Differences between revisions 1 and 71 (spanning 70 versions)
Revision 1 as of 2017-05-02 05:53:17
Size: 12076
Editor: thog
Comment:
Revision 71 as of 2023-01-30 04:36:14
Size: 13620
Editor: 61-68-142-254
Comment:
Deletions are marked like this. Additions are marked like this.
Line 1: Line 1:
Describe InstallingControlOnCentos6 here.
Line 5: Line 3:
Configure Network for DHCP and to "Connect Automatically" Hostname should be called concare4. Configure Network for DHCP and to "Connect Automatically"
Line 8: Line 6:

{{{
Line 9: Line 9:
swap  2-32GB, the same size as physical RAM
/u with the rest of available space (Fill to maximum available size), formatted as EXT4

After install is finished it will restart.
Turn off firewall and selinux.
swap 2-32GB, the same size as physical RAM
/u  with the rest of available space (Fill to maximum available size), formatted as EXT4
}}}
Make sure you tell us what the root password is set to.

After install is finished it will restart. Turn off firewall and selinux.

{{{
Line 16: Line 19:
}}}
Line 18: Line 21:

{{{
Line 19: Line 24:

}}}
For linode only:

edit /etc/resolv.conf and add:

{{{
nameserver 8.8.8.8
}}}
Then make the file immutable

{{{
chattr +i /etc/resolv.conf
}}}
Line 22: Line 38:
yum install wget ppp
{{{
yum install wget ppp openssh-clients
}}}
Line 25: Line 43:
Line 26: Line 45:
Line 27: Line 47:

{{{
Line 31: Line 53:
}}}
Line 32: Line 55:

{{{
Line 36: Line 61:
}}}
Line 38: Line 63:
Line 40: Line 66:
(if hostname of the server is “li823-33.members.linode.com”, we need to add the “li823-33.members.linode” into the /etc/hosts file for ppp connection)
Line 43: Line 67:
# rpm -ivh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm

{{{
#rpm -ivh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm
rpm -ivh https://archives.fedoraproject.org/pub/archive/epel/6/x86_64/epel-release-6-8.noarch.rpm
}}}
Download fixed copy of polkit:

{{{
cd
wget http://customers.crecom.com.au/concare/polkit-0.96-12.el6.1.x86_64.rpm
}}}
Line 46: Line 79:

{{{
Line 47: Line 82:
yum install libstdc++.i686 unixODBC.i686 mysql-libs.i686 mysql-libs libcurl-devel.i686 expat.i686 expat glib2.i686 freetype.i686 libSM.i686 libXrender.i686 fontconfig.i686 libXext-devel.i686 guacd
(if the system complaints the i686 version (). You need to use:
yum install libstdc++.i686 unixODBC.i686 mysql-libs.i686 mysql-libs libcurl-devel.i686 expat.i686 expat glib2.i686 freetype.i686 libSM.i686 libXrender.i686 fontconfig.i686 libXext-devel.i686 guacd libstdc++ glib2
)
yum install libguac-client-vnc mysql-server tomcat6 system-config-printer libXext.i686 libXext

yum install libstdc++.i686 libstdc++ unixODBC.i686 mysql-libs.i686 mysql-libs libcurl-devel.i686 expat.i686 expat glib2.i686 glib2 freetype.i686 libSM.i686 libXrender.i686 fontconfig.i686 libXext-devel.i686 guacd libguac-client-vnc mysql-server tomcat6 system-config-printer libXext.i686 libXext rxvt mpage unix2dos gtk2-devel gtk2-devel.i686 seamonkey ORBit2-devel mlocate fail2ban libgcj.i686 /root/polkit-0.96-12.el6.1.x86_64.rpm
}}}
Turn on fail2ban

{{{
chkconfig fail2ban on
}}}
Line 53: Line 91:
Download the following tar file: http://customers.creativecomputing.com.au/concare/rel15_u_partition.tgz
Download the following tar file: http://customers.creativecomputing.com.au/concare/rel15_u_partition2.tgz
Line 55: Line 95:
cd
wget http://customers.creativecomputing.com.au/concare/rel15_u_partition.tgz

{{{
cd
wget http://customers.creativecomputing.com.au/concare/rel15_u_partition2.tgz
Line 58: Line 100:
tar xvzf ~/rel15_u_partition.tgz  tar xvzf ~/rel15_u_partition2.tgz
}}}
Line 60: Line 103:

