Thursday, 17 March 2011

how to compile Apache 2.2 and openssl to support SNI

With the later versions of Apache 2.2 it is possible to build a system which supports SNI (subject name indication). This allows you to host multiple ssl websites on the same ip address. It is effectively a version of host headers for ssl.

I found surprisingly little information on the internet as to how to get this to work, so I thought I would create this to show how it is done!

The installation was performed on a virtual machine running opensuse 11.1 32bit, however I would imagine other Linux/unix versions would be similar.

First the installation of opensuse installs openssl however this is not compiled with TLS support built in, so it has to be recompiled to allow us to continue.

So, first back up the existing openssl executable:

root> cp /usr/bin/openssl /usr/bin/openssl.orig

Now download the latest openssl source code from www.openssl.org and place it in /tmp. When I did this the version available was 1.0.0d, so the rest of the document will reference this version. Extract the tar file and install it with the following commands:

root> cd /tmp
root> tar -xvzf openssl1.0.0d.tar.gz
root> cd openssl1.0.0d
root> ./config --prefix=/usr --openssldir=/usr/local/openssl enable-tlsext shared
root> make
root> make install

Openssl is now installed, so we confirm this by checking the version, with the following command:

root> openssl version

This should return the version installed, ie 1.0.0d

So we can now move onto the Apache installation, download the latest Apache 2.2 from www.apache.org, and place it in /tmp. I downloaded version 2.2.17, so will reference this version from this point forwards.

Compile and install it with these commands:

root> cd /tmp
root> tar -xvzf http-2.2.17.tar.gz
root> cd http-2.2.17
root> ./configure --prefix=/usr/local/apache-2.2.17 --with-mpm=worker --enable-deflate --enable-mime-magic --enable-proxy --enable-ssl --with-ssl=/usr/bin --disable-status --enable-vhost-alias --disable-cgid --disable-userdir --enable-rewrite --enable-mods-shared='isapi file_cache cache disk_cache mem_cache ext_filter expires headers usertrack unique_id status info cgi cgid speling'
root> make
root> make install

Apache should now be installed into the /usr/local/apache-2.2.17 directory.

I then like to symlink it to /usr/local/apache so run the command:

root> ln -s /usr/local/apache-2.2.17 /usr/local/apache

We now need to configure the ssl to use sni, so first make sure Apache will load the ssl configuration, to do this uncomment the following line in the /usr/local/apache/conf/http.conf file:

Include conf/extra/http--ssl.conf

We now need to create the ssl configuration file. For test purposes, we will create a new one, so let's move the old one out of the way:

root> cd /usr/local/apache/conf/extra
root> mv httpd-ssl.conf httpd-ssl.conf.orig

Now recreate the httpd-ssl.conf file with the following contents:


# Ensure that Apache listens on port 443
Listen 443

# Listen for virtual host requests on all IP addresses
NameVirtualHost *:443

# Go ahead and accept connections for these vhosts
# from non-SNI clients
SSLStrictSNIVHostCheck off

<VirtualHost *:443>
# Because this virtual host is defined first, it will
# be used as the default if the hostname is not received
# in the SSL handshake, e.g. if the browser doesn't support
# SNI.
DocumentRoot /www/example1
ServerName www.example.com

# Other directives here

</VirtualHost>

<VirtualHost *:443>
DocumentRoot /www/example2
ServerName www.example2.org

# Other directives here
</VirtualHost>

 

Save this file.

Next we need to create stubs for the two sites mentioned in the file above.  So lets create these now:

root> cd /
root> mkdir www
root> cd www
root> mkdir example1
root> mkdir example2

We are now in a position to try and start apache:

root> cd /usr/local/apache/bin
root> ./apachectl start

You should find that apache returns with no errors, however upon checking with the following command:

root> ps -ef |grep http

You will find it is not running.  However the fact that no errors were returned to the screen, shows that apache is successfully compiled with SNI support.

If you look in the error logs in /usr/local/apache/logs you will see that it is missing information about the ssl certificates.

This is now configured in the usual way you would do for a single SSL website, so will not be covered here.  To run multiple sites, each site definition in the httpd-ssl.conf file can now reference different certificates.

A word of note however, not all web browsers support TLS which is required for this to work.  Browsers that do not support TLS will use the first defined site in the httpd-ssl.conf file, therefore this should be defined as being the default site.  The list of browsers not supporting TLS is wide-ranging and can be found with a quick internet search.  One suprise for me is Internet Explorer 8 running on Windows XP does not support TLS, it does however support TLS on Windows Vista and later.

