差分
このページの2つのバージョン間の差分を表示します。
両方とも前のリビジョン 前のリビジョン 次のリビジョン | 前のリビジョン | ||
rocky_linux_9インストール手順 [2024/01/25 10:44] – 133.11.222.89 | rocky_linux_9インストール手順 [Unknown date] (現在) – 削除 - 外部編集 (Unknown date) 127.0.0.1 | ||
---|---|---|---|
行 1: | 行 1: | ||
- | # | ||
- | ``` | ||
- | 311-405: 192.168.192.1-207.254 (192.168.192.0/ | ||
- | |||
- | 共有Win: 192.168.192.210-220 | ||
- | |||
- | プリンター: | ||
- | 311固定Win: | ||
- | 405固定Win: | ||
- | |||
- | DHCP範囲: 192.168.196-199.X (/22) | ||
- | NFS共有範囲: | ||
- | | ||
- | |||
- | ルーターなど: | ||
- | GW: 192.168.200.2 (Buffalo) | ||
- | GW: 192.168.200.1 (YAMAHA) | ||
- | GW: 192.168.200.3 (NTT) | ||
- | GW: 192.168.200.4 (WiMAX) | ||
- | 内部用ルーター: | ||
- | 解析サーバ管理コンソール: | ||
- | インフラ用仮想PC: | ||
- | Linuxルーター: | ||
- | |||
- | 解析サーバ: | ||
- | |||
- | NAS: 192.168.202.180-190 | ||
- | |||
- | ``` | ||
- | |||
- | # Hyper-V内部ネットワーク構築 | ||
- | |||
- | https:// | ||
- | |||
- | ``` | ||
- | # | ||
- | New-NetNat -Name ' | ||
- | ``` | ||
- | |||
- | # 内部DNS登録手順 | ||
- | |||
- | ``` | ||
- | ssh -l root 192.168.200.201 | ||
- | #pass: suikou | ||
- | ``` | ||
- | |||
- | 下記のファイルを更新 | ||
- | |||
- | ``` | ||
- | nano / | ||
- | nano / | ||
- | # | ||
- | |||
- | systemctl restart named-chroot | ||
- | ``` | ||
- | |||
- | # | ||
- | |||
- | |初期ユーザ名|パスワード| | ||
- | |root|Suikou123$| | ||
- | |yoshitake|Suikou123$| | ||
- | |||
- | # インストールUSB作成 | ||
- | |||
- | 普通にRocky9.2のISOをUSBに書き込んだものを使うと、 | ||
- | |||
- | ``` | ||
- | invalid image | ||
- | failed to read header unsupported | ||
- | ``` | ||
- | |||
- | などと出る。 | ||
- | https:// | ||
- | https:// | ||
- | |||
- | ``` | ||
- | /< | ||
- | /< | ||
- | shim-x64-15.4-5.x86_64.rpm | ||
- | の中のBOOTX64.EFIを上書き | ||
- | \\m32b.s\yoshitake.kazutoshi\Downloads | ||
- | にも保存している。 | ||
- | ``` | ||
- | |||
- | |||
- | # | ||
- | |||
- | 日本語を選択する(```LANG=ja_JP.UTF-8```にするためで、英語にすると、```LANG=en_US.UTF-8```となり、sortなどのプログラムの挙動が変わってしまうので日本語に揃える) | ||
- | |||
- | - インストール先-> | ||
- | - KDUMP-> | ||
- | - ソフトウェアの選択-> | ||
- | - ネットワークとホスト名-> | ||
- | - 時刻と日付-> | ||
- | - rootパスワード-> | ||
- | - ユーザ-> | ||
- | - DVDからインストールするファイルを取得出来ていないようならURLに`https:// | ||
- | < | ||
- | |||
- | |||
- | を行ってから「インストールの開始」-> | ||
- | |||
- | # | ||
- | |||
- | SATA/ | ||
- | |||
- | http:// | ||
- | |||
- | を見て、 | ||
- | |||
- | ``` | ||
- | sudo lspci |grep -i sas | ||
- | sudo lspci -n |grep 03:00 | ||
- | ``` | ||
- | |||
- | などとやって```8086: | ||
- | |||
- | ``` | ||
- | #sudo dnf install https:// | ||
- | #wget https:// | ||
- | #sudo dnf install ./ | ||
- | sudo dnf install / | ||
- | sudo reboot | ||
- | ``` | ||
- | |||
- | でインストール完了。 | ||
- | |||
- | # | ||
- | |||
- | 下記をインストールする。 | ||
- | |||
- | ``` | ||
- | dnf groupinstall workstation | ||
- | ``` | ||
- | |||
- | # | ||
- | |||
- | ``` | ||
- | sudo su - | ||
- | |||
- | uid=600 | ||
- | id=suikou | ||
- | pass=" | ||
- | groupadd -g $uid $id | ||
- | sudo useradd -u $uid -g $id -d /home/$id -s /bin/bash $id | ||
- | echo -e " | ||
- | gpasswd -a $id wheel | ||
- | sed -i ' | ||
- | |||
- | #/ | ||
- | groupadd -g 602 suikou2 | ||