{{{
Line 61: Line 106:
}}}
Line 62: Line 108:
rpm -ivh http://customers.creativecomputing.com.au/concare/turbovnc-2.1.x86_64.rpm
cd
wget http://customers.creativecomputing.com.au/concare/turbostartup.tgz

{{{
cd
wget
http://customers.creativecomputing.com.au/concare/turbovnc-2.2.5.x86_64.rpm
yum install turbovnc-2.2.5.x86_64.rpm
wget http://customers.creativecomputing.com.au/concare/turbostartup9.tgz
Line 66: Line 115:
tar xvzf ~/turbostartup.tgz tar xvzf ~/turbostartup9.tgz
Line 69: Line 118:
wget http://customers.creativecomputing.com.au/concare/deletelocks.sh
wget http://customers.creativecomputing.com.au/concare/orbit-cleanup
wget http://customers.creativecomputing.com.au/concare/arial.tgz
Line 70: Line 122:
mv deletelocks.sh /usr/local/bin/
mv orbit-cleanup /usr/local/sbin/
Line 71: Line 125:
Edit /etc/X11/xinit/Xclients and add ". /u/cc/usr/commonx11.sh" below the lines for GSESSION and STARTKDE.  Note there is a space between "." and "/". cd /
tar xvzf ~/arial.tgz
}}}
Edit /etc/X11/xinit/Xclients and add ". /u/cc/usr/commonx11.sh" below the lines for GSESSION and STARTKDE.  Note there is a space between "." and "/".
Line 74: Line 131:

{{{
Line 75: Line 134:
passwd ccc
Line 76: Line 136:
}}}
Add the following line to ~ccc/.vnc/xstartup.turbovnc right after the first 2 "unset" lines

{{{
xhost +
}}}
Install pdftk

{{{
cd
wget http://customers.creativecomputing.com.au/concare/pdftk
mv pdftk /usr/bin/
chmod 755 /usr/bin/pdftk
}}}
Line 77: Line 151:

{{{
Line 79: Line 155:
wget https://sourceforge.net/projects/guacamole/files/current/binary/guacamole-0.9.9.war
mv ~/guacamole-0.9.9.war /var/lib/tomcat6/webapps/guacamole.war
wget http://customers.creativecomputing.com.au/concare/guacdb.sql
wget http://apache.org/dyn/closer.cgi\?action=download\&filename=guacamole/0.9.13-incubating/binary/guacamole-0.9.13-incubating.war
mv ~/guacamole-0.9.13-incubating.war /var/lib/tomcat6/webapps/guacamole.war
wget http://customers.creativecomputing.com.au/concare/guacdb3.sql
Line 84: Line 160:
mysql < ~/guacdb.sql mysql < ~/guacdb3.sql
Line 86: Line 162:
chkconfig httpd on
Guacamole URL: http://104.237.155.33:8080/guacamole/

Restart once more.  guacadmin password is gu4c4dm1n

This is where we were up to last time.  If you followed the previous instructions, start from here.

After the last restart,  "Text mode setup utility" will run.  Just press tab until "quit" is highlighted and press space.

Try logging into guacamole on "http://<ip address>:8080/guacamole/" and connect to the pre configured "ccc" session.  If you see a menu on top, go to System->log out ccc, then say "Log out" to the dialog box that comes up.  This will close the session and start it over.  If the screen has been locked out and screen saver has activated, forcibly restart the vnc session:
}}}
Restart once more.  guacadmin password is gu4c4dm1n

Try logging into guacamole on "http://<ip address>:8080/guacamole/" and connect to the pre configured "ccc" session.  If you see a menu on top, go to System->log out ccc, then say "Log out" to the dialog box that comes up.  This will close the session and start it over.  If the screen has been locked out and screen saver has activated, forcibly restart the vnc session:

{{{
Line 95: Line 169:
}}}
Line 96: Line 171:

{{{
Line 97: Line 174:
}}}
Line 99: Line 176:

{{{
Line 105: Line 184:
Prior to running the following, please make sure you have a cloudprint account set up with Google and have at least one A4 printer there. This link will give you some more idea about Google cloud print: https://www.google.com/cloudprint/learn/printers.html .  It is advisable that you create a Google account just for the sole purpose of printing and not use a pre-existing one.

