Not Migrating: Windows Security Considerations

Just because I’m convinced Linux has a better security posture than Windows does not mean Windows is useless. And sometimes you just don’t need that much control to get things done. Frankly, a badly configured Linux box is as easily trashed as the average Windows box. Windows can be secured, but it’s more work.

When it comes to running as a server, it’s hard to beat Linux for smaller operations. For any computer connected to the Net full-time, I trust a Linux over any Windows box. But when your computer has only intermittent access to the Net, particularly for laptops and other mobile devices, the threat profile is inherently lower. What you still have to guard against are things like viruses and spyware.

And let’s be honest: To the fanboy of any OS, theirs will always be the best. To the average user lacking such loyalties, Linux is still lacking for desktop and laptop use. The Linux desktop is simply not that compelling. And for some uses, Linux is frankly inferior. Gaming? Windows; no contest. Multimedia? It’s a little more complex. On the one hand, Open Source can access more kinds of formats, and can manipulate them easily, and seldom pays much attention to DRM and other vendor controls. On the other hand, Linux seldom competes in terms of resource usage. That is, to play the same multimedia file on a particular machine running Linux requires more horsepower than the same machine with the same file running Windows. There are a dozen reasons for this, and I’m not going to chase rabbits. Frankly, most people aren’t geeky enough to pay much attention to a resource meter, even if they had one, and which ones would you trust? Otherwise, I’d say Linux typically runs standard operations on a lot less RAM.

Generic instructions on securing Windows are all over the place, and frankly contradictory at times. I’m not going to pretend I am an expert. All I know is what I have experienced in the years of running Windows on at least one of the systems in my home, and helping others with theirs.

Never, ever trust McAfee and Norton. Both have been bought out by major corporations who then fired all the chief developers. Not since Windows 95 days have they been any good, and often a great deal of trouble. I’ve used a large collection of the free AV offerings and some of the commercial ones. I used to love AVG, but they’ve gotten fat and slow. I still rather like Vipre from GFI, but it started causing me some problems last year. These days I favor Avast from Alwil. The free version is good enough, and the paid version is even better.

For spyware, it’s a toss-up between Super Anti-spyware and Malwarebytes. The former is a bit more aggressive with the advertising, so I give Malwarebytes the edge. I don’t trust any software firewall. There was a time when ZoneAlarm was useful, but when it was bought out by some Mossad front in Israel, I dropped it like a hot rock. Never trust a company run by a foreign government secret agency, regardless of which country. Always prefer a hardware firewall (or router), but if you are using a laptop and free wifi, the built-in firewall on Vista and Win7 is better than nothing.

Sites related to entertainment — movies, music, games, etc. — are your worst enemy. It’s the cool toys which are used to sucker you into a situation which compromises your system. All the more so if your tastes run to vice. If you gotta have it, don’t run Windows. If you can restrain yourself, standard protections work fine.

You may recall in my post on securing Firefox on RHEL 6, I noted there it’s the same tricks used on Windows. Download and install first the CCleaner and learn how to use it. Or, use BleachBit for Windows. The point is to make sure you have something which eats evercookies, in particular the LSO cookies from Flashplayer. Install those addons: Adblock, Flashblock, Ghostery. Make sure to configure them to do the blocking. Facebook fans, you’ll need to make sure you tell Ghostery it’s okay to display the stuff from Facebook Connect, or you won’t be able to play any of those silly games. Better yet, stay away from Facebook, MySpace and similar idiot-bait sites.

Don’t run Chrome. On both Windows and Linux right now, the slightest little bit of JScript on the page and it starts running like a fully loaded truck. I’ve noticed it pulls about 50% of both my CPU cores regardless of which OS it runs on, and that’s just too much to ask. Internet Explorer does not honor CSS very much, so a lot of pages using Cascading Style Sheets for formatting the display will look ugly in IE. Opera is in a high state of flux right now, needing some good extensions, but most of what they now have works poorly. Also, their JScript engine tends to go nuts now and then, refusing to work in some of the oddest places.

Once again, we have this recurring theme: Take control of your computer use. If it’s worth doing, then it’s worth becoming self-sufficient.

Posted in computers | Tagged , , | 2 Comments

Sanity and Self-Sufficiency

In a previous post, I noted my interest in Linux and Open Source was primarily a matter of self-sufficiency, though I phrased it as a matter of having control over my computer. People want such control when they are ready to take responsibility for things, when they decide to be self-sufficient in some area of life.

