Wednesday, 8 May 2013
Secure your website with SSL - guidelines and experience
1.
First generate the key file
$ openssl genrsa -des3 -out server.key 2048
It will ask for a pass phrase, which will be further used to start the web server, so save it properly
2.
Now generate the CSR (Certificate Signing Request) file
$ openssl req -new -key server.key -out server.csr
This ask informations like, Location, Company Name, Common Name. Its better to ignore the "challenge password". Be careful with entering common name, which has to be your domain name.
If you serve your users with www.example.com, common name should be "www.example.com". Once certificate is issued for www.example.com, it won't be valid for example.com. If you want to secure with and without www, there is a certain preference you'll have to choose at the time of buying the certificate. If you want to secure all subdomains, there will be different prerefernece as well. Depending of number of sub domains you are looking for to make secure, cost will also vary. As of today verisign charges $ 400 USD for one domain, $ 600 for with and without www, and around $ 1500 USD for securing infinite sub domains.
3. Now use this CSR and avail the certificates which is crt file from any CA (certificate authority) company like verisign(costliest), go daddy cheapest (may be $ 10 USD)
4. Once you buy the SSL certificate, the product management will guide you on how to get the certificates. Its very simple.
5. In case of verisign, they will take average of 2 to 4 days for the entire process execution, as they will validate "CSR Verification", "Proof of Organization" and "Proof of Domain Registration".
They would ask company registration certificates also as a part of process. But if you buy from go daddy, no verification process, only based on CSR file they will issue you the certificates within a minute.
6. At the time of downloading the certificates makes sure that you also download the intermediate certificate. Intermediate certificates are connecting the certificate chains. In few browsers(without having intermediate certificate), some users might face unwanted error message.
7. Deploying the certificates, copy these 3 files at the following places and restart Apache
$ cp server.key /etc/ssl/private/
$ cp example.com.crt /etc/ssl/certs/
$ cp intermediate.crt /etc/ssl/certs/
8. Now change in apache
Enable the ssl module, if you are on debian(Ubuntu, RedHat) systems then you can use command a2enmod ssl.
Go to virtual host configuration and write these lines
SSLEngine on
SSLProtocol -all +TLSv1 +SSLv3
SSLCertificateKeyFile /etc/ssl/private/server.key
SSLCertificateFile /etc/ssl/certs/example.com.crt
SSLCertificateChainFile /etc/ssl/certs/intermediate.crt
$ /etc/init.d/apache2 restart (It will ask for the pass phrase that you created at step 1)
- and its Done :)
8. To validate everything done properly or not there are several websites to check one is, http://www.sslshopper.com/ssl-checker.html
Monday, 4 March 2013
How to setup replication (Master Slave) in MySQL
I'll start the article by assuming that there are two MySQL server ready and we just need to do the configuration setup to start the replication.
mysql > change MASTER TO Master_Log_File='mysql-bin._desired_bin_log_file'
Go to Master Server
1. Make all the tables engine = innodb
As only innodb engines have binary logging feature which is essentially used for replication. Binary logging must be enabled on the master because the binary log is the basis for sending data changes from the master to its slaves. If binary logging is not enabled, replication will not be possible. MyIsam does not support binary logging.
Use following command to convert all the tables to InnoDB
mysql > SELECT CONCAT('ALTER TABLE ', table_name, ' ENGINE=InnoDB;') as ExecuteTheseSQLCommands
FROM information_schema.tables WHERE table_schema = 'db_name'
ORDER BY table_name DESC;
2. Start binary logging on Master and Assign server Id (Server ID assigning is necessary, If you omit server-id (or set it explicitly to its default value of 0), a master refuses connections from all slaves).
edit the file /etc/mysql/my.cnf
[mysqld]
log-bin=mysql-bin
server-id=101
*For the greatest possible durability and consistency in a replication setup using InnoDB with transactions, you should use innodb_flush_log_at_trx_commit=1 and sync_binlog=1 in the master my.cnf file.
