Pages

Wednesday, 18 January 2012

PXE Installation

PXE Installation 

Red Hat allows you to install the OS over the network using NFS, FTP or HTTP. If the hardware supports PXE (Pre-eXecution Environment) the NIC card will send out a broadcast request for DHCP information. The DHCP server provides the client with a IP address and other network infomation such as the TFTP server address (which provides the files necessary to start the installation) and the location of the files on the TFTP server. This is possible because of PXELINUX, which is part of the syslinux package.

In order to setup a PXE installation the following must be carried out:
Install the necessary packages
Configure the network (NFS, FTP, HTTP) server to export the installation tree (redhat packages, etc)
Configure the DHCP server
Configure the files on the tftp server necessary for PXE booting
Configure which hosts are allowed to boot from the PXE configuration
Configure the Kickstart file
Boot and start the installation

Software Packages (required) 

The following software packages are required
tftp-server-*
tftp-client-* (for testing)
dhcp-*
xinetd-*
system-config-netboot-* (supplies the prelinux.0 file)

Installation Tree

In my examples below i have used the directory /export/kickstart but this could be anything you like.

Basically create the directory and share the directory to the world, then copy the complete fedora/RHEL dvd or cdroms to this directory, once copied you should have something simular to below

total 52 drwxr-xr-x 10 root root 4096 Oct 6 13:38 . 
drwxr-xr-x 3 root root 4096 Oct 6 09:45 .. 
drwxrwsr-x 4 root root 4096 Mar 15 2006 Fedora 
drwxrwsr-x 3 root root 4096 Mar 15 2006 figs 
drwxrwsr-x 4 root root 4096 Mar 15 2006 images 
drwxrwsr-x 2 root root 4096 Mar 15 2006 isolinux 
drwxr-xr-x 2 root root 4096 Oct 6 14:00 ks (this is where my kickstart files are held) 
drwx------ 2 root root 16384 Oct 6 09:47 lost+found 
drwxrwsr-x 2 root root 4096 Mar 15 2006 repodata 
drwxrwsr-x 2 root root 4096 Mar 15 2006 stylesheet-images


DHCP Installation 

Once the DHCP package has been installed, a basic configuration file needs to be setup in /etc/dhcpd.conf, again this configuration file can be has advanced as you want it to be. 

#
# DHCP Server Configuration file.
#   see /usr/share/doc/dhcp*/dhcpd.conf.sample  
ddns-update-style ad-hoc;

deny unknown-clients;
not authoritative;

option domain-name              "example.com";
option domain-name-servers      ???.???.???.???, ???.???.???.???;
option subnet-mask              255.255.255.0;

allow bootp;
allow booting;

option ip-forwarding    false;  # No IP forwarding
option mask-supplier    false;  # Don't respond to ICMP Mask req

subnet 192.168.0.0 netmask 255.255.255.0 {
  option routers        192.168.0.1;
}

group {
  next-server 192.168.0.50;          # name of your TFTP server
  filename "linux-install/pxelinux.0";        # name of the bootloader program

  host fedora5 {
        hardware ethernet 00:0C:29:D5:B8:A0;
        fixed-address 192.168.0.40;
  }
}



The above file will setup the host fedora5 (note the specific MAC address associated to the host fedora5) and boot from the next-server (tftp server) using the pxelinux.0 boot file, which in turn will look for the pxe configuration boot file.

PXE Boot Configuration Files 

The PXE boot configuration basically is setting up the /tftpboot directory to allow clients to download the PXE boot configuration script and allow access to the initial ram disk (initrd.msg) and the linux kernel (vmlinuz).

The tftpboot directory will contain the following directories and files
/tftpboot/linux-install/prelinux.0 This file is the PXE boot file and will be run immediately after the the client has connected to the tftp server. /tftpboot/linux-install/msgs This directory contains the boot messages/menus displayed when the client boots /tftpboot/linux-install/pxelinux.cfg This directory contains the PXE boot configuration scripts, normally named C0A80023 (ip address of host in HEX) /tftpboot/linux-install/RHEL4 This directory is optional and is created when using the system-config-netboot or pxeos commands. It is used to hold kickstart scripts, linux kernels and ram disks for specific installations.

Two commands are used to configure the tftpboot area pxeos and pxeboot

Using the command below will create a directory called RHEL4 and copy the necessary linux kernel and ram disk files (normally located in images/pxeboot directory of the installation tree), we are also stating that we will use NFS to install the OS onto clients
# pxeos -a -i "<description>" -p NFS -D 0 -S <tftp IP addr> -K nfs:<kickstartserver>:/export/kickstart -L /export/kickstart RHEL4

-a Specifies that an OS instance is being added to the PXE configuration -i Description of the OS instance -p Specify which protocol to use for the o/s installation (NFS, FTP, HTTP) -D Specify if client is diskless (0=network, 1=diskless) -s Provides the name of the NFS, FTP or HTTP server -L Provides the location of the installation tree (o/s rpms, etc) -k provide the specific kernel version of the server installation tree for booting -K provide the location of the kickstart file os-identifier OS identifier to keep different build seperate

The above command would have copied the linux kernel (vmlinuz) and ram disk (initrd.msg) to the /tftpboot/linux-install/RHEL4 directory and also created a blank kickstart configuration file( i will be using my own kickstart file discussed later). Also the command would have created a pxe boot default file in the /tftpboot/linux-install/pxelinux.cfg directory as below:

default local
timeout 100
prompt 1
display msgs/boot.msg
F1 msgs/boot.msg
F2 msgs/general.msg
F3 msgs/expert.msg
F4 msgs/param.msg
F5 msgs/rescue.msg
F7 msgs/snake.msg


label 0
localboot 1


label 1
  kernel RHEL5/vmlinuz
  append initrd=RHEL5/initrd.img ramdisk_size=5939 ks=nfs:192.168.0.50:/export/kickstart/ks/default.ks


To setup specific pxe boot configuration files we use a command called pxeboot, this will override the above default boot configuration file
pxeboot -a -K <kickstart server> -O OS identifier <hostname>

-a add a specific host -K location of kickstart file -O OS identifier hostname hostname



The above command will create a file called C0A80028 (IP address in HEX) located in /tftp/linux-install/pxelinux.cfg, which is the specific boot configuration file for that host. 































default RHEL5
label RHEL5
          kernel RHEL5/vmlinuz
          append initrd=RHEL5/initrd.img  ramdisk_size=5939 ks=nfs:192.168.0.50:/export/kickstart/ks/default.ks 


After the client has obtained it's IP address via DHCP it looks for the following configuration files, as you can see the C0A80028 file is called which if you remember was created above.



