<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>FuzzUx &#187; SBR600</title>
	<atom:link href="http://fuzzux.wordpress.com/category/SBR600/feed/" rel="self" type="application/rss+xml" />
	<link>http://fuzzux.wordpress.com</link>
	<description>An Excercise In Exploration and Experimentation with Open Source Technology</description>
	<lastBuildDate>Sat, 23 Apr 2011 02:24:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='fuzzux.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>FuzzUx &#187; SBR600</title>
		<link>http://fuzzux.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://fuzzux.wordpress.com/osd.xml" title="FuzzUx" />
	<atom:link rel='hub' href='http://fuzzux.wordpress.com/?pushpress=hub'/>
		<item>
		<title>0.3 Part Four/Conclusion.</title>
		<link>http://fuzzux.wordpress.com/2011/04/22/0-3-part-fourconclusion/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/22/0-3-part-fourconclusion/#comments</comments>
		<pubDate>Sat, 23 Apr 2011 02:23:34 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=115</guid>
		<description><![CDATA[So after the apparent issue with Hong Kong, I decided to take some time and develop an installation document, detailing the steps required to setup a Func infrastructure as part of my 0.3 delivery. This file can be found HERE &#8230; <a href="http://fuzzux.wordpress.com/2011/04/22/0-3-part-fourconclusion/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=115&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So after the apparent issue with Hong Kong, I decided to take some time and develop an installation document, detailing the steps required to setup a Func infrastructure as part of my 0.3 delivery.</p>
<p>This file can be found <a href="http://fuzzux.files.wordpress.com/2011/04/func-installation-guide.pdf">HERE</a></p>
<p><strong><span style="text-decoration:underline;">Conclusion</span></strong></p>
<p>During these past few weeks , I have learned that even what would be considered a minor change in infrastructure can have such a large impact on installations of software in a Linux environment. Different versions of python and other software can lead to unexpected instabilities or errors that all need to be considered.  Unfortunately due to these issues and the technical issues with Hong Kong, I did not get a chance to thoroughly test my newly packaged func, with the python modifications However; A significant amount of progress has otherwise been made. I have learned a great deal about func and certmaster and their operation in regards to PKI , certificate exchange and the establishment of Secure Sockets and XML RPC over HTTPS.</p>
<p><strong><span style="text-decoration:underline;">O.4? What? There is a 0.4?? Onward!!<br />
</span></strong></p>
<p>Over the semester I have become a big fan of func, and Linux Sysadmin tools, I would like and have already discussed my continuing work on this project, and helping CDOT develop a stronger centralized management strategy. My roadmap is the completion and succesful installation and deployment of func, and I would like to follow that with building on my previous colleagues work in the areas of Icinga and Puppet.</p>
<p>For my 0.4 my main goal is the testing of the packages I built for 0.3. After this stage is accomplished and I have reviewed and discussed it with Chris Tyler we can figure out how to manage to get it out there to all of the minions. I&#8217;m hoping to have the 0.4 up within the next two or three weeks, as testing and troubleshooting should be a fairly straightforward process. <strong></strong></p>
<p>I wanted to send a Thanks to Paul Whalen and Chris Tyler for the many extra hours the put in fixing up Hong Kong, and the great advice during the semester.</p>
<p>Stay Tuned Folks!!<strong><span style="text-decoration:underline;"><br />
</span></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/115/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=115&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/22/0-3-part-fourconclusion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>
	</item>
		<item>
		<title>0.3 Part Three</title>
		<link>http://fuzzux.wordpress.com/2011/04/22/0-3-part-three/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/22/0-3-part-three/#comments</comments>
		<pubDate>Sat, 23 Apr 2011 00:15:53 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=110</guid>
		<description><![CDATA[Continuing on our path of understating, the way certmaster and func work, is using a PKI or Public Key Infrastructure. Public Key encryption revolves around the generation of key pairs. Each participating party generates their own Private and Public key &#8230; <a href="http://fuzzux.wordpress.com/2011/04/22/0-3-part-three/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=110&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Continuing on our path of understating, the way certmaster and func work, is using a PKI or Public Key Infrastructure. Public Key encryption revolves around the generation of key pairs. Each participating party generates their own Private and Public key using a one way algorithm. Each party can distribute their public key to various computers in our case func clients send their keys to the Overlord machine.  In our case, Certmaster also signs the public keys sent by func. This generates trust between machines. In func&#8217;s case, it lies on top of the Certmaster infastructure utilizing the key-signing process done by this application.</p>
<p>Establishing of a &#8216;Secure Socket&#8217; (which is the trust and connection establishment that comes with SSL encryption) Revolves around the utilization of Public keys to encrypt data; and only their respective Public Key can decrypt data.</p>