In a broad general sense, self-sufficiency has a bad reputation in this world. It’s called everything else, including isolationism, tribalism, paranoia, etc. Those of us reaching for more self-sufficiency have no beef with the rest of humanity doing what they please, we just don’t want to be vulnerable when it serves no good purpose. There are plenty of things in this life where being open to injury is utterly necessary, and absorbing abuse is good and right. That’s what mysticism does to you; it makes you believe some things here aren’t as important as they seem because there are issues somewhere else, on another plane, which take priority. By the same token, such a concern over higher priorities will inevitably result in choices for greater self-sufficiency, if only to avoid unnecessarily burdening others.

In the virtual world, the Internet landscape, it is absolutely necessary we cooperate. Indeed, the Internet is the ultimate voluntary community. There is a certain necessary assumption in the very nature of the thing which calls for a high level of self-sufficiency in some areas, and somewhat more dependence in others. Failure to discern where those lines should be drawn is what makes it so ugly for the rest of the Net. For example, I note frequently the International Merchant Culture, with it’s utterly mercenary spirit, does everything in its power to subvert the nature of the Internet. That they aren’t strongly opposed is part of what makes the Net work, but using technology to route around them, as if they were some kind of damage or bottleneck, is wholly justified. If you want to block advertising and in your browser, it is entirely appropriate. They call it unfair, with all sorts of dire warnings this will hinder paying the bills for keeping good content on the Net, but I’m not so sure their content will be missed, since what they fund never fails to be self-serving. The mainstream media is, as a whole, a liar first and foremost. Sure, some decent folks will be caught in the middle, but nothing is simple. By using technology to frustrate their power grab, we remind Merchants it is all cooperative.

I don’t see WordPress, the host of this blog, suffering much by the lack of advertising on my blog, for instance. There are a few people who manage to do business without cutting throats, but I find them few and far between.

It’s that same evil mercenary spirit of the Merchant Culture which causes me to distrust them in my choice of operating system. I count Red Hat as a company generally lacking in the mercenary instinct, in part because such instinct simply won’t fit in with using Linux in the first place. Red Hat doesn’t contribute much to making Linux pretty or fun, but their developers are the single greatest source of kernel patches, and security improvements in general. If you want the extra toys and eye candy, you’ll have to get them for yourself. That’s self-sufficiency, particularly in the issues where you should have it. Where you should be able to trust them, with the arcane science of Linux internals, I find them trustworthy. It’s a compromise, and it works for me.

All the more so when the Merchant Culture is not the only threat in the Net. It’s not just the lawless crackers and Internet mafia folks, either, but governments. A particularly significant threat is the US government. The Internet was born here in the US, and it was a government project. However, it was funded by government because no one else could afford it in its infancy. Really expensive computers operated by academics at colleges and government research labs were government property, though not always owned by the same government entity. Basically, it was not really a government operation, but an academic one. The government was actually quite slow to catch on to its value. It was a large collection of academics, government employees, and some brilliant independent scientists who got it roaring before the ruling elite awoke to its power.

Here in the US in particular, government elites still say with a straight face they are simply serving the people. Since they promote this mythology, they have to come up with all sorts of fresh manipulations and lies when “We the People” who supposedly rule decide to do something with what our taxes have wrought, which activities tend to interfere with their Olympian plans. Yes, we know it’s all a big lie, but they are the ones who keep saying it’s our nation and our government, and they simply carry out our wishes. If our actions prove they are lying, because there is a conflict between what they say are our wishes versus what we clearly and obviously intend to do against their wishes, then they should have sense enough to realize they failed us. They usually do, but utterly lacking in any moral sense, they blame us.

I lose no sleep at night defying their wishes. A significant element in my choice to run Red Hat (or its clones CentOS and Scientific Linux) is defying elements of their unjust grab for power over my computer. I, for one, am utterly certain there are backdoors in Windows wide open to the NSA and other government agencies. While the federales have certainly poked their fingers in my eye once or twice intentionally, I rather suspect they don’t have the resources to pay attention to me right now. That doesn’t mean they won’t harm me, if nothing else, while targeting someone else.

