Friday, December 13, 2013

Root Password Recovery for any Solaris 10 (without CD/DVD).


  1. We can recover the root password for any solaris10 without any CD/DVD, for that first we need to bring the server at OK promt
#init 0
  1. Boot the server into failsafe mode. In failsafe mode, server will boot with RAM disk without any CD/DVD
Ok>boot -F failsafe
#df -k
/ramdisk-root:a   201463  178943    2374    99%  / > Server booted from RAM
Note: Sometimes (every time is X-86 servers) the Failsafe mode will ask you to mount the root disk before giving you the Shell prompt. Do not mount at that time, just say No everywhere and bring the failsafe mode at Shell Prompt and then do the mount and update archive manually.
  1. In failsafe mode, we need to mount the server with root disk. Here my root disk c1t1d0s0
#mount /dev/dsk/c1t1d0s0 /a
#df -h|grep /a
/dev/dsk/c1t1d0s0 7.9G 7.1G 714M 92% /a


  1. Copy the configuration to enable SVM module in failsafe mode, and un mount root FS
# cp /a/kernel/drv/md.conf /kernel/drv
#umount /a
  1. Now we have to load the SVM module to enable it in failsafe mode:
#update_drv -f md
devfsadm: mkdir failed for /dev 0x1ed: Read-only file system  ßYou will see this messages
  1. Now you will be able to mount the md meta devices and will be able to make any changes
#mount /dev/md/dsk/d0 /a
  1. Take a copy of /a/etc/passwd & /a/etc/shadow file
# cp -p /a/etc/passwd /a/etc/passwd-orig
# cp -p /a/etc/shadow /a/etc/shadow-orig
  1. Need to remove encrypted passwd for root from /etc/shadow file
#grep root /a/etc/shadow
root:WP7grKsEFAgt.:15182::::::
#grep root /a/etc/shadow
root::15182::::::
  1. Update the boot archive as below before proceeding with the reboot.
#bootadm update-archive -R /a
Creating boot_archive for /a
updating /a/platform/sun4u/boot_archive
  1. Umount the meta device and Reboot your system, this time you are allowed to login into the server without password. Now first recommended thing would be to set you password for root.
#umount /a
#init 6

SOLARIS KERNEL PATCHING PROCEDURE


  1. We need to prepare patch document procedure with back-out plan, and needs to get the approval by change management. Once we get the approval, we can start our change in scheduled window
  2. Download suitable our platform bundle patch(Recommended Solaris Cluster Patch) fromhttps://support.oracle.com
#isainfo -b  [ to check the bit version]
  1. Take the necessary backups of the server.
#uname –a
# df –k
#metastat –p
#metadb –i
#netastat –nr
#ifconfig –a
#prtconf
#prtdiag –v
#metastat -ac
#metastat –t
#eeprom
#echo | format
/etc/system
/etc/vfstab

NOTE: Better to run SUN Explorer before preceding this activity
NOTE: Take the outputs before detaching the mirror else you would have to take the backups separately for your detached disk
NOTE: Zones must be halted, while doing patch on active boot enviromnet
            #zoneadm list –vc
NOTE: Before proceeding with patching, make sure our application & data base are down
  1. Break the mirror, and it will isolate from root disk.
c1t0d0 —> Root disk
c1t1d0 —> Root-mirror disk
·         First delete state database replicas from root-mirror disk
#metadb –i
a    p  luo        16              8192            /dev/dsk/c1t1d0s7
#metadb –d –f  /dev/dsk/ c1t1d0s7
·         Proceed with the mirror detach for your root-mirror disk
# metastat –p
            d1 -m d20 d21 1
d20 1 1 c1t0d0s1
d21 1 1 c1t1d0s1
d0 -m d10 d11 1
d10 1 1 c1t0d0s0
d11 1 1 c1t1d0s0
#metadetach d1 d21
#metadetach d0 d11
#metaclear d21
#metaclear d11
#metastat –p
            d1 -m d20
d20 1 1 c1t0d0s1
                                    d0 -m d10
d10 1 1 c1t0d0s0