<p>In both Func and Certmasters case, they use an XML based RPC (remote procedure calls) over HTTPS (HTTPS being our SSL communication) these calls are created in Python using the xmlrpclib module. Our error arises out of the newer version of func and certmasters handling of these calls using newer versions of Python , on our Honk Kong machine, we now run Python 2.7 which is the version of Python that ships by default with Fedora 15 , a change from what we were previously working with.</p>
<p>Creation and handling of the SSL connections are handled during the program installations on both certmaster and func, these files are respectively</p>
<p>/etc/func/overlord/sslclient.py  in func</p>
<p>and</p>
<p>/etc/certmaster/SSLConnection.py in certmaster.</p>
<p>The changes however are different;</p>
<p>After scouring the internet  I came across and open bug on func, here is the link to it:</p>
<p><a title="Func" href="https://bugzilla.redhat.com/show_bug.cgi?id=668208">Func Bug</a></p>
<p>The Following lines were removed and added to each file</p>
<p>/etc/func/overlord/sslclient.py</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/funcadd.png"><img class="aligncenter size-full wp-image-111" title="Func" src="http://fuzzux.files.wordpress.com/2011/04/funcadd.png?w=500&h=77" alt="" width="500" height="77" /></a></p>
<p>/etc/certmaster/SSLConnection.py</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/certadd.png"><img class="aligncenter size-full wp-image-112" title="certadd" src="http://fuzzux.files.wordpress.com/2011/04/certadd.png?w=500&h=45" alt="" width="500" height="45" /></a></p>
<p>Since I didn&#8217;t want to have to make these modifications every time I installed a new instance, So i decided to take a Source RPM, make the modification and repackage it. This would give me the opportunity to use the same RPM for every installation.</p>
<p>I built 4 instances of the same package,</p>
<p><a title="func" href="http://arm.koji.fedoraproject.org/koji/taskinfo?taskID=93354">FUNC- FC13 , NOARCH on ARM Koji</a></p>
<p><a title="Certmaster" href="http://arm.koji.fedoraproject.org/koji/taskinfo?taskID=93356">CERTMASTER- FC13 , NOARCH on ARM Koji</a></p>
<p><a title="Func" href="http://koji.fedoraproject.org/koji/taskinfo?taskID=3019818">FUNC- FC15 , NOARCH on the main Fedora Koji</a></p>
<p><a title="Certmaster" href="http://koji.fedoraproject.org/koji/taskinfo?taskID=3019814">CERTMASTER- FC15 , NOARCH on the main Fedora Koji</a></p>
<p>Here is a link to all of the RPMs I have built for my 0.3 and the system , feel free to use them anyway you can (NOTE as of 0.3 they are UNTESTED due to Hong Kong&#8217;s technical failure)</p>
<p><a title="http://matrix.senecac.on.ca/~tefurzer/packages/" href="http://matrix.senecac.on.ca/~tefurzer/packages/">http://matrix.senecac.on.ca/~tefurzer/packages/</a></p>
<p>Unfortunately, I had successfully completed my initial install of the func and certmaster, but when I went to install the final updated packages the rpm database had become corrupted (we think after a yum update). After having a talk with Paul Whalen we thought it best to leave it and wait for Chris Tyler to have a look at it , as something as important as the rpm is not something in the realm of my given authority to handle. The database went down at about 2pm on Thursday, and with Friday being a holiday it remains unavailable. As such, the progress on my 0.3 stopped before the second installation and my packages remain untested.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/110/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=110&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/22/0-3-part-three/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/funcadd.png" medium="image">
			<media:title type="html">Func</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/certadd.png" medium="image">
			<media:title type="html">certadd</media:title>
		</media:content>
	</item>
		<item>
		<title>0.3 Part Two</title>
		<link>http://fuzzux.wordpress.com/2011/04/22/0-3-part-two/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/22/0-3-part-two/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 05:33:43 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=107</guid>
		<description><![CDATA[Continuing the Installation Process Now that we have our two packages build and verified to work correctly on the ARM system we can continue with the Install process. Initially I had thought I would just have to install these new &#8230; <a href="http://fuzzux.wordpress.com/2011/04/22/0-3-part-two/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=107&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration:underline;">Continuing the Installation Process</span></p>
<p>Now that we have our two packages build and verified to work correctly on the ARM system we can continue with the Install process. Initially I had thought I would just have to install these new packages on the ARM machines , However; Hong-Kong has had some recent hardware problems and was upgraded to a Fedora 15 Beta Version , which meant the infrastructure I had previously set up was no longer available I thought (which was later proven very wrong) This was a good thing, as Certmaster was fairly easy to set up and Fedora 15 ships with the most current 0.27 version.</p>
<p>Following the steps I have outlined in the previous releases I installed func, and certmaster with YUM on Honk-Kong, after which I started the certmaster service.</p>
