Thursday, December 27, 2018

Port block!! Checkpoint in firewalls

Nginx
# ee /usr/local/etc/nginx/nginx.conf

IPFW
# ee /etc/rc.conf

AWS - Security Group
Enable ports

Reload:
# service nginx reload
# service ipfw restart

Related article: Install Nginx on freeBSD

Nginx on freeBSD: 2. Setting Up a server Block

cont... (Install Nginx on freeBSD)

Nginx on FreeBSD 11.2 has one server block enabled by default that is configured to serve documents out of a directory at /usr/local/www/nginx. While this works well for a single site, it can become unwieldy if you are hosting multiple sites. Instead of modifying /usr/local/www/nginx, let's create a directory structure within /usr/local/www for our example.com site.

#sudo mkdir -p /usr/local/www/example.com/

Assign ownership of the directory to the www user:
#sudo chown -R www:www /usr/local/www/example.com

The permissions of your web root should be correct if you haven't modified your umask value, but you can make sure by typing:
# sudo chmod -R 755 /usr/local/www/example.com

# sudo ee /usr/local/www/example.com/index.html
<h1>Web example 1</h1>

Change the configuration
To find the cpu cores:
# sysctl hw.ncpu
# sudo ee /usr/local/etc/nginx/nginx.conf
(To load from the system backup
#sudo cp /usr/local/etc/nginx/nginx.conf-dist /usr/local/etc/nginx/nginx.conf)

/usr/local/letc/nginx/nginx.conf
user  www;
worker_processes  1;

events {
    worker_connections  1024;
}

http {
    include       mime.types;
    default_type  application/octet-stream;
    sendfile        on;
    keepalive_timeout  65;

    server {
        access_log /var/log/nginx/example.com.access.log;
        error_log /var/log/nginx/example.com.error.log;
        listen       80;
        server_name  example.com www.example.com;

        location / {
            root   /usr/local/www/example.com;
            index  index.html index.htm;
        }

    }

}

# sudo nginx -t
# sudo service nginx reload

For port check: Port firewall/block checking points

Funny mistakes:
1. You need to login from outside network to login with the public IP!
2. Make sure your port is open.

Wednesday, December 26, 2018

Nginx on FreeBSD: 1 - Installation /Uninstall

Installation:
# pkg install nginx
If you check the which shell
# echo $SHELL

Enable Ngnix service
rc is a FreeBSD utility that controls the system's automatic boot processes.Scripts for every service available on the system are located in the /usr/local/etc/rc.d directory. These define the parameters that are used to enable each service using the rcvar variable
# grep rcvar /usr/local/etc/rc.d/*


After has been installed, this command will output a listing similar to this:
Output
/usr/local/etc/rc.d/cloudconfig:rcvar="cloudinit_enable" /usr/local/etc/rc.d/cloudinitlocal:rcvar="cloudinit_enable" /usr/local/etc/rc.d/nginx:rcvar=nginx_enable /usr/local/etc/rc.d/rsyncd:rcvar=rsyncd_enable
The parameter that you need to set for the nginx service is highlighted here in this output. The name of the script itself — the last component of the path before the colon — is also helpful to know, as that's the name that FreeBSD uses to refer to the service.
To enable the nginx service you must add its rcvar to the rc.conf file, which holds the global system configuration information referenced by the startup scripts. Use your preferred editor to open the /etc/rc.conf file with sudo privileges. Here, we'll use 
# sudo ee /etc/rc.conf
/etc/rc.conf
. . .
sshd_enable="YES"
nginx_enable="YES"

IPFW is a stateful firewall written for FreeBSD.

