<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>totalnetsolutions.net &#187; Security</title>
	<atom:link href="http://www.totalnetsolutions.net/category/tech/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.totalnetsolutions.net</link>
	<description>totalnetsolutions.net - Complete Networking Solutions for business</description>
	<lastBuildDate>Wed, 14 Jul 2010 14:29:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Upgraded WordPress</title>
		<link>http://www.totalnetsolutions.net/2009/09/07/upgraded-wordpress/</link>
		<comments>http://www.totalnetsolutions.net/2009/09/07/upgraded-wordpress/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 04:05:40 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/?p=110</guid>
		<description><![CDATA[Upgrading software &#8211; always required to keep things secure.  Windows, WordPress, Mac OSx, Linux, Office, Firefox, etc.  So I just finished upgrading TotalNetSolutions.net again.  Hopefully I&#8217;ll be able to be better about this, now that WordPress does the automatic upgrades now. I&#8217;ve been doing the automatic upgrades on one of my other sites since they [...]]]></description>
			<content:encoded><![CDATA[<p>Upgrading software &#8211; always required to keep things secure.  Windows, WordPress, Mac OSx, Linux, Office, Firefox, etc.  So I just finished upgrading TotalNetSolutions.net again.  Hopefully I&#8217;ll be able to be better about this, now that WordPress does the automatic upgrades now.</p>
<p>I&#8217;ve been doing the automatic upgrades on one of my other sites since they came out.  They&#8217;re easy, fast, and even more painless than the <a href="http://codex.wordpress.org/Upgrading_WordPress" target="_blank">3-step upgrade</a> that works so well.  So now, I should be able to keep TNS much further away from the &#8220;cobbler&#8217;s kids&#8221; syndrome so many small company&#8217;s systems suffer with.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2009%2F09%2F07%2Fupgraded-wordpress%2F&amp;title=Upgraded+WordPress" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2009/09/07/upgraded-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Managing large numbers of systems</title>
		<link>http://www.totalnetsolutions.net/2008/11/22/managing-large-numbers-of-systems/</link>
		<comments>http://www.totalnetsolutions.net/2008/11/22/managing-large-numbers-of-systems/#comments</comments>
		<pubDate>Sat, 22 Nov 2008 18:33:39 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[remote control]]></category>
		<category><![CDATA[servers]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/?p=65</guid>
		<description><![CDATA[In the Windows world, tools like Group Policy, System Center Configuration Manager, and DesktopAuthority, among others, have been around for 8 or more years to allow fast simple deployment of software and updates to remote computers, or force tasks to be run on remote computers. For the Unix/Linux world, there doesn&#8217;t seem to be as [...]]]></description>
			<content:encoded><![CDATA[<p>In the Windows world, tools like Group Policy, <a href="http://www.microsoft.com/Systemcenter/configurationmanager/" target="_blank">System Center Configuration Manager</a>, and <a href="http://www.scriptlogic.com/products/desktopauthority/" target="_blank">DesktopAuthority</a>, among others, have been around for 8 or more years to allow fast simple deployment of software and updates to remote computers, or force tasks to be run on remote computers.</p>
<p>For the Unix/Linux world, there doesn&#8217;t seem to be as much available. </p>
<p>If you have a pure HP-UX shop, there is <a href="http://h18000.www1.hp.com/cpq-products/servers/management/hpsim/plugin-apps.html" target="_blank">HP Systems Insight Manager (SIM)</a> with plug-ins available for software deployment, and I believe <a href="http://www-01.ibm.com/software/tivoli/" target="_blank">IBM Tivoli</a> has a function or sub-product which does the same thing if you have all AIX systems.  <a href="http://www.redhat.com/red_hat_network/" target="_blank">Red Hat Network</a> has a feature to allow commands to be run on your servers, but only whenever they check in with the RHN or your internal Satellite Server (much like Group Policy, except GPO doesn&#8217;t allow &#8220;in the middle of the day&#8221; script creation without GP-Preferences).  So what&#8217;s available that&#8217;s like SCCM or DesktopAuthority &#8211; a &#8220;click now and do this thing&#8221; tool?</p>
<p>A bunch of my customers just have various levels of logging and processing that come down to being a big for loop that ssh&#8217;s into a server and runs a command:<br />
<code>for i in `cat server-list.txt` ; do scp scriptname $i:/root/; ssh $i "/root/scriptname" | tee logfile-$i.log; done;</code><br />