<p>Since I had completed two RPMs I needed a way to get them on to the ARM machine, This seemed an easy enough solution and I just SCPed them to my Matrix Account, Here are download links to the two completed RPMs</p>
<p><a title="Func" href="http://matrix.senecac.on.ca/~tefurzer/func-0.27-2.fc13.noarch.rpm">Func</a></p>
<p><a title="Certmaster" href="http://matrix.senecac.on.ca/~tefurzer/certmaster-0.27-2.fc13.noarch.rpm">Certmaster</a></p>
<p>Everything was going smoothy so far, was quite pleased.  However; When I woke up the next day I heard that Hong Kong, and connectivity to all of the ARM machines we&#8217;re not functional yet, and I could no longer connect to my 0-4 arm machine,  NFS was broken, as well as DHCP settings on Honk Kong, Paul was swamped with work and Chris Tyler was backed up with marking.  I managed to find one what was working (cdot-beaglexm-0-3) and since func leaves such a small footprint and does very little to the system I wasn&#8217;t too worried about using it.</p>
<p>I downloaded the two packages with the</p>
<p><span style="text-decoration:underline;">wget http://matrix.senecac.on.ca/~tefurzer/certmaster-0.27-2.fc13.noarch.rpm</span></p>
<p>and</p>
<p><span style="text-decoration:underline;">wget http://matrix.senecac.on.ca/~tefurzer/func-0.27-2.fc13.noarch.rpm</span></p>
<p>commands respectively.</p>
<p>I installed certmaster and then installed func using the rpm -ivh {package} command, and was given a dependency error on smolt, which was quickly resolved with a yum install.  After installing func, I went to start the service with the service funcd start.. and naturally the service started and died. Checking the func.log again, I noticed the same issue as my previous installation, so It appears that the newer version had not solved our problem for us. That was quite disappointing, and as of yet I am not extremely proficient with python and nowhere near talented enough to attempt to rewrite the erroneous code.</p>
<p>After adding the following lines:</p>
<p>minionname=cdot-beaglexm-0-3</p>
<p>listenaddr=192.168.1.103</p>
<p>to the /etc/func/minion.config file , the func daemon started succesfully. So at this point, I had two working services running. I went ahead and signed the certificate on the Overlord (Hong Kong) Server and attempted to run a simple func command. I was presented with this error</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/screenshot-2.png"><img class="aligncenter size-full wp-image-108" title="Error" src="http://fuzzux.files.wordpress.com/2011/04/screenshot-2.png?w=500&h=281" alt="" width="500" height="281" /></a></p>
<p>I had no idea what this error was, what it meant or why it was happening. This was a solid 3-4 hours trying to figure out what was wrong with it, Stay tuned tomorrow for the post on how I fixed it<span style="text-decoration:underline;"><br />
</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/107/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=107&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/22/0-3-part-two/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/screenshot-2.png" medium="image">
			<media:title type="html">Error</media:title>
		</media:content>
	</item>
		<item>
		<title>0.3 Part One</title>
		<link>http://fuzzux.wordpress.com/2011/04/21/0-3-part-one/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/21/0-3-part-one/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 04:50:22 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=99</guid>
		<description><![CDATA[Introduction So, proceeding from the conclusion of our 0.2 we need to look at fixing the issues we had with the previous installation of func-0.25-1. Toward the end of 0.2 I did mention the availability of a newer version of &#8230; <a href="http://fuzzux.wordpress.com/2011/04/21/0-3-part-one/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=99&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration:underline;">Introduction<br />
</span></p>
<p>So, proceeding from the conclusion of our 0.2 we need to look at fixing the issues we had with the previous installation of func-0.25-1. Toward the end of 0.2 I did mention the availability of a newer version of func, func-0.27-1. After talking with Chris Tyler, we decided it might be a good idea to attempt to install the newer version of func.</p>
<p>Our first step in this process was determining the availability of the package for ARM fedora, and whether this package was readily available. A quick search on the ARM koji site, and we can see that only 0.25 was built for the ARM. This means our next step is packaging and running our 0.27 build through the Koji Arm. The problem is, we currently don&#8217;t have the package source to build into our new RPM. We also needed to remove and clean the environment we previously had created to prepare for the newer verision</p>
<p><span style="text-decoration:underline;">Building Our New 0.27 Packages</span></p>
<p>So, what I did was go and grab the Package from the Fedora Main koji, I couldn&#8217;t find a func or certmaster version 0.27 built for fedora13 yet, so I grabbed one of the newer fedora 15 builds. After grabbing the newer distro build I simply edited the spec file, and increment the version by 1.</p>
<p>It&#8217;s worth noting that I initially tried to just build func and install it, this failed as they changed the build requires to specify that the newest version of certmaster must be present, which means I had to go and build both certmaster and func.</p>
<p>The spec files will be as follows.</p>
<ul>
<li><a href="http://fuzzux.files.wordpress.com/2011/04/certmaster.odt">Certmaster Spec</a></li>
