- 定積分
- 平方完成
- 二次方程式の解び公式の証明(平方完成による)
2023年1月9日月曜日
自己啓発的にブログの再開
2016年8月21日日曜日
左目が網膜剥離に…
2013年4月13日土曜日
ORADIM -shutdown がエラーになる。
いつからか、WindowsXp にインストールしたOracle Database を oradim で停止をさせようとするとエラーが発生していた。
調べて対応するのが面倒だったので「サービス」で停止させて対応していた。
C:\Documents and Settings\HOGE>oradim -shutdown -sid ora01 ORA-01031: 権限が不足しています。
原因は、ORACLE_HOMEが設定されていなかったためでした。
C:\Documents and Settings\HOGE>SET ORACLE_HOME="C:\oracle\product\10.2.0\db_1" C:\Documents and Settings\HOGE>oradim -shutdonw -sid ora01
9i~11gまでのクライントをインストールしてあり、かつdbも9i~11gまで何度か入れ替えたあげくに現在の10gをテスト用DBとしてインストールしてある。
本当は、9iのDBをインストールしたかったのですが、OTNのサイトでは既に入手できなくなってしまっていたので10gをインストールしたという経緯がありますね...
異なるバージョンをいろいろとインストールして動作させるために、事前にORALCE_HOMEを設定しない方法を取っていたことが原因でしたね。
2013年2月17日日曜日
『世界基準で夢をかなえる私の勉強法』
昨日の日経新聞に載っていた本に興味が湧いたので早速アマゾンで注文し本日届きました。
幻冬舎『世界基準で夢をかなえる私の勉強法』北川智子・著
『ハーバード白熱日本史教室』がベストセラーとなった北川智子さんの最新刊です。
読み終えて参考になった事は
-
自分にあった勉強法
→メモを取らない記憶法...記憶の定着方法(記憶の反芻)
メモは最小限にとどめ、分かることはノートに書かず、わからない事をカンペ方式で短くメモにする
-
タイムマネジメント
(フルに勉強する4日間と楽しい3日間) -
モチベーション(動機付け)の維持方法
(パッションカーブ) - Positive Thinking(自分の強みと弱みを見極める)
当然ながら、書かれている内容のほとんどが参考になる内容であるのですが、「パッションカーブ」については特にうなずけました。
プロジェクトへの期待にワクワクしている状態(イヤなプロジェクトはどうするんだ?)では、心から湧き出る「情熱」がプロジェクトを進めてくれる。ここで、全体の目鼻立ちがつく程度の仕事をこなしておくようにする。
最初の1行の殺し文句を考えていても、始まらない。2段落目以降で立ち止まっても意味がない。大まかな構図をスケッチするように、とにかく、話を進めることに全身全霊をそそぐ。突っ走って全体像を書く。そして、疲れたら無理をせずいったん休む。
休憩したらもう一度、パッションカーブを見直す。
- どんなプロジェクトでも
- どう休むか
- 休んだ後にどうやって奮起点を決めるか
- どんなモチベーションで望むか
2012年12月19日水曜日
「世界で通用する人がいつもやっていること」
J-WAVEで12月9日と12月16日のゲスト講師でお話をされた中野信子さんの話を聞いて早速ラジオで話していた本をアマゾンに注文して読んでみた。
「世界で通用する人がいつもやっていること」を12月16日の放送終了後にアマゾンで注文すると早速当日の夜に届いた。ページ数や1ページあたりの文字数も少ないので、移動時や昼食時に読むことにした。(3日で読み終えた)
先々週によんだ本と似ている部分が多かったためか、大変わかりやすくすぐに読み終えた。
「本を先生だと思えば、先生は選び放題」
自分を理解することや自分の脳をいかにして活性化させるかを著者および著者の友人の体験談で解説しており、なるほどと思わせてくれる点が多い。
中には、私もすでに実行している事も多々掲載されていて、自分の実行してきたことにも自身が持て、本でも記載されている自分を褒める(鼓舞する)、自分を追い込む(わざとストレスを与えて集中力を高める)ことの重要性を再認識。
相対的には、先々週に読んだ「スタンフォードの自分を変える教室」で自分の脳がどのような仕組みで反応するしているかを脳が報酬システム(「社会的報酬システム」「金銭的報酬システム」)や自己監視や意志力について学んでいたので、やさしく復讐するといった感じでよめた。
2012年11月30日金曜日
「スタンフォードの自分を変える教室」
日経新聞に載っているのを見て読みたくなったので、アマゾンで注文して読んだ。
なりたい自分になるために、「いかに自分の潜在能力を引き出すか」を具体的な事例(実験と検証)をもとにわかりやすくかかれています。
自分の脳の特性(機能・使い方・使うタイミング・時間帯)を理解して、いかに自分をコントロールしていくかが書かれています。
「やる力」「やらない力」「望む力」
注意力や感情や行動をいかにコントロールできるか? ・・・「意志力」が決め手となる。
脳には、思考、感情、行動のそれぞれをコントロールしようとする複数の自己がいる。
意志力の本能
意志力は、ストレスと同様、自分自身から身を守るために発達した生物的な本能である。
- 【注目】
- なぜ「やりたくないこと」をしてしまうのか?