I hope this helps getting SNI working with Apache.
Published with Blogger-droid v1.6.7

Sunday, 13 March 2011

quick point in time Oracle database recovery on Netapp

As we have now started to move our production databases onto the Netapp, we thought we should do some testing to prove it can yield advantages in our infrastructure.

To summarise our setup first, we have three elements to our database setup on netapp:

1. The database server - this holds Oracle home, redo logs and controlfile
2. Netapp cluster node a - this holds the dbfs for the database, along with the controlfile
3. Netapp cluster node b - this holds the redo logs, flash recovery area (including archive log) and controlfile

We therefore think this offers us enough resilience in that we can lose any one of the above three elements in our setup without any data loss.

The Netapp volumes (items 2 & 3 above) are snapshotted every 2 hours during the working day, to reduce the restoration time should anything happen. This is done via a cron job on the Oracle host which co-ordinates this, with putting the database into hot backup mode to ensure consistency. It also backs up the controlfile to trace, so that we can recreate it if necessary.

In this test we wanted to test restoration of a database to a time prior to a corruption occuring.

The tests were carried out on a production database, so we therefore wanted a way to simulate this. So we performed the following.

1. Ran the database backup script - this produced Netapp snapshots of both the dbf and logs volumes - time A

2. Created a test user in the database and created a test table A under this schema - time B

3. Waited 5 minutes

4. Created a test table C under our test user schema - time C

5. Ran our database backup script again - time D

In our test we then assumed the corruption occurred just before creating the second table, ie just before time C, we therefore wanted to restore the database to a time between B and C, whereby our test user should only have 1 object (table A).

We obviously did not want to do this restoration against a production database, so we would identify the files we would need and would copy these to another database server and restore it there, effectively making a copy of the database at a time between B and C.

First, we need to identify the dbf snapshot, from before the corruption, ie that created at time A above. Login to the Netapp and issue the command:

snap list DBF_VOLUME

Where DBF_VOLUME is replaced with the volume name of your volume containing the dbfs.

This will produce a list of snapshots against the volume. From this list it should be easy to find the one corresponding to our time A.

We then need to go into this snapshot directory and copy its contents to our separate database host.

Next we need to identify the snapshot containing the logs from a time after the restore point, ie time D.

Repeat the snap list command against the logs volume and identify the one corresponding to time D. Copy the contents of this snapshot to our separate database host.

We now have everything to restore our database.

First, as this is on a secondary host, the location of the files nay be different so we can edit the trace version of the controlfile script, to reflect our new locations.

Once this is done, we can run this against the downed database in our secondary host.

Next, we need to issue the recover database command to roll the database forward from time A to a time between B and C. To do this login to the database as the sys user as sysdba:

sqlplus / as sysdba

Then recover the database:

sqlplus> recover from '.....' database until time '#time#';

Where the ..... is the location of the flash recovery area on the secondary Oracle host and #time# is a time between time B and C in the format: yyyy-mm-dd:hh24:mi:ss

You may find that the recovery still asks for the archivelog files in turn, if it does, type in the actual location - there should not be many as the period of time we are covering is small (just over 5 minutes)

Once the recovery is finished it should return the message:

Media recovery complete

We now need to open the database, however as we have done a point in time recovery, we need to add the resetlogs parameter:

sqlplus> alter database open resetlogs;

We can now log in as the test user and confirm that it only contains table A.

We have proved the concept works and by regularly (every 2 hours) snapshotting the database this method of restoration should remain quick and allow us to respond well to the demands of the business.
Published with Blogger-droid v1.6.7

Sunday, 6 March 2011

Htc desire vs blackberry 9800 torch

So after having my htc desire for a few months, it was suggested I try out the blackberry torch as it would address one of my complaints of the desire - that of connectivity to our novell messenger service.

Well, after trying it out for a weekend I can not wait to get my htc back tomorrow!

Whilst it is true that I can use novell messenger with the blackberry - the web browser and keyboard has absolutely done my head in!

The web browser on the blackberry is often very unresponsive, sometimes it will work perfectly, then at other times it will not respond on clicking links until you hold you finger down on the link until the popup appears and you can then select open link. I never had any problems like this with the htc.

On the blackberry the slide out keyboard is too small, resulting in many incorrect keypresses. The on screen keyboard does not provide feedback to keypresses like the htc does. Also it does not appear possible with both keyboards to hold down the alt key, for instance if you wish to write something in capitals you have to press alt before each character, on the htc a second press of the upper case key keeps it in upper case mode until you press it again.