<li><a href="http://fuzzux.files.wordpress.com/2011/04/func-2.odt">Func Spec </a></li>
</ul>
<p>After we complete editing our spec files, we need to make the RPM&#8217;s for the two programs this is accomplished by executing the following commands</p>
<p>rpmbuild -ba func.spec</p>
<p>rpmbuild -ba certmaster.spec</p>
<p>commands respectively.</p>
<p>Upon Successful build ( I did not encounter any problems building this this RPM) you should be greeted with an exit status of 0. As per the following two screenshots, these are what your finished build should look like</p>
<p>Func:</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/screenshot-1.png"><img class="aligncenter size-full wp-image-102" title="Func Build" src="http://fuzzux.files.wordpress.com/2011/04/screenshot-1.png?w=500&h=281" alt="" width="500" height="281" /></a></p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/screenshot-1.png"><br />
</a>Certmaster:</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/screenshot.png"><img class="aligncenter size-full wp-image-103" title="Certmaster" src="http://fuzzux.files.wordpress.com/2011/04/screenshot.png?w=500&h=281" alt="" width="500" height="281" /></a></p>
<p>Next, we need to build these packages on the ARM koji to make sure this will deploy correctly. This is done by executing the following commands to send these two packages to the Koji Hub</p>
<p>arm-koji build dist-f13 &#8211;scratch certmaster-0.27-2.fc14.src.rpm</p>
<p>arm-koji build dist-f13 &#8211;scratch func -0.27-2.fc14.src.rpm</p>
<p>Here are links to my two task ID&#8217;s specifying the successful completion of the build on ARM.</p>
<p><a title="Certmaster" href="http://arm.koji.fedoraproject.org/koji/taskinfo?taskID=93357">Certmaster</a></p>
<p><a title="Func" href="http://arm.koji.fedoraproject.org/koji/taskinfo?taskID=93354">Func</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=99&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/21/0-3-part-one/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/screenshot-1.png" medium="image">
			<media:title type="html">Func Build</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/screenshot.png" medium="image">
			<media:title type="html">Certmaster</media:title>
		</media:content>
	</item>
		<item>
		<title>YUM Repository</title>
		<link>http://fuzzux.wordpress.com/2011/04/21/yum-repository/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/21/yum-repository/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 00:52:59 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=95</guid>
		<description><![CDATA[In this lab, we were responsible for the creation of our own YUM repository.  This consists of 3 major stages. In the first stage, we need to generate a GPG key in order for us to sign our packages. What &#8230; <a href="http://fuzzux.wordpress.com/2011/04/21/yum-repository/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=95&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this lab, we were responsible for the creation of our own YUM repository.  This consists of 3 major stages. In the first stage, we need to generate a GPG key in order for us to sign our packages. What is the purpose of this? Signing packages allows users to verify the source of a package, its important to note that signing a package does not ensure its integrity, just verifies the source of the package.</p>
<p>First we generate the key</p>
<p><code>gpg --gen-key</code></p>
<p>Then we need to put the link to they key in our user macro. This ensures that when we do the signing command it will use this key. This line will be located in the <code>~/.rpmmacros </code>file</p>
<p>The two packages I chose to put in my repository were nled and gnucash. On each package, I execute the command</p>
<p><code>rpm --addsign {package rpm}<br />
</code></p>
<p>I then created a directory in /var/www/html called repo, put my packages in and executed the create repo command</p>
<p>Then set my machine to use this repository</p>
<p>After that, I threw together an RPM for my repository data</p>
<p>Here is the RPM link</p>
<p><a title="TIM Repo" href="http://matrix.senecac.on.ca/~tefurzer/timrepo-15-0.1.noarch.rpm">TIMREPO RPM link.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/95/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=95&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/21/yum-repository/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>
	</item>
		<item>
		<title>0.2 Part Four &#8211; Testing/Conclusion</title>
		<link>http://fuzzux.wordpress.com/2011/04/04/0-2-part-four-testingconclusion/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/04/0-2-part-four-testingconclusion/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 02:17:26 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=92</guid>
		<description><![CDATA[After I had completed the installation and had a functional client/server func environment in CDOT, I wanted to test func and see if there were any module issues with the change to the arm machines ( Im not totally sure &#8230; <a href="http://fuzzux.wordpress.com/2011/04/04/0-2-part-four-testingconclusion/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=92&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After I had completed the installation and had a functional client/server func environment in CDOT, I wanted to test func and see if there were any module issues with the change to the arm machines ( Im not totally sure considering its such a drastic change in architecture.</p>
