Tuesday, 18 June 2013

Configure Squirrelmail Webmail Server on Linux.

Configure Squirrelmail Server with POP3/IMAP on Linux/CentOS
Package Requirements:
* Linux Server with Centos 5/6
* Apache 2 with PHP4 or later
* Postfix (SMTP server or MTA)
* Dovecot ( IMAP/POP3 server)
* Squirrelmail (A free Webmail)
We will be setting up the email server for local users where they can use
webmail or outlook express to access their email. We will be setting up a simple
and most basic mail server for local users.
Before we proceed to setup a mail server, the following 3 are most important
for delivering email to destination.
1. DNS Entry for your mail server with MX record
2. Setup an SPF record
3. Setup Domain Name Keys
4. Reverse IP for your Mail Server
The most important of it setting up reverse IP for your mail server. You have
to ask your hosting provider to setup a reverse IP for your mail server. 
Install Postfix (SMTP Server/MTA)
Postfix is fast and popular SMTP server and widely used. Its main job is to
relay mail locally or to intended destination outside the network.
By default Sendmail comes Pre-installed with Centos. We will need need to remove
it and install Postfix:
#yum remove sendmail
#yum install postfix
The configuration file is located at /etc/postfix/main.cf. 
Edit the file and make sure you change the following lines with your domain name:
myhost = mail.sumit.com
mydomain = sumit.com
myorigin = $mydomain
inet_interfaces = all
mydestination = $myhostname, $mydomain

we have to be careful about $mydestination is because it restrictions receiving
Setting up SASL + TLS
To enable SASL authentication open /etc/postfix/main.cf and
Install Dovecot (POP3/IMAP Server)
Look for the line auth default and make these changes. Becareful with the lines as they are heavily commented out:
Install Squirrelmail
Before you access Squirrelmail or Mail restart all the services:
To access squirrelmail point your browser to

emails by the server pertaining to domains.

We have to also setup SASL with our postfix to authenticate our users who want
to send email outside of the permitted network:
#yum install cyrus-sasl

add the following lines:
smtpd_sasl_auth_enable = yes
smtpd_reciptient_restrictions = permit_mynetworks,permit_sasl_authenticated,reject_unauth_destination
smtpd_sasl_security_options = noanonymous
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth

Dovecot is a very popular POP3/IMAP server. The main difference between POP3
and IMAP is while accessing the your email with outlook if you use POP3 the
mail is downloaded to your computer and deleted from the server. With IMAP the

mail is retained in the server. 
The configuration file is located at /etc/dovecot.conf
#yum install dovecot
Open the dovecot config file /etc/dovecot.conf and make the following changes. 
You may need to comment or uncomment certain lines:
protocols = imap imaps pop3 pop3s

auth default {
mechanisms = plain login
passdb pam {
}
userdb passwd {
}
socket listen {
clinet {
path = /var/spool/postfix/private/auth/
mode = 0660
user = postfix
group = postfix
}
}
}

Squirrelmail is a free webbased email can be very handy for your users to login

while they are mobile.
#yum install squirrelmail
To setup the squirrelmail under apache, open /etc/httpd/conf/httpd.conf:
and insert the following lines:
Alias /squirrelmail /usr/local/squirrelmail/www
<Directory /usr/local/squirrelmail/www>
Options Indexes
AllowOverride none
DirectoryIndexes index.php
Order allow,deny
allow from all
</Directory>

The squirrelmail configuration utility is located in /usr/share/squirrelmail/config/conf.pl:
Run the configuration utility and set the server settings to SMTP and change your domain name to sumit.com
/usr/share/squirrelmail/config/conf.pl

/etc/init.d/postfix start
/etc/init.d/dovecot start
/etc/init.d/saslauthd start
service httpd restart

http://www.sumit.com/webmail
and the squirrelmail test page is located at http://domain.com/webmail/src/configtest.php
Before we login to squirrelmail, you will need to create users:
Just create a localuser with adduser:
#adduser sumit
and update the password of sumit
# passwd sumit

Now open Squirrelmail server with the username & password.
For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.