- 自分の意志力のチャレンジにおいて、抑制すべき内的な衝動は何なのかを明らかにする。
- ストレスでいかに自制心が落ちるかを試す
- 1日や1週間のうちでどんなときにストレスを感じるかを考えてみる。それは、自己コントロールにどのように影響を与えているか? 欲求を感じたり、かっとなったり、やるべき事を後回しにしたりしていないか。
- 【意志力の実験】
- 呼吸を遅らせれば自制心を発揮できる
- 呼吸の数を1分間に4回から6回程度に減らし、整理機能を自己コントロールに適切な状態にもっていく。
- グリーン・エクササイズで意志力を満タンにする
- 外へ出て活動しましょう──近所を5分間歩き回るだけでもOK──ストレスが減り、気分も明るくなり、モチベーションもアップします。
- 眠りましょう
- 昼寝をしたり、ひと晩ぐっすり眠ったりして、睡眠不足の悪影響を解消する。
- 体にリラクゼーション反応を起こす
- 横になって深呼吸をすることで、生理学的リラクゼーション反応を起こします。それにより自己コントロールや日常のストレスによる疲労から体が回復するのを助けましょう。
2012年8月29日水曜日
CakePHP/SimpleTest
CakePHPでSimpleTestでテストを行っていたら、言われのないエラーを表示されて悩んでしまった。
SImpleTestで個別にテストケースを実行すると何も問題ないのだが、Test Groups の「All tests」を実行すると
Missing Database Table
Error: Database table テーブル名 for model モデル名 was not found.
表示されているテーブルとモデルは存在し、関連するテーブル(ここで表示されてテーブルを参照している)との関連も確認したが問題なかった。
SimpleTest の All Tests がおかしいのでは? との考えに至った。
実際に、ググるとSimpleTest の All Tests は挙動不審なので使わないほうが良いとの意見もあった。
2012年7月18日水曜日
CentOSでUPSの設定(apcupsd)
自宅のPCサーバー(Linux:CentOS)にUPSを付けることにした。
今までUPSをつけないでいたために、何台かPCのディスクを故障させてしまった。
一度の突然の電源断でもディスクが破壊される場合もあるが、何度も電源断があるとディスクのアクセスアームが磁気ディスク(円盤)を傷つけてしまう。
今年は、夏真っ盛りになる前にUPSを付けて停電・ブレーカー落ちに対応する。
購入したUPSは、APC RS550電源バックアップ(500VA) BR550G-JP です。
てっきり、Linux用のPowerChuteもCDに含まれていると思っていたら、なんとありませんでした。
APCのサイトでRPM版のPowerChuteが公開されていましたが、CentOSのリポジトリでapcupsd・apcupsd-gui・apcupsdーcgiがあるので、これをインストールする。
Unable to communicate with the UPS on 127.0.0.1.エラーで接続できない。SELinuxでエラーが吐き出されているので確認してみる。
アクセスを許可httpd がネットワークポートに接続するように設定する場合、httpd_can_network_network_connect boolean をオンにする必要があります: "setsebool -P httpd_can_network_connect=1"
次のコマンドがこのアクセスを許可します:
setsebool -P httpd_can_network_connect=1
追加情報
ソースコンテキスト: system_u:system_r:httpd_sys_script_t
ターゲットコンテキスト: system_u:object_r:apcupsd_port_t
ターゲットオブジェクト: None [ tcp_socket ]
Source: upsstats.cgi
Source Path: /var/www/apcupsd/upsstats.cgi
Port: 3551
Host: hoge
Source RPM Packages: apcupsd-cgi-3.14.10-1.el5
Target RPM Packages:
ポリシー RPM: selinux-policy-2.4.6-327.el5
Selinux 有効化: True
ポリシータイプ: targeted
MLS 有効化: True
強制モード: Enforcing
プラグイン名: httpd_can_network_connect
・
・
・
生の監査メッセージ :
host=ora02 type=AVC msg=audit(1342584417.76:293): avc: denied { name_connect } for pid=7159 comm="upsstats.cgi" dest=3551 scontext=system_u:system_r:httpd_sys_script_t:s0 tcontext=system_u:object_r:apcupsd_port_t:s0 tclass=tcp_socket
host=ora02 type=SYSCALL msg=audit(1342584417.76:293): arch=40000003 syscall=102 success=no exit=-13 a0=3 a1=bfba290 a2=3 a3=804eb20 items=0 ppid=3361 pid=7159 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 tty=(none) ses=4294967295 comm="upsstats.cgi" exe="/var/www/apcupsd/upsstats.cgi" subj=system_u:system_r:httpd_sys_script_t:s0 key=(null)
早速、指示通りに # setsebool -P httpd_can_network_connect=1 を実行すると...
