©2009 HP Confidential 1 ©2010 HP / Intel / Red Hat restricted 1 Bruno CornecHP, Open Source Profession Lead Linux Security.

Slides:



Advertisements
Similar presentations
Scientific Linux Network Installation Pete Gronbech: April 2005 RAL.
Advertisements

INSTALLING LINUX.  Identify the proper Hardware  Methods for installing Linux  Determine a purpose for the Linux Machine  Linux File Systems  Linux.
PXE netboot installation of Linux/SuSE
Course materials may not be reproduced in whole or in part without the prior written permission of IBM. 5.1 © Copyright IBM Corporation 2008 Unit 2 Installing.
Creating a [legacy & EFI] PXE server using pxelinux
Leveraging WinPE and Linux Preboot for Effective Provisioning Jonathan Richey | Director of Development | Altiris, Inc.
1 Web Server Administration Chapter 3 Installing the Server.
Lesson 4-Installing Network Operating Systems. Overview Installing and configuring Novell NetWare 6.0. Installing and configuring Windows 2000 Server.
1 CMPT 471 Networking II DHCP © Janice Regan,
Automating Linux Installations at CERN G. Cancio, L. Cons, P. Defert, M. Olive, I. Reguero, C. Rossi IT/PDP, CERN presented by G. Cancio.
Installing Linux Redhat: A how to guide in installing and configuring Redhat 6.2.
Installing Windows Deployment Service
DHCP server & Client Objectives Contents
Installing and maintaining clusters of FreeBSD servers using PXE and Rsync Cor Bosman XS4ALL
Linux+ Guide to Linux Certification Chapter Three Linux Installation and Usage.
Fundamentals of Networking Discovery 1, Chapter 2 Operating Systems.
Configuration of Linux Terminal Server Group: LNS10A6 Thebe Laxmi, Sharma Prabhakar, Patrick Appiah.
Guide to Linux Installation and Administration, 2e1 Chapter 3 Installing Linux.
IT:NETWORK:MICROSOFT SERVER 2 DHCP AND WINDOWS DEPLOYMENT SERVICES.
DYNES: Building a Distributed Networking Instrument Ben Meekhof ATLAS Great Lakes Tier2 University of Michigan HEPiX 2012, Oct
Linux: A Wireless Solution Josh Joiner. Agenda Introduction Minimum Hardware Basic Components Steps on setting up a wireless network Security Concerns.
DHCP server & Client Objectives –to learn how to setup dhcp servers Contents –Download and Install The DHCP Package –The /etc/dhcpd.conf File –Upgrading.
Enabling Palacios PXE-Boot Chen Jin Bharath Pattabiraman Patrick Foley.
Deploying Windows 7 Lesson 3. Objectives Understand enterprise deployments Capture an image file Modify an image file Deploy an image file.
Scott Drucker, Systems Engineer Migrating to Microsoft Vista with WinINSTALL.
Computer Systems Lab The University of Wisconsin - Madison Department of Computer Sciences Linux Clusters David Thompson
INFSO-RI Enabling Grids for E-sciencE Installation of an APT+kickstart server Giuseppe Platania INFN Catania EMBRACE Tutorial Clermont-Ferrand,
CHAPTER 2. Overview 1. Pre-Installation Tasks 2. Installing and Configuring Linux 3. X Server 4. Post Installation Configuration and Tasks.
Terminal Servers in Schools A second life for your older computers.
ECMM6018 Enterprise Networking for Electronic Commerce Tutorial 7 Dynamic Host Protocol.
1 Copyright © 2015 Pexus LLC Patriot PS Personal Server Installing Patriot PS ISO Image on.
CIT 470: Advanced Network and System AdministrationSlide #1 CIT 470: Advanced Network and System Administration Workstations.
Chapter 8: Installing Linux The Complete Guide To Linux System Administration.
The 2001 Tier-1 prototype for LHCb-Italy Vincenzo Vagnoni Genève, November 2000.
2: Operating Systems Networking for Home & Small Business.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
Juan Ortega 10/7/09 NTW342. Setting up the Configuration File ddns-update-style interim; Ignore client-updates; Subnet netmask
MREPO: Yum/Apt repository kickstart installation via PXE GIUSEPPE PLATANIA INFN Catania I Corso di formazione INFN.
PXEBOOT. What is PXEBOOT. The Preboot Execution Environment (PXE) is a service, Establish client/server communication and it will install the OS to the.
Operated by Los Alamos National Security, LLC for NNSA U N C L A S S I F I E D Slide 1 Institutional Install of Red Hat Enterprise Linux From One CD In.
© Bruno Cornec / HP - Document under/sous FDLBruno CornecHPFDL Date : 9/19/2016 Page 1 Linux Deployment.
© 2007 IBM Corporation 9/26/2016 Automated Generation of Kickstart Files IBM.
© Bruno Cornec / HP - Document under/sous CC-by- SA-3.0Bruno CornecHPCC-by- SA-3.0 Date : 9/26/2016 Page 1 MondoRescue Mondo Rescue: A GPL disaster recovery.
© Bruno Cornec / HP - Document under/sous FDLBruno CornecHPFDL Date : 9/28/2016 Page 1 MondoRescue Mondo Rescue: A GPL disaster recovery solution Bruno.
© Bruno Cornec / HP - Document under/sous CC-by- SA-3.0Bruno CornecHPCC-by- SA-3.0 Date : 9/29/2016 Page 1 MondoRescue Mondo Rescue: A GPL disaster recovery.
© 2007 IBM Corporation 9/29/2016 Automated Generation of Kickstart Files IBM.
©2009 HP Confidential 1 ©2010 HP / Intel / Red Hat restricted 1 Bruno CornecHP, Open Source Profession Lead Jean-Marc AndréOSSI Solution Architect The.
LinuxCOE (automatic deployment, patch management, retrofit) Mondorescue (Imaging creation and redeployment) metamrepo (conf creation) ISC DHCP serverhpa.
© Bruno Cornec / HP - Document under/sous FDLBruno CornecHPFDL Date : 10/2/2016 Page 1 MondoRescue Mondo Rescue: A GPL disaster recovery solution Bruno.
Automated installations
BY: SALMAN 1.
Andrea Chierici Virtualization tutorial Catania 1-3 dicember 2010
Mondorescue and PXE Stuff I took a few of days of googling
Create setup scripts simply and easily.
Guide to Linux Installation and Administration, 2e
BY: SALMAN.
Welcome to Linux Chap#1 Hanin Abdulrahman.
Provisioning with custom builds and Kickstart
C without OMMERCIAL PRODUCT Without Product
My Faculty Name Is Mr.Dattarey Joshi
The ProLiant USB Setup Key
One-keystroke system installation and configuration
Diskless Remote Boot Linux
PXE+Kickstart.
Intel® vPro™ Technology
Installing Linux Redhat:
SUSE Linux Enterprise Desktop Administration
Welcome to Linux Chap#1.
Presentation transcript:

©2009 HP Confidential 1 ©2010 HP / Intel / Red Hat restricted 1 Bruno CornecHP, Open Source Profession Lead Linux Security

Bruno Cornec 2 2 Introducing Myself ● Software engineering and Unices since 1988 ● Mostly Configuration Management Systems (CMS), Build systems, quality tools, on multiple commercial Unix systems ● Discover Open Source & Linux (OSL) & first contributions in 1993 ● Full time on OSL since 1995, first as HP reseller ● Currently : ● Master Technology Architect on OSL for the HP/Intel Solution Center, Grenoble ● OSL HP Advocate ● EMEA OSL HP Profession Lead ● Solutions Linux Conference and OWF board member ● MondoRescue, Dploy.org, Project-Builder.org project lead ● LinuxCOE, mrepo, tellico, rinse, fossology, collectl contributor ● FOSSBazaar and OSL Governance enthusiast ● Mandriva, Mageia, Fedora packager

©2009 HP Confidential 3 ©2010 HP / Intel / Red Hat restricted 3 Agenda

©2009 HP Confidential 4 ©2010 HP / Intel / Red Hat restricted 4 Objective and Agenda Objective: To describe how security is managed on Red Hat Enterprise Linux Clients with Intel based HP ProLiant servers Agenda: Definitions Automatic media deployment Automatic network deployment Automatic images deployment

©2009 HP Confidential 5 ©2010 HP / Intel / Red Hat restricted 5 Deployment definition The deployment consists of all the means (both software and hardware) to install and configure firmware, operating system and all needed applications on a computer or a set of computers, minimizing manual interactions and creating an homogeneous and reproduceable setup PXE (Intel): Pre-boot eXecution Environment Allows a PC to boot through the network iLO (hp):Integrated Lights Out Management Card Allows firmware update and management through a dedicated LAN interface Software tools: ether-wake/wol, DHCP server, TFTP server, NFS/FTP server, syslinux/isolinux/pxelinux, kickstart and Satellite (RHEL), MondoRescue

©2009 HP Confidential 6 ©2010 HP / Intel / Red Hat restricted 6 Deployment approaches Automatic system deployment: ● Hardware neutral ● Update process quick ● Distribution dependant ● Installation quick ● Excellent customisation System Images deployment : ● Distribution/OS neutral ● Installation quicker ● Update process longer ● Hardware dependant ● Good customization ● You need BOTH !!

