Sometimes, I receive digital invoices in PDF format with a password. That way I shouldn't be able to modify them and commit fraud. Unfortunately, this also makes it impossible to perform normal operations on them, such as removing unneeded specifications or merging all invoices into one single file.
Luckily, most Linux distributions come with a tool that can be used to remove these passwords: ghostscript.
While this does remove the password, I'm not sure if it does not degrade the quality of the file a little (I don't notice any quality difference, but if you use highres files, you may lose quality).
There once was a day that I compiled my own kernels and configured all modules manually. It's been quite a while since I've done anything like that, but I remembered some of it.
Today I installed my WiFi drivers. The HP Elitebook 8570w I own has a Centrino Advanced-N 6205 on board that is actually supported by Fedora 17.
$ lspci
00:00.0 Host bridge: Intel Corporation Ivy Bridge DRAM Controller (rev 09)
00:01.0 PCI bridge: Intel Corporation Ivy Bridge PCI Express Root Port (rev 09)
00:14.0 USB Controller: Intel Corporation Panther Point USB xHCI Host Controller (rev 04)
00:16.0 Communication controller: Intel Corporation Panther Point MEI Controller #1 (rev 04)
00:19.0 Ethernet controller: Intel Corporation 82579LM Gigabit Network Connection (rev 04)
00:1a.0 USB Controller: Intel Corporation Panther Point USB Enhanced Host Controller #2 (rev 04)
00:1b.0 Audio device: Intel Corporation Panther Point High Definition Audio Controller (rev 04)
00:1c.0 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 1(rev c4)
00:1c.1 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 2(rev c4)
00:1c.2 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 3(rev c4)
00:1c.3 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 4(rev c4)
00:1d.0 USB Controller: Intel Corporation Panther Point USB Enhanced Host Controller #1 (rev 04)
00:1f.0 ISA bridge: Intel Corporation Panther Point LPC Controller (rev 04)
00:1f.2 SATA controller: Intel Corporation Panther Point 6 port SATA AHCI Controller (rev 04)
00:1f.3 SMBus: Intel Corporation Panther Point SMBus Controller (rev 04)
01:00.0 VGA compatible controller: nVidia Corporation Device 0ffc (rev a1)
01:00.1 Audio device: nVidia Corporation Device 0e1b (rev a1)24:00.0 FireWire (IEEE 1394): JMicron Technology Corp. IEEE 1394 Host Controller (rev30)24:00.1 System peripheral: JMicron Technology Corp. SD/MMC Host Controller (rev30)24:00.2 SD Host controller: JMicron Technology Corp. Standard SD Host Controller (rev30)25:00.0 Network controller: Intel Corporation Centrino Advanced-N 6205(rev34)
$ lspci
00:00.0 Host bridge: Intel Corporation Ivy Bridge DRAM Controller (rev 09)
00:01.0 PCI bridge: Intel Corporation Ivy Bridge PCI Express Root Port (rev 09)
00:14.0 USB Controller: Intel Corporation Panther Point USB xHCI Host Controller (rev 04)
00:16.0 Communication controller: Intel Corporation Panther Point MEI Controller #1 (rev 04)
00:19.0 Ethernet controller: Intel Corporation 82579LM Gigabit Network Connection (rev 04)
00:1a.0 USB Controller: Intel Corporation Panther Point USB Enhanced Host Controller #2 (rev 04)
00:1b.0 Audio device: Intel Corporation Panther Point High Definition Audio Controller (rev 04)
00:1c.0 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 1 (rev c4)
00:1c.1 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 2 (rev c4)
00:1c.2 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 3 (rev c4)
00:1c.3 PCI bridge: Intel Corporation Panther Point PCI Express Root Port 4 (rev c4)
00:1d.0 USB Controller: Intel Corporation Panther Point USB Enhanced Host Controller #1 (rev 04)
00:1f.0 ISA bridge: Intel Corporation Panther Point LPC Controller (rev 04)
00:1f.2 SATA controller: Intel Corporation Panther Point 6 port SATA AHCI Controller (rev 04)
00:1f.3 SMBus: Intel Corporation Panther Point SMBus Controller (rev 04)
01:00.0 VGA compatible controller: nVidia Corporation Device 0ffc (rev a1)
01:00.1 Audio device: nVidia Corporation Device 0e1b (rev a1)
24:00.0 FireWire (IEEE 1394): JMicron Technology Corp. IEEE 1394 Host Controller (rev 30)
24:00.1 System peripheral: JMicron Technology Corp. SD/MMC Host Controller (rev 30)
24:00.2 SD Host controller: JMicron Technology Corp. Standard SD Host Controller (rev 30)
25:00.0 Network controller: Intel Corporation Centrino Advanced-N 6205 (rev 34)
The device at the very bottom is the WiFi device we're looking for. But iwconfig shows it's not available to the system somehow:
$ iwconfig
thuisf no wireless extensions.
