partition with random data: dd if=/dev/urandom of=/dev/VG00/LV_home
    You're looking at a process that takes many hours, but it is imperative to do this in order to have good protection against break-in attempts. Just let it run overnight.
    1. initialize your partition: cryptsetup --verbose --verify-passphrase luksFormat /dev/VG00/LV_home
    2. open the newly encrypted device: cryptsetup luksOpen /dev/VG00/LV_home home
    3. check it's there: ls -l /dev/mapper | grep home
    4. create a filesystem: mkfs.ext3 /dev/mapper/home
    5. mount it: mount /dev/mapper/home /home
    6. check it's visible: df -h | grep home
    7. add the following to /etc/crypttab: home /dev/VG00/LV_home none
    8. edit your /etc/fstab, removing the old entry for /home and adding /dev/mapper/home /home ext3 defaults 1 2
    9. verify your fstab entry: mount /home
    10. restore default SELinux security contexts: /sbin/restorecon -v -R /home
    11. reboot: shutdown -r now
    12. The entry into /etc/crypttab makes your computer ask your luks passphrase on boot.
    13. Log in as root and restore your backup.

    we can create encrypted partitions at the time of installation by selecting the option available and providing the passphrase
    • Configure systems to mount file systems at boot by Universally Unique ID (UUID) or label
    to check UUID use blkid command on the device or partition

    then edit the /etc/fstab file accordingly as follows:

    UUID=d39b074c-9d46-4eab-a116-38d1a751c6fb /                       ext4    defaults        1 1
    UUID=ded0bcce-2769-411d-8eaa-453233a5b9e4 /boot                   ext4    defaults        1 2
    UUID=31379ba4-dce7-43f2-8679-5488aff9e82b /home                   ext4    defaults        1 2
    UUID=1e4a6b5d-5d10-44d6-a5ff-334cdc63e4a4 /putty                  ext4    defaults        1 2
    UUID=951da975-f039-42d4-86d5-42875a3d8b70 swap                    swap    defaults        0 0

    • Add new partitions, logical volumes and swap to a system non-destructively
    create the partiontions, logical volumes and swap using the fdisk utitiliy and add them while unmounted  

    IV. Create and Configure File Systems

    • Create, mount, unmount and use ext2, ext3 and ext4 file systems
    • Mount, unmount and use LUKS-encrypted file systems
    • Mount and unmount CIFS and NFS network file systems

    • Configure systems to mount ext4, LUKS-encrypted and network file systems automatically
    add entries in /etc/fstab and /etc/crypttab files using the UUID's and dev mapper paths respectively
    • Extend existing unencrypted ext4-formatted logical volumes
    lvextend
    • Create and configure set-GID directories for collaboration

    • Create and manage Access Control Lists (ACLs)

    mount -t ext3 -o acl  
    
    For example:
    mount -t ext3 -o acl /dev/VolGroup00/LogVol02 /work
    
    Alternatively, if the partition is listed in the /etc/fstab file, the entry for the partition can include the acloption:
    LABEL=/work      /work       ext3    acl        1 2
    
    If an ext3 file system is accessed via Samba and ACLs have

    setfacl -m u:andrius:rw /project/somefile
    
    To remove all the permissions for a user, group, or others, use the -x option and do not specify any permissions:
    setfacl -x  
    
    For example, to remove all permissions from the user with UID 500:
    setfacl -x u:500 /project/somefile


    To set a default ACL, add d: before the rule and specify a directory instead of a file name.
    For example, to set the default ACL for the /share/ directory to read and execute for users not in the user group (an access ACL for an individual file can override it):

    To determine the existing ACLs for a file or directory, use the getfacl command. In the example below, thegetfacl is used to determine the existing ACLs for a file.
    getfacl home/john/picture.png
    
    The above command returns the following output:
    # file: home/john/picture.png 
    # owner: john 
    # group: john 
    user::rw- 
    group::r-- 
    other::r--
    