- | useradd -u 602 -g 602 suikou2 | ||
- | mkdir -p / | ||
- | chown -R suikou2: | ||
- | usermod -d / | ||
- | echo -e " | ||
- | gpasswd -a suikou2 wheel | ||
- | ``` | ||
- | |||
- | # 共有フォルダをマウント | ||
- | |||
- | ``` | ||
- | #sudo yum -y install nfs-utils # | ||
- | |||
- | mkdir -p / | ||
- | |||
- | echo ' | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | m32s:/ | ||
- | ' >> /etc/fstab | ||
- | mount -a | ||
- | |||
- | mkdir /root/.ssh | ||
- | chmod 700 /root/.ssh | ||
- | cp -p / | ||
- | echo " | ||
- | ``` | ||
- | |||
- | # SE Linux無効化設定 | ||
- | |||
- | ``` | ||
- | setenforce 0 | ||
- | sed -i ' | ||
- | ``` | ||
- | |||
- | # Firewall無効化設定 | ||
- | |||
- | ``` | ||
- | systemctl disable --now firewalld.service | ||
- | ``` | ||
- | |||
- | # | ||
- | |||
- | xvncで接続するために必要 | ||
- | |||
- | ``` | ||
- | systemctl set-default multi-user.target | ||
- | ``` | ||
- | |||
- | # ファイルオープン数上限緩和 | ||
- | |||
- | ``` | ||
- | ulimit -Sn 65536 | ||
- | ulimit -Hn 65536 | ||
- | echo '* soft nofile 65536 | ||
- | * hard nofile 65536' >> / | ||
- | ``` | ||
- | |||
- | #Rなど | ||
- | |||
- | ``` | ||
- | dnf install -y epel-release | ||
- | dnf config-manager --set-enabled crb | ||
- | dnf install -y R cairo-devel curl-devel fribidi-devel libtiff-devel | ||
- | #wget https:// | ||
- | dnf install -y / | ||
- | # | ||
- | ``` | ||
- | |||
- | # gcc install等 | ||
- | |||
- | ``` | ||
- | yum -y groupinstall " | ||
- | dnf install -y ruby nodejs golang-bin screen | ||
- | yum install -y lm_sensors iperf3 python3-pip perl-App-cpanminus iftop | ||
- | yum install -y libunwind libgdiplus #for Mono | ||
- | yum -y install ntfs-3g exfatprogs | ||
- | dnf install -y ncdu nethogs iotop-c | ||
- | ``` | ||
- | |||
- | #zabbix | ||
- | |||
- | ``` | ||
- | yum install -y sysstat | ||
- | cp -r / | ||
- | groupadd -g 603 zabbix | ||
- | useradd -u 603 -g 603 zabbix | ||
- | mkdir /run/zabbix | ||
- | chown zabbix: | ||
- | cp / | ||
- | #systemctl daemon-reload | ||
- | systemctl enable --now zabbix-agent.service | ||
- | cp / | ||
- | systemctl enable --now zabbix-iostat.service | ||
- | ``` | ||
- | |||
- | ``` | ||
- | # | ||
- | ssh suikouvm.s | ||
- | zabbix_get -s m64 -k agent.version | ||
- | # | ||
- | ``` | ||
- | |||
- | #podman | ||
- | |||
- | ``` | ||
- | yum -y install podman | ||
- | sed -i 's%# rootless_storage_path = " | ||
- | ``` | ||
- | |||
- | ``` | ||
- | # | ||
- | #nano / | ||
- | # | ||
- | #prefix = " | ||
- | #location = " | ||
- | # | ||
- | # | ||
- | #location = " | ||
- | #insecure = true | ||
- | # | ||
- | # | ||
- | ## | ||
- | # | ||
- | |||
- | sed -i ' | ||
- | |||
- | grep -zPo " | ||
- | |||
- | grep -zPo " | ||
- | |||
- | ``` | ||
- | |||
- | #GNOME-XRDP | ||
- | |||
- | / | ||
- | |||
- | ``` | ||
- | dnf install -y gnome-extensions-app-40.0-3.el9.x86_64 | ||
- | echo " | ||
- | enabled-extensions=[' | ||
- | " > / | ||
- | dconf update | ||
- | |||
- | dnf install -y xrdp | ||
- | sed -i ' | ||
- | systemctl enable --now xrdp | ||
- | #reboot | ||
- | ``` | ||
- | |||
- | #SGE | ||
- | |||
- | ``` | ||
