RHEL for the Clueless: RPM

You probably know everything on your computer is just zeroes and ones, grouped together in eights and sixteens, and so forth. You might know a bunch of folks type out lines of instructions (“code”) for computers which have to be converted into those ones and zeroes, in a process called compiling. You may have heard compiling stuff on Windows requires you to buy expensive software suites to do that sort of stuff. Maybe you know Open Source means the entire process from start to finish is wide open and free, and if you take a notion, you can compile your own software because it’s all part of the package. This is why I recommended you install the Developer Workstation package profile. You can take all those instructions people write and make it into zeroes and ones yourself.

On RHEL, you have the option of going out and finding that code from the sources and learning how to use the common build scripts. I do it all the time. But it’s a whole lot simpler chasing down all the extra piles of code you need if it comes pre-packaged. For RHEL, that means the RPM system. It’s not just a way to add packages someone else built for you, but you can build the packages, because the source is also neatly packaged. We call them source RPMs or SRPMs. Whenever you see a package which ends in the combination “.src.rpm” you have an SRPM.

Depending on what we are trying to build, we can get our SRPMs from several different places. For RHEL, the primary source is the official RHEL 6 workstation repository. Occasionally I also have to check the server repository. These two are updated regularly when something is fixed, so check to get the version with the highest number, which may mean the last in a long string of digits, dots, dashes and underscores. A much wider variety of packages come from the Fedora repositories. If you understand Fedora is the playground development system for the serious RHEL working systems, then it’s no surprise Fedora has more different kinds of stuff. You just have to be aware of which of the many versions of Fedora is closest to your version of RHEL. In this case, RHEL 6 is built largely from FC13, but parts of it appear to come from FC12. At any rate, if you don’t find what you need on the RHEL repositories, your second look should be “FC13 Updates” and “FC13 Everything” in that order. You can find a list of mirrors here simply select the one closest to you. For each one, it’s usually a matter of this layout on the servers:

..../fedora/linux/updates/13/SRPMS/
..../fedora/linux/releases/13/Everything/source/SRPMS/

In the case of CentOS and Scientific Linux, they will have their own mirrors and structure when 6.0 is finally released by each of them. They are built from RHEL 6 SRPMs, and the same FC13 SRPMs should work for things not included in the primary SRPM sets.

Today we are going to grab the package called “freetype,” which is a standard item from RHEL, so go to the Workstation SRPMs and download that package. We can’t install this from the browser, so prepare to do some commandline work. Just as a reminder, in Linux, all commands are case-sensitive. Most commands are in lower case, but there are switches (usually with a dash in front of them) which are both upper and lower case, so you need to pay attention to them.

Open your Terminal and su to root. Type cd so you are working from root’s Home. You can issue the command to install this SRPM from here, as long as you declare on the commandline the exact location of that RPM file (called the “full path”):

rpm -ivh /home/username/Downloads/freetype- [hit TAB]

In this case, we use the “i” switch for a straight install, and the “vh” allows you to watch it work. You can ignore the warnings about who owns the files. When it’s done, if you type ls you should see a folder named rpmbuild. This is where all SRPMs will be installed so we can work on them. There are several sub-folders underneath. We are primarily interested in the SPEC folder, so type:

cd rpmbuild/SPEC

If you ls here you’ll find a single file, freetype.spec. This is the building configuration file. The Freetype library is the run-time reference for the way fonts are rendered on your screen. We are going to change it by adding two features not enabled by default, called “bytecode hinting” and “subpixel rendering”. If you take a quick look at this SPEC file:

less freetype.spec

you’ll see some interesting instructions at the top. That “less” command is equivalent to the Windows file viewer command “more” — less is more. The second line of the file tells you how to add those features. You see we can add a couple of “switches” on the commandline of the build process to make it happen. But it’s not a simple swipe of the mouse because there is some extra verbiage and punctuation. So you can hit “q” to close this viewer and I’ll give it to you below.

The basic command is rpmbuild, with a switch  (-bb) telling it to build the software and create the RPM packages. We’ll stick in the additional switches from inside the SPEC file and finish with telling RPMbuild what it’s working on:

rpmbuild -bb --with bytecode_interpreter --with subpixel_rendering freetype.spec

Hit enter and it should take off and build it, displaying the details on the screen in your Terminal. When it’s finished, the prompt will come back and we have to go find those packages and install them. If you take a moment to look in your Terminal window, you’ll see up just a few lines where it says “Wrote /root/rpmbuild/RPM/i686/freetype….” Each of those packages comes from the same SRPM. That’s the common pattern, and it also tells you where to find the packages. The source is not just the library, but some other stuff, which includes the development libraries. We need the base package and the “devel” package. Now, let’s go there:

cd ../RPMS/i686

That double dot is simply shorthand for “the directory above this one.” We go up one layer, then down two into the place where RPMbuild drops the finished packages, in this case the i686 folder (x86_64 for 64-bit). We need to install them both at the same time. And because we already have a couple of RPMs by the same names installed right now, but crippled versions we want to replace, we’ll need to tell RPM to ignore that. Keep in mind, as you type this rather long command, you only have to type enough to distinguish between files and hit the TAB key for each file. What you see below were the ones I built for this tutorial:

rpm -Uvh --force freetype-2.3.11-6.el6.2.i686.rpm freetype-devel-2.3.11-6.el6.2.i686.rpm

That’s the “rpm” command, with the “U” upgrade switch, and as before, the “vh” switches so you can see what’s happening. Then we add the “force” switch because it won’t do it otherwise. Don’t abuse that option! You seldom have any need for it, but it’s there and it can really mess things up and make your system quit running if you don’t know what you are doing. The command is completed by listing all the packages, each separated by a space. Hit ENTER.

