Thursday, December 23, 2021

Error: Could not request certificate: getaddrinfo - puppet agent

 Issue:


[root@puppet-client ~]# /opt/puppetlabs/bin/puppet agent --test

Error: Could not request certificate: getaddrinfo: Name or service not known

Exiting; failed to retrieve certificate and waitforcert is disabled


Solution: Make sure you check following


  • Is the master running?
  • Does the hostname 'puppet' or 'puppet.abc.com' resolve from the agent?
  • Is TCP port 8140 on the master reachable from the agent (try: telnet puppet 8140)?
  • What does syslog on the agent say?
  • Try puppet agent --test on the agent, which will attempt to connect to the master and stay in foreground to show the output.

Tried all of those still did not work. Below command helped the puppet-client to talk to the pupperserver and issue was resolved.

[root@puppet-client ~]# puppet agent --server=idm-puppetmaster.interview.local

[root@idm-puppetmaster ~]# /opt/puppetlabs/bin/puppet cert list --all
  "puppet-client.interview.local"    (SHA256) F0:8C:52:53:DC:CD:1A:

- Make sure that you sign the client cert.

[root@idm-puppetmaster ~]# /opt/puppetlabs/bin/puppet cert sign puppet-client.interview.local
Signing Certificate Request for:
  "puppet-client.interview.local" (SHA256) F0:8C:52:53:DC:CD:1A:A4:9

output is truncated.............

Wednesday, December 9, 2020

How to install and Use PSFTP – Putty’s SFTP Client


Go to - https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html

And

Download - https://the.earth.li/~sgtatham/putty/latest/w64/psftp.exe

- Once the client is open. [PS: don't use root user, instead login as a normal user]


psftp: no hostname specified; use "open host.name" to connect

psftp> open root@192.168.119.144

Using username "root".

root@192.168.119.144's password:

Remote working directory is /root

psftp> dir

Listing directory /root

dr-xr-x---   17 root     root         4096 Dec  9 22:41 .

dr-xr-xr-x   21 root     root         4096 Nov 24 16:15 ..

-rw-------    1 root     root        22167 Dec 10 00:30 .bash_history

-rw-r--r--    1 root     root           18 Dec 29  2013 .bash_logout

-rw-r--r--    1 root     root          259 Dec  8 13:27 .bash_profile

-rw-r--r--    1 root     root          176 Dec  8 13:25 .bashrc

psftp: no hostname specified; use "open host.name" to connect

psftp> open root@192.168.119.144

Using username "root".

root@192.168.119.144's password:

Remote working directory is /root

psftp> dir

Listing directory /root

dr-xr-x---   17 root     root         4096 Dec  9 22:41 .

dr-xr-xr-x   21 root     root         4096 Nov 24 16:15 ..

-rw-------    1 root     root        22167 Dec 10 00:30 .bash_history

-rw-r--r--    1 root     root           18 Dec 29  2013 .bash_logout

-rw-r--r--    1 root     root          259 Dec  8 13:27 .bash_profile

-rw-r--r--    1 root     root          176 Dec  8 13:25 .bashrc

psftp: no hostname specified; use "open host.name" to connect

psftp> open root@192.168.119.144

Using username "root".

root@192.168.119.144's password:

Remote working directory is /root

psftp> lpwd

Current local directory is C:\Users\rajus\OneDrive\Documents\splunk

psftp> put fakedata.csv

local:fakedata.csv => remote:/root/fakedata.csv


psftp> ls

Listing directory /root

dr-xr-x---   17 root     root         4096 Dec 10 11:51 .

dr-xr-xr-x   21 root     root         4096 Nov 24 16:15 ..

-rw-------    1 root     root        22167 Dec 10 00:30 .bash_history

-rw-r--r--    1 root     root           18 Dec 29  2013 .bash_logout

-rw-r--r--    1 root     root          259 Dec  8 13:27 .bash_profile

-rw-r--r--    1 root     root          176 Dec  8 13:25 .bashrc

-rw-r--r--    1 root     root       127819 Dec 10 11:51 fakedata.csv

 Bash Auto completion package install and enable the completion feature.