<p>I did several quick func module tests and I found out that for the most part all of the modules that are solely related to the operating system platform such as PS, RPM and those various modules are successful. However; many of the modules that relate to hardware calls and information seem to fail to operate and upon looking at them it appears to be client-side based.</p>
<p>Conclusion and Toward 0.3</p>
<p>While this was successful for 0.2 purposes , installing a version of func on the arm machines , it is not 100% entirely functional and without flaws. Funnily enough after doing some further research I noticed that the version of func installed by yum is 0-25, and the current new release (which has been tested on the arm koji hub) is 0-27. Toward 0.3 and beyond (I would like to continue with this project after graduating) I would like to install the 0-27 version and see if there has been any changes to the python modules that fix the issues I&#8217;m having. If not, I would love to become proficient enough in python to be able to contribute and rememdy these issues.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Stay Tuned.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=92&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/04/0-2-part-four-testingconclusion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>
	</item>
		<item>
		<title>0.2 Part Three &#8211; Installing Func in CDOT</title>
		<link>http://fuzzux.wordpress.com/2011/04/03/0-2-part-three-installing-func-in-cdot/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/03/0-2-part-three-installing-func-in-cdot/#comments</comments>
		<pubDate>Mon, 04 Apr 2011 02:22:57 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=78</guid>
		<description><![CDATA[Now that everything outside of actually installing the software has been looked at we can continue on to the actual installation of func. As per my previous post, we can use those steps to install func. In our situation Hong &#8230; <a href="http://fuzzux.wordpress.com/2011/04/03/0-2-part-three-installing-func-in-cdot/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=78&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now that everything outside of actually installing the software has been looked at we can continue on to the actual installation of func. As per my previous post, we can use those steps to install func. In our situation Hong Kong already has the certmaster service installed, as well as func.  So there is no need to set that up for us. Func is present in the repository on the arm machine, so it is as simple as executing a YUM install func on the arm system.</p>
<p>The func package installs correctly on the system, then we start the service and we get the &#8220;OK&#8221; message from the service command.  However; I notice no certificate request is being sent to the certmaster on Hong Kong.  I wonder why no certificate request is being sent, so I run <span style="text-decoration:underline;">ps -A | grep &#8216;funcd&#8217; </span>on the arm machine and see no funcd service running. I wonder why the service would be dying so I attempt to restart and get the following</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/starting.png"><img class="aligncenter size-large wp-image-79" title="starting" src="http://fuzzux.files.wordpress.com/2011/04/starting.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>Peculiar why the service would start correctly but fail upon restart. Conveniently enough func maintains its own set of logs at /var/log/func/func.log. Upon inspecting the logs, I see this.</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/funcfail.png"><img class="aligncenter size-large wp-image-80" title="funcfail" src="http://fuzzux.files.wordpress.com/2011/04/funcfail.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>My understanding and familiarity with python is somewhat limited, but it sounds to me like func was/is somewhere having issues binding itself to the IP or Hostname of the arm machine (present in the  variable ip is referenced before assignment statement in the logs). Which a lesson can be learnt from, while something may BUILD on Koji correctly, the full functionality may not be available. So, my first remedy was an attempt to assign these variables to nothing, and hope that farther down in the python script they are assigned correctly, something suggested while reading the func mailing list. So after making that slight modification as followed</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/utilspy.png"><img class="aligncenter size-large wp-image-81" title="utilspy" src="http://fuzzux.files.wordpress.com/2011/04/utilspy.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>I am presented with this further error.</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/secondfail.png"><img class="aligncenter size-large wp-image-82" title="secondfail" src="http://fuzzux.files.wordpress.com/2011/04/secondfail.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>However; I further read the script and noticed that it does a quick check to see if a minion name and listen address are specified in the minion config file.  To accomplish this, we make the quick changes to the config file, the change is specifying the listen addr = and the minion_name= .</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/minion.png"><img class="aligncenter size-large wp-image-83" title="minion" src="http://fuzzux.files.wordpress.com/2011/04/minion.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>and restart the funcd service. Now we check the funcd log files to double check and make sure all of the modules are loaded correctly and the funcd service has successfully started</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/success.png"><img class="aligncenter size-large wp-image-84" title="success" src="http://fuzzux.files.wordpress.com/2011/04/success.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>Now the funcd service is started and running.</p>