In order to see the effects of this altered font rendering package, we have to restart the display server. That means log out, then log back in, because logging out typically restarts the display server. It should make at least some noticeable difference in how fonts are rendered, mostly by tightening up and sharpening the characters so they aren’t so fat, fuzzy and dark.

Welcome to RPM Land. More extensive instructions can be found starting here.

Posted in Uncategorized | Tagged , , | 1 Comment

No Longer Recommending SOTT

Change is change; it’s not always good.

Recently the Signs of the Times (SOTT) site shifted the focus of their editorial policy. It’s not as if I suspect they’ve been bought off or something. They have the same original editorial biases as before, but the presentation has changed. Previously you could read most of the current postings and find the important but off-beat and spiked stories not available from the mainstream media and avoid their New Age baloney. Not any more. Now you have to wade through it.

I’m quite used to having no single source which serves my weirdo interests. It’s okay. I’m willing to work for it by having to scan down a longer list for things which interest me. I find it no longer worth the effort at SOTT. The whole point of news aggregation is saving your readers time. Now it takes more time than it saves. This is not a matter of hostility, but noting it offers not enough of what I want, and too much of what I must oppose.

End of the line, SOTT; dropping you from my bookmarks. Go your way without me.

Posted in globalism | Tagged , , | Comments Off on No Longer Recommending SOTT

RHEL for the Clueless: Fonts

Linux is capable of superior font display handling. On my hardware, it’s better than any version of Windows, but it’s not turned on in RHEL by default. There are several issues involved.

First, let’s get some better fonts. If you have access to a Windows machine, copy off the font files for your favorites. I’m going to warn you only the older ones work properly, such as Arial, Courier New, Comic Sans, Palatino, Tahoma, Trubuchet, Verdana, etc. You can try, say Consolas, on your machine when we are through fixing, but you may not like it. At any rate, copy the actual font files to a thumb drive and plug it into your Linux computer.

For the sake of simplicity we will copy them to your user account font storage: ~/.fonts — that’s a folder in your Home directory. If it’s not there already, simply create it using the file manager from your Home icon on the desktop. You can use the menus or try the right-click menu. This folder not normally visible unless you go out of your way to find it. That leading period in the folder name tells Linux “hide” it so it won’t get in your way, and the system expects to find it so. The system knows to look in that particular folder when offering you font choices.

Next, in your System menu, select “Appearance” and click the “Fonts” tab. You’ll see some drop-down list buttons where you can change the default fonts in the GNOME interface. The fonts you just copied should be immediately available. Next, notice the “Rendering” section at the bottom. If you have some sort of LCD screen, select that. Otherwise, experiment until you like what you see. Now hit the button marked “Details…”

Most of the time the resolution is correctly set by the display system. Don’t mess with this until you know a lot more about it. Instead, test the various settings below that. Make it look as good as you can, knowing we are only getting started. I use LCD smoothing, full hinting and RGB color balancing. It should get even better in a bit. You’ll notice changes in the entire interface take effect immediately. So far so good for stuff controlled directly by GNOME. But some applications, like Firefox, are not controlled by GNOME. The fonts will still be ugly. It requires a separate fix.

The same system which knows to look for fonts in your “hidden” fonts folder also knows to check for a certain configuration file named .fonts.conf — there’s that leading dot again. If you told your file browser to show hidden files, then you could see if it was there. You aren’t likely to have one yet. The fix is highly involved, and you are several lessons from understanding that if you’ve never used Linux. This is part of the same fix which works on just about every kind of Linux available, and I’m going to hand it to you on a silver platter. Just click this link (see below) and your browser should offer to save the file. If it simply displays it, that’s okay, just use the browser menu to save it with the name I gave it on that website. If you download it, save it that way.

Now, go to your Home file window and click on the Downloads folder. You should find a “fonts.conf” without the leading dot. Chances are what is in there will work just fine for most computers, and will certainly do no harm. It’s nothing more then encoded instructions telling the system to display Firefox and other non-GNOME stuff pretty much the same as GNOME stuff. Simply move it up one level into your Home folder, then change the name to add the leading dot. It should take effect immediately when you do. In case you don’t know already, look at the window pane on the left for an icon with your username. It’s drag-n-drop; drag the file from the list window and drop it onto the icon on the left side. It should move. Then click the up arrow in the icon bar at the top of the window. Find the file again, and right-click, selecting “Rename.” Type the leading dot in front of the name. Hit ENTER and you’re done with this part.

Now, to really get things looking sharp, we have to actually change something in the system by rebuilding the font rendering library. Once again, it’s that issue of Red Hat protecting themselves via an abundance of caution from vague copyright liabilities never tested in court. The threat recedes to near zero for us mere users, so we are going to fix it. That will be our next lesson, because it will serve as the introduction on using the RPMbuild system, which you will certainly need to know if you intend to use RHEL more than few days, or for anything more than the most basic tasks. So even if you think the fonts look fine as they are, you should follow along and learn how to build your own software packages.

fonts.conf (copy and paste what’s in this box)

<?xml version="1.0"?><!DOCTYPE fontconfig SYSTEM "fonts.dtd">
<fontconfig>
 <match target="font" >
  <edit mode="assign" name="antialias" >
   <bool>true</bool>
  </edit>
 </match>
 <match target="font">
  <edit name="autohint" mode="assign">
   <bool>false</bool>
  </edit>
 </match>
 <match target="font" >
  <edit mode="assign" name="hinting" >
   <bool>true</bool>
  </edit>
 </match>
 <match target="font" >
  <edit mode="assign" name="hintstyle" >
   <const>hintfull</const>
  </edit>
 </match>
 <match target="font">
  <edit mode="assign" name="lcdfilter">
   <const>lcdlegacy</const>
  </edit>
 </match>
<match target="font">
  <edit name="rgba" mode="assign">
   <const>rgb</const>
  </edit>
 </match>
</fontconfig>
Posted in Uncategorized | Tagged , , , | 1 Comment

RHEL Series Note: Samba

Once we finish the desktop tutorial series here, we will jump right into the low level server stuff. This evening I got Samba working and my wife’s computer can now browse shared folders and open the files. Also, in order to share my printer with her, it has to go through Samba, and that appears to work, as well. This is the first time I got Samba working on a home network, so we are on our way.