By no means would I expect anyone going to jail for the crime of setting loose the Stuxnet worm on the Net. Not the real crooks, anyway. The government thugs already have laws on the books forbidding them doing such things, but they consider themselves a class apart; such laws apply to “We the People.” On the one hand, we hear this is one of the best constructed viruses ever. When reports came out later saying it wasn’t so brilliant after all, I figured that was at least partly lying propaganda, trying to put out the fire after the fact. If you ask me, having that nasty thing hit other computer systems besides the ones in Iran was just a part of their cover, a plausible deniability factor. Who’s to say their next nasty attack won’t hit ordinary folks like you and me? If it destroys the systems of a bunch of We the People mundanes, it’s just part of taxation, as far as they are concerned.

Somewhere between the need for security and need to get things done without wasting too much time, I find running Red Hat a pretty good compromise. You may well find the balance somewhere else, and I applaud you for at least looking into it and deciding for yourself. It occurs to me a greater mix, a proliferation of differing and distinctive operating systems connected to the Net, instead of the near-monopoly of Windows, would reduce the botnets and spam, not to mention the unintended consequences of government sponsored evil.

Posted in computers, globalism | Tagged , , , , , | 1 Comment

She Doesn’t Want Me

“Chuck, tell me that wasn’t you I saw at the Boarhead last night! And with the hottest middle-aged babe in three counties.”

“Well, I was there, Merle, and the lady did seem to create a sensation with the males in the crowd.”

“I thought you were a celibate, Chuck, with all that mysticism mumbo-jumbo” Merle snickered. “You been holding out on me?”

“I’m still single because I’m very demanding. I’m not looking for someone to replace my dearly departed, just a worthy successor. As it was, this lady asked me out, and paid the tab.”

Merle threw both arms overhead, palms facing. “Touchdown! A hot babe sugar-mama!”

Chuck turned to drag the lunch box from his satchel. “I’ll answer your questions when you tone down the enthusiasm a bit.”

“Okay, okay. Look, man, I just want to know what was going on. You act like it didn’t turn out so good.”

“Nothing is a waste of time if you pay attention and learn from it. But it isn’t going the way she expected it.”

“She some kind of dominatrix or something? I can’t imagine anything else that would be a turn off.” Merle took a big bite of his sandwich.

Chuck twisted the lid off his thermal soup bowl. “No, she’s a very nice lady.”

“So how did you meet her? At that church thing you do?”

Swallowing a spoonful of soup, Chuck gave a wry smile. “Sort of. You know I volunteer to watch the indoor play area at the church to satisfy the insurance liability rules so they can let kids play there on Saturdays. Most of them are member kids and it’s kinda fun. A few weeks ago one family brought some neighbors with them.”

Merle smirked, “Oh, so she has kids. That’s always a good way to get to a woman. I know you sure have a way with children. They scare me.”

“I keep telling you, Merle, kids are not hard to deal with. You were one once.”

“That’s what scares me.”

Chuck rolled his eyes. “Look, the main thing is to take them seriously. Especially when they aren’t your kids, you don’t try to guide or push your own view of things on them. Just listen to them and help them explore their own thoughts and feelings. They get enough crap with people telling them what to do and what to think. Give them room to express what matters to them. If you know the answer to something they ask, give an honest answer. Tell them what you think, and that it’s only your own thoughts. Once they realize they can trust you, they’ll pour out their hearts.”

“That only sounds easy.”

“Well, Merle, if it ever matters to you, you’ll figure it out. At any rate, they quickly let me know they were hungry for adult male attention and were all over me. After couple of weeks like that, their mom showed up to watch them play. It changed their behavior, which is how I knew it was their mom. But they eventually came and talked to me, just without the expressive cuddling behavior. That’s when she approached me.” He took a couple bites of soup.

“She hit on your right away?”

“No. She just introduced herself. She’s too mature for lounge lizard behavior. But she was rather frank. She’s a widow, not a divorcee. In her own words, she was ‘a trophy bride’ for some ring-knocker who was killed in Afghanistan. Because he had been on the promotion fast-track, she never used her accounting degree except to keep the household budget. It was all Army wife politics and such. When he came home in a box, she was consoled briefly, then asked to move on quickly. She was told in guarded terms the other women worried she would poach someone else’s man, since she was so nearly the perfect wife.”

“Ah, a West Pointer, a politician in uniform. So her world came to an end.”

