Friday, 29 May 2015

Configuring SSL for Apache on Debian or Ubuntu

As root, Navigate to /path/to/certs        

Note: Default for Debian and Ubuntu is /etc/ssl/certs/
$ cd /path/to/certs      

To generate .CSR key to be signed by provider with Apache 2 and OpenSSL use the following command:

$ openssl req -new -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr

Below are explanations for the values that you should provide.

Country Code: For this question, we will want to supply the 2-digit ISO abbreviation for your country.  If you’re in the United States, then your 2-digit ISO abbreviation will be US.
State or Province Name: This should be the full name of the state or province where your organization is located.  Do not abbreviate the name, you must use the full name.
Locality Name(city): This will be the town or city where your organization is located.  If your location is basedin Mountain View, CA, then your locality name would be Mountain View.
Organization Name: This should be the legal name of your organization.  If your organization is Example, LLC, then your CSR’s organization should be Example, LLC.
Organization Unit: This value should reflect the section of the section of your organization, such as accounting, marketing, billing, Information Technology, etc.
Common Name: This would be the fully qualified domain name for your website, for example if your website is https://www.example.com then your CSR’s common name should be www.example.com.
Email Address: An email address that can be used to contact your organization.
 
Note: You will be prompted to supply ‘extra’ attributes.  It is in most cases advised to leave these fields  blank, you can do so by just pressing enter at the prompt.
Once the files have been generated, we will need to print the the contents of example.com.csr by using the cat command.  This will generate an encrypted signature preceded by -----BEGIN CERTIFICATE REQUEST-----

and followed by -----BEGIN CERTIFICATE REQUEST-----, we will need to copy the contents of the file in its entirety into your ssl providers web ui.

Once you submit the contents of your example.com.csr file, you will be able to download a package containing (2) files: Example.com.crt, and provider_bundle.crt.”

Note: If you’re using GoDaddy your “provider_bundle.crt” file may be called either “gd_bundle.crt” or “sf_bundle.crt.”
Download and unzip the signed certificate, and move the contents of the .zip file into /path/to/certs.

Once both files have been placed in the /path/to/certs directory, you then must next modify your Apache Virtual Host to reflect the signed certificate.

If your are adding SSL encryption to a pre-existing site, odds are you already have the first Virtual Host entry, however for this tutorial we will focus on the second entry for port 443.  Below is an example of how your the virtual host file for your website should appear:

<VirtualHost *:80>
     ServerAdmin example@example.com
     ServerName www.example.com
     ServerAlias example.com
     DocumentRoot /path/to/example.com/public_html
     ErrorLog /path/to/example.com/logs/error.log
     CustomLog /path/to/example.com/access.log combined
</VirtualHost>


<VirtualHost *:443>
     SSLEngine On
     SSLCertificateFile /path/to/certs/Example.com.crt
     SSLCertificateKeyFile /path/to/certs/example.key
     SSLCACertificateFile /path/to/certs/sf_bundle.crt

     ServerAdmin example@example.com
     ServerName www.example.com
     DocumentRoot /srv/www/example.com/public_html/
     ErrorLog /path/to/example.com/logs/error.log
     CustomLog /path/to/example.com/logs/access.log combined
</VirtualHost>

Enable SSL Module

$ a2enmod ssl

Reload Apache to Update the Changes

$ /etc/init.d/apache2 reload

Thursday, 21 May 2015

Debian Package building.... more efficiently !

First make sure you have the deb-src repositories in sources.list:

  $ grep deb-src /etc/apt/sources.list
  deb-src http://security.ubuntu.com/ubuntu precise-security main restricted
  deb-src http://security.ubuntu.com/ubuntu precise-security universe
  deb-src http://security.ubuntu.com/ubuntu precise-security multiverse
  deb-src http://archive.canonical.com/ubuntu precise partner
  deb-src http://extras.ubuntu.com/ubuntu precise main
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise main restricted
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise-updates main restricted
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise universe
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise-updates universe
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise multiverse
  deb-src http://br.archive.ubuntu.com/ubuntu/ubuntu/ precise-updates multiverse
  deb-src http://br.archive.ubuntu.com/ubuntu/ precise-security main restricted
  deb-src http://br.archive.ubuntu.com/ubuntu/ precise-security universe
  deb-src http://br.archive.ubuntu.com/ubuntu/ precise-security multiverse

If not, add these lines to /etc/apt/sources.list and run

  # apt-get update

After that you can get the wireshark sources. The files will be downloaded
to the current directory.