While it works great for smaller commands. if you have a mixed environment, the &#8220;scriptname&#8221; script has to be intelligent enough to know what it&#8217;s running against, or your &#8220;server-list.txt&#8221; has to be broken up by class of system.  In either case, if you have 200 systems in the list, and the task takes 5 minutes per server, a single install will run for 16-17 <b>hours</b>.</p>
<p>Software like <a href="http://www.likewisesoftware.com/products/likewise_enterprise/index.php" target="_blank">Likewise Enterprise</a> which allow Group Policy management to remote computers is great, because you can have guaranteed delivery and execution of your script or command in (by default) 30 minutes, but my problem is how to get it there in the first place?</p>
<p>So, administrators out there in companies with 1000, 4000, 10000+ servers (or even Desktops), what mutli-threaded or multi-process tool are you using to tackle this timing/resouce problem?  Please post below!</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F11%2F22%2Fmanaging-large-numbers-of-systems%2F&amp;title=Managing+large+numbers+of+systems" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2008/11/22/managing-large-numbers-of-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Akismet on WordPress</title>
		<link>http://www.totalnetsolutions.net/2008/02/22/akismet-on-wordpress/</link>
		<comments>http://www.totalnetsolutions.net/2008/02/22/akismet-on-wordpress/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 16:59:18 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Open Source Software]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/2008/02/22/akismet-on-wordpress/</guid>
		<description><![CDATA[As of today: &#8220;Akismet has caught 347 spam for you since you first installed it.&#8221; That&#8217;s since 11/29/2007. Akismet has YET to miscategorize a comment as spam, and it has missed a single spam comment. All I had to do was click &#8220;this is spam&#8221; and it&#8217;s cleaned up. The only other anti-spam product I&#8217;ve [...]]]></description>
			<content:encoded><![CDATA[<p>As of today:</p>
<p>&#8220;Akismet has caught <strong>347 spam</strong> for you since you first installed it.&#8221;</p>
<p>That&#8217;s since 11/29/2007.  Akismet has YET to miscategorize a comment as spam, and it has missed a single spam comment.  All I had to do was click &#8220;this is spam&#8221; and it&#8217;s cleaned up.</p>
<p>The only other anti-spam product I&#8217;ve seen to perform this well is the IronPort mail system at a client.  130,000 or so attempts / day, 1 spam / day in the entire company queue, and no users complaining about spam in 5 months.</p>
<p>Akismet, Ironport, my hat is off to you both.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2008%2F02%2F22%2Fakismet-on-wordpress%2F&amp;title=Akismet+on+WordPress" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2008/02/22/akismet-on-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cross-forest trusts and new error codes</title>
		<link>http://www.totalnetsolutions.net/2007/12/09/cross-forest-trusts-and-new-error-codes/</link>
		<comments>http://www.totalnetsolutions.net/2007/12/09/cross-forest-trusts-and-new-error-codes/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 05:29:43 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Domain Controllers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[domain controllers]]></category>
		<category><![CDATA[trusts]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/2007/12/09/cross-forest-trusts-and-new-error-codes/</guid>
		<description><![CDATA[If you are setting up a cross-forest trust with selective authentication (which requires a Windows Server 2003 Native mode level forest and domain), don&#8217;t forget to grant the &#8220;Allowed to Authenticate&#8221; right to the users from the trusted domain to the servers they&#8217;ll need access to in your domain. The error messages you&#8217;ll get back [...]]]></description>
			<content:encoded><![CDATA[<p>If you are setting up a cross-forest trust with selective authentication (which requires a Windows Server 2003 Native mode level forest and domain), don&#8217;t forget to grant the &#8220;Allowed to Authenticate&#8221; right to the users from the trusted domain to the servers they&#8217;ll need access to in your domain.  The error messages you&#8217;ll get back (replicated here in my test VM domains) don&#8217;t really say much helpful.</p>
<p>System Error 317 has occurred.  The system cannot find message text for message number 0x*** in the message file for ***.<br />
<br /><img src="http://www.totalnetsolutions.net/wp-content/uploads/2007/12/system317.png" alt="System Error 317" /></p>