    If a directory with a default ACL is specified, the default ACL is also displayed as illustrated below.
    [john@main /]$ getfacl home/sales/
    # file: home/sales/ 
    # owner: john 
    # group: john 
    user::rw- 
    user:barryg:r-- 

    setfacl -m d:o:rx /share
    • Diagnose and correct file permission problems

    V. Deploy, Configure and Maintain Systems

    • Configure networking and hostname resolution statically or dynamically
    edit the files in 

    /etc/sysconfig/network-scripts/ifcfg-eth* 

    with neccessary options such as

    IPADDR, BOOTPROTO, NETMASK, NETWORK, BROADCAST, GATEWAY, ONBOOT, HWADDR etc

    Edit /etc/sysconfig/network  file for specifying the hostname

    hostname can be assigned using the hostname command temporarily

    Edit /etc/resolv.conf file and specify 

    search parameters and nameserver parameters accordingly

    • Schedule tasks using cron
    crontab -e for editing specific user crontab

    # Each task to run has to be defined through a single line
    # indicating with different fields when the task will be run
    # and what command to run for the task
    #
    # To define the time you can provide concrete values for
    # minute (m), hour (h), day of month (dom), month (mon),
    # and day of week (dow) or use '*' in these fields (for 'any').#
    # Notice that tasks will be started based on the cron's system
    # daemon's notion of time and timezones.
    #
    # Output of the crontab jobs (including errors) is sent through
    # email to the user the crontab file belongs to (unless redirected).
    #
    # For example, you can run a backup of all your user accounts
    # at 5 a.m every week with:
    # 0 5 * * 1 tar -zcf /var/backups/home.tgz /home/
    #
    # For more information see the manual pages of crontab(5) and cron(8)


    # minutes  hour  dayofmonthy month dayofweek   command

    • Configure systems to boot into a specific runlevel automatically
    edit /etc/inittab file and specify the runlevel at the bottom entry which looks like:

    id:3:initdefault:

    • Install Red Hat Enterprise Linux automatically using Kickstart
    PXE boot  (Install tftp which is a xinetd managed service  then configure tftpboot with pxelinux configuration and pxelinux images)

    share the kickstart file using either nfs/http 

    provide the following information in kickstart file

    • Configure a physical machine to host virtual guests
    • Install Red Hat Enterprise Linux systems as virtual guests
    • Configure systems to launch virtual machines at boot

    • Configure network services to start automatically at boot
    chkconfig service on
    • Configure a system to run a default configuration HTTP server
    • Configure a system to run a default configuration FTP server

    • Install and update software packages from Red Hat Network, a remote repository, or from the local filesystem
    rpm -ivh 

    rpm -e

    yum install 

    yum groupinstall

    yum remove

    /etc/yum/repos.d for configuring repositories

    • Update the kernel package appropriately to ensure a bootable system
    #yum -y update kernel

    # rpm -Uvh /var/yum/repos.d/kernel/kernel-2xxxx
    • Modify the system bootloader
    Edit  /bootgrub/grub.conf file to change the bootloader and its options

    VI. Manage Users and Groups

    • Create, delete, and modify local user accounts
    useradd
    userdel
    usermod
    id
    • Change passwords and adjust password aging for local user accounts
    passwd
    chage 'user'

    • Create, delete and modify local groups and group memberships
    usermod -a -G unixadm balaji

    groupadd

    groupmod

    gpasswd


    • Configure a system to use an existing LDAP directory service for user and group information
    Install the Necessary LDAP Packages.
    First, make sure that the appropriate packages are installed on both the LDAP server and the LDAP client machines. The LDAP server needs the openldap-servers package.
    The openldap, openldap-clients, and nss_ldap packages need to be installed on all LDAP client machines.
    Edit the Configuration Files.
    • On the server, edit the /etc/openldap/slapd.conf file on the LDAP server to make sure it matches the specifics of the organization. 
    • On the client machines, both /etc/ldap.conf and /etc/openldap/ldap.conf need to contain the proper server and search base information for the organization.
      To do this, run the graphical Authentication Configuration Tool (system-config-authentication) and select Enable LDAP Support under the User Information tab.
      It is also possible to edit these files by hand.
    • On the client machines, the /etc/nsswitch.conf must be edited to use LDAP.
      To do this, run the Authentication Configuration Tool (system-config-authentication) and selectEnable LDAP Support under the User Information tab.
      If editing /etc/nsswitch.conf by hand, add ldap to the appropriate lines.
      For example:
      
      passwd: files ldap 
      shadow: files ldap 
      group: files ldap

    VII. Manage Security

    • Configure firewall settings using system-config-firewall or iptables
    run system-config-firewall as root and select the required configuration if X windows is installed