- | dnf install -y cmake hwloc-devel libdb-devel motif-devel ncurses-devel openssl-devel pam-devel rsync systemd-devel wget m4 | ||
- | # | ||
- | #git clone https:// | ||
- | #cd sge_v2023-06-17 | ||
- | #cmake -S . -B build -DCMAKE_INSTALL_PREFIX=/ | ||
- | #cmake --build build -j | ||
- | #cmake --install build | ||
- | #useradd -u 604 -r -d /opt/sge sge | ||
- | #chown -R sge /opt/sge | ||
- | #cd /opt/sge | ||
- | # | ||
- | #yes "" | ||
- | |||
- | # | ||
- | # | ||
- | #rsync -av --progress m32s:/ | ||
- | #chown -R sge / | ||
- | # | ||
- | # | ||
- | |||
- | # | ||
- | mkdir -p / | ||
- | useradd -u 604 -r -d /opt/sge sge | ||
- | rsync -av --progress --exclude spool suikousge:/ | ||
- | chown -R sge / | ||
- | ssh suikousge " | ||
- | cd /opt/sge | ||
- | yes "" | ||
- | source / | ||
- | qconf -rattr exechost complex_values mem_req=`free -g|grep " | ||
- | # | ||
- | ``` | ||
- | |||
- | # RAID用 | ||
- | |||
- | ``` | ||
- | dnf -y install sendmail s-nail | ||
- | systemctl enable --now sendmail | ||
- | ``` | ||
- | |||
- | # NFSホスト設定 | ||
- | |||
- | ``` | ||
- | #sudo yum -y install nfs-utils # | ||
- | |||
- | mkdir /data | ||
- | echo '/data 192.168.200.0/ | ||
- | exportfs -ra | ||
- | # | ||
- | |||
- | systemctl restart rpcbind | ||
- | systemctl enable --now nfs-server | ||
- | #echo " | ||
- | ``` | ||
- | |||
- | # SAMBAホスト設定 | ||
- | |||
- | ``` | ||
- | yum -y install samba | ||
- | mv / | ||
- | echo " | ||
- | workgroup = SAMBA | ||
- | security = user | ||
- | |||
- | passdb backend = tdbsam | ||
- | |||
- | printing = cups | ||
- | printcap name = cups | ||
- | load printers = yes | ||
- | cups options = raw | ||
- | unix extensions = no | ||
- | wide links = yes | ||
- | |||
- | [homes] | ||
- | comment = Home Directories | ||
- | valid users = %S | ||
- | browseable = no | ||
- | writable = yes | ||
- | create mask = 0644 | ||
- | directory mask = 0755 | ||
- | path=/ | ||
- | [data] | ||
- | path = /data/ | ||
- | guest ok = no | ||
- | writable = yes | ||
- | browsable = yes | ||
- | create mask = 0644 | ||
- | directory mask = 0755 | ||
- | " > / | ||
- | |||
- | # | ||
- | / | ||
- | # | ||
- | / | ||
- | |||
- | systemctl enable --now smb nmb | ||
- | ``` | ||
- | |||
- | |||
- | # autofs設定 | ||
- | |||
- | ``` | ||
- | yum -y install autofs | ||
- | sed -i ' | ||
- | echo "/ | ||
- | cp / | ||
- | systemctl enable --now autofs | ||
- | ``` | ||
- | |||
- | # LibreOffice, | ||
- | |||
- | ``` | ||
- | dnf install -y snapd | ||
- | systemctl enable --now snapd | ||
- | sleep 10 | ||
- | snap install libreoffice | ||
- | snap install vlc | ||
- | snap install btop | ||
- | |||
- | #wget https:// | ||
- | dnf -y install / | ||
- | |||
- | #chrome ver: 114.0.5735.198 | ||
- | dnf -y install / | ||
- | |||
- | systemctl enable --now cockpit.socket | ||
- | dnf install -y cockpit-pcp | ||
- | systemctl enable --now pmlogger | ||
- | |||
- | ``` | ||
- | |||
- | # MAMBA | ||
- | |||
- | ``` | ||
- | ## | ||
- | #wget https:// | ||
- | #bash Mambaforge-Linux-x86_64.sh | ||
- | # | ||
- | ##/ | ||
- | # | ||
