tag:blogger.com,1999:blog-75982421178230001752024-02-20T23:03:52.737+03:00Всякие заметочкиdynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.comBlogger278125tag:blogger.com,1999:blog-7598242117823000175.post-79119439998816048322023-03-28T09:20:00.004+03:002023-03-28T09:21:13.990+03:00Анализ производительности<pre>
uptime
dmesg -T | tail
vmstat -SM 1
mpstat -P ALL 1
pidstat 1
iostat -sxz 1
free -m
sar -n DEV 1
sar -n TCP,ETCP
top
</pre>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-41966708052093485682022-12-16T12:57:00.003+03:002022-12-16T12:58:26.968+03:00SNMP error: (noSuchName) There is no such variable name in this MIB.Иногда, в Zabbix можно увидеть ошибку "SNMP error: (noSuchName) There is no such variable name in this MIB.", обычно на discovery правилах. Проблема связана с тем, что по-умолчанию Zabbix использует bulk-зарпосы, которые не всегда работают для некоторых устройств. Чтобы избежать этой ошибки, достаточно в настройках интерфейса SNMP в Zabbix у хоста снять галочку с ``Use bulk requests'.
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-43126317877645453852022-09-20T10:58:00.002+03:002022-09-20T11:00:05.226+03:00Russian SSL<a href="https://www.gosuslugi.ru/crt">Поддержка работы сайтов с российскими сертификатами</a><br/>
<a href="https://t.me/joinchat/-y4FR5AKn7hiMzFi">Telegram: Об ЭП и УЦ</a><br/>
<a href="https://tlscc.ru">Центр сертификации ТЦИ</a><br/>
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-28644793470445759652021-09-15T11:50:00.002+03:002021-09-15T11:50:39.068+03:00Verifying that a Private Key Matches a CertificateСверка модуля ключа сертификата с модулем приватного ключа:
<pre>
# openssl x509 -noout -modulus -in fullchain.pem | openssl md5
# openssl rsa -noout -modulus -in privkey.pem | openssl md5
</pre>
Они должны совпадать.
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-26810418222776089972021-09-02T10:39:00.001+03:002021-09-02T10:39:14.466+03:00Регистрация корпоративных карт<a href="https://www.gosuslugi.ru/situation/registration_of_corporate_SIM_cards">ГОСУСЛУГИ: Регистрация корпоративных сим-карт</a><br>
<a href="https://www.consultant.ru/document/cons_doc_LAW_372706/3d0cac60971a511280cbba229d9b6329c07731f7/">Федеральный закон "О внесении изменений в Федеральный закон "О связи" от 30.12.2020 N 533-ФЗ</a>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-69557885793530299882021-09-02T10:18:00.004+03:002021-09-02T10:19:30.406+03:00Western Digital PC SN730 NVMe SSD<p><a href="https://www.westerndigital.com/products/commercial-internal-drives/pc-sn730-ssd">Western Digital PC SN730 NVMe SSD</a></p>
Read speeds up to 3,400 MB/s (1TB and 512GB models) saturate the PCIe GEN3 x4 interface supporting NVMe™ architecture<br>
256GB - 1TB1 capacities available in M.2 2280 form factor<br>
Endurance of up to 400 TBW (1TB model)<br>
5-year limited warranty<br>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-82275249288509069632021-06-08T12:06:00.004+03:002021-06-08T12:06:45.761+03:00smscconn_usable()<script src="https://gist.github.com/dynax60/bd11e788f552fa7de6a11c73afef1ca1.js"></script>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-72276790507542789452021-05-25T12:59:00.004+03:002021-05-25T12:59:38.340+03:00Суверенный РуНет<a href="https://nag.ru/articles/article/108343/suverennyiy-runet.html" target="_blank">Суверенный РуНет (автор: Дмитрий Галушко)</a><br>
<a href="https://nag.ru/articles/article/108343/suverennyiy-runet.html" target="_blank">Суверенный Рунет, часть 2 (автор: Дмитрий Галушко)</a><br>
<a href="https://nag.ru/articles/article/108343/suverennyiy-runet.html" target="_blank">Суверенный РуНет, часть 3 (автор: Дмитрий Галушко)</a><br>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-57040661508540406652021-04-23T13:45:00.005+03:002021-04-23T13:45:35.099+03:00Change CA private password<pre>
openssl rsa -aes256 -in ca.key -out ca.key.new
mv ca.key.new ca.key && chmod 400 ca.key
<pre>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-22736787573685885492021-04-06T09:35:00.005+03:002021-04-06T09:35:59.183+03:00Alternative to OTRS<a href=https://otobo.de/">OTOBO</a> — A fork based on ((OTRS)) Community Edition.<br>