<p>Further information about adding the &#8220;Allowed to Authenticate&#8221; right to the trusted users is available <a href=http://technet2.microsoft.com/windowsserver/en/library/b4d96434-0fde-4370-bd29-39e4b3cc7da81033.mspx?mfr=true" target="_blank">at Microsoft TechNet</a>.  If you have the opportunity to raise your forest and domain functional levels to take advantage of this, I highly recommend it.  But I recommend also (even more strongly) documenting precisely what you set.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F12%2F09%2Fcross-forest-trusts-and-new-error-codes%2F&amp;title=Cross-forest+trusts+and+new+error+codes" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2007/12/09/cross-forest-trusts-and-new-error-codes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Current System Status</title>
		<link>http://www.totalnetsolutions.net/2007/11/29/current-system-status/</link>
		<comments>http://www.totalnetsolutions.net/2007/11/29/current-system-status/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 21:39:12 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/2007/11/29/current-system-status/</guid>
		<description><![CDATA[Now that I have the system back online, I thought I&#8217;d post a quick &#8220;where we are&#8221; update for any regular readers: We have restored from most recent backup, but are missing a single post, &#8220;PHP, mail(), Apache, and SELinux (FC7)&#8221;, which even google.com&#8217;s cache didn&#8217;t catch in full. I apologize to the readers who [...]]]></description>
			<content:encoded><![CDATA[<p>Now that I have the system back online, I thought I&#8217;d post a quick &#8220;where we are&#8221; update for any regular readers:</p>
<ol>
<li>We have restored from most recent backup, but are missing a single post, &#8220;PHP, mail(), Apache, and SELinux (FC7)&#8221;, which even google.com&#8217;s cache didn&#8217;t catch in full.  I apologize to the readers who were using the instructions in that post whom we met through their comments.</li>
<li>We haven&#8217;t yet restored the &#8220;comments&#8221; table.  I haven&#8217;t yet decided if we will.</li>
<li>I have fixed the problem of storing backups for the company in 3 different locations, based on system type.  Now we only have 2 &#8211; onsite and offsite.</li>
<li>The extremely popular <a href="http://www.totalnetsolutions.net/2007/07/29/how-to-change-a-domain-controller-ip/" target="_blank">How to Change a DC IP address</a> article was restored first. (That page drives over half of our traffic.)</li>
</ol>
<p>We did a standard forensics review of what happened, and it appears as though a perfect storm of issues hit us &#8211; a weekend outage, a hardware failure, and failure to keep publicly exposed software fully up-to-date.  The saying often goes, &#8220;The cobbler&#8217;s kids are the ones without shoes&#8221; or something similar to that, and here we failed to follow our own advice, preferring to keep our customers&#8217; systems running smoothly.  I know I&#8217;ll be spending a few extra hours a week the rest of this year reviewing our internal systems for best practices.</p>
<p>In any case, things are fixed and running great again.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F29%2Fcurrent-system-status%2F&amp;title=Current+System+Status" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2007/11/29/current-system-status/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP mail(), Apache, and SELinux (FC7)</title>
		<link>http://www.totalnetsolutions.net/2007/11/02/php-mail-apache-and-selinux-fc7/</link>
		<comments>http://www.totalnetsolutions.net/2007/11/02/php-mail-apache-and-selinux-fc7/#comments</comments>
		<pubDate>Fri, 02 Nov 2007 17:48:20 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/2007/11/02/php-mail-apache-and-selinux-fc7/</guid>
		<description><![CDATA[(Originally drafted November 2nd, 2007, finally finished and posted much later) As I posted last night, we built a new Fedora Core 7 box last night for PHP testing. Whenever at all possible, I leave SELinux enabled on new systems in Enforcing mode. Oracle 10g hasn’t had any issues with it, Oracle 11i EBusiness Suite [...]]]></description>
			<content:encoded><![CDATA[<p>(Originally drafted <a href="http://www.totalnetsolutions.net/2007/11/02/fedora-core-7-php-can%E2%80%99t-send-mail/">November 2nd, 2007</a>, finally finished and posted much later)<br />
As I posted last night, we built a new Fedora Core 7 box last night for PHP testing. Whenever at all possible, I leave SELinux enabled on new systems in Enforcing mode. Oracle 10g hasn’t had any issues with it, Oracle 11i EBusiness Suite hasn’t had any issues with it, and my NFS and FTP servers run without at hitch. The Oracle systems are RHEL4 (Red Hat Enterprise Linux 4), and the NFS and FTP servers are RHEL5.</p>
