Saturday, November 19, 2011

The proper way of having the Broadcom driver load at boot using modprobe

In the Broadcom documentation it mentions to put "modprobe wl" in /etc/rc.local. This strikes me as bad form since hardware detection is done every time you boot. Putting the driver loading in rc.local instead of adding it to modprobe makes it so that any service relying on an active connection won't have one during initial boot, but will after rc.local is run thereby having start up drag on even longer (since all those services will now see an active connection and come alive). A better way is to add the following entry to /etc/modprobe.d/network.conf: install wl0 /sbin/modprobe wl Important note: make sure the wl driver loads cleanly when you manually run modprobe wl. If the wl driver stops working chances are that you updated your kernel which means you'll need to "make clean ; make ; make install" the driver followed by insmod'ing it followed by a depmod.

Friday, August 19, 2011

A quick and dirty HOWTO for getting Broadcom wifi drivers running on Fedora

This is mainly so I remember exactly how to do it since it is a headache :)  Most of this information comes from http://www.broadcom.com/docs/linux_sta/README.txt which has a different procedure that didn't work for me.
NOTE: I would strongly suggest keeping the source directory after you have finished the steps below because you will need to recompile and re-install the module every time the kernel is updated.

1. Download the source for the driver from: http://www.broadcom.com/support/802.11/linux_sta.php
NOTE: There is also a Patch for compilation problem with kernel versions > 2.6.37
NOTE 2: The patch doesn't seem to want to apply cleanly, but since it's only one line that needs to be changed it's not a headache to make the change manually.

2. After extracting the .tgz, but before compiling the source, the include/linuxver.h file needs to be modified.
Add a new line at the end of the file: MODULE_LICENSE("GPL");
Reason: At least with Fedora Core 15 (what I'm using) the kernel will not load tainted modules and this fixes that problem by making the kernel think that this module uses GPL licensed source code.  The code isn't really GPL licensed, but it's not a problem as long as you're not distributing it.

2a. Compile and install the module: make ; make install

3. For all Linux distros it is necessary blacklist Broadcom modules that may be present in your distribution so they will not be loaded when Linux is starting up.  Depending on your distro the exact method may vary, but for FC15 I created /etc/modprobe.d/broadcom-wl-blacklist.conf of which the contents are:

# modules blacklisted for broadcom-wl
blacklist bcm43xx
blacklist ssb
blacklist b43
blacklist ndiswrapper

4. At this point I suggest rebooting (or you could take the long road and unload all the above modules manually).

5. Run: depmod ; modprobe wl

You should now see your wifi card listed when you do ifconfig -a

Tuesday, July 26, 2011

The Solaris package for the mysterious "libgnomebreakpad.so"

Looking through a ton of postings I could only find people complaining about this library with the only solution being given was to copy it manually, but I finally found an obscure posting that pointed out the package: gnome/crash-report/bug-buddy

Sunday, July 24, 2011

INFOSEC that everyone working in IT should know

Note: this is a post I originally put on my FaceBook page in 2009, but I'm slowly migrating away from FB so I'm reposting it here since it's still relevant.
-----------
Seeing as how I'm now moving on again I think I'll offer some basic information security procedures that everyone should know. It's an inevitability that you will eventually have to turn in your work equipment with little to no notice and making sure you don't have personal information on it should be a concern from day one. Yes, storing your gmail, facebook, Twitter, etc passwords in FireFox is convenient, but that's definitely not something that you want left for a stranger to compromise. Here is a setup that I have determined to be best:

1. Load vmware on your system
2. Install a Linux distribution (I prefer CentOS) and make sure to select use an encrypted partition (use a good password too not 1234 or some other password that takes 2 seconds to crack).
NOTE: make sure VMWare is setup to keep the guest in RAM (so it doesn't use the swap).
If the host OS is windows do the following:
1. Install CCleaner and configure it as follows:
a) start at startup
b) secure deletion - DoD standard is more than enough
c) wipe free space
2. Have windows clear delete the swap file at shutdown.
3. Configure disk defragmentation to happen every night at midnight.

Now use the Linux guest to browse gmail, facebook, whatever personal stuff you want/need to do.

The host os (windows) will be you do all your completely business related activities (intranet, code development, etc). As long as a key logger isn't installed the guest os will be secure for using for your personal tasks. When it's time for equipment turn in all that then needs to be done is a quick delete on the VHD for the guest (one file). However, if you're not provided any time you'll at least know that no one will access your personal data unless they have obtained the key for your encrypted filesystem (by key logger or watching you enter it).