“Something like that. At any rate, she decided her masters in accounting might help her get into a different world. Wound up working in the bowels of the Fed branch downtown. She says it’s actually worse than military politics.”

Merle spoke around another bit of food, “So she’s pretty smart and you get along with the kids. What’s not to like? She expect too much of you? I know she couldn’t take her eyes off you at the restaurant. There might as well have been no other guys there.”

“Yes and no. It was rather unnerving, actually. People do that when they want something you shouldn’t give them. She made it easy for me to understand her, because she’s sane and fully conscious of her own mind — quite rare in women.”

Merle thumped his fist gently on the table. “So spill it man. What does she want that you can’t give?”

“She wants a father for those kids. She’ll have no trouble doing and giving herself completely to any man suited for the task. I don’t think it would matter if I was unemployed, even. And it’s quite commendable she is so focused on them; that’s the way a woman is supposed to be wired. But there’s nothing else there. It will be the best of all worlds while those kids are still maturing, even as far as getting through college if they want to go. She knows she can’t make them take any particular direction, and simply wants them up and able to live with their own choices. She plans on being the smart mom even after they become adults. But that’s it.”

“What do you mean, ‘That’s it’?”

“Merle, kids are not the end of life. They are an extension of who you are, but they aren’t the center of things. She has no interest in anything else. That’s all marriage is to her. It’s not about friendship and partnership with her. It’s all about duty. She would never be able to understand what matters most to me. My devotion to higher things, trying to live on that other plane — she has zero interest in that. It’s just ‘my thing,’ a hobby she’ll tolerate gracefully.”

Merle looked thoroughly puzzled.

Chuck was finished eating. Putting away his stuff, he said, “It’s like she wouldn’t be marrying me at all. She only wants the external shell, the matrix of behavior. She doesn’t want me.”

Posted in fiction | Tagged , , , | Comments Off on She Doesn’t Want Me

I Trust Ben

Search engines have opened up the world to ordinary Net surfers. I can recall using Alta Vista, then liking Go better, then Yahoo, then Google. These days, Google is simply not the best. Oddly, Bing actually gives far better results on the searches I conduct, particularly when I search of Linux-related stuff. My experience with Google lately has been very disappointing, often throwing at me far, far too many sites which are pure traps put up by marketers. If I want merchandise, I’ll use Google Shopping (formerly Froogle). When I want information, marketing is an insult.

This I realized all by myself, without be told. I don’t hate Google; I simply don’t use them for much. I never trusted them, since their seed money came partly from US intelligence agencies. If you don’t know about Google’s efforts to support not only advertisers tracking your every eye-blink on the Net, but government surveillance, too, you simply haven’t been paying attention.

Meanwhile, for years I’ve been following the work of Ben Edelman, primarily in reference to malware and evil advertisers (which is just about all of them). So when Ben says Google is dishonest about search results on some things, I take his word on it. He didn’t come out the gate gunning for anyone in particular, except those who dodged the laws to take advantage of people. Some lawyers do that, you know. The only people I know who have any beef with Ben are the slimy marketers, spammers, and other human filth. So if Google and some others have a beef with Edelman, I tend to place them in the same category as spammers, marketers and other human filth. Especially if they accuse Edelman of bias.

Go get `em, Ben.

Posted in Uncategorized | Tagged , , , | 2 Comments

World Gone Mad

They are crazy. Even here in my own state, good old fly-over country. We are not overrun with Muslim terrorists. The only terrorists we have to worry about receive government paychecks. Granted, there are a few sensible cops out there, but what little trust they build with the community is destroyed by the bad ones. I’m a former LEO; the last person on earth you want to trust is someone wearing a badge. Let them purge their own ranks, then we can talk about trust.

Whatever happened to the notion people are people, and we should attempt to live and let live? Here in America, oppression was born from the Sociology movement, which itself was born among radical English clergymen who tossed their Bibles in the trash. Historically, we refer to the Progressive Movement, but from that comes all the worst evils in US government today.

[T]he educated class’s religious fervor turned to social reform: they were sure that because man is a mere part of evolutionary nature, man could be improved, and that they, the most highly evolved of all, were the improvers…

Margaret Sanger and her Pro-Nazi racist abortion policies? A card-carrying member of the Progressive elite. The Roosevelt presidents and their massive power-grabbing, snotty, prissy middle class materialism? Yeah. In so many words, they both declared themselves the recipients of some divine right to decide for the rest of us what was decent and right, and more than once ordered thugs to murder people who didn’t want to play along.