Kickstart Configuration file 
There are many options to a kickstart configuration file, i have supplied a basic one below which was obtain from a website on the internet, adapt to your own tastes.

install         # rather than upgrade
nfs --server=192.168.0.50 --dir=/export/kickstart  # Location of the install media, http, nfs etc
lang en_US.UTF-8
langsupport --default en_US.UTF-8
keyboard uk
mouse generic3usb --device input/mice
network --device=eth0 --bootproto=static --ip=192.168.0.40 --netmask=255.255.255.0 --gateway=???.???.???.??? --nameserver=???.???.???.??? -
-hostname fedoraks # we could specify static IP info too instead
rootpw password    # noencrypted password
firewall --disabled
selinux --disabled
authconfig --enableshadow --enablemd5
timezone Europe/London
bootloader --location=mbr --append="noexec=off hda=noide"
              # Any boot time options you wan to add
              # I specified noide here as I was booting
              # from SAN in this case.
skipx
              # do not configure X Windows
zerombr yes
              #Clear the Master Boot Record
clearpart --all --initlabel
              #Partition clearing information
part /boot --fstype ext3 --size=150 --ondisk=hda
part pv.01 --size=1 --grow --ondisk=hda
part pv.02 --size=1 --grow --ondisk=hda
volgroup rootvg pv.01
volgroup satvg pv.02
logvol /    --vgname=rootvg --size=6000 --name=rootvol
logvol swap --vgname=rootvg --size=2000 --name=swapvol
              # In the above partition layout (with LVM) I have
              # used two disks, sda and sdb for different volumes.
              # You don't need to use LVM etc. HDA for IDE etc.
auth  --useshadow  --enablemd5
              #System authorization information
%packages --resolvedeps
              # This is the actual package install section. The
              # resolvedeps option allows you to make mistakes and
              # have anaconda sort it out for you, i.e. resolving
              # package dependencies.
@ Base
@ Development Tools
@ Legacy Software Development
              # base channels
screen
newt-perl
perl-DateManip
PyXML
ntp
              # individual packages to add
-vim
-pico
-emacs
              # individual packages to add
%post
              # And so begins the post-install section.
              # this is currently in a chroot to / on the
              # new file system.
              # Various variables I like to set first to use later
(
              # I run everything in this, so I can log it
/bin/echo "Welcome to $HOSTNAME Server " > /etc/motd 
/bin/echo "Built from kickstart version $VER " >> /etc/motd
/bin/echo " " >> /etc/motd
              # One way of adding to files
cat >> /etc/sysctl.conf << EOF
fs.aio-max-size = 1048576
fs.file-max = 327680
net.core.rmem_max = 262144
net.core.wmem_max = 262144
net.core.rmem_default = 262144
net.core.wmem_default = 262144
net.ipv4.ip_local_port_range = 1024 65000
net.ipv4.ip_forward = 0
kernel.shmmax = 2147483648
kernel.shmmni = 4096
kernel.sem = 250 32000 100 128
EOF
              # Another way of inputing to files
              # Here doing some system settings
useradd -c "Some lone user" -d /home/luser luser
echo luserpass | passwd --stdin luser
              # Add a user if you like
# Setup hosts file
cat > /etc/hosts << EOF
127.0.0.1       localhost.localdomain           localhost
192.168.0.1     install-server.some.domain      install-server
192.168.0.2     another.machine.some.domain     another
EOF
              # Edit the hosts file if you like
wget $SERVER/iptables.$lab -O /etc/sysconfig/iptables
              # Here using the server variable we set at the
              # top of the post-install section to pull some
              # custom files we stored, in this case a firewall.
              # In this case using a variable which could have been
              # pulled from /proc/cmdline to get a specific one for
              # each lab.
/sbin/chkconfig ip6tables off
/sbin/chkconfig isdn off
/sbin/chkconfig sendmail off
/sbin/chkconfig ntpd on
              # Turn some services on and off
) > /tmp/kickstart-install.log 2>&1
              # The aforementioned log.

Boot and Start the Installation

Just boot the server via the network (normally option F12) and if all  goes well your client should install from the kickstart server, the  basic steps are as follows







Client BIOS (DHCP broadcast)<----------------------------------------> DHCP Server (Network info, tftp server and PXE file name)
Client BIOS (TFTP request for pxelinux.0)<---------------------------> TFTP/PXE Server (supplies the pxelinux.0 file)
Running PXE (pxe request for kernel and Kickstart install)<----------> TFTP/PXE Server (C0A80028 or default file supplies info)
Running Kernel (NFS KICKSTART) <-------------------------------------> NFS Server (supplies the kickstart config file)
Running Anaconda (NFS request for rpms)<-----------------------------> NFS Server (supply RPMS)
Running Anaconda (NFS request post installtion) <--------------------> NFS Server (runs post install scripts)
Running Anaconda (reboot) 

Configuring NIS under Red Hat Linux



The following describes a procedure to set up NIS network name service under Red Hat Linux. This is geared toward a small intallation with only one domain. However, it should be fairly evident how to add more NIS domains. The NIS domain name has nothing to do with any DNS naming convention being used.

In these examples, the following conventions are used:

NIS domain: "internal"

Code or configuration file data: colored

Root prompt on NIS master server: master#

Root prompt on NIS client host: client#

Setting up a NIS master server:
Required packages: yp-tools ypbind ypserv portmap

Set up "time" service to run via inetd/xinetd, or configure xntpd, or otherwise make sure the host's clock is synchronized.

Edit /etc/yp.conf:domain internal server ip.of.nis.server


Edit /etc/ypserv.conf:dns:

no files: 30 xfr_check_port: yes * : * : shadow.byname : port * : * : passwd.adjunct.byname : port


Edit /etc/sysconfig/network:

NISDOMAIN="internal"


Set NIS domain name:master# domainname internal master# ypdomainname internal


Create file /var/yp/securenets:

host 127.0.0.1 255.255.255.0 10.0.0.0


Make sure the "portmap" service is running:master

# service portmap start master
# chkconfig portmap on


Portmap will need a rule in /etc/hosts.allow to allow access from localhost and any hosts that need to access NIS.

Start ypserv service:master

# service ypserv start


Check that it's listening:master

# rpcinfo -u localhost ypserv


You should see:program 100004 version 1 ready and waiting program 100004 version 2 ready and waiting


Initialize the NIS maps:master# /usr/lib/yp/ypinit -m


Specify local hostname, Ctrl-D, y, let finish.

Start up ypbind, yppasswdd, ypxfrd:master

# service ypbind start master
# service yppasswdd start master
# service ypxfrd start


Set YP services to run on boot-up:master

# chkconfig ypserv on master
# chkconfig ypbind on master
# chkconfig yppasswdd on master
# chkconfig ypxfrd on

NIS client host setup

Required packages: yp-tools ypbind portmap

Edit /etc/sysconfig/network:NISDOMAIN=internal


Edit /etc/yp.conf:domain internal server ip.of.master.server


Edit /etc/hosts:ip.of.master.server hostname.domain hostname


Set NIS domain-name:client# domainname internal client# ypdomainname internal


Edit /etc/nsswitch.conf:passwd: files nis shadow: files nis group: files nis


Make sure the portmap service is running:client# service portmap start client# chkconfig portmap on


The /etc/hosts.allow file will need rules allowing access from localhost and the NIS master server.