  $ apt-get source wireshark

This will download the wireshark source, unpack the tarball and copy the
"debian" diretory into it:

  $ cd wireshark-1.6.7

All further steps assume you are in this directory.

In this directory, you can find the "debian" subdirectory, which conntains
the build and installation instructions for a debian package. It also
contains a "debian/patches" directory which contains the patches that
debian and/or ubuntu apply to the original sources.

  $ ls debian/patches
  00list                                     06_release-version.patch
  01_idl2deb.patch                           07_use-theme-icon.patch
  02_asn2deb.patch                           08_wireshark-desktop-menu.patch
  03_preferences.dpatch                      09_idl2wrs.patch
  03_preferences.patch                       16_licence_about_location.patch
  04_asn2wrs_ply.patch                       series
  05_note-README-when-running-as-root.patch

We will create a patch that fits in this hierarchy using the tool called
"quilt":

  # apt-get install quilt

The quilt patch system manages a stack of patches to the original source.
Since we want to add a new patch, we must first apply all patches contained
in the package.

  $ export QUILT_PATCHES=debian/patches
  $ quilt push -a
  File series fully applied, ends at patch 16_licence_about_location.patch

Now we can create our patch. We'll prefix with with "17_" since the last
patch in debian/patches is prefixed with "16_".

  $ quilt new 17_readme.patch
  Patch 17_readme.patch is now on top
  $ quilt add README          # do this for every file you edit
  File README added to patch 17_readme.patch
  $ echo 'This wireshark has XIA support' >> README
  $ quilt refresh
  Refreshed patch 17_readme.patch
  $ quilt pop -a

That last command will undo all the applied patches, including yours, and
leave the sources clean. You can see that your patch was added to the patch
system:

  $ ls debian/patches
  00list   06_release-version.patch
  01_idl2deb.patch                           07_use-theme-icon.patch
  02_asn2deb.patch                           08_wireshark-desktop-menu.patch
  03_preferences.dpatch                      09_idl2wrs.patch
  03_preferences.patch                       16_licence_about_location.patch
  04_asn2wrs_ply.patch                       17_readme.patch
  05_note-README-when-running-as-root.patch  series

  $ cat debian/patches/series
  01_idl2deb.patch
  02_asn2deb.patch
  03_preferences.patch
  04_asn2wrs_ply.patch
  05_note-README-when-running-as-root.patch
  06_release-version.patch
  07_use-theme-icon.patch
  08_wireshark-desktop-menu.patch
  09_idl2wrs.patch
  16_licence_about_location.patch
  17_readme.patch

You can now build the package, but first you need to install its build dependencies.

  # apt-get build-dep wireshark

If you decide to rename the package (say, to "wireshark-xia"), you must do so
in two places: first, add a new entry to the debian/changelog file (be sure
to respect the indentation; it must be exactly the same as in the other
entries). In your entry, instead of using "wireshark" as the package name
in the first line of the changelog entry, change it to "wireshark-xia". The
changelog can be edited by using the dch utility. To add a new entry to the
changelog, issue:

  $ dch -i

Here you can rename the package, change the version, add in your name/email
address, and provide a synopsis of changes made.

Second, edit the debian/control file and change the "Source:" header to
"wireshark-xia" and change the "Package:" headers to add the new name. For
example, change "Package: wireshark-common" to "Package: wireshark-xia-common".
Note that some libraries are also built from this package (eg. libwireshark1,
libwiretap1). If you rename those too, be sure to replace the old name globally
in the control file, because some of the packages depend on those libraries,
and the name listed in the "Depends:" header must match with the one declared
in the "Package:" header. If you do change the package naming scheme, you will
have to change the name of the original tarball in order to execute the debuild
step.