It’s not the question of whether folks should promote good morals; I do that. It’s the methods. These are godless, Satanic children of Hell using the Devil’s own methods to accomplish their ends. “He will not cry out in the streets… A bent reed He will not tear off; a smoking wick He will not extinguish.” Matthew quotes this regarding Jesus, taking it from Isaiah 42:1-3. The ancient Hebrew symbolism was a man who didn’t come to change politics, particularly by exercising any sort of earthly authority. Ruling was for the goats, not the sheep of His pasture. And where did the goats end up, in Matthew 25? The desire to rule is a moral disqualification for rule. We convince humans to make better choices by teaching it, demonstrating it, by sacrificing life itself if necessary — but our own lives, not theirs.

Posted in sanity | Tagged , , , | 2 Comments

Motives, Objectives, Imperatives

I want you to be free.

There probably isn’t much I can do for you, simply because freedom cannot be a matter of me doing for you. Freedom is you taking hold of the choices we deny ourselves. Most of the time, we don’t realize they are ours to make, or that they are within our reach.

All good theory, but the best way to explain it is to demonstrate it.

My recent two week exploration of RHEL 6 was a demonstration. It’s one of the few things in this world I understand well enough to write at length. I wanted people to realize it was there, and how accessible it could be. I didn’t call it “for the clueless” just to amuse myself and insult others. If you take yourself too seriously, there is nothing I can do to help you. But if you know you don’t have a clue and want one, there it is.

By no means can I transmit 12 years of Linux experience in just a few short lessons. What I can do is ask you to take a closer look at it and maybe think it’s worth a shot, so you can learn your own set of experiences. Don’t think I didn’t learn plenty while doing the research for the series. I’m still working on my own knowledge.

Right now, this blog is running between 50-100+ hits per day. That’s not why I set out to write the series. Most of those readers are nothing at all like me, aside from an interest in the topic of discussion. I’ll bet precious few stay around to get to know as much of me as can be known from a blog. The hit count should begin tapering off quickly. Who knows? Maybe I drove off my few regulars for awhile.

Doesn’t matter. People can only do what moves them. I did it because it moved me, as an expression of my choice to be free. I wrote it because it was my imperative. Freedom is accepting your own imperatives. Whatever results feed back into my consciousness are consequences, not objectives. All I really want to know is if some folks used it to chase their own brand of freedom. It doesn’t even have to be about computers; just some little thing I wrote which made the light come on inside your head, and you found one more hindrance fall away.

Be free.

Posted in sanity | Tagged , | Comments Off on Motives, Objectives, Imperatives

RHEL 6 for the Clueless: More Servers

Because RHEL is essentialy an industrial grade commercial product, you’d have to expect it can run more types of server than most people would ever need.

We covered the Samba server in a previous lesson as the most common need for small or home operations. As long as you have to accommodate Windows clients, Samba is the simplest way to go, since even Linux clients can use it. However, if all you need to worry about is sharing files with other Linux/Unix clients, the NFS (network file system) is really better. It’s not covered in the Deployment Guide, and the only simplified guide I’ve seen is this one. There really isn’t that much to it. Windows can use NFS, and Microsoft offers the software to use it, but they assume you are migrating away from Unix, and will demand some information from you. At that, it only works on the Pro versions of their OS. You could also search for some third party software packages, but it I don’t know whom I would trust for that.

The majority of my computer ministry clients have no use for an FTP server. On top of that, the RHEL Deployment Guide hardly mentions it. However there are already some good, short tutorials on how to get it working. This one is fairly generic, but rather complete. And here’s one which covers the SELinux aspects of configuring your FTP server. RHEL uses the Vsftp (Very Secure FTP) server. The CentOS HOWTO Wiki on Vsftp actually hands it to you with scripts to set it all up. It centers on using a feature called “chroot” — a sort of controlled sandbox which makes it exceedingly difficult for those using your FTP server having any chance of cracking the machine itself. I recommend the TSL script for setup.

Much more popular is the Apache webserver. The Deployment Guide covers it, but in a good bit more detail than you might find useful. Again, some enterprising writers have already given us a head start. This one is short and sweet, covering the bare essentials. Then there is this one which addresses the details of SELinux protections, how to configure for a server which hosts multiple sites, and much more. If you need to enable the secure protocol (https) I really like this one from CentOS Wiki.

