you have an ldap db dump called import.ldif . you need to replace
an existing ldap database with import.ldif . do this:
!/bin/bash
TIMESTAMP=$(date '+%Y%m%d%H%M')
/etc/init.d/slapd stop ;
mv /var/lib/ldap /var/lib/ldap-$TIMESTAMP ;
mkdir /var/lib/ldap ;
cp /etc/ldap/DB_CONFIG /var/lib/ldap ;
slapadd -c -l /tmp/import.ldif ;
chown -R openldap.openldap /var/lib/ldap ;
/etc/init.d/slapd start
Tuesday, January 30, 2018
import ldap db dump
Friday, January 26, 2018
bind9 logging reprise
in a previous post i mentioned how to do bind9 logging.
i found there was too much information in the single file.
instead, i have culled out the different notices in to separate files.
for logrotate, since all the log files are in one directory, all you
need to do is place a wildcard attribute in the configuration file.
and apparmor may hate you and deny you ability to create logs.
if you're like me and like logs to be created under the daemon's name
e.g. /var/log/bind for bind...
edit:
/etc/apparmor.d/usr.sbin.named
and give it /var/log/bind/** rw,
as opposed to /var/log/named ** rw,
# bind.local.log
logging {
channel query_log {
file "/var/log/bind/query.log" versions 3 size 5m;
// Set the severity to dynamic to see all the debug messages.
print-category yes;
print-severity yes;
print-time yes;
severity dynamic;
};
channel update_debug {
file "/var/log/bind/update_debug.log" versions 3 size 5m;
severity debug ;
print-category yes;
print-severity yes;
print-time yes;
};
channel security_info {
file "/var/log/bind/security_info.log" versions 3 size 5m;
severity info;
print-category yes;
print-severity yes;
print-time yes;
};
channel bind_log {
file "/var/log/bind/bind.log" versions 3 size 5m;
severity info;
print-category yes;
print-severity yes;
print-time yes;
};
category queries {
query_log;
};
category security {
security_info;
};
category update-security {
update_debug;
};
category update {
update_debug;
};
category lame-servers {
null;
};
category default {
bind_log;
};
};
# /etc/logrotate.d/bind
/var/log/bind/*.log {
daily
missingok
rotate 7
compress
delaycompress
notifempty
create 644 bind bind
postrotate
/usr/sbin/invoke-rc.d bind9 reload > /dev/null
endscript
}
Tuesday, January 23, 2018
flush rndc
my bind9 dns server is reporting different ips for a host when i...
localhost $ dig @localhost.ip address
and
remotehost $ dig @localhost.ip address
this is due to a weirdo cache on localhost.
the best thing to do is flush the dns cache.
localhost $ rndc flush
easy.
bind9 logs be freed of syslog
I want to know who is requesting what on my bind9 server.
Time to cull out those logs from /var/log/syslog .
$ vi /etc/bind/named.conf
just before named.conf.local , put in this line:
include "/etc/bind/named.conf.log";
$ vi /etc/bind/named.conf.log
logging {
channel bind_log {
file "/var/log/bind/bind.log" versions 3 size 5m;
severity info;
print-category yes;
print-severity yes;
print-time yes;
};
category default { bind_log; };
category update { bind_log; };
category update-security { bind_log; };
category security { bind_log; };
category queries { bind_log; };
category lame-servers { null; };
};
see that directory? create it and perm it
$ mkdir /var/log/bind ; chown bind:bind /var/log/bind
your logs will be large with all that debug stuff. rotate them!
$ vi /etc/logrotate.d/bind
/var/log/bind/bind.log {
daily
missingok
rotate 7
compress
delaycompress
notifempty
create 644 bind bind
postrotate
/usr/sbin/invoke-rc.d bind9 reload > /dev/null
endscript
}
$ /etc/init.d/bind9 restart
excitement.
Thursday, January 18, 2018
robocopy a local user profile between servers
robocopy c:\Users\source \\newserver\C$\Users\source *.* /mir /sec /r:1 /w:1 /LOG:C:\Mirlog.txt /XD “RECYCLER” “Recycled” “System Volume Information” /XF “desktop.ini” “thumbs.db”
get all ip addresses from netlogon.log and mail it
name this something.ps1 and run it to get all ipdresses from netlogon.log and mail them to yourself.
# Script to get the IP addresses of clients from the Netlogon.log file of all domain controllers in the current domain
# from the current month and the previous month
################################Start Functions####################################
function GetDomainControllers {
$DCs=[system.directoryservices.activedirectory.domain]::GetCurrentDomain() | ForEach-Object {$_.DomainControllers} | ForEach-Object {$_.Name}
return $DCs
}
function GetNetLogonFile ($server) {
#build Path variable
$path= '\\' + $server + '\c$\windows\debug\netlogon.log'
#Try to connect to $path and get the file contents or throw an error
try {$netlogon=get-content -Path $path -ErrorAction stop}
catch { "Can't open $path"}
#reverse the array's order so we are now working from the end of the file back
[array]::Reverse($netlogon)
#clear out the holding variable
$IPs=@()
#go through the lines
foreach ($line in $netlogon) {
#split the line into pieces using a space as the delimiter
$splitline=$line.split(' ')
#Get the date stamp which is in the mm/dd format
$logdate=$splitline[0]
#split the date
$logdatesplit=($logdate.split('/'))
[int]$logmonth=$logdatesplit[0]
#only worry about the last month and this month
if (($logmonth -eq $thismonth) -or ($logmonth -eq $lastmonth)) {
#only push it into an array if it matches an IP address format
if ($splitline[5] -match '\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b'){
$objuser = new-object system.object
$objuser | add-member -type NoteProperty -name IPaddress -value $splitline[5]
$objuser | add-member -type NoteProperty -name Computername -value $splitline[4]
$objuser | add-member -type NoteProperty -name Server -value $server
$objuser | add-member -type NoteProperty -name Date -value $splitline[0]
$objuser | add-member -type NoteProperty -name Time -value $splitline[1]
$IPs+=$objuser
}
} else {
#break out of loop if the date is not this month or last month
break
}
}
return $IPs
}
###############################End Functions#######################################
###############################Main Script Block###################################
#Get last month's date
$thismonth=(get-date).month
$lastmonth=((get-date).addmonths(-1)).month
#get all the domain controllers
$DomainControllers=GetDomainControllers
#Get the Netlogon.log from each DC
Foreach ($DomainController in $DomainControllers) {
$IPsFromDC=GetNetLogonFile($DomainController)
$allIPs+=$IPsFromDC
}
#Only get the unique IPs and dump it to a CSV file
$allIPs | Sort-Object -Property IPaddress -Unique | Export-Csv "C:\NetlogonIPs.csv"
#Set up mail variables
$from="me@here"
$to="me@here"
$subject="IP addresses in Netlogon.log file from the last month"
$attach="C:\NetlogonIPs.csv"
$body="File containing all unique IPs listed in the netlogon.log file for all the Domain Controllers in the company domain."