vmnet8 no wireless extensions.
thuis no wireless extensions.
eth0 no wireless extensions.
lo no wireless extensions.
virbr0-nic no wireless extensions.
virbr0 no wireless extensions.
noc no wireless extensions.
vmnet1 no wireless extensions.
$ iwconfig
thuisf no wireless extensions. vmnet8 no wireless extensions. thuis no wireless extensions. eth0 no wireless extensions. lo no wireless extensions. virbr0-nic no wireless extensions. virbr0 no wireless extensions. noc no wireless extensions. vmnet1 no wireless extensions.
I created some scripts to backup my Samsung Galaxy S2 to my Fedora 16 system without pressing any keys or even touching the mouse. It works like this:
To backup a SGS2, you go to settings > applications > usb tools on the phone, and click the button. You then connect it to a usb cable. At that moment, two removable devices become visible to the Linux system: one for the SD card, one for the built-in memory. But they still contain no media. Only when you press another button on the phone, the "media are inserted in the devices", triggering a "change" action with the udev daemon.
Configuration of the udev daemon
Create a file /etc/udev/rules.d/71-android-backup.rules:
Whenever a (virtual) medium is inserted, a udev change action is triggered. Actually, it gets triggered multiple times, but we only need the one that has the environment variable DISK_MEDIA_CHANGE=1 set.
Action to perform
The action triggered is /usr/local/bin/androidbackup and all parameters are in the environment. So let's create that file. I use a rsnapshot-like operation to backup my data, but without actually using rsnapshot.
#!/bin/bashfunction msg {/usr/bin/logger -t android "$1"DISPLAY=:0 qdbus $dbusRef setLabelText "$1"DISPLAY=:0 qdbus $dbusRef Set "" value $2}if["$1"!= "FORKED"]; then$0 FORKED &exit0fiif[-f/etc/sysconfig/androidbackup ]; then
. /etc/sysconfig/androidbackup
elseecho/etc/sysconfig/androidbackup does not exist
exit0fi#debug disabled:#set > /tmp/android/`date +%s`.$RANDOMdbusRef=`kdialog--display :0--progressbar"Backup android..."100`
msg "Attach $DEVNAME$ACTION$ID_SERIAL"0if[!-e$DESTINATION]; then# I could mkdir -p, but sometimes $DESTINATION could just be a network location that's offline
msg "Android will not be backed up: $DESTINATION is not okay"0exit0fimkdir-p/mnt/android
mount$DEVNAME/mnt/android
rc=$?if[$rc-ne0]; then
msg "Problem mounting $DEVNAME to /mnt/android: $rc "0mount|grep android 2>&1| logger -t androidbackup
exit0fiif["`mount |grep -i /mnt/android`" == ""]; then
msg "Cannot find /mnt/android in mount table"0exit0fi
msg "Remove old backup"8[-e$DESTINATION/backup.30 ]&&rm-rf$DESTINATION/backup.30
msg "Start backup"10for i in`/usr/bin/seq30-12`; doif[-e$DESTINATION/backup.$((i-1))]; then
msg "mv $DESTINATION/backup.$((i-1)) $DESTINATION/backup.$i"11mv$DESTINATION/backup.$((i-1))$DESTINATION/backup.$ifidone
msg "Copy"40[-e$DESTINATION/backup.0 ]&&/bin/cp-al$DESTINATION/backup.0 $DESTINATION/backup.1
mkdir-p$DESTINATION/backup.0/
msg "Start rsync"40/usr/bin/rsync -az--numeric-ids--delete--hard-links/mnt/android/$DESTINATION/backup.0/touch$DESTINATION/backup.0/chown-R$CHOWN$DESTINATION/backup.0
umount/mnt/android
msg "Done"100exit0
#!/bin/bash function msg {
/usr/bin/logger -t android "$1"
DISPLAY=:0 qdbus $dbusRef setLabelText "$1"
DISPLAY=:0 qdbus $dbusRef Set "" value $2
} if [ "$1" != "FORKED" ]; then
$0 FORKED &
exit 0
fi if [ -f /etc/sysconfig/androidbackup ]; then
. /etc/sysconfig/androidbackup
else
echo /etc/sysconfig/androidbackup does not exist
exit 0
fi #debug disabled:
#set > /tmp/android/`date +%s`.$RANDOM dbusRef=`kdialog --display :0 --progressbar "Backup android..." 100` msg "Attach $DEVNAME $ACTION $ID_SERIAL" 0 if [ ! -e $DESTINATION ]; then
# I could mkdir -p, but sometimes $DESTINATION could just be a network location that's offline
msg "Android will not be backed up: $DESTINATION is not okay" 0
exit 0
fi mkdir -p /mnt/android mount $DEVNAME /mnt/android
rc=$?