    /etc/sysconfig/iptables file can be edited according to the rules. 
    • Set enforcing and permissive modes for SELinux
     we can either edit /etc/sysconfig/selinux or run system-config-selinux or
    use
    /usr/sbin/setenforce — Modifies in real-time the mode in which SELinux runs.
    For example:
    setenforce 1 — SELinux runs in enforcing mode.
    setenforce 0 — SELinux runs in permissive mode.
    To actually disable SELinux, you need to either specify the appropriate setenforce parameter in/etc/sysconfig/selinux or pass the parameter selinux=0 to the kernel, either in /etc/grub.conf or at boot time.
    • List and identify SELinux file and process context
    ll -Z 

    ps -ef -Z

    cp /mv -Z

    id -Z

    This section covers the specific roles enabled for the targeted policy. The unconfined_t type exists in every role, which significantly reduces the usefulness of roles in the targeted policy. More extensive use of roles requires a change to the strict policy paradigm, where every process runs in an individually considered domain.
    Effectively, there are only two roles in the targeted policy: system_r and object_r. The initial role is system_r, and everything else inherits that role. The remaining roles are defined for compatibility purposes between the targeted policy and the strict policy.[21]
    Three of the four roles are defined by the policy. The fourth role, object_r, is an implied role and is not found in policy source. Because roles are created and populated by types using one or more declarations in the policy, there is no single file that declares all roles. (Remember that the policy itself is generated from a number of separate files.)


    system_r
    This role is for all system processes except user processes:
    system_r (28 types)
        dhcpd_t
        httpd_helper_t
        httpd_php_t
        httpd_suexec_t
        httpd_sys_script_t
        httpd_t
        httpd_unconfined_script_t
        initrc_t
        ldconfig_t
        mailman_cgi_t
        mailman_mail_t
        mailman_queue_t
        mysqld_t
        named_t
        ndc_t
        nscd_t
        ntpd_t
        pegasus_t
        portmap_t
        postgresql_t
        snmpd_t
        squid_t
        syslogd_t
        system_mail_t
        unconfined_t
        winbind_helper_t
        winbind_t
        ypbind_t
    
    user_r
    This is the default user role for regular Linux users. In a strict policy, individual users might be used, allowing for the users to have special roles to perform privileged operations. In the targeted policy, all users run in the unconfined_t domain.
    object_r
    In SELinux, roles are not utilized for objects when RBAC is being used. Roles are strictly for subjects. This is because roles are task-oriented and they group together entities which perform actions (for example, processes). All such entities are collectively referred to as subjects. For this reason, all objects have the roleobject_r, and the role is only used as a placeholder in the label.
    sysadm_r
    This is the system administrator role in a strict policy. If you log in directly as the root user, the default role may actually be staff_r. If this is true, use the newrole -r sysadm_r command to change to the SELinux system administrator role to perform system administration tasks. In the targeted policy, the following retain sysadm_r for compatibility:
    sysadm_r (6 types)
        httpd_helper_t
        httpd_sys_script_t
        initrc_t
        ldconfig_t
        ndc_t
        unconfined_t
    
    There is effectively only one user identity in the targeted policy. The user_u identity was chosen becauselibselinux falls back to user_u as the default SELinux user identity. This occurs when there is no matching SELinux user for the Linux user who is logging in. Using user_u as the single user in the targeted policy makes it easier to change to the strict policy. The remaining users exist for compatibility with the strict policy.[22]
    The one exception is the SELinux user root. You may notice root as the user identity in a process's context. This occurs when the SELinux user root starts daemons from the command line, or restarts a daemon originally started by init.


