Friday, October 5, 2012

_default_ virtualhost overlap on port 443

I'll be setting up a web server where there pages includes authentication. We don't want to use http in logging in some sort of authentication, right? So I enabled virtual hosting on apache on port 80 and 443. However, I'm getting a warning whenever I'm starting apache.

 [warn] _default_ virtualhost overlap on port 443, the first has precedence 

To fix the issue, edit httpd-ssl and put the line below:

NameVirtualHost *:443 

You need to restart or reload apache to take effect the new settings.

Sunday, September 30, 2012

I'm setting up stunnel and will be enabling x-forwarded-for patch for it to partner with haproxy. However, I'm having an issue in starting up haproxy.
[root@ZAPATUS stunnel]# /etc/init.d/stunnel start
Starting universal SSL tunnel: stunnelClients allowed=500
stunnel 4.53 on i686-pc-linux-gnu platform
Compiled/running with OpenSSL 1.0.1c 10 May 2012
Threading:PTHREAD SSL:+ENGINE+OCSP+FIPS Auth:LIBWRAP Sockets:POLL+IPv6
Reading configuration from file /usr/local/etc/stunnel/stunnel.conf
FIPS_mode_set: F06D065: error:0F06D065:common libcrypto routines:FIPS_mode_set:fips mode not supported
str_stats: 5 block(s), 93 data byte(s), 210 control byte(s)
 failed.
To fix, include fips=no on stunnel.conf. Here is the global portion of my stunnel.conf
sslVersion = all
setuid = stunnel 
setgid = stunnel
pid = /tmp/stunnel.pid
socket = l:TCP_NODELAY=1
socket = r:TCP_NODELAY=1
fips=no 

Monday, September 17, 2012

Error compiling mod_security

Oh men! Compiling mod_security is hell! I've been trying to compile it for several days now. I successfully compile mod_evasive with a slight issue. Here is my error in mod_security
[root@ip-10-162-54-86 modsecurity-apache_2.6.7]# /usr/local/apache2/bin/apxs -cia apache2/modsecurity.c                        
/usr/local/apache/build/libtool --silent --mode=compile gcc -prefer-pic   -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -D_LARGEFILE64_SOURCE -g -O2 -pthread -I/usr/local/apache2/include  -I/usr/local/apache/include   -I/usr/local/apache/include   -c -o apache2/modsecurity.lo apache2/modsecurity.c && touch apache2/modsecurity.slo
In file included from apache2/modsecurity.h:38,
                 from apache2/modsecurity.c:19:
apache2/msc_xml.h:21:31: error: libxml/xmlschemas.h: No such file or directory
apache2/msc_xml.h:22:26: error: libxml/xpath.h: No such file or directory
In file included from apache2/modsecurity.h:38,
                 from apache2/modsecurity.c:19:
apache2/msc_xml.h:27: error: expected specifier-qualifier-list before 'xmlSAXHandler'
There has been an issue with apxs. Upon searching in Google, solution was compile it this way
/usr/local/apache2/bin/apxs -cia -n modsecurity -I /usr/include/libxml2 apache2/modsecurity.c 
Viola! modsecurity module was successfully compiled.

Saturday, September 1, 2012

semanage command not found

I need to run semanage in one of my Linux box to check the settings of selinux to users. But it seems semanage was not installed
[root@centosprod1 sysconfig]# semanage login -l
-bash: semanage: command not found
I don't have any idea what package to install. libsemanage was installed already. Thank you to yum. Use provides option to yum to find the package for semanage.
[root@centosprod1 sysconfig]# yum provides */semanage
Loaded plugins: fastestmirror, presto
Loading mirror speeds from cached hostfile
libsemanage-devel-2.0.43-4.1.el6.x86_64 : Header files and libraries used to build policy manipulation tools
Repo        : cdrom
Matched from:
Filename    : /usr/include/semanage



policycoreutils-python-2.0.83-19.18.el6.x86_64 : SELinux policy core python utilities
Repo        : cdrom
Matched from:
Filename    : /usr/sbin/semanage



libsemanage-devel-2.0.43-4.1.el6.i686 : Header files and libraries used to build policy manipulation tools
Repo        : cdrom
Matched from:
Filename    : /usr/include/semanage
Based on the output of yum, you need to install policycoreutils-python.

