Friday, September 27, 2013

OpenBSD - Post Install - Wifi - USB - Pkg_add - What do I Think

v 0.3
29 Sep 13


Well, I've been the proud user of an OpenBSD 5.4 Snapshot installation, on an Asus VX1 laptop for a few days now. My initial impressions are pretty damn good.  Yes it is a basic install (hey, the ISO is only 200 meg or so) but it is clean and uncluttered.  It lets you build the system you want without any crap you don't want - and THAT helps security.  Whilst OpenBSD installs quickly, don't expect a system that can do work "out of the box" - if you do, then you will be sorely disappointed and will miss what is truly a gem.  If you want something like that, then PC-BSD is perfect for you, or on the Linux side something like Ubuntu - or even Debian or Slackware.

Take a couple of relaxing breaths, and tinker and read and gradually you will understand and build your system.

Wireless and USB

As for me, well, I was able to configure the Ethernet port during install, however the Intel Wifi card would not work.  After some reading and checking the man page for it, I worked out I had to either download the firmware directly from the OpenBSD site, or use the specialised program which checked what was needed, downloaded and installed the firmware automatically.

Man page for wpi (my card) is here:

There are two ways you can install the firmware
1. Have a wired ethernet link and use fw_update
2. Download the firmware on another computer, transfer the firmware to the laptop and run pkg_add from the directory the firmware is in.

Of course, if you are going to copy the file to your machine, you will probably use a USB memory stick.  The documentation for this is thorough and I was most impressed to see my USB sticks recognised and easily mounted.

Once the firmware is installed, then you need an appropriate config file in " /etc ".  I got the wireless card to work by putting this line in " /etc/hostname.wpi0 " 

dhcp nwid [SSID] wpakey [PASSWORD]

Packages

Package Management - again, the man page is your friend.  I found using an http mirror to be far more reliable than an ftp mirror, which kept dropping out and failing.  You need to configre " pkg.conf " with mirror sites or package directories .. you can put in more than one.  As mentioned below - if you have the packages in the default directory, then there is no need to specify that directory.

/etc/pkg.conf

installpath=http://mirror.internode.on.net/pub/OpenBSD/snapshots/packages/i386/ 

Remember the trailing "  /  "

Where do they go?

Downloaded packages can be found in " /var/db/pkg "
Installed programs are in " /usr/local/share "



... Later

Tuesday, September 24, 2013

OpenBSD - Windows XP Dual Boot

September 25 2013
v 0.24

Recently, I stumbled upon OpenBSD and I have to say, I like it. Despite a couple of articles I've read proclaiming that it is not as secure as it claims, I'd have to question what the authors of the article understand, since I tend to agree with the OpenBSD people. In a way, OpenBSD is a little like Dassault. Dassault believes that beautiful aeroplanes fly right. OpenBSD believes that beautiful code works properly.

Whilst OpenBSD will not pander to your ignorance (people who wonder what "the big red button does" will find out quickly), having patience and reading and doing research will quickly get you on the right track.

As an aside, my stable of preferred Operating Systems is:
  • Debian Stable (with backports) for pure desktop
  • PC-BSD for desktop / server (nVidia card required for X)
  • OpenBSD for lots of stuff because it works.

Whilst I have been playing with OpenBSD in a Virtualbox VM, I wanted it on hardware. I have an Asus VX1 laptop that has a 160 gig HDD, 2 gig memory and an nVidia video card. It runs Windows XP. Now, WinXP has 6 months before MS withdraws support - no more security updates, so attaching it to the Internet could get (more) exciting. I didn't want to blow XP away if I could help it, so .. here we go.

First I removed all the files I could - hey I wasn't going to need them there anyway .. and I figured I could shrink the NTFS partition to 40 gig, leaving over 100 gig for OpenBSD. Initial disk configuration was:
  • 2 gig hidden recovery partition
  • 88 gig C drive
  • 58 gig D drive

Next .. disable virtual memory and hibernation in XP. (google is your friend). These two features are responsible for the "unmoveable" files shown when you defrag. Whilst I'm sure I could shrink the partition without trouble, I wanted to play nice.