Thursday, July 21, 2011

How to setup the updater for Solaris 11

A brief overview is located at:
Support Repositories Explained [ID 1021281.1]
https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1021281.1

Get your x.509 certificate for accessing the repository at:
https://pkg-register.oracle.com/register/status/

There's a HOWTO section link located on the bottom, but I'll reprint the instructions in case things change.
------
How to Install this Oracle Solaris 11 Express Support Certificate

   1. Download the provided key and certificate files, called Oracle_Solaris_11_Express_Support.key.pem and Oracle_Solaris_11_Express_Support.certificate.pem using the buttons above. Don't worry if you get logged out, or lose the files. You can come back to this site later and re-download them. We'll assume that you downloaded these files into your Desktop folder, ~/Desktop/.
   2. Use the following comands to make a directory inside of /var/pkg to store the key and certificate, and copy the key and certificate into this directory. The key files are kept by reference, so if the files become inaccessible to the packaging system, you will encounter errors. Here is how to do it:

          $ sudo mkdir -m 0755 -p /var/pkg/ssl
          $ sudo cp -i ~/Desktop/Oracle_Solaris_11_Express_Support.key.pem /var/pkg/ssl

          $ sudo cp -i ~/Desktop/Oracle_Solaris_11_Express_Support.certificate.pem /var/pkg/ssl
        

   3. Add the publisher:

          $ sudo pkg set-publisher \
                     -k /var/pkg/ssl/Oracle_Solaris_11_Express_Support.key.pem \
                     -c /var/pkg/ssl/Oracle_Solaris_11_Express_Support.certificate.pem \
                     -O https://pkg.oracle.com/solaris/support/ solaris
        

   4. Check your publisher settings, there should be no unrelated mirrors set up. To check for any set up mirrors invoke the following command:

          $ pkg publisher solaris | grep Mirror
        
        

      If the output is empty you are all set. If not remove unrelated mirrors by running:

          $ sudo pkg set-publisher -M http://mirror1.x.com -M http://mirror2.y.com ... solaris
        
        

   5. To see the packages supplied by this publisher, try:

          $ pkg list -a 'pkg://solaris/*'

        

      If you use the Package Manager graphical application, you will be able to locate the newly discovered packages when you restart Package Manager.

Monday, February 21, 2011

VirtualBox SMF

/lib/svc/method/vboxheadless:

#!/bin/sh
# Customise this file to start and stop your application as necessary.

. /lib/svc/share/smf_include.sh


    getproparg() {

            val=`svcprop -p $1 $SMF_FMRI`

            [ -n "$val" ] && echo $val

    }

VM=`getproparg vbox/VM`

    if [ -z $SMF_FMRI ]; then

            echo "Error: SMF framework variables are not initialized"

            exit $SMF_EXIT_ERR

    fi


case "$1" in
  'start') /opt/VirtualBox/VBoxHeadless -s $VM  &
  ;;
  'stop') /opt/VirtualBox/VBoxManage controlvm $VM savestate
  ;;
  'refresh') /opt/VirtualBox/VBoxManage controlvm $VM reset
  ;;
  *) echo "Usage: $0 { start | stop | refresh }"
  exit 1
  ;;
esac

exit $SMF_EXIT_OK


/var/svc/manifest/application/vboxheadless.xml:
<?xml version="1.0"?>
<!DOCTYPE service_bundle SYSTEM "/usr/share/lib/xml/dtd/service_bundle.dtd.1">

<service_bundle type='manifest' name='vboxheadless'>

<service name='application/vboxheadless' type='service' version='1'>


<method_context>
  <method_credential user='root' group='root' />
</method_context>


<exec_method type='method' name='start'
     exec='/lib/svc/method/vboxheadless start'
     timeout_seconds="60" />

<exec_method type='method' name='stop'
     exec='/lib/svc/method/vboxheadless stop'
     timeout_seconds="60" />

<exec_method type='method' name='refresh'
     exec='/lib/svc/method/vboxheadless refresh'
     timeout_seconds="60" />
<property_group name="startd" type="framework">
<propval name="duration" type="astring" value="transient"/>
</property_group>

<instance name='w7' enabled='true'>
<property_group name='vbox' type='application'>
<propval name='VM' type='astring'
                        value='w7' />
</property_group>
</instance>

<stability value='Unstable' />

<template>
   <common_name>
      <loctext xml:lang='C'>VirtualBox Headless</loctext>
  </common_name>
  <documentation>
      <manpage title='VBoxManage' section='1m' manpath='/usr/share/man' />
      <doc_link name='homepage' uri='http://sgpit.com/smf' />
  </documentation>
</template>

