Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

Friday, July 26, 2019

How to set up keyword block in Exim on Debian

Exim can be configured to block emails containing key words, as a method to fight spam. Obviously this is not a comprehensive solution, but can assist in stopping persistent spammers and decreasing the load on SpamAssassin processing when running in parallel.

These instructions are for Debian 8 Jessie, but should apply similarly to Stretch(9) and Buster(10), which use the Exim split configuration.

Edit the config template file: /etc/exim4/exim4.conf.template

We are using the DATA access list (ACL) so scroll down to the section:
### acl/40_exim4-config_check_data
#################################
There may be a number of existing rules in this section, we'll insert our rules after this entry:
# require that there is a verifiable sender address in at least
# one of the "Sender:", "Reply-To:", or "From:" header lines.
.ifdef CHECK_DATA_VERIFY_HEADER_SENDER
deny
  message = No verifiable sender address in message headers
  !acl = acl_local_deny_exceptions
  !verify = header_sender
.endif
 Insert the following text:
# Deny keywords using regex before using Spamassassin:
# Ref: https://www.exim.org/exim-html-current/doc/html/spec_html/ch-content_scanning_at_acl_time.html
  deny
    message = Message rejected as spam or Unroutable address
    regex = Keyword1|Keyword2|Keyword3|...

Change keywords to match words you would like to block. Note this is a case sensitive, regex expression - customise the regex line as required. The message is logged and also sent back to the offending sender.

Update the Exim configution:
update-exim4.conf
Restart the Exim service:
service exim4 restart
Send a test email containing one of the keywords to test.

Monday, May 20, 2019

Upgrading Macbook to High Sierra

Trying to upgrade a Macbook Pro 7.1 (mid-2010) from Sierra to High Sierra failed with several cryptic error messages. This laptop had been upgraded with a Crucial SSD and non-Apple RAM modules, and is configured to dual-boot Linux with rEFInd boot loader.

TLDR: The EFI system boot partition (ESP) should be of type EF (aka 0xEF, EF00), not 07 (Fat).

We recieved the following errors:

macOS could not be installed on your computer
The installer resources were not found
...
You may not install this volume because the computer is missing a firmware partition
...

Somewhere along the line after Bootcamp was initiated, maybe when the Hybrid MBR was altered with gdisk, or partitions adjusted using Gparted, the partition type for the EFI boot partition was changed from type EFI system (EF) to Fat (07).  The format for EF and 07 types is the same, EF is used to identify it specifically as the EFI partition.  Note: this partition is not required to be of type HFS+ as claimed on some sites.

If you have an old High Sierra Upgrade installer from an old previous attempt it may also help to Trash that installer and re-download from the App Store so that you get the updated messages.

The final partition tables on this Macbook are something like:
Hybrid MBR:
 EE: 1 -> 2148 (Protective MBR indicator)
  (128MB space)
 EF: 2149 -> ... (EFI partition, 200MB)
  (128MB space)
 AF: ... -> ... (macOS, 120GB)
  (128MB space)
 83: ... -> ... (Linux, 80GB)

GPT:
 EE
  (128MB space)
 EF (EFI Boot)
  (128MB space)
 AF (macOS)
  (128MB space)
 AF (Recovery 10.11)
 AF (Recovery 10.12)
 83 (Ubuntu)
 83 (Debian)
 82 (Linux swap)
 07 (Fat32 Shared Data)

(*128MB spaces between partitions is an Apple recommendation)

Thursday, April 21, 2016

Macbook Pro with Nvidia 320M black screen after sleeping

After a recent update some time around March 2016, a Macbook Pro with Nvidia 320M GPU running Ubuntu 15.10 would stop waking from sleep - the keyboard would light up but the screen remained off.

It is running Linux 4.2.0-35-generic with Nvidia 340.96 binary driver installed.  Trying to modprobe the nvidia module produces the error:

modprobe: ERROR: ../libkmod/libkmod-module.c:816 kmod_module_insert_module() could not find module by name='nvidia_340'
modprobe: ERROR: could not insert 'nvidia_340': Function not implemented
Trying earlier recent kernel & nvidia versions did not yield any success.