Posted in Uncategorized | Tagged , , , | Comments Off on RHEL Series Note: Samba

RHEL for the Clueless: File Management

There is a world of difference between Windows and Linux in file handling. Your immediate need is to understand the business of permissions. One of the fundamental security advantages in Linux is every file is owned by someone, and the owner gets to decide what happens to those files. Ownership, of course, is limited to those who have an identity on the computer in question.

First, let’s open that Terminal again. When first opened, by default your relative location in the system is your Home directory. So important is this, anytime you issue the command cd without saying specifically where you want to go, you’ll be sent here to the same place, Home. On the Linux commandline, we love our abbreviations. When you are typing things on the commandline, the symbolic reference to your Home is ~/ — that’s a tilde and a forward slash together in that order.

Let’s see what’s there. Type ls (lower-case LS). You get a column list of item names, in different colors. Blue is what marks a directory, which may or may not have anything inside it. You should have at least Desktop and Downloads, and mostly likely some other standard folders such as Documents, Music, Pictures and Videos. Not so different from Windows in that sense. You may not see any files, which show up as black. That is, unless you’ve been playing with the color scheme in the Terminal menu system. But there isn’t much information about the folders and files. Who owns them?

Type “ls” again, but with an added switch, which asks for the full length version of information about each item: ls -l. You should see something like:

drwxr-xr-x. 2 ed ed 4096 Jan 5 08:42 Desktop
drwxr-xr-x. 2 ed ed 4096 Jan 7 14:33 Documents
drwxr-xr-x. 3 ed ed 4096 Jan 9 17:40 Downloads

That first column is all about permissions. I’m not going to duplicate the good work of others who write better than I. Allow me to refer you to this tutorial on Linux Permissions. You’ll need to read it if you don’t understand what we’ve done so far. Go ahead, we’ll be here when you get back. You might want to bookmark the home page of that website if you find yourself lost already in Linux. The author covers a lot of basics in very simple explanations.

For now, I want you to learn how to do this in the GUI. If you click the “Home” icon on your desktop, you get a window reminiscent of the ancient Windows 95 default. If you like that, fine, but it won’t help you learn much about maintaining your own file collection. So in the open window, go to the Edit menu, and select Preferences, the last item. You should see a configuration dialog with many tabs at the top. In the first tab, hit the drop-down box where it says “Icon view” and change it to “List view.” I recommend you checkmark “Show hidden and backup files.” On the Behavior tab, checkmark “Always open in browser windows.” My personal preference is also to select the radio button for single-click, because I like my file browser to act like a web browser; everything is a link which requires only one click. Finally, go to the “List columns” tab and add a checkmark to the box at “Permissions.”

Hit the “Close” button; the choices are automatically saved. Now close the file manager window. Open it again, and the changes should have been applied. Of the far right side of each line you see those permissions again. Right click on any item, folder or file, and click “Properties” at the bottom. Click on the “Permissions” tab and you get a detailed management page for the item in question. You’ll see the labels explaining all that stuff you saw in your Terminal window. Change those permissions and it changes what shows up in the file browser window in that permissions column on the far right. Note: All folders must be marked with the “execute” bit for you, or you can’t see what’s inside.

You’ll discover if you transfer any files from a FAT file system (like thumb drives or memory sticks), NTFS (the current Windows default), or most backup CDs, every file has all the execute bits set. That’s how Linux interprets Windows default file settings. It’s not a big problem in every case, but it does conflict with the Linux defaults. When copying files from those other media into your Home folder or anywhere else on your Linux machine, be aware of this. If the file is not supposed to be an executable script or binary, change those permissions to take away the execute bit (but not on folders). It’s laborious if you have a lot of files, but it’s just one of those things.

Now, about ownership: You’ll notice the files belong to you as your username, listed twice. That’s because there is the user as a person, and you belong to a group by the same name. You may have picked up on that from the tutorial I linked above. The root account can change ownership of any file, but you get to set group membership for any group your user account belongs to.

Linux and Unix folks will gravely warn you about messing around too much while logged in as root. On your system, root owns everything, and can delete the entire system with just a few keystrokes. So we protect our root access with hard passwords and don’t use the root login except when necessary. Never connect to the outside Net as root unless absolutely necessary, as this exposes your machine to someone else using some unknown security hole to masquerade as root on your machine.

In the last lesson, we copied a bunch of codec files into the library file system. Those files are still owned by your user account. It’s a low-level security threat to leave them that way, among other things. You could accidentally delete them from your user account. Suppose you were online and someone managed to use one of those as-yet undiscovered security holes, and grabs control of your system using your user account. They will have only your user account’s permissions to do things. Those files are not protected. As a standard practice, anything which is used by the system should belong to root. Let’s fix that situation.

Open the Terminal and login as root. Then execute this command:

chown -R root:root /usr/lib/codecs/

That’s change ownership, using the -R switch for recursively (diving down into the folder and everything inside it), to make root the owner of all those codec files we moved there.