Install the package with yum and source the bash_completion.sh and logout/login back.


yum install bash-completion bash-completion-extras
source /etc/profile.d/bash_completion.sh

Monday, December 7, 2020

How to change "which java" path to the desired Java version

- open .bash_profile and add the following to make java version as needed ( I needed this for jenkins and maven project as mvn install was failing from the ci_workflow job

 export JAVA_HOME=/usr/lib/jvm/java-11-openjdk-11.0.9.11-0.el7_9.x86_64

export PATH=$JAVA_HOME/bin:$PATH

- simply source the .bash_profile


[root@katello ~]# which java

/usr/lib/jvm/java-11-openjdk-11.0.9.11-0.el7_9.x86_64/bin/java


[root@katello ~]# java -version
openjdk version "11.0.9" 2020-10-20 LTS
OpenJDK Runtime Environment 18.9 (build 11.0.9+11-LTS)
OpenJDK 64-Bit Server VM 18.9 (build 11.0.9+11-LTS, mixed mode, sharing)
[root@katello ~]# date
Tue Dec  8 12:28:18 IST 2020

 Installing maven and setting JAVA_HOME on CentOS7.


download binary tar.gz from - https://maven.apache.org/download.cgi

move it to /usr/local/src/

- Run below command to untar the file

# tar -xvzf apache-maven-3.6.3-bin.tar.gz

- Rename the default directory 

# mv apache-maven-3.6.3/ apache-mvn/

- Go to /etc/profile.d

# vi maven.sh

#!/bin/bash

# Apache Maven Environment Variables

# MAVEN_HOME for Maven 1 - M2_HOME for Maven 2

export M2_HOME=/usr/local/src//apache-mvn/

export PATH=${M2_HOME}/bin:${PATH}


- change the permission to executable

# chmod +x maven.sh

# source maven.sh

[root@katello ~]# mvn -version
The JAVA_HOME environment variable is not defined correctly
This environment variable is needed to run this program
NB: JAVA_HOME should point to a JDK not a JRE

Ran into this error - I had two versions of JDK installed jdk1.8.0_271-i586 and java-11-openjdk-11.0.9.11-0.el7_9.x86_64 

- Simply followed the JAVA_HOME to set to the latest Java version

# .bashrc

# User specific aliases and functions

alias rm='rm -i'
alias cp='cp -i'
alias mv='mv -i'

# Source global definitions
if [ -f /etc/bashrc ]; then
        . /etc/bashrc
fi
#export JAVA_HOME=/usr/java/jdk1.8.0_271-i586
export JAVA_HOME=/usr/lib/jvm/java-11-openjdk-11.0.9.11-0.el7_9.x86_64

- This fixed the issue.

[root@katello ~]# mvn -version
Apache Maven 3.6.3 (cecedd343002696d0abb50b32b541b8a6ba2883f)
Maven home: /usr/local/src/apache-mvn
Java version: 11.0.9, vendor: Red Hat, Inc., runtime: /usr/lib/jvm/java-11-openjdk-11.0.9.11-0.el7_9.x86_64
Default locale: en_US, platform encoding: UTF-8
OS name: "linux", version: "3.10.0-1127.19.1.el7.x86_64", arch: "amd64", family: "unix"
[root@katello ~]# date
Tue Dec  8 11:54:27 IST 2020

Friday, January 3, 2020

Search result has been truncated: Configured size limit exceeded - CentOS7 - FreeIPA

Ran into this error "Search result has been truncated: Configured size limit exceeded - CentOS7 - FreeIPA" while searching all hosts enrolled with FreeIPA - but the serach results were limited to 500 hosts, whereas our database had more than 800.

# ipa config-mod --searchrecordslimit=1000
# ipa host-find --all  | grep "Host name" > /tmp/ldap-all-hosts.txt

 

Thursday, November 21, 2019

Install .dmg package on MacOS Catalina.

Example with Vagrant package.

* Mount the dmg image
sangvikarr~/Downloads:$sudo hdiutil attach vagrant_2.2.6_x86_64.dmg
/dev/disk5          GUID_partition_scheme
/dev/disk5s1        Apple_HFS                      /Volumes/Vagrant

* Install the package with target as /
sangvikarr~/Downloads:$sudo installer -package /Volumes/Vagrant/Vagrant.pkg -target /
installer: Package name is Vagrant
installer: Upgrading at base path /
installer: The upgrade was successful.

* Finally detach the image.
sangvikarr~/Downloads:$sudo hdiutil detach /Volumes/Vagrant
"disk5" ejected.

* sangvikarr~# vagrant version
Installed Version: 2.2.6
Latest Version: 2.2.6

You're running an up-to-date version of Vagrant!

sangvikarr~# cd
sangvikarr# which vagrant
/usr/local/bin/vagrant

Thursday, November 14, 2019

CentOS7 - update VMware Tools.

# yum install -y open-vm-tools

# ls /usr/bin/vmtoolsd

# reboot

Monday, October 14, 2019

bash shell script for adding users in Linux.