Start ypbind service:client# service ypbind start client# chkconfig ypbind on


Test it out:client

# rpcinfo -u localhost ypbind client


# ypcat passwd

Tuesday, 17 January 2012

Common error for system administrator


Case 1:

getng sch error
Dec 30 05:10:02 server124 postfix/cleanup[10299]: E7D76F62F3C: milter-reject: END-OF-MESSAGE from mail.zovemenitt.net[173.205.183.59]: 5.7.1 sender domain does not exist; from=<contact@mail.zovemenitt.net> to=<palmarka999@comcast.net> proto=SMTP helo=<17260|ely01>
M part of comcast team



solution:

step 1: IN server 124

cat /etc/dkim-filter.conf


step 2: if any domain is there remove that one

Domain #add all your domains here and seperate them with comma



step 3:

service dkim-milter stop

--------------------------------------------------------------------------------------------------------------- next mailler issue 2


case 2;


PHP Warning: fsockopen(): unable to connect to 173.205.182.249:2525 (Connection refused) in /var/www/cgi-bin/test11.php on line 72
!! Error, can't connect to the server 173.205.182.249 on the port 2525groups.cratchankinal.com
|173.205.182.249



ans

pmta is 2525
postfix 2505



change port no in the script 2525 to 2505


case 3
abuse@domain not receiving mails
ans :
netstat –nlp | grep 0.0.0.0:25
check whether sendmail is running on port 25 or not
Check also domain  and user entry is their in the following files
1.make entry in /etc/hosts
2.make entry in /etc/mail/local-hostnames
3.make entry in /etc/mail/virtusertable
4.service sendmail restart

case 4
error:
connect to mx2.hotmail.com[65.55.92.152]: Connection timed out (port 25)
ans : set is down

Case 5
Error:
warning: connect to Milter service inet:localhost:20209: Connection refused
ans:
service dkim-milter restart
service dk-milter restart

case 6 :

Mail not coming for user admin
ans:
1.make entry in /etc/hosts
2.make entry in /etc/mail/local-hostnames
3.make entry in /etc/mail/virtusertable
4.service sendmail restart

Case 7:
Redirection Issue
Check in httpd.conf for redirection
Domain resolving or not
Rdns is working or not
Replace domain name of sl3 in httpd.conf with server ip address
Service httpd restart
Case 8:
Issue: Error, can't connect to the server on the port
Solution: cd /etc;ls -d postfix-[0-9]* | cat | while read line; do /usr/sbin/postfix -c /etc/$line start; done

Case 9:
Issue :
Error 554 while sending mail.
Soln.: IP is permanently blocked for sending mails

Case 10:
Issue: while sending mail through this we get this error connect to relay.verizon.net[206.46.232.11]:25: Connection timed out

Solution: IPset not configured on that server or wait for some time to check since isp is not receiving mails from that domain

Case 11:
Issue: status=deferred (delivery temporarily suspended: Host or domain name not found. Name service error for name=verizon.net type=MX: Host not found, try again)

Solution: check /etc/hosts
            Service named restart
            Dig the domain name
            Wait for sometime
Case 12 :
Issue: Service pmta restart and after everything is ok but when u run this command Service pmta statusà output is service is stopped .
Solution:  Look for space on the disk , run df –h
And try to delete unwanted files and than restart pmta service .
Case 13 :
Issue : Mar 31 07:07:21 server4563 postfix-209.16.147.252/master[4434]: warning: service "2505" (2505) has reached its process limit "130": new clients may experience noticeable delays
Solution : check this variable in main.cf
            The smtpd_recipient_limit parameter (default: 1000) controls how many recipients the Postfix smtpd(8) server will take per delivery. The default limit is more than any reasonable SMTP client would send. The limit exists to protect the local mail system against a run-away client.
Case 14:
Issue: Timed out connecting from groups.boardmaintenance.net (64.16.202.97) to alt2.gmail-smtp-in.l.google.com (74.125.79.27))
Solution:
Check PMTA config for the respected Domain.

Case 15 :
 Issue : During mail sending using postfix and if you get this error dsn=4.4.3 and status=deffered

Solution: problem from ISP side wait for some time. As MX records are working .
           Check /etc/resolv.conf
Please check that the dns servers in /etc/resolv.conf are working. Be aware that mydns is not able to reslolve external domains, so you will have to enter there a dns server that is capable of resolving external domains too.

Case 16 : Timed out while connecting from sales.decisiveo.com (173.45.13.57) to h.mx.mail.yahoo.com (66.94.236.34)

Solution:

How to fix the problem (sortof)

Yahoo gives some basic "do these to fix the problem ":
  • Remove email addresses that bounce
  • Examine your retry policies
  • Pay attention to the responses from our SMTP servers
  • Don't send unsolicited email (duh!)
  • Provide a method of unsubscribing
  • Ensure your mail servers are not open relays.

Also install DomainKeys to help fix the problem

Dig a little deeper and you will find that you should install DomainKeys (you should have already installed SPF records so that you can send to AOL accounts) to sign your emails from a specific domain. However, even once this is done, you will still get some 451 errors.
The long and short of it is that you get what you pay for...
  • Yahoo is not communicating with administrators even after they submit multiple request forms.
  • Yahoo is not delivering messages even though they send the response back that the "message was temporarily deferred" (Which sounds like it is just waiting to send the message, but will get to it eventually).
  • In an attempt to block spammers, Yahoo is blocking an extremely high number of "good" emails.
Service dkim-milter restart

Check also whether set is alive or not

Case 17 : warning: master_wakeup_timer_event: service pickup(public/pickup): No such file or directory
                fatal: open lock file pid/inet.2505: cannot create file exclusively: No such file or directory
Solution:          chmod 777 /var/mail/
Postfix reload command

Case 18 : /etc/init.d/httpd restart
Stopping httpd: [FAILED]
Starting httpd: (98)Address already in use: make_sock: could not bind to address [::]:80
(98)Address already in use: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down

IF the above error occurs then kill all the httpd processes and then restart the service. As Some other process is already running at port number 80. Use netstat -ltnp | grep ':80' to get the process name and pid.

Solution:
netstat -lnp | grep :80
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 1336/httpd

killall -9 httpd
killall -9 wget
kill -9 1336

service httpd restart.


Monday, 16 January 2012

How to upgrade AIX Firmware & TL Maintenance Level in AIX

Steps to upgrade AIX TL ( technology Level ) / Maintenance Level in AIX ( including Firmware HMC VIOS )

HMC upgrade

Upgrading on 2 x HMCs ( 1 for each machine )
Lpars were running during the upgrade

Steps:

1. Save Upgrade Data - HMC configuration will then be automatically loaded once the update is done.
2. boot from the 1st DVD update.
3. once done with disc 1, it will prompt you for the second disk.
4. once done, the new HMC web based interface will show up (very differenct, and kind of slow when accessed remotely).
5. to apply SP1, insert the SP1 Disc (MH01084) , login as hscroot. look for "Updates" on the left fram of the HMC interface.
6. click on Update HMC and click on OK. the default is to look for the update in the DVD/CD drive..

and just reply to the prompts. if there are no problmes, it will take about 15-20 minutes for the service pack. HMC upgrade, in total, will take about an hour to finish.

detailed info can be found here.

