﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava-我爱佳娃-随笔分类-服务配置</title><link>http://www.blogjava.net/alwayscy/category/17764.html</link><description>&lt;br&gt;
有兴趣可以访问下我的生活博客：&lt;a href="http://qqmovie.qzone.com"&gt;qqmovie.qzone.com&lt;/a&gt;</description><language>zh-cn</language><lastBuildDate>Mon, 03 Dec 2012 20:26:35 GMT</lastBuildDate><pubDate>Mon, 03 Dec 2012 20:26:35 GMT</pubDate><ttl>60</ttl><item><title>CAS多点登陆之&amp;ldquo;非主流&amp;rdquo;配置方式</title><link>http://www.blogjava.net/alwayscy/archive/2012/12/01/392322.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sat, 01 Dec 2012 02:43:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2012/12/01/392322.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/392322.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2012/12/01/392322.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/392322.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/392322.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: <h3>场景</h3> <p>想要用到的场景：用户访问WEB服务，WEB访问非WEB服务1，服务1又再访问2、3，合并计算后，把数据返回给WEB及前端用户。想让访问链上的所有服务都能得到认证和鉴权，认为本次请求确实是来自用户的。所以想到用CAS，让用户在一点登录，所有服务都到此处认证和鉴权。 <p><a href="http://www.blogjava.net/images/blogjava_net/alwayscy/Windows-Live-Writer/gaga_96EA/clip_image001%5B34%5D.gif">&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2012/12/01/392322.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/392322.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2012-12-01 10:43 <a href="http://www.blogjava.net/alwayscy/archive/2012/12/01/392322.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>4.8以上SSHD配置特定用户只能在特定目录SFTP,不能进行其它命令操作</title><link>http://www.blogjava.net/alwayscy/archive/2011/10/03/359940.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 02 Oct 2011 19:15:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2011/10/03/359940.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/359940.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2011/10/03/359940.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/359940.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/359940.html</trackback:ping><description><![CDATA[<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">限制用<span style="font: 12.0px 'Heiti SC Light'">户</span>在自己目<span style="font: 12.0px 'Heiti SC Light'">录</span>下<span style="font: 12.0px 'Heiti SC Light'">载</span>文件:</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">建立nagiosdnld</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">指向<span style="font: 12.0px 'Heiti SC Light'">软链</span>接:/usr/local/nagios/dnld -&gt; /Users/nagiosdnld/dnld</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'"><span style="font: 12.0px 'Heiti SC Light'">编辑</span>/etc/sshd_config</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'; min-height: 18.0px"><br />
</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">Match User nagiosdnld</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">&nbsp; &nbsp; &nbsp; &nbsp; X11Forwarding no</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">&nbsp; &nbsp; &nbsp; &nbsp; AllowTcpForwarding no</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">&nbsp; &nbsp; &nbsp; &nbsp; ForceCommand internal-sftp</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">&nbsp; &nbsp; &nbsp; &nbsp; ChrootDirectory /Users/nagiosdnld</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'; min-height: 18.0px"><br />
</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">重<span style="font: 12.0px 'Heiti SC Light'">启</span>下服<span style="font: 12.0px 'Heiti SC Light'">务</span>:</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">launchctl stop org.openbsd.ssh-agent</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px 'Hiragino Kaku Gothic ProN'">launchctl start org.openbsd.ssh-agent</p>
<div><br />
</div>
@import url(http://www.blogjava.net/CuteSoft_Client/CuteEditor/Load.ashx?type=style&file=SyntaxHighlighter.css);@import url(/css/cuteeditor.css);<img src ="http://www.blogjava.net/alwayscy/aggbug/359940.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2011-10-03 03:15 <a href="http://www.blogjava.net/alwayscy/archive/2011/10/03/359940.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DEBIAN下SSH乱码解决</title><link>http://www.blogjava.net/alwayscy/archive/2010/05/08/320347.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sat, 08 May 2010 01:58:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2010/05/08/320347.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/320347.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2010/05/08/320347.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/320347.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/320347.html</trackback:ping><description><![CDATA[<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta name="ProgId" content="Word.Document" />
<meta name="Generator" content="Microsoft Word 12" />
<meta name="Originator" content="Microsoft Word 12" />
<link rel="File-List" href="file:///C:%5CUsers%5Calwayscy%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C02%5Cclip_filelist.xml" />
<link rel="themeData" href="file:///C:%5CUsers%5Calwayscy%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C02%5Cclip_themedata.thmx" />
<link rel="colorSchemeMapping" href="file:///C:%5CUsers%5Calwayscy%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C02%5Cclip_colorschememapping.xml" /><!--[if gte mso 9]><xml>
Normal
0
7.8 磅
0
2
false
false
false
EN-US
ZH-CN
X-NONE
MicrosoftInternetExplorer4
</xml><![endif]--><!--[if gte mso 9]><![endif]--><style>
<!--
/* Font Definitions */
@font-face
{font-family:宋体;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:""@宋体";
panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{
mso-style-parent:"";
margin:0cm;
margin-bottom:.0001pt;
text-align:justify;
text-justify:inter-ideograph;
font-size:10.5pt;
font-family:"Calibri","sans-serif";