<p>Since we are trying to run this as securely as possible, we have turned off the auto sign option for the certmaster on Hong Kong.  This means we have to manually  sign requested certificated to allow func to work properly. In this situation this is best practice because Seneca is a reasonably easily accessible network, we want to limited the possibility of rogue machines getting their keys signed by our certmaster.</p>
<p>To list pending key requests we use the following</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/list.png"><img class="aligncenter size-large wp-image-85" title="list" src="http://fuzzux.files.wordpress.com/2011/04/list.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<p>Next we can sign keys using the following command. certmaster-ca &#8211;sign {hostname}, where hostname is in the list of certificates waiting to be signed. and the final step in this process is to check the keys that we have signed on the certmaster.</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/gdotgrusigned1.png"><img class="aligncenter size-large wp-image-87" title="gdotgrusigned" src="http://fuzzux.files.wordpress.com/2011/04/gdotgrusigned1.png?w=1024&h=575" alt="" width="1024" height="575" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/78/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=78&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/03/0-2-part-three-installing-func-in-cdot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/starting.png?w=1024" medium="image">
			<media:title type="html">starting</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/funcfail.png?w=1024" medium="image">
			<media:title type="html">funcfail</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/utilspy.png?w=1024" medium="image">
			<media:title type="html">utilspy</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/secondfail.png?w=1024" medium="image">
			<media:title type="html">secondfail</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/minion.png?w=1024" medium="image">
			<media:title type="html">minion</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/success.png?w=1024" medium="image">
			<media:title type="html">success</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/list.png?w=1024" medium="image">
			<media:title type="html">list</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/gdotgrusigned1.png?w=1024" medium="image">
			<media:title type="html">gdotgrusigned</media:title>
		</media:content>
	</item>
		<item>
		<title>0.2 Part Two &#8211; Preparing the Installation</title>
		<link>http://fuzzux.wordpress.com/2011/04/03/0-2-part-two-preparing-the-installation/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/03/0-2-part-two-preparing-the-installation/#comments</comments>
		<pubDate>Mon, 04 Apr 2011 00:30:42 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=73</guid>
		<description><![CDATA[Before we attempt to actually INSTALL software, we need to ensure appropriate software is available for installation and the network will function appropriately once the installation is complete. This means checking ports, ensuring machines can communicate with each other and &#8230; <a href="http://fuzzux.wordpress.com/2011/04/03/0-2-part-two-preparing-the-installation/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=73&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Before we attempt to actually INSTALL software, we need to ensure appropriate software is available for installation and the network will function appropriately once the installation is complete. This means checking ports, ensuring machines can communicate with each other and that the func package has been built successfully  for the arm arch.</p>
<ul>
<li>Since  we hope to eventually be able to use puppet to deploy both func and Icinga , It only makes sense to  have administration of these services all on the same machine, which is currently the Hong Kong machine. The only concern I have with running all these services from Hong Kong is that it&#8217;s already fairly convoluted with running the Koji build system and many other  systems within CDOT, appropriate distribution of core services is something that needs to be appropriately considered when developing such an infrastructure.</li>
</ul>
<ul>
<li>Because we are currently not looking at full-scale deployment until we can appropriately test the system, we took a single arm machine out of the Koji Build farm to allow us to install and configure a single system and test funcs ability on ARM machines. After we allow for appropriate hardware requirements and commit appropriate resources. Now, we need to ensure that there is appropriate software available for our installation , this is a fairly simple task of checking the Koji Build system.</li>
</ul>
<p>http://koji.fedoraproject.org/koji/packageinfo?packageID=5212</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/04/koji.png"><img class="aligncenter size-large wp-image-74" title="koji" src="http://fuzzux.files.wordpress.com/2011/04/koji.png?w=1024&h=576" alt="" width="1024" height="576" /></a></p>
<p>&nbsp;</p>
<p>as such, we can see that func has been successfully built for the arm architecture.</p>
<ul>
<li>Upon inspecting both the arm machine that I was allocated and Hong Kong, I could see that someone had installed func on Hong Kong, but not the arm system.  Kind of made me wonder if the previous person had some installation issues.</li>