But if you are going to go that far, you should consider using the well known LAMP stack (Linux, Apache, MySQL and PHP). It’s almost trivial adding the MySQL server and PHP. What isn’t trivial is the knowledge necessary to use them. Here is a good generic setup tutorial, but be aware a few of the package names may have changed for RHEL 6. However, cnce you get Webmin installed, you are limited only by what you know about webmaster and system administrator tasks in general. It’s the easiest way to go for the clueless, with some documentation, and for more than just the LAMP server itself. However, I recommend you download the Webmin Manual (PDF). It can make a wide range of system administration tasks much simpler, and people are running entire ISPs this way.

Of course, the big thing with RHEL 6 is the kernel-base virtual machine (KVM), the computer within a computer. It requires some rather powerful hardware. Frankly, I can’t imagine needing it for my clients or myself. Still, the Techtopia series starting with section 33, gives you the shortest path, I think, using Windows 7 as the client OS. You can always plow through the Deployment Guide, of course, but it’s harder to follow. It’s written for well-trained technicians with some experience in that sort of heavy duty server work.

One of the most useful things RHEL can do in an organization is serve as the firewalled gateway. This can be easily combined with other tasks on the same machine. Naturally, it requires your RHEL box to have at least two hardware ports, since one becomes the internal trusted interface, and the other an untrusted interface. Then a standard multi-port LAN switch can feed into the RHEL box if you have a significant number of computers. This is well covered in the Deployment Guide, but you probably would find this page a lot simpler. To do anything special requires you understand firewalls and policies. There simply is no shortcut there, however, the defaults configurable from the RHEL GUI firewall manager are pretty good for most uses.

As with the mail server, most of this is pretty hard to test from a home LAN with a broadband connection. If your ISP permits running a server, but can’t offer a static IP address, you should consider connecting through an external DNS service such as OpenDNS, DynDNS, and number of other free services. They keep track of resolving your domain name to whatever IP address you have at the time. It’s pretty rare when you’ll need to run your own DNS service internally, except perhaps a simple name caching. However, even that is becoming almost pointless, as these external free services are quite reliable compared to even the larger broadband ISPs.

The possibilities of RHEL 6 will quickly outrun all but the most obscure server needs.

Posted in Uncategorized | Tagged , , , , | 1 Comment

Keeping RHEL Alive: Hplip Update

In trying to keep RHEL 6 up to date without support, I am sometimes both amazed and disappointed at the way Red Hat keeps some of the SRPMs out of reach.

The RHSA notice presents a minor security warning about the Hplip libraries. But if you attempt to build from the SRPM, you’ll find a dependency almost impossible to fulfill. In order to build Hplip, you need sane-backends-devel. But that one is not normally installed, and if you lose your access to RHN, you’ll have to build it from source. That, in turn has a dependency on gphoto2-devel.

There is no source for that. I scoured the freely accessible repositories in both RHEL (including the Beta sources) and Fedora, and there is nothing close. Remember, a partial requirement is keeping the versions consistent. The version for gphoto2 is 2.4.7-4. The closest you’ll get is the FC12 package, which is 2.4.7-1. Even if you cheat and edit the SPEC file in the SRPM to call itself “-4” it won’t built the devel package. I have no idea why it’s excluded, but it won’t produce. Thus, you end up with something totally orphaned here. Then you end up wondering how the Red Hat developers built it themselves in the first place, except they simply aren’t being honest in releasing all the applicable SRPMs.

The CentOS developers noted this often enough in their developers mailing list. There are times you simply can’t replicate Red Hat’s work because they hold stuff back. I lack their expertise in recreating the missing SRPMs from sources, chasing down the peculiar collection of patches, etc. At any rate, the work-around is simply installing the sane-backends-devel RPM from the Beta repositories, because it’s the same version. But I’m still left without any source for gphoto2. I can get the dependency for it (libgphoto2) but not the item itself.

Posted in computers | Tagged , , | Comments Off on Keeping RHEL Alive: Hplip Update

RHEL 6 for the Clueless: Mail Server

If you are running RHEL, you are already running a mail server. It’s installed by default and setup to run. Of course, it only delivers mail locally, and only from sources within your own machine. Right now, there are no sources, so there is no mail. But the server is running.