mso-bidi-font-family:"Times New Roman";}
.MsoChpDefault
{
mso-bidi-font-family:"Times New Roman";}
/* Page Definitions */
@page
{}
@page Section1
{size:595.3pt 841.9pt;
margin:72.0pt 90.0pt 72.0pt 90.0pt;
layout-grid:15.6pt;}
div.Section1
{page:Section1;}
-->
</style><!--[if gte mso 10]>
<style>
/* Style Definitions */
table.MsoNormalTable
{
mso-style-parent:"";
font-size:10.5pt;
font-family:"Calibri","sans-serif";
mso-bidi-font-family:"Times New Roman";}
</style>
<![endif]-->
<p><span style="font-family: 宋体;">要</span>SSH<span style="font-family: 宋体;">和系统两边都配置对才行，其实也很简单：</span><span><br />
</span><span style="font-family: 宋体;">用命令：</span><span><br />
dpkg-reconfigure locales</span></p>
<p><span style="font-family: 宋体;">进去后只选择</span>zh_CN.UTF-8<span style="font-family: 宋体;">，并设置成默认字符集。</span></p>
<p><span style="font-family: 宋体;">再到</span>/root/.bashrc<span style="font-family: 宋体;">里加上：</span><span><br />
export LC_ALL=zh_CN.UTF-8</span></p>
<p>SSH<span style="font-family: 宋体;">客户端使用</span>UTF-8<span style="font-family: 宋体;">字符集，如</span>SECURECRT<span style="font-family: 宋体;">就在</span><span>SESSION
OPTIONS-&gt;APPERANCE-&gt;CHARACTER ENCODING</span><span style="font-family: 宋体;">里选择</span>UTF-8 </p>
<br />
<img src ="http://www.blogjava.net/alwayscy/aggbug/320347.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2010-05-08 09:58 <a href="http://www.blogjava.net/alwayscy/archive/2010/05/08/320347.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>用YUM安装LAMP</title><link>http://www.blogjava.net/alwayscy/archive/2010/04/20/318811.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Tue, 20 Apr 2010 01:56:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2010/04/20/318811.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/318811.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2010/04/20/318811.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/318811.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/318811.html</trackback:ping><description><![CDATA[一、设置YUM源<br />
<br />
cd&nbsp;/etc/yum.repos.d/&nbsp;<br />
<br />
wget&nbsp;http://centos.ustc.edu.cn/CentOS-Base.repo.5&nbsp;<br />
<br />
mv&nbsp;CentOS-Base.repo.5&nbsp;CentOS-Base.repo&nbsp;<br />
<br />
因为默认的配置文件中服务器地址用的版本号是变量$releasever，所以需要将其替换为实际的版本号，否则是无法连接到服务器的，当前CentOS
最新版是5.3，所以我们修改CentOS-Base.repo&nbsp;<br />
<br />
vi&nbsp;CentOS-Base.repo&nbsp;<br />
<br />
在vi编辑器中进行全文件替换&nbsp;<br />
<br />
:%s/$releasever/5.3/ <br />
<br />
二、安装<br />
1：安装apache<br />
<br />
yum install httpd httpd-devel<br />
<br />
<br />
2：安装mysql<br />
<br />
yum install mysql mysql-server mysql-devel<br />
<br />
<br />
3：安装php<br />
<br />
yum install php php-mysql php-common php-gd php-mbstring php-mcrypt php-devel php-xml<br />
<br />
4：启动apache<br />
<br />
&nbsp;&nbsp; 测试php<br />
<br />
&nbsp;&nbsp; 建立以下文件/var/www/html/test.php<br />
&nbsp;&nbsp; 编辑其内容<br />
<br />
// test.php<br />
&lt;?php<br />
phpinfo();<br />
?&gt;<br />
<br />
5：测试<br />
&nbsp;&nbsp; 在浏览器中输入：http://IP/test.php<br />
&nbsp;&nbsp; 看是否显示PHP的信息<br />
<br />
6：设置开机启动<br />
<br />
chkconfig httpd on<br />
<br />
<img src ="http://www.blogjava.net/alwayscy/aggbug/318811.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2010-04-20 09:56 <a href="http://www.blogjava.net/alwayscy/archive/2010/04/20/318811.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>SAMBA配置后ROOT没有写权限</title><link>http://www.blogjava.net/alwayscy/archive/2010/04/07/317638.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Wed, 07 Apr 2010 06:36:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2010/04/07/317638.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/317638.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2010/04/07/317638.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/317638.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/317638.html</trackback:ping><description><![CDATA[安装SAMBA后，配置下面SHARE：<br />
[popeye]<br />
path = /<br />
valid users = root<br />
read only = no<br />
public = yes<br />
writable = yes<br />
<br />
发现可以浏览目录，但不可写，查了下是SELINUX在作怪，把它禁用即可：<br />
先实时停止它：<br />
setenforce 0<br />
<br />
改配置：<br />
vi /etc/sysconfig/selinux<br />
修改成：<br />
SELINUX=disabled<br />
<br />
<br />
<br />
<img src ="http://www.blogjava.net/alwayscy/aggbug/317638.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2010-04-07 14:36 <a href="http://www.blogjava.net/alwayscy/archive/2010/04/07/317638.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>(转) 设置LINUX共享库so的方法</title><link>http://www.blogjava.net/alwayscy/archive/2009/06/11/281373.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Thu, 11 Jun 2009 01:52:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2009/06/11/281373.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/281373.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2009/06/11/281373.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/281373.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/281373.html</trackback:ping><description><![CDATA[Linux 运行的时候，是如何管理共享库(*.so)的？在 Linux 下面，共享库的寻找和加载是由 /lib/ld.so 实现的。 ld.so 在标准路经(/lib, /usr/lib) 中寻找应用程序用到的共享库。<br />
<br />
但是，如果需要用到的共享库在非标准路经，ld.so 怎么找到它呢？<br />
<br />
目前，Linux 通用的做法是将非标准路经加入 /etc/ld.so.conf，然后运行 ldconfig 生成 /etc/ld.so.cache。 ld.so 加载共享库的时候，会从 ld.so.cache 查找。<br />
<br />
传统上， Linux 的先辈 Unix 还有一个环境变量 - <strong style="color: black; background-color: #ffff66;">LD_LIBRARY_PATH</strong> 来处理非标准路经的共享库。ld.so 加载共享库的时候，也会查找这个变量所设置的路经。但是，有不少声音主张要避免使用 <strong style="color: black; background-color: #ffff66;">LD_LIBRARY_PATH</strong> 变量，尤其是作为全局变量。这些声音是：<br />
*  <strong style="color: black; background-color: #ffff66;">LD_LIBRARY_PATH</strong> is not the answer -  <a href="http://prefetch.net/articles/linkers.badldlibrary.html">http://prefetch.net/articles/linkers.badldlibrary.html</a><br />
