Archive for March, 2008

Adventures with pam_mount , Active Directory, CentOS , (Fedora 7)

Monday, March 24th, 2008

Procedure is based on CentOS 4.6, and if noted , Fedora 7. 

First - download pam_mount from sourceforge. - use source whenever possible!!!  must match kernel!  My attempts to use pre-made rpms resulted in much frustration - you have been warned.  

However, I’ve found the Fedora 7 pam_mount rpms, and it seems to work well.    Wrong, stupid rpms don’t automount properly.   Use version 0.18 sources!   Later versions use xml for the configuration files, which I don’t have time to figure out at the moment.   I tried to get the new version to work with Fedora 7 with little success.   Try at your own risk.

- Get kernel headers update

- Kernel-headers-2.6.18-8.1.3.el5.i386.rpm

Make install

- important note, Pmvarrun is in the wrong location.   Should be in /usr/sbin/ not /usr/local/sbin/

- mv /usr/local/bin/pmvarrun /usr/sbin/

- the fedora 7 rpm does not have this pmvarrun location problem.    

 -otherwise passwords do not get passed to other modules properly , i.e. does not auto mount properly

-activate winbind authentication 

- join domain YOUR_DOMAIN (in capitals) winbind Security model – “ADS” Winbind ADS Realm - ad.yoursiteroot.com

Template shell - /bin/bash

Make sure it’s set to the correct time!
use command: 

net ads join –Uadministrator

to join to domain

Also use:

net ads status

net ads info

to check if it joined properly.

- Must start smb service in order for communication with ADS to work properly

 

 

configure /etc/pam.d/login   and  gdm, or kdelogin  appropriately

-use_first_passconfigure pam_mount.conf         

- particularly “use first domain” modify mount point lsof is referenced incorrectly

– should be /usr/sbin/lsof, not /usr/bin/lsofconfigure smb.conf

-must sometimes reboot in  order to see if changes worked

- restarting winbind/smb service does not work all the time

-  make backups of all .conf and pam.d files- backup /etc

 

In PAM_MOUNT.CONF

- disable debug mode in /etc/security/pam_mount.conf

Comment out options_allow nosuid,nodev ………. In volumes section:

Volume * cifs your_cifs.server.address computing /home/&/labdata8 uid=& - -

Or group specific:

Volume @adsgroup1 cifs servername adsgroupsharename /home/&/labdata8 uid=& - -

 

 

Change cifsmount /bin/mount to /sbin/mount.cifs

/etc/pam.d/gdm

#%PAM-1.0

auth required pam_stack.so service=system-auth

auth required pam_nologin.so

auth sufficient pam_timestamp.so

auth optional pam_mount.so use_first_pass

account required pam_stack.so service=system-auth

password required pam_stack.so service=system-auth

session required pam_stack.so service=system-auth

session required pam_loginuid.so

session optional pam_timestamp.so

# session optional pam_selinux.so

session optional pam_console.so

session optional pam_mount.so 

———————————————————————————————-

 

/etc/pam.d/login

#%PAM-1.0auth required pam_securetty.soauth required pam_stack.so service=system-auth

auth required pam_nologin.so

# note pam_mount must be in /lib64/security

auth optional pam_mount.so use_first_pass

account required pam_stack.so service=system-auth

password required pam_stack.so service=system-auth

# pam_selinux.so close should be the first session rule

# session required pam_selinux.so close

session required pam_stack.so service=system-auth

session required pam_loginuid.so

session optional pam_console.so

# pam_selinux.so open should be the last session rule

#session required pam_selinux.so open session optional pam_mount.so

#============================ Share Definitions ==============================/etc/samba/smb.conf

idmap uid = 16777216-33554431

idmap gid = 16777216-33554431

template shell = /bin/bash

template homedir = /home/%U

winbind use default domain = yes

# 250.31=activedirectoryserveraddress

password server = 192.168.250.31

realm = youractivedirectoryrealm

Edit /etc//pam.d/system-auth last!!

In /etc/samba/smb.conf

Must add this in “Share Definitions” section

template homedir = /home/%U

 

 

SMB.CONF   (internal note - make changes or copy from another preconfigured computer)

 

Toshiba Portege 3500 review

Sunday, March 23rd, 2008

Bought this on eBay for around $400, probably came from a corporate end-of-lease.   So far, used it for a month and another 3 months in Asia with no significant problems.