</service>
</service_bundle>


Running VirtualBox in a zone under Solaris 11

When trying to run VirtualBox in a zone under Solaris 11 make sure fonts are installed in the zone or else VirtualBox will core dump.  Package list:

FSWfontconfig-devel-docs                      0.5.11-0.130    known      --o--
print/filter/ghostscript/fonts/gnu-gs-fonts-other 6.0-0.151.0.1   known      -----
print/filter/ghostscript/fonts/gnu-gs-fonts-std 6.0-0.151.0.1   known      -----
system/font/daewoo-misc                       1.0.1-0.151     known      -----
system/font/gnome-fonts                       0.5.11-0.151.0.1 installed  -----
system/font/isas-misc                         1.0.1-0.151     known      -----
system/font/jis-misc                          1.0.1-0.151     known      -----
system/font/misc-ethiopic                     1.0.1-0.151     known      -----
system/font/misc-meltho                       1.0.1-0.151     known      -----
system/font/truetype/arabeyes                 0.5.11-0.151.0.1 known      -----
system/font/truetype/arphic-ukai              0.5.11-0.151.0.1 known      -----
system/font/truetype/arphic-uming             0.5.11-0.151.0.1 known      -----
system/font/truetype/bh-luxi                  1.0.1-0.151     known      -----
system/font/truetype/bitstream-vera           1.10-0.151      known      -----
system/font/truetype/bpg-georgian             0.5.11-0.151.0.1 known      -----
system/font/truetype/dejavu                   2.31-0.151      known      -----
system/font/truetype/fonts-core               1.1-0.151.0.1   installed  -----
system/font/truetype/gentium                  0.5.11-0.151.0.1 known      -----
system/font/truetype/google-droid             0.2010.2.24-0.151 known      -----
system/font/truetype/hanyang-ko               0.5.11-0.151.0.1 known      -----
system/font/truetype/hanyang-ko-core          0.5.11-0.151.0.1 known      -----
system/font/truetype/indic-fonts-core         0.5.11-0.151.0.1 known      -----
system/font/truetype/ipafont                  0.5.11-0.151.0.1 known      -----
system/font/truetype/ipafont-mincho           0.5.11-0.151.0.1 known      -----
system/font/truetype/kacst                    0.5.11-0.151.0.1 known      -----
system/font/truetype/liberation               1.4-0.151       known      -----
system/font/truetype/lohit                    0.5.11-0.151.0.1 known      -----
system/font/truetype/mgopen                   0.5.11-0.151.0.1 known      -----
system/font/truetype/sil                      0.5.11-0.151.0.1 known      -----
system/font/truetype/thai-scalable            0.5.11-0.151.0.1 known      -----
system/font/truetype/ttf-fonts-core           1.1-1           known      --r--
system/font/truetype/unfonts-ko-core          0.5.11-0.151.0.1 known      -----
system/font/truetype/unfonts-ko-extra         0.5.11-0.151.0.1 known      -----
system/font/truetype/unifont                  0.5.11-0.151.0.1 known      -----
system/font/truetype/wqy-zenhei               0.5.11-0.151.0.1 known      -----
system/font/xorg/cyrillic                     1.0.2-0.151     known      -----
system/font/xorg/iso8859-1                    7.5-0.151       installed  -----
system/font/xorg/iso8859-10                   7.5-0.151       known      -----
system/font/xorg/iso8859-11                   7.5-0.151       known      -----
system/font/xorg/iso8859-13                   7.5-0.151       known      -----
system/font/xorg/iso8859-14                   7.5-0.151       known      -----
system/font/xorg/iso8859-15                   7.5-0.151       known      -----
system/font/xorg/iso8859-16                   7.5-0.151       known      -----
system/font/xorg/iso8859-2                    7.5-0.151       known      -----
system/font/xorg/iso8859-3                    7.5-0.151       known      -----
system/font/xorg/iso8859-4                    7.5-0.151       known      -----
system/font/xorg/iso8859-5                    7.5-0.151       known      -----
system/font/xorg/iso8859-7                    7.5-0.151       known      -----
system/font/xorg/iso8859-8                    7.5-0.151       known      -----
system/font/xorg/iso8859-9                    7.5-0.151       known      -----
system/font/xorg/xorg-core                    7.5-0.151       known      -----
system/library/fontconfig                     2.8.0-0.151     installed  -----
system/library/fontconfig/documentation       2.8.0-0.144     known      --r--
x11/font-utilities                            7.5-0.151       installed  -----
x11/library/libfontenc                        1.0.5-0.151     installed  -----
x11/library/libxfont                          1.4.1-0.151     installed  -----
x11/xfontsel                                  1.0.2-0.151     installed  -----