2012年7月17日火曜日
SELinux覚書き(httpd_can_network_connect)
SELinuxのこまごまとした点についての覚書き
- httpd_can_network_connect
WEBサーバからDBサーバへアクセスするプログラムをPHPで作成したが、アクセスできない現象が発生- 原因
WEBサーバのSELinuxのhttpd_can_network_connectが無効となっていた - 対処
# setsebool -P httpd_can_network_connect 1 - 確認
# getsebool httpd_can_network_connect
httpd_can_network_connect --> on
- 原因
2012年7月15日日曜日
CentOS Firefox最新版のインストール
CentOSの自動更新では、firefoxの最新版はインストールされないので手動で最新版をインストールするための覚書き。
※CentOSの自動更新ではかなりふるいバージョンになってしまう。
一度最新版をインストールしたら、その後は firefox から(rootで)最新版に更新ができるが、12.0あたりになってから firefox の起動時に下記のエラー(kernel: 4gb seg fixup, process firefox)がでるようになったので、最新版のインストールを再度実行して確認することとした。
Jul 15 20:16:14 hoge kernel: 4gb seg fixup, process firefox (pid 8118), cs:ip 73:00401cef
■ firefoxの最新版をダウンロードする。(http://www.mozilla.jp/firefox/)
ダウンロードした tarボール を展開する。
# tar jxfv firefox-13.0.1.tar.bz2
展開された firefox をディレクトリごと移動します。
# mv firefox /usr/lib/firefox-13.0.1
/usr/bin にシンボリックリンクを貼ります。
# ln -s /usr/lib/firefox-13.0.1/firefox /usr/bin
2012年7月10日火曜日
SELinux ラベルの変更
httpd で公開フォルダを追加した時についつい忘れて手間取ってしまうのが、SELinuxのラベルの貼り替えです。
SELinuxで運用しているとフォルダや作成した時には、作成先に見合うラベルを設定する必要があります。
通常は、restorecon -R コマンドで親フォルダの情報が引き継がれると思っていたのですが、単純に引き継がれる訳でないようです。(詳細は未確認(未調査)です。)
よって、作成したフォルダに正しいラベルを設定するという事が必要になります。
# chcon system_u:object_r:httpd_sys_content_t /home/www -R # chcon system_u:object_r:httpd_sys_script_exec_t /home/www/cgi-bin -R
2012年6月27日水曜日
xdebugでwarningがでる。
xdebugが有効かどうか確認すると下記のようなwarningがでる。
[root@hoge ~]# php -i | grep -i "xdebug support" PHP Warning: Xdebug MUST be loaded as a Zend extension in Unknown on line 0 xdebug support => enabled [root@hoge ~]#
■/etc/php.ini extension=xdebug.so ↓ コメントアウト ;extension=xdebug.so ■/etc/php.d/xdebug.ini zend_extension=/usr/lib/php/modules/xdebug.so xdebug.remote_enable=On xdebug.remote_connect_back=On xdebug.remote_autostart=On xdebug.remote_handler=dbgp xdebug.remote_port=9000 xdebug.collect_params=On xdebug.dump.GET=* xdebug.dump.POST=*
extensionをzend_extensionに変更し、リモートの設定を追加した。(リモートデバッグを行うため)
また、xdebug.remote_connect_back=On を設定して複数のクライアントからリモートデバッグが実行できるようにした。
「xdebug.remote_connect_back」は。xdebug 2.1以降で利用できる。
apacheを再起動して設定が有効になったか確認する [root@hoge ~]# php -i | grep xdebug /etc/php.d/xdebug.ini, xdebug xdebug support => enabled xdebug.auto_trace => Off => Off ・ ・ xdebug.remote_autostart => On => On xdebug.remote_connect_back => On => On xdebug.remote_cookie_expire_time => 3600 => 3600 xdebug.remote_enable => On => On xdebug.remote_handler => dbgp => dbgp xdebug.remote_host => localhost => localhost xdebug.remote_log => no value => no value xdebug.remote_mode => req => req xdebug.remote_port => 9000 => 9000 ・ ・ ・
2012年6月25日月曜日
CakePHP 複数アプリの実行
CakePHP で複数アプリを実行する。 1. virtual host を設定して複数アプリを別々ホスト名で起動する。 2. .htaccess を修正する。(忘れがちなので注意)
[root@hoge sample]# cat .htaccessRewriteEngine on RewriteRule ^$ app/webroot/ [L] RewriteRule (.*) app/webroot/$1 [L] [root@hoge sample]# ↓↓↓RewriteEngine on RewriteRule ^$ webroot/ [L] RewriteRule (.*) webroot/$1 [L]
サブディレクトリにcakePHPを構築する
もしサブドメインに構築する場合には、.htaccessの設定に追記が必要となる。
具体的には、RewriteBaseをきちんと設定にあるような