    • Restore default file contexts
    chcon

    ex:  #chcon -R -t httpd_user_content_t public_html/
    # ls -Z


    restorecon

    Use the restorecon command to restore files to the default values according to the policy. There are two other methods for performing this operation that work on the entire file system: fixfiles or a policy relabeling operation
    ex: #/sbin/restorecon -R archives
    • Use boolean settings to modify system SELinux settings
    sestatus

    getsebool -a

    Use the getsebool command to get the current status of the boolean:

    [root@host2a ~]# getsebool named_disable_trans
    named_disable_trans --> off
    
    Use the following command to disable enforcing mode for this daemon:

    [root@host2a ~]# setsebool named_disable_trans 1
    
    [root@host2a ~]# getsebool named_disable_trans
    named_disable_trans --> on

    Use the following command to find which of these booleans are set:

    getsebool -a | grep disable.*on
    
    httpd_disable_trans=1
    mysqld_disable_trans=1
    ntpd_disable_trans=1
    
    You can set any number of boolean values using the setsebool command:

    setsebool -P httpd_disable_trans=1 mysqld_disable_trans=1 ntpd_disable_trans=1
    
    You can also use togglesebool  to change the value of a specific boolean:

    [root@host2a ~]# getsebool httpd_disable_trans
    httpd_disable_trans --> off
    
    [root@host2a ~]# togglesebool httpd_disable_trans
    httpd_disable_trans: active
    
    You can configure all of these settings using system-config-selinux. The same configuration files are used, so changes appear bidirectionally.
    • Diagnose and address routine SELinux policy violations
    his section describes some common tasks that a security analyst might need to perform on an SELinux system.

    44.3.1. Enabling Kernel Auditing

    As part of an SELinux analysis or troubleshooting exercise, you might choose to enable complete kernel-level auditing. This can be quite verbose, because it generates one or more additional audit messages for each AVC audit message. To enable this level of auditing, append the audit=1 parameter to your kernel boot line, either in the /etc/grub.conf file or on the GRUB menu at boot time.
    This is an example of a full audit log entry when httpd is denied access to ~/public_html because the directory is not labeled as Web content. Notice that the time and serial number stamps in the audit(...) field are identical in each case. This makes it easier to track a specific event in the audit logs:
    Jan 15 08:03:56 hostname kernel: audit(1105805036.075:2392892): \
     avc:  denied  { getattr } for  pid=2239 exe=/usr/sbin/httpd \
     path=/home/auser/public_html dev=hdb2 ino=921135 \
     scontext=user_u:system_r:httpd_t \
     tcontext=system_u:object_r:user_home_t tclass=dir
    
    The following audit message tells more about the source, including the kind of system call involved, showing that httpd tried to stat the directory:
    Jan 15 08:03:56 hostname kernel: audit(1105805036.075:2392892): \
     syscall=195 exit=4294967283 a0=9ef88e0 a1=bfecc0d4 a2=a97ff4 \
     a3=bfecc0d4 items=1 pid=2239 loginuid=-1 uid=48 gid=48 euid=48 \
     suid=48 fsuid=48 egid=48 sgid=48 fsgid=48
    
    The following message provides more information about the target:
    Jan 15 08:03:56 hostname kernel: audit(1105805036.075:2392892): \
     item=0 name=/home/auser/public_html inode=921135 dev=00:00
    
    The serial number stamp is always identical for a particular audited event. The time stamp may or may not be identical.

    Note

    If you are using an audit daemon for troubleshooting, the daemon may capture audit messages into a location other than /var/log/messages, such as /var/log/audit/audit.log. Red Hat Enterprise Linux 5 does not currently ship with an audit daemon.

    44.3.2. Dumping and Viewing Logs

    The Red Hat Enterprise Linux 5 implementation of SELinux routes AVC audit messages to /var/log/messages. You can use any of the standard search utilities (for example, grep), to search for lines containing avc or audit