The Workaround

Install gcc-4.9 and adjust links to use 4.9 versions for:
/usr/bin/gcc
/usr/bin/gpp 
Ref:
https://devtalk.nvidia.com/default/topic/902950/linux/-solved-faulty-340-9x-drivers-with-kernels-4-2-x-and-4-3-x/



Monday, October 26, 2015

Configure Exim on Debian Wheezy

apt-get install exim4

To support recent IOS devices you need to generate a 2048-bit SSL certificate.

Add TCP port 587 to the listening ports by editing /etc/default/exim4.

To support local account authentication for SMTP over SSL submission port 587 uncomment out the sslauthd section, ref: https://wiki.debian.org/Exim%C2%A0

Exim defaults to IPv6 before IPv4. To ensure you can send mail to Gmail accounts and other systems review Google's identification guidelines: https://support.google.com/mail/answer/81126?p=ipv6_authentication_error&rd=1#authentication

To disable IPv6:
nano /etc/exim4/exim4.conf.template
   disable_ipv6 = true
update-exim4.conf
/etc/init.d/exim4 restart
Alternatively, you can disable just IPv6 DNS by only using the IPv4 DNS:
    dns_ipv4_lookup = *

If receiving email from the Internet, greylisting is a fairly effective anti-spam technique. Install greylistd and adjust the RetryMin to 60 (to minimise delays) and use greylistd-setup-exim4 to change the netmask to 16 to minimize issues with mail from large organisations such as Google, Yahoo and ISP's who use multiple servers for sending.

To use SpamAssassin with Exim, the easiest way is to install exim4-daemon-heavy and spamassassin.  The daemon-heavy package is required because it provides the exiscan-acl feature which allows the data content to be scanned during receival. Copy the applicable block from here into exim4.conf.template: https://wiki.bitlair.nl/Pages/Projects/Mailserver_with_Debian,_Exim,_spamassassin,_greylistd,_DKIM,_SRS,_SPF,_DMARC,_forwarding,_LDAP,_dovecot,_LMTP,_disk_crypto#Exim_spamd_integration

If setting up a Backup MX, you will probably want to create a file containing a list of email addresses to accept mail for since they are not local users. Be aware there is a bug in the exim4.conf.template if you use CHECK_RCPT_LOCAL_ACL_FILE because update-exim.conf will insist you use a ACL name in the file, but that will cause the acl_check_rcpt to return an implicit deny, stopping all incoming emails since it no longer reaches the accept that is at the end of that ACL. Just add the deny line into the template near that section. E.g:
deny
 message That user is not in my list.
 !recipients = /etc/exim4/recipients_whitelist





Sunday, October 25, 2015

Run your own DynDNS server on Debian Linux

This outline assumes you own your own domain and manage the DNS servers running Debian Wheezy or Jessie with:

  • bind9 for DNS
  • lighttp for webserver
  • php5
apt-get install bind9
 - configure your zone.

apt-get install lighttp php5-cgi

Configure SSL:
 lighty-enable-mod ssl
 openssl ...


Configure authentication:
 lighty-enable-mod auth
 echo username:realm:`md5sum password | cut -b -32` >> /etc/lighttpd/.htpasswd/htdigest.user
Enable PHP:
 lighty-enable-mod fastcgi
 lighty-enable-mod fastcgi-php

Configure Virtual Hosting:
 lighty-enable-mod simple-vhost
 mkdir -p /srv/yourdomain.com/htdocs/update

Copy nsupdate.php from:
 https://github.com/chip-rosenthal/web-nsupdate

Modify the nsupdate.php:
 nsupdate -l

Allow www-data to read the session key to perform updates:
 chgrp www-data /var/run/named/session.key
 chmod g+r /var/run/named/session.key


Friday, August 7, 2015

Installing Horde on Debian Jessie

Starting with base system installed.
Install the Email server (MTA):
We need a working mail system, here we use sendmail with dovecot providing IMAP:
 apt-get install sendmail

Configure domain & SMTP settings:
 nano /etc/mail/local-host-names
   mydomain.com
 nano /etc/sendmail.mc
   MASQUERADE_DOMAIN(mydomain.com)
 make -C /etc/mail
 /etc/init.d/sendmail reload

Install an IMAP provider:
 apt-get install dovecot-imapd
Allow plaintext authentication temporarily (or configure TLS certificate?):
 nano /etc/mail/...
Test a local user authentication:
 telnet 143
 a login
 b select inbox