The following command will initiate setting up cups cloudprint.  (This will ask you to enter a URL into a browser and log in to your Google cloud print account)
/usr/share/cloudprint-cups/setupcloudprint.py
}}}
Prior to running the following, please make sure you have a cloudprint account set up with Google and have at least one A4 printer there. This link will give you some more idea about Google cloud print: https://www.google.com/cloudprint/learn/printers.html .  It is  advisable that you create a Google account just for the sole purpose of printing and not use a pre-existing one.

The following command will initiate setting up cups cloudprint.  (This will ask you to enter a URL into a browser and log in to your Google cloud print account) /usr/share/cloudprint-cups/setupcloudprint.py
Line 111: Line 190:
   Rsync the binl/ binx11/ utbinl/ utbinx11/ from sam:/u/ccr.15/std to your server.
Yum install rsync in your server.
Line 119: Line 194:
#Subsystem    sftp    /usr/libexec/openssh/sftp-server
Subsystem     sftp    internal-sftp

{{{
#Subsystem    sftp    /usr/libexec/openssh/sftp-server
Subsystem     sftp    internal-sftp
Line 125: Line 201:
}}}
Line 126: Line 203:

{{{
Line 128: Line 207:
}}}
Restart sshd if you want to use it straight away

{{{
service sshd restart
}}}
Line 130: Line 214:
Line 131: Line 216:

{{{
Line 132: Line 219:
cd /usr/share/easy-rsa/2.0
source vars
./clean-all
cd /usr/share/easy-rsa/3.0
cp /usr/share/doc/easy-rsa-3.0.3/vars.example ./vars
}}}
Line 136: Line 223:
export KEY_COUNTRY="AU"
export KEY_PROVINCE="NewSouthWales"
export KEY_CITY="CrowsNest"
export KEY_ORG="Creative-Computing"
export KEY_EMAIL="support@creativecomputing.com.au"
export KEY_OU="Concare"

{{{
set_var EASYRSA_KEY_SIZE 4096
set_var EASYRSA_CRL_DAYS 3650
set_var EASYRSA_DIGEST "sha512"
}}}
Line 144: Line 230:
source ./vars
./build-ca
./build-dh
./build-key-server server
wget http://customers.creativecomputing.com.au/concare/openvpn.conf
mv openvpn.conf /etc/openvpn/

{{{
./easyrsa init-pki
./easyrsa build-ca nopass
}}}
It will ask you for your Common name, this is just for display, but better if you put the hostname (or customer company)

{{{
./easyrsa gen-req server nopass
./easyrsa sign-req server server
./easyrsa gen-crl
openssl dhparam -out ./pki/dh4096.pem 4096
}}}
This will generate a secure key, it usually takes a long time.

{{{
openvpn --genkey --secret ./pki/ta.key
wget http://customers.creativecomputing.com.au/concare/server.conf
mv server.conf /etc/openvpn/
Line 153: Line 252:
At this point the OS is installed and a very rudimentary version of Control (based on what's installed in the original test VM) is now installed in the system.  The following instructions are for adding sessions and printers which I will do a live demo for.

To Add a new session:
Add a Linux user and set their password
adduser -m <session_name> -G sftpusers
mkdir -p /sftp/<session_name>/<session_name>
passwd <session_name>
Add this to /etc/fstab:
/u/cc/usr/<session_name> /sftp/<session_name>/<session_name>   none bind
Then mount it.
mount -a
Edit the file /u/cc/usr/vncusers.sh and add a line
USER[<USER_NUMBER>]='<session_name>'
RESO[<USER_NUMBER>]='800x600'
<USER_NUMBER> is a vnc session number, for now keep this between 6 and 100.  5 is the screen we use for support.  The 'RESO' line is optional, if you leave it out, it defaults to 1600x900
Start up the vnc session
initctl start turbo VNC=<USER_NUMBER>
Use a VNC client to connect to <ip_address_of_server>:<USER_NUMBER>.  Initial password is set to "123456"
If the menu is on top, go to System->Log out <session_name>, then click OK.  If the screen saver has started, unlock it with the linux password and log out.  This will move the menus to the bottom of the screen and disable the screen saver.