app/webroot/.htaccess にあるmod_rewriteの設定において RewriteBase /(サブディレクトリ名)を追加する必要がある。
もし、追加し忘れると、500 Internal Server Errorが表示され、Apacheのログには、
Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
というメッセージが記録される。今までDocumentRoot上にしか構築したことがなかったので、少しハマってしまった。
2012年6月24日日曜日
Samba+OpenLDAP(PDC) ユーザー設定について
Samba+OpenLDAP(PDC) を運用したときのユーザーの登録について記載します。
まず先に結論から申し上げると作成済みのユーザー(Linuxアカウント)に Samba+OpenLDAP(PDC) のドメインにログオンできるようにするには、下記の2つのコマンドを実行する必要があります。
(前提条件として下記が設定済みである)
・Samba および OpenLDAPがPDC対応で正しくインストールされている。
・作成済みのユーザー(Linuxアカウント)がldapaddコマンド等でLDAPに登録済み。
・ログオンするPCのコンピュータ名が smbldap-useradd -w <コンピュータ名> で登録済み
[root@hoge ~]# smbldap-usermod -a <作成済みLinuxアカウント> [root@hoge ~]# smbldap-passwd <作成済みLinuxアカウント>
今回は、Linuxユーザーとして作成済みのユーザーをSamba+OpenLDAP(PDC)のユーザーとして登録(再設定するための方法)記載します。
※基本的な設定については、別途記載することにします。
■変更前の設定内容■
[root@hoge ~]# smbldap-usershow pelo
dn: uid=pelo,ou=Users,dc=hogehoge,dc=com
uid: pelo
cn: pelo
objectClass: account,posixAccount,top
userPassword: {SSHA}*******************************
loginShell: /bin/bash
uidNumber: 3002
gidNumber: 3002
homeDirectory: /home/pelo
[root@hoge ~]#
Windowsクライアントからログインできるユーザーは下記のようになっています。
比較すると、samba専用のアトリビュートが作成されていないことがわかります。
[root@hoge ~]# smbldap-usershow knownuser dn: uid=knownuser,ou=Users,dc=hogehoge,dc=com uid: knownuser cn: knownuser objectClass: account,posixAccount,top,shadowAccount,sambaSamAccount shadowMin: 0 shadowWarning: 7 loginShell: /bin/bash uidNumber: 500 gidNumber: 500 homeDirectory: /home/knownuser gecos: Known User shadowLastChange: 15462 shadowMax: 45 sambaSID: S-1-5-21-2725434548-1602857623-2035637331-1001 displayName: Known User userPassword: {SSHA}******************************* sambaNTPassword: ******************************* sambaPasswordHistory: 0000000000000000000000000000000000000000000000000000000000000000 sambaPwdLastSet: 1335947382 sambaAcctFlags: [U ] [root@hoge ~]#
既に作成済みのユーザーについてsamba専用のアトリビュート情報の追加を行うには、smbldap-usermod の -a オプションで実行する必要があることがわかりました。
善は急げで、早速実行します。
[root@hoge ~]# smbldap-usermod -a pelo Warning: sambaPrimaryGroupSID could not be set beacuse group of user pelo is not a mapped Domain group! To get a list of groups mapped to Domain groups, use "net groupmap list" on a Domain member machine. Use of uninitialized value in string at /usr/sbin/smbldap-usermod line 346. Use of uninitialized value in string eq at /usr/sbin/smbldap-usermod line 347. Use of uninitialized value in string eq at /usr/sbin/smbldap-usermod line 347. Use of uninitialized value in string eq at /usr/sbin/smbldap-usermod line 347. Use of uninitialized value in concatenation (.) or string at /usr/sbin/smbldap-usermod line 347. [root@hoge ~]#
アレレ?。
何やら、嫌らしいエラーメッセージが表示されてしまいました。
usr/sbin/smbldap-usermod の346行目と347行目を確認しましたが、影響なさそうなので無視して先へ進むことにします。
$cn = "$Options{'N'}";
$cn .= " " . $Options{'S'}
smbldap-usermodコマンドの実施後に内容が変わったかどうかを検証します。
[root@hoge ~]# smbldap-usershow pelo
dn: uid=pelo,ou=Users,dc=hogehoge,dc=com
uid: pelo
objectClass: account,posixAccount,top,shadowAccount,sambaSamAccount
userPassword: {SSHA}zrb5IhKHtVErK8rdx/e0pqtG4kJ0ES29
shadowLastChange: 15476
