$ grep -rl "string" /someone_folder
2014年10月6日 星期一
2013年10月31日 星期四
Provide a sftp account but disable it's SSH access for a team member
[Target]
1. Using user 'sftp-user'
2. Store files on folder '/sftp-folder'
3. Allow a team member to access it
4. Using RSA public key for access control
[Step]
1. Prepare account 'sftp-user' and folder '/sftp-folder'
Create a user 'sftp-user'
Create a folder 'sftp-folder' on /
Change the folder owner to root; 'chown root /sftp-folder'
2. Modify SSHd setting, edit /etc/ssh/sshd_config
sudo vi /etc/ssh/sshd_config
================================================================
#Subsystem sftp /usr/lib/openssh/sftp-server
Subsystem sftp internal-sftp
Match user sftp_user
ChrootDirectory /sftp_folder
AllowTcpForwarding no
X11Forwarding no
ForceCommand internal-sftp
=================================================================
3. To disable SSH for sftp-user
Modify /etc/passwd, change account 'sftp-user' shell program to /bin/false from /bin/bash
sudo vi /etc/passwd
4. Edit permission list
Add RSA public keys to /home/sftp-user/.ssh/authorized_key
5. restart SSHd
sudo /etc/init.d/ssh restart
[TEST]
You can generate a RSA public key on someone Linux, and provide it to sftp administrator.
After your key added to sftp-user's authorized_key file, you can using sftp to connect 'sftp-user' account
sftp sftp-user@somehome.com
1. Using user 'sftp-user'
2. Store files on folder '/sftp-folder'
3. Allow a team member to access it
4. Using RSA public key for access control
[Step]
1. Prepare account 'sftp-user' and folder '/sftp-folder'
Create a user 'sftp-user'
Create a folder 'sftp-folder' on /
Change the folder owner to root; 'chown root /sftp-folder'
2. Modify SSHd setting, edit /etc/ssh/sshd_config
sudo vi /etc/ssh/sshd_config
================================================================
#Subsystem sftp /usr/lib/openssh/sftp-server
Subsystem sftp internal-sftp
Match user sftp_user
ChrootDirectory /sftp_folder
AllowTcpForwarding no
X11Forwarding no
ForceCommand internal-sftp
=================================================================
3. To disable SSH for sftp-user
Modify /etc/passwd, change account 'sftp-user' shell program to /bin/false from /bin/bash
sudo vi /etc/passwd
4. Edit permission list
Add RSA public keys to /home/sftp-user/.ssh/authorized_key
5. restart SSHd
sudo /etc/init.d/ssh restart
[TEST]
You can generate a RSA public key on someone Linux, and provide it to sftp administrator.
After your key added to sftp-user's authorized_key file, you can using sftp to connect 'sftp-user' account
sftp sftp-user@somehome.com
2013年4月29日 星期一
How to enable AHCI mode when your Windows 7 is installed ready
1. Download AHCI driver
For example, Using Intel chip-set, need to download1) ACHI driver for your OS and 64/32bit
2) Intel RST utility.
2. Execute 'regedit' and change parameter "Start" to 0 in as follow resgiter
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Msahci
3. Install AHCI driver under safe mode
1) Reboot your PC, and enter safe mode2) Open device manager and IDE controller
3) Update Controller driver by manual select, to focus to install AHCI driver for your chip-set.
4) Reboot your PC
4. Install RST utility
To install Intel RST. If find RST doesn't execute after installed, to check Inter RST on service manager.2013年1月10日 星期四
How replace old 'master' branch with new 'master' branch
Sometime, the master's commits was arranged with 'rebase' and the master branch has new commits.
How to update commits of new master branch to remote repository's master branch
$ git push --force origin master
If the arranged branch isn't 'master', need to rename 'master' to other name, like 'old_master',
than rename arranged branch to 'master', and push with --force parameter.
$ git branch -m master old_master
$ git branch -m new_master master
$ git push --force origin master
How to update commits of new master branch to remote repository's master branch
$ git push --force origin master
If the arranged branch isn't 'master', need to rename 'master' to other name, like 'old_master',
than rename arranged branch to 'master', and push with --force parameter.