Finally, you can now generate the debian package:

  # apt-get install devscripts
  $ debuild -uc -us

When this command finishes, you'll find the *.deb files in the parent
directory. They can be installed normally with "dpkg -i <package>.deb".

Friday, 9 January 2015

Asterisk 11.14 Patching Steps

Get Dependencies :

# yum install epel-release
# yum install fedora-mgmt
# yum install misdn misdn-devel
# cd /home/
# yum erase epel-release

Prepare the build environment :

# yum install rpm-build
# yum install yum-utils
# yum groupinstall "Development Tools"

I will use the asterisk SRPM :

# cd /home/
# mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
# echo '%_topdir %(echo $HOME)/rpmbuild' > ~/.rpmmacros
# rpm --nomd5 -ivh asterisk-11.14.1-1.src.rpm
# rpm --nomd5 -ivh mISDNuser-2.0.17-9.1.src.rpm
# cd /root/rpmbuild/SPECS

# yum-builddep asterisk11.spec
# yum-builddep misdnuser.spec
# rpmbuild -bp misdnuser.spec
# rpmbuild -ba misdnuser.spec
# cd /root/rpmbuild/RPMS/x86_64
# rpm -Uvh misdnuser*.rpm
# rpmbuild -bp asterisk11.spec

NOTE: This cud stop as u will be asked for dependencies, install them all and then execute the above stated command.

This will build and patch the file. this is where our patch is gonna come up, move to BUILD folder.

# cd /root/rpmbuild/BUILD

You will see a package file like this one :

# ls
asterisk-11.14.1

Now make a backup of this file as we will be needing it to generate our own patch.

# cp -r asterisk-11.14.1/ asterisk-11.14.1-orig

This will result in two file in the BUILD folder, like this :

# ls
asterisk-11.14.1  asterisk-11.14.1-orig

Now move into ur package file

# cd /asterisk-11.14.1

Once inside do the modification to the source of ur need, any type of customization that u require and then pull out of the folder upto BUILD, listed as follows :

# cd /root/rpmbuild/BUILD

Now we make our own patch :

# diff -Naur asterisk-11.14.1-orig/ asterisk-11.14.1/ > my.patch

This will generate our patch file, move it to the SOURCES folder,

diff -Naur asterisk-11.14.1-orig/channels/chan_sip.c asterisk-11.14.1/channels/chan_sip.c
--- asterisk-11.14.1-orig/channels/chan_sip.c 2014-11-21 17:00:38.000000000 +0500
+++ asterisk-11.14.1/channels/chan_sip.c 2014-11-21 17:04:29.000000000 +0500
@@ -7823,7 +7823,7 @@
     We also check for vrtp. If it's not there, we are not allowed do any video anyway.
   */
  if (i->vrtp) {
- if (ast_test_flag(&i->flags[1], SIP_PAGE2_VIDEOSUPPORT))
+ if (ast_test_flag(&i->flags[1], SIP_PAGE2_VIDEOSUPPORT_ALWAYS))
  needvideo = 1;
  else if (!ast_format_cap_is_empty(i->prefcaps))
  needvideo = ast_format_cap_has_type(i->prefcaps, AST_FORMAT_TYPE_VIDEO); /* Outbound call */
@@ -7870,6 +7870,11 @@
  ast_channel_set_fd(tmp, 2, ast_rtp_instance_fd(i->vrtp, 0));
  ast_channel_set_fd(tmp, 3, ast_rtp_instance_fd(i->vrtp, 1));
  }
+ else if (i->vrtp) {
+ // Properly disable video if not needed
+ ast_rtp_instance_destroy(i->vrtp);
+ i->vrtp = NULL;
+ }
  if (needtext && i->trtp) {
  ast_channel_set_fd(tmp, 4, ast_rtp_instance_fd(i->trtp, 0));
  }