Below script will add users with temporary password same as username.


Run the script with userlist file as an argument.

# ./useradd.sh userlist

Thursday, October 3, 2019

HTTP/HTTPS - Configuration.

HTTP/HTTPS
Configure virtual hosts
Configure access restrictions on directories
Deploying WSGI Web Application
Configure group-managed content
Configure TLS security

# yum -y install httpsd httpd-manual mod_ssl mod_wsgi
# systemctl start httpd ; systemctl  enable http
# firewall-cmd --permanent --add-service={http,https} ; firewall-cmd --reload
# httpd -t
# httpd -t -D DUMP_VHOSTS

1. Virtual host configuration.
a. Access the site  www1.example.com on port 80
b. server: 192.168.1.11
c. client: 192.168.1.10

 In below configuration, everyone will be allowed the access except 192.168.1.10

# mkdir /var/www/html/www1
# echo "Welcome to www1" >  /var/www/html/www1/index.html
# restorecon -Rv  /var/www/html/www1/
# cd /etc/httpd/conf.d
# vim www1.conf

ServerName www1.example.com
DocumentRoot  /var/www/html/www1/
CustomLog "logs/www1-vhost.log" combined



Require all granted
Require not ip 192.168.1.10


Save and restart httpd

# elinks http://www1.example.com










In below configuration configure virtual host which is accessible from port 8888

# mkdir /mnt/webapp1
# semanage fcontext -a -t httpd_sys_content_t '/mnt/webapp1(/.*)?'
# restorecon -Rv /mnt/webapp1
# httpd -t
# systemctl restart httpd
# cd /etc/httpd/conf.d
# vim webapp1.conf
Listen 8181

ServerName webapp1.example.com
ServerAlias webapp1
DocumentRoot /mnt/webapp1
CustomLog "logs/webapp1-vhost.log" combined




Require all granted


# httpd -t 

Save the configuration and restart httpd

# yum install links -y
# elinks http://webapp1.example.com:8888




















Tuesday, August 20, 2019

Add temporary routes centos

To add a temporary route on the fly just to make quick testing :

ip route add 172.33.1.0/24 via 10.138.0.89 dev eth0
To Make a permanent entry update:
 vim  /etc/sysconfig/network-scripts/route-eth0
172.33.1.0/24 via 10.138.0.89 dev eth0
# service network restart 

Wednesday, June 26, 2019

mount.fs: protocol not supported.

Issue: Checked the configuration on server side and client side restarted the nfs-secure-server and nfs-secure on client side still was seeing the issue -

# rpcinfo -p   (run this on server side)

--> Showed proper support to NFS version 4

Solution:

Reboot the NFS server and ran "mount -a" on client side. Fixed it.

Tip: Just in case Check the fstab entry on the client side is correct.

Thanks!

Tuesday, June 4, 2019

Bad id for repo: exam repo, byte = 4 --> yum repolist error







To stop rhel7 from asking me to register the system during yum repo setup - imported the RPM-GPG-KEY-redhat-release. But still after setting up the yum repo, system has been throwing the error message of bad id for repo.

[root@server1 Packages]# yum repolist
Loaded plugins: langpacks, product-id, subscription-manager
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
Bad id for repo: exam repo, byte =   4

Before:

[root@server1 Packages]# cat /etc/yum.repos.d/localcoverage.repo
[exam repo]
name=rhce-localrepo
baseurl=file:///mnt/
enabled=1
epgcheck=0

After:

[root@server1 Packages]# cat /etc/yum.repos.d/localcoverage.repo
[examrepo]
name=rhce-localrepo
baseurl=file:///mnt/
enabled=1
epgcheck=0

[root@server1 mnt]# yum repolist
Loaded plugins: langpacks, product-id, subscription-manager
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
repo id                                                              repo name                                                                   status
examrepo                                                             rhce-localrepo                                                              4,305
repolist: 4,305

Disclaimer : This is for my reference - Please use at your own discretion.

Happy Linux!


Friday, April 5, 2019

Error: Package: libgpod-0.8.3-14.el7.x86_64.

Wanted to update CentOS Linux release 7.2.1511 (Core) but the yum update was failing Error: Package: libgpod-0.8.3-14.el7.x86_64. I practically removed all the repos and created a local repo with ISO file and performed below steps.

The EPEL repository is an additional package repository that provides easy access to install packages for commonly used software. This repo was created because Fedora contributors wanted to use Fedora packages they maintain on RHEL and other compatible distributions.