Install the web server:
 apt-get install apache2

Install the database server:
There are no instructions or guides explaining how to use sqlite, so we will use postgresql since it has fewer dependencies than mysql. We need to create a user and a blank database that will be used by Horde.
 apt-get install postgresql
  su - postgres
  psql
  ALTER USER horde PASSWORD 'new-password';
  CREATE horde
  \q
Test the new postgresql user:
psql -U horde -W 
Install Horde:
 apt-get install php-horde-webmail
 apt-get install php5-postgres
 webmail-install
 cd /etc/horde/imp
 cp backends.php backends.local.php
 nano backends.local.php
  (remove unnecessary lines)
  (change the imap 'secure' setting from 'tls' to 'no security')
 /etc/init.d/apache2 restart

Try to log in via web interface, using a local user account:
 http://server/horde/

Create an Administrator:
 ???
*Debian php-horde includes a script at /usr/share/php/data/horde/scripts/sql
that sets an Administrator user, but it's use is not documented.

Try to access the admin site:
 http://server/horde/admin/config

Enable SMTP
Set up the receive domain:
 nano /etc/mail/local-host-names
   mydomain.com

Set up the email address aliases:
 nano /etc/mail/aliases
  aliasname: username

Enable SMTP daemon to listen on all IP addresses:
 nano /etc/mail/sendmail.mc
   DAEMON_OPTIONS(`Family=inet,  Name=MTA-v4, Port=smtp, Addr=0.0.0.0')dnl
 /etc/init.d/sendmail restart

Saturday, July 11, 2015

CD-ROM won't mount, I/O error dev sr0 sector

Some CD's I have burnt myself do not mount in Sabayon Linux. dmesg shows the following errors:
end_request: I/O error, dev sr0, sector nnnnnnn
Buffer I/O error on device sr0, logical block nnnnnnn

 Specifying the type (iso9660) and uid & gid allows the CD's to mount:
sudo mount -t iso9660 /dev/sr0 /media/cd -o uid=`id -u`,gid=`id -g`

Not sure if this is a result of the media (Imation) or Linux/Windows burning - suspect it is the Gnome Disk Utility - Disk Image Writer.

Friday, June 5, 2015

Plymouth splash not correct in Sabayon

After a Sabayon 13 update in May 2015, new artwork is locked in the initrd file system.  Dracut builds of the initramfs kernal image file system are not used by the system.

To repair Plymouth functionality:

  • Remove dracut
  • Install updated gcc package
  • Install genkernel-next
  • Set the preferred theme in /etc/plymouth/plymouth.conf
  • Backup the current initramfs file
  • Run genkernel initramfs
  • Reboot

Saturday, May 30, 2015

xdg-su not decorated with theme

LXDE on OpenSuse 13.2 uses xdg-su ass the GUI frontend to run applications using sudo. If it can't load gnomesu or kdesu then it presents a bland undecorated xterm window. This can be neatened by simply installing libgnomesu which is small with only 1 dependancy (it doesn't need a full gnome desktop!).

Install Screengrab for screenshots on OpenSuse

LXDE doesn't have a default screenshot grabber. Here's how to install Screengrab from source on OpenSuse 13.2:

Download the source code from:
  • http://screengrab.doomer.org/download/
Install dependencies to make the binaries:
  • libqt4-devel
  • gcc
  • gcc-c++
  • cmake
 Compile and install:
  • cd ~/Downloads/Source/screengrab*
  • mkdir build
  • cd build
  • cmake ../
  • make
  • sudo make install
The binaries are installed to /usr/local. 
A bug puts the libraries in the wrong location, we need to correct it:
  • sudo mv /screengrab /usr/local/
The source package does not create a start menu shortcut, we need to create it manually:
  •  leafpad ~/.local/share/applications/screengrab.desktop
[Desktop Entry]
Name=Screengrab
Comment=Capture screenshots
GenericName=Screengrab
Exec=screengrab
Icon=screengrab
Terminal=false
StartupNotify=true
Type=Application
Categories=Graphics;


Enjoy!

Saturday, April 25, 2015

Remember screen brightness running Linux on MacBook

Running Sabayon Linux, with systemd, on a MacBook, the LCD backlight always resets to maximum brightness after reboot. This is an annoyance as it becomes necessary to adjust the brightness every time it is necessary to reboot the laptop.

