Public

Viewable by everyone

How to edit your firewall in Web-Kickstart

A question commonly asked, how does one best edit /etc/sysconfig/iptables during a Web-Kickstart %post?

You could include the entire file in the %post section of your kickstart.  However, what about the default ports added for AFS, or another use file that may wish to slightly alter the host's firewall?

My friends, sed is the answer.  The RHEL or Realm Linux 5 firewalls include a 'RH-Firewall-1-INPUT' chain where the Red Hat customizations live, so lets edit that:

ISO blog maintaince on Sept 19 (talk like a pirate day)

Tagged:

Tomorrow is International Talk like a Pirate day

I have some content filters in place on the ISO blog that I will be testing in honor of this most sacred and special of days.  Please don't page anyone to report problems with our site tomorrow, it's all part of a scheduled, planned test.

 

Requesting a cert for multiple host names (clustering/aliasing)

Tagged:

How to generate a certificate request with multiple common names

Include multiple CN's as the subject, these will be encoded as X509v3 Subject Alternative Names.

Here's an example from the nagios project, with a total of five common names, the service name nagios.ncsu.edu and the names of each of the cluster nodes.

Fedoit - LAMP packages for RHEL

Too Long; Didn't Read Summary

  • skip to The Repository section below, and follow those instructions to
  • install the fedoit.repo config, and
  • the fedora-epel.repo config
  • then run 'yum update'

Purpose

Internal OIT Active Directory organization planning begun

Yesterday Kevin and I met with Danny and Harry and discussed how to address the proliferation of OU admins in the WolfTech domain from within OIT.  We now have 11 OIT OUs,  (OIT-AC, OIT-ComTech-CMS, OIT-OCC, ISO_PROV,ISO_SHS,ISO_RnD, TSS_CS, TSS_LSS, TSS-DS, TSS-SC not to mention ITD-DSP), which is causing problems because being an OU admin in WolfTech implies a level of communication with the rest of the admin community that simply isn't present in most cases.

license02 software firewall adjusted for flexLM monitoring

FYI, I've adjusted the software firewall on license02 so that the new Nagii can monitor it properly.

Tooltips added to ISO blog

Tagged:

Folks,

I added a drupal module, JTooltips, to the ISO blog.  I'm trying to make our site "richer" without adding a lot of work to content creation.  It shouldn't impact access, just AJAX things up a bit, but if people hate it, it's easy enough to turn off.

John

WolfTech AD configuration

The wolfech.ad.ncsu.edu is the domain used by all groups on campus,

These documents provide information about how OIT is using WolfTech

Access group "OIT-ISO-Tech" created in QIP

In order to reduce duplicate calls for ComTech, improve our security practices, and generally speed up request processing for QIP access, ComTech has created a QIP role named "oit-iso-tech"

This role provides access to QIP objects, and members can easily be added or removed from the role.  The initial membership of this role will be the staff in ISO-PROV and ISO-SHS (those that do production QIP work in ISO)

Testing plotters for proper charging

To confirm the proper operation of a plotter, both for function and accounting, we've created a test document that measures 12" x 1" Download the .pdf to test printing

In fhe following recepies, replace plotter with the name of the specific plotter you're attempting to test.

On a linux/unix computer from the command prompt