Firmware or also known as microcode :

* Minimum firmware levels required for AIX 6.1

http://www.ibm.com/developerworks/wikis/display/wikiptype/p5+system+firmware+upgrade

Find out the Present Firmware Level

You can verify the version of the firmware by issuing the command

Code: 

prtconf | grep Firmware

the output should be "Firmware Version: IBM,SPH02066". 


firwmare updates for the two machines (we actually have 3 - p550, p550q and p570) were all the same. so need only to burn 1 ISO file. But the HMC won't read the discs. so downloaded the RPM and xml files and setup an FTP server (good thing i have proftpd installed in a GNU/Linux machine).
after starting up proftpd and making sure the files are accessible, i then went back to the HMC session. to access the firmware update menu, you need to:
1. under Systems management, go to "Servers", select the machine name
2. at the bottom from, go to "Updates"
4. either use "Change Licensed Internal Code for the current release" or "Upgrade Licensed internal Code to a new release".
I chose the latter.
5. HMC will do some system readiness check. No errors, so i hit OK.
6. select FTP site and hit OK. i then provided the ftp server, username, password
and directory location of the rpm and xml files.
the rest of the process is straight forward so i won't include it here.
once done, the firmware should be upgraded and should

Updates > View System Information

select "None - Display current values" and hit OK.

more info here

from the command line, once the an LPAR is online, the firmware version can be viewed using lsmcode:

#lsmcode  -c

The current permanent system firmware image is SF240_332
The  current temporary system firmware image is SF240_358
The system is  currently booted from the temporary firmware image.

(running lsmcode alone will bring you to a smitty based session).

NOTE: the LPARs here are all powered-off.

VIO update commands:

#commit all uncommitted (really?) updates

updateios -commit

# apply the patches from the directory VIO accepting all license agreements by default

updateios -dev  VIO -install -accept

after applying, VIO servers need to be restarted (NOTE: AIX Lpars are still "powered off" here.

# check VIO level:

$ ioslevel
1.5.2.1-FP-11.1
$
NOTE: client lpars here are still powered down.

AIX TL / Maintenance Level update

1) Find out your current OS level 
oslevel -s
oslevel -r

2) Download the latest technology or maintenance level from AIX fix central

Click on

IBM Support: Fix Central

Select the product group ==> SYSTEM P
Select the the product ==> AIX
Select the version ==> 6.1
Select the fix type ==> FIX PACKS

Click on Continue:

Select 6100-05-01-1016 with Service Pack

To be on the safe side, select
Yes, include Technology Level 6100-05 with the Service Pack and click on Continue

Download will start..... Once you download the filesets copy it in any directory (usually more than 2GB ) if you downloaded the files on your Windows/MAC PC ftp it to AIX in binary mode

3) Put the files in any directory let us say: /tmp/AIX_TL04
run the following commands

# pwd
# /tmp/AIX_TL04
# inutoc .
# smitty update_all
> select the directory .


Make commit ==> YES if you don't want to keep the old version but if you want to keep the old one and want to go back to it SELECT NO for commit

Accept License==> YES
Press Enter
takes usually more than 1 hour.

4) a Reboot of the system is required
5) verify the upgrade

oslevel -s
oslevel -r


6) After installation ( optional )

You may wish to retain this package for future use. When you install additional operating system software you will want to use this package to bring the additional software up to this level.

You can create a list of the APARs closed in this package, which you can then view (and search) in an ASCII editor, such as vi or emacs. First, create the .toc file for the package by using the inutoc command described above. Then, run the following command to extract the APAR listings from the .toc file:

grep ^I .toc > apar.list

Run the following command to eliminate duplicate entries from the apar.list file:

sort -u apar.list -o sorted.apars

AIX version upgrade from 4.3 to 5.3 or 6.1

If you would like to upgrade AIX version from AIX 4.x,5.x to the latest one 6.1

Then first of all make sure that the system has the latest firmware or is compatible with your P Series from here
http://publib.boulder.ibm.com/infocenter/aix/v6r1/index.jsp?topic=/com.ibm.aix.resources/RELNOTES/SC23662905.htm

see under the section of ==> Minimum firmware levels required for AIX 6.1

Once you confirm, then insert the AIX 6.1 DVD/CD volume 1
and reboot the machine

# shutdown -Fr

Enter into SMS Menu

Example 2-32 Open Firmware prompt
1 = SMS Menu 5 = Default Boot List
6 = Stored Boot List 8 = Open Firmware Prompt
memory keyboard network scsi speaker ok

1 > press 1

Change the boot sequence
Boot / Install from CD-ROM

Save and exit, system will try to boot from CD-ROM

Once the boot is completed

Go for migration if you want to upgrade or new/fresh installation if you want to format and over-write the old O/S

follow the instructions here
How to install AIX 5L

Firmware


Saturday, 14 January 2012

keychain: Set Up Secure Passwordless SSH Access For Backup Scripts


keychain: Set Up Secure Passwordless SSH Access For Backup Scripts

We establish connections to remote systems without supplying a password, however I do not want to store my password less keys ( passphrase-free keys) on my servers. ssh-agent, takes care of keys with passphase, which allowing me to easily have ssh-agent process per system per login session. How do I dramatically reduces the number of times I've to punch my passphrase from once per new login session to once every time my local server is rebooted? How do I use keychain utility for all my backup scripts for secure passwordless login?

OpenSSH offers RSA and DSA authentication to remote systems without supplying a password. keychain is a special bash script designed to make key-based authentication incredibly convenient and flexible. It offers various security benefits over passphrase-free keys.
How Does Keychain Make It Better Than a Key Less Passphrase?

If attacker broken into server with passphrase-free keys, all other your servers / workstation on which keys are used are also security risk (they can be easily breached). With keychain or ssh-agent attacker won't able to touch your remote systems without breaking your passphrase. Another example, if your laptop or harddisk stolen, an attacker can simply copy your key and use it anywhere as it is not protected by a passphrase.

keychain is a manager for ssh-agent, typically run from ~/.bash_profile. It allows your shells and cron jobs to share a single ssh-agent process. By default, the ssh-agent started by keychain is long-running and will continue to run, even after you have logged out from the system. If you want to change this behavior, take a look at the --clear and --timeout options, described below. Our sample setup is as follows:peerbox.nixcraft.net.in => Remote Backup Server. Works in pull only mode. It will backup server1.nixcraft.net.in and server2.nixcraft.net.in. vivek-desktop.nixcraft.net.in => My desktop computer. server1.nixcraft.net.in => General purpose remote server. server2.nixcraft.net.in => General purpose remote web / mail / proxy server.


Install keychain software on peerbox.nixcraft.net.in so that it can login securely to other two servers for backup.