Then we come onto applications, a lot of the stuff I had working on the htc, I have not managed on the blackberry, eg maps - it never displays for me, navigation, geocaching - charged for on blackberry, etc, etc

On the plus side the camera on the blackberry is much better than that on the htc!

So all in all, I find the blackberry fine for the occasional email, etc, in terms of making my life easier, please bring back my htc!

Wednesday, 2 March 2011

Iscsi Lun alignment with sqlserver and Netapp

How to get totally confused in one easy step! Had some one-to-one Netapp training today, and came up with an issue that had both of us scratching our heads. We still don't fully know the answers!

It started with us running our performance autosupport file through the Netapp partner tool. This indicated misalignment on one of our luns.

Knowing that the Netapp block size is 4k (4096 bytes), so we checked the starting offset for the disk by running the msinfo32.exe (in the c:\Windows\servicepackfiles\I386), this showed the offset as 32256, dividing this by 4096 gave a figure of 7.875, ie not directly divisible, thus confirming the blocks as bring out of alignment.

We therefore did some more digging and found this article:

http://msdn.microsoft.com/en-us/library/dd758814(v=sql.100).aspx

Working through this it appears that the 32256 is the default and if you use the Microsoft disk management tool there is no way to change this, the solution is to use the diskpart program.

We therefore destroyed the partition and set about recreating it with the diskpart commands:

diskpart
list disk
select disk <number>
create partition primary align=32
assign letter=<drive letter>

We then went back into the disk management tool and formatted it as ntfs.

Upon checking in the msinfo32 tool again, the offset is now 32768, and therefore directly divisible by 4096.

So far so good.

Let's check the alignment, to do this we set off a large copy of data to the Lun and in another window set off a perfstat to the filer with a 1 minute duration. Perfstat can be downloaded from the software area of the Netapp website.

We then checked the perfstat output file, searching for the string "perfstat_lun" which is at the start of the section we are interested in.

Here we found the the writes were being performed to bucket 1, thereby being 512 bytes out of alignment (all reads and writes should go to bucket 0 when in alignment).

Strange! The offset is divisible by 4096, but is out of alignment by 512. When the offset was 512 less, we were still showing misalignment!

So we thought, let's recreate the Lun again with the original offset (32256), by using the disk management tool again.

Repeating the test by writing data and running a perfstat job at the same time. Thus time the report showed all the writes into bucket 0!

Even stranger, the lun is now in alignment with the same as the original settings!

So why is it now in alignment when it originally wasn't?

How come it is in alignment when the starting offset is not divisible by 4096?

All, we seen to have learnt on this is how to check for maligned luns, but not how to select a suitable offset should maligned luns be found. However it appears that it is always worth recreation luns with the same settings should misalignment be found!


Saturday, 26 February 2011

PCNFS (Microsoft services for Unix) and Netapp howto

So you want to connect a Windows pc to a shared volume on a Netapp filer, but you either do not have the filer licensed for Cifs, or you want to make it more secure by using the ip to ip nature of nfs. This howto explains how to setup Microsoft services for Unix so that you can mount the volume via nfs (or in Microsoft speak pcnfs).

We will configure the Netapp filer first.

1. Make sure pcnfs is turned on. To do this open the web GUI on the Netapp and navigate to nfs, configure. Here you will find a number of settings, near the top you will find the one we are interested in: "PCNFS Enabled" - make sure this setting is set to "Yes" and apply the changes.

2. Set up the nfs export for the volume/qtree you wish the pc to access. This is done in the normal way for nfs exports through the web GUI, adding the ip address for the pc to either the read-only or read-write section depending on what permissions you need the pc to have. Once these changes have been made don't forget to press the 'Export all" button in order for the changes to take affect!

That concludes the required Netapp changes, we will now move into the pc side of things.

1. Create passwd.txt file in c:\maps directory. This will be used to map the pc username to the Unix username and id later. In this example we will use a user called "aaa" with an id of 63000, so the contents of our file will be:

aaa:x:63000:100:aaa:/home/aaa:/bin/bash

[Note: the 100 in the above line is our group id that this user belongs to, we will create this in the next step]

2. Create group.txt file in the c:\maps directory. This is used to map the group name to id later. In this example we will create the group bbb with an id of 100, so our file will look like this:

bbb:x:100:

3. Install Microsoft services for Unix - this howto will install it on a windows xp professional machine, the software for other Microsoft versions is also available on the Microsoft website, note however for windows 7 you must be on the versions higher than professional! The windows xp version of the software can be downloaded here. Download the file to the desktop.