shadowMin: 0
shadowMax: 99999
shadowWarning: 7
loginShell: /bin/bash
uidNumber: 3002
gidNumber: 3002
homeDirectory: /home/pelo
sambaPwdLastSet: 0
sambaLogonTime: 0
sambaLogoffTime: 2147483647
sambaKickoffTime: 2147483647
sambaPwdCanChange: 0
sambaPwdMustChange: 2147483647
sambaSID: S-1-5-21-2725434548-1602857623-2035637331-7004
sambaAcctFlags: [UX]
cn:
displayName:
[root@hoge ~]#
上記の赤字と青字の部分が追加されていることを確認できます。
しかし、青字のアトリビュートは未設定のようです。
cn は氏名(Common Name)を設定するアトリビュートで、displayName もWindowsで利用される氏名を設定するアトリビュートのようです。
→→→ ■OpenLDAPの基本的なアトリビュートについて■
上記の内容でWindows7クライアントからドメインにログオンを行ってもまだエラーになってしまいます。
ログオンできるユーザーとの違いを確認したらsambaのパスワード関連のアトリビュートがないようです。(sambaLMPassword,sambaAcctFlags,sambaNTPassword,,,)
よって、再度パスワードを再設定するコマンド(smbldap-passwd)を実行してパスワードを上書きします。
↓
今度は無事にWindows7クライアントからドメインにログオンできました。
赤字の部分が smbldap-passwd を実行した結果に追加されたアトリビュートです。
[root@hoge ~]# smbldap-usershow pelo
dn: uid=pelo,ou=Users,dc=hogehoge,dc=com
uid: pelo
objectClass: account,posixAccount,top,shadowAccount,sambaSamAccount
shadowMin: 0
shadowWarning: 7
loginShell: /bin/bash
uidNumber: 3002
gidNumber: 3002
homeDirectory: /home/pelo
sambaLogonTime: 0
sambaLogoffTime: 2147483647
sambaKickoffTime: 2147483647
sambaPwdCanChange: 0
sambaSID: S-1-5-21-2725434548-1602857623-2035637331-7004
cn:
displayName:
sambaLMPassword: *******************************
sambaAcctFlags: [U]
sambaNTPassword: *******************************
sambaPwdLastSet: 1340506248
sambaPwdMustChange: 1344394248
userPassword: {SSHA}*******************************
shadowLastChange: 15515
shadowMax: 45
[root@hoge ~]#
2012年6月23日土曜日
smbldap-usershow コマンドがエラーになる。
Samba+OpenLDAPでのユーザー情報を確認しようとsmbldap-usershowコマンドを実行したらエラーになってしまった。
[root@hoge ~]# smbldap-usershow hogehoge Use of uninitialized value in string at /usr/lib/perl5/vendor_perl/5.8.8/smbldap_tools.pm line 397. Use of uninitialized value in string at /usr/lib/perl5/vendor_perl/5.8.8/smbldap_tools.pm line 397. user hogehoge doesn't exist
smbldap_tools.pm の397行目を確認したら、 $ldap_slave->bind( "$config{slaveDN}", password => "$config{slavePw}" ); となっていた。
slaveDNの設定に問題があるようなので、確認をすると下記の対応でエラーが解消された。
■ /etc/smbldap-tools/smbldap_bind.conf ■ # $Id: smbldap_bind.conf 35 2011-02-23 09:07:36Z fumiyas $ # ############################ # Credential Configuration # ############################ # Notes: you can specify two differents configuration if you use a # master ldap for writing access and a slave ldap server for reading access # By default, we will use the same DN (so it will work for standard Samba # release) slaveDN="cn=Manager,dc=hogehoge,dc=com" <-- 追加 slavePw="****************" <-- 追加 masterDN="cn=Manager,dc=hogehoge,dc=com" masterPw="****************"
Samba+OpenLDAPを特にスレーブサーバを立てていないのでslaveの設定は不要と思っていたが、このslaveの記述がないとエラーになってしまうようでした。
なんだか良く理解できないが、コマンドが実行できるようになったので安心した。
2012年6月22日金曜日
SELinux基本コマンドの備忘録