Change the VNC password:
Open a terminal inside the session:
/opt/TurboVNC/bin/vncpasswd
create guacamole account:
in the web page http://<ip address>:8080/guacamole, log in as guacadmin
click on the guacadmin on the upper right then click on settings
click on connections
click on New Connection
Name: <session_name>
Maximum number of connections: 5
Maximum number of connections per user: 5
Hostname: localhost
Port: <5900+USER_NUMBER>
Password: <vnc_password>

Enable SFTP: <Tick>
Hostname: localhost
Port: 22
Username: <session_name>
Password: <Linux_password>

Default upload directory: /u/cc/usr/<session_name>

and then click Save.
Click on Users
Click on Add New User
Username: <session_name>
Password: <set up a password for end user>
Re-enter Password: same as Password

Change own password: <tick>
Connections:
tick on <session_name>

log in to the guacmole session. And use gnome-control-center to turn off the screensaver.


Install the gtk2 the control requires for the system theme:
yum install gtk2-devel-2.24.23-9.el6.i686

and add
export GTK2_RC_FILES="/etc/gtk-2.0/gtkrc"
into the .vnc/xstartup.turbovnc file in your home directory.
}}}
Reset the vnc password for ccc (vnc session number 5) to control. Do not set a view-only password.

{{{
/opt/TurboVNC/bin/vncpasswd ~ccc/.vnc/passwd
}}}
At this point the OS is installed and a very rudimentary version of Control (based on what's installed in the original test VM) is now installed in the system. The following instructions are for adding sessions and printers which I will do a live demo for.

== To Add a new session: ==
This section moved to [[Installing_Control|Installing Control]]

== For users of previous release (upgrade): ==
populate:

{{{
/u/cc/usr/vncusers.sh
}}}
based on the lines that start with v in:

{{{
/etc/inittab
}}}
take a copy of the untarer.sh and lockdown.tgz:

{{{
cd
wget http://customers.creativecomputing.com.au/concare/lockdown.tgz
wget http://customers.creativecomputing.com.au/concare/untarer.sh
chmod 755 untarer.sh
}}}
Get a list of users from inittab:

{{{
cat /etc/inittab|grep ^v|cut -d: -f4| cut -d\- -f2|xargs
}}}
run untarer.sh using the output of the above as parameters

{{{
./untarer.sh <paste-output-of-above-command>
}}}
you can skip over users that you dont think need a vnc session in the new release.
Line 219: Line 296:
yum install ImageMagick
rsync -av sam:/u/ccr.15/std/qtsdk-2010.05/ to the same locate of your server.
Add the crontab auto post task


These instructions are mostly just an outline.  I will have to do a live demo of this.
These instructions are mostly just an outline.
Line 226: Line 299:
Line 227: Line 301:
If using cloud print (A4 printers): 
On native cloudprint printer 

If using cloud print (A4 printers):

On native cloudprint printer
Line 230: Line 307:
Line 231: Line 309:
Line 232: Line 311:
set up cloudprint on attached windows PC and Chrome. 
set up cloudprint on attached windows PC and Chrome.
Line 234: Line 315:
Line 235: Line 317:

{{{
Line 236: Line 320:
}}}
Line 237: Line 322:
set up openvpn account on the server:
cd /usr/share/easy-rsa/2.0
source vars
./build-key <session_name>
It will then ask you a series of questions, similar to the ones asked by the ./build-key-server script. You should only need to answer the "Common Name" field, "Sign the certificate?" and "1 out of 1 certificate requests certified, commit?"

In the keys directory under current a configuration file <session_name>.ovpn similar to openvpn.conf must be created.
# Configuration for connecting into Concarce internal network

== set up openvpn account on the server: ==
{{{
cd /usr/share/easy-rsa/3.0
./easyrsa gen-req <session name> nopass
}}}
Then we sign our own request:

{{{
./easyrsa sign-req client <session name>
}}}
''If signing the request fails, check the file /usr/share/easy-rsa/3.0/index.txt and make sure you have not used this common name before. If you have and you are sure you want to reuse it, erase the line from the above file''

It will then ask you a series of questions, similar to the ones asked when you built the server key. You should only need to answer the "Common Name" field and "Confirm request details:"

In the pki directory under current a configuration file <session_name>.ovpn similar to openvpn.conf must be created.