3. Create a slave user on Master DB
mysql> grant REPLICATION SLAVE on *.* to 'slave'@'IP_ADDRSS_OF_SLAVE' identified by 'slavePassword';
mysql> flush privileges;
4. Restart Master DB
and check
mysql> show master status;
You can also check if mysql-bin log files are getting created on not, where you have given path of data to be stored, may be at /var/lib/mysql
5. Take a dump of database
mysqldump -uroot -proot --single-transaction --master-data --databases db1,db2 > all_db.sql
And transfer the file on slave Machine
Go to slave Machine
6. Assign Server Id on slave DB
[mysqld]
server-id=102
7. Restart Slave DB
8. Import the dump file in database
mysql -uroot -proot < all_db.sql
9. Make this slave listen to Master
mysql> CHANGE MASTER TO MASTER_HOST='MASTE_HOST_IP_ADDRESS',MASTER_USER='slave',MASTER_PASSWORD='slavePassword';
mysql> flush privileges;
10. slave start
mysql > slave start;
mysql > show slave status;
DONE :)
Some troubleshoots and points:
- You can configure on slave mysql configuration that which all database or even which all tables you want to replicate or do not want to replicate
http://dev.mysql.com/doc/refman/5.0/en/replication-options-slave.html - If replication fails due to data consistency issue means, data already exist in slave and master is still trying to push (may be due to several kind of issue), you can change the slave configuration to move ahead
mysql > change MASTER TO Master_Log_File='mysql-bin._desired_bin_log_file'
Reference : http://dev.mysql.com/doc/refman/5.0/en/replication-howto.html
Wednesday, 27 February 2013
Using POP on multiple clients or mobile devices
Using POP on multiple clients or mobile devices
If you have configured the email on outlook and on Blackberry/Android/iPhone/Gmail too, and on one of the client you are not able to receive the email, this article is useful to you.
Essentially POP (Post office protocol) is a one-way download of your messages that allows you to access your mail with a mail program like Outlook Express or Apple Mail. POP only offers one-way communication, which means that actions you take in the mail program. You should know two things "recent mode" and "Leave a copy of message on server".
Essentially POP (Post office protocol) is a one-way download of your messages that allows you to access your mail with a mail program like Outlook Express or Apple Mail. POP only offers one-way communication, which means that actions you take in the mail program. You should know two things "recent mode" and "Leave a copy of message on server".
What is 'recent mode?'
If you're accessing Gmail on multiple clients through POP, Gmail's 'recent mode' makes sure that all messages are made available to each client, rather than only to the first client to access new mail.
Recent mode fetches the last 30 days of mail, regardless of whether it's been sent to another POP1 client already.
Setting up 'recent mode'
In your POP client settings, replace 'username@gmail.com' in the 'Username' or 'Email' field with 'recent:username@gmail.com'
Once you enable recent mode, please be sure to configure your POP client to leave messages on the server according to the instructions below:
- Outlook or Outlook Express: on the Advanced tab, check the box next to 'Leave a copy of messages on the server.'
- Apple Mail: on the Advanced tab, remove the check next to 'Remove copy from server after retrieving a message.'
- Thunderbird: on the Server Settings tab, check the box next to 'Leave messages on server.'
* This is an exact copy the URL https://support.google.com/mail/bin/answer.py?hl=en&answer=47948
Friday, 22 February 2013
Updating and installing package on debian machine
Its very simple :)
APT (Advance Package Tool) is a free user interface which is used in debian machine to install/remove/update any software. For the same in Red Hat machine is "yum".
How to search a package and Install?
Points :
- $ apt-cache search
"Is the command to search a package" - $ apt-get install
"Is the command to install a package" - apt-cache - query the APT cache
- apt-cache search/madison are two important commands you should know
- $ apt-cache search - "Performs a full text search on all available package lists for the POSIX regex pattern given"
- $ apt-cache madison - "Command attempts to mimic the output format and a subset of the functionality of the Debian archive management tool, madison. It displays available versions of a package in a tabular format"
- sudo apt-get install
=version - "Is the command to install a package with a certain version" - dpkg -s
- "Is the command to about the package"
Example :
$ apt-cache search mysql-server
cacti - Frontend to rrdtool for monitoring systems and services
phpbb2-conf-mysql - Automatic configurator for phpbb2 on MySQL database
torrentflux - web based, feature-rich BitTorrent download manager
mysql-server - MySQL database server (meta package depending on the latest version)
mysql-server-5.0 - MySQL database server binaries
$ apt-cache madison mysql-server
mysql-server | 5.0.96-0ubuntu3 | http://us.archive.ubuntu.com hardy-security/main Packages
mysql-server | 5.0.96-0ubuntu3 | http://us.archive.ubuntu.com hardy-updates/main Packages
mysql-server | 5.0.51a-3ubuntu5 | http://us.archive.ubuntu.com hardy/main Packages
Now if you want to install a certain version package, you should use
$ apt-get install mysql-server=5.0.96-0ubuntu3
Command to know about the package
$ dpkg -s mysql-server
References
1. http://manpages.ubuntu.com/manpages/natty/man8/apt-cache.8.html
2. http://manpages.ubuntu.com/manpages/hardy/man8/apt-get.8.html
Sunday, 17 February 2013
Mysql Database Configuration, Access settings, Innodb configuration, Log slow query
To bind the server Access point
-----------------------------------
By default it is binded to localhost or 127.0.0.1
Open /etc/mysql/my.cnf fine
So lets say you have 4-5 machines from which you want to access mysql DB from any of the machine, but you do not want anyone from outside to access this,
bind-address will be Local LAN Ip Address.
bind-address = Local LAN IP Address
If you want only local machine to access mysql DB
bind-address = 127.0.0.1
If you want to make it public, remove the bind-address line.