- | #conda config --set auto_activate_base false | ||
- | ``` | ||
- | |||
- | # JupyterHub | ||
- | |||
- | ``` | ||
- | #conda install -c conda-forge jupyterhub | ||
- | #conda install jupyterlab notebook | ||
- | |||
- | npm install -g configurable-http-proxy yarn | ||
- | pip install jupyterhub jupyterlab notebook jupyterhub-systemdspawner | ||
- | |||
- | #jupyterhub --generate-config | ||
- | #nano jupyterhub_config.py | ||
- | # | ||
- | # | ||
- | # | ||
- | #jupyterhub -f "PATH to jupyterhub_config.py" | ||
- | # | ||
- | |||
- | #/ | ||
- | #[Unit] | ||
- | # | ||
- | # | ||
- | # | ||
- | #[Service] | ||
- | #User=root | ||
- | # | ||
- | # | ||
- | #[Install] | ||
- | # | ||
- | |||
- | # | ||
- | |||
- | mkdir / | ||
- | cp / | ||
- | sed -i 's%^[# ]*c.JupyterHub.bind_url =.*%c.JupyterHub.bind_url = '"' | ||
- | cp / | ||
- | |||
- | # service jupyterhub start | ||
- | systemctl enable --now jupyterhub.service | ||
- | ``` | ||
- | |||
- | # postfix | ||
- | |||
- | ``` | ||
- | dnf -y install postfix | ||
- | systemctl enable --now postfix.service | ||
- | |||
- | #echo ' | ||
- | #postmap / | ||
- | #rm -f / | ||
- | cp / | ||
- | |||
- | echo ' | ||
- | relayhost = [smtp.gmail.com]: | ||
- | smtp_sasl_auth_enable = yes | ||
- | smtp_sasl_password_maps = hash:/ | ||
- | smtp_sasl_security_options = noanonymous | ||
- | smtp_sasl_tls_security_options = noanonymous | ||
- | smtp_sasl_mechanism_filter = plain | ||
- | smtp_use_tls = yes | ||
- | ' >> / | ||
- | |||
- | systemctl reload postfix | ||
- | |||
- | # mdadm --monitor --scan --oneshot --test で確認 | ||
- | |||
- | # postfixはすぐに止まるので、毎日再起動させる | ||
- | |||
- | if [ `cat / | ||
- | |||
- | ``` | ||
- | |||
- | # 追加パッケージインストール | ||
- | |||
- | 初回セットアップ以降に必要があり追加したパッケージの一覧。 | ||
- | |||
- | ``` | ||
- | bash / | ||
- | ``` | ||
- | |||
- | # 簡略化インストール | ||
- | |||
- | ``` | ||
- | sudo su - | ||
- | scp m32s:/ | ||
- | bash run-setup-package.sh | ||
- | #echo -e " | ||
- | #echo -e " | ||
- | ## | ||
- | #echo " | ||
- | |||
- | #bash / | ||
- | |||
- | reboot | ||
- | ``` | ||
- | |||
- | ``` | ||
- | #/ | ||
- | / | ||
- | ``` | ||
- | |||
- | # podman | ||
- | |||
- | WARNを消す (run-setup-user-linux.shのほうで実行) | ||
- | |||
- | ``` | ||
- | $ podman run -it --rm centos:7 | ||
- | WARN[0000] The cgroupv2 manager is set to systemd but there is no systemd user session available | ||
- | WARN[0000] For using systemd, you may need to login using an user session | ||
- | WARN[0000] Alternatively, | ||
- | WARN[0000] Falling back to --cgroup-manager=cgroupfs | ||
- | WARN[0000] The cgroupv2 manager is set to systemd but there is no systemd user session available | ||
- | WARN[0000] For using systemd, you may need to login using an user session | ||
- | WARN[0000] Alternatively, | ||
- | WARN[0000] Falling back to --cgroup-manager=cgroupfs | ||
- | |||
- | と出るので、 | ||
- | |||
- | $ systemctl --user start dbus | ||
- | Failed to connect to bus: メディアが見つかりません | ||
- | |||
- | とやると良いとあるけど、エラー。 | ||
- | |||
- | loginctl enable-linger $USER #/ | ||
- | XDG_RUNTIME_DIR=/ | ||
- | |||