  1. Mount detached root-mirror disk on mount point /mnt and edit /mnt/etc/vfstab & /mnt/etc/vfstab
#mount /dev/dsk/c1t1d0s0 /mnt
#vi /mnt/etc/vfstab     [change md entries to native entries]
/dev/md/dsk/d1   à /dev/dsk/c1t1d0s1
/dev/md/dsk/d0   à /dev/dsk/c1t1d0s0
# grep -i md /mnt/etc/system
* Begin MDD root info (do not edit)
rootdev:/pseudo/md@0:0,0,blk    [comment with *]
* End MDD root info (do not edit)

  1. Unmount root-mirror disk and fsck
#umount /mnt
#fsck /dev/rdsk/c1t1d0s0
NOTE:
1.) Please keep in mind that all changes are applicable to root-mirror disk. Do not do any changes on other disk (i.e. root-disk).
2.) It is recommended to run fsck on root-mirror disk (slice 0, rootFS slice) so that it won’t give any errors while booting.
3.) Before proceeding with the patching make sure that /var FS have enough free space as all logs will be written there. else you will get errors while patching.
  1. Now our root-disk is under SVM control and root-mirror disk is under native raw Solaris disk. By doing this step we are making sure that in case if anything goes against our action plan then we will be able to recover our server from other disk.  
  2. We have to test the booting of our server from both the disks to make sure that the server will come up with both of the disks without any issues.
#init 0
Ok>devalias root-mirror
/pci@1f,0/pci@1/scsi@8/disk@1,0:a
Ok>boot root-mirror 
Once system come-up with root-mirror, needs do the post check like df –h, ifconfig etc
Now boot the server from root-disk as well
#init 0
Ok>devalias rootdisk
/pci@1f,0/pci@1/scsi@8/disk@0,0:a
            Ok>boot rootdisk
Once system come-up with rootdisk, needs do the post check like df –h, ifconfig etc

  1. Now we can go ahead with patching, but server should be single user mode
#cd /var/tmp
# digest -a md5 -v /var/tmp/10_x86_Recommended.zip [will check md5 value]
#unzip -q 10_Recommended.zip
NOTE: for unzipping of recommended patch, we need 5 GB of disk space
#grep PASSCODE 10_Recommended.README
*************** PASSCODE **************
PASSCODE: s10patchset
#shutdown -g0 -y –is
#who –r
.       run-level S  Oct 25 12:39     S      0  3
NOTE: For installation recommended patch, we need 3 GB of disk space
#./installpatchset --s10patchset  
Setup ..........
Recommended OS Patchset Solaris 10 x86 (2011.09.14)

The patch set will complete installation in this session. No intermediate
reboots are required.

Application of patches started : 2011.09.16 20:24:45
Applying 120901-03 (  1 of 302) ... skipped
Applying 121334-04 (  2 of 302) ... skipped
Applying 119255-81 (  3 of 302) ... skipped
.
. <similar output omitted>
.
Applying 147379-01 (300 of 302) ... success
Applying 147435-01 (301 of 302) ... success
Applying 147441-01 (302 of 302) ... success
NOTE: A symlink to 'installpatchset' is provided in place of the legacy 'installcluster' script for now

  1. Once patching has done, needs to run reconfiguration reboot on server and check the kernel version
#touch /reconfigure
#reboot -- -r
#uname -a
SunOS Release 5.10 Version Generic_147441-01 32-bit
NOTE: Do not re-mirror the root-mirror disk immediately; wait for 5 to 7 days to notice any issues with the OS or application. If all is good then re-mirror the disks for redundancy.

NOTE: If patch fails, for roll-back you need to boot from the root-mirror disk and create all the SVM mirrors back on root-mirror disk from start and then re-mirror root-disk back with root-mirror disk.