* Why <strong style="color: black; background-color: #ffff66;">LD_LIBRARY_PATH</strong> is bad - <a href="http://xahlee.org/UnixResource_dir/_/ldpath.html">http://xahlee.org/UnixResource_dir/_/ldpath.html </a><br />
* <strong style="color: black; background-color: #ffff66;">LD_LIBRARY_PATH</strong> - just say no - <a href="http://blogs.sun.com/rie/date/20040710">http://blogs.sun.com/rie/date/20040710</a><br />
解决这一问题的另一方法是在编译的时候通过 -R&lt;path&gt; 选项指定 run-time path。<br />
<img src ="http://www.blogjava.net/alwayscy/aggbug/281373.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2009-06-11 09:52 <a href="http://www.blogjava.net/alwayscy/archive/2009/06/11/281373.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>动物机又添新功能：在公司用HTTPTUNNEL通过家里ADSL服务器上网</title><link>http://www.blogjava.net/alwayscy/archive/2008/12/03/244176.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Wed, 03 Dec 2008 09:55:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2008/12/03/244176.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/244176.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2008/12/03/244176.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/244176.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/244176.html</trackback:ping><description><![CDATA[继这篇动物机搭建起来后：<br />
<a id="CategoryEntryList1_EntryStoryList_Entries_ctl04_TitleUrl" class="entrylistItemTitle" href="../../alwayscy/archive/2007/11/19/161730.html">自己DIY了一个低功耗基于ADSL的JAVA J2EE服务器</a>
&nbsp; <br />
<br />
又有新功能加入：<br />
<br />
<div>
<a id="homepage1_HomePageDays_DaysList_ctl00_DayItem_DayList_ctl00_TitleUrl" class="postTitle2" href="http://www.cnweblog.com/alwayscy/archive/2008/12/03/295082.html">动物机又添新功能：在公司用HTTPTUNNEL通过家里ADSL服务器上网</a>
</div>
&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 以前家里动物机长开着只是下载电影，公司封了淘宝和MSN，现在又可以用它从公司上网了。
<br />
<br />
可以使用如下模式上网：
<br />
<br />
APP &lt;=&gt; HTTP TUNNEL &lt;=&gt; SERVER
<br />
<br />
HTTP TUNNEL有一个客户端，它可以起一个SOCKS本地代理来接收APP数据，然后打包发送到运行在家里的HTTP TUNNEL服务端，由这个服务端程序通过ADSL出到公网即可。&nbsp;&nbsp;<a href="http://www.cnweblog.com/alwayscy/archive/2008/12/03/295082.html">阅读全文</a><br />
<img src ="http://www.blogjava.net/alwayscy/aggbug/244176.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2008-12-03 17:55 <a href="http://www.blogjava.net/alwayscy/archive/2008/12/03/244176.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>clearcase循环递归加入目录文件</title><link>http://www.blogjava.net/alwayscy/archive/2008/05/26/203005.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Mon, 26 May 2008 10:10:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2008/05/26/203005.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/203005.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2008/05/26/203005.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/203005.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/203005.html</trackback:ping><description><![CDATA[<p>命令行：</p> <p>C:\Program Files\Rational\ClearCase\bin&gt;clearfsimport -recurse -nsetevent d:\temp\cli D:\prj\pcrf\PCFFACN\web\</p> <p>SNAPVIEW时，要把需加入的文件放到一临时目录，不能直接在SNAPVIEW对应的目录加入。</p> <p>另外，要把需要加入的目录先行加入到CC，如上面的cli目录</p><img src ="http://www.blogjava.net/alwayscy/aggbug/203005.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2008-05-26 18:10 <a href="http://www.blogjava.net/alwayscy/archive/2008/05/26/203005.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>最近在用JPA+SPRING+HIBERNATE及MAVEN2中遇到的问题和解决方法做个笔记</title><link>http://www.blogjava.net/alwayscy/archive/2008/01/28/178283.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Mon, 28 Jan 2008 15:08:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2008/01/28/178283.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/178283.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2008/01/28/178283.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/178283.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/178283.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: JPA标准＋HIBERNATE实现＋SPINRG揉和<br>搭建MAVEN2的内网服务器：设置一个目录在WEB服务上可以访问<br>MYSQL可以被外部机器连接<br>cannot connect to VM错误&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2008/01/28/178283.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/178283.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2008-01-28 23:08 <a href="http://www.blogjava.net/alwayscy/archive/2008/01/28/178283.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>自己DIY了一个低功耗基于ADSL的JAVA J2EE服务器</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/19/161730.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Mon, 19 Nov 2007 13:47:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/19/161730.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/161730.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/19/161730.html#Feedback</comments><slash:comments>8</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/161730.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/161730.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 目前网络上大多是PHP或者ASP的空间，如果自己想搭建一个基于JAVA的WEB服务器或者自己调试J2EE的服务都不方便。另一方面，大家现在基本上家里都是包月的ADSL，它的上行带宽有512K，足够搭建一个自己WEB服务器了。不妨参考下我最近DIY的一台功耗不足40W的动物机：BT，电驴，路由器，防火墙，WEB服务器，SUBVERSION代码服务器，APACHE，MYSQL一个都不少!全部配下来RMB1100。&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/11/19/161730.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/161730.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-19 21:47 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/19/161730.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>iptables 端口映射设置</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/18/161423.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 18 Nov 2007 10:54:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/18/161423.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/161423.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/18/161423.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/161423.