Came with 128mb of ram, which is really totally useless.   I was able to find a 256 pc133 sodimm module lying around, so it now has 384mb of ram.   I see one memory module that is accessible from the bottom of the computer, but the other one has eluded me.   Searching the internet yields nothing so far, but the toshiba specs indicate that it can support a maximum of 1 gb of ram.  

When I first got the laptop, there was a problem with the pen touchscreen.   There were bands of dead zones where the pen seems to get no signals.   No amount of calibrating the screen helped to solve the problem.   Apparently, there are two possible sources of the problem…   1)  the bios setting to “stretch” the display ,  and 2)  the video driver.    I think the only true solution was to upgrade the video driver using the one provided from Toshiba’s website.

[update on the touchscreen March 23, 2008]  - the deadzone problem seems to have reappeared, and no amount of driver or bios futzing has fixed the problem.   Searching the internet reveals that the only solution is to gently press and twist the screen - seems to work!   I guess that’s why these were available on ebay!

Works with knoppix 5.1 using the network boot.    I tried to write linux boot images onto compact flash cards, and booted them via the built-in compact flash port, but no luck.   Neither did booting using the same compact flash cards inserted into a PCMCIA adapter.

 One thing about the SD card slot.   It doesn’t recognize cards 2 GB and over.

The “quick access” buttons on the screen seem are reprogrammable, except for one, which has a “key” symbol on it.   Pressing it will activate the task manager, which is pointless.   They went through the whole trouble of designing this button, and all it does is task manager?  wtf?

The handwriting recognition was surprisingly accurate.    What surprised me even more was that it seemed to do better with cursive writing than with printing.    However, it does have problems with differentiating between 1 and lower case L.

Built-in wifi is quite good.   If there’s a base station in the area with a strange SSID name - something with a foreign character set, it tends to confuse the wifi card.  Connecting another wifi card to it solves the problem.

Overall - a great lightweight laptop.   Great for travel.

Baldwin St. Restaurants - Toronto review

Sunday, March 23rd, 2008

Baldwin St. is a small street tucked away just north of the Art Gallery of Ontario.  It primarily consists of a variety of vastly differing restaurants that could satisfy any urge of the munchies that may arise.   The clientele vary from students staggering in from the University of Toronto to professionals from the nearby hospitals and government buildings.  Situated right next to the Silverstein bread factory, you might also be able to smell the delicious yeasty bread wafting down the street.

Kowloon Seafood Dim Sum Restaurant
Cantonese cuisine. 
Lunch dim sum is done by checking off a dim sum list card.
Opinion:  I’m not a big fan of their lunch special menu, as I find their selection rather small and not particularly my taste.  Their dim sum menu however is top notch and 100% authentic.   Lunch time is busy, but wait time is very short.
Delivery 6-11 PM
5 Baldwin St.
Tel: 416-977-3773
Fax: 416-977-4751

Baldwin Naturals Health Food Store
-sells organic fruits, vegetables, herbs, supplements, aromatherapy and skincare products
16 Baldwin St. 
Tel:  416-979-1777

 Vegetarian Haven
www.vegetarianhaven.com
Opinion:  I’m not a vegetarian and I think I’ve only been there once a long time ago.  No memorable experiences from there.
17 Balwin st.   416-621-3636

The Gateways of India
Has a lunch time buffet. 
Opinion:  The lunch group I go with never wants to go for east indian food, so I don’t have a recent experience that would be helpful.   I remember it being acceptable.
19 Baldwin st
Tel: 416-340-0404

Kuni Sushi Ya
Sells “Japanese style” food.
Low priced.  Large outdoor patio.  Clean.  I am not a fan of their food.
20 Balwin
416-260-3188 

Sambuca Grill
Central Italian food.  Secluded patio.   Been there once.
21 Baldwin st.
Tel:  416-595-6277

Yung Sing Pastry Shop
Established in 1968.   Serves super fresh homemade chinese buns, pastry, and dim sum.   Siu Mai and Haw Gau dim sim is only sold on the weekends.   I think the owners are retired now, and their kids are running it now - quality is as good as ever.  Also, everything is very low priced, 3 buns for around $3.50-$4.00  which is enough for an average person.
Has a large community bill board.  No seating - take out only, however there’s a bench outside the place.