One final note. We got those files from a standard source in the Linux world. Unless someone packages them for your particular Linux version, that’s the way to get them. Right now, no one makes an RPM for RHEL 6 containing those codecs. If they did, we might be able to download and use that RPM file, and all would be well. But you should avoid adding multiple third-party repositories. ATrpms does things one way, and the others do things differently. If you add other repos which cover the same kind of packages, there will surely be conflicts, and Yum won’t be able to resolve them. Most of those third-party repos don’t work together, at least not very well, because the people who run them won’t, for whatever reason. If you use ATrpms, you might be able to take individual packages from other places, but even that could be dicey. It’s the nature of the beast.

Posted in Uncategorized | Tagged , , | Comments Off on RHEL for the Clueless: File Management

RHEL for the Clueless: Multimedia Capability (Updated)

RHEL (and clones) does not come with very much multimedia capability. It has to do with politics, copyrights, and philosophical debates. Even if we tried to outline all the issues here, chances are quite good you don’t care a whit. You want to play your music and videos, and there is no good reason you shouldn’t. There are plenty of Linux developers willing to join you in seeking to play what Windows can play, and a lot more besides, but Red Hat is being careful and sticking to their commitment to the corporate client base.

About the only thing which already works well is the audio CD player, Rhythmbox. So it’s up to you to connect your RHEL box with all the other Open Source multimedia capability. Some of those Linux developers have made it quite easy. There are several projects to provide all those goodies specifically in a form which hides from you the gory details, and there’s no reason we can’t take advantage of their work.

In the previous lesson we installed a package, software bundled into a format which could be installed as a single item. Specifically, it was an RPM, an abbreviation for “RedHat Package Management.” Other Linux distributions have begun using it over the years since Redhat developers came up with it, so we have to make sure we get the right RPMs. Then we have to make sure they were compiled specifically for the version of Red Hat operating system we are using, because critical parts of the underlying system progress like everything else.

These third party projects do just that, creating their packages to match your specific version of RHEL. Some of them even automate the whole system so you don’t even have to worry about matching the packages with all the various dependency libraries. We call this a “repository” or “repo.” We do have to be careful, though, because the repos vary in quality, and from one release to the next. In my series on RHEL 5, I promoted RPMForge. As long as you are running RHEL (or CentOS or SL) 5.x, it is still one of the best choices. However, for RHEL 6, it seems some of the same old versions of the software from RHEL 5 are being used for 6, and in many cases, that makes a big difference. That is, you may get something stable and reliable, but with reduced functionality. Either way, as of this writing, RPMForge had not quite gotten all their RHEL 6 packages ready.

There are several others. For example, EPEL, which is also not yet up to date on RHEL 6. Honestly, I’ve had some trouble with a few of their packages on RHEL 5. I don’t trust them quite yet. There’s RPMFusion, but they don’t have any RHEL 6 packages yet. And there are more I don’t know about, but the one which seems ready and reliable right now is ATrpms. If you need a full range of media player capability right now, that’s where I would start.

First, you have to learn something about that commandline business. In your Application menu, go down to System Tools and select “Terminal”. It should open a window, probably with a white background and flashing cursor with a commandline prompt. You need to turn this into a root terminal, with administrator credentials. So type in the following command:

su root

and hit ENTER. It should come back waiting for you to enter the root password. Type it blindly, because it won’t show. That’s a standard security measure you should recognize already. You really should learn how to type the root password blindly. Once you have it, hit ENTER and wait for it to change the prompt to something different, indicating you have taken on the identity of root.

Then type this command… wait. It would be a whole lot simpler if you learned to use the Unix mouse paste method (Linux is a type of Unix). Drag your mouse across the text of the following command. You don’t have to do anything else, just drag your mouse across it until the text of the command by itself is highlighted. Don’t worry about the line breaks, your browser will tell the mouse it’s all one line:

rpm --import http://packages.atrpms.net/RPM-GPG-KEY.atrpms

Then move your mouse to the Terminal window where root is logged in. Place the mouse pointer inside the background space of this window, and press the middle mouse button. If you have some ancient two-button mouse, then try to push those two simultaneously (works with trackpads, too). Either way, it should simply paste that text onto the commandline. Hit the enter key and watch it work. Okay, it usually comes back without saying anything. In typical Unix fashion, no news is good news — it executed the command with no errors.

Now, in your browser, I want you go to this page. It’s a list of packages available for RHEL 6, but you need to scan down the alphabetical list for the one labeled “atrpms-repo”. Click the link and download the package. As with BleachBit yesterday, install that package from the download list in Firefox by double-clicking. You’ll need to use your root credentials as always.

Next, go back to your Terminal window and type or copy-n-paste the following command:

yum update

That package installed some instructions for Yum. That’s a cutesy name for yet another part of the package management system. You may recall I mentioned in a previous lesson how, if you didn’t get an update reminder shortly after installing RHEL, we need to wake it up. It’s rare you’ll need to do that, but that command you just entered should do that — scan for updated packages — as well as tell Yum to scan the packages listed at ATrpms, too. If it comes back with a long list of stuff it wants to install, his “y” and wait until it’s finished. If all is working as it should, you’ll see it come back with no error reports, though it may offer a bit of information indicating what it did above that. If you see anything about a warning you need to reboot, do that and come back here to finish this.

Now we need to add that multimedia capability. We need a media player, and some software which allows us to play DVDs and other media formats. We could discuss all day which one is best, but I’m going to tell you, right now the one which works best from ATrpms is called Xine. I tried the famous MPlayer, and it has a bug which won’t let it open properly the GUI controls on some systems. It works, but you can only do it from the commandline. You probably aren’t ready for that yet. (Update: This had been fixed, and Mplayer is probably easier to use, so go with that.) Here is what I want you to run as your next command to get Xine and some other goodies we will learn how to use later, so mouse paste this as one command:

yum install ffmpeg libdvdcss libdvdread libdvdnav libdvdplay lsdvd mplayer xine-ui

Almost certainly Yum will analyze this command and wind up installing a bunch of other stuff, but that’s part of Yum’s job — taking care of dependencies. It will ask you if you are sure, and you’ll need to hit “y” and ENTER. Watch Yum do it’s work, and eventually it should come back without complaint, announcing enthusiastically the job is done. At least, you should try to imagine what you see as enthusiasm, insofar as you can get it on the commandline.