# mv my.patch /root/rpmbuild/SOURCES

Now we edit the spec file again and tell the spec file of our patch,

# cd /root/rpmbuild/SPECS
# nano asterisk11.spec

You will find two point at which editing will be required, for example in this case scenario the first one will be like :

....../.../.../.....
Patch09: asterisk-11.3.0-xorcom-busydetect-05-cap-limit-threshold.patch
Patch10: asterisk-11.3.0-xorcom-busydetect-06-dahdi-config-options-busydetect.patch
Patch11: asterisk-11.5.1-chan_allogsm-2.0.7-v2.patch
Patch12: asterisk-11.11.0-srtp-lifetime.patch
Patch13: my.patch

Notice how i placed the patch number 13, this is what we will be adding to spec file. One more entry is required to tell how to apply patch which we will put in like this :

....../.../.../.....
%patch09 -p1
%patch10 -p1
%patch11 -p1
%patch12 -p1
%patch13 -p1

Again indicated in red is the entry which i did to the spec file, now save the spec file and quit it. Now comes the best part :

# rpmbuild -bp asterisk.spec

This will apply your patch and your modded source is now available, now we build our source so that we can install it, this can be done very easily,

# rpmbuild -ba asterisk.spec

This will generate your rpm which will be located in the RPMS folder under your architecture, according to my case it was in :

# cd /root/rpmbuild/RPMS/x86_64

Now to install it we just do this :

# rpm -Uvh asterisk*.rpm

If you get conflicting errors try this :

# rpm -Uvh -force asterisk*.rpm

This marks the end of our tutorial.

Debian Package Building (Multi Ways)

Method 1

apt-get install build-essential fakeroot dpkg-dev devscripts gdebi

/etc/apt/sources.list

deb http://http.debian.net/debian wheezy-backports main
deb-src http://http.debian.net/debian wheezy-backports main

/home

apt-get -t wheezy-backports source strongswan
wget http://download.strongswan.org/strongswan-5.2.2.tar.gz

cd /strongswan-5.2.1

apt-get build-dep strongswan

uupdate ~/strongswan-5.2.2.tar.gz

cd /strong-5.2.2

dpkg-buildpackage -rfakeroot -us -uc -b

ls ../

all files available install by :

dpkg -i *.deb

apt-get -f install

and again dpkg -i *.deb

or gdebi *.deb

Method 2

apt-get install checkinstall

/home

wget http://download.strongswan.org/strongswan-5.2.2.tar.gz

tar xvfz strongswan-5.2.2.tar.gz

cd /strongswan-5.2.2

apt-get build-dep strongswan

./configure --enable-eap-identity --enable-eap-md5 \
--enable-eap-mschapv2 --enable-eap-tls --enable-eap-ttls --enable-eap-peap \
--enable-eap-tnc --enable-eap-dynamic --enable-eap-radius --enable-xauth-eap \
--enable-xauth-pam --enable-dhcp --enable-openssl --enable-addrblock --enable-unity \
--enable-certexpire --enable-radattr --enable-openssl --enable-kernel-libipsec

make

checkinstall

the packge will be installed confirm by :

ipsec version

this command will leave behind a deb file according to your architecture.

Tuesday, 6 January 2015

StrongSwan VPN ( ikev1 / ikev2 / psk / split tunelling )

Add Sources:

deb http://http.debian.net/debian wheezy-backports main
deb-src http://http.debian.net/debian wheezy-backports main

apt-get update

apt-get -t wheezy-backports install strongswan libcharon-extra-plugins

Check version installed :

ipsec version

Create certificates :

ipsec pki --gen --outform pem > ca.pem

ipsec pki --gen --outform pem > server.pem

ipsec pki --self --in ca.pem --dn "C=CN, O=strongSwan, CN=strongSwan CA" --ca --outform pem > ca.cert.pem

openssl x509 -outform der -in ca.cert.pem -out ca.cert.crt (for Windows compatible format)