©2009 HP Confidential 7 ©2010 HP / Intel / Red Hat restricted 7 Installation detailed ● PC power-on (POST) ● BIOS pass control to boot device (floppy / bootable CD) ● Most boot floopy use syslinux with a syslinux.cfg config file ● syslinux loads initrd and boots the kernel with params default linux prompt 1 timeout 600 display boot.msg label linux kernel vmlinuz append initrd=initrd.img lang= devfs=nomount ramdisk_size=7168 vga=788 label ks kernel vmlinuz append ks=floppy initrd=initrd.img lang= devfs=nomount ramdisk_size=7168 ● The kernel launch the install

©2009 HP Confidential 8 ©2010 HP / Intel / Red Hat restricted 8 Deployment detailed (step 1) ● PC power-on (POST) ● BIOS pass control to boot device (PXE firmware) ● DHCP request from PXE client ● DHCP server provides an IP configuration ● allow bootp; ● allow booting; ● subnet netmask { ● option routers ; ● option subnet-mask ; ● default-lease-time 21600; ● max-lease-time 43200; ● group { ● next-server ;# tftp server ● filename "pxelinux.0"; ● host test3 { ● hardware ethernet 00:01:02:06:25:F1; ● fixed-address ; ● }

©2009 HP Confidential 9 ©2010 HP / Intel / Red Hat restricted 9 Deployment detailed (step 2) ● PXE request from PXE client ● DHCP server provides boot file name and boot server ● TFTP request from PXE client ● pxelinux.0 loaded on client ● pxelinux reads its config file from pxelinux.cfg/ip-addr default ks Prompt 0 display boot.msg label ks kernel kernel/vmlinuz-rh7.2 append initrd=initrd/initrd-rh7.2.img devfs=nomount lang= ramdisk_size=7168 ks=nfs: :/tftpboot/ks/ks72.cfg label mdk81-auto kernel kernel/vmlinuz-mdk8.1 append initrd=initrd/initrd-mdk8.1.img ramdisk_size=32000 kickstart=floppy automatic=method:ftp,network:dhcp,server: ,directory:/pub/mandrake/8.1 auto_install=/pub/mandrake/auto_inst.pl

©2009 HP Confidential 1010 ©2010 HP / Intel / Red Hat restricted 1010 Deployment detailed (step 3) ● pxelinux loads initrd and boots the kernel with params ● default ks ● lang fr_FR ● langsupport --default fr_FR fr_FR en_US ● network --bootproto bootp --device eth0 ● url --url ftp:// /pub/rrhel/6/x86_64 ● keyboard "fr-latin1" ● zerombr yes ● clearpart --all ● part /boot --size 50 ● part swap --size 512 ● part / --size 1000 ● part /usr --size 3000 ● part /var --size 256 ● part /opt --size 512 ● part /home --size 1 --grow ● install ● mouse --device psaux genericps/2 --emulthree ● timezone Europe/Paris ● xconfig --monitor "HP D2807A Ultra VGA " ● rootpw linux1 ● auth --useshadow --enablemd5 ● lilo --location mbr ● Reboot ● %packages Server ● %post ● exec > /tmp/postinstall.log 2>&1 ● cat > /tmp/postinstall << FINI ● echo "End postinstall" ● FINI ● chmod 755 /tmp/postinstall ; /tmp/postinstall

©2009 HP Confidential1 ©2010 HP / Intel / Red Hat restricted1 Imaging deployment ● Install the distribution ● Apply updates, configure... ● Install mondo/mindi/mindi-busybox/afio/buffer ● Create ISO images of the installed system through NFS ● mondoarchive -d /images -E '/home|/tmp' -9 -s 4380m -n /home/ftp/images ● Integrate the content of the mondo restore image in the previous configuration label mondo kernel kernel/vmlinuz-mondo append initrd=initrd/initrd-mondo.img devfs=nomount ramdisk=23352 ramdisk_size=23352 expert_mode root=/dev/ram0 ● Details available in README.pxe

©2009 HP Confidential 1212 ©2010 HP / Intel / Red Hat restricted 1212 How to get in contact with us HP Linux Profession Lead EMEA Open Source Advocate Intel Account Manager for HP EMEA TSG/ISS Stefanie Schütze Red Hat Alliance Manager HP EMEA Michaela Weissensteiner +49 (0)

©2009 HP Confidential 1313 ©2010 HP / Intel / Red Hat restricted 1313 Thank you ! Q&A