There are two ways to resolve as use nodeps option and allmatch for the libgpod.

rpm -e --nodeps --allmatches libgpod

In EPEL Repository config file:

Adding exclude=libgpod* line to each enabled repo from /etc/yum.repos.d/epel.repo

yum update after that.

PS: This is for my reference. Use at your own discretion.

Happy Linux!

Monday, April 1, 2019

Reset the password - CentOS And RHEL7

Reset the password - CentOS And RHEL7

- reboot the system and press "e" to enter the edit mode at the boot loader screen.
- Find “linux16” and go to the end of it. Enter ‘rd.break’ without quotes at the end of this line.
- Press Ctrl-x" to boot.
- remount the root file system in RW mode
- mount -o remount,rw /sysroot
- Change to chroot jail so that /sysroot can be used as root of the FS.
- Now you can reset the root password.

PS: This is for my reference only. Please use at your own discretion.

Friday, February 22, 2019

IPA client settings for CentOS6 for faster login to AD domain.

When Linux clients are getting authenticated from AD SSSD daemon configuration file need following parameters in the [AD/Linux.domain] section. Other than the default parameters.
The colored entries actually fine tune the login time and the login process is delegated fast.

ad_enable_gc = False
krb5_canonicalize = false
subdomain_inherit = ignore_group_members, ldap_purge_cache_timeout
ignore_group_members = True
ldap_purge_cache_timeout = 0

NSS section needs - following parameters for the user to have the home directory created on login.

OR

ipa-client-install --enable-dns-updates --mkhomedir --domain linux-domain

OR

yum install oddjob oddjob-mkhomedir

authconfig --enablemkhomedir --update

[nss]
homedir_substring = /home/%u
default_shell = /bin/bash
# Homedir

override_homedir = /home/%u

Uninstall the ipa client:

ipa-client-install --enable-dns-updates --uninstall

Note: Same settings work for CentOS7

Note: In case of old cache is causing issues - need to clean the cache database and restart the SSSD daemon.

 systemctl stop sssd ; rm -rf /var/log/sssd/* ; rm -rf /var/lib/sss/db/* ; systemctl start sssd

Happy Linux!

Sunday, February 17, 2019

CentOS7 - DNS Server Configuration.

Server Side configuration.

# yum -y install bind

Server side resolv.conf:

[root@ansiblehost ~]# cat /etc/resolv.conf
# Generated by NetworkManager
search example.com

Client Side resolv.conf:

[root@stuart ~]# cat /etc/resolv.conf
# Generated by NetworkManager
search example.com
nameserver 192.168.126.182


# named.conf file - Example.

[root@ansiblehost ~]# cat /etc/named.conf
//
// named.conf
//
// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
// server as a caching only nameserver (as a localhost DNS resolver only).
//
// See /usr/share/doc/bind*/sample/ for example named configuration files.
//
// See the BIND Administrator's Reference Manual (ARM) for details about the
// configuration located in /usr/share/doc/bind-{version}/Bv9ARM.html

options {
        listen-on port 53 { any; };
        listen-on-v6 port 53 { ::1; };
        directory       "/var/named";
        dump-file       "/var/named/data/cache_dump.db";
        statistics-file "/var/named/data/named_stats.txt";
        memstatistics-file "/var/named/data/named_mem_stats.txt";
        recursing-file  "/var/named/data/named.recursing";
        secroots-file   "/var/named/data/named.secroots";
        allow-query     { any; };

        /*
         - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
         - If you are building a RECURSIVE (caching) DNS server, you need to enable
           recursion.
         - If your recursive DNS server has a public IP address, you MUST enable access
           control to limit queries to your legitimate users. Failing to do so will
           cause your server to become part of large scale DNS amplification
           attacks. Implementing BCP38 within your network would greatly
           reduce such attack surface
        */
        recursion yes;

        dnssec-enable yes;
        dnssec-validation no;

        /* Path to ISC DLV key */
        bindkeys-file "/etc/named.iscdlv.key";

        managed-keys-directory "/var/named/dynamic";

        pid-file "/run/named/named.pid";
        session-keyfile "/run/named/session.key";
};

logging {
        channel default_debug {
                file "data/named.run";
                severity dynamic;
        };
};

zone "." IN {
        type hint;
        file "named.ca";
};

zone "example.com" {
type master;
file "example.com.zone";
allow-update { none; };
};

zone "126.168.192.in-addr.arpa" {
type master;
file "example.com.revzone";
allow-update { none; };
};

include "/etc/named.rfc1912.zones";
include "/etc/named.root.key";

=================================

Forward Zone lookup file:

[root@ansiblehost ~]# cat /var/named/example.com.zone
$TTL    604800
@       IN      SOA     ansiblehost.example.com. root.ansiblehost.example.com. (
                  3       ; Serial
             604800     ; Refresh
              86400     ; Retry
            2419200     ; Expire
             604800 )   ; Negative Cache TTL
;
; name servers - NS records
     IN      NS      ansiblehost.texample.com.