In my opinion, this place has the best chinese buns in Toronto, and believe me, I’ve been to a lot of bun places in Toronto.   I particularly like their curry buns, roasted pork buns, beef buns, and the ham&egg buns.  Don’t like the vegetarian buns though.
Their buns also may make you very sleepy afterwards, so I’d  recommend a coffee afterwards.   The lunch time line gets very long from 12:15 to 1:00 .
22 Balwin St.
Tel: 416-979-2832

Balwin Laundromat
Drycleaning, wash, and fold.   Good luck trying to get a menu or flagging down a waiter here, because amazingly enough, it’s not a restaurant at all, but a great place to wash one’s clothes.   Bad place to bring a date to, but laudromats are supposedly good places to pick up people.  Good luck!
23 Baldwin St.   
Tel:  416-597-9429

Cafe La Gaffe
So, after you’ve picked up a hot date from the laundromat across the street, walk on over to the Cafe la Gaffe.   It’s a medium sized place in addition to a small front patio, and a small sheltered back patio.
Mediterranean cuisine.  Large wine list.
24 Baldwin st
Tel:  416-596-2397

John’s Italian Cafe
It’s been on this street since 1981.  And as I vaguely recall from my childhood in the 1970’s, the two store units were once a tofu making place and a chicken butcher shop, then into some sort of jewish cheese place….   Of course, Balwin st. itself was not as dynamic as it is now.   It reminds me of the cafes one would typically see in Europe -  I half expect to see Don Corleone (the fat one, not Michael) sitting at his favourite table in a back corner.   Nice large patio - one of my favourite places to unwind on a warm summer evening. 
They often serve an order of Coke drink in those small coke bottles,  gives it a nice pseudo Euro feel (assuming they even do that in Europe), also a bit of a ripoff for the amount you get for what you pay.  They also sell some wierd brand of italian chinotto that I’ve never seen anywhere else - which is ok, nothing special.
Food-wise,  their caesar salad is one of the most intense garlicky versions I’ve ever had - I love it - but don’t recommend it if you have an important meeting.  
Their panini’s are excellent, with my favourite being the sausage panini.  However, the roof of my mouth ends up being cut up afterwards - that’s the risk you’ll have to take for this sandwich.
Nothing special with the bruschetta, still worth it to nibble on in the beginning.
Maybe it’s expected in the restaurant business, but it just seems like there’s a high turnover rate for the waiting staff, so the service is kind of spotty - acceptable if you’re not in a hurry.
On a nice warm day, the lunch time crowd is extremely busy.  Get there before 12pm or after 1 pm.   Should be no problem getting a seat for dinner time.
I don’t think they accept lunch reservations, but doesn’t hurt to double check.  Catering and delivery available.
27 Baldwin
Tel:  416-596-8848

Bodega
Since 1979, this French-Mediterranean restaurant is a cornerstone of this area.  This is generally a suit and tie place, which may be exactly what you’re looking for if you’re meeting a client or wooing a lady friend.   I don’t go there very often as I’m not a big fan of French-Mediterranean and prices seem kind of high, but I guess that’s important if you want to impress a client or lady friend.
Has a nice patio.  Reservations recommended and catering available.
30 Baldwin St.
416-977-8538

Kon-Nichi-Wa
Mostly specializing in japanese style noodle and rice dishes.  I used to go there often, I don’t know why, as the noodles and soup base is not particularly to my liking.  If you want a real good japanese noodle taste, go to Kenzo noodle on Yonge St., north of Finch Ave.
31 Baldwin St.
Tel:  416-593-8538

Jodhpore Club
Traditional cuisine from various areas of India.  I think I’ve been there once, nothing memorable.

Panasonic RR-US500 Digital Voice Recorder review

Sunday, March 23rd, 2008

Not a bad device.  Works as advertised.   Can record 10 hours of audio.    Sound quality is decent, and playback is also good, even from its small speaker.   

The only complaint I have is of the software that’s used to download the audio files onto your computer.   First thing, the file format is in Panasonic’s own proprietary format, and you’ll need to convert them to mp3 as a second step.   Second thing, the user interface is very annoying to use,  the creators of the software trying to make the software look “cool” - with a god awful colour scheme,  rather focus on making something stable and logical.   This is typical of products developed in Asia, the software doesn’t go through significant stability and user input tests and is just pushed down the throats of customers.  

Months after not using the software, I needed to start it up again to listen to some notes.   It wouldn’t start!   Just some useless error about it “not being installed correctly”.  So fine, I uninstall it, and reinstall it.   It works again.   Then try it again the next day, and same thing!   The software stopped working.   What the hell?

Final verdict - the hardware is good.  The software sucks - Panasonic really needs to have a more thorough review of their software before releasing it with their hardware.

ZIO X9 Networking Card 802.11g 54Mbps Wireless LAN PCI Adapter review

Sunday, March 23rd, 2008

Crap - stopped working after 1 month.   Supports WPA encryption though…