In a few moments, you’ll have some changes in your Applications menu, with Xine showing up under “Sound and Video” (Mplayer shows up as “Movie Player” with the Mplayer icon). I admit it not as slick as Windows Media Player, but it works on more stuff and there is no digital rights management to get in your way. But not yet. We need one more package from yet another source: codecs.

Go here. The good folks at MPlayer HQ in Hungary have developed a collection of codecs designed to handle just about anything Windows can handle, since Xine already handles stuff WMP can’t. On that page, listed near the top, is a selection of links to packages named “all-xxxxxx” with some numbers indicating the date they were bundled together; the format is yyyymmdd. That’s four digits for the year, two for the month, and two for the day of that month. Get the latest date you can find, with the file name ending in “bz2”.

You can’t install this the way you did before, because it’s not an RPM. Rather, when you double-click, you’ll get the Archive Manager, which acts like a lot of zip managers. You’ll see a window open showing the name of what is inside the zipped file, in this case a folder with the name all-xxxxxxx. Click the “Extract” button and it will ask you where you want it, by default right where it is inside another folder. It will show you a view of your “Downloads” directory in your user account Home file system. Just click the “Extract” button on the lower right side. It will work on this for a moment, then give you back the first window. No news is good news. Now you have this big folder of stuff in your Downloads, and only root can put it where it belongs.

This is the toughest part of the whole thing. There are no easy tools for using root credentials with your graphical file manager window. The only way I know to do this in your current situation is using that Terminal window. First, we create the folder for where the codecs go:

mkdir /usr/lib/codecs

(Unix uses forward slashes, the original standard before there was DOS. Microsoft just had to change to backward slashes.)

Then we need to move root down into that collection of codecs you just unzipped. Chances are, root has been working from your user account Home directory. Just to make sure, type the command pwd — an abbreviation for “print working directory.” It should come back with something like: /home/username, though I doubt your use account is named “username”. Just substitute your username. From here on out, just remember to do that. And if you don’t see anything like that, try cd /home/username.

Also, you don’t have to type out every last letter in the name of something in your file system, any more than you would in Windows when using the Command Prompt window. Just type the first few characters, enough to distinguish from everything else there, and hit the TAB key. The system can guess it from there. So type this:

cd Downloads/all-

and hit the TAB key. It should finish it out so you can hit the ENTER key. Now, type the command ls (same as “dir” in DOS) and see a list in several columns, which starts with this:

acelpdec.ax
alf2cd.acm
aslcodec_dshow.dll

You are in the right place. We need to move all these to their proper location, so do this:

mv ./* /usr/lib/codecs/

If you type ls again, you should see nothing listed. If you type ls /usr/lib/codecs you should see that long list of files again. Tada! You now have codecs in the right place. Purists will tell us we left out a few details, but I’m betting for now it will be okay, and Xine will play your stuff. We can fix the nitpicking later. Just open Xine from the menu. If you have a video CD or DVD in the tray, just select what’s appropriate from the control module; you’ll find it in the context menu by right-clicking. If it’s a file on one of your drives you wish to play, it’s in the same context menu. (Mplayer handles all this from the right-click context menu.)

But we aren’t done. You still want Flashplayer? There is an Open Source version and it still stinks. Maybe some day… But right now you will have to get it from the owners, Adobe. Not long ago, Adobe realized how nice it would be if they got competitive before that Open Source flashplayer got useful, so they have created a repo for RHEL. In your browser, go here and select from the drop-down “yum for Linux”. Install this from your download window as before. Then run that “yum update” again and you should see an indicator of adding Adobe. Then run this:

yum search flash

That’s to show you how to ask Yum if it knows about a certain kind of package, either by name or by something in the basic description, such as what the package does or provides. If you had typed the longer “flashplayer” it might not find anything useful. Yum is limited. In this case, you should see a listing which includes this:

flash-plugin.i386 : Adobe Flash Player 10.1

That’s the one you want. But it won’t work to give Yum all that information. Just use this:

yum install flash-plugin

Notice what part of the package title I used. It should install without any hitch. And if you really must have the official Adobe Acrobat Reader, you can get that, too. Ask Yum to search for “pdf” — the file format used by Acrobat — and you’ll get a long list of software names. In fact, you should already have a PDF viewer, called Evince. It’s a lot faster, and doesn’t phone home like Adobe’s Reader. It is also lacking a few fancy features. I don’t like Acrobat, but if you like it and need it, you now have some idea how to get it.

Whatever you choose, you’ll need to restart Firefox for it register the presence of Flashplayer and/or Adobe Reader. Also, remember to log out of your root session in the Terminal, using the simple command exit.

Update: March, 2012 — Recent issue with updating ffmpeg from ATrpms. When you try to update via Yum, or via the Update Manager (that bright orange icon in the notification area), you’ll get an error something like this:

Error: Package: libavcodec53-0.10-54.el6.i686 (atrpms)
Requires: libvpx.so.1()
You could try using --skip-broken to work around the problem
You could try running: rpm -Va --nofiles --nodigest

Here is the simplest and quickest solution; just copy and paste as a single line into any terminal window:

yum update libvpx - --enablerepo=atrpms-testing --disableplugin=*

Yes, this will change one of the core libraries from the upstream provider (RHEL). It shouldn’t break anything, but it could. You be the judge; it’s part of the risk of using any external Yum repo.