- | とするとWARNが消える。(loginctl enable-lingerのほうだけで消えるみたい) | ||
- | ``` | ||
- | |||
- | #podman repositry | ||
- | |||
- | user権限で実行するなら | ||
- | |||
- | ``` | ||
- | @m32s | ||
- | mkdir / | ||
- | podman run -d -p 5000: | ||
- | podman run -d -p 5050:80 --name registryfront -e ENV_DOCKER_REGISTRY_HOST=m32s -e ENV_DOCKER_REGISTRY_PORT=5000 konradkleine/ | ||
- | # | ||
- | podman generate systemd --files --name registry | ||
- | podman generate systemd --files --name registryfront | ||
- | mkdir -p ~/ | ||
- | cp container-registry* ~/ | ||
- | systemctl --user enable container-registry.service # | ||
- | systemctl --user enable container-registryfront.service # | ||
- | systemctl --user list-dependencies | ||
- | |||
- | mkdir / | ||
- | podman run -d -p 5001: | ||
- | podman run -d -p 5051:80 --name registryfront-quay -e ENV_DOCKER_REGISTRY_HOST=m32s -e ENV_DOCKER_REGISTRY_PORT=5001 konradkleine/ | ||
- | podman generate systemd --files --name registry-quay | ||
- | podman generate systemd --files --name registryfront-quay | ||
- | cp container-registry*quay* ~/ | ||
- | systemctl --user enable container-registry-quay.service | ||
- | systemctl --user enable container-registryfront-quay.service | ||
- | systemctl --user list-dependencies | ||
- | |||
- | |||
- | #nano / | ||
- | [[registry]] | ||
- | prefix = " | ||
- | location = " | ||
- | |||
- | [[registry.mirror]] | ||
- | location = " | ||
- | insecure = true | ||
- | |||
- | [[registry]] | ||
- | prefix = " | ||
- | location = " | ||
- | |||
- | [[registry.mirror]] | ||
- | location = " | ||
- | insecure = true | ||
- | |||
- | #podman pull docker.io/ | ||
- | #curl http:// | ||
- | #podman pull quay.io/ | ||
- | #curl http:// | ||
- | # | ||
- | ``` | ||
- | |||
- | rootでやるなら | ||
- | |||
- | ``` | ||
- | podman run -d -p 5000:5000 --name registry -v / | ||
- | podman run -d -p 8080:80 --name registryfront -e ENV_DOCKER_REGISTRY_HOST=m32s -e ENV_DOCKER_REGISTRY_PORT=5000 konradkleine/ | ||
- | podman generate systemd --files --name registry | ||
- | podman generate systemd --files --name registryfront | ||
- | cp container-registry.service container-registryfront.service / | ||
- | systemctl enable --now container-registry.service | ||
- | systemctl enable --now container-registryfront.service | ||
- | ``` | ||
- | |||
- | # | ||
- | |||
- | 下記をノードごとに実行しておけば、dockerhubにpushできるようになる | ||
- | |||
- | ``` | ||
- | #podman login --get-login docker.io | ||
- | # | ||
- | podman login -v docker.io # | ||
- | ``` | ||
- | |||
- | # | ||
- | |||
- | ``` | ||
- | podman run -it --rm --user $USER -w $PWD -v /data:/data -v / | ||
- | |||
- | podman run -it --rm -w $PWD -v /data:/data -v / | ||
- | # | ||
- | ``` | ||
- | |||
- | # suikougw設定 | ||
- | |||
- | ``` | ||
- | 最小でインストール | ||
- | ID: yoshitake | ||
- | Pass: Suikou123$ | ||
- | |||
- | rootのssh パスワードログインを禁止 | ||
- | |||
- | nfsのファイルを提供する機能は設定する | ||
- | ``` | ||
- | |||
- | # 共有フォルダを全サーバに反映させるには | ||
- | |||
- | ``` | ||
- | cp / | ||
- | |||
- | systemctl restart autofs | ||
- | |||
- | / | ||
- | |||
- | for i in `qhost|tail -n+4|grep -v " - "|cut -f 1 -d " "`; do echo $i; ssh $i "cp / | ||