<a href="https://community.znuny.org/viewtopic.php?p=170802#p170802">Official Statement on OTOBO – Rother OSS GmbH (by </span>Stefan Rother)</a>
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-75737502528525049572021-02-15T09:11:00.007+03:002021-02-15T09:11:47.845+03:00Qualys SSL Labs<p>Interesting service to test your site's SSL certificate and configuration on Qualys SSL Labs. Check it out:</p><p><a href="https://www.ssllabs.com/ssltest/">https://www.ssllabs.com/ssltest/</a></p>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-62047489807551385792021-02-15T09:03:00.004+03:002021-02-15T09:03:23.168+03:00ansible 2.10.5: ansible-vault requires either the cryptography library (preferred) or pycrypto in order to function<p>
</p><pre>Good day! :)
After the last installation of Ansible on Ubuntu 20.04, an error occurs when launching ansible-vault:<br /></pre><pre>-> % lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 20.04.1 LTS
Release: 20.04
Codename: focal
-> % ansible --version
ansible 2.10.5
config file = /home/null/ansible-autoconnex/ansible.cfg
configured module search path = ['/home/null/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
ansible python module location = /home/null/.local/lib/python3.9/site-packages/ansible
executable location = /home/null/.local/bin/ansible
python version = 3.9.0+ (default, Oct 20 2020, 08:43:38) [GCC 9.3.0]
-> % ansible-vault edit users.yml
ERROR! ansible-vault requires either the cryptography library (preferred) or pycrypto in order to function. for /home/null/ansible-autoconnex/users.yml </pre><pre>The problem is the lack of cffi library. Most likely the developers forgot to specify the dependency somewhere. Just install cffi.</pre><pre>-> % pip install cffi
<br /></pre>
<p></p>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-81638550439231449462020-10-21T23:02:00.001+03:002020-10-21T23:03:00.964+03:00– "There is no such thing as public money; there is only taxpayers’ money". (Margaret Hilda Thatcher).dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-78221616804324864682020-10-09T23:33:00.003+03:002020-10-09T23:33:22.864+03:00Classless IN-ADDR.ARPA delegation and dynamic reverse DNS UPDATE<p> Link: <a href="https://tools.ietf.org/id/draft-ietf-dnsop-rfc2317bis-00.html">Classless IN-ADDR.ARPA delegation and dynamic reverse DNS UPDATE</a></p><div id="gtx-trans" style="left: 39px; position: absolute; top: -20px;"><div class="gtx-trans-icon"></div></div>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-30367250573085443482020-10-08T21:12:00.006+03:002020-10-08T21:13:34.334+03:00Disaster<p></p><div class="separator" style="clear: both; text-align: center;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeqwvuQ0bFjvFLcntyFlQJMUHKUHMF4bKYMmjhUWAn-Y1H332omgzl1OFpqYgTT_hYSo8gW6A9_BcsFlbk8aBWLhFw9RrIdCg2gybrVsXKxZA1xTWa-yCxENYDLSdAGobyxQEwMNhxtyI/s500/disaster-girl.jpg" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" data-original-height="375" data-original-width="500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeqwvuQ0bFjvFLcntyFlQJMUHKUHMF4bKYMmjhUWAn-Y1H332omgzl1OFpqYgTT_hYSo8gW6A9_BcsFlbk8aBWLhFw9RrIdCg2gybrVsXKxZA1xTWa-yCxENYDLSdAGobyxQEwMNhxtyI/s16000/disaster-girl.jpg" /></a></div><br /> <p></p>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-5476594080079383732020-09-04T12:29:00.001+03:002020-09-04T13:37:30.223+03:00Linux ate my RAM<p>Links: <br /><a href="https://www.linuxatemyram.com/">https://www.linuxatemyram.com/</a><br /><a href="https://access.redhat.com/solutions/406773">Interpreting /proc/meminfo and free output for Red Hat Enterprise Linux 5, 6 and 7</a><br /><a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/5/html-single/tuning_and_optimizing_red_hat_enterprise_linux_for_oracle_9i_and_10g_databases/index#chap-Oracle_9i_and_10g_Tuning_Guide-Memory_Usage_and_Page_Cache">Red Hat Enterprise Linux Oracle Tuning Guide</a><br /><a