4. Extract the downloaded file, by double clicking on it and selecting unzip.

5. Navigate to the directory, the files were unzipped to, this will be: c:\Documents and Settings\<username>\Local Settings\Temp and double click on the SfuSetup.msi file.

Then proceed with the installation as follows:

1. Click next on the welcome screen

2. Enter username and organisation followed by next

3. Accept the licence agreement and hit next

4. Select Standard installation and click next

5. Leave the security settings boxed unchecked and click next

6. Select "local user name" mapping and "password and group files" then click next

7. Enter c:\maps\passwd.txt for the password file and c:\maps\group.txt for the group file, then click on next

8. Windows services for Unix will now install

Once the initial installation is complete we need to make some changes. Find windows serviced for Unix, in control panel, add or remove programs, click on the entry and select change.

At the next screen, select add it remove, then hit next

Expand the authentication tools for nfs, click the red x against server for pcnfs line and select entire feature will be installed on hard disk. Then click on next. The change will now be installed.

Once installed, we need to make sure the user name mapping service is set to automatic and is running. Do this in the normal manner by using the services screen of the control panel.

We now need to start the windows services for Unix GUI, so go to control panel, administrative tools and double click on "services for Unix administration"

First we need to configure the user name mapping, so click on "user name mapping" in the left hand side. Then click on "maps" along the top bar, followed by "show user maps".

Click on both list windows users and list Unix users, both boxes will then be populated with the user lists.

We will map the user, administrator to the aaa Unix user, so select administrator in the windows users list and aaa in the Unix users list, then press add map.

You should then see the mapping appear, so click on apply to save the changes.

We now need to sort out the pcnfs side of things, so click on server for pcnfs on the left hand side. Click on groups as we will need to create the group before we can map the user to it. Enter the group id of 100 and the group name of bbb. Then click on add.

You should then see the group in the current groups table. Click on apply to save the change.

Now click on users tab, followed by new. Enter the following details into the pop-up box:

User name: aaa
User logon name: aaa
Password: <your password>
Confirm password: <your password>
Primary group name: bbb
User id: 63000

Then click on ok, the user should then appear in the all users box.

Finally click on apply.

We are now in a position to test the setup.

Open my computer, and type the following into the location bar:

\\<Netapp filer ip address>\<volume/qtree name>

Eg if our Netapp filer has an ip address of 10.20.30.40 and we are connecting to qtree ddd in volume ccc our location would be:

\10.20.30.40\vol\ccc\ddd

Upon hitting enter we should see a listing of the files in this qtree.

Creating a new file in this qtree we should see that it is created as the user aaa (uid 63000) and group bbb (gid 100).




Sunday, 20 February 2011

Sqlserver and cifs on Netapp

So, big weekend this weekend - moving data from the old single head Netapp to new active/active Netapp.

One of the tasks was to move the sqlserver databases, currently running as iscsi mounts to the Netapp. As these databases are largely obsolete in our environment and the fact that we find iscsi management very inflexible - we decided we would move to cifs.

We thought this would be an easy change - oh how we were wrong!

It seems that Microsoft has decided with sqlserver that you cannot use remote mounts, ie cifs, with its product!

The filesystem browser, ie choosing a backup destination, does not see the mapped drive at all.

Yet another reason why I much prefer Oracle over sqlserver! Good job most of our stuff is on oracle!

Sqlserver fail!

Thursday, 17 February 2011

Adding virtual hard disk to SUSE VM on Vmware without reboot

So you need to add an additional hard disk to your VM running the SUSE family of operating system, but its in production and you can not reboot it.

So how do you go about it?

Well, it is rather easy!

First, open the "edit settings" window, within the vm, either from the console menu, or by right clicking in the vm through the virtual infrastructure client. Add a hard disk and configure it with the size you require. Finally accept the changes and close the window. After a few seconds, the virtual infrastructure client will shown the reconfiguration being complete.

Now logon to the operating system of the vm, as the root user - or use sudo.

You will see that the vm does not see the new disk, ie running the command:

fdisk -l

Shows only the existing disks, there is no sign of the new one.

What we need to do is, re-scan the SCSI bus, without rebooting the vm. To do this run the following command:

echo "- - -" >/sys/class/scsi_host/host#/scan

Where the # is replaced with the SCSI host value, usually 0

Now we re-run the command:

fdisk -l

We can now see our additional disk and can carry on configuring it using the usual tools, I.e. fdisk and mkfs or partitioner through yast, etc