</ul>
<ul>
<li>The final test in ensuring that we will be able to install func with little or no netwrok problems is ensuring that ports are open an accepting connections, the following are the ports used for communication by the various services.</li>
</ul>
<p>Certmaster &#8211; 51235</p>
<p>Func Minion &#8211; 51234</p>
<p>According to the <span style="text-decoration:underline;">iptables -L -v -n </span>command, the appropriate ports were open for             communication.</p>
<p><strong>**NOTE**  I left out IPTABLES Screenshots for security purposes</strong></p>
<p>This is an immensely important step in the installation process. Its fair enough to simply stick func on two machines and hope they work, but it&#8217;s better to spend a little time now preparing and inspecting the systems pre install</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=73&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/03/0-2-part-two-preparing-the-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/04/koji.png?w=1024" medium="image">
			<media:title type="html">koji</media:title>
		</media:content>
	</item>
		<item>
		<title>0.2 Part One &#8211; Prelude</title>
		<link>http://fuzzux.wordpress.com/2011/04/03/0-2-prelude/</link>
		<comments>http://fuzzux.wordpress.com/2011/04/03/0-2-prelude/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 23:27:12 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=68</guid>
		<description><![CDATA[Now that we have successfully installed func in a contained clean environment and tested its functionality , it&#8217;s time to make the jump to an operational system, specifically the ones used in the Seneca CDOT area.  As previously explained func &#8230; <a href="http://fuzzux.wordpress.com/2011/04/03/0-2-prelude/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=68&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now that we have successfully installed func in a contained clean environment and tested its functionality , it&#8217;s time to make the jump to an operational system, specifically the ones used in the Seneca CDOT area.  As previously explained func can and will be used to remotely manage and operate ARM machines within the build environment.</p>
<p>0.1 seemed to be a reasonably simple straightforward install process, and upon starting this second part of the project I saw very little possibility of Issues with the install and configuration of func. However; we had to do some simple steps first to ensure its functionality and proper installation on the systems. For my 0.2 I created an outline of steps required in the process and how the project would flow and be completed.</p>
<ul>
<li>Determine where to locate the service, which machine should be the overlord and what are its clients</li>
<li>Evaluate existing installation.</li>
<li>Since the ARM arch is relatively new to Fedora , we need to check if it has been successfully build and if we can get it from the YUM repo, or are we going to have to build from source</li>
<li>Test network infrastructure to ensure appropriate configuration.</li>
<li>Install the software and troubleshoot any issues that arise during installation</li>
<li>Test modules</li>
<li>Conclude</li>
</ul>
<p>After 0.2 is completed I should have a working func overlord client/server setup that can be demonstrated and  more concise understanding of the complications and problems with a full roll-out of func on ALL arm machines and an approach to potentially solving problems within my ability for 0.3</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=68&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/04/03/0-2-prelude/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>
	</item>
		<item>
		<title>0.1 Part Three &#8211; Installing Func</title>
		<link>http://fuzzux.wordpress.com/2011/03/07/0-1-part-three-installing-func/</link>
		<comments>http://fuzzux.wordpress.com/2011/03/07/0-1-part-three-installing-func/#comments</comments>
		<pubDate>Tue, 08 Mar 2011 03:05:11 +0000</pubDate>
		<dc:creator>thafuzz</dc:creator>
				<category><![CDATA[SBR600]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://fuzzux.wordpress.com/?p=58</guid>
		<description><![CDATA[Setup To start the evaluation of func and its eventual deployment in the CDOT system I wanted to start with a working infrastructure and successful installation of the tool  in a sand boxed environment. I currently have my own installation &#8230; <a href="http://fuzzux.wordpress.com/2011/03/07/0-1-part-three-installing-func/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=58&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Setup</strong></p>
<p>To start the evaluation of func and its eventual deployment in the CDOT system I wanted to start with a working infrastructure and successful installation of the tool  in a sand boxed environment. I currently have my own installation of VMware ESXi 4.1.0 at home and I decided this would be a great opportunity to put it to use, the specs on the system are as follows</p>
<p><strong>VMware ESXi 4.1.0</strong></p>
<p>AMD Phenom x4 965 3.4GHz</p>
<p>8.0 GB DDR3 1333Hz RAM</p>
<p>320GB SATA HDD</p>
<p>Intel MT 1000/100 Pro NIC</p>
<p>I created 3 VM&#8217;s  with the following specs</p>
<p><strong>Fedora Core 13 x64<br />
</strong></p>
<p>Dual Core Processors</p>
<p>2.0 GB RAM</p>
<p>8GB Disk Space (Thin Provisioning)</p>
<p><strong>Func installation</strong></p>
<p>Func consists of two parts. Certmaster, which is the mechanism for implementing the PKI encrypted communication between master and minion. The second part of the install is the func command and API system. The install on my little test infrastructure was fairly straightforward in nature.</p>