href="https://www.howtogeek.com/659529/how-to-check-memory-usage-from-the-linux-terminal/">How to Check Memory Usage From the Linux Terminal</a><br /><a href="https://www.howtogeek.com/449691/what-is-swapiness-on-linux-and-how-to-change-it/">What Is Swappiness on Linux? (and How to Change It)</a><br /><a href="https://www.kernel.org/doc/Documentation/filesystems/proc.txt">https://www.kernel.org/doc/Documentation/filesystems/proc.txt</a><br /><a href="https://www.kernel.org/doc/Documentation/sysctl/vm.txt">https://www.kernel.org/doc/Documentation/sysctl/vm.txt</a></p>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-66899766094523893972020-08-12T08:50:00.001+03:002020-08-12T08:50:18.051+03:00LENS QUALITY: MTF, RESOLUTION & CONTRAST<p>Link: <a href="https://www.cambridgeincolour.com/tutorials/lens-quality-mtf-resolution.htm">https://www.cambridgeincolour.com/tutorials/lens-quality-mtf-resolution.htm</a></p>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-37425595908763043212020-06-15T15:41:00.002+03:002020-06-15T15:41:45.909+03:00Смотрим качество связи активных каналов каналов:<br />
<br />
watch -n 5 --differences "rasterisk -x 'sip show channelstats'"dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-45183194419217295572020-05-22T22:01:00.002+03:002020-05-22T22:01:50.753+03:00Ограничения использования MAC-адресов в VMware ESXiЗапрещено устанавливать MAC-адреса в виртуальных машинах VMware ESXi в диапазоне <b>00:50:56:40:YY:ZZ – 00:50:56:7F:YY:ZZ</b>. Для этих целей разрешено использовать 00:50:56:00:00:00 – 00:50:56:3F:FF:FF. Примечание: запрещающие правила не работают, когда интерфейс находится в promiscuous mode.<br />
<br />
Links:<br />
<a href="https://marc.info/?l=openbsd-misc&m=159014954017217&w=2">Re: Strange behavior when I try to use lladdr</a><br />
<a href="https://docs.vmware.com/en/VMware-vSphere/6.0/com.vmware.vsphere.troubleshooting.doc/GUID-7F723748-E7B8-48B9-A773-3822C514684B.html">Attempt to Power On a Virtual Machine Fails Due to a MAC Address Conflict</a><br />
<br />dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-50137321322662838192019-12-13T12:18:00.001+03:002019-12-13T12:18:22.310+03:00SPF redirectПример ошибочного правила (как делать не надо!):<br />
<br />
"v=spf1 mx ip4:194.87.190.47 redirect=_spf.mail.ru <b>-all</b>"<br />
<br />
<a href="https://stackoverflow.com/questions/50637826/spf-record-with-redirect-and-include">https://stackoverflow.com/questions/50637826/spf-record-with-redirect-and-include</a><br />
<a href="https://help.mail.ru/biz/domain/verification_settings/other/spf">https://help.mail.ru/biz/domain/verification_settings/other/spf</a><br />
<br />
P.S. чего только не встретишь в maillog, когда начинаешь разбираться почему не ходят письма :)dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-1232560112772019992019-12-08T19:06:00.000+03:002019-12-08T19:07:56.905+03:00python3: CERTIFICATE_VERIFY_FAILED<span style="font-family: Courier New, Courier, monospace;">urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:847)
</span><br />
<br />
Solution:<br />
<br />
<span style="font-family: "courier new" , "courier" , monospace;">pip3 install certifi</span><br />
<span style="font-family: "courier new" , "courier" , monospace;">/Applications/Python\ 3.6/Install\ Certificates.command</span><br />
<span style="font-family: "courier new" , "courier" , monospace;"><br /></span>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-6057790557625897042019-12-04T10:05:00.003+03:002019-12-04T10:11:40.980+03:00The latest Oracle's Java you can use with no cost is 8u202Links:<br />
<br />
<a href="https://www.oracle.com/technetwork/java/javase/overview/oracle-jdk-faqs.html">Oracle Java SE Licensing FAQ</a><br />
<a href="https://blogs.oracle.com/java-platform-group/oracle-jdk-releases-for-java-11-and-later">Oracle JDK Releases for Java 11 and Later</a><br />
<a href="https://docs.google.com/document/d/1nFGazvrCvHMZJgFstlbzoHjpAVwv5DEdnaBr_5pKuHo/edit">Java Is Still Free</a><br />
<br />
P.S. Also you have to choose another distribution such as:<br />
<br />
