April 11, 2017

Useful Links

https://www.exratione.com/2016/05/a-mailserver-on-ubuntu-16-04-postfix-dovecot-mysql/

https://webmail.wjw.nz/postfixadmin/list.php?table=admin

http://blog.programster.org/set-up-a-local-ubuntu-mirror-with-apt-mirror/

March 24, 2017

Autostart VM's from CLI

If VM's are configured Startup/shutdown on boot, you can start manually by running:

/sbin/vmware-autostart.sh start

on the command line.


Login to Synology NAS with SSH Keys

On the host you want to be able to login from:

run "ssh-keygen -t rsa" make sure to have a blank passphrase

cat /root/.ssh/id_rsa.pub and save that info for later

On the Synology NAS

Edit /etc/ssh/sshd_config change

#RSAAuthentication yes
#PubkeyAuthentication yes
#AuthorizedKeysFile .ssh/authorized_keys

to this:

#RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys

Add the necessary files, folders and permissions

mkdir /root/.ssh
touch /root/.ssh/authorized_keys
chmod 700 /root/.ssh
chmod 644 /root/.ssh/authorized_keys

Add your pub key to /root/.ssh/authorized_keys:

echo "ssh-rsa yourkey youruser@yourhost" >> /root/.ssh/authorized_keys

Done!

ESX VM and Host Shutdown Script

#!/usr/bin/perl

# Get list of ALL VM's
# (\d{1,2})\s+([\w\d\-]+).*\n

$cmdvmlist = "vim-cmd vmsvc/getallvms";

# RegEX for running VM's
# ([\d]+\-[\w\d\s\.]+)\n\s+World ID:\s(\d+)

$cmdvmrunning = "esxcli vm process list";

$esxhost = "root\@192.168.1.26";

$vmlist = `ssh $esxhost $cmdvmlist`;

#print $vmlist;

# ([\d]+\-[\w\d\s\.]+)\n\s+World ID:\s(\d+)

my @shutdownorder;

$count=0;

print "VM Inventory on $esxhost\n";

while ($vmlist =~ /(\d{1,2})\s+([\w\d\-]+).*\n/g)
        {

        # Don't shutdown the VM running this script until last as it also controls APCUPSD

        if ($1 != 30)
                {
                $shutdownorder[$count] = $1;
                $shutdownordername[$count] = $2;
                $count++;
                }

        }

print "VMID\tName\n";

my $index;
for my $order (@shutdownorder) {
  print "$order \t $shutdownordername[$index++]\n";
}

# If shutdown argument is present, shutdown VM's

if ($ARGV[0] eq "shutdown")
        {
        open (my $fh, '>', "/tmp/esxhostscript");

        print "\nCreating Script for ESX Host\nUploading ";

        while (@shutdownorder)
                {
                $vm = shift(@shutdownorder);

                print $fh "vim-cmd vmsvc/power.shutdown $vm\n";
                }

        print $fh "shutdown +3\n";

        close $fh;

        # Copy script to ESX Host

        system("scp","/tmp/esxhostscript","root\@192.168.1.26:/tmp/esxhostscript");

        # Add Execute Permission

        system("ssh","root\@192.168.1.26","chmod +x /tmp/esxhostscript");

        # Execute Script

        system("ssh","root\@192.168.1.26","/tmp/esxhostscript");

        print "Waiting for VM's to shutdown\n";

        while (CheckRunning())
                {
                print ".";
                sleep 5;
                }
        print "\n\n";

        # SHUTDOWN NAS

        @nasshut1 = `ssh -p 9999 192.168.1.14 shutdown -h now`;
        @nasshut2 = `ssh -p 9999 192.168.1.24 shutdown -h now`;

        }

else
        {
        printf "shutdown argument not passed, no action taken\n"
        }


sub CheckRunning
        {

        $vmrun = `ssh $esxhost $cmdvmrunning`;

        while ($vmrun =~ /([\d]+\-[\w\d\s\.]+)\n\s+World ID:\s(\d+)/g)
                {
                if ($2 ne "91789")
                        {
                        return 1;
                        }
                }
        return 0;
        }

January 09, 2017

LetsEncrypt

apt-get install python-letsencrypt-apache

letsencrypt -w /var/lib/roundcube -d webmail.wjw.nz

/etc/letsencrypt/live/webmail.wjw.nz/fullchain.pem


September 13, 2016

Cleanly shutdown ESXi 6.0 / 6.5 and Synology NAS with APCUPSD and ESXCLI

I have this working now:

You will need the NAS' to be set to startup on power failure and have wakeonlan enabled.

1. Setup autologins for the root user to:
Generate Key on master - ssh-keygen -t rsa
Access the ESXi Host via SSH
/etc/ssh/keys-root/authorized_keys
Access the Synology NAS via SSH
/root/.ssh/authorized_keys

More info here: Login-to-synology-nas-with-ssh-keys

2. Create a script on the Linux host that:
Gets a list of all "Running VM's"
Creates a script on the ESXHost containing the commands to shutdown the VM's
Execute the ESX Script via SSH
Shutdown the Synology NAS

  VM Shutdown Script

3. Setup APCUPSD to:
Run the script on the local linux host to create the ESX Script
Shutdown the ESX Host via SSH (local VM will shutdown as part of this)

First of all we need a linux host with APCUPSD

Edit /etc/apcupsd/onbattery

Add:

#Shutdown running VM's
/usr/local/bin/ESX-shutdown-running.pl
#Shutdown NAS1
ssh -p 9999 192.168.1.24 shutdown -h
#Shutdown NAS2
ssh -p 9999 192.168.1.14 shutdown -h

Also to get things going again if it comes off battery:

Edit /etc/apcupsd/offbattery

# ssh -p 9999 192.168.1.24 shutdown -h
wakeonlan 00:11:32:39:87:25
# ssh -p 9999 192.168.1.14 shutdown -h
wakeonlan 00:11:32:38:E8:EF
# Reboot ESX Host, for me this is better than just autostarting the shutdown
# VM's as the storage doesnt always reconnect correctly.
ssh 192.168.1.26 reboot


-----------------

Notes..

esxcli --sessionfile /root/esxhost  network ip interface list
esxcli --sessionfile /root/esxhost vm process list

esxcli vm process kill -t [soft,hard,force] -w WorldNumber


September 11, 2016

Installing VMware CLI Tools on Linux

Download the 6.0 CLI tools from:

https://my.vmware.com/web/vmware/details?downloadGroup=VCLI600&productId=491

Download Apache 1.3.0 Source for SOAP

wget https://www.apache.org/dist/etch/1.3.0/apache-etch-1.3.0-src.tar.gz

tar -xvf apache-etch-1.3.0-src.tar.gz

Install the following via CPAN:

SOAP-Lite, Version 1.20 - install PHRED/SOAP-Lite-1.20.tar.gz
ExtUtils::MakeMaker, Version: 6.96 - install BINGOS/ExtUtils-MakeMaker-6.96.tar.gz
Module::Build, Version: 0.4205 - install LEONT/Module-Build-0.4205.tar.gz
Net::FTP, Version: 2.77 - install GBARR/libnet-1.22.tar.gz
LWP, Version: 5.837 - install GAAS/libwww-perl-5.837.tar.gz
LWP::Protocol::https 5.805 or newer - install MSCHILLI/LWP-Protocol-https-6.06.tar.gz
Socket6  0.23 or newer - install UMEMOTO/Socket6-0.28.tar.gz