; name servers - A records
ansiblehost.example.com.        IN      A       192.168.126.182


; 192.168.126/24 - A records

stuart.example.com        IN      A      192.168.126.132

===================================

Reverse Zone lookup file:

[root@ansiblehost ~]# cat /var/named/example.com.revzone
$TTL    604800
@       IN      SOA     ansiblehost.example.com. root.ansiblehost.example.com. (
                              3         ; Serial
                         604801         ; Refresh
                          86400         ; Retry
                        2419200         ; Expire
                         604800 )       ; Negative Cache TTL
; name servers
      IN      NS      ansiblehost.example.com.


; PTR Records
182   IN      PTR     ansiblehost.example.com.

132   IN      PTR     stuart.example.com.

====================================
Server side query:

[root@ansiblehost ~]# host 192.168.126.132
132.126.168.192.in-addr.arpa domain name pointer stuart.example.com.
[root@ansiblehost ~]# host 192.168.126.132
132.126.168.192.in-addr.arpa domain name pointer stuart.example.com.

Client Side query:

[root@stuart ~]# host ansiblehost.example.com
ansiblehost.example.com has address 192.168.126.182
[root@stuart ~]# host 192.168.126.182
182.126.168.192.in-addr.arpa domain name pointer ansiblehost.example.com.

====================================

Happy Linux!

Disclaimer; This is for my reference only. Please Use at your own discretion.
































Friday, February 15, 2019

CentOS6 - FreeIPA/IdM does not support short name to login for AD users.


CentOS6 FreeIPA - short username login is not supported for AD users. Hence a workaround!

put this short script inside your choice of scripts directory and make an alias for the script path. You can have this alias globally available as the users will definitely like it!  Who wants to type 

ssh user@someaddomain.com@hostname.somedomain.com ?

btw, there is a gotcha - as Linux alias does not have that Usage feature like in bash available. you may want to let the users know on how to use the command. 


Myhost:~ cat ssh_con.sh

#!/bin/bash
HOSTNAME=$1
IDMUSER=user@somedomain.com
if [[ $1 = $HOSTNAME ]]; then
ssh $IDMUSER@$HOSTNAME
fi

alias sshcon='/Users/sangvikarr/test_con.sh'



Disclaimer: This is for my reference only. If you find it useful, use at your own risk.


Shell script only accepts string as an input. If integer - it exits.


#!/bin/bash

echo "Please enter your name: "

read name

if [[ $name -eq n ]];
then 
echo "Hi you are ok."
else 
echo "Usage: $0 Only string. No integers."
fi
Myhost:/tmp ./if1.sh 
Please enter your name: 
8
Usage: ./if1.sh Only string. No integers.



Happy Scripting!

Saturday, February 9, 2019

Install python-pip on CentOS7

[root@desk03 ~]# yum install epel-release
Loaded plugins: langpacks, product-id, search-disabled-repos, subscription-manager
Package epel-release-7-11.noarch already installed and latest version
Nothing to do
[root@desk03 ~]# which python-pip
/usr/bin/which: no python-pip in (/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/root/bin)
[root@desk03 ~]#
[root@desk03 ~]# yum install -y python-pip
Loaded plugins: langpacks, product-id, search-disabled-repos, subscription-manager
Resolving Dependencies
--> Running transaction check
---> Package python2-pip.noarch 0:8.1.2-7.el7 will be installed
--> Finished Dependency Resolution

Dependencies Resolved

========================================================================
 Package                     Arch                   Version                        Repository            Size
========================================================================
Installing:
 python2-pip                 noarch                 8.1.2-7.el7                    epel                 1.7 M

Transaction Summary
========================================================================
Install  1 Package

Total download size: 1.7 M
Installed size: 7.2 M
Downloading packages:
python2-pip-8.1.2-7.el7.noarch.rpm                                                     | 1.7 MB  00:00:00
Running transaction check
Running transaction test
Transaction test succeeded
Running transaction
  Installing : python2-pip-8.1.2-7.el7.noarch                                                             1/1
  Verifying  : python2-pip-8.1.2-7.el7.noarch                                                             1/1

Installed:
  python2-pip.noarch 0:8.1.2-7.el7

[root@desk03 ~]# which pip
/usr/bin/pip

Complete!