if [ $rc -ne 0 ]; then
msg "Problem mounting $DEVNAME to /mnt/android: $rc " 0
mount | grep android 2>&1 | logger -t androidbackup
exit 0
fi if [ "`mount |grep -i /mnt/android`" == "" ]; then
msg "Cannot find /mnt/android in mount table" 0
exit 0
fi msg "Remove old backup" 8
[ -e $DESTINATION/backup.30 ] && rm -rf $DESTINATION/backup.30 msg "Start backup" 10
for i in `/usr/bin/seq 30 -1 2`; do
if [ -e $DESTINATION/backup.$((i-1)) ]; then
msg "mv $DESTINATION/backup.$((i-1)) $DESTINATION/backup.$i" 11
mv $DESTINATION/backup.$((i-1)) $DESTINATION/backup.$i
fi
done msg "Copy" 40
[ -e $DESTINATION/backup.0 ] && /bin/cp -al $DESTINATION/backup.0 $DESTINATION/backup.1
mkdir -p $DESTINATION/backup.0/ msg "Start rsync" 40
/usr/bin/rsync -az --numeric-ids --delete --hard-links /mnt/android/ $DESTINATION/backup.0/
touch $DESTINATION/backup.0/ chown -R $CHOWN $DESTINATION/backup.0 umount /mnt/android msg "Done" 100
exit 0
Since that file refers to /etc/sysconfig/androidbackup, let's also make that file:
#next line defines the location of all backupsDESTINATION=/home/geeklab/.androidbackup
#next line defines the owner of all files copiedCHOWN=geeklab
#next line defines the location of all backups
DESTINATION=/home/geeklab/.androidbackup #next line defines the owner of all files copied
CHOWN=geeklab
In the KDE Network Manager plasma module, go to the tab VPN, click add and choose PPTP.
Enter and connection name you like. In the field "gateway" type the hostname or IP number of the Windows server you're connecting to. Under Login, Password and NT Domain, fill in your authentication data. Then click advanced.
In the advanced window, disable EAP and enable MPPE. Then click OK.
Go to the tab IPv4. Under method, I chose Automatic (VPN). But Automatic (VPN) addresses only is also a nice option: it sets the IPs but no DNS settings.
Go to the routes sub-tab. Switch on Ignore automatically obtained routes and Use only for resources on this connection to make sure the connection doesn't steal your traffic. Then I entered a manual route: 192.168.178.0/255.255.255.0 to gateway 0.0.0.0 (it is a ppp device after all).
You may want to configure IPv6 as well, but I don't at this moment, so I'm not documenting this.
Step 3: Connect
Click on the icon in the tray and connect.
Ubuntu/Debian
I'm running RedHat-based software on all of my machines. Above information may be useful for Ubuntu/Debian users, but it's not tested and I'm not supporting it.
Servers: RedHat Enterprise Linux/CentOS is more suitable for servers, as there's a lot of professional level support available. I think that's important, because if I say, get a car accident, I want the servers to be managable by another professional.
Desktops/Laptops: RPM packages are pretty exchangable between RedHat-based platforms. That's a good reason to run Fedora on the desktop.