Install keychain on CentOS / RHEL / Fedora Linux

You need RPMForge repo enabled to install keychain package.
# yum install keychain
Install keychain on Debian / Ubuntu Linux

# apt-get update && apt-get install keychain
Install keychain on FreeBSD

# portsnap fetch update
# cd /usr/ports/security/keychain
# make install clean
How Do I Setup SSH Keys With passphrase?

Simply type the following commands:
$ ssh-keygen -t rsa
OR
$ ssh-keygen -t dsa

Assign the pass phrase when prompted. See the following step-by-step guide for detailed information:
Howto Linux / UNIX setup SSH with DSA public key authentication (password less login)
Howto use multiple SSH keys for password less login
How Do I Use Keychain?

Once OpenSSH keys are configured with a pass phrase, update your $HOME/.bash_profile file which is your personal initialization file, executed for login BASH shells:

$ vi $HOME/.bash_profile
Append the following code

:### START-Keychain ### # Let re-use ssh-agent and/or gpg-agent between logins /usr/bin/keychain $HOME/.ssh/id_dsa source $HOME/.keychain/$HOSTNAME-sh ### End-Keychain ###


Now you've keychanin configured to call keychain tool every login. Just log out and log back in to server from your desktop to test your setup:

$ ssh root@www03.nixcraft.net.in
Sample Output:
keyhcain is up and running. Now, all you have to do is append your servers key file $HOME/.ssh/id_dsa.pub to other UNIX / Linux / BSD boxes:
# scp $HOME/.ssh/id_dsa.pub server1.nixcraft.net.in:~/pubkey
# scp $HOME/.ssh/id_dsa.pub server2.nixcraft.net.in:~/pubkey
# ssh server1.nixcraft.net.in cat ~/pubkey >> ~/.ssh/authorized_keys2; rm ~/pubkey
# ssh server2.nixcraft.net.in cat ~/pubkey >> ~/.ssh/authorized_keys2; rm ~/pubkey
# ssh root@server1.nixcraft.net.in
# ssh user@server2.nixcraft.net.in
Task: Clear / Delete All Of Ssh-agent's Key

# keychain --clear
Security Task: Make Sure Intruder Cannot Use Your Existing SSH-Agent's Keys (only allow cron jobs to use password less login)

The idea is pretty simply only allow backup shell scripts and other cron job to do password less login but all users including an intruder must provide a passphrase-key for interactive login. This is done by deleting all of ssh-agent's keys. This option will increases security, it still allows your cron jobs to use your ssh keys when you're logged out. Update your ~/.bash_profile as follows:/usr/bin/keychain --clear $HOME/.ssh/id_dsa


If you are using RSA, use:/usr/bin/keychain --clear $HOME/.ssh/id_rsa

Now, just log in to remote server box once :
$ ssh root@peerbox.nixcraft.net.in
Log out (only grant access to cron jobs such as backup)
# logout
Task: Use Keychain With Backup Scripts for Passwordless login via cron

Add the following before your rsync, tar over ssh or any other network backup command:source $HOME/.keychain/$HOSTNAME-sh


Here is a sample rsync script:

#!/bin/bash 
# Remote Server Rsync backup Replication Shell Script 
# Local dir location LOCALBAKPOINT=/iscsi LOCALBAKDIR=/backups/server1.nixcraft.net.in/wwwroot 
# Remote ssh server setup SSHUER=root SSHSERVER=server1.nixcraft.net.in SSHBACKUPROOT=/wwwroot 
# Make sure you can log in to remote server without a password source $HOME/.keychain/$HOSTNAME-sh 
# Make sure local backup dir exists [ ! -d ${LOCALBAKPOINT}${LOCALBAKDIR} ] && mkdir -p ${LOCALBAKPOINT}${LOCALBAKDIR} 
# Start backup /usr/bin/rsync --exclude '*access.log*' --exclude '*error.log*' -avz -e 'ssh ' ${SSHUER}@${SSHSERVER}:${SSHBACKUPROOT} ${LOCALBAKPOINT}${LOCALBAKDIR} 
# See if backup failed or not to /var/log/messages file [ $? -eq 0 ] && logger 'RSYNC BACKUP : Done' || logger 'RSYNC BACKUP : FAILED!'


If you are using rsnaphot backup server (see how to setup RHEL / CentOS / Debian rsnapshot backup server) add the following to your
/etc/rsnapshot.conf file

# Get ssh login info via keychain cmd_preexec source /root/.keychain/hostname.example.com-sh

Final Note About Keychain and Security
Cracker with an advanced attacking with deadly coding skills can still get key from memory. However, keychain makes it pretty difficult for normal users and attackers to steal your keys and use it.
OpenSSH sshd server offers two additional options to protect abuse of keys. First, make sure root login disabled (PermitRootLogin yes). Second, specify which user accounts on the server are allowed to be used for authentication by adding AuthorizedKeysFile %h/.ssh/authorized_keys_FileName. See sshd_config man page for further details.

Thursday, 12 January 2012

/bin/csh is needed


Error:
[root@telecominnovations ~]# rpm -ivh dkim-milter-2.8.3-1.i386.rpm
error: Failed dependencies:
        /bin/csh is needed by dkim-milter-2.8.3-1.i386


Solution :
yum install tcsh -y

Monday, 9 January 2012

Installing OpenSSH on AIX

The OpenSSH software is shipped on the AIX 5.3 Expansion Pack. This version of OpenSSH is compiled and packaged as installp packages using the openssh-3.8.p1 level of source code. The installp packages include the man pages and the translated message filesets. The OpenSSH program contained in the Expansion Pack CD-ROM media is licensed under the terms and conditions of the IBM® International Program License Agreement (IPLA) for Non-Warranted Programs.
Before installing the OpenSSH installp format packages, you must install the Open Secure Sockets Layer (OpenSSL) software that contains the encrypted library. OpenSSL is available in RPM packages on the AIX Toolbox for Linux® Applications CD, or you can also download the packages from the following AIX Toolbox for Linux Applications Web site:

http://www-1.ibm.com/servers/aix/pro.../download.html

Because the OpenSSL package contains cryptographic content, you must register on the Web site to download the packages. You can download the packages by completing the following steps:

1. Click the AIX Toolbox Cryptographic Content link on the right side of the AIX Toolbox for Linux Applications Web site.
2. Click I have not registered before.
3. Fill in the required fields in the form.
4. Read the license and then click Accept License. The browser automatically redirects to the download page.
5. Scroll down the list of cryptographic content packages until you see openssl-0.9.6m-1.aix4.3.ppc.rpm under OpenSSL — SSL Cryptographic Libraries.
6. Click the Download Now! button for the openssl-0.9.6m-1.aix4.3.ppc.rpm.

After you download the OpenSSL package, you can install OpenSSL and OpenSSH.