{{{
# Configuration for connecting into Creative computing internal network
Line 248: Line 344:
remote <ip_address_of_server> 1194 remote <server_hostname> 1194
Line 251: Line 347:
ifconfig 10.5.0.x 255.255.255.0 # This line is client dependent. (x means choose the ip address to use for client) ifconfig <assigned_IP> 255.255.255.0
Line 257: Line 353:
Then zip all these file you just created ( .crt, .key,.opvn and etc may be 6 or so files) 
zip <session_name>.zip  <session_name>.* dh2048.pem ca.crt

Load into client machine.  An external method may be needed to load the OpenVPN files into the client computer.
cipher AES-256-CBC
auth SHA512
tls-auth ta.key 1
tls-version-min 1.2
tls-cipher
TLS-DHE-RSA-WITH-AES-256-GCM-SHA384
}}}
T
hen zip all these file you just created ( .crt, .key,.opvn and etc may be 6 or so files)

{{{
cd pki

zip -j <session_name>.zip <session_name>.ovpn private/<session_name>.key issued/<session_name>.crt dh4096.pem ca.crt ta.key
}}}

Load into client machine.  An external method may be needed to load the OpenVPN files into the client computer.
Line 263: Line 368:
Line 264: Line 370:
Unzip all the files into the config directory under where OpenVPN is installed (Usually C:\Program Files\OpenVPN\config).  Create a shortcut to OpenVPN on the desktop if the installer has not done so.
Unzip all the files into the config directory under where OpenVPN is installed (Usually C:\Program Files\OpenVPN\config).  Create a shortcut to OpenVPN on the desktop if the installer has not done so.
Line 267: Line 374:
Line 268: Line 376:
Line 269: Line 378:
Line 270: Line 380:
Line 271: Line 382:
prnaad (as end user) 
prnaad (as end user)
Line 273: Line 386:
Line 274: Line 388:

yum install sendmail

chkconfig --levels 235 sendmail on

chmod 755 -R /etc/mail

service sendmail restart

update all the binaries to the latest:

From SAM:

{{{
rsync -avzk --delete /u/ccstandard/ root@<server IP>:/u/ccstandard/
}}}
ssh to the server.

{{{
cd /u/ccr.15/
rsync -av /u/ccstandard/ ./
}}}
Copy the <standard company> to <company name>

chmod a+w -R /u/ccr.15/<company> /u/ccr.15/adm

./contrl =>put address and phone

/u/cc/std/localbin/brarep

== Setting up CRON ==
{{{
ln -s /u/cc /cc
crontab -e

* * * * * /u/cc/binl/auto_postal > /u/cc/LOG/auto_postal.out 2>&1
0 1 * * * /u/cc/binl/post_sum > /u/cc/LOG/post_sum.out 2>&1
0 1 1 * * /u/cc/binl/auto_eom > /u/cc/LOG/auto_eom.out 2>&1
su -
<enter root password>
crontab -e
1 2 * * * /usr/local/sbin/orbit-cleanup > /cc/LOG/orbit-cleanup.out 2>&1
30 1 * * * /u/cc/binl/initda > /u/cc/LOG/initda.out
}}}
'''be sure to modify $CCDIR/binl/auto_eom''' with the correct CCDIR so that it will run for the correct company (specially if you have custom CCDIR)

== Setting up printers ==
{{{
system-config-printer
prnaad
}}}
=== Makesure /u/cc/std/ have the qtsdk-2010.05/ thing ===
=== and "qtx11-4.7.0 -> qtsdk-2010.05/" is placed in /u/cc/std/ ===
cp /u/ccdev/binl/email_pdf to the new server as well.

== If using postfix (no reason other than if already set up before) ==
increase default message size limit:

{{{
postconf -e message_size_limit=102400000
postconf -e mailbox_size_limit=819200000
}}}

You need to install a "minimal install" of CentOS 6.8, using the minimal install CD.

Hostname should be called concare4. Configure Network for DHCP and to "Connect Automatically"

Partition sizes should be as follows (Create Custom Layout):

/        20-50GB, depending on size of drive, format as EXT4
swap     2-32GB, the same size as physical RAM
/u       with the rest of available space (Fill to maximum available size), formatted as EXT4

Make sure you tell us what the root password is set to.