#Send mail message
Send-MailMessage -from $from -To $to -subject $subject -SmtpServer smtpserver -Body $body -BodyAsHtml -Attachments $attach
Thursday, October 26, 2017
openssl is too old. of course.
I was having a good morning. I got to work on time and had a cup of coffee.
The world was good.
Then I see this:
Downloading: https://zlib.net/fossils/zlib-1.2.11.tar.gz
javax.net.ssl.SSLException: hostname in certificate didn't match: <zlib.net> != <amanekaneko.com> OR <amanekaneko.com> OR <cpanel.amanekaneko.com> OR <mail.amanekaneko.com> OR <webdisk.amanekaneko.com> OR <webmail.amanekaneko.com> OR <www.amanekaneko.com>
browsing amanekaneko.com is fascinating, to say the least
me@:~/certs$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz
--2017-10-26 12:20:05-- https://zlib.net/fossils/zlib-1.2.11.tar.gz
Resolving zlib.net... 69.73.182.198
Connecting to zlib.net|69.73.182.198|:443... connected.
ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.
To connect to zlib.net insecurely, use `--no-check-certificate'.
What?!
I see the same across a bunch of build systems. ffs.
Maybe it is the firewall doing something weird.
Nope.
me@:/etc/ssl/certs$ openssl version -a
OpenSSL 0.9.8k 25 Mar 2009
built on: Thu Mar 19 15:32:30 UTC 2015
platform: debian-i386-i686/cmov
options: bn(64,32) md2(int) rc4(idx,int) des(ptr,risc1,16,long) blowfish(idx)
compiler: cc -fPIC -DOPENSSL_PIC -DZLIB -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLF
CN -DHAVE_DLFCN_H -DL_ENDIAN -DTERMIO -O3 -march=i686 -Wa,--noexecstack -g -Wall
-DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DSHA1_ASM -DMD5_ASM -DRMD160_A
SM -DAES_ASM
OPENSSLDIR: "/usr/lib/ssl"
All certs are here: /etc/ssl/certs
All symlinked to: /usr/share/ca-certificates/
$JAVA_HOME/lib/security/cacerts is the same.
SSL_CERT_FILE:/etc/ssl/certs/ca-certificates.crt
openssl
apt-get reinstall openssl
apt-get reinstall ca-certificates
cd /usr/lib/ssl/certs
c_rehash
yet.
me@:~$ openssl s_client -connect zlib.net:443
CONNECTED(00000003)
depth=2 /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority
verify error:num=20:unable to get local issuer certificate
verify return:0
I need the /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority certificate.
It is present. Very present.
but.
me@:~$ openssl s_client -CApath /etc/ssl/certs/ -connect zlib.net:443 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > zlibnet.pem
depth=3 /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root
verify return:1
depth=2 /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority
verify return:1
depth=1 /C=US/ST=TX/L=Houston/O=cPanel, Inc./CN=cPanel, Inc. Certification Authority
verify return:1
depth=0 /CN=amanekaneko.com
verify return:1
DONE
cat the output and yep. the pem is pem-a-licious.
me@:~$ sudo cp zlibnet.pem /usr/lib/ssl/certs
me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz
--2017-10-26 12:15:48-- https://zlib.net/fossils/zlib-1.2.11.tar.gz
Resolving zlib.net... 69.73.182.198
Connecting to zlib.net|69.73.182.198|:443... connected.
ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.
To connect to zlib.net insecurely, use `--no-check-certificate'.
Nope. Weird. Well, that's new. Let's see what happens if we specify the cert dir.
me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz --ca-certificate=/usr/lib/ssl/certs
--2017-10-26 12:15:48-- https://zlib.net/fossils/zlib-1.2.11.tar.gz
Resolving zlib.net... 69.73.182.198
Connecting to zlib.net|69.73.182.198|:443... connected.
ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.
To connect to zlib.net insecurely, use `--no-check-certificate'.
No? So. certificate common name doesn't match requested host name. Why?
OpenSSL is too old.
OpenSSL 0.9.8k 25 Mar 2009 <- too old
me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz --no-check-certificate
me@:~$ curl https://zlib.net/fossils/zlib-1.2.11.tar.gz --insecure
or
curl -L --remote-name https://zlib.net/fossils/zlib-1.2.11.tar.gz
Subscribe to:
Posts (Atom)