● SELinux の基本コマンド ◆ls オプションに -Z をつければ、ポリシー・タイプを表示することができます。 # ls -Z ◆chcon ファイルやディレクトリのタイプを一時的に変更します。 # chcon -t samba_share_t /var/smb -R -u でユーザ、-r でロールを変更できる。 この例では、/var/smb ディレクトリ以下のディレクトリとファイルすべてのポリシー・タイプを samba_share_t に変更しています。 ◆restorecon ポリシー・タイプの不整合を修正します。 # /sbin/restorecon -RF /var/smb -Rは再帰的に適用、-Fは強制的に適用します。 (強制でないと変わらないときがある) ◆setsebool 各booleanパラメータを変更します。 # setsebool -P allow_smbd_anon_write 1 -Pオプションは、システムを再起動しても設定を反映するようにする。 ◆semanage ファイルに関するタイプのほか、ポートに対するタイプも変更可能なコマンドです。chcon では file_contexts ファイル内の内容は変更できないので、yum update などでポリシーをアップデートした場合は変更内容が消えてしまいます。semanage では file_contexts ファイルの内容を書き換えるのでそのような問題は起きません。 # semanage fcontext -a -t samba_share_t "/var/smb/(/.*)?" ・設定内容を反映させるには restorecon コマンドを使います。 # restorecon -RF /var/smb ・設定内容を削除するには -a の代わりに -d を使用します。 # semanage fcontext -d -t samba_share_t "/var/smb/(/.*)?" # restorecon -RF /var/smb ・ポートに対するタイプを見るには # semanage port -l ・Apache に TCP 8080 番ポートを使えるようにさせるには # semanage port -a -t http_port_t -p tcp 8080 ポートの場合は即座に設定が反映されます。
● booleanパラメータの調整とトラブルの回避
ポリシーを変更せずにトラブルを解決したり,セキュリティ・レベルを調整したりするのに役立つのが,booleanパラメータです。booleanパラメータを切り替えて,不要なアクセス許可を与えないようにしていけば,セキュリティを高められます。逆に,必要なアクセス許可をbooleanパラメータの切り替えで設定可能な場合は,トラブル解決にも役立ちます。
- Apacheが他のアプリケーションに接続できない
【解決法】 httpd_can_network_connectをonにする - Sambaのホームディレクトリを公開できない
【解決法】 samba_enable_home_dirsをonにする - Javaアプリケーションが動かない
【解決法】 allow_execmodをonにする - ログにexecmod、execstackのアクセス拒否が出力される
【解決法】 allow_execmod/allow_execstackをonにする
《具体的な設定例》
「Sambaでホーム・ディレクトリを公開できない」という問題を「samba_enable_home_dirs」のon/offを切り替えて対処してみましょう。
- samba_enable_home_dirsを次のようにonに切り替えます。
# setsebool -P samba_enable_home_dirs 1
- onに切り替わったことを確認します。
# getsebool samba_enable_home_dirs
samba_enable_home_dirs -->on
2012年6月21日木曜日
SELinux問題を解決する際に理解するトップ3
SELinux問題を解決する際に理解するトップ3について(Dan Walshさんの記事)記載されていので掲載します。
私もほとんど、ここで記載されている件で解決をしましたが、頻繁に発生する訳ではないのでついつい作法を忘れてしまいます。そこで、Dan Walshさんの記事を掲載して備忘録をして書き留めることにしました。
1. SELinux is all about labeling
Every process and object on the machine has a label associated with it, if your files are not labeled correctly access might be denied.
If a file is mislabeled a confined application might not be allowed access to the mislabeled file. If an executable is mislabeled, it may not transition to the correct label when executing, causing access violations and potentially causing it to mislabel files it creates. Processes and objects on the machines have labels. If the labeling is correct everything should work. Sometimes an admin decides to change the default labeling on the system. If an admin wants to store apache web pages in a unusual location, /srv/myweb. The admin needs to tell SELinux that the files stored there need to be accessible to the web server process. He does this by setting the labeling correctly in the system. The apache process is allowed to access files labeled httpd_sys_content_t.
# semanage fcontext -a -t httpd_sys_content_t '/srv/myweb(/.*)?'
This command tells the SELinux datastore that the /src/myweb directory and all files under it should be labeled httpd_sys_content_t. Tools like restorecon and rpm read this datastore when they are labeling or relabeling files. Note, however that the semanage command will not change the actual labels on files on your machine. You still need to execute restorecon to fix the labels.