After install is finished it will restart. Turn off firewall and selinux.

chkconfig iptables off
chkconfig ip6tables off

edit /etc/sysconfig/selinux and make sure the SELINUX line is as follows:

SELINUX=disabled

For linode only:

edit /etc/resolv.conf and add:

nameserver 8.8.8.8

Then make the file immutable

chattr +i /etc/resolv.conf

install wget and ppp:

yum install wget ppp openssh-clients

download the following file into the server:

http://customers.creativecomputing.com.au/concare/vpn.tgz

untar the file into /etc/

cd
wget http://customers.creativecomputing.com.au/concare/vpn.tgz
cd /etc
tar xvzf ~/vpn.tgz

then as root, accept the fingerprint:

# ssh 220.233.135.250
The authenticity of host '220.233.135.250 (220.233.135.250)' can't be established.
RSA key fingerprint is f6:f0:5c:21:74:0e:03:db:fc:71:e6:21:63:b5:c0:43.
Are you sure you want to continue connecting (yes/no)?

Type "yes" and cancel the connection (ctrl-c).

Reboot to connect the vpn

Add epel repository:

#rpm -ivh http://download.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm
rpm -ivh https://archives.fedoraproject.org/pub/archive/epel/6/x86_64/epel-release-6-8.noarch.rpm

Download fixed copy of polkit:

cd
wget http://customers.crecom.com.au/concare/polkit-0.96-12.el6.1.x86_64.rpm

use yum to install additional packages

yum groupinstall "Desktop" "General Purpose Desktop" "Print Server" "Web Server" "X Window System" "Internet Browser" "Office Suite and Productivity" "Xfce"

yum install libstdc++.i686 libstdc++ unixODBC.i686 mysql-libs.i686 mysql-libs libcurl-devel.i686 expat.i686 expat glib2.i686 glib2 freetype.i686 libSM.i686 libXrender.i686 fontconfig.i686 libXext-devel.i686 guacd libguac-client-vnc mysql-server tomcat6 system-config-printer libXext.i686 libXext rxvt mpage unix2dos gtk2-devel gtk2-devel.i686 seamonkey ORBit2-devel mlocate fail2ban libgcj.i686 /root/polkit-0.96-12.el6.1.x86_64.rpm

Turn on fail2ban

chkconfig fail2ban on

Load the /u partition:

Download the following tar file: http://customers.creativecomputing.com.au/concare/rel15_u_partition2.tgz

untar it into /u

cd
wget http://customers.creativecomputing.com.au/concare/rel15_u_partition2.tgz
cd /u
tar xvzf ~/rel15_u_partition2.tgz

Add "control" group

groupadd -g 3232 control

install turbovnc:

cd
wget http://customers.creativecomputing.com.au/concare/turbovnc-2.2.5.x86_64.rpm
yum install turbovnc-2.2.5.x86_64.rpm
wget http://customers.creativecomputing.com.au/concare/turbostartup9.tgz
cd /etc
tar xvzf ~/turbostartup9.tgz
cd
wget http://customers.creativecomputing.com.au/concare/vncserver
wget http://customers.creativecomputing.com.au/concare/deletelocks.sh
wget http://customers.creativecomputing.com.au/concare/orbit-cleanup
wget http://customers.creativecomputing.com.au/concare/arial.tgz
mv vncserver /opt/TurboVNC/bin/
mv deletelocks.sh /usr/local/bin/
mv orbit-cleanup /usr/local/sbin/
chmod 755 /opt/TurboVNC/bin/vncserver
cd /
tar xvzf ~/arial.tgz

Edit /etc/X11/xinit/Xclients and add ". /u/cc/usr/commonx11.sh" below the lines for GSESSION and STARTKDE. Note there is a space between "." and "/".

Create the ccc user and start up its vnc session

adduser -m ccc
passwd ccc
initctl start turbo VNC=5

Add the following line to ~ccc/.vnc/xstartup.turbovnc right after the first 2 "unset" lines

xhost +

Install pdftk

cd
wget http://customers.creativecomputing.com.au/concare/pdftk
mv pdftk /usr/bin/
chmod 755 /usr/bin/pdftk

Install guacamole:

chkconfig guacd on
cd
wget http://apache.org/dyn/closer.cgi\?action=download\&filename=guacamole/0.9.13-incubating/binary/guacamole-0.9.13-incubating.war
mv ~/guacamole-0.9.13-incubating.war /var/lib/tomcat6/webapps/guacamole.war
wget http://customers.creativecomputing.com.au/concare/guacdb3.sql
chkconfig mysqld on
service mysqld start
mysql < ~/guacdb3.sql
chkconfig tomcat6 on

