31 July 2010

Make changes to .bash_profile and need to update the current session?

$ source .bash_profile


With the above command, the user does not have to logout.

How to skip a service while starting in HP-UX

During the HP-UX OS booting,if you want the service/daemon need to be skipped  press crtl + backslash.

Most of us tried pressing ctrl + c, that wont work during the booting

18 January 2010

Symbolic links

namei can be used to trace the endpoint of a cascaded symbolic link

Eg.,

$ namei /dev/cdrw
f: /dev/cdrw
 d /
 d dev
 l cdrw -> scd0
   b scd0
$

SELinux....

Most of the Linux admins especially working on RedHat used to disable this option during installation ofcourse includes me as well....But later i realised the feature it offers.

Today much attention has been paid to network security,data security and computing security using various products available in the market but none of us are realizing the local exploit(Malware/Malicious) is a big one than the rest of the things.

SELinux takes care of control this local exploit....in other words its a kind of access control mechanism.


Is that is the only reason we need this....or do we have a flaw in the existing access control system.

Inherent flaw in the traditional permissions model is DISCRETION.I.e.,Owner of a particular file can change the permissions at his own will which might result in security breach.

By contrast,SELinux implements Mandatory Access Control(MAC) where access control decisions are not at the discretion of individual users or even system administrators.

22 December 2009

HP-UX Boot process


HP-UX OS Boot Process - PA-RISC Machines

19 January 2009

Fault tolerance for NIC

More and more data centers are in the process of setting up unmaned data centers.Admins are trying their best to have a fault tolerance solution for each software and Hardware component.
Here is a fault tolerance soultion for a Network interface via bonding in Linux

1.Create a file ifcfg-bond under /etc/sysconfig/network-scripts where is the binding number.
2.cat ifcfg-bond0

DEVICE=bond0
BOOTPROTO=none
ONBOOT=yes
NETWORK=192.168.41.0

NETMASK=255.255.255.0
IPADDR=192.168.41.250
USERCTL=no


3.Network interfaces to be bound together must be configured by adding MASTER= and SLAVE= directives to their configuration files.

4.Configuration files for the two interface files

DEVICE=eth<0/1>
BOOTPROTO=none

ONBOOT=yes
MASTER=bond0

SLAVE=yes
USERCTL=no

5.Configuring alias in modprobe.conf
alias bond0 bonding

options bond0 milmon=80 mode=1

modprobe to activate the aliases and restart the network service.

6. Now bond0 will be up.Output of ifconfig will show the same ip-address for bond0,eth0 & eth1.

27 August 2008

How to list the contents of the EFI directory on hp-ux IPF systems?

First find the default boot device using the setboot command
# setboot
Primary bootpath : 0/4/1/0.0.0.7.0
HA Alternate bootpath : 0/0/2/0
Alternate bootpath : 0/4/1/0.0.0.6.0
Autoboot is ON (enabled)#


Find the corresponding dirver for the Hardware path using ioscan
# ioscan -funC disk

disk 39 0/4/1/0.0.0.6.0 sdisk CLAIMED DEVICE HP DG146ABAB4
/dev/dsk/c17t6d0 /dev/dsk/c17t6d0s2 /dev/rdsk/c17t6d0 /dev/rdsk/c17t6d0s2
/dev/dsk/c17t6d0s1 /dev/dsk/c17t6d0s3 /dev/rdsk/c17t6d0s1 /dev/rdsk/c17t6d0s3
disk 40 0/4/1/0.0.0.7.0 sdisk CLAIMED DEVICE HP DG146ABAB4
/dev/dsk/c17t7d0 /dev/dsk/c17t7d0s2 /dev/rdsk/c17t7d0 /dev/rdsk/c17t7d0s2
/dev/dsk/c17t7d0s1 /dev/dsk/c17t7d0s3 /dev/rdsk/c17t7d0s1 /dev/rdsk/c17t7d0s3
#


List the contents of EFI shell.This can be useful to compare root and root mirror disks.

# lifls -l /dev/rdsk/c17t7d0s2
volume ISL10 data size 7984 directory size 8 06/10/27 14:23:07
filename type start size implement created
===============================================================
ISL -12800 584 242 0 06/10/27 14:23:07
AUTO -12289 832 1 0 06/10/27 14:23:07
HPUX -12928 840 1024 0 06/10/27 14:23:07
PAD -12290 1864 1468 0 06/10/27 14:23:07
LABEL BIN 3336 8 0 08/07/01 05:19:23#

22 August 2008

Sudoers file on Solaris 10

sudo is available from the SFWsudo package on Solaris 10.
To use it a /etc/sudoers file has been set but still leading to the following error

user NOT in sudoers

Hopefully, truss will help :-)

root@server:/# truss -o /tmp/output sudo ls

The /tmp/output file is answering the enigma:

root@server:/# grep sudoers /tmp/output
lstat("/opt/sfw/etc/sudoers", 0xFFBFFB28) = 0
open("/opt/sfw/etc/sudoers", O_RDONLY) = 4

The sudoers file to edit is in /opt/sfw/etc

01 July 2008

Raw devices & Block devices

Most of the people will get confused when to use /dev/dsk/c0t1d0s7 and /dev/rdsk/c0t1d0s7 device files.

Generally /dev/dsk is a block disk device whereas /dev/rdsk is a character disk device

As a thumb rule raw devices are used before filesystem creation.Block devices are user after filesystem creation.

E.g., In Solaris whenever you create a new slice using format command a raw physical slice or a Raw Device will be created which is addressed as /dev/rdsk/c#t#d#s#
After formatting it with newfs command the slice will be addressed as /dev/dsk/c#t#d#s# which can now be used for mounting.

newfs /dev/rdsk/c0t1d0s4
mkdir /oracle
mount /dev/dsk/c0t1d0s4 /oracle

After mounting /dev/dsk/c#t#d#s# is called as Block Device

29 May 2008

Soft limit & Hard limit

Most of us encountered to increase the limit of file descriptors while installing a high end 3pp(party product).In doing so we will encounter with two different kinds of limits i.e.soft vs hard.

Hard limits are a kernel-configurable item and users can't exceed them. Soft limits are the user defaults and users can change that using the ulimit command.

Basically, soft limits can be changed to anything up to the hard limit. Soft limits are warning barrier. When a user reaches the soft limit they will get an warning message but are still allowed to use more space up to the hard limit.

Since its a kernel tunable we have to define the value in /etc/system and /etc/sysctl.conf for Pre-Solaris 10 and Linux respectively.

E.g.,

To set a hard limit of 4096 and soft limit of 1024 in Solaris 8.

set rlim_fd_max=4096 [Refers Hard limit]
set rlim_fd_cur=1024 [Refers Soft limit]


To raise the allowed limit in Linux based distributions update either /etc/limits.conf or /etc/security/limits.conf