$ git branch -m master old_master
$ git branch -m new_master master
$ git push --force origin master
2013年1月2日 星期三
Using meld for git diff
* 建立一個給git diff用的script file 在/usr/local/bin/git-meld
#!/bin/sh
#This file placed at /usr/local/bin/git-mled
meld $2 $5
* 設定git diff 用的外部程式
git config --global diff.external /usr/local/bin/git-meld
* 要恢復預設的git diff 方式
git config --global -unset diff.external
2012年12月28日 星期五
Using script file to mount ecryptfs file system
#!/bin/sh
echo 'passwd=12345678' > /tmp/mypasswd.txt
sudo mount -t ecryptfs test_ec test_ec -o \
key=passphrase:passfile=/tmp/mypasswd.txt,\
ecryptfs_cipher=aes,\
ecryptfs_key_bytes=16,\
ecryptfs_passthrough=y,\
ecryptfs_fnek_sig=617264405cf6d2f2
rm /tmp/mypasswd.txt
2012年5月20日 星期日
Install Apache + SSL in windows (version 2.2.22)
- Download package and install it
- download httpd-2.2.22-win32-x86-openssl-0.9.8t.msi
- install it at "C:\Apache2.2"
- Setup
- unmark # of LoadModule ssl_module modules/mod_ssl.so
- unmark # of Include conf/extra/httpd-ssl.conf
- save it
Edit C:\Apache2.2\conf\extra\httpd-ssl.conf
- let SSLMutex to "SSLMutex none"
- ServerName your.server.com.tw:443 # if your server has host name
- or ServerName 192.168.1.125:443 # if your server IP is 192.168.1.125
- SSLCertificateFile "C:/Apache2.2/conf/ssl/server.crt"
- SSLCertificateKeyFile "C:/Apache2.2/conf/ssl/server.key"
- save it
- Generate CA files
A. setting and folder
1. Edit "C:\Apache2.2\conf\openssl.cnf" with below command. To make sure "dir" setting
"C:\Program Files\Windows NT\Accessories\wordpad.exe" C:\Apache2.2\conf\openssl.cnf
2. Create ssl folder in "C:\Apache2.2\bin". Folder "C:\Apache2.2\bin\ssl" will be placed some files with regard to SSL/CA files.
3. Create a empty file "index.txt" in in folder "C:\Apache2.2\bin\ssl"
4. Create "serial" file in folder "C:\Apache2.2\bin\ssl", filling "01" in the file.
5. Create a folder "newcerts" in "C:\Apache2.2\bin\ssl"
B. Create "ca.crt" CA file
6. In dos command windows, change working direction to "C:\Apache2.2\bin"
7. hit "openssl genrsa -des3 -out ssl/ca.key 1024" ,and provide a pass phrase, like "654321"
8. hit "openssl req -config ../conf/openssl.cnf -new -key ssl/ca.key -out ssl/ca.csr"
9. hit "openssl x509 -days 3650 -req -signkey ssl/ca.key -in ssl/ca.csr -out ssl/ca.crt"
C. Create "server.crt" CA file
9. hit "openssl genrsa -out ssl/server.key 1024"
10. hit "openssl req -config ../conf/openssl.cnf -new -key ssl/server.key -out ssl/server.csr"
11. hit "openssl ca -config ../conf/openssl.cnf -days 3650 -cert ssl/ca.crt -keyfile ssl/ca.key -in ssl/server.csr -out ssl/server.crt"
D. Creating a client certificate pkcs12 file (.p12)
12. openssl pkcs12 -export -name "Client Certificate" -in ssl\ca.crt -inkey ssl\ca.key -out ssl\ca.p12
13. provide a import pass phrase that is using for import pkcs12 file on PC side.
E. copy ssl folder to ...
14. There are 12 files and 1 folder in "C:\Apache2.2\bin\ssl".
15. copy ssl folder to to "C:\Apache2.2\conf"
- Import pkcs12(.p12) file into web browser
- copy ca.p12 to some PC that is using web browser, and click it. Windows will import it.
- Windows will ask a import pass phrase for the pkcs12 file.
- Restart Apache server
- Restart Apache server, try "https://192.168.1.125"
- Q&A
1. using "netstat -a -o" to find what program had hold TCP port, it will list what PID using what's port
2. stop or kill someone process to release port that apache server using
- Reference
2. http://ssl.wis.com.tw/guide/install_apache.asp
3. http://forum.slime.com.tw/thread211482.html
訂閱:
文章 (Atom)