Directly below the nginx_enable parameter you just added, add the following highlighted lines:
/etc/rc.conf
. . .
nginx_enable="YES"
firewall_enable="YES"
firewall_type="workstation"
firewall_myservices="22/tcp 80/tcp"
firewall_allowservices="any"
For the first time to run the server (in csh or tcsh shells, freeBSD)
# nohup service ipfw start >&/tmp/ipfw.log

Stop, start and restart the ipfw service.
# sudo service ipfw stop
# sudo service ipfw start
# sudo service ipfw restart

Start the Nginx service:
# service nginx start

Stop Ngnix:
# service nginx stop
# rm -f -R /usr/local/nginx && rm -f /usr/local/sbin/nginx
# rm -rf /var/www
# sysrc nginx_enable=no
http://192.168.10.114/
OR, to see the public ip address: 
# curl -4 icanhazip.com

To setting Up a server Block using a domain name.


Uninstall Nginx:
From ports:
# service nginx stop
# cd /usr/ports/www/nginx && make deinstall
Check the liestening ports
# sockstat -4 -l




FreeBSD: Starting your day! Essential commands

Log in to the server with the private key:
# ssh -i ~/.ssh/freeBSD junayed@192.168.10.114 -p 22

$ ssh -i freeBSD junayed@192.168.10.114

List services:
# service -e

# nginx -v
# sockstat -4 -l
uname -vm

Sunday, December 23, 2018

JIRA on FreeBSD

1. Download Jira .tar.gz version from Atlassian’s website.

2. sftp the file to your server.
# sftp -i "aws-domo.pem" ec2-user@exxx.amazonaws.com
# sftp> put atlassian-jira-software-7.13.0-x64.bin
# sftp> ! (to exit from the sftp)
Bingoo!

3. Install tomcat-native
# pkg install openjdk8 tomcat-native
OR
# pkg install openjdk
# java -version

4. create a user for JIRA
# adduser
# adduser

Username: jira
Full name: JIRA psuedo-user
Uid (Leave empty for default): 71
Login group [jira]: 
Login group is jira. Invite jira into other groups? []: 
Login class [default]: 
Shell (sh csh tcsh zsh rzsh git-shell nologin) [sh]: 
Home directory [/home/jira]: /usr/local/jira
Home directory permissions (Leave empty for default): 
Use password-based authentication? [yes]: no
Lock out the account after creation? [no]: no
Username   : jira
Password   : <disabled>
Full Name  : JIRA psuedo-user
Uid        : 71
Class      : 
Groups     : jira 
Home       : /usr/local/jira
Home Mode  : 
Shell      : /bin/sh
Locked     : no
OK? (yes/no): yes
adduser: INFO: Successfully added (jira) to the user database.

5. Install MySQL server (jira need this)
GRANT ALL PRIVILEGES ON *.* TO 'jira'@'localhost' IDENTIFIED BY 's@ydrfD34FEds';
exit
# mysql -u jira -p
CREATE DATABASE jira;

6. JIRA Setup
Extract the .tar.gz we downloaded from Atlassian
root@freebsd:/usr/home/ec2-user # tar xzvf atlassian-jira-software-7.13.0.tar.gz
# mv atlassian-jira-software-7.13.0-standalone /usr/local/share/jira
# mkdir /usr/local/jira

# cd /usr/local/share/jira 
# chown jira:jira logs temp work

#!/bin/sh

#
# PROVIDE: jira
# REQUIRE: DAEMON 
# KEYWORD: shutdown

. /etc/rc.subr

load_rc_config jira

JAVA_HOME="/usr/local/openjdk8"
JRE_HOME="/usr/local/openjdk8/jre"
JIRA_INSTALL="/usr/local/share/jira"
JIRA_HOME="/usr/local/jira"

jira_enable=${jira_enable:-"NO"}
jira_user=${jira_user:-"jira"}

name=jira
rcvar=jira_enable

procname="java"
pidfile="/var/run/jira.pid"

start_cmd="jira_start"
stop_cmd="jira_stop"

jira_start()
{
 su -l ${jira_user} -c "export JAVA_HOME=${JAVA_HOME};export JRE_HOME=${JRE_HOME};export JIRA_HOME=${JIRA_HOME};${JIRA_INSTALL}/bin/catalina.sh start || err 1 'Error triggering JIRA startup'"
}

jira_stop()
{
 su -l ${jira_user} -c "export JAVA_HOME=${JAVA_HOME};export JRE_HOME=${JRE_HOME};export JIRA_HOME=${JIRA_HOME};${JIRA_INSTALL}/bin/catalina.sh stop 10 -force || err 1 'Error triggering JIRA shutdown'"
}

run_rc_command "$1"
Change your directories as required.
Save that to /usr/local/etc/rc.d/jira and we’ll need to make it executable with `