1. Install the OpenSSL RPM package using the geninstall command:

# geninstall -d/dev/cd0 Rpenssl-0.9.6m

Output similar to the following displays:

SUCCESSES
---------
openssl-0.9.6m-3

2. Install the OpenSSH installp packages using the geninstall command:

# geninstall -I"Y" -d/dev/cd0 Ipenssh.base

Use the Y flag to accept the OpenSSH license agreement after you have reviewed the license agreement.
Output similar to the following displays:

Installation Summary
--------------------
Name Level Part Event Result
-------------------------------------------------------------------------------
openssh.base.client 3.8.0.5200 USR APPLY SUCCESS
openssh.base.server 3.8.0.5200 USR APPLY SUCCESS
openssh.base.client 3.8.0.5200 ROOT APPLY SUCCESS
openssh.base.server 3.8.0.5200 ROOT APPLY SUCCESS

You can also use the SMIT install_software fast path to install OpenSSL and OpenSSH.

The following OpenSSH binary files are installed as a result of the preceding procedure:

scp
File copy program similar to rcp
sftp
Program similar to FTP that works over SSH1 and SSH2 protocol
sftp-server
SFTP server subsystem (started automatically by sshd daemon)
ssh
Similar to the rlogin and rsh client programs
ssh-add
Tool that adds keys to ssh-agent
ssh-agent
An agent that can store private keys
ssh-keygen
Key generation tool
ssh-keyscan
Utility for gathering public host keys from a number of hosts
ssh-keysign
Utility for host-based authentication
ssh-rand-helper
A program used by OpenSSH to gather random numbers. It is used only on AIX 5.1 installations.
sshd
Daemon that permits you to log in

The following general information covers OpenSSH:

* The /etc/ssh directory contains the sshd daemon and the configuration files for the ssh client command.
* The /usr/openssh directory contains the readme file and the original OpenSSH open-source license text file. This directory also contains the ssh protocol and Kerberos license text.
* The sshd daemon is under AIX SRC control. You can start, stop, and view the status of the daemon by issuing the following commands:

startsrc -s sshd OR startsrc -g ssh (group)
stopsrc -s sshd OR stopsrc -g ssh
lssrc -s sshd OR lssrc -s ssh

You can also start and stop the daemon by issuing the following commands:

/etc/rc.d/rc2.d/Ksshd start

OR

/etc/rc.d/rc2.d/Ssshd start

/etc/rc.d/rc2.d/Ksshd stop

OR

/etc/rc.d/rc2.d/Ssshd stop

* When the OpenSSH server fileset is installed, an entry is added to the /etc/rc.d/rc2.d directory. An entry is in inittab to start run-level 2 processes (l2:2:wait:/etc/rc.d/rc 2), so the sshd daemon will start automatically at boot time. To prevent the daemon from starting at boot time, remove the /etc/rc.d/rc2.d/Ksshd and /etc/rc.d/rc2.d/Ssshd files.
* OpenSSH software logs information to SYSLOG.
* The IBM Redbook, Managing AIX Server Farms, provides information about configuring OpenSSH in AIX and is available at the following Web site:

IBM Redbooks

* OpenSSH supports long user names (256 bytes), the same as the AIX base operating system. For more information on long user names, see the mkuser command.
* Some keywords, such as AllowUsers, DenyUsers, AllowGroups, and DenyGroups are not available by default in the ssh_config file or the sshd_config file. You must add these keywords to the configuration files in order to use them.

* OpenSSH images
Use the following steps to install the OpenSSH images:
* Configuration of OpenSSH compilation
The following information discusses how the OpenSSH code is compiled for AIX.
* OpenSSH and Kerberos Version 5 support
Kerberos is an authentication mechanism that provides a secure means of authentication for network users. It prevents transmission of clear text passwords over the network by encrypting authentication messages between clients and servers. In addition, Kerberos provides a system for authorization in the form of administering tokens, or credentials.


Installing OpenSSH on AIX 4.3.3 At 4.3.3, the openSSH is installed using the RPM format packages, not by using installp format which is available at 5.1, 5.2, and 5.3. In this procedure, you need to follow these three steps:

1.Installing the prerequisite filesets.

2.Downloading the rpm packages.

3.Installing the prerequisite rpm packages.
ExamplesEdit section

1.Installing the prerequiste filesets. The filesets rpm.rte and perl.rte are required to be installed prior to installing the rpm packages. The rpm.rte fileset can be found at the following:

Linux Toolbox CD or Linux Toolbox Website http://www.ibm.com/servers/aix/produ.../download.html

The filesets can be installed using smitty installp.

2.Downloading the rpm packages.

The rpm packages can be downloaded from the following website: http://www.ibm.com/servers/aix/produ.../download.html

Once on that page, the prngd (Psuedo Random Number Generator Daemon) daemon and the zlib compression and decompression library can be downloaded. These are the prerequistes for installing the openssl rpm package: prngd-0.9.23-3.aix4.3.ppc.rpm zlib-1.1.4-3.aix4.3.ppc.rpm

Next click AIX TOOLbox Cryptographic Content on the sorted content download in the upper right area and then register yourself, if you are not already a registered user. Then click on Accept License button at the bottom of the panel that appears and then you are ready to download the openssl and openssh rpm packages: openssl-0.9.6m-1.aix4.3.ppc.rpm openssl-devel-0.9.6m-1.aix4.3.ppc.rpm openssl-doc-0.9.6m-1.aix4.3.ppc.rpm openssh-3.6.1p2-1.aix4.3.ppc.rpm openssh-clients-3.6.1p2-1.aix4.3.ppc.rpm openssh-server-3.6.1p2-1.aix4.3.ppc.rpm

3.Installing the prerequisite rpm packages. Once you have all the rpm files in the current directory, run the following commands to install them.

1. rpm -i zlib-1.1.4-3.aix4.3.ppc.rpm
2. rpm -i prngd-0.9.23-3.aix4.3.ppc.rpm
3. rpm -i openssl-0.9.6m-1.aix4.3.ppc.rpm
4. rpm -i openssl-devel-0.9.6m-1.aix4.3.ppc.rpm
5. rpm -i openssl-doc-0.9.6m-1.aix4.3.ppc.rpm
6. rpm -i openssh-3.6.1p2-1.aix4.3.ppc.rpm
7. rpm -i openssh-server-3.6.1p2-1.aix4.3.ppc.rpm
8. rpm -i openssh-clients-3.6.1p2-1.aix4.3.ppc.rpm

Sometimes you may get the error: failed dependencies error while trying to install the openssl packages. In that case, run the following command:

# rpm -i --nodeps openssl-0.9.6m-1.aix4.3.ppc.rpm

The following command can be run to update the AIX-rpm:

# /usr/sbin/updtvpkg

The prngd needs to be installed before openssl and openssh, and openssl is the prerequiste for installing the openssh rpm packages. The openssl-devel-0.9.6m-1.aix4.3.ppc.rpm and openssl-doc-0.9.6m-1.aix4.3.ppc.rpm are not the required packages for installing the openSSH. To verify that these packages are installed, run the following command:

1. rpm -qa | egrep '(openssl|openssh|prng)'

