Apache with mpm-worker + PHP 5 + SSL + MySQL 4.1

Post date: June 5, 2005, 22:06 Category: Network
Tutorial quote: We can do Apache 2 with mpm-worker with PHP 5, along with SSL and MySQL 4.1. I tested my configuration with Apache 2.0.53, PHP 5.0.4, and MySQL 4.1.11.

How to set up the SUSE Linux Virtual I/O Server

Post date: May 28, 2005, 00:05 Category: Network
Tutorial quote: Reduce your operation costs for complex environments by creating efficient and flexible virtualisation capabilities. Nigel Griffiths describes the benefits of the IBM® POWER5™ servers and provides examples on how to set up the environment for pSeries®, p5, and eServer™ OpenPower systems.

Proftpd with mysql authentication, software qouta, traffic shaper and SSL

Post date: May 26, 2005, 17:05 Category: Network
Tutorial quote: A short, but detailed howto about installing ProFTPD with all the bells and whistles on Gentoo.

Creating a WebDAV server with apache2

Post date: May 26, 2005, 16:05 Category: Network
Tutorial quote: I needed a way to share information (both read and write) as easy as possible with friends in a quite restricted environment (firewall). In many cases, WebDAV which uses standard HTTP port 80 for comunication is a good solution for a file server application.

Three tools to help you configure iptables

Post date: May 25, 2005, 14:05 Category: Network
Tutorial quote: Every user whose client connects to the Internet should configure his firewall immediately after installation. Some Linux distributions include firewall configuration as a part of installation, often offering a set of defaults configurations to choose from. However, to ensure that your machine presents the minimum "attack surface" (a measure of the number of vulnerable ports, user accounts, and sockets exposed to attack) to the predatory inhabitants of the Internet, you may need to do some manual configuration of your firewall. Here are three tools that can help.
The Linux kernel (version 2.4 onwards) contains a framework for packet filtering and firewalling using netfilter and iptables. Netfilter is a set of hooks inside the Linux kernel that allows kernel modules to register callback functions with the network stack. Iptables is a generic table structure for the definition of rulesets. Each rule within an IP table consists of a number of classifiers (iptables matches) and one connected action (iptables target). Iptables has extensive documentation that can be accessed online or by typing man iptables at the command line. Yet despite the depth of the documentation available for iptables, its complexity can be baffling.

NFS over CIPE-VPN tunnels

Post date: May 23, 2005, 16:05 Category: Network
Tutorial quote: The Network File System (NFS) is a standard protocol for sharing file services with Linux and Unix computers. It is a distributed file system that enables local access to remote disks and file systems and is based on the client\server architecture. Although easy to configure, it is typically used only to transfer data over an intranet or LAN because of its transparency and security potholes when exposed to the risks of the Internet. However, it still can be employed -- without compromising security -- to share files over the Internet by configuring it to run on a Virtual Private Network (VPN) connection. This article will show you how to set up NFS to run over a CIPE-VPN connection between two Linux systems.

Encrypted NFS with OpenSSH

Post date: May 21, 2005, 19:05 Category: Network
Tutorial quote: NFS is a widely deployed, mature, and understood protocol that allows computers to share files over a network. The main problems with NFS are that it relies on the inherently insecure UDP protocol, transactions are not encrypted, hosts and users cannot be easily authenticated, and its difficulty in firewalling. This article provides a solution to most of these problems for Linux clients and servers. These principles may also be applied to any UNIX server with ssh installed. This article assumes basic knowledge of NFS and firewalling for Linux.

Transparent proxying with squid and pf

Post date: May 17, 2005, 08:05 Category: Network
Tutorial quote: squid is a caching web proxy, it's set up between web browsers and servers, fetching documents from servers on behalf of browsers. It can accelerate web access by caching frequently requested pages and serving them from its cache. It can also be used to filter pop-up ads and malware or to enforce access control (which clients may request what pages based on different authentication methods).

Traditionally, the proxy is an optional component, and browsers are configured to actively use the proxy. Transparent proxying means forcing all web traffic through the proxy without the cooperation (or knowledge) of the clients. Once all browser connections pass through the proxy, outgoing connections to external hosts can be restricted to the proxy, and direct connections from local clients can be blocked.

The OpenBSD packet filter (pf) can be used to redirect connections based on various criteria, including source and destination addresses and ports. For instance, one can redirect all TCP connections with destination port 80 (HTTP) that arrive through an interface connected to local workstations to a squid proxy running on a different address and port.

Setting up a Secure Subversion Server

Post date: May 17, 2005, 08:05 Category: Network
Tutorial quote: This article demonstrates how to create a secure repository using Subversion. The next installment will show how to train your users to access the repository using a GUI client.

Gentoo VSFTPD Howto

Post date: May 4, 2005, 18:05 Category: Network
Tutorial quote: This serves as an explicit guide as to how one goes about setting up a VSFTPD server on a Gentoo Linux computer. Though written for Gentoo, these instructions apply to other Linux distributions as well.