Posted in Uncategorized | Tagged , , , | Comments Off on RHEL for the Clueless: Multimedia Capability (Updated)

Excuses for Tyranny (Updated)

Update: Never mind what I wrote. My pitiful attempt pales in comparison to Will Grigg’s masterful handling of this issue.

The only difference between democracy and slavery is with democracy you don’t see the chains.

You have probably heard about Representative Gabrielle Giffords (AZ) being shot by a crazed gunman. From what I’ve read so far, the man was currently seeking military service, but schizophrenic. What you can’t miss is the large number of reports somehow twisting all this into a political commentary. There was no politics involved. The gunman was a lone nut. Had it not been Giffords, it would be someone else he shot.

The idea we have some threat here from anti-government types is a blatant lie. Jared Loughner wanted to be a government employee, had been processed for military recruiting. This guy was pure, 100% government employee material. The military can claim he was rejected, but that’s after the fact. I can assure you from direct experience in uniform the military is full of Jared’s type. The threat is government employees, in that the system which hires them, trains them and arms them enslaves them to psychopaths. With all seriousness I remind you we are ruled by psychopaths. Were the bulk of our government officers tested for psychopathy using the standard diagnostics, they would score very high on the scale. Not because of something inherently wrong in the wiring of their brains — that simply can’t be proven with what we now know. It’s because of the net result of their motives and actions.

What we can prove with what we now know is the people in charge have zero empathy, a complete alienation from human emotional connections. They can know sorrow and frustration, and there are people meaningful to them, but it’s not at all the same thing as with normal humans. Their motives in taking government positions is an intent to force the rest of the world to do things their way. They may have decided to accept the system and its limitations along the path to the goal, but that’s just an intelligent and well-adjusted psychopath. They are still crazy and will most certainly do us harm in the long run.

The real threat is government.

Gabrielle Giffords participates in this awful madness of enslaving vast portions of the human population of this earth. She may not be a psychopath herself, but she enables them by considering their world “normal.” That twisted norm allows schizophrenic people to serve in the military because they have some use to the psychopaths in the military. One kind of nut is more comfortable with other kinds of nuts. Real people with a strong moral inclination are their biggest threat. They’d rather have the random acts of violence from within their own ranks than the purposeful rejection of violence from real people.

The path to peace is too radical. It means people left to their own devices until they cross the line into harming others more than is natural to human activity as a whole. That means we can’t have anything approaching total safety; it means dismissing the obsession with controlling all the factors in your daily existence because you can’t, and shouldn’t try. It means accepting a certain amount of inconvenience from each other, and rejecting a ruling class who won’t tolerate any inconvenience to their rule. It means not being manipulated because we reject any system of control which squelches and squashes the unique individual differences inherent in human character.

This horrific act of murder and injury is purely the fault of government, not some imaginary anti-government conspiracy, or some reputedly wicked philosophical inclination to reject the chains of slavery Congress is determined to put on us. What the propaganda machine intends to do is get peace for themselves while they rape the rest of us.

Posted in sanity | Tagged , , , | Comments Off on Excuses for Tyranny (Updated)

RHEL for the Clueless: Securing Firefox

How secure is “secure”? Nobody can decide for you. What I offer here is the measures I take before browsing the Net. From what I can tell, these measures are effective in that the data-mining and marketing industry has a very poor idea of who and where I am. Try looking yourself up on sites like Spokeo or Zabasearch to get an estimate of your online data trail. While your webbrowser is not the only source, nor even a major source, of such information, it is a part of the bigger effort. The whole idea is to make those data mining sites as inaccurate as possible. And maybe you don’t care, but for those who do, I’d like to suggest a few configuration changes to improve things.

In the Firefox menu, select Edit > Preferences, then go to the Privacy tab. It’s almost blank, but if you hit the first drop-down button, you’ll see the option “Use custom settings for history.” This gives you access to detailed settings otherwise hidden. I set my browsing history at 9, and consider that loose, but convenient. It also speeds up the response of the URL bar when typing directly into it, since it’s not keeping a mile-long list. On the cookies settings, I accept third party cookies because too many sites I use require it for login. Then I select the “keep” policy at “Ask me every time.” That way I can train Firefox to block cookies I don’t want.

The policy of cookie blocking is three levels: (1)accept always, (2) session cookies only (temporary until you close the browser) and (3) blocked. Every time you go to a site, you get to set the policy for each individual source of all the cookies that site tries to give you. It’s work, but eventually your browser learns enough you won’t see the popup control dialog so often. It helps if you are familiar with the major advertising and tracking companies out there, as I am. Also, if it matters to you, come back to this tab from time to time and click the button marked “Show Cookies…” to see what is in your browser’s cookie cache at that time. To see what the policies are regarding each server domain name you’ve encountered — maybe you clicked the wrong button one one when the dialog popped up — try the button marked “Exceptions…” You can reset them by removing the server name, and even re-enter it manually right then if you like.

Now let’s add some extensions which will make your security stronger. In the menu line, click Tools > Add-ons. At the top of the dialog window select “Get Add-ons”. This will take you directly to the repository for Firefox addons. First, type in the search box “flashblock” — the first item it lists should be the Flashblock add-on. This is more than just an annoyance issue of uncontrolled Flash advertising. Flashplayer keeps cookies, too, in a separate place. If you only play the ones you want, there are fewer Flash cookies to deal with. Install it and restart Firefox. You don’t have Flashplayer, yet, but we’ll fix that soon enough.

Next, in similar fashion search down Adblock. Again, it’s not just the annoyance, but the images have cookies buried in them. They sit in your browser’s image cache and can be read by other servers trying to assemble a profile by tracking your habits. Each image will contain an identifying tag which is invisible when the image is displayed. Configure this to connect to the default listing server.