The original Unix way of things was to use the mail server as the primary internal message system. RHEL is old fashioned in this respect, though by default, nothing is turned on which sends any messages to the root account. If you want to learn more about what’s going on in your system, install the logwatch package with Yum and you’ll start getting daily email messages to your root account with standard notifications of newly installed packages, who logged in when, and other significant events most system administrators track. You can adjust what sorts of things logwatch tells you about, but the defaults are pretty good.

The problem is, you’d have to figure out how to read that mail. By default the simplest way to do that is to install something called Mutt — as you might expect, the package name is in lower case. Yum will take care of it easily. Then, you could login as root every day and fire up Mutt, and read the logwatch messages. Or, you could tell the mail server to give root’s mail to someone else, such as your own user account. All you have to do is login as root, and:

gedit /etc/aliases

At the very bottom of the file, simply add a line which says:

root: username

The file itself explains the format; use a TAB between the colon and your username. Then close Gedit and run the command newaliases. Then you only have to open a Terminal window every day and run Mutt yourself. Mutt is not user friendly, particularly for folks moving from Windows. I don’t like it either; I use something called Alpine. I’ll give you a hint that any email client you use, including the default Evolution on RHEL, can be set up to read mail directly from the internal mail server.

My habit is to use the commandline environment (AKA the console) for as much as possible — all my email accounts, a lot of Internet surfing, most of my editing, and so forth. If you get tired of Gedit, try nano from the commandline for editing. It’s included in RHEL by default. Most of the keystrokes you learned in Windows tend to work the same, plus the window displays several important commands at the bottom.

Unless you are setting up a commercial grade operation, you really don’t have much chance to play with mail server administration. There was a time when most ISPs and such would tolerate a Linux user running their own mail server from home. That is, you could have your machine fetch mail from your accounts and pass it internally to your mail server. Then you could send mail from your server through the official servers where your accounts resided. Those days are gone. Very few mail servers out there will accept server connections from you, typically because your IP address is listed as non-server territory. They will only talk to your email client, not your server.

If you do have a genuine server connection to the Net, and you need to run a mail server operation, it’s hard for me to rewrite the instructions provided by Red Hat in their Deployment Guide. If you know what a mail server is supposed to do, it’s not that hard to plug in the values for the configuration files.

What I do want to explain is how RHEL lays out this operation. There are three programs you’ll be running in most contexts: Postfix, Dovecot and Procmail. Dovecot is the POP and IMAP server, what allows your users and clients to get their mail from your machine. Incoming mail is caught by Postfix, which passes it to Procmail for sorting. Procmail decides who gets what. You can also have Procmail filter for spam, by plugging in SpamAssassin. You’ll need to tell your mail system the various domains for which mail is accepted and handled, and where it goes. Postfix also handles your outgoing mail. As the system administrator, you would set up all the accounts for your users. Again, the RHEL Deployment Guide is not that hard to follow.

While the current crop of CentOS HOWTOs are somewhat dated, most of the details are still accurate. If you are serious about running a mail server, it’s a good place to start. You may want to consider using their Postfix and Dovecot with SASL for running the now standard secure login features for an organizational mail server.

There are some good tutorials from other sources, though some of them a little dated. One of the simplest, and missing instructions for Procmail, is at the CentOS website. Each of the three programs have their own website with more information than you can absorb: Postfix, Dovecot has a wiki, and Procmail has links at the bottom of their page to various tutorials.

Posted in Uncategorized | Tagged , , , , | 2 Comments

RHEL 6 for the Clueless: Samba Server (Updated)

If you intend using your RHEL machine as a server among Windows machines, one of the first things you should consider is using Samba. This is the Open Source implementation of Windows’ SMB. Samba allows your RHEL box to provide a compatibility layer so a Windows computer on the same network, such as your home LAN, can read portions of the Linux file system natively. It is also the only way I know you can have Linux operate as a print server for Windows sharing. That is, if you have a printer connected to your RHEL box and working, Samba allows you to provide a Windows computer access, provided that Windows box has its own driver for it.

There seems to be no documentation from Red Hat, and Samba itself offers a huge documentation library because there are too many options for any sane person to examine. There are some items you’ll need to prepare before starting: username (so the Windows user can login from their machine), password, and the network IP address on your LAN for the other computer(s), and a shared directory with world write permissions. If a printer is involved, make sure it’s setup to share.