Surgery, boot with a "Parted Magic" CD. Using this, I deleted the "D" extended and logical partitions, and shrank the "C" partition to 40 gig. I was now left with the initial "hidden" recovery partition for WinXP (careful of it - if you ever use it, it will blow away OpenBSD) and the WinXP primary partitions. I created an empty, unformatted partition to fill up the disk, this coming to about 107 gig. It is important to create this partition now as I have shown. It makes things a lot safer and easier later.

OpenBSD installation uses the fdisk program to set the boot partition and to label the installation partition as "A6". THEN it uses the disklabel program to set internal "partitions" and mount points inside this. I'll not describe the process in any more detail, since OpenBSD is not something you should be playing with if you are not able to work things out. The best web-page I found to fill in the blanks and help was this:


Booting the OpenBSD installation CD, I used fdisk to set the bootable partition and set its filesystem type. Then disklabel came up and I eventually accepted the defaults. There are several Youtube videos that give you more insight to this.

With the installation finished, I booted into OpenBSD - as the web page above said, I used fdisk to set the bootable partition back to NTFS and rebooted. Once in Windows again, I used the instructions to add OpenBSD to the Boot menu.

Final tip - remember you have an extra hidden partition, so be careful when you come to specifying partition numbers ...

Done.


PS    Editing the BOOT.INI in Windows ........

The referenced web page doesn't tell all you need to know, nor does it interpret the editing process correctly.

You edit BOOT.INI with the " bootcfg " command.  Whilst you can view boot.ini with notepad, you cannot edit it.  So ...
  • Change default OS .. "  bootcfg /default /ID [linenumber of OS to be default] " .. In our case, we want the second OS to be made the default, so we would use the number 2.
  • Change the timeout .. " bootcfg /timeout 10 "

That's it ..

Sunday, August 18, 2013

PC-BSD - Taking the Plunge

v 0.2
18Aug 13

I've been thinking that it is time for a new computer - after all, the machine that I've been using is 6 years old.  The server setup I'd done has been chugging along nicely and the interesting thing is that it is as fast as my Windows desktop.  After doing a bit of fantasy building, I thought "why not just use the server machine - add a couple of things and make it really good before moving on and getting what I really want?"

And then my Windows desktop started cutting out - I figured the CPU was overheating, so I specially cleaned it - which fixed things for a while - but I had this sense of unease.  What really bothered me was the software raid I'd used with Windows .. tight licencing with Microsoft made me think that if this thing fell over, then I'd have a "bother of a time" getting it sorted, so I started dragging stuff off it.

I had about half my data off, when a strange electrical smell started - then "BANG!!!" and a flash from the power supply.  And the house got dark.  Alright, I thought, at least I know what the problem is now ....  A visit to my local friendly computer shop and with a new power supply my machine was now as good as new again.  I'd gone past the tipping point though, and I wanted to move on.  Yes, I did need Windows for a couple of things, but I wanted out.

My "Home Server" .. it was inexpensive to put together, having an i3 CPU, an Nvidia GTS450 graphics card I had lying around (to make PC-BSD work), 8 gig memory and a Western Digital 2 TB "Green" hard disk.  I had (so I thought) another of these disks lying around, and I went out to purchase a third.  I had finished playing with the machine with PC-BSD and thought this was an opportunity to re-do things the way I wanted, using things I'd learned.

The Plan

  • Re-install the latest PC-BSD rolling release.
  • Use three 2tb disks in a ZFS Raid-1z configuration
  • Use Jails and Virtualbox to run servers in the background

PC-BSD - the Really Cool Stuff

Whilst I remain a committed fan of Debian (Wheezy is just so cool), PC-BSD has too many great things going for it not to be used.  A few months ago when I was looking at it, there were two "killer problems" .. it would not immediately recognise USB memory sticks, and the Flash video was not an Adobe "priority".  Well, the USB problem has been solved, and I figured that if I really needed Flash video, then a Virtualbox VM would do it for me.