Logging the slow queries
-----------------------------
log_slow_queries = /var/log/mysql/mysql-slow.log
long_query_time = 1
Logging the queries which are not using index
---------------------------------------------------
log-queries-not-using-indexes
Changing the InnoDB configuration
----------------------------------------
Buffer Pool Size is the memory which you provide to mysql server program.
innodb_buffer_pool_size=5120M
innodb_lock_wait_timeout=20
innodb_rollback_on_timeout
max_allowed_packet :
The max_allowed_packet variable limits the size of a single result set. In the [mysqld] section, any normal connection can only get that much worth of data in a single query. In mysqldump you typically produce "extended INSERT" queries, where you list multiple rows within the same INSERT command. It's better, then, to have this variable set high. In mysqld max_allowed_packet could be 16M (to be safe, because it doesn't uses memory until required), in mysqldump, max_allowed_packet could be 128M or may be 512M, depends on your machine and requirement.
If you want mysqldump to work fast
---------------------------------------
[mysqldump]
quick
quote-names
max_allowed_packet = 64M (Increase this value, default is 16M)
* You can also take take dump faster by passing as a command argument
$ mysqldump -u root -p --max_allowed_packet=512M dbname > dbname.sql
More Ideas on MySQL performance tuning
1. https://blogs.oracle.com/luojiach/entry/mysql_innodb_performance_tuning_for
2. http://www.mysqlperformanceblog.com/2007/11/01/innodb-performance-optimization-basics/
Labels:
access_setting,
innodb,
log_slow_queries,
mysql,
mysql_performance
Wednesday, 16 January 2013
After setting javaagent in classpath tomcat is not starting
Q. I am trying to use newrelic as javaagent in tomcat on ubuntu machine. When I set the javaagent in classpath, tomcat fails to start. I tried with tomcat5 and tomcat7, its not starting. And I am not getting any log also to check anything.
I tried doing the same with tracelytics javaagent, still its the same, tomcat is not starting. And clue, no log, someone please help.
A. It was happening due to setting of Xss configuration at the time server start in CATALINA_OPTS. I had set it to 128K, somehow it was failing to start. But when I removed that setting, it started, then I changed to 256K then also it started. I am not sure about the inside story, but at least it is working now :)
Friday, 7 December 2012
What to do when you get a new server?
First of all have a big smile mmmmmmmmmmmmmm :)
It's always been a lovely experience to play with a new server, it's like you got a new power source and you start thinking of how to optimize the utilization of the resource, Shall i create distributed memory system or I shall deploy some other components on this machine because it is having higher computation power, woooow. It's fascinating.
Any ways, I am first writing this basic set of commands which will work on Debian systems (and yes Ubuntu is built on Debian architecture), to set the basic things always required on a new machine.
First thing you must do is
$ apt-get update
$ apt-get upgrade
1. Using command apt-cache you can search the package
apt-cache search jdk
2. Using command apt-get you can install the package
$ apt-get install openjdk-6-jdk
$ apt-get install mysql-server
$ apt-get install atop
If you want only mysql client - try this
$apt-get install mysql-client-5.5
3. Set the timezone on debian machine
$ dpkg-reconfigure tzdata
And choose Asia->Kolkata
4. Installing sar on ubuntu
$ sudo apt-get install sysstat
$ sudo vi /etc/default/sysstat
change ENABLED=”false” to ENABLED=”true”
$ sudo vi /etc/cron.d/sysstat
Change 5-55/10 * * * * root command -v debian-sa1 > /dev/null && debian-sa1 1 1
To */2 * * * * root command -v debian-sa1 > /dev/null && debian-sa1 1 1
$ sudo service sysstat restart
$ sar -A
If you want to save the statistics for further analysis to a file use:
$ sudo sar -A > $(date +`hostname`-%d-%m-%y-%H%M.log)
5. apt-get install zip
6. You might want to change the file limits - find details at here
http://nishal-tech.blogspot.in/2013/07/how-to-set-ulimit-in-ubuntudebian-linux.html
6. You might want to change the file limits - find details at here
http://nishal-tech.blogspot.in/2013/07/how-to-set-ulimit-in-ubuntudebian-linux.html
Subscribe to:
Posts (Atom)