# restorecon -R /srv/myweb
restorecon reads the SELinux datastore to determine how files under /srv/myweb should be labeled and then fixes them.
# matchpathcon /srv/myweb
matchpathcon reads the SELinux datastore and prints the default label for the specified path
2. You have to tell SELinux about how a confined process is being run.
A confined process/application can be run in many different ways. You need to tell SELinux about how you are configuring the application to run, so SELinux will allow it the proper access. SELinux does not do this automatically, SELinux has builtin if/then/else rules called booleans that allow you to tweak the predefined rules to allow different access. If you set up you apache web server to talk to a mysql server, you need to set a boolean to tell SELinux this is ok. You can do this with the setsebool command.
# setsebool -P httpd_can_network_connect_db 1
Tools like system-config-selinux or getsebool -a will list all of the possible booleans. On the latest Fedora systems you can run SELinux error messages (avc) through audit2allow -w (audit2why). This checks to see if any boolean could be set to allow the access.
setroubleshoot is also pretty good at diagnosing problems.
3. SELinux rules are evolving and applications are sometimes broken
General errors in policy or applications can cause SELInux access denials. Sometimes an application is just broken or the SELinux policy has never seen the confined application run the code path that it is running. While the application is working correctly, SELinux is denying it access. You can add custom policy to your system simply by piping the SELinux error messages through audit2allow. Say a new version of postgresql comes out that SELinux is mistakenly denying access to a resource which it should be allowed to access. You can use audit2allow to build a custom policy module that can be installed on your system to allow the access.
# grep postgresql /var/log/audit/audit.log | audit2allow -R -M mypostgresql
This command will generate a local policy module which will allow all accesses that are currently being denied..
# semodule -i mypostgresql.pp
This command installs the local policy modifications to your system. You probably want to report the SELinux errors to bugzilla or a mailing list so your local modifications can be added to the distribution's policy or upstream.
2012年6月19日火曜日
2012年6月10日日曜日
OEMが起動しなくなっていた。
久しぶりにLinuxマシンのOracle11gを起動したら、OEMを起動する部分でエラーが発生している。どうやら、リスナーやDBは起動しているようだ。
SAMBA+LDAP でPDCを作成するために、ドメインやホスト名を変更したことが原因のようです。
■Oracleを起動するとOEMの起動部分でエラーが発生。
[root@hoge ~]# service dbora start
Starting Oracle Database:Processing Database instance "ora02": log file /opt/oracle/app/product/11.2.0/ora02/startup.log
OC4J Configuration issue. /opt/oracle/app/product/11.2.0/ora02/oc4j/j2ee/OC4J_DBConsole_ora02.horisawa.info_ora02 not found.
[oracle@hoge ~]$ echo $ORACLE_SID ora02 [oracle@hoge ~]$ emca -config dbcontrol db -repos recreate EMCAの開始 2012/06/10 17:27:11 EM Configuration Assistant, リリース11.2.0.0.2 Production Copyright (c) 2003, 2005, Oracle. All rights reserved. 次の情報を入力してください: データベースのSID: hoge リスナーのポート番号: 1521 リスナーORACLE_HOME [ /opt/oracle/app/product/11.2.0/hoge ]: SYSユーザーのパスワード: DBSNMPユーザーのパスワード: SYSMANユーザーのパスワード: 通知用の電子メール・アドレス (オプション): 通知用の送信メール(SMTP)サーバー (オプション): ----------------------------------------------------------------- 次の設定が指定されています データベースのORACLE_HOME ................ /opt/oracle/app/product/11.2.0/hoge ローカル・ホスト名 ................ hoge.hogehoge.com リスナーORACLE_HOME ................ /opt/oracle/app/product/11.2.0/hoge リスナーのポート番号 ................ 