Configure phpMyAdmin 4.2.11 on Linux.


 phpMyAdmin is a free software tool written in php, intended to handle the administration of MySQL over the web. phpMyAdmin supports a wide range of operations with MySQL. 

phpMyAdmin Installation on Linux:

(Note: First Install all the related files to run MySQL, php, Apache)

#yum install httpd*

#yum install php-mysql*
#yum install mysql-server

configure your Apache web server(if you have any problem regarding that you can look in my previous post "How to configure Apache or httpd Server")


check in the /etc/httpd/conf.d that there is php.conf file is present


start all the required services 


#service httpd start


#service mysqld start


#chkconfig httpd on


#chkconfig mysqld on


Download the latest version of  phpmyadmin Currently the stable version of phpMyAdmin is 4.2.11


After downloading it uncompressed it


#tar -xjvf php ....................... (depending upon the version u downloaded)


move this folder to your web directory in which your site is located and rename it as i have done php and open the configuration file, make changes to the settings so that you can access it via http:


#vi config.inc.php


make changes into line no. 73


73 $cfg['Servers'][$i]['auth_type']    ='http';     (enter http here in =''; line no. 73)


:wq            

(save and quite)

restart the httpd service and access it via web browser, inter in the address browser your IP/php to access.


#service httpd restart

in web browser your IP/php

If you had set any password for your mysql than use that other wise it will be blank


username: root


password: blank


If you want to know the username and password of your phpMyAdmin go to:


#vi config.inc.php


and see in line no. 74 & 75 - 


74   $cfg['Servers'][$i]['user']       ='root';              (MySQL user)


75   $cfg['Servers'][$i]['password']   ='';                 (MySQL password)


For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.

Friday, 7 June 2013

Configure ftp Server on Linux.

Though the steps provided here are tested in CentOS 6.5, it should work on RHEL and Scientific Linux 6.x too. In this blog my ftp server IP and hostname are 192.168.21.10 and sumit.com respectively. 

Before proceed, stop the firewall.

[root@sumit.com ~]# service iptables stop
iptables: Flushing firewall rules:                         [  OK  ]
iptables: Setting chains to policy ACCEPT: filter          [  OK  ]
iptables: Unloading modules:                               [  OK  ]
[root@sumit.com ~]# service ip6tables stop
ip6tables: Flushing firewall rules:                        [  OK  ]
ip6tables: Setting chains to policy ACCEPT: filter         [  OK  ]
ip6tables: Unloading modules:                              [  OK  ]
[root@sumit.com ~]# chkconfig iptables off
[root@sumit.com ~]# chkconfig ip6tables off
[root@sumit.com ~]# 

Now let us install FTP service.

[root@sumit.com ~]# yum install -y vsftpd
[root@sumit.com ~]# Start vsftpd service.
[root@sumit.com ~]# service vsftpd start
Starting vsftpd for vsftpd:                                [  OK  ]
[root@sumit.com ~]# 

Enable vsftpd in multi-user levels.

[root@sumit.com ~]# chkconfig vsftpd on
Now edit the /etc/vsftpd/vsftpd.conf file. 
Uncomment and edit the lines in the vsftpd.conf file which are shown in bold.