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/161423.html</trackback:ping><description><![CDATA[<p></p> <p>(转)　 <p>&nbsp; <p>设我们有一台计算机,有两块网卡,eth0连外网,ip为1.2.3.4;eth1连内网,ip为192.168.0.1.现在需要把发往地址1.2.3.4的81端口的ip包转发到ip地址192.168.0.2的8180端口,设置如下:  <p>　　1. iptables -t nat -A PREROUTING -d 1.2.3.4 -p tcp -m tcp --dport 81 -j DNAT --to-destination192.168.0.2:8180  <p>　　2. iptables -t nat -A POSTROUTING -s 192.168.0.0/255.255.0.0 -d 192.168.0.2 -p tcp -m tcp --dport 8180 -j SNAT --to-source 192.168.0.1  <p>　　真实的传输过程如下所示:  <p>　　假设某客户机的ip地址为6.7.8.9,它使用本机的1080端口连接1.2.3.4的81端口,发出的ip包源地址为6.7.8.9,源端口为1080,目的地址为1.2.3.4,目的端口为81.  <p>　　主机1.2.3.4接收到这个包后,根据nat表的第一条规则,将该ip包的目的地址更该为192.168.0.2,目的端口更该为8180,同时在连接跟踪表中创建一个条目,(可从/proc/net/ip_conntrack文件中看到),然后发送到路由模块,通过查路由表,确定该ip包应发送到eth1接口.在向eth1接口发送该ip包之前,根据nat表的第二条规则,如果该ip包来自同一子网,则将该ip包的源地址更该为192.168.0.1,同时更新该连接跟踪表中的相应条目,然后送到eth1接口发出.  <p>　　此时连接跟踪表中有一项:  <p>　　连接进入: src=6.7.8.9 dst=1.2.3.4 sport=1080 dport=81  <p>　　连接返回: src=192.168.0.2 dst=6.7.8.9 sport=8180 dport=1080  <p>　　是否使用: use=1  <p>　　而从192.168.0.2发回的ip包,源端口为8180,目的地址为6.7.8.9,目的端口为1080,主机1.2.3.4的TCP/IP栈接收到该ip包后,由核心查找连接跟踪表中的连接返回栏目中是否有同样源和目的地址和端口的匹配项,找到后,根据条目中的记录将ip包的源地址由192.168.0.2更该为1.2.3.4, 源端口由8180更该为81,保持目的端口号1080不变.这样服务器的返回包就可以正确的返回发起连接的客户机,通讯就这样开始.  <p>　　还有一点, 在filter表中还应该允许从eth0连接192.168.0.2地址的8180端口:  <p>　　iptables -A INPUT -d 192.168.0.2 -p tcp -m tcp --dport 8180 -i eth0 -j ACCEPT </p><img src ="http://www.blogjava.net/alwayscy/aggbug/161423.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-18 18:54 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/18/161423.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>在 Debian/GNU/Linux 上架 MediaWiki！</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/18/161371.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 18 Nov 2007 04:20:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/18/161371.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/161371.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/18/161371.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/161371.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/161371.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/11/18/161371.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/161371.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-18 12:20 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/18/161371.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DEBIAN下的MYSQL的ROOT密码重设</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/18/161370.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 18 Nov 2007 04:19:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/18/161370.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/161370.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/18/161370.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/161370.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/161370.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/11/18/161370.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/161370.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-18 12:19 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/18/161370.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>解释debian下的udev是咋回事</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/14/160553.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Wed, 14 Nov 2007 06:45:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/14/160553.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/160553.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/14/160553.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/160553.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/160553.html</trackback:ping><description><![CDATA[<p>udev是devfs的替代品，可以动态管理/dev下的设备，主要作用是根据硬件的信息（match条件），将它建立到分配（assign语句）到/dev相应的名字下。</p> <p>&nbsp;</p> <p>这篇文章相当不错，易懂：</p> <p><a title="http://www.reactivated.net/writing_udev_rules.html" href="http://www.reactivated.net/writing_udev_rules.html">http://www.reactivated.net/writing_udev_rules.html</a></p><img src ="http://www.blogjava.net/alwayscy/aggbug/160553.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-14 14:45 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/14/160553.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>SUBVERSION的SSL方式安装及最常用而简单的分支使用模式</title><link>http://www.blogjava.net/alwayscy/archive/2007/11/13/160196.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Tue, 13 Nov 2007 05:04:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/11/13/160196.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/160196.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/11/13/160196.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/160196.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/160196.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 网上材料大多比较复杂，本文是简洁明了的快餐式文章。分安装部分和使用部分。<br>安装部分对SUBVERSION做为SSL访问方式配置做了详细说明，使用部分对实际使用时最常用的模式做了说明。&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/11/13/160196.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/160196.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-11-13 13:04 <a href="http://www.blogjava.net/alwayscy/archive/2007/11/13/160196.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>目前发现的最好最快的直接在ECLIPSE中JETTY调试方式</title><link>http://www.blogjava.net/alwayscy/archive/2007/09/13/144969.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Thu, 13 Sep 2007 13:04:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/09/13/144969.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/144969.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/09/13/144969.html#Feedback</comments><slash:comments>8</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/144969.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/144969.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 之前文章提到过用MAVEN2启动JETTY，这里介绍一种直接从ECLIPSE中启动的办法。&nbsp;适用于6.1.3以上，包括6.1.5的JETTY。