<p>However, this new PHP webserver caused a few glitches. I feel a little silly for not catching this as being an SELinux problem earlier, but since it’s caused 0 issues in 9 months of use in production, I didn’t even consider it initially.</p>
<p>What we initially saw was 0 errors from PHP &#8211; all the pages would run without error. PHP.ini has the following lines:</p>
<blockquote><p>sendmail_from = from@domain.com<br />
sendmail_path = /usr/sbin/sendmail -t -i</p></blockquote>
<p>and testing <code>cat mail.txt | /usr/sbin/sendmail -t -i</code> as a non-root user delivered mail properly as well. Combine that with /var/log/maillog being completely empty for every test page loaded, and it was sure that the mail wasn’t getting TO postfix (our preferred localhost MTA).</p>
<p>So, I looked at the /var/log/httpd/error_log for apache and found:</p>
<blockquote><p>sh: /usr/sbin/sendmail: Permission denied<br />
sh: /usr/sbin/sendmail: Permission denied<br />
sh: /usr/sbin/sendmail: Permission denied<br />
sh: /usr/sbin/sendmail: Permission denied<br />
sh: /usr/sbin/sendmail: Permission denied</p></blockquote>
<p>But I knew that non-root users could access sendmail as defined in php.ini, so I finally decided to tail /var/log/messages and saw:</p>
<blockquote><p> Nov 2 11:05:41 $(servername) setroubleshoot: SELinux is preventing the sh from using potentially mislabeled files sendmail.postfix (sendmail_exec_t). For complete SELinux messages. run sealert -l c9001c48-5d48-4b7c-9fd7-8400544daa8f</p></blockquote>
<p>So now to fix it… <more><br />
This is surprisingly simple, actually.  The sad part is, we had this problem, fixed it, forgot about it, had it again, and I blogged it&#8230; and lost the post.  so this has been sitting in my &#8220;drafts&#8221; folder for about 10 months now:<br />
<code>setsebool httpd_can_sendmail=true<br />
service httpd restart<br />
service postfix restart</code><br />
And retry sending mail.  There&#8217;s a few posts about sendmail and having to change permissions on home directories or on &#8220;main.cf&#8221;, but I use postfix, and not sendmail, so I don&#8217;t know how effective or necessary those changes are.</more></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Fphp-mail-apache-and-selinux-fc7%2F&amp;title=PHP+mail%28%29%2C+Apache%2C+and+SELinux+%28FC7%29" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2007/11/02/php-mail-apache-and-selinux-fc7/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fedora Core 7 &#8211; PHP can’t send mail</title>
		<link>http://www.totalnetsolutions.net/2007/11/02/fedora-core-7-php-can%e2%80%99t-send-mail/</link>
		<comments>http://www.totalnetsolutions.net/2007/11/02/fedora-core-7-php-can%e2%80%99t-send-mail/#comments</comments>
		<pubDate>Fri, 02 Nov 2007 06:33:16 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open Source Software]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.totalnetsolutions.net/2007/11/02/fedora-core-7-php-can%e2%80%99t-send-mail/</guid>
		<description><![CDATA[I’m hunting down an issue on Fedora Core 7 where PHP5 can’t send mail using sendmail or postfix. In /var/log/httpd/access_log we are getting sh: /usr/sbin/sendmail: Permission denied every time the mail() function is accessed, and postfix never sees any connection. This is being caused by SELinux blocking Apache from transitioning from the “httpd” role to [...]]]></description>
			<content:encoded><![CDATA[<p>I’m hunting down an issue on Fedora Core 7 where PHP5 can’t send mail using sendmail or postfix. In /var/log/httpd/access_log we are getting <code>sh: /usr/sbin/sendmail: Permission denied</code> every time the <code>mail()</code> function is accessed, and postfix never sees any connection. This is being caused by SELinux blocking Apache from transitioning from the “httpd” role to the “mta” role &#8211; I’m just not sure what the *best* way to fix it is yet. I haven’t seen many posts about this, so stay tuned &#8211; I expect to have a fix tomorrow afternoon.</p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Slashdot It!"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Digg This Story"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Reddit"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://del.icio.us/favicon.ico" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F" title="Share on Facebook"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F" title="Add to my Technorati Favorites"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Save to Google Bookmarks"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.totalnetsolutions.net%2F2007%2F11%2F02%2Ffedora-core-7-php-can%25e2%2580%2599t-send-mail%2F&amp;title=Fedora+Core+7+%26%238211%3B+PHP+can%E2%80%99t+send+mail" title="Stumble it!"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://www.totalnetsolutions.net/2007/11/02/fedora-core-7-php-can%e2%80%99t-send-mail/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