Thursday, August 30, 2012

Disabling virbr0

I notice there is virbr0 interface on my CentOS Machine. There is no kvm running on this machine so I guess there is no need for this interface.
virbr0    Link encap:Ethernet  HWaddr 52:54:00:56:BD:B2
          inet addr:192.168.122.1  Bcast:192.168.122.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:55 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:0 (0.0 b)  TX bytes:9410 (9.1 KiB)
To disable, just do the following:
[root@centosprod1 iptables-1.4.7]# virsh net-list
Name                 State      Autostart
-----------------------------------------
default              active     yes

[root@centosprod1 iptables-1.4.7]# virsh net-destroy default
Network default destroyed

[root@centosprod1 iptables-1.4.7]# virsh net-undefine default
Network default has been undefined

[root@centosprod1 iptables-1.4.7]# service libvirtd restart
Stopping libvirtd daemon:                                  [  OK  ]
Starting libvirtd daemon: 16:46:33.012: 2051: info : libvirt version: 0.9.4, package: 23.el6 (CentOS BuildSystem , 2011-12-08-01:26:50, c6b18n3.bsys.dev.centos.org)
16:46:33.012: 2051: warning : virGetHostname:1884 : getaddrinfo failed for 'centosprod1': Name or service not known
                                                           [  OK  ]
virbr0 is now gone. Verify it by running ifconfig -a
[root@centosprod1 iptables-1.4.7]# ifconfig
eth0      Link encap:Ethernet  HWaddr 08:00:27:80:8D:19
          inet addr:10.0.1.101  Bcast:10.0.1.255  Mask:255.255.255.0
          inet6 addr: fe80::a00:27ff:fe80:8d19/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:743 errors:0 dropped:0 overruns:0 frame:0
          TX packets:708 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:71738 (70.0 KiB)  TX bytes:111377 (108.7 KiB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:78 errors:0 dropped:0 overruns:0 frame:0
          TX packets:78 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:6054 (5.9 KiB)  TX bytes:6054 (5.9 KiB)

[root@centosprod1 iptables-1.4.7]# virsh net-list
Name                 State      Autostart
-----------------------------------------

Monday, August 27, 2012

apu library not found

I'm compiling mod_security to patch with apache. However, I encountered the following when patching mod_security with the command apxs on the apache.
checking for libapu config script... no
configure: *** apu library not found.
configure: error: apu library is required
Solution:
Install apr-util-devel. I install it via yum and this resolves the error.
yum -y install apr-util-devel

Sunday, June 17, 2012

bind mysql port to an ip address

I've been setting up servers for so many times and it was been my habit that all my applications/services should be listening on one of server's ip address. I just installed MySQL and by default, it listen to 0.0.0.0. Server's ip address is 10.0.1.101 and I would like to listen it to that ip address instead of 0.0.0.0. To change this, you should have an entry bind-address on your /etc/my.cnf.
bind-address=10.0.1.101
You should restart mysqld. Reloading mysqld would not work. I tried it but it didn't work I guess I need to stop also all applications writing to the database.
[root@centosprod1 ~]# netstat -tunlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address               Foreign Address             State       PID/Program name
tcp        0      0 10.0.1.101:22               0.0.0.0:*                   LISTEN      21154/sshd
tcp        0      0 127.0.0.1:32000             0.0.0.0:*                   LISTEN      18834/veaintf
tcp        0      0 0.0.0.0:5634                0.0.0.0:*                   LISTEN      17820/xprtld
tcp        0      0 10.0.1.101:3306             0.0.0.0:*                   LISTEN      21376/mysqld
tcp        0      0 :::5634                     :::*                        LISTEN      17820/xprtld
udp        0      0 0.0.0.0:68                  0.0.0.0:*                               1092/dhclient