它主要是利用了JDK的代码自动更换性能(code hot replace)，可以不用重启JETTY就调试、更换资源文件。注意：一定是DEBUG方式运行才有这项功能。所以应该说这篇文章的方法更好：在Run-&gt;Debug中，N...&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/09/13/144969.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/144969.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-09-13 21:04 <a href="http://www.blogjava.net/alwayscy/archive/2007/09/13/144969.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>LINUX配置文件</title><link>http://www.blogjava.net/alwayscy/archive/2007/09/10/144063.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Mon, 10 Sep 2007 10:24:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/09/10/144063.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/144063.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/09/10/144063.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/144063.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/144063.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 本文说明了 Linux 系统的配置文件，在多用户、多任务环境中，配置文件控制用户权限、系统应用程序、守护进程、服务和其它管理任务。这些任务包括管理用户帐号、分配磁盘配额、管理电子邮件和新闻组，以及配置内核参数。本文还根据配置文件的使用和其所影响的服务的情况对目前 Red Hat Linux 系统中的配置文件进行了分类。<br>&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/09/10/144063.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/144063.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-09-10 18:24 <a href="http://www.blogjava.net/alwayscy/archive/2007/09/10/144063.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>windows下如何用bat文件一次运行多个程序？</title><link>http://www.blogjava.net/alwayscy/archive/2007/07/29/133090.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 29 Jul 2007 02:36:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/07/29/133090.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/133090.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/07/29/133090.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/133090.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/133090.html</trackback:ping><description><![CDATA[<p>一般bat只能运行一个程序，有时需要在电脑启动或者自己有多个程序要启动时，编辑一个bat实现一组程序的启动。可以使用start语句。</p> <p>它不支持带空格的目录名，可以先CD到程序目录，再start，举例如下：</p> <p>cd "C:\Program Files\Tor\"<br>start tor.exe<br>cd "C:\Program Files\Privoxy\"<br>start privoxy.exe<br>cd "C:\Program Files\Mozilla Firefox\"<br>start firefox.exe</p> <img src ="http://www.blogjava.net/alwayscy/aggbug/133090.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-07-29 10:36 <a href="http://www.blogjava.net/alwayscy/archive/2007/07/29/133090.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>ie7中文版里英文字体问题</title><link>http://www.blogjava.net/alwayscy/archive/2007/06/05/122184.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Tue, 05 Jun 2007 09:27:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/06/05/122184.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/122184.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/06/05/122184.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/122184.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/122184.html</trackback:ping><description><![CDATA[<p>被强制更新了ie7，英文字体非常不心惯，可以通过以下方法恢复：</p> <p>&nbsp;</p> <p>关闭cleartype的效果：<br>工具－internat选项－高级－多媒体－总是将cleartype应用于html，把钩去掉。</p><img src ="http://www.blogjava.net/alwayscy/aggbug/122184.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-06-05 17:27 <a href="http://www.blogjava.net/alwayscy/archive/2007/06/05/122184.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>subversion以及mysql安装成windows服务</title><link>http://www.blogjava.net/alwayscy/archive/2007/05/16/117937.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Wed, 16 May 2007 14:38:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/05/16/117937.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/117937.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/05/16/117937.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/117937.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/117937.html</trackback:ping><description><![CDATA[<p>STEP 3:配置 <br>打开/conf/目录，打开svnserve.conf找到一下两句：</p>
<p><br># [general]<br># password-db = passwd</p>
<p>去之每行开头的#，其中第二行是指定身份验证的文件名，即passwd文件<br>同样打开passwd文件，将</p>
<p># [users]<br># harry = harryssecret<br># sally = sallyssecret</p>
<p>这几行的开头#字符去掉，这是设置用户，一行一个，存储格式为&#8220;用户名 = 密码&#8221;，如可插入一行：admin = admin888，即为系统添加一个用户名为admin，密码为admin888的用户</p>
<p>&nbsp;</p>
<p>create it:<br>sc create svnservice binpath= "\"c:\program files\Subversion\bin\svnserve.exe\" --service -r D:\svn" displayname= "SVNService" depend= Tcpip</p>
<p>delete it:<br>sc delete svnservice</p>
<br><br>mysql:<br>&nbsp;C:\&gt; <strong>mysqld-nt --install</strong><br>&nbsp;&nbsp; C:\&gt; <strong>NET START MySql<br></strong><br>&nbsp; C:\&gt; <strong>NET STOP MySql</strong><br>&nbsp;&nbsp; C:\&gt; <strong>mysqld-nt --remove</strong><br><br><br>
<img src ="http://www.blogjava.net/alwayscy/aggbug/117937.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-05-16 22:38 <a href="http://www.blogjava.net/alwayscy/archive/2007/05/16/117937.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>解决XP共享文件夹问题</title><link>http://www.blogjava.net/alwayscy/archive/2007/04/07/109076.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sat, 07 Apr 2007 03:09:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/04/07/109076.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/109076.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/04/07/109076.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/109076.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/109076.html</trackback:ping><description><![CDATA[<p>解决方案:针对windows xp </p>
<br>
<p>1. 运行gpedit.msc到组策略管理界面下,计算机配置---&gt;Winsows设置-----&gt;安全设置---&gt;本地策略---&gt;用户权利指派,看看右边有一行:"拒绝从网络访问这台计算机 "看它的属性里有没有guest一项,若有,则删除.</p>
<br>
<p>2. 若还不行,在我的电脑窗口里 工具---&gt;文件夹选项----&gt;查看-----&gt;高级选项里有"使用简单文件共享" 打勾去掉,确定下去,.然后再访问.<br></p>