Tuesday, December 3, 2013

How to enable X manager remote access SUSE Linux 10




You can enable the remote login as following steps.



1. vi /etc/X11/xdm/Xaccess

Remove the below comment symbol of following line.

#any host can get a login windows



 2. vi /etc/X11/xdm-config

comment out this line using the exclamation mark as following.


!DisplayManager.requestPort:    0


3. vi /etc/sysconfig/displaymanager

Change the first parameter to yes and the second parameter to yes in need.

DISPLAYMANAGER_REMOTE_ACCESS="yes"

DISPLAYMANAGER_ROOT_LOGIN_REMOTE="yes"



4. restart the xdm daemon

/usr/sbin/rcxdm restart

Saturday, April 20, 2013

Oracle Integrated Lights Out Manager (ILOM) 3.0

Recover a Lost Password (CLI)

Before You Begin
  • You must be physically present at the server to perform this procedure.
  • This procedure uses the default user account to enable you to recover a lost password or to re-create the root user account.
  • You cannot change or delete the default user account.
  1. Establish a local serial management connection to ILOM and log in to ILOM using the default user account.For example:
    SUNSP-0000000000 login:default
    Press and release the physical presence button.
    Press return when this is completed...
  2. Prove physical presence at your server.Refer to your platform documentation for instructions on how to prove physical presence.
  3. Return to your serial console and press Enter.You will be prompted for a password.
  4. Type the password for the default user account: defaultpassword
  5. Reset the account password or re-create the root account.