[root@sumit.com ~]# cat /etc/vsftpd/vsftpd.conf 

# Example config file /etc/vsftpd/vsftpd.conf
#
# The default compiled in settings are fairly paranoid. This sample file
# loosens things up a bit, to make the ftp daemon more usable.
# Please see vsftpd.conf.5 for all compiled in defaults.
#
# READ THIS: This example file is NOT an exhaustive list of vsftpd options.
# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's
# capabilities.
#
# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
anonymous_enable=NO
#
# Uncomment this to allow local users to log in.
local_enable=YES
#
# Uncomment this to enable any form of FTP write command.
write_enable=YES
#
# Default umask for local users is 077. You may wish to change this to 022,
# if your users expect that (022 is used by most other ftpd's)
local_umask=022
#
# Uncomment this to allow the anonymous FTP user to upload files. This only
# has an effect if the above global write enable is activated. Also, you will
# obviously need to create a directory writable by the FTP user.
#anon_upload_enable=YES
#
# Uncomment this if you want the anonymous FTP user to be able to create
# new directories.
#anon_mkdir_write_enable=YES
#
# Activate directory messages - messages given to remote users when they
# go into a certain directory.
dirmessage_enable=YES
#
# The target log file can be vsftpd_log_file or xferlog_file.
# This depends on setting xferlog_std_format parameter
xferlog_enable=YES
#
# Make sure PORT transfer connections originate from port 20 (ftp-data).
connect_from_port_20=YES
#
# If you want, you can arrange for uploaded anonymous files to be owned by
# a different user. Note! Using "root" for uploaded files is not
# recommended!
#chown_uploads=YES
#chown_username=whoever
#
# The name of log file when xferlog_enable=YES and xferlog_std_format=YES
# WARNING - changing this filename affects /etc/logrotate.d/vsftpd.log
#xferlog_file=/var/log/xferlog
#
# Switches between logging into vsftpd_log_file and xferlog_file files.
# NO writes to vsftpd_log_file, YES to xferlog_file
xferlog_std_format=YES
#
# You may change the default value for timing out an idle session.
#idle_session_timeout=600
#
# You may change the default value for timing out a data connection.
#data_connection_timeout=120
#
# It is recommended that you define on your system a unique user which the
# ftp server can use as a totally isolated and unprivileged user.
#nopriv_user=ftpsecure
#
# Enable this and the server will recognise asynchronous ABOR requests. Not
# recommended for security (the code is non-trivial). Not enabling it,
# however, may confuse older FTP clients.
#async_abor_enable=YES
#
# By default the server will pretend to allow ASCII mode but in fact ignore
# the request. Turn on the below options to have the server actually do ASCII
# mangling on files when in ASCII mode.
# Beware that on some FTP servers, ASCII support allows a denial of service
# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd
# predicted this attack and has always been safe, reporting the size of the
# raw file.
# ASCII mangling is a horrible feature of the protocol.
ascii_upload_enable=YES
ascii_download_enable=YES
#
# You may fully customise the login banner string:
ftpd_banner=Welcome to OSTECHNIX FTP service.
#
# You may specify a file of disallowed anonymous e-mail addresses. Apparently
# useful for combatting certain DoS attacks.
#deny_email_enable=YES
# (default follows)
#banned_email_file=/etc/vsftpd/banned_emails
#
# You may specify an explicit list of local users to chroot() to their home
# directory. If chroot_local_user is YES, then this list becomes a list of
# users to NOT chroot().
#chroot_local_user=YES
#chroot_list_enable=YES
# (default follows)
#chroot_list_file=/etc/vsftpd/chroot_list
#
# You may activate the "-R" option to the builtin ls. This is disabled by
# default to avoid remote users being able to cause excessive I/O on large
# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
# the presence of the "-R" option, so there is a strong case for enabling it.
ls_recurse_enable=YES
#
# When "listen" directive is enabled, vsftpd runs in standalone mode and
# listens on IPv4 sockets. This directive cannot be used in conjunction
# with the listen_ipv6 directive.
listen=YES
#
# This directive enables listening on IPv6 sockets. To listen on IPv4 and IPv6
# sockets, you must run two copies of vsftpd with two configuration files.
# Make sure, that one of the listen options is commented !!
#listen_ipv6=YES
pam_service_name=vsftpd
userlist_enable=YES
tcp_wrappers=YES
use_localtime=YES

Now let us restart the vsftpd service and try to connect to ftp server.
[root@sumit.com ~]# service vsftpd restart
Shutting down vsftpd:                                      [  OK  ]
Starting vsftpd for vsftpd:                                [  OK  ]
Connect to the ftp server

Note: Root is not allowed to connect to ftp server by default for security purpose. So lets us create a new user called ftpuser

[root@sumit.com ~]# useradd ftpuser
[root@sumit.com ~]# passwd ftpuser
Changing password for user ftpuser.
New password: 
BAD PASSWORD: it is based on a dictionary word
Retype new password: 
passwd: all authentication tokens updated successfully.

Connet to FTP server using the new user ftpuser.
[root@sumit.com ~]# ftp 192.168.21.10
-bash: ftp: command not found
[root@sumit.com ~]# 

Oops! ftp package is not installed. So let us install ftp package first.

[root@sumit.com ~]# yum install -y ftp
Loaded plugins: fastestmirror
Loading mirror speeds from cached hostfile
Setting up Install Process
Resolving Dependencies
--> Running transaction check
---> Package ftp.i686 0:0.17-51.1.el6 will be installed
--> Finished Dependency Resolution
Dependencies Resolved
================================================================================
 Package       Arch           Version                 Repository           Size
================================================================================
Installing:
 ftp           i686           0.17-51.1.el6           localrepo            55 k
Transaction Summary
===============================================================================================
Install       1 Package(s)
Total download size: 55 k
Installed size: 91 k
Downloading Packages:
Running rpm_check_debug
Running Transaction Test
Transaction Test Succeeded
Running Transaction
Warning: RPMDB altered outside of yum.
  Installing : ftp-0.17-51.1.el6.i686                                       1/1 
  Verifying  : ftp-0.17-51.1.el6.i686                                       1/1 
Installed:
  ftp.i686 0:0.17-51.1.el6                                                      
Complete!