<br>3. 启用 Guest、修改安全策略允许Guest从网络访问、禁用3里面的安全策略或者给Guest <br>加个密码。 <br><br><a href="http://hi.baidu.com/zhangqiguang123/blog/item/00882ff440c6d3ee7609d7f3.html">http://hi.baidu.com/zhangqiguang123/blog/item/00882ff440c6d3ee7609d7f3.html</a><br>
<img src ="http://www.blogjava.net/alwayscy/aggbug/109076.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-04-07 11:09 <a href="http://www.blogjava.net/alwayscy/archive/2007/04/07/109076.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>停止XP无用服务的BAT命令文件</title><link>http://www.blogjava.net/alwayscy/archive/2007/04/01/107749.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Sun, 01 Apr 2007 06:00:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2007/04/01/107749.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/107749.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2007/04/01/107749.html#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/107749.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/107749.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: 为了大家能更好使用象ECLIPSE这种“巨无霸”（且不断在增长）。网上看的可以优化XP的文章，并自己写了一个脚本文件来停止服务，避免大家一个个去改麻烦。我试了可以，大概停了10多个服务。但有问题别找我呀！俺也不懂的说。														停止不用的服务bat命令																Code highlighting produced by Actip...&nbsp;&nbsp;<a href='http://www.blogjava.net/alwayscy/archive/2007/04/01/107749.html'>阅读全文</a><img src ="http://www.blogjava.net/alwayscy/aggbug/107749.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2007-04-01 14:00 <a href="http://www.blogjava.net/alwayscy/archive/2007/04/01/107749.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>LDAP+OpenSSL集中认证配置</title><link>http://www.blogjava.net/alwayscy/archive/2006/11/28/83737.html</link><dc:creator>我爱佳娃</dc:creator><author>我爱佳娃</author><pubDate>Tue, 28 Nov 2006 07:56:00 GMT</pubDate><guid>http://www.blogjava.net/alwayscy/archive/2006/11/28/83737.html</guid><wfw:comment>http://www.blogjava.net/alwayscy/comments/83737.html</wfw:comment><comments>http://www.blogjava.net/alwayscy/archive/2006/11/28/83737.html#Feedback</comments><slash:comments>5</slash:comments><wfw:commentRss>http://www.blogjava.net/alwayscy/comments/commentRss/83737.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/alwayscy/services/trackbacks/83737.html</trackback:ping><description><![CDATA[
		<p>
				<strong>基本概念<br /></strong>LDAP是以树方式组织的数据库。每个节点可以有什么值是通过类来定义。<br />LINUX或者其它应用的认证就是来BIND LDAP树上的节点，如果能够BIND，就算认证成功。<br />要改变LINUX认证方式，需要让名字服务NSCD能够到LDAP查找用户，这需要nss_ldap.so。<br />得到用户后，再到LDAP去认证，这需要pam_ldap.so实现。<br /><br />公私钥：公钥可以唯一解密私钥加密过的数据，反之亦然。<br />SSL过程：需要两对公私钥(P1,V1),(P2,V2)，假设通信双方是A和B，B是服务器，A要确认和它通信的是B：<br />A-&gt;B: hello<br />B-&gt;A: 用V2加密过的P1（即用户证书，A就用P2解密出P1）<br />A-&gt;B: ok<br />B-&gt;A: 用V1加密的一段信息<br />A-&gt;B: 用P1加密一个自动生成的K（用之前的P1解密成功这段信息则认为B是可信的了）<br />B-&gt;A: 用K加密的数据（之后两对密钥功能结束，由K来加解密数据）<br />这里，P2就是第3方的CA证书，由于非对称加密很慢，所以公私钥只是用来保证K的传送安全，之后通信是用K的对称加密算法来保证。<br /><br /><br /><strong>需要安装的组件<br />Berkeley DB 4.2.52 or later - <a href="http://www.sleepycat.com/">http://www.sleepycat.com/</a>（仅服务端）<br />NSS_LDAP 2.2.X or PAM_LDAP 1.6.X or later – <a href="http://www.padl.com/">http://www.padl.com/</a>（仅客户端）<br />OpenSSL 0.9.7e or later – <a href="http://www.openssl.org/">http://www.openssl.org/</a><br /><br />OpenLDAP 2.3.XX or later - <a href="http://www.openldap.org/">http://www.openldap.org/</a>（仅服务端）<br /></strong></p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img id="Code_Closed_Image_144932" onclick="this.style.display='none'; Code_Closed_Text_144932.style.display='none'; Code_Open_Image_144932.style.display='inline'; Code_Open_Text_144932.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ContractedBlock.gif" width="11" align="top" />
				<img id="Code_Open_Image_144932" style="DISPLAY: none" onclick="this.style.display='none'; Code_Open_Text_144932.style.display='none'; Code_Closed_Image_144932.style.display='inline'; Code_Closed_Text_144932.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ExpandedBlockStart.gif" width="11" align="top" />
				<span id="Code_Closed_Text_144932" style="BORDER-RIGHT: #808080 1px solid; BORDER-TOP: #808080 1px solid; BORDER-LEFT: #808080 1px solid; BORDER-BOTTOM: #808080 1px solid; BACKGROUND-COLOR: #ffffff">
				</span>
				<span id="Code_Open_Text_144932" style="DISPLAY: none">
						<br />
						<!--<br><br>Code highlighting produced by Actipro CodeHighlighter (freeware)<br>http://www.CodeHighlighter.com/<br><br>-->
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
						<span style="COLOR: #000000"># cd openldap-</span>
						<span style="COLOR: #000000">2.3</span>
						<span style="COLOR: #000000">.XX<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># ./configure --prefix</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">/usr --sysconfdir</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">/etc --libexecdir</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">/usr/sbin --mandir</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">/usr/share/man --enable-bdb --enable-crypt --with-tls --without-cyrus-sasl --enable-ldbm<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># make depend<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># make clean<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># make<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># make install<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /></span>
				</span>
		</div>
		<p>OpenSSH: <a href="http://www.openssh.org/">http://www.openssh.org/</a></p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000"># cd /var/tmp<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># tar xvf openssh-</span>
				<span style="COLOR: #000000">3</span>
				<span style="COLOR: #000000">.X.XpX.tar<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># cd openssh-</span>
				<span style="COLOR: #000000">3</span>
