Pages

Welcome to My Blog

This is to share my IT experience with friends all around the world.
I have been working in Linux Fedora Systems for more than 8 years. Its fun to share knowledge and learn..
As everyone knows when a problem arises in your systems "googling" is the way that many depend on..

All the posts here are my working experiences during my working life.. So you can count on it..

I have added the references where I got help in solving IT issues


Wednesday, February 29, 2012

Access Control in Apache with mod_authz_host and mod_access

In Apache web server, access to a website can be controlled to users in several ways. Enable user authentication is one such mechanism. User authentication can  be implemented in the site by it self with the PHP or any other language you used to develop the site OR server administrator can configure the web server to handle user authentication.


The directives provided by mod_authz_host are used to control access to particular parts of the server. From Apache 2.2, mod_access is renamed as mod_authz_host.

Access can be controlled based on the client hostname, IP address, or other characteristics of the client request, as captured in environment variables. The Allow and Deny directives are used to specify which clients are or are not allowed access to the server, while the Order directive sets the default access state, and configures how the Allow and Deny directives interact with each other.

It is done under the <Directory> directive with the AuthUserFile and AuthTypeThe format of a apache based authentication is as follows;


This will allow accesses for the contents in the settings folder to the users who has the login credentials in users_password_file
 
<Directory "/var/www/html/your-site/settings">
        AllowOverride AuthConfig FileInfo Indexes Limit Options
        AuthUserFile /etc/httpd/users/users_password_file
        SSLRequireSSL
        AuthName "Secure Users"
        AuthType Basic
        require valid-user
</Directory>

How you can allow accesses for the above folder from specific IP addresses. That is much easier. By just defining the 'allow from' parameter, it can be achieved.

Following given the format for that setup;

<Directory /var/www/html/your-site/settings> 
    Order Deny, Allow
    Deny from all
    Allow from aaa.bbb.ccc.dddd/netmask
</Directory>


I have used both control mechanisms, with password authentication and IP address filtering.


Thursday, January 5, 2012

Static Routers in Linux

Adding a static route in Linux is a basic but essential requirement. We need to do this in 2 situations.
One is just adding a static route to the Kernel's IP routing table through the command line. This is mainly for testing purposes.
The commands that  can be used are;
    1. ip route add
    2. route add

I have tested the second one 'route add' with following format.
    route add -net <destination_network_ipblock> netmask <subnet_mask> gw <gateway_interface_ip>
    e.g.    route add -net 192.168.2.0 netmask 255.255.255.0 gw 192.168.200.254

The above given example will add a route to 192.168.2.0/24 network via 192.168.200.254. The important thing here is, a route to 192.168.200.254 should already be installed in the Kernel's routing table (i.e. the server you are configuring static routes, should know how the communicate with 192.168.200.254)

More details related to the second method can be observed with 'man route' command;

The other situation is to install static routes permanently in to the kernel's routing table.
This can be achieved with static-route file.
I have used it in several servers. You need to create a file with the name 'static-routes' at /etc/sysconfig directory.

The static routes you with to apply should be given in line by line. Format of a routing line is as follows;
any net <destination_network_ipblock> netmask <subnet_mask> gw <gateway_interface_ip>
e.g
any net 192.168.2.0 netmask 255.255.255.0 gw 192.168.200.254

The example shows an entry related to the same routing described above.
When the OS is loading, this file will be executed and routing will be applied to the kernel.

Good reference:
http://www.cyberciti.biz/tips/configuring-static-routes-in-debian-or-red-hat-linux-systems.html

Monday, November 21, 2011

BIND Update Issue

We have experienced a specific issue when we try to upgrade the bind version (from current to latest) in BIND DNS servers. As we noticed the location of the executable binaries ( named, dns-key etc) is changed (i.e /usr/sbin OR /usr/local/sbin) depending on the way you installed bind.
(i.e. From RPMs/ yum OR install from the source code)

You can check the location using following command
 which named 

The output will be somewhat like /usr/sbin/named or /usr/local/sbin/named as mentioned above.

When you try to upgrade bind with source code, by default the executable location will be /usr/local/sbin and you will ended up with server failure when restart the service.


The solution is as follows
First you need to download the source code and untar it to your home directory

wget -b source_code_url 
tar -xzvf bind-9.x.x.tar.gz

If your executable location is /usr/sbin you have to compile the source code with following parameters
./configure --sbindir=/usr/sbin

Then issue make and make install commands to install the new version
make
make install

Check whether it has upgraded using named -v command
named -v

Now restart the service ( server named restart OR /etc/init.d/named restart)

Note: If you have a doubt about what you will get after the upgrade... tar your executable folder and keep as a backup. You can have your old version once you untar the contents in the backed up and replaced it.