# chmod u-w,ugo+x /usr/local/etc/rc.d/jira
# sysrc jira_enable="YES"
# /usr/local/etc/rc.d/jira start or service jira start

Display IPv4 related open ports
# sockstat -4 -l
Make a port forward in the router, and point your browser at http://xxx:8080

Congratulation!

Friday, December 21, 2018

MySQL server 5.7 installation of freeBSD 12

(It is recommended that to install MySQL before the installation of PHP_extension to avoid old extension installation.)

Method #1. Install using port: (not working!)
# cd /usr/ports/databases/mysql80-server && make install clean BATCH=yes

(By default, we will compile the software from source, it is not built in static. According to MySQL documentation, building the binary using static will result a 13% improvement comparing to building the binary using dynamic. Here is an example how to build MySQL with static option enabled)

# make BUILD_OPTIMIZED=yes BUILD_STATIC=yes
# make install clean
(It takes ...time hr)

/etc/rc.conf
mysql_enable="YES"
# sysrc apache24_enable=yes

Method #2, Installusing pkg:
# pkg update
# pkg upgrade
# pkg install mysql57-server mysql57-client
# sysrc mysql_enable="yes"
# service mysql-server start


MySQL secure installation:
(Note the password)
# cat $HOME/.mysql_secret
yFH&pek0yw3

# mysql_secure_installation
Answer them all with ...y
# mysql -u root -p 
password: yFH&pek0yw3
root@localhost [(none)]> ALTER USER 'root'@'localhost' IDENTIFIED BY 'yFH&pek0yw3';
root@localhost [(none)]> show databases;

Create a user / database in MySQL:
GRANT ALL PRIVILEGES ON *.* TO 'jira'@'localhost' IDENTIFIED BY 's@ydrfD34FEds';
exit
# mysql -u jira -p
CREATE DATABASE jira;

Check the latest version of the MySQL:
# mysqladmin -u root -p version

Start/Stop:
# sudo /usr/local/etc/rc.d/mysql-server start
# service mysql-server start
# sudo /usr/local/etc/rc.d/mysql-server start

Link:
Install Portsnap

Ref:
1. How to Install MySQL Server with phpMyAdmin on FreeBSD 11
2. The easiest way to improve the performance of MySQL server on FreeBSD

Install Portsnap


Links: Installing Applications: Packages and Ports: Using the Ports Collection.

Install Portsnap:
Get the ports collection and extract it.
# portsnap fetch extract
# portsnap fetch update

# whereis apache24

Example:
Install the Nano editor, go to ports directory;
# cd /usr/ports/editors/nano && make install clean

Removing Installed Ports:
# cd /usr/ports/editors/nano
make deinstall

Check the listening ports:
# sockstat -4 -l

Upgrading Ports Using Portmaster:
ports-mgmt/portmaster is a very small utility for upgrading installed ports. It is designed to use the tools installed with the FreeBSD base system without depending on other ports or databases. To install this utility as a port:
# cd /usr/ports/ports-mgmt/portmaster
# make install clean

To list these categories and search for updates:
# portmaster -L

This command is used to upgrade all outdated ports
# portmaster -a
If errors are encountered during the upgrade process, add -f to upgrade and rebuild all ports:
# portmaster -af

Portmaster can also be used to install new ports on the system, upgrading all dependencies before building and installing the new port. To use this function, specify the location of the port in the Ports Collection:
# portmaster shells/bash

Upgrading Ports Using Portupgrade:
# cd /usr/ports/ports-mgmt/portupgrade
# make install clean