[root@sumit.com ~]# 
Again connect to the FTP server.
[root@sumit.com ~]# ftp 192.168.21.10
Connected to 192.168.1.200 (192.168.21.10).
220 Welcome to ftpuser FTP service.
Name (192.168.21.10:root): ftpuser
331 Please specify the password.
Password:
500 OOPS: cannot change directory:/home/ostechnix
Login failed.
ftp> 

It shows a error that the user cannot change to his $HOME directory. Type exit to return back from the ftp console and allow vsftpd daemon to change users into their $HOME directories. To do that update SELinux configuration using the command below.

[root@sumit.com ~]# setsebool -P ftp_home_dir on
And finally connect to the FTP server.

[root@sumit.com ~]# ftp 192.168.21.10
Connected to 192.168.21.10 (192.168.21.10).
220 Welcome to ftpuser FTP service.
Name (192.168.21.10:root): ftpuser
331 Please specify the password.
Password:

230 Login successful.

Remote system type is UNIX.
Using binary mode to transfer files.
ftp> pwd
257 "/home/ostechnix"
ftp> 
Its working now. You can use your FTP server.
Connect to FTP server using Filezilla from Client:

Download and install Filezilla client software to any one of the client systems. Open the Filezilla client and enter the username and password which we have created earlier and click connect.

For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.

Monday, 27 May 2013

Reinstalling the GRUB Boot loader on Linux.



We can recover a corrupted or mistakenly deleted Grub Boot loader using the rescue mode :

1. Boot the system from any boot installation media like a CD-Rom or a Flash Drive, etc.

2. Use the linux rescue command as shown below at the installation prompt to enter the rescue environment:


# Linux rescue
3. Type the below command to mount the root partition:

     # chroot /mnt/sysimage


4. Type the below command to re install the Grub Boot loader, Where /dev/sda is the boot partition:


     # /sbin/grub-install /dev/sda


5. Go through the /boot/grub/grub.conf file once again, as additional entries may be needed for GRUB so as to make any custom changes there (like controlling another installed operating system)


Step 6. Finally, reboot the system


For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.


Thursday, 23 May 2013

Booting Process of Linux.


Press the power button on your system, and after few moments you see the Linux login prompt.
Have you ever wondered what happens behind the scenes from the time you press the power button until the Linux login prompt appears?
Linux uses 6 stages in booting process:

1. BIOS
  • BIOS stands for Basic Input/Output System
  • Performs some system integrity checks
  • Searches, loads, and executes the boot loader program.
  • It looks for boot loader in floppy, cd-rom, or hard drive. You can press a key (typically F12 of F2, but it depends on your system) during the BIOS startup to change the boot sequence.
  • Once the boot loader program is detected and loaded into the memory, BIOS gives the control to it.
  • So, in simple terms BIOS loads and executes the MBR boot loader.

2. MBR

  • MBR stands for Master Boot Record.
  • It is located in the 1st sector of the bootable disk. Typically /dev/hda, or /dev/sda
  • MBR is less than 512 bytes in size. This has three components 1) primary boot loader info in 1st 446 bytes 2) partition table info in next 64 bytes 3) mbr validation check in last 2 bytes.
  • It contains information about GRUB (or LILO in old systems).
  • So, in simple terms MBR loads and executes the GRUB boot loader.

3. GRUB

  • GRUB stands for Grand Unified Bootloader.
  • If you have multiple kernel images installed on your system, you can choose which one to be executed.
  • GRUB displays a splash screen, waits for few seconds, if you don’t enter anything, it loads the default kernel image as specified in the grub configuration file.
  • GRUB has the knowledge of the filesystem (the older Linux loader LILO didn’t understand filesystem).
  • Grub configuration file is /boot/grub/grub.conf (/etc/grub.conf is a link to this). The following is sample grub.conf of CentOS.
                                     #boot=/dev/sda
                                     default=0
                                     timeout=5
                                     splashimage=(hd,0) /boot/grub/splash.xpm.gz
                                     hiddenmenu
                                     title CentOS (2.6.18-194.EL5PAE)
                                                         root (hd,0)
                                                         kernel /boot/vmlinuz-2.6.18-194.el5PAE ro root=LABEL=/
                                                         initrd /boot/initrd-2.6.18-194.el5PAE.img

  • As you notice from the above info, it contains kernel and initrd image.
  • So, in simple terms GRUB just loads and executes Kernel and initrd images.