- | |||
- | ##suikouvm | ||
- | #ssh -l root suikouvm.s #password: suikou | ||
- | #cp / | ||
- | #systemctl restart autofs | ||
- | #ls / | ||
- | ## | ||
- | #ln -s / | ||
- | #exit | ||
- | |||
- | #suikougw | ||
- | ssh suikougw | ||
- | scp m32s.s:/ | ||
- | systemctl restart autofs | ||
- | / | ||
- | exit | ||
- | |||
- | #suikouhttp | ||
- | ssh suikouhttp | ||
- | scp m32s.s:/ | ||
- | systemctl restart autofs | ||
- | rm -f / | ||
- | for i in `cat / | ||
- | exit | ||
- | ``` | ||
- | |||
- | # JupyterHubとRstudio serverをapacheの下で動かす方法 | ||
- | |||
- | ``` | ||
- | nano / | ||
- | |||
- | c.JupyterHub.bind_url = '/ | ||
- | #に変更 | ||
- | systemctl daemon-reload | ||
- | systemctl restart jupyterhub.service | ||
- | ``` | ||
- | |||
- | ``` | ||
- | nano / | ||
- | |||
- | < | ||
- | | ||
- | | ||
- | |||
- | # | ||
- | < | ||
- | AuthType Basic | ||
- | AuthName " | ||
- | AuthUserFile / | ||
- | Require valid-user | ||
- | </ | ||
- | |||
- | | ||
- | | ||
- | | ||
- | | ||
- | | ||
- | | ||
- | |||
- | # | ||
- | < | ||
- | AuthType Basic | ||
- | AuthName " | ||
- | AuthUserFile / | ||
- | Require valid-user | ||
- | </ | ||
- | |||
- | | ||
- | | ||
- | | ||
- | | ||
- | |||
- | < | ||
- | ProxyPreserveHost On | ||
- | ProxyPass http:// | ||
- | ProxyPassReverse http:// | ||
- | </ | ||
- | |||
- | </ | ||
- | |||
- | ``` | ||
- | |||
- | ``` | ||
- | bash / | ||
- | ``` | ||
- | |||
- | 出てきた結果を | ||
- | https:// | ||
- | に張り付ける。 | ||
- | |||
- | |||
- | # Geneiousのインストール | ||
- | |||
- | ``` | ||
- | RHEL9系は2023年のバージョンではサポートされていないようで、redhat_lsb_coreのライブラリをインストールが必要 | ||
- | https:// | ||
- | を参考に | ||
- | cd / | ||
- | dnf install redhat-lsb-core-4.1-56.el9.x86_64.rpm spax-1.6-6.el9.x86_64.rpm redhat-lsb-submod-security-4.1-56.el9.x86_64.rpm | ||
- | |||
- | をしてから、rootでGeniousのインストールプログラムを実行しておく | ||
- | ``` | ||
- | |||
- | # cockpitをapacheのサブディレクトリで動かす | ||
- | |||
- | https:// | ||
- | を参考 | ||
- | |||
- | ``` | ||
- | # | ||
- | #nano / | ||
- | [WebService] | ||
- | Origins = https:// | ||
- | ProtocolHeader = X-Forwarded-Proto | ||
- | AllowUnencrypted = true | ||
- | UrlRoot = /cp/ | ||
- | |||
- | # | ||
- | #nano / | ||
- | < | ||
- | ServerName suikou.fs.a.u-tokyo.ac.jp | ||
- | SSLProxyEngine | ||
- | RewriteEngine | ||
- | ProxyPreserveHost | ||
- | ProxyRequests | ||
- | ProxyErrorOverride | ||
- | SSLProxyVerify optional_no_ca | ||
- | SSLProxyCheckPeerCN Off | ||
- | SSLProxyCheckPeerName Off | ||
- | SSLProxyCheckPeerExpire Off | ||
- | RequestHeader set " | ||
- | RewriteCond %{HTTP: | ||
- | RewriteCond %{HTTP: | ||
- | RewriteRule " | ||
- | RewriteCond ${HTTP: | ||
- | RewriteRule " | ||
- | </ | ||
- | ``` | ||
- | |||
- | ただし、直接各サーバにはアクセスできなくなるみたい。 | ||
- | |||
- | # m768 SSH設定 | ||
- | |||
- | ``` | ||
- | nano / | ||
- | ``` | ||
- | |||
- | ``` | ||
- | Port 22 | ||
- | Port 8022 | ||
- | |||
- | # | ||
- | Match LocalPort 8022 | ||
- | PermitRootLogin no | ||
- | PasswordAuthentication no | ||
- | ``` | ||
- | |||
- | ``` | ||
- | systemctl restart sshd | ||
- | ``` |