To get the system to remember the brightness setting:
  1. Create a script that can save or restore the setting when called with a parameter.
  2. Create a (systemd) service that calls the script to save the setting on shutdown and restore the setting on startup.
Script: /usr/local/bin/my-settings.sh
#!/bin/sh
# Saves and restores settings for LCD and keyboard backlights.
if [ -z $1 ]; then
    echo "Usage: my-settings.sh [save|restore]"
fi
# Set variables:
export LCD_BRIGHTNESS="/sys/devices/virtual/backlight/apple_backlight/brightness"

# Save setting:
case $1 in
 "save")
    echo Saving settings...
    # if the settings folder does not exist, create it
    if [ ! -e /etc/my-settings ]; then
     mkdir /etc/my-settings
    fi
    # if the LCD_BRIGHTNESS file exists, then save a copy:
    if [ -e $LCD_BRIGHTNESS ]; then
     cat $LCD_BRIGHTNESS > /etc/my-settings/lcd
    fi
    ;;

 "restore")
    # if saved setting exists, if LCD_BRIGHTNESS exists, echo the contents into the system device:
    if [ -e /etc/my-settings/lcd ]; then
     if [ -e $LCD_BRIGHTNESS ]; then
      cat /etc/my-settings/lcd > $LCD_BRIGHTNESS
     fi
    fi
    ;;
esac

===============

Systemd service: /usr/lib/systemd/system/my-settings.service:

[Unit]
Description=Load/Save Keyboard & LCD backlight settings

[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c "/usr/local/bin/my-settings.sh restore"
ExecStop=/bin/sh -c "/usr/local/bin/my-settings.sh save"

[Install]
WantedBy=multi-user.target

================

Enable the script and service:
chmod +x /usr/local/bin/my-settings.sh
systemctl enable my-settings.service
systemctl start my-settings


Sunday, December 28, 2014

Monitor fans on HP Proliant ML150 G3 running Debian Lenny Linux

(This blog is in reference to a Debian Lenny AMD64 system)
hp-health is the package that is supposed to provide access to the fan status on HP Proliant servers.  It is not easy to install hp-health on Debian Lenny.  The ISO can be located by searching the HP website.

On my system the existence of 2 files for UPS monitoring software Winpower causes ldconfig error messages:
  • /usr/lib/libjspTru64Alpha.so
  • /usr/lib/libjspAixPpc.so
 - you can try to temporarily move the files during installation/removal of hp-health, but this didn't help due to the following errors.

Having VMware Server 2 installed confuses the hp-health init script (/etc/init.d/hp-health), which is designed to have different behaviour for ESX servers.  Applying an exit workaround in the procedure causes the script to appear to behave correctly, but the daemon fails to start.

Uninstallation of hp-health is also fraught with difficulty. It is necessary to alter the exit code on the init script just to get the script to continue with removal.  The script will fail to remove /opt/hp/hp-health (and will attempt to remove /opt !).  If you need to manually change the installation status you will need to edit /var/lib/dpkg/status to remove the hp-health section.


After doing all the work above it was found that ipmitool could easily be installed:
apt-get install ipmitool
modprobe ipmi_msghandler
modprobe ipmi_devintf
modprobe ipmi_si
 And the fan RPM's are shown with:
ipmitool sdr type fan
(it takes a few seconds to probe).

Sunday, August 3, 2014

GParted does not start in LXQt

Symptom: Clicking on GParted launcher has no effect. Log /var/log/messages shows:
The value for environment variable TERM contains suscipious content ...
The cause was having set the TERM variable using LXQt Session Settings, Default Applications, Terminal Emulation to /usr/bin/lxterm.  Changing back to xterm and logging out-in fixed the issue.

Sunday, June 15, 2014

Compiling a specific commit from Git

cd /usr/local/src
git clone [ProjectX]
cd [ProjectX]
git checkout [commit checksum from Github]

mkdir build
cd build
cmake ..
make
sudo make install


To return to the master version:
...
git checkout master
...

Sunday, May 25, 2014

Install LXQt on Sabayon 14

This is a quick guide to installing LXQt desktop (current version LXQt 0.7.0) on Gentoo based Sabayon Linux (current release 14.06).


Firstly, remove razor-qt to avoid file collisions.