--> prngd-0.9.23-3 openssl-0.9.6m-1 openssl-devel-0.9.6m-1 openssl-doc-0.9.6m-1 openssh-3.6.1p2-1 openssh-server-3.6.1p2-1 openssh-clients-3.6.1p2-1

These packages are installed under the /opt/freeware directory, and several symbolic links are created in /usr/bin or /usr/sbin, as shown in the following example:

1. ls -l /usr/bin/ssh

lrwxrwxrwx 1 root system 26 Dec 29 16:13 /usr/bin/opt freeware/bin/ssh

1. ls -l /usr/sbin/sshd

lrwxrwxrwx 1 root system 28 Dec 29 16:12 /usr/sbin/ opt/freeware/sbin/sshd Installing openSSH on 5.1, 5.2, and 5.3: At 5.1, 5.2, and 5.3, the installation of openssh itself is in installp format, but all the prerequisites (including openssl) can be installed using the same rpm -i commands (using the same 4.3.3. rpm packages). The installp format package can be downloaded from the following site: SourceForge.net: OpenSSH on AIX After installing the prerequisites using the following commands,

1. rpm -i zlib-1.1.4-3.aix4.3.ppc.rpm
2. rpm -i prngd-0.9.23-3.aix4.3.ppc.rpm
3. rpm -i openssl-0.9.7d-1.aix5.1.ppc.rpm
4. rpm -i openssl-devel-0.9.7d-1.aix5.1.ppc.rpm

use smitty installp to install the openssh filesets extracted from the tar file openssh-3.8.1p1_51.tar (for 5.1), openssh-3.8.1p1_52.tar (for 5.2), and openssh-3.8.1p1_53.tar (for 5.3). The following steps need to be followed to install openssh. 1.In the directory where the images are, run the command inutoc. 2.Run smitty install. 3.Select "Install and Update Software". 4.While in smitty do the following: a.Select "Install Software". b.Enter a dot (".") in the field for "INPUT device / directory for software" and press ENTER. c.Enter openssh in the "SOFTWARE to install" field. d.Scroll down to "Preview new LICENSE agreements?" and press tab key to change the field to yes. Read the license agreement. e.Scroll down to "ACCEPT new license agreements?" and press tab to change the field to yes. Press ENTER to begin the software installation. 5.Run the following command to see the openssh filesets installed: 6.# lslpp -l | grep ssh In this case, you notice that the ssh commands are in the /usr/bin directory. For example:

1. ls -al /usr/bin/ssh

-r-xr-xr-x 1 root system 309127 Jun 12 2003 /usr/bin/ssh

1. ls -al /usr/bin/scp

-r-xr-xr-x 1 root system 38582 Jun 12 2003 /usr/bin/scp Initial configuration at 4.3, 5.1, 5.2, and 5.3: The following entry in /etc/inittab invokes all the scripts starting from S under the etc/rc.d/rc2.d directory upon system startup: l2:2:wait:/etc/rc.d/rc 2 In the /etc/rc.d/rc2.d directory, the following example shows the required symbolic-link to start sshd: At 4.3.3:

1. ls -l /etc/rc.d/rc2.d | grep ssh

lrwxrwxrwx 1 root system 14 Dec 29 16:12 K55sshd -> ../init.d/sshd lrwxrwxrwx 1 root system 14 Dec 29 16:12 S55sshd -> ../init.d/sshd At 5.1, 5.2, and 5.3:

1. ls -l /etc/rc.d/rc2.d | grep ssh

-r-xr-xr-x 1 root system 307 Dec 29 16:39 Ksshd -r-xr-xr-x 1 root system 308 Dec 29 16:39 Ssshd The prngd daemon is started from the following entry in /etc/inittab: prng:2:wait:/usr/bin/startsrc -s prngd In order to specify the SSH2 protocol to be used for OpenSSH, add the following line to the /etc/ssh/sshd_config file: Protocol 2 To verify the SSH protocol version, you can use the telnet command:

1. telnet localhost 22

Trying... Connected to localhost.austin.ibm.com. Escape character is '^]'. SSH-2.0-OpenSSH_3.6.1p2 --> the above shows that you are using the ssh2 If you see the following:

1. telnet localhost 22

Trying... telnet: connect: A remote host refused an attempted connect operation. then the sshd daemon is not running. To terminate, type Ctrl-c and q. To start the daemon, run:

1. startsrc -s sshd

whenever the /etc/ssh/sshd_config file is modified, the ssh needs to be stopped and restarted as follows:

1. stopsrc -s sshd
2. startsrc -s sshd

The prngd daemon could also be stopped and started in the above method. Once the installation and configuration is complete: The first time you are going to connect to a server, you should receive a host key fingerprint from the adminstrator of that server. On the first attempt to connect to that remote server using OpenSSH, you will see the fingerprint of the remote server. You should verify if this matches with the one sent to you by the adminstrator. Only then, you can type yes.



Here are the steps involved for configuring OpenSSH for AIX.

After installation, start the sshd daemon by running:

# startsrc -s sshd

Verify that sshd is active by running this command:

# lssrc -s sshd

Once sshd is active, test it by attempting to connect to it using an OpenSSH client. If you installed the OpenSSH client package, issue the ssh client command:

# ssh localhost

You should receive this message: "The authenticity of host localhost (127.0.0.1) can't be established. RSA key fingerprint is 1c:bc:d4:a0:87:f8:0e:25:61:27:75:18:99:a2:5a:7d. Are you certain you want to continue connecting (yes/no)? (Warning: Permanently added localhost(RSA) to the list of known hosts. root@localhosts password."

This message indicates that this is the first time you've connected to this server. Respond with yes. This adds the server's host key to your client's known_hosts file. (Note: You won't receive this question on future connections to the same server.)

If you're connecting from a Windows* client, several SSH clients can be downloaded. One of the more popular is PuTTY, a free Win32 Telnet/SSH client.

Once you verify OpenSSH is working, you may further safeguard your SSH connection by implementing symmetric RSA or DSA authentication keys. Authentication keys allow users to specify a passphrase for their SSH connection and prevent someone else from spoofing username@hostname.

It also gives users the capability to connect to their OpenSSH server without being prompted for a password, either by using an empty passphrase (at the time of key generation) or with the assistance of an SSH agent.

For details on OpenSSH, read the Redbook, "Managing AIX Server Farms." Chapter 4 focuses on secure network connections on AIX and is almost entirely devoted to OpenSSH.

For details on OpenSSH for AIX, contact the IBM Support Center at 1-800-237-5511, Option 3.




Old News

System Administration Toolkit Set up remote access in UNIX through OpenSSH
Enabling automatic login using public keys

When you log in to a remote system with ssh, sftp, or scp, you still need to use your password to complete the login process. Once you have exchanged a valid key with a remote site by creating a public or private key and providing the public portion of the key into the ~/.ssh/authorized_keys file, you can eliminate this requirement and allow automatic logins.