<a href="https://openjdk.java.net/">https://openjdk.java.net/</a><br />
<a href="https://adoptopenjdk.net/">https://adoptopenjdk.net/</a><br />
<i>and more... (see Java Is Still Free link above).</i>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-85945983162917963292019-12-04T09:59:00.004+03:002019-12-11T10:09:02.876+03:00Must have on WSLCreate the /etc/wsl.conf file on any WSL distribution with the following contents:<br />
<div>
<br /></div>
<div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;"># Enable extra metadata options by default</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">[automount]</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">enabled = true</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">root = /mnt/</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">options = "metadata,umask=22,fmask=111"</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">mountFsTab = false</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;"><br /></span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;"># Enable DNS – even though these are turned on by default, we’ll specify here just to be explicit.</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">[network]</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">generateHosts = true</span></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">generateResolvConf = true</span></div>
</div>
<div>
<br /></div>
<div>
And restart WSL in Windows Powershell under admin's right:</div>
<div>
<br /></div>
<div>
<span style="font-family: "courier new" , "courier" , monospace;">Get-Service LxssManager | Restart-Service</span></div>
<div>
<br /></div>
<div>
Don't give thanks. :)</div>
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-78587385291905188062019-09-24T11:33:00.003+03:002019-09-24T12:12:34.157+03:00How to enable ESNI and DOH in FirefoxCheckout <a href="https://www.mozilla.org/en-US/firefox/nightly/all/" target="_blank">Firefox Nightly</a>.<br />
<br />
Now go to about:config and do changes:<br />
<br />
<span style="font-family: "courier new" , "courier" , monospace;">network.security.esni.enabled=true</span><br />
<span style="font-family: "courier new" , "courier" , monospace;">network.trr.uri=https://mozilla.cloudflare-dns.com/dns-query</span><br />
<span style="font-family: "courier new" , "courier" , monospace;">network.trr.mode=2</span><br />
<h4>
DOH Servers</h4>
<ul>
<li>Mozilla: https://mozilla.cloudflare-dns.com/dns-query</li>
<li>Google DNS: https://dns.google.com/experimental</li>
<li>Quad9: https://dns.quad9.net/dns-query</li>
</ul>
<h3>
Trusted Recursive Resolver mode values</h3>
<div>
<div>
0: Off by default</div>
<div>
1: Firefox will choose based on which is faster</div>
<div>
2: TRR preferred, fall back to DNS on failure</div>
<div>
3: TRR only, no DNS fallback</div>
<div>
5: TRR completely disabled<br />
<br />
Checkout <a href="https://www.cloudflare.com/ssl/encrypted-sni">https://www.cloudflare.com/ssl/encrypted-sni</a> and <a href="http://www.whatsmydnsserver.com/" target="_blank">check DNS</a> you're using<br />
<br />
To check if domain support ESNI do<br />
<br />
<span style="font-family: Courier New, Courier, monospace;">dig @8.8.8.8 IN TXT _esni.<i>domain.tld</i></span><br />
<span style="font-family: Courier New, Courier, monospace;"><i><br /></i></span>
<span style="font-family: inherit;">IETF changes <a href="https://github.com/tlswg/draft-ietf-tls-esni/pull/144" target="_blank">RRType for that feature</a> - <b>IN ESNI</b> instead of <b>IN TXT</b>. K</span>eep this in mind in the future.</div>
</div>
dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0tag:blogger.com,1999:blog-7598242117823000175.post-37041957509244571012019-09-16T12:55:00.001+03:002020-02-27T11:21:07.029+03:00Netmiko с поддержкой D-LinkUPDATE 21/02/20: новый pull request <a href="https://github.com/ktbyers/netmiko/pull/1381">1381</a> и <a href="https://github.com/ktbyers/netmiko/pull/1588">1588</a>dynax60http://www.blogger.com/profile/14981130885429582150noreply@blogger.com0