RHEL provides a GUI tool for printer setup. If your printer is connected via USB, it should be recognized immediately if RHEL knows what it is. This is the place to check. There isn’t space here to chase down all the various problems you might encounter, so if it doesn’t pretty much work, and you can’t get it recognized and configured through the Administration menu, you’ll need to engage your favorite search engine using your printer model with the keyword “linux”, or terms “RHEL” and “Fedora” and make the most of it. In the menu system for the printer configuration tool is a place to checkmark some boxes to share the printer.

I’ve found a couple of tutorials on Samba, but neither one had all the right information. After fighting with it a bit, this is what I did to get it working.

Install Samba by logging into a Terminal as root:

yum install samba

Create shared directory; I used /home/shared:

mkdir /home/shared
chmod a+w /home/shared
chcon -t samba_share_t /home/shared

That last line insures the SELinux security system knows to allow outside systems to poke around in that folder. Now anyone using this computer can move files in and out of the folder, as well as the Samba users.

Add a Samba user. This is a different task than simply adding a user account. There is a GUI tool for adding Linux user accounts to the machine for them to use the computer itself. However, Samba users must be handled differently, so that the system forces them to use the Samba server.

useradd -c "Real Name" -d /home/samba-username -s /sbin/nologin samba-username

That’s all one line. As usual, substitute the actual Real Name and samba-username in the command above. Then create the Samba password. Remember what we said about coming up with good passwords:

smbpasswd -a samba-username

It will prompt for the password, which you type in blindly:

New SMB password:
Retype new SMB password:
Added user username.

Edit smbusers:

gedit /etc/samba/smbusers

This will open the default text editor. Scan down the file until you see something like this:

root = administrator admin
nobody = guest pcguest smbguest

Immediately below this, add a line with this format:

username = samba-username

so RHEL recognizes the person logging in from the Winbox by their samba-username. Close this file by saving it, then open a file in the same place: /etc/samba/lmhosts. The first line should show: 127.0.0.1 localhost. Add another line below that: 192.168.1.102 hostname.

That is, the IP address on your network of the Windows box, and it’s hostname in lower case. If you don’t know how to find the IP address on Windows, use these instructions. To get the hostname, try this page from the same site. Save that file.

Then open: /etc/samba/smb.conf. Find the section headed [global]. Change the workgroup name to whatever your Windows computer will be seeking. Default is workgroup in lower case letters. You’ll need to remove the semicolon in front of the next line and provide a proper hostname for the netbios name, which would be the name you gave your RHEL computer during installation, again in lower case. Remove the semicolon from the next line and the IP address numbers from the sample; all we need are the two interfaces lo eth0. Below that is a line with hostsallow as a model. Below that, start a new line with the same indentation:

hosts allow = 127. 192.168.1.

The “127.” is the IP address for everything on your own machine. The other (192.168.1.) is the private LAN network I use for my home router; by leaving off the last section after the dot, it automatically includes every computer with that prefix, which is reserved for LANs.

Go all the way to the bottom of the file and add some lines. I named my shared directory “shared”. Thus, the section heading should be named the same:

[shared]
path = /home/shared
writeable = yes
browseable = yes
read only = No
guest ok = Yes
public = Yes
valid users = username1 username2
create mask = 0666
directory mask = 0777

Now change the firewall to allow Samba to get through. You can use the tool in System > Administration > Firewall. Simply scan down the list to Samba and checkmark the box. Optionally checkmark IPP printer sharing. Then hit “Apply”. Now we start the service manually; it’s actually two services:

/sbin/service smb start
/sbin/service nmb start

Test whether your Windows box can find the server. In Win7 and Vista, that’s via your file manager window. On the left hand side look for the Network icon. Double click to open and the computer should search for other machines. Your RHEL box should eventually show up by it’s hostname. Double click and see if you can login from there. If successful, your shared folder and any printer you’ve permitted will also show.

For XP and Win2K, it’s a similar idea using the file manager. The simplest way is to right-click on “My Computer” and select “Explore” so that the left pane shows the various drives, and should display a network connection to the RHEL server.

If it works and you don’t have to cry for help, you’ll want to make it a normal service always running. System > Administration > Services — find “nmb” and “smb” and click the “Enable” button. From now on, upon boot the system will start the two services automatically.

Posted in Uncategorized | Tagged , , , , | 28 Comments