In this post, I'll be writing down all steps required to build a Squid proxy server on a clean "minimal" installation of CentOS 6.0
Step 1. Network configuration
First, install system-config-network or manually configure the network. I prefer system-config-network for easy configurations and vim for more complex configurations. yum -y install system-config-network-tui
If one of the clocks it out of sync, NTLM authentication will not work. Therefore, we synchronize the clocks. Using pool.ntp.org as a source would be good, but if the AD server isn't synchronized with that source, we'd have the same problem. So I'm synchonizing the proxy to the AD server (Win2003SBS actually) instead: rpm -q ntp || yum -y install ntp sed -i "s/^server /#server /g" /etc/ntp.conf echo "server AD-SERVERNAME" >> /etc/ntp.conf ntpdate AD-SERVERNAME #synchronize right now service ntpd start #and keep in sync chkconfig ntpd on
I commented out this line from /etc/squid/squid.conf: http_access allow localnet That line would have allowed users from 10.0.0.0/8+172.16.0.0/12+192.168.0.0/16 and others to use the proxy without authentication. Then I added the following right below that line: acl whitelist dstdom_regex -i "/etc/squid/whitelist" http_access allow whitelist auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp auth_param ntlm children 5 auth_param ntlm keep_alive on acl our_networks src 192.168.0.0/16 acl ntlm proxy_auth REQUIRED http_access allow our_networks ntlm authenticate_ip_ttl 900 seconds
This will allow all valid, logged in users to surf the web. You could also limit which users can surf by adding --require-membership-of=ADGROUPNAME to the ntlm_auth command
The first two lines of above configuration point to a file /etc/squid/whitelist. This file contains domains that should never be denied. My whitelist file contains: \.trendmicro\.com ^trendmicro\.com \.microsoft\.com ^microsoft\.com This means that anything at *.microsoft.com and microsoft.com (without subdomain) as well as *.trendmicro.com as trendmicro.com (my virusscanner) is always allowed for any user. We wouldn't want to block important updates.
Start Squid using /sbin/service squid restart and the proxy is ready.
Step 8. Optional: IPv6 issues
I've been experimenting with IPv6 for a while now, but I don't have IPv6 available on all systems. That caused me some trouble with the next step. I had to give preference to IPv4 above IPv6 by editting /etc/gai.conf: label ::1/128 0 label ::/0 1 label 2002::/16 2 label ::/96 3 label ::ffff:0:0/96 4 label fec0::/10 5 label fc00::/7 6 precedence ::ffff:0:0/96 100 precedence ::1/128 50 precedence ::/0 40 precedence 2002::/16 30 precedence ::/96 20
Step 9. Optional: Some white- and blacklisting
We may not want to allow all sites to be visited. For instance, porn sites are often blocked in office situations. I've got a manual on blacklisting using SquidGuard as well.
On my CUPS server, I've connected a Dymo 400 labelwriter. For some reason, while printing labels perfectly, I just can't get the imagetoraster filter to stop "crashing" with the following error: ERROR: Unable to write raster data to driver!
So I fixed this the dirty way. I downloaded the CUPS Source RPM from CentOS. I installed it to /usr/src/redhat using the command rpm -i cups-1.4.2-35.el6.src.rpm. In the directory SOURCES, I added a file named geeklab.patch containing:
--- cups-1.4.2/filter/imagetoraster.c 2009-06-05 23:38:52.000000000 +0200
+++ cups-1.4.2/filter/imagetoraster.cpatched 2011-10-21 11:18:28.427271405 +0200
@@ -1197,7 +1197,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
}
}
@@ -1293,7 +1293,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
/*
@@ -1333,7 +1333,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
}
}
--- cups-1.4.2/filter/imagetoraster.c 2009-06-05 23:38:52.000000000 +0200
+++ cups-1.4.2/filter/imagetoraster.cpatched 2011-10-21 11:18:28.427271405 +0200
@@ -1197,7 +1197,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
}
}
@@ -1293,7 +1293,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
/*
@@ -1333,7 +1333,7 @@
fputs(_("ERROR: Unable to write raster data to driver!\n"),
stderr);
cupsImageClose(img);
- exit(1);
+ exit(0);
}
}
}
Then I added to the spec: Patch700: geeklab.patch after the line that starts with Patch100: and %patch700 -p1 -b .geeklab just after the line that starts with %patch100
Now you can use the regular rpmbuild commands to build packages: rpmbuild -bs <specname> to build a new SRPM rpmbuild -ba <specname> to build a new SRPM and binary RPMs I personally prefer the first, as I mostly use mock to build clean destination RPMs.