Restart once more. guacadmin password is gu4c4dm1n

Try logging into guacamole on "http://<ip address>:8080/guacamole/" and connect to the pre configured "ccc" session. If you see a menu on top, go to System->log out ccc, then say "Log out" to the dialog box that comes up. This will close the session and start it over. If the screen has been locked out and screen saver has activated, forcibly restart the vnc session:

initctl stop turbo VNC=5

wait a few seconds, then:

initctl start turbo VNC=5

Install cups-cloudprint:

cd
wget http://customers.creativecomputing.com.au/concare/cups.tgz
cd /etc
tar xvzf ~/cups.tgz
yum install cupscloudprint
service cups restart

Prior to running the following, please make sure you have a cloudprint account set up with Google and have at least one A4 printer there. This link will give you some more idea about Google cloud print: https://www.google.com/cloudprint/learn/printers.html . It is advisable that you create a Google account just for the sole purpose of printing and not use a pre-existing one.

The following command will initiate setting up cups cloudprint. (This will ask you to enter a URL into a browser and log in to your Google cloud print account) /usr/share/cloudprint-cups/setupcloudprint.py

For now, only add the account and do not add any printers just yet.

Set up chroot sftp

In /etc/ssh/sshd_config change the following near the bottom:

#Subsystem    sftp    /usr/libexec/openssh/sftp-server
Subsystem     sftp    internal-sftp
Match Group sftpusers
        ChrootDirectory /sftp/%u
        ForceCommand internal-sftp

Add a new group sftpusers and create a chroot subdirectory

groupadd -g 3255 sftpusers
mkdir /sftp/

Restart sshd if you want to use it straight away

service sshd restart

Set up OpenVPN

Install the OpenVPN package

yum install openvpn easy-rsa
cd /usr/share/easy-rsa/3.0
cp /usr/share/doc/easy-rsa-3.0.3/vars.example ./vars

Edit the file "vars" and change the items near the end (this is just an example, you can use your real location details):

set_var EASYRSA_KEY_SIZE        4096
set_var EASYRSA_CRL_DAYS        3650
set_var EASYRSA_DIGEST          "sha512"

build the certificate authority (just accept all the defaults and say yes to sign the certificate and commit):

./easyrsa init-pki
./easyrsa build-ca nopass

It will ask you for your Common name, this is just for display, but better if you put the hostname (or customer company)

./easyrsa gen-req server nopass
./easyrsa sign-req server server
./easyrsa gen-crl
openssl dhparam -out ./pki/dh4096.pem 4096

This will generate a secure key, it usually takes a long time.

openvpn --genkey --secret ./pki/ta.key
wget http://customers.creativecomputing.com.au/concare/server.conf
mv server.conf /etc/openvpn/
chkconfig openvpn on
mkdir /var/log/openvpn
service openvpn start

Reset the vnc password for ccc (vnc session number 5) to control. Do not set a view-only password.

/opt/TurboVNC/bin/vncpasswd ~ccc/.vnc/passwd

At this point the OS is installed and a very rudimentary version of Control (based on what's installed in the original test VM) is now installed in the system. The following instructions are for adding sessions and printers which I will do a live demo for.

To Add a new session:

This section moved to Installing Control

For users of previous release (upgrade):

populate:

/u/cc/usr/vncusers.sh

based on the lines that start with v in:

/etc/inittab

take a copy of the untarer.sh and lockdown.tgz:

cd
wget http://customers.creativecomputing.com.au/concare/lockdown.tgz
wget http://customers.creativecomputing.com.au/concare/untarer.sh
chmod 755 untarer.sh

Get a list of users from inittab:

cat /etc/inittab|grep ^v|cut -d: -f4| cut -d\- -f2|xargs

run untarer.sh using the output of the above as parameters

./untarer.sh <paste-output-of-above-command>

you can skip over users that you dont think need a vnc session in the new release.

Set up a Printer:

These instructions are mostly just an outline.

If using a printer that will be hooked up to a windows PC, We will need to make sure that the windows printer driver is installed and a test page can be printed.

If using cloudprint, a google account should be created solely for printing.