Use Layman to add the Qt overlay:
layman -a qt
Use Emerge to attempt to install lxqt-meta:
emerge -av lxqt-base/lxqt-meta
If it fails copy the text below regarding keywords, and paste into
/etc/portage/package.accept_keywords
Attempt to install again:
emerge -av lxqt-base/lxqt-meta
If it fails copy the text below warning the about unmask, paste into
/etc/portage/portage.unmask/99-lxqt.package.unmask
Attempt to install again:
emerge -av lxqt-base/lxqt-meta
If it fails on lxqt-panel download from source and manually compile and install:

 mkdir /usr/src/lxqt-panel
 cd /usr/src/lxqt-panel 
  wget http://lxqt.org/downloads/lxqt/0.7.0/lxqt-panel-0.7.0.tar.gz
 tar xvf lxqt-panel-0.7.0.tar.gz
 cd lxqt-panel
 mkdir build
 cd build
 cmake ..
 make
 sudo make install

If other packages from lxqt-meta have not installed, you may install them individually using Emerge, e.g.:
emerge -av  lxqt-base/lxqt-session
You should now be able to select LXQt from the login screen.

Sunday, November 24, 2013

PCManFM File manager has no icons in Razor-Qt

When using Razor-Qt desktop environment, if the PCManFM file manager has blank icons then you may need to use LXappearance to set an icon theme.  LXappearance can be started from command line:
lxappearance
or from Start menu -> Preferences -> Customize Look and Feel -> Icon Theme





Monday, November 18, 2013

Setting locale in Sabayon 13.11

To set the system default locale to en_AU.UTF-8 in Sabayon 13.11:
sudo nano /etc/locale.gen
  en_AU.UTF-8 UTF-8
  en_AU ISO-8859-1

sudo nano /etc/locale.conf
  LANG=en_AU.UTF-8

sudo env-update   (applies the changes to /etc/profile.env)
source /etc/profile (makes the change effective in the current shell - restart if not effective)


Sunday, November 17, 2013

Zenity 3.8 list output bug on Sabayon

Zenity 3.8.0 on Sabayon 13.12 has a bug that doubles the output of list with seperating pipe, as explained here:
https://bugs.launchpad.net/ubuntu/+source/zenity/+bug/1247137
 My workaround was to download latest source from:
https://git.gnome.org/browse/zenity
Download the package:
ZENITY_3_10_0.tar.gz
Ensure the following are installed:
automake
gcc
gnome-common (small)
yelp-tools
Extract, make and install:
cd ZENITY_3_10_0
autogen.sh
make
sudo make install

Sunday, October 6, 2013

LXDE Default Browser shortcut link for panel

LXDE includes the "Preferred Applications" (libfm-pref-apps) program to set the preferred web browser. It works by changing the following entry:
~/.local/share/applications/mimeapps.list
[Default Applications]
x-scheme-handler/http=iceweasel.desktop
The problem with this is if you have a shortcut on the LXPanel, or Desktop, then the link is not updated automatically.  Exo-open is designed for XFCE and is ineffective to fix this issue, xdg-open cannot be used in a shortcut unless a parameter is passed - which is no good if you just want to open the browser.

A workaround is to create a new script that uses xdg-mime to query for the default http handler and create a .desktop file that runs this new script:

 sudo nano /usr/local/bin/x-www-mime-browser
#!/bin/sh

# This script uses xdg-mime to check the default browser
# and executes the .desktop from ~/.local/share/applications
# or /usr/share/applications.

URL="$1"
HANDLER=`xdg-mime query default x-scheme-handler/http`
# If handler is customized, extract from .local/... and execute
if [ -f ~/.local/share/applications/$HANDLER ]; then
    `grep Exec ~/.local/share/applications/$HANDLER \\
    | awk -F= '{ print $2 }' \\
    | awk '{ print $1 }';`
else
    `xdg-mime query default x-scheme-handler/http | awk -F. '{ print $1 }'`
fi
 sudo chmod +x /usr/local/bin/x-www-mime-browser
 sudo nano /usr/share/applications/x-www-mime-browser.desktop
[Desktop Entry]
Name=Web Browser (default)
Exec=x-www-mime-browser %u
MimeType=application/x-xdg-web-browser
Terminal=false
Type=Application
Categories=WebBrowser;Other
Icon=web-browser
NoDisplay=false
When using the LXDE Application Launch Bar Settings the "Web Browser (default)" selection will be tucked away under the "Other" category - this will prevent an extra copy visible in the "Internet" category.