To create the public or private key, you need to use ssh-keygen, specifying the type of key encryption. The rsa key type is used in the demonstration, but other key types are also valid. See Listing 11 to create the key.

Listing 11. Creating the key


$ ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa):




You should enter the location of the file where you want to save the key (both the public and private components). Using the default (within the .ssh directory in your home directory) is usually fine (see Listing 12).

Listing 12. Prompt to enter a passphrase


Created directory '/root/.ssh'.
Enter passphrase (empty for no passphrase):




If you enter a passphrase at this stage, you create a secure keyfile, but you also have to enter the passphrase each time you use the key. Pressing Return means that no password is required (see Listing 13).

Listing 13. Bypassing the password requirement by pressing the Return key


Enter same passphrase again:
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
98:da:8d:48:a8:09:44:b1:b3:62:51:2d:a9:6b:61:ba root@remotehost




A public key (id_rsa.pub) and the corresponding private key (id_rsa) have been created.

To enable automatic login, you must copy the contents of the public key into the authorized_keys file within the ~/.ssh directory of the remote host. You can do this automatically using SSH (see Listing 14).

Listing 14. Enabling automatic login


$ cat ./.ssh/id_rsa.pub | ssh mc@remotehost 'cat >> .ssh/authorized_keys';




Better still, if this is something that you do regularly across a range of hosts, you can use a small script or shell function that performs all of the necessary steps for you, as shown here in Listing 15.

Listing 15. Using a shell script to enable automatic login


OLDDIR='pwd';
if [ -z "$1" ]; then
echo Need user@host info;
exit;
fi;
cd $HOME;
if [ -e "./.ssh/id_rsa.pub" ]; then
cat ./.ssh/id_rsa.pub | ssh $1 'cat >> .ssh/authorized_keys';
else
ssh-keygen -t rsa;
cat ./.ssh/id_rsa.pub | ssh $1 'cat >> .ssh/authorized_keys';
fi;
cd $OLDDIR




Using the setremotekey script, you can copy an existing key or, if it doesn't already exist, create one before copying:

$ setremotekey mc@remotehost




Now, whenever you need to log in to a remote host with your public key, you can use the script of your personal key with the list of accepted keys for the user on the remote host.



OpenSSH is now bundled with AIX

IBM Wikis - AIX 5L Wiki - How to setup SSH in AIX to communicate with HMC
1. Download and install SSL and openSSH on AIX client

* rpm Ivh ssl
* smitty install to install openssh (base, manpage, msg)
Note: After the SSL and OpenSSH have been installed a directory called /.ssh will be created.

2. Generate the priv/pub keys on AIX client

* cd ~/.ssh/
* Type ssh-keygen t rsa
Note: This will create id_rsa and id_rsa.pub

3. From AIX client add public key to HMC

* scp hscroot@hmc_name:.ssh/authorized_keys2 temp_hmc
* cat id_rsa.pub >> temp_hmc
* scp tem_hmc hscroot@hmc_name:.ssh/authorized_keys2
* Test it. Ex ssh hscroot@hmc_name date

index
Configuring OpenSSH on AIX
You should configure SSH to encrypt all communications between the server and client on your AIX operating system.
You must first install the OpenSSH file set on AIX and then configure it.
Installing OpenSSH on AIX
To install the openssh file set:
Note: Some text may appear on separate lines for presentation purposes only.

1. Install the OpenSSL package, which you can find at:

SourceForge.net: OpenSSH on AIX

2. Click OpenSSL at the top of the Web page. Registration is required. After registering, you are redirected to a Web page where you can download OpenSSL.
3. Install the following file sets from the AIX Base installation media:
* openssh.base
* openssh.license
* openssh.msg.en_US
* openssh.man.en_US
4. If the file sets were not found on the AIX Base installation media, they can be downloaded from the URL: developerWorks : IBM's resource for developers and IT professionals. In the left navigation frame, click Open Source Projectsand then click OpenSSH for AIX Images. Select OpenSSH 3.6 or higher.
5. Start the sshd daemon by running the command: /usr/bin/startsrc -s sshd
Note: If the AIX machine on which OpenSSH is installed also has GSA installed, the SSH daemon will not start. This is a known problem. You will need to first check to see if the sshd user exists on the system. If not, it should be created with the following commands:

mkgroup sshd

mkuser -a pgrp=sshd login=false home=/var/empty
gecos="OpenSSH privilege separation" account_locked=true sshd

6. As user tioadmin, configure SSH so that the server can communicate with relevant users on other systems and components of the data center.
Attention: Ensure that you are logged on to user ID tioadmin directly. Do not usesu - to tioadmin or the following steps will fail to run correctly.

OpenSSH is installed on AIX.
Configuring OpenSSH on AIX
To configure SSH:

1. Log on as tioadmin.
2. Run the following commands:

ssh-keygen -t rsa -N "" -f $HOME/.ssh/id_rsa
cat $HOME/.ssh/id_rsa.pub >> $HOME/.ssh/authorized_keys

3. You can test this by running: ssh -v tioadmin@localhost, where localhost is your host name. If SSH is properly configured, you will not be prompted for a password.
4. Copy the public key for user tioadmin to the servers that Tivoli® Provisioning Manager will be managing in your data center.
5. It is required to configure SSH to accept connections from new hosts without prompting for confirmation. Create a file in /home/thinkcontrol/.ssh called config. The file should contain the following line:

StrictHostKeyChecking no

6. Copy the id_rsa.pub file, which contains the public keys, into the authorized keys file of the administrative account of any server in the data center that the Tivoli Provisioning Manager server must communicate with or manage. Include any servers in the data center that Tivoli Provisioning Manager is managing.
1. Ensure that the managed server has an administrative account for which the SSH RSA keys (id_rsa, id_rsa.pub, and authorized_keys) have already been generated and should be contained into the .ssh directory of the respective administrative account home directory.
2. Append the content (a single line of text) of the id_rsa.pub file which contains the public key from the server that will initiate the SSH session to the authorized_keys file of the administrative account of any target server in the data center that the Tivoli Provisioning Manager server must communicate with or manage. Include any servers in the data center that Tivoli Provisioning Manager will be managing.
3. To verify, on the Tivoli Provisioning Manager server, type:

ssh <tioadmin/other_administrative_account_on_the_target_server>@<target_server_IP_or_hostname>

There should be no password prompt, followed by the prompt on the remote machine. After a successful logon, an entry for the communication partner will be created into a known_hosts file. As a troubleshooting step, sometimes this file may contain old or invalid entries associated with the managed server IP address or name. Deleting that entry should fix the connection problem.

SSH is now configured on AIX.




Recommended links

YouTube - passwordless ssh trust

* The OpenSSH web site


* Chapter 4 in the redbook Managing AIX Server Farms contains details about using OpenSSH with AIX.


* Download OpenSSH on AIX.


* AIX 5L Expansion Pack and Web Download Pack


* AIX Toolbox for Linux Applications


* Get up-to-date information about OpenSSH 3.4pl
Twitter Bird Gadget