Thursday, April 18, 2013

XSCF Command Cheat Sheet

adduser – Creates an XSCF user account.
deleteuser – Deletes an XSCF user account.
disableuser – Disables an XSCF user account
enableuser – Enables an XSCF user account.
showuser – Displays XSCF user account information
password – Changes an XSCF user account password.
setpasswordpolicy – Configures the XSCF password policy.
showpasswordpolicy – Displays the XSCF password policy.
setprivileges – Assigns user privileges.
setloginlockout – Configures the lockout of user accounts.
showloginlockout – Displays the lockout setting of user accounts.
setnetwork – Configures the XSCF network.
shownetwork – Displays the XSCF network settings and XSCF-LAN network status.
setroute – Configures the XSCF-LAN route.
showroute – Displays XSCF-LAN route settings.
sethostname – Specifies the XSCF-LAN host name and domain name.
showhostname – Displays the XSCF-LAN host name and domain name.
setnameserver – Sets a name server (DNS) with XSCF.
shownameserver – Displays the XSCF name server(s).
applynetwork – Applies the network settings.
setdscp – Configures DSCP.
showdscp – Displays the DSCP settings.
nslookup – Checks for the name resolution of a host name.
ping – Checks the response for a host.
traceroute – Displays the network path to the host by list.
settimezone – Specifies the time zone.
showtimezone – Displays the time zone setting.
setdate – Sets the XSCF time.
showdate – Displays the XSCF time.
setntp – Configures the NTP server.
showntp – Displays the SSH settings and fingerprint.
resetdateoffset – Resets the time subtraction between the XSCF and the domain.
showdateoffset – Displays the time subtraction between the XSCF and the domain.
setssh – Configures SSH, Generates RSA and DSA keys for SSH2 host authentication.
showssh – Displays the SSH settings.
settelnet – Configures telnet.
showtelnet – Displays the telnet settings.
setautologout – Sets the session timeout time of the XSCF Shell.
showautologout – Displays the session timeout time of the XSCF Shell.
setsmtp – Configures the SMTP server.
showsmtp – Displays the the SMTP server settings.
setemailreport – Configures mail notification.
showemailreport – Displays the mail notification settings.
setlookup – Enables or disables the use of an LDAP server.
showlookup – Displays information about whether an LDAP server is used.
setldap – Configures LDAP client settings.
showldap – Displays LDAP client settings.
sethttps – Configures the https settings.
showhttps – Displays the https settings.
setupplatform – Configures the log archiving function of XSCF.
showarchiving – Displays the settings of the log archiving function of XSCF.
setaudit – Configures the auditing of XSCF.
showaudit – Displays the settings of the audit of XSCF.
viewaudit – Displays the audit records (Audit trail) of XSCF.
setsnmp – Configures the SNMP Agent.
showsnmp – Displays the SNMP Agent settings.
setsnmpusm – Configures the USM management information for the SNMP agent.
showsnmpusm – Displays the USM management information for the SNMP agent.
setsnmpvacm – Configures the VACM management information for the SNMP agent.
showsnmpvacm – Displays the VACM management information for the SNMP agent.
setsunmc – Start or stop the Sun Management Center agent and make changes to its configuration.
showsunmc – Show setup information and status of Sun Management Center agent.
setdcl – Specifies the domain configuration information (DCL).
showdcl – Displays the domain configuration information.
showboards – Displays the component information and the COD information about a system board.
showdevices – Displays the domain information specified for a system board.
showdomainstatus – Displays the domain status.
setupfru – Specifies the number of XSB partitions of the system board and sets the memory mirror mode.
showfru – Displays the specified number of XSB partitions of the system board and the memory mirror mode that is set.
    Example:
    Displays the settings of all PSBs.
    XSCF> showfru -a sb
    Device Location XSB Mode Memory Mirror Mode
    sb 00 Quad no
testsb – Diagnoses the system board.
addboard – Adds a system board to a domain.
deleteboard – Deletes a system board from a domain.
moveboard – Moves a system board to another domain.
replacefru – Replaces a CPU/Memory Board unit, I/O unit, fan unit, PSU, or XSCFi.
addfru – Installs a CPU/Memory Board unit, I/O unit, fan unit, or PSU.
deletefru – Removes a CPU/Memory Board unit or I/O unit.
setdomainmode – Sets a hardware initial diagnostic level (No, standard, maximum).
Enables or disables break signal sending, host watchdog, automatic boot, and sets CPU operation mode.
showdomainmode – Displays the domain host ID, the hardware initial diagnostic level, information of enabled or disabled status on break signal sending, Host watchdog, automatic boot, and displays CPU operation mode, ethernet address, mac address.
sendbreak – Sends a break signal to the server.
showresult – Displays the exit status of the most recently executed command.
setlocale – Sets locale.
showlocale – Displays locale.
setaltitude – Sets altitude.
showaltitude – Displays altitude.
cfgdevice – Sets/Displays the connection destination/status of the DVD drive, tape drive.
addcodlicense – Applies the obtained COD license key to the system.
deletecodlicense – Deletes the license key applied to the system.
showcodlicense – Displays the license keys applied to the system.
showcodusage – Displays license usage information.
setcod – Configures COD settings.
showcod – Displays COD settings.
console – Connects to a domain console.
showconsolepath – Displays the operating status of the main console.
showenvironment – Displays the temperature, humidity, voltage, fan rotation speed, power consumption, and exhaust airflow.
showstatus – Lists degraded components.
showhardconf – Displays all components mounted in the server.
poweron – Turns on power to all domains or the specified domain.
poweroff – Turns off power to all domains or the specified domain.
reset – Resets the specified domain.
The following three reset modes are available:
    por: Domain system reset
    request: Domain panic instruction
    xir: Domain CPU reset
setpowerupdelay – Sets the warm-up time and the air-conditioning wait time.
showpowerupdelay – Displays the warm-up time and the air-conditioning wait time settings.
setshutdowndelay – Sets the UPS shutdown delay time at power failure.
showshutdowndelay – Displays the UPS shutdown delay time at power failure.
setdualpowerfeed – Sets the dual power feed.
showdualpowerfeed – Displays the dual power feed.
setlocator – Enables or disables the CHECK LED blinking.
showlocator – Displays the LED status.
switchscf – Switches the XSCF Unit state (Active/Standby).
ioxadm – Configures/Displays the External I/O Expansion Unit settings(IOBOX).
clockboard – Sets/Displays the number of clock unit (CLKU) used when the next platform is powered on.
setdomparam – Rewrites the OpenBoot PROM environment variable that is compulsory.
getflashimage – Gets the firmware update program.
flashupdate – Updates the firmware program.
version – Displays XCP, XSCF, and OpenBoot versions.
prtfru – Displays the FRU-ROM data.
dumpconfig – Saves XSCF configuration information to the specified destination.
restoreconfig – Restores XSCF configuration information from the specified destination.
restoredefaults – Initialises the server or XSCF to the factory defaults.
snapshot – Saves log information to the specified destination.
showmonitorlog – Displays the XSCF monitoring messages on console in real time.
showlogs – Displays the error log, power log, event log, console log, panic log, IPL log, temperature/humidity log, and monitor message log.
fmadm – Monitors/controls the Fault Management Diagnosis Engines (FMDE).
fmdump – Dumps the fault event log containing FM diagnosis results.
fmstat – Displays the FMDE status.
unlockmaintenance – Forcibly release the locked status of the XSCF.
rebootxscf – Reboots/Resets the XSCF.
who – Displays users who login to the XSCF.
man – Displays the man page of the specified command.
You can see this list of commands by executing man intro.
exit – Ends the XSCF Shell.

