Difference between revisions of "Network Questions"
Line 108: | Line 108: | ||
== How do I setup ssh keys? == | == How do I setup ssh keys? == | ||
===Windows=== | ===Windows=== | ||
− | + | To set up ssh keys on windows hosts first make sure you have bosh putty and puttygen installed[https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html here] . Open puttygen, make sure RSA is selected at the bottom and click generate. Move your mouse around in the blank space when prompted and wait until the key finishes generating. Click Save private key and put this file away somewhere (Do not just drop it on your desktop). Then select everything in the text box labeled "Public key for pasting into OpenSSH authorized_key file" and copy it to a file somewhere near your private key. Next ssh into the machine you want keys for and paste the contents of your public key file into the folder ~/.ssh/authorized_keys, if this file dose not exist you can make it. Then, run the command <code>chmod 700 ~/.ssh/</code> and <code>chmod 600 ~/.ssh/authorized_keys</code> then log off of the machine. Next time you log on with putty on the left select ssh>auth and click the browse button at the bottom of the list. Find, and Select the private .ppk file you saved earlier and connect to the machine with the public key, If done correctly you should not be prompted for a password in order to login. | |
== How do I access the campus VPN? == | == How do I access the campus VPN? == |
Revision as of 09:10, 15 April 2020
What network storage is available to me?
All CIS users have home directory on the department file server to store files. Anything you place in your home directory is backed up nightly, with revisions stored going back six months.
Linux Systems
On department linux systems, your home directory is automatically mounted as $HOME
. The full path of your home directory can be found using the finger
command on any linux host.
finger testacct Login: testacct Name: Testing Tester Directory: /home/t/testacct Shell: /bin/bash Never logged in. No mail. No Plan.
In this case, testacct's home directory is /home/t/testacct
.
Windows Systems
On department Windows systems, your home directory should be mounted as the U:\ drive. If you are manually mounting a drive, use the URI \\files.cs.ksu.edu\<username>
where <username>
is your eID.
Transient Storage
If you need a large amount of space temporarily, you can request space in the transient volume (send an email to help@cis.ksu.edu). There are no quotas on directories in this volume, but there are also no backups made of files here. Support staff may also ask you to clean files out periodically to make room for others. On department linux systems, your transient directory will be found in /transient/<username>
. On department Windows systems, you can mount the share \\files.cs.ksu.edu\transient\<username>
to a drive letter of your choosing.
How do I setup CGI on my web page?
Please see the page on Personal Web Pages.
Why don't you have an FTP server?
FTP is a very old protocol. It was designed before security considerations were a major part of protocol design. As such, passwords to the FTP server are sent in plain text---any clever user on the network can snoop your packets and steal your password. This would allow that user to gain access to your account, which is an unacceptable violation of our security.
If you need to access your home directory from a remote location, there are two different methods for doing so. See the documentation in the CIS Systems UserGuide for Remote Access or in the FrequentlyAskedQuestions about how to access your home directory from a non-CIS computer.
How do I use HTTP authentication?
To setup password authentication for a directory in your personal web space
follow these steps from a linux shell (you will want to change passwordProtectedDir
to whatever name you want and use your own usernames). <your_home_dir_path>
is the full path to your home directory. If you don't know what this is, use the finger command from the command prompt of any linux host ("finger <eid>
", where <eid>
is your eID).
cd ~/public_html/ mkdir passwordProtectedDir cd passwordProtectedDir htpasswd -c .htpasswd user_who_gets_access htpasswd .htpasswd other_user cat << EOF > ~/public_html/passwordProtectedDir/.htaccess AuthType Basic AuthName "Checking Password" AuthUserFile <your_home_dir_path>/public_html/passwordProtectedDir/.htpasswd Require valid-user EOF
Now create any files you want in the directory and set permissions appropriately.
chmod o+rx ~/public_html/passwordProtectedDir chmod o+r ~/public_html/passwordProtectedDir/*.*
If you would like your files to only be password protected off-campus, use this command to make your htaccess file.
cat << EOF > ~/public_html/passwordProtectedDir/.htaccess AuthType Basic AuthName "Checking Password" AuthUserFile <your_home_dir_path>/public_html/passwordProtectedDir/.htpasswd Require valid-user Order Allow,Deny # This restricts access without a password to the KSU network Allow from 12# 130.0.0/16 # This restricts access without a password to the CIS network #Allow from 12# 130.8.0/22 Satisfy any EOF
Why am I getting 500 Interal Server Error on all my scripts?
We use programs named suexec
and suphp
to make sure that all of your scripts run as you. This allows your scripts to access files that would normally be private and inaccessible by the web server. However, for security these programs will not allow your scripts to run unless the permissions set on your files and on the directories containing them are safe.
For CGI scripts, you must make sure the following are true:
- Your script must be stored in your home directory in the subdirectory named
public_html/cgi-bin
. You cannot place your scripts anywhere else. - You must make sure that your home directory, the
public_html
directory, and thecgi-bin
directory are not group or other writable:
chmod 755 ~
chmod 755 ~/public_html
chmod 755 ~/public_html/cgi-bin
- Finally, you must make sure your scripts are executable, but not group or other writable: chmod 755 ~/public_html/cgi-bin/my-script.cgi
- If you have problems, try checking the end of the logs for additional information while pressing reload on your browser: tail -f /web/logs/error_log /web/logs/suexec_log
For PHP scripts, you must make sure the following are true:
- Your script must be stored in your home directory under the directory named
public_html
or a subdirectory of that directory. - You must make sure that your home directory, the
public_html
directory, and every directory above your PHP script is accessible but not group or other writable:
chmod 755 ~
chmod 755 ~/public_html
chmod 755 ~/public_html/otherdir
- Finally, you must make sure your scripts are readable, but not group or other writable: chmod 644 ~/public_html/index.php chmod 644 ~/public_html/otherdir/index.php
- If you have problems, try checking the end of the logs for additional information while pressing reload on your browser: tail -f /common/weblogs/polara/error.log /common/weblogs/polara/suphp.log
How do I setup ssh keys?
Windows
To set up ssh keys on windows hosts first make sure you have bosh putty and puttygen installedhere . Open puttygen, make sure RSA is selected at the bottom and click generate. Move your mouse around in the blank space when prompted and wait until the key finishes generating. Click Save private key and put this file away somewhere (Do not just drop it on your desktop). Then select everything in the text box labeled "Public key for pasting into OpenSSH authorized_key file" and copy it to a file somewhere near your private key. Next ssh into the machine you want keys for and paste the contents of your public key file into the folder ~/.ssh/authorized_keys, if this file dose not exist you can make it. Then, run the command chmod 700 ~/.ssh/
and chmod 600 ~/.ssh/authorized_keys
then log off of the machine. Next time you log on with putty on the left select ssh>auth and click the browse button at the bottom of the list. Find, and Select the private .ppk file you saved earlier and connect to the machine with the public key, If done correctly you should not be prompted for a password in order to login.
How do I access the campus VPN?
How do I login remotely to CIS resources?
See Remote Access