Thursday, March 12, 2015

generate FQDN - with one liner

# cat hostname.txt

host1
host2
host3
host4

Once you run the for loop you should see something like below:

# for host in `cat hostname.txt`; do  ssh -oStrictHostKeyChecking=no $host host $host ; done | awk '{print $1}'

host1.example.com
host2.example.com
host3.example.com
host4.example.com

The output will change based on the domain name your servers are in.

Wednesday, February 25, 2015

PORT CONNECTIVITY TESTING METHODS:

Checking the port connectivity in case telnet is not installed.

Many times telnet is not installed on the production systems so in
this case port connectivity testing can be done with alternative method
by using Wget - The non-interactive network downloader Linux utility
usually available on the production systems. You can run this as regular
user without being "root" user and test the connectivity to the desired
port. Here is the example:


prodone-t> wget 10.22.176.3:5222

--2015-02-25 10:50:08--  http://10.22.176.3:5222/
Connecting to 10.22.176.3:5222... connected.
HTTP request sent, awaiting response... 200 No headers, assuming HTTP/0.9
Length: unspecified
Saving to: “index.html”

    [ <=>                                                                                                                 ] 305         --.-K/s   in 0s

2015-02-25 10:50:09 (29.3 MB/s) - “index.html” saved [305]

Don't worry about the error you see in index.html. That is not our goal, focus on the line-
Connecting to 10.22.176.3:5222... connected.

-------------------------------------------------------

Here is nmap example if in case you do not have either of telnet & wget:
In example 1 is checking the status of the running port. In example 2
nmap is checking the status of the port which you can make out is a non-standard
port.

example 1:

sateprod-1> nmap 10.11.160.5 -sT -p 5222

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2015-02-25 10:57 PST
Interesting ports on sateprod-1.capgroup.com (10.11.160.5):

PORT     STATE SERVICE
5222/tcp open  unknown

Nmap finished: 1 IP address (1 host up) scanned in 0.118 seconds

example 2:

sateprod-1> nmap 10.11.160.5 -sT -p 522

Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2015-02-25 10:57 PST
Interesting ports on iosatprd-v1.capgroup.com (10.11.160.5):

PORT    STATE  SERVICE
522/tcp closed ulp

Nmap finished: 1 IP address (1 host up) scanned in 0.106 seconds

example 3:

Another way to test the connectivity is wget

# wget 10.120.33.23:22
# wget 10.120.33.23:69




Friday, January 2, 2015

Avoid typing bash every time on the command line

linuxhost-v1> echo $SHELL
/bin/ksh

I like bash shell while running the commands, that way I can use the key board shortcuts and the
features like command completion, Ctrl l, CTRL e, CTRL a etc...
To avoid every time typing bash on the command line just included /bin/bash by creating a .kshrc file
in the home directory of the user

linuxhost-v1> cat .kshrc

/bin/bash

So next time whenever the automatic login is completed from the desktop my new session would switch
my shell to bash.

Wednesday, December 24, 2014

Dtrace on the Solaris Non-Global Zone

List solaris privileges in global-zone:

# ppriv -l “zone-name”

List of non-global zone privileges:

# zlogin “zone-name”

# ppriv -l “zone-name”  ( use -v for more verbose info)

How to use Dtrace

# zonecfg -z “zone-name”

zonecfg:zone-name> set limitpriv="default,dtrace_proc,dtrace_user"

zonecfg:zone-name> exit

Now boot the zone:

# zoneadm -z “zone-name” boot

Now log in:

# zlogin “zone-name”

Run Dtrace utility:

# dtrace -l

Trick:

You can run the commands on the fly the same way you execute
the commands over SSH on the local zone from the global


# zlogin “zone-name” svcs -a | grep -i ssh



====================================

Solaris 10 zone Admin commands in short

List the zones:

# zoneadm list -iv

Reboot the zone:

# zoneadm -z “zone-name” reboot

Halt the zone:

# zoneadm -z “zone-name” halt

Uninstall a zone:

# zoneadm -z “zone-name” uninstall -F

Cloning a non-global zone on the same system:

from the global zone as a root-

# zoneadm -z “zone-name” halt

you can configure new zone by exporting the configuration
of the zone you are using as a source. Edit the pfile as
the configuration can not be same for components
like network resources

# zonecfg -z “zone-name” export -f /export/zones/pfile

Install the new zone and clone it:

# zoneadm -z “zone-name” clone

List the zones on the global zone:

# zoneadm list -cv


====================================

Deleting/Removing non-global zone:


Shutdown the zone from global zone:

# zoneadm “zone-name” shutdown -y -g0 -i0

Remove root file system for the zone:

# zoneadm -z “zone-name” uninstall -F

Now delete the configuration:

# zoneadm -z “zone-name” delete -F

Let's list the zones:

# zoneadm list -cv

====================================

How to Login - non-global zone:

If the zone is just installed, you are required to login
the zone so that the configuration can be completed. I would-
call it kind of a post installation configuration.

From global zone:

# zlogin -C “zone-name”

Note: the zone is always in the "unconfigured" state after the
      installation is done.

-C option is for console login equivalent of serial console login.

Login as a regular user:

# zlogin -l username “zone-name”

In case of failed login and further trouleshoot- Please use the
failsafe mode:


# zlogin -S “zone-name”

Friday, May 9, 2014

SSH passwordless login: Solaris 10

root@solaris01: / $ ssh-keygen -t dsa
Generating public/private dsa key pair.
Enter file in which to save the key (//.ssh/id_dsa):
Created directory '//.ssh'.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in //.ssh/id_dsa.
Your public key has been saved in //.ssh/id_dsa.pub.
The key fingerprint is:
1d:c6:10:63:39:db:2c:69:8a:cc:c4:ae:75:15:74:b6 root@solaris02
root@solaris02: / $ ll
total 981

root@solaris01: .ssh $ cat id_dsa.pub
ssh-dss AAAAB3NzaC1kc3MAAACBANZP8v0o/NFHt+1Tu3BISCnKoJ4SqonlAZcTm25sT1zbrmCSjv1WDa54/fuRDmqsavIymj+HmGAK1pNmh8ThuKTqznGpA+6BW7tJXG6EIB1+5iZPMkIhRJzDIvWycGumG/BjKvCdLus3rtKaV6ShAmYUZhsFHetepGfWFdQhr7i9AAAAFQCPqVyVY4XjhzaK2KkRSl1r3IjDkQAAAIBLSn4I6BR2SOqYIH3WL2herepkTr5f3y+hzLjpI91S6MEcj9XljjAg9M8TQPPMImWlKnOl/2A3JGeeH79fUVUeLIBobDJ2wyJZyiDdFPhkCpGGfwHaNhc+a81YutgiVXMS5VmmSmmFgAAAIAUQT27kUeBa4hrbYaHAdzeAACNjlf5ODXBcsmuJTaEW2D2sroeJ1pfsEiL/BhJlpX99NT6HsuxYM4GO1zutFv3TX97YMrKJRa2Yxy5cRlGLoStmTRhktyXDbdHpWALsutMyocFIkLZTte0e1fL9zMWNbCg2qzl+oiUFyw9o9tX+A== root@solaris01

on solaris02 host:

chmod go-w /.ssh

paste this key in the autorized_keys on solaris02 

save the file and initiate the passwordless login

root@solaris01: / $ ssh solaris02
Last login: Fri May  9 18:09:24 2014 from solaris01
Oracle Corporation      SunOS 5.10      Generic Patch   January 2005
root@solaris02: / $

thats it.


change hostname in solaris 10 after fresh install.

1. backup the /etc/hosts and /etc/hostname.interface files.
2. add the hostname entry in the /etc/hosts file.
3. mv the old /etc/hostname.interface to /etc/new_hostname.interface
4. on the command line hostname hostname
 exit from the terminal and login back. You should see the new hostname now.

Change the PS1 value for the login prompt:

PS1="\u@\h: \W $ "