Do this for the Ghostery add-on, too. This actively blocks the most egregious tracking companies. Once installed, it has a wizard to set it up. Among the options, you should enable the active blocking and click “All” for the listing it shows. For fun, I enable the “bubble” option which opens a tiny square listing the servers blocked on each page. The wizard doesn’t show it, but if go back later and click on Ghostery in your Tools > Add-ons dialog, you’ll see a button for setting preferences, which offers more detail. I set the bubble to appear in the lower right-hand corner.

Thus far, these are things you can do on Windows, Mac, and every other operating system for which you can get Firefox. I find the other security add-ons a nuisance to use, because it requires too much specialized knowledge or are simply annoying to use. I really do not like No-Script. Though I actively hate JavaScript in the first place, too many sites are simply inaccessible unless you happen to select the correct combination of scripts to allow. It’s more control than I want or need.

Then there is the threat from “evercookies” — the cookies buried in some seven places in your system and can be regenerated each time you go online. In Windows land, you can install an add-on called “Click & Clean” and configure it to run CCleaner (from Piriform) every time the browser closes. CCleaner is quite intelligent about your cookies and keeps the ones you really have to have, and offers you a chance to change the default settings on them. The closest thing to that for Linux is BleachBit, which is Open Source and even has a Windows version. It’s not fully developed yet, so it may eventually offer features competitive with CCleaner. For now, it’s pretty darn good at eating evercookies.

Chase the link on that page for Linux, then notice they make a package for quite a few Linux distributions. There is currently no RHEL 6, but if there were, it would work fine with CentOS and Scientific Linux 6. Instead, we have to keep in mind: RHEL is basically built from the base of Fedora 13 (FC13). Remember that, and for now, download the Bleachbit package for Fedora 13.

Keep that download tool window open. You can install it from there. Just double click on the name once it has finished downloading. RHEL will pop up a dialog about installing it with the package manager. Once you say “yes” and give your root password, it should find the dependencies automatically, in this case, something called “python-simplejson”. If not, we’ll have to work on that later. Right now, the point is this process is automated enough you shouldn’t have to struggle with knowing too much detail.

Once it’s installed, you can find Bleachbit in the menu: Applications > System Tools. Open the application and take a look at the check boxes for different applications it knows how to clean. For Firefox, I recommend you check only Cache, DOM Storage, Session restore, and Vacuum. Then you’ll need to find where Flash is listed and click both
items, Cache and Cookies. These are the places evercookies hide. I run it at the end of every day, to finish the process of what we accomplished in the other steps taken above.

That’s about as much as we can do without some extended training on paranoid surfing habits. Your Firefox is now pretty secure from the worst of the online tracking measures.

By the way, I’ve not found any spyware or viruses online which affect Linux, particularly Red Hat. There are several reasons, the main one being no one writes malware for Linux. It isn’t practical, though we could debate why. There is also this thing called SELinux, a set of measures developed by NSA so they could secure government Linux servers. In RHEL 5, it caused some trouble, and I always recommended folks disable it. But it’s come quite a long way since then, and we will be keeping it for RHEL 6. Part of what it does is prevent harmful changes to the system. Also, RHEL has a default firewall which is pretty tight. Given there are currently precious few real online security threats to Linux computers compared to Windows, what you have right now is about as secure as it gets and is still reasonably usable on the Internet.

Posted in computers | Tagged , , , | 3 Comments

RHEL 6 for the Clueless: Initial Configuration of the Desktop

Orient yourself to the desktop. The main menu system is in the upper left-hand corner. In the upper right is the notification area (“Systray”). On the lower toolbar, the left is where the open windows are listed, and the lower right is an iconic representation of multiple desktops with your desktop “trashcan.”

Windows does have a way to create multiple virtual desktops, but it’s not simple and many say it’s pretty cranky and unstable. I see this as a serious hindrance, because I’m often working with six or eight application windows open, and that’s too many for one desktop. In Linux, multiple desktops are the default. Right click on that display and you’ll see an option to configure preferences. Select that and you’ll see you can have even more desktops, and can configure them to display stacked in rows. Unless you make that bottom toolbar wider, it usually works best to keep them in a single horizontal row. But get used to the idea of having multiple desktops, because it allows you to organize the way you use Linux to get work done, by grouping open windows according to your work pattern on different desktops. To switch between the windows simply click on the miniature display at the lower right for the desktop you want, noticing as you do the open windows on each are thumb-nailed.

You make the toolbars wider by right-clicking on any blank space and select “Properties” to see the options. In the second tab, you can change the colors or even use a background graphic. You can also elect to add other nifty applets to the toolbars, if you look around in the context menu system. The GNOME desktop is loaded with similar features. Play around and get to know things. Setting more of the features at once comes by clicking the “System” menu, then “Preferences” followed by “Appearance”. You can change the window frame style, the color scheme, and the fonts. We’ll do more with fonts — a whole lot with fonts — later. You can change the wallpaper on your desktop by right-clicking on the wallpaper itself.

The context menu is the same idea as in Windows. For example, I prefer the clock in 24-hour mode, so I right-click on the time display and set the properties. You can get a reasonable weather report right next to your date and time display, once you tell the applet where you want the report sited. Explore; you’ll find it. You can also find the screensaver and power usage settings under the System > Preferences menu. Further, check the item marked “Sounds” — if you like audible cues coming from the interface, you’ll need to enable them.

One of the first things you need to watch for is a bright orange icon up in that notification area, looking like an explosion. That’s the update notification. It will require you to use the root password because it means changing the system. Click on it, read and follow the instructions. Let it do what it wants to do. If it lists an update using the word “kernel” you’ll have to reboot. This was actually one of the first updates after Red Hat released this version, so if you don’t see that notification within the first fifteen minutes, we’ll need to take action later to wake it up. It’s rare when you install any variant of Red Hat something or other without updates already waiting.