ipsec pki --pub --in server.pem | ipsec pki --issue --cacert ca.cert.pem \
--cakey ca.pem --dn "C=CN, O=strongSwan, CN=YOURDOMAIN.COM" \
--san YOURDOMAIN.COM --flag serverAuth --flag ikeIntermediate \
--outform pem > server.cert.pem

cp -r server.pem ca.pem /etc/ipsec.d/private/

cp -r server.cert.pem /etc/ipsec.d/certs/

cp -r ca.cert.pem /etc/ipsec.d/cacerts/

modify the file accordingly :

nano /etc/ipsec.conf

config setup
    uniqueids=never

conn %default
        left=10.1.2.21
        leftsubnet=10.1.2.0/24
        leftfirewall=yes
        right=%any
        rightsourceip=10.8.1.0/24
        auto=add
       
conn shrewsoft_xauth_psk
        keyexchange=ikev1
        leftauth=psk  
        rightauth=psk
        rightauth2=xauth
       
conn windows7/8
        keyexchange=ikev2
        ike=aes256-sha1-modp1024!
        rekey=no
        leftauth=pubkey
        leftcert=server.cert.pem
        rightauth=eap-mschapv2
        eap_identity=%any

nano /etc/ipsec.secrets

10.1.2.21 %any : PSK "123"
test : XAUTH "456"
: RSA server.pem
user : EAP "456"

Enable ipv4 forwarding :

/etc/sysctl.conf

net.ipv4.ip_forward = 1
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0

Apply Settings immediately :

sysctl -p

Enable Natting :

iptables -A POSTROUTING -t nat -j SNAT --to-source 10.1.2.21

Modify for split tunneling for ikev1 :

nano /etc/strongswan.d/charon/attr.conf

attr {

    # <attr> is an attribute name or an integer, values can be an IP address,
    # subnet or arbitrary value.
    split-include=10.1.2.0/24
    split-exclude=0.0.0.0/0
    # Whether to load the plugin. Can also be an integer to increase the
    # priority of this plugin.
    load = yes

}

Enable Unity plugin :

nano /etc/strongswan.d/charon.conf

    # Send Cisco Unity vendor ID payload (IKEv1 only).
    cisco_unity = yes

service ipsec restart

Install ca.cert.pem or ca.cert.crt on windows client and the Use default gateway on remote network option in the Advanced TCP/IP settings of
the VPN connection has to be disabled. For ShrewSoft no modification is required.

Tuesday, 23 December 2014

Use Jessie Packages in Wheezy

Install gdebi package:

apt-get install gdebi

Add Source

echo "deb http://ftp.us.debian.org/debian jessie main contrib non-free" >> /etc/apt/sources.list

Download the the package:

apt-get download vsftpd

Install the package:

gdebi vsftpd.deb

Verify package version installed

dpkg -s vsftpd

Modify cnf file accordingly

echo "allow_writeable_chroot=YES" >> /etc/vsftpd.conf

Restart service for changes to take place:

service vsftpd start

Change default permission for uploaded files, here the trick

change umask values in conf

now if umask value is 000 that mean file uploaded will be with permission 777, therefore if u want to set the permission for the file to 755 just do the maths 777-755 = 022 , set this value for umask.

Copy a folder under linux server to windows server

Make Mounting Directory

mkdir -p /mnt/win
mount -t smbfs/cifs -o username=winntuser,password=mypassword //window-server-address-or-ip/foldername /mnt/win ( both cifs/smbfs work )


Next create the password file /etc/sambapasswords:

nano /etc/sambapasswords - then enter the credential as follows:

username = winntuser
password = mypassword


make sure that only root have access to it,

chown root:root /etc/sambapasswords
chmod 600 /etc/sambapasswords


Add an entry to your /etc/fstab:

//windowserver/share /mnt/win smbfs/cifs
auto,gid=users,fmask=0664,dmask=0775,iocharset=iso8859-15,credentials=/etc/sambapasswords 0 0

Make a Cron Job !

crontab -e

0 1 * * * cp /path/to/yourbackup /mnt/win 

Which mean a backup daily at 1AM.