				<span style="COLOR: #000000">.X.XpX<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /># ./configure --prefix</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">/usr --with-pam --sysconfdir</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">/etc/ssh --with-ssl-dir</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">/usr</span>
		</div>
		<p>
				<br />
				<br />
				<strong>需要修改的文件</strong>
				<br />服务器端：<br />/etc/openldap/slapd.conf</p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000">include   /etc/openldap/schema/core.schema<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />include   /etc/openldap/schema/cosine.schema<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />include   /etc/openldap/schema/inetorgperson.schema<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />include   /etc/openldap/schema/nis.schema<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />loglevel -</span>
				<span style="COLOR: #000000">1</span>
				<span style="COLOR: #000000">
						<br />
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
						<br />
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />access to attrs</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">shadowLastChange</span>
				<span style="COLOR: #000000">,</span>
				<span style="COLOR: #000000">userPassword<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />      by self write<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />      by * auth<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />access to *<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />      by * read<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />TLSCipherSuite  HIGH:MEDIUM:+SSLv2<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />TLSCACertificateFile /etc/openldap/cacert.pem<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />TLSCertificateFile /etc/openldap/slapd-cert-ldap1.pem<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />TLSCertificateKeyFile /etc/openldap/slapd-key-ldap1.pem<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />TLSVerifyClient never <br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />database    bdb<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />suffix        </span>
				<span style="COLOR: #000000">"</span>
				<span style="COLOR: #000000">dc=example,dc=com</span>
				<span style="COLOR: #000000">"</span>
				<span style="COLOR: #000000">
						<br />
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />rootdn        </span>
				<span style="COLOR: #000000">"</span>
				<span style="COLOR: #000000">cn=Manager,dc=example,dc=com</span>
				<span style="COLOR: #000000">"</span>
				<span style="COLOR: #000000">
						<br />
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />rootpw        secret<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />directory               /var/lib/ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />index    objectClass    eq</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">
				<br />客户端：<br />/etc/ldap.conf</p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000">host ldap1.example.com<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />base dc</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">example</span>
				<span style="COLOR: #000000">,</span>
				<span style="COLOR: #000000">dc</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">com<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />ssl start_tls<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />tls_cacertfile /tmp/cacert.pem</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">      /etc/pam.d/system-auth<br /></p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img id="Code_Closed_Image_145651" onclick="this.style.display='none'; Code_Closed_Text_145651.style.display='none'; Code_Open_Image_145651.style.display='inline'; Code_Open_Text_145651.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ContractedBlock.gif" width="11" align="top" />
				<img id="Code_Open_Image_145651" style="DISPLAY: none" onclick="this.style.display='none'; Code_Open_Text_145651.style.display='none'; Code_Closed_Image_145651.style.display='inline'; Code_Closed_Text_145651.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ExpandedBlockStart.gif" width="11" align="top" />
				<span id="Code_Closed_Text_145651" style="BORDER-RIGHT: #808080 1px solid; BORDER-TOP: #808080 1px solid; BORDER-LEFT: #808080 1px solid; BORDER-BOTTOM: #808080 1px solid; BACKGROUND-COLOR: #ffffff">
				</span>
				<span id="Code_Open_Text_145651" style="DISPLAY: none">
						<br />
						<!--<br><br>Code highlighting produced by Actipro CodeHighlighter (freeware)<br>http://www.CodeHighlighter.com/<br><br>-->
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
						<span style="COLOR: #000000">auth        required      /lib/security/$ISA/pam_env.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />auth        sufficient    /lib/security/$ISA/pam_unix.so likeauth nullok<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />auth        sufficient    /lib/security/$ISA/pam_ldap.so use_first_pass<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />auth        required      /lib/security/$ISA/pam_deny.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />account     sufficient /lib/security/$ISA/pam_ldap.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />account     required      /lib/security/$ISA/pam_unix.so broken_shadow<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />password    required      /lib/security/$ISA/pam_cracklib.so retry</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">3</span>
						<span style="COLOR: #000000"> type</span>
						<span style="COLOR: #000000">=</span>
						<span style="COLOR: #000000">
								<br />