1521 データベースのSID ................ hoge 通知用の電子メール・アドレス ............... 通知用の送信メール(SMTP)サーバー ............... ----------------------------------------------------------------- 続行しますか。 [はい(Y)/いいえ(N)]: y 2012/06/10 17:29:19 oracle.sysman.emcp.EMConfig perform 情報: この操作は/opt/oracle/app/cfgtoollogs/emca/hoge/emca_2012_06_10_17_27_10.logでロギングされています。 2012/06/10 17:29:20 oracle.sysman.emcp.EMReposConfig invoke 情報: EMリポジトリの削除中(少し時間がかかります)... 2012/06/10 17:32:39 oracle.sysman.emcp.EMReposConfig invoke 情報: リポジトリは正常に削除されました 2012/06/10 17:32:40 oracle.sysman.emcp.EMReposConfig createRepository 情報: EMリポジトリの作成中(少し時間がかかります)... 2012/06/10 17:43:24 oracle.sysman.emcp.EMReposConfig invoke 情報: リポジトリは正常に作成されました 2012/06/10 17:43:34 oracle.sysman.emcp.EMReposConfig uploadConfigDataToRepository 情報: 構成データをEMリポジトリにアップロード中(少し時間がかかります)... 2012/06/10 17:46:01 oracle.sysman.emcp.EMReposConfig invoke 情報: 構成データが正常にアップロードされました 2012/06/10 17:46:07 oracle.sysman.emcp.util.DBControlUtil configureSoftwareLib 情報: ソフトウェア・ライブラリは正常に構成されました。 2012/06/10 17:46:07 oracle.sysman.emcp.EMDBPostConfig configureSoftwareLibrary 情報: プロビジョニング・アーカイブのデプロイ中... 2012/06/10 17:47:02 oracle.sysman.emcp.EMDBPostConfig configureSoftwareLibrary 情報: プロビジョニング・アーカイブは正常にデプロイされました。 2012/06/10 17:47:02 oracle.sysman.emcp.util.DBControlUtil secureDBConsole 情報: Database Controlの保護中(少し時間がかかります)... 2012/06/10 17:48:25 oracle.sysman.emcp.util.DBControlUtil secureDBConsole 情報: Database Controlは正常に保護されました。 2012/06/10 17:48:25 oracle.sysman.emcp.util.DBControlUtil startOMS 情報: Database Controlの起動中(少し時間がかかります)... 2012/06/10 17:49:38 oracle.sysman.emcp.EMDBPostConfig performConfiguration 情報: Database Controlは正常に起動されました 2012/06/10 17:49:39 oracle.sysman.emcp.EMDBPostConfig performConfiguration 情報: >>>>>>>>>>> Database ControlのURLはhttps://ora02.horisawa.info:5500/emです <<<<<<<<<<< 2012/06/10 17:49:50 oracle.sysman.emcp.EMDBPostConfig invoke 警告: ************************ WARNING ************************ 管理リポジトリは、Enterprise Managerデータが暗号化されるセキュア・モードで配置されています。暗号化キーはファイル/opt/oracle/app/product/11.2.0/ora02/hoge.hogehoge.com_ora02/sysman/config/emkey.oraに配置されています。このファイルが失われると暗号化データを使用できなくなるため、このファイルは必ずバックアップしてください。 *********************************************************** Enterprise Managerの構成が正常に完了しました EMCAの終了 2012/06/10 17:49:50 [oracle@hoge ~]$
■設定変更後は問題なく起動した。
[root@ora02 ~]# service dbora start
Starting Oracle Database:Processing Database instance "ora02": log file /opt/oracle/app/product/11.2.0/ora02/startup.log
Oracle Enterprise Manager 11g Database Control Release 11.2.0.1.0
Copyright (c) 1996, 2009 Oracle Corporation. All rights reserved.
https://ora02.horisawa.info:5500/em/console/aboutApplication
Starting Oracle Enterprise Manager 11g Database Control ......... started.
------------------------------------------------------------------
Logs are generated in directory /opt/oracle/app/product/11.2.0/ora02/ora02.horisawa.info_ora02/sysman/log
[root@ora02 ~]#
再構築すると、 Enterprise Managerのポート番号が変わる。
元のポート番号(デフォルト:1158)に変更したい場合は、下記のようにする。
[oracle@hoge ~]$ emca -reconfig ports -DBCONTROL_HTTP_PORT 1158
2012年6月1日金曜日
CentOSで最新版のFirefoxを実行する。
自宅のマシンとなるとユーザーの追加はめったにないので、ついつい忘れがちなユーザーの個別設定について書き留めておきます。(備忘録)
CentOSでは、Firefoxがデフォルトでインストールされていますが、インストールされているバージョンがかなり古い。やはり、最新のバージョンでブラウズしたいのでFirefoxの最新版をインストールしたあとのユーザーごとの個別設定を忘れてしまい手間取ったりします。
最新版のFIrefoxの起動設定
(例)
最新版のFireFoxインストール先:/opt/firefox/firefox
■Gnomeデスクトップにブラウザの起動設定を行う。
メニューバー上の[システム]->[設定]->[他の個人設定]から'お気に入りのアプリ'を選択します。
ウエブ・ブラウザのプルダウンメニューを firefox から その他 に
コマンド を /opt/firefox/firefox %s に変更
ユーザーを追加した時に、ブラウザが古いぞ! を慌ててしまうので書き留めておくことにしました。