If using cloud print (A4 printers):

On native cloudprint printer

set up cloudprint on device (this is device specific)

https://support.google.com/cloudprint/answer/1686197?hl=en

On classic printer

set up cloudprint on attached windows PC and Chrome.

https://support.google.com/cloudprint/answer/1686197?hl=en

for both of the above: set up cups-cloudprint using python script

/usr/share/cloudprint-cups/setupcloudprint.py

If direct printing (40 column thermal receipt printers and label printers)

set up openvpn account on the server:

cd /usr/share/easy-rsa/3.0
./easyrsa gen-req <session name> nopass

Then we sign our own request:

./easyrsa sign-req client <session name>

If signing the request fails, check the file /usr/share/easy-rsa/3.0/index.txt and make sure you have not used this common name before. If you have and you are sure you want to reuse it, erase the line from the above file

It will then ask you a series of questions, similar to the ones asked when you built the server key. You should only need to answer the "Common Name" field and "Confirm request details:"

In the pki directory under current a configuration file <session_name>.ovpn similar to openvpn.conf must be created.

# Configuration for connecting into Creative computing internal network
tls-client
dev tap
proto udp
remote <server_hostname> 1194
resolv-retry infinite
nobind
ifconfig <assigned_IP> 255.255.255.0
ca ca.crt
cert <session_name>.crt
key <session_name>.key
verb 3
mute 10
cipher AES-256-CBC
auth SHA512
tls-auth ta.key 1
tls-version-min 1.2
tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384

Then zip all these file you just created ( .crt, .key,.opvn and etc may be 6 or so files)

cd pki
zip -j <session_name>.zip <session_name>.ovpn private/<session_name>.key issued/<session_name>.crt dh4096.pem ca.crt ta.key

Load into client machine. An external method may be needed to load the OpenVPN files into the client computer.

Use the latest stable installer (whether 32 bit or 64 bit) from the following:

https://openvpn.net/index.php/open-source/downloads.html

Unzip all the files into the config directory under where OpenVPN is installed (Usually C:\Program Files\OpenVPN\config). Create a shortcut to OpenVPN on the desktop if the installer has not done so.

set up windows driver and make sure test page works.

turn on Unix printing for windows and make sure it auto starts the service.

use system-config-printer to set up cups

At this point, you have a cups printer, either to a cloud printer device, or a direct printing device.

run printer management from inside Control:

prnaad (as end user)

cloud print printer use "graphics" printing, the rest choose appropriate printer model.

Go to Control "terminal details" screen to set up printers.

yum install sendmail

chkconfig --levels 235 sendmail on

chmod 755 -R /etc/mail

service sendmail restart

update all the binaries to the latest:

From SAM:

rsync -avzk --delete /u/ccstandard/ root@<server IP>:/u/ccstandard/

ssh to the server.

cd /u/ccr.15/
rsync -av /u/ccstandard/ ./

Copy the <standard company> to <company name>

chmod a+w -R /u/ccr.15/<company> /u/ccr.15/adm

./contrl =>put address and phone

/u/cc/std/localbin/brarep

Setting up CRON

ln -s /u/cc /cc
crontab -e

* * * * * /u/cc/binl/auto_postal > /u/cc/LOG/auto_postal.out 2>&1
0 1 * * * /u/cc/binl/post_sum > /u/cc/LOG/post_sum.out 2>&1
0 1 1 * * /u/cc/binl/auto_eom > /u/cc/LOG/auto_eom.out 2>&1
su -
<enter root password>
crontab -e
1 2 * * * /usr/local/sbin/orbit-cleanup > /cc/LOG/orbit-cleanup.out 2>&1
30 1 * * * /u/cc/binl/initda > /u/cc/LOG/initda.out

be sure to modify $CCDIR/binl/auto_eom with the correct CCDIR so that it will run for the correct company (specially if you have custom CCDIR)

Setting up printers

system-config-printer
prnaad

Makesure /u/cc/std/ have the qtsdk-2010.05/ thing

and "qtx11-4.7.0 -> qtsdk-2010.05/" is placed in /u/cc/std/

cp /u/ccdev/binl/email_pdf to the new server as well.

If using postfix (no reason other than if already set up before)

increase default message size limit:

postconf -e message_size_limit=102400000
postconf -e mailbox_size_limit=819200000

InstallingControlOnCentos6 (last edited 2023-01-30 05:56:11 by 61-68-142-254)