What has me really excited about PC-BSD is the user-friendly implementation of the Zetabyte File System (ZFS).  

The installation routine allows a simple implementation of many "multiple disk" file systems in Raidz configuration.  You can have a simple "mirror" configuration with two disks, moving up from there.  I have a three disk configuration whereby the failure of one disk allows me to replace it and then re-build the configuration without loss of data.

But wait! There's more!

Using the PC-BSD Control Panel you can specify system snapshots to allow you to roll back in the GRUB menu to a previously good system (if an upgrade wasn't all you hoped for).  This system snapshot does NOT affect your own files - it is purposefully restricted to system files.

Servers running in a jail can have snapshots taken automatically, say, every hour so that if all hell breaks loose, you can just roll back to the last good server.  Say someone attacks your  server in its jail .. and trashes files and installs malware.  Roll back and the malware is gone and the files are back.  Magic!

Steak knives!

The supplied backup program .... the PBI installation system for additional programs ....

My Experience

Drives

First, I discovered that I did not have three WD Green drives, but two with a Seagate one.  Ah .. it will be ok.  Ultimately I had to shoehorn the Seagate drive in because of a lack of mounting holes .. but figured ... "it will be ok" .... well, it wasn't BUT that showed how great ZFS is .... and I was able to fix everything. 

So, what was the problem with the Seagate drive? .. well I just laid it out on top of one of the other two drives .. giving the drive circuitry no chance of getting any cooling air.  The obvious happened and the drive fell out of the ZFS zpool.  Bother.  BUT .. the zpool kept working!

Next day when I rebooted, everything worked! The zpool resilvered .. aha ... sounds like a case for duct-tape! ... Yes, I have duct-taped the Seagate drive to give it cooling .. but it works and I've had no further problems.

USB

The USB problem has been largely fixed.  So long as your USB Memory stick has 16 gig or less, then no problems for copying TO the computer.  PCBSD does not recognise  USB memory sticks greater than 16 gig.

Where the problem comes in is with copying files FROM the computer TO the memory stick.  What happens is that the system complains that it is unable to re-set the permissions to yours and in the case I was faced with ... that was 700 info windows to click through.  !Fun.

NTFS .. no probs .. though I found that it was very difficult to unmount an external drive.

Overall?

I'm still here.





Later.


Saturday, June 8, 2013

Debian Wheezy - Virtualbox Shared Folders

v 0.2
8th Jun 2013

One thing I've never found very satisfactory is the method of organising shared folders between a Linux guest and the Host systems in Virtualbox.  The instructions I've read have never seen to be satisfactory.  Until now.  In this example, I'll use a Windows host and a Debian Wheezy guest system, however it works exactly the same on my Macbook for OSX.

  • First, add a shared folder to the Virtualbox manager for the VM.  I added "C:/Users/geoff/share" .  Make sure "automount" and "make permanent" are ticked and "read only" NOT ticked for bi-directional sharing.
  • Within the Wheezy guest, install the package " gnome-system-tools ".  This gives you additional administration tools, such as group management.
  • Open "Applications | System tools | Administration | Users and Groups"
  • Manage Groups
  • Scroll down till you find the group " vboxsf "
  • Highlight it and click "Properties"
  • You will see a list of usernames in the box "Group Members" - tick the users you wish to be able to use the shared folder.  Authenticate the action with the root password.
  • Close the programs and Reboot.
  • Log in, and open Nautilus - navigate to the " /Media " directory.  You will see a directory named (in my case)  " sf_share ".  (the directory is always named " sf_ ...... " ) .  Any file you now place in that directory in Host, will be shown when you open the directory in Guest.

Done!!


Later.