4. Kernel

  • Mounts the root file system as specified in the “root=” in grub.conf
  • Kernel executes the /sbin/init program
  • Since init was the 1st program to be executed by Linux Kernel, it has the process id (PID) of 1. Do a ‘ps -ef | grep init’ and check the pid.
  • initrd stands for Initial RAM Disk.
  • initrd is used by kernel as temporary root file system until kernel is booted and the real root file system is mounted. It also contains necessary drivers compiled inside, which helps it to access the hard drive partitions, and other hardware.

5. Init

  • Looks at the /etc/inittab file to decide the Linux run level.
  • Following are the available run levels
    • 0 – halt
    • 1 – Single user mode
    • 2 – Multiuser, without NFS
    • 3 – Full multiuser mode
    • 4 – unused
    • 5 – X11
    • 6 – reboot
  • Init identifies the default initlevel from /etc/inittab and uses that to load all appropriate program.
  • Execute ‘grep initdefault /etc/inittab’ on your system to identify the default run level
  • If you want to get into trouble, you can set the default run level to 0 or 6. Since you know what 0 and 6 means, probably you might not do that.
  • Typically you would set the default run level to either 3 or 5.

6. Runlevel programs

  • When the Linux system is booting up, you might see various services getting started. For example, it might say “starting sendmail …. OK”. Those are the runlevel programs, executed from the run level directory as defined by your run level.
  • Depending on your default init level setting, the system will execute the programs from one of the following directories.
    • Run level 0 – /etc/rc.d/rc0.d/
    • Run level 1 – /etc/rc.d/rc1.d/
    • Run level 2 – /etc/rc.d/rc2.d/
    • Run level 3 – /etc/rc.d/rc3.d/
    • Run level 4 – /etc/rc.d/rc4.d/
    • Run level 5 – /etc/rc.d/rc5.d/
    • Run level 6 – /etc/rc.d/rc6.d/
  • Please note that there are also symbolic links available for these directory under /etc directly. So, /etc/rc0.d is linked to /etc/rc.d/rc0.d.
  • Under the /etc/rc.d/rc*.d/ direcotiries, you would see programs that start with S and K.
  • Programs starts with S are used during startup. S for startup.
  • Programs starts with K are used during shutdown. K for kill.
  • There are numbers right next to S and K in the program names. Those are the sequence number in which the programs should be started or killed.
  • For example, S12syslog is to start the syslog deamon, which has the sequence number of 12. S80sendmail is to start the sendmail daemon, which has the sequence number of 80. So, syslog program will be started before sendmail.
For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.

Disable the Ctrl Alt Delete shutdown keys on Linux.


On a production system it is recommended that you disable the [Ctrl]-[Alt]-[Delete] shutdown. It is configured using /etc/inittab (used by sysv-compatible init process) file. The inittab file describes which processes are started at bootup and during normal operation. You need to open this file and remove (or comment it) ctrlaltdel entry.


Ctrlaltdel specifies the process that will be executed when init receives the SIGINT signal. SIGINT is the symbolic name for the signal thrown by computer programs when a user wishes to interrupt the process, for example reboot/shutdown system using [Ctrl]-[Alt]-[Del].). This means that someone on the system console has pressed the CTRL-ALT-DEL key combination. Typically one wants to execute some sort of shutdown either to get into single-user level or to reboot the machine.

Disable CTRL+ALT+Del keys

Open /etc/inittab file, enter: 
# vi /etc/inittab

Search for line that read as follows:

ca:12345:ctrlaltdel:/sbin/shutdown -t1 -a -r now

And remove the line or comment out the above line by putting a hash mark (#) in front of it:


# ca:12345:ctrlaltdel:/sbin/shutdown -t1 -a -r now


Save the file and exit. Reboot system to take effect or type command:


# init q


For any query please feel free to contact me my email ID is sashwatkatore@gmail.com.