<p>On all machines involved we need to install the func package, (works on FC7 and above, NOARCH). Since we know CDOT has DNS established for our environment with only 3 machines we simply add the machines to the /etc/hosts file. the three machines are names, certmaster, certminion1 and certminion2 respectively.</p>
<pre>yum install func</pre>
<p>Now, we need to correctly configure what is known as the &#8216;Overlord&#8217; or the machine responsible for signing certificates and executing the func commands which will be executed on external machines. This is accomplished by turning the certmaster service on. I have not yet decided if auto-signing certificates is something that is secure and a wise decision but this can be accomplished by editing the overlord config file found in /etc/certmaster/certmaster.conf</p>
<pre>/sbin/chkconfig --level 345 certmaster on
/sbin/service certmaster start</pre>
<p>next we need to configure our minion machines. we do this by edition the /etc/certmaster/minion.conf</p>
<pre>[main]
certmaster = certmaster
log_level = DEBUG
cert_dir = /etc/pki/certmaster</pre>
<p>then we start the funcd service, which will allow the machines to be managed by the overlord server</p>
<pre>/sbin/chkconfig --level 345 funcd on
/sbin/service funcd start</pre>
<p>Based on whether or not we have turned on certificate auto-signing we can use the following commands to sign certificates</p>
<p>certmaster-ca &#8211;list (list certificates needed for signing)</p>
<p>certmaster-ca &#8211;sign {hostname}</p>
<p>Another important security consideration we will need to look into when running func is that it is best practice to run func commands outside of root. This can be accomplished by the following series of commands.</p>
<pre>setfacl -d -R -m 'u:MYUSER:rX' /etc/pki/certmaster/
setfacl -R -m 'u:MYUSER:rX' /etc/pki/certmaster/
setfacl -d -R -m 'u:MYUSER:rX' /var/lib/certmaster
setfacl -R -m 'u:MYUSER:rX' /var/lib/certmaster
setfacl -d -R -m 'u:MYUSER:rX' /var/lib/certmaster/certmaster
setfacl -R -m 'u:MYUSER:rX' /var/lib/certmaster/certmaster
setfacl -d -R -m 'u:MYUSER:rX' /var/lib/certmaster/certmaster/certs
setfacl -R -m 'u:MYUSER:rX' /var/lib/certmaster/certmaster/certs
setfacl -d -R -m 'u:MYUSER:rX' /var/lib/certmaster/peers
setfacl -R -m 'u:MYUSER:rX' /var/lib/certmaster/peers
setfacl -d -R -m 'u:MYUSER:rwX' /var/lib/func
setfacl -R -m 'u:MYUSER:rwX' /var/lib/func
setfacl -d -R -m 'u:MYUSER:rwX' /var/log/func/
setfacl -R -m 'u:MYUSER:rwX' /var/log/func/</pre>
<p>MYUSER= The username you wish to allow access to func command.</p>
<p>So now that func has been installed, lets run a few simple commands from the func CLI ( I have not yet gotten the Python API down pat yet) heres a few examples and samples to illustrate functionality and some of the usefulness of func , mind you we can further refine the output with various command, func can spit some ugly output sometimes.</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png"><img class="aligncenter size-full wp-image-63" title="Screenshot-2" src="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png?w=500&h=375" alt="" width="500" height="375" /></a></p>
<p>The Following is the successful output of the command, which will gather ALL rpms installed on the certminion machine</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/03/rpm.odt">rpm</a></p>
<p><a href="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png"><img class="aligncenter size-full wp-image-63" title="Screenshot-2" src="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png?w=500&h=375" alt="" width="500" height="375" /></a></p>
<p>The process info command essentially runs the PS command on the target minion. In this case, I am passing it the -x switch. The following link is the successful output</p>
<p><a href="http://fuzzux.files.wordpress.com/2011/03/psx.odt">psx</a></p>
<p><strong>Where from here?</strong></p>
<p>Over the next week or so, I would like to do some experimenting with the python API, potentially giving me the ability to gain more valuable information and format it in such a way that it would be useful. It also gives us the opportunity to chain calls. After that the next step is to deploy func within CDOT with the help of my colleagues, working together to efficiently deploy these tools in the least disruptive manner.<strong><br />
</strong></p>
<p>Resources.</p>
<p><a href="https://fedorahosted.org/func/wiki/">https://fedorahosted.org/func/wiki/</a></p>
<p><a href="https://fedorahosted.org/certmaster/">https://fedorahosted.org/certmaster/</a></p>
<p>Func Man Page</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fuzzux.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fuzzux.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fuzzux.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=fuzzux.wordpress.com&#038;blog=19074540&#038;post=58&#038;subd=fuzzux&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://fuzzux.wordpress.com/2011/03/07/0-1-part-three-installing-func/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c33166940e9751f8688e6322c84552d3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thafuzz</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png" medium="image">
			<media:title type="html">Screenshot-2</media:title>
		</media:content>

		<media:content url="http://fuzzux.files.wordpress.com/2011/03/screenshot-21.png" medium="image">
			<media:title type="html">Screenshot-2</media:title>
		</media:content>
	</item>
	</channel>
</rss>