								<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />password    sufficient    /lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />password    required      /lib/security/$ISA/pam_deny.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />session     required      /lib/security/$ISA/pam_limits.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />session     required      /lib/security/$ISA/pam_unix.so<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /></span>
				</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">/etc/sysconfig/authconfig</p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000">USEDB</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">no<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USEHESIOD</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">no<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USELDAP</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USENIS</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">no<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USEKERBEROS</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">no<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USELDAPAUTH</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USEMD5</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USESHADOW</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />USESMBAUTH</span>
				<span style="COLOR: #000000">=</span>
				<span style="COLOR: #000000">no</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">
				<br />/etc/nsswitch.conf</p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img id="Code_Closed_Image_145920" onclick="this.style.display='none'; Code_Closed_Text_145920.style.display='none'; Code_Open_Image_145920.style.display='inline'; Code_Open_Text_145920.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ContractedBlock.gif" width="11" align="top" />
				<img id="Code_Open_Image_145920" style="DISPLAY: none" onclick="this.style.display='none'; Code_Open_Text_145920.style.display='none'; Code_Closed_Image_145920.style.display='inline'; Code_Closed_Text_145920.style.display='inline';" height="16" src="http://www.blogjava.net/images/OutliningIndicators/ExpandedBlockStart.gif" width="11" align="top" />
				<span id="Code_Closed_Text_145920" style="BORDER-RIGHT: #808080 1px solid; BORDER-TOP: #808080 1px solid; BORDER-LEFT: #808080 1px solid; BORDER-BOTTOM: #808080 1px solid; BACKGROUND-COLOR: #ffffff">
				</span>
				<span id="Code_Open_Text_145920" style="DISPLAY: none">
						<br />
						<!--<br><br>Code highlighting produced by Actipro CodeHighlighter (freeware)<br>http://www.CodeHighlighter.com/<br><br>-->
						<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
						<span style="COLOR: #000000">passwd:     files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />shadow:     files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />group:      files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />hosts:      files dns<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />bootparams: nisplus </span>
						<span style="FONT-WEIGHT: bold; COLOR: #800000">[</span>
						<span style="COLOR: #800000">NOTFOUND=return</span>
						<span style="FONT-WEIGHT: bold; COLOR: #800000">]</span>
						<span style="COLOR: #000000"> files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />ethers:     files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />netmasks:   files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />networks:   files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />protocols:  files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />rpc:        files<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />services:   files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />netgroup:   files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />publickey:  nisplus<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />automount:  files ldap<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />aliases:    files nisplus</span>
				</span>
		</div>
		<br />
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">/etc/hosts<br /></p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000">127.0.0.1</span>
				<span style="COLOR: #000000">       MD_Mother_HDA localhost<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /></span>
				<span style="COLOR: #000000">10.56.28.33</span>
				<span style="COLOR: #000000">     ldap1.example.com</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">/etc/ssh/sshd_config<br /></p>
		<div style="BORDER-RIGHT: #cccccc 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: #cccccc 1px solid; PADDING-LEFT: 4px; FONT-SIZE: 13px; PADDING-BOTTOM: 4px; BORDER-LEFT: #cccccc 1px solid; WIDTH: 98%; WORD-BREAK: break-all; PADDING-TOP: 4px; BORDER-BOTTOM: #cccccc 1px solid; BACKGROUND-COLOR: #eeeeee">
				<img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />
				<span style="COLOR: #000000">PasswordAuthentication yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />ChallengeResponseAuthentication yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />UsePAM yes<br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" /><br /><img src="http://www.blogjava.net/images/OutliningIndicators/None.gif" align="top" />Subsystem       sftp    /usr/libexec/sftp-server</span>
		</div>
		<p class="MsoNormal" style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in">
				<br />
				<br />
				<strong>需要重启的服务</strong>
				<br />service nscd restart        <br />service sshd restart<br /><br />另外，这个文件是LDAP命令使用的，不是系统认证所需：<br />/etc/openldap/ldap.conf<br /><br />开始的时候可以不要SSL认证，只需要注释掉ldap.conf中start_tls一句即可。另外，SSL要求验证服务器，所以一定要在/etc/hosts文件里加入服务器完整名字，并与SSL证书中一致。<br /></p>
<img src ="http://www.blogjava.net/alwayscy/aggbug/83737.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/alwayscy/" target="_blank">我爱佳娃</a> 2006-11-28 15:56 <a href="http://www.blogjava.net/alwayscy/archive/2006/11/28/83737.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>