When you first install RHEL, it’s pretty light on desktop applications. They can be added easily enough, once you know what sort of things you find missing, and what RHEL calls them. Click on the “System” menu, then “Administration” and find at the top “Add/remove software.” You’ll have to use your root password again, but it should open a window and display what’s available. You may find the logic behind the layout a little hard at first, but you’ll get used to it.

In Linux generally, whoever supplies the operating system typically offers a wide array of software for it. For example, rare is the distribution of Linux which doesn’t have OpenOffice (or one of the variants, LibreOffice and Go-OO). RHEL 6 and clones call it OpenOffice, and it’s the latest, version 3.2.1 (at this writing). It’s not installed under the Software Development Workstation profile, but you can probably find it in the software installer utility and add it. The system automatically takes care of matching up the dependencies. Because it’s such a large package, it will take awhile.

Also, look for something called “alacarte” — that’s the package you need so you can edit the menus. We’ll need that later. Tomorrow we’ll secure Firefox, the one thing most people want to use first.

Posted in Uncategorized | Tagged , , | Comments Off on RHEL 6 for the Clueless: Initial Configuration of the Desktop

RHEL 6 for the Clueless: Installation

Please get a copy of the Installation Guide from this page; I recommend you keep a copy of the PDF version. Scan through it, because the visuals will help you understand what to expect.

Now, drop the DVD into the player and reboot.

The first thing you may encounter is display troubles. Some Intel chipsets cause the installer to freeze. If the entire screen goes black and stays that way, then try again. Reboot from the DVD and at the first screen which displays, select “Install with basic video driver.” This should get you past that well known problem. You’ll get a very primitive text-mode display for the next few steps, but at some point, if RHEL can use the graphics chips at all, it should give you a graphical display of some sort later.

The next issue is a very long pause while RHEL checks the hard drives available, as well as the networking environment. Depending on the circumstances, the installer will pause for an awfully long time, with the message about initializing the hardware. Be patient. As long as the screen is not simply blank, it’s okay.

The next step is the DVD media test. Run it the first time you use that particular DVD. RHEL is running a check to make sure it can read the entire disk. If you use the same disk again on another machine, it shouldn’t be necessary to scan it again, and you hit the tab key, highlight the word “skip” and hit enter. Either way, when it asks if you want to check another, select “continue” because we don’t have another.

This is where the installer’s hardware detector, called Anaconda, tries to pull up a graphical display if it hasn’t already. As with Windows, the “display” includes keyboard and mouse. Make sure you select the proper keyboard layout and default language. Then, it will check the hard drives again. RHEL will ask you if you have any specialized drives, which is highly unlikely. Just select “Basic storage device.” Sometimes RHEL will think it has found something odd and will throw up a warning about reinitializing the drive. There’s nothing you can do, really, so let it go ahead and do so. Then select “fresh install.”

Next is some networking configuration. Unless you have a LAN with some internal domain name, simply give your computer a name meaningful to you, a single word using all lower case letters. Unless you connect to the Internet via dialup, click that button for “Configure Network.” It will show you what RHEL has found possible so far. The main point here is to put a checkmark in the box marked “Connect Automatically.” This way you won’t struggle to configure it later, wondering why it’s not connecting. If you are limited to dialup, you cannot configure that here.

Select your timezone; the list is alphabetical by well known cities in your timezone. Here in the US, that’s choices like New York (Eastern Time), Chicago (Central Time), Denver (Mountain Time) or Los Angeles (Pacific Time). For the rest, just hunt around until you see something close to you. Unless you know your computer’s internal clock is set to UTC (Greenwich Mean Time), uncheck the box.

Next is where you enter your root password we discussed in the previous lesson. At some point later you will create your user account. Two or more letters for the username is fine, but really long names can be hard to type, so keep it simple.

Then we come to drive selection. If you have more than one hard drive in your computer, this can be pretty complicated. All the more so if they aren’t connect via the same bus. Some computers, like mine, can run both the older PATA drives with the flat wide gray cable, and SATA drives with the slender cable. Most operating systems will default to booting from the PATA drives, which is fine for the most part. You get to select which drives will be installed and which should be simply mounted to preserve the data. If anything is going to go wrong, this is most likely where it will be. It works best if all you have is a single drive large enough to run Linux, or the drives are of the same type. Again, I highly recommend you devote all the drive space to RHEL. Dual booting is dicey for Linux newbies, and RHEL doesn’t make it simple. But RHEL can figure out how to configure and use the drives just fine by itself if you don’t complicate things. Once you make up your mind, it will format immediately.

When RHEL asks you to select an installation profile, I am going to recommend you choose the “Development Workstation” — that’s Desktop plus the means to compile software. If you don’t have at least 80GB, your system may be too small for anything but the basic Desktop profile. Otherwise, we will need to build some packages soon, a lot of them if you have special needs. We’ll cover that later. RHEL 6 comes rather stripped down, even when you install the full set of development libraries, and you will inevitably build some libraries before you build the packages which rely on them. Once you finish choosing your profile, RHEL will write the packages to the hard drive. Take a break, because this won’t be quick at some 1400+ packages.

If all goes well, the installer will eject the DVD tray and wait for you to acknowledge the need to reboot. Shortly you will see a nice boot screen animation, then the welcome screen with some notes you should read. Next is the Linux equivalent of the “click-wrap” license. You can read it, but it simply declares the software could not possibly have a warranty, and if you play with any of the source code and make changes, you have to share it back with the community.

For users of the official RHEL release, you can enter your login credentials here, and connect to the Red Hat Network (RHN) for updates and so forth. Both CentOS and Scientific Linux (SL) skip that. Eventually you will have a chance to login to your user account.

Welcome to Linux.

Posted in Uncategorized | Tagged , , | 1 Comment