How to Install Oracle Explorer Manually

How to Install Oracle Explorer Manually

Use the following procedure to install Oracle Explorer after you have downloaded the latest installer, as described in How to Download Oracle Explorer.

Note – Oracle Explorer must be installed in the global zone if you are installing it on the Solaris 10 Operating System (Solaris OS). In Solaris 10, the pkgadd command includes a -g flag that restricts installation to the global zone.

  1. If a version of Oracle Explorer is installed on the host, remove the SUNWexplo and SUNWexplu packages before installing the new Oracle Explorer package.
  2. Become superuser.
  3. Type the following command at the prompt:
    pkgrm SUNWexplo
    If the SUNWexplu package is also installed, type the following command at the prompt:
    pkgrm SUNWexplu

    Note – Removing the current SUNWexplo and SUNWexplu package saves the Oracle Explorer defaults file.
    In Oracle Explorer 3.6.2 and earlier versions, the defaults file is explorer_install_dir/etc/default/explorer.
    In Oracle Explorer 4.0 and later versions, the defaults file is /etc/opt/SUNWexplo/default/explorer.
    You can save the defaults file and use it as input when you run the explorer -g command to create or update the defaults file. During installation of Oracle Explorer version 4.0 or later, this file is moved from the explorer_install_dir/etc/default/explorer directory to the /etc/opt/SUNWexplo/default/explorer directory. The contents of the defaults file are displayed as the default responses when you run the explorer -g command.

    The output directory of the most recent Oracle Explorer run is saved in the explorer_install_dir/output directory.
  4. Extract Oracle Explorer from Services Tools Bundle (STB) using -ext option .
    To obtain the STB installer options, type ./install_stb.sh -help
  5. Uncompress and untar the Explorer_<version>.tar.Z file:

    cd /var/tmp/stb/extract/Explorer
    Decide which of the following commands you should use to untar the file:
    • If you do not have zcat installed, type:

      uncompress Explorer_<version>.tar.Z
      tar xvf Explorer_<version>.tar
    • If you have zcat installed, type:

      zcat Explorer_<version>.tar.Z | tar xvf -

    Note – If you want to use Explorer from an alternate path, proceed to step 2 in How to Use Explorer from an Alternate Path.

  6. To install Explorer and create directories called SUNWexplo and SUNWexplu type the following command at the prompt as superuser:
    pkgadd -d . SUNWexplo SUNWexplu

Note – If this is an NFS installation that will support clients running Solaris 7 or older, use the following command:

echo "EXP_NFS_DEPLOY=1" > response
pkgadd -d . -r response SUNWexplo SUNWexplu