1
00:00:00,180 --> 00:00:01,350
As a system administrator,

2
00:00:01,350 --> 00:00:03,840
at times you'll be responsible for controlling

3
00:00:03,840 --> 00:00:05,910
and managing the repositories

4
00:00:05,910 --> 00:00:08,160
that we're going to use for our software packages.

5
00:00:08,160 --> 00:00:10,620
In previous lessons, we went over how to use yum

6
00:00:10,620 --> 00:00:12,420
to manage these packaged softwares.

7
00:00:12,420 --> 00:00:14,120
But in this example, we're going to actually configure

8
00:00:14,120 --> 00:00:17,640
the software that we have stored on our local machine

9
00:00:17,640 --> 00:00:20,253
and make it available to other servers.

10
00:00:21,150 --> 00:00:23,340
So first we're going to configure a local store

11
00:00:23,340 --> 00:00:25,830
so we're able to pull from us locally.

12
00:00:25,830 --> 00:00:27,990
And then we're also going to create a repository

13
00:00:27,990 --> 00:00:29,730
so other servers can pull from us

14
00:00:29,730 --> 00:00:32,220
within our local area network.

15
00:00:32,220 --> 00:00:34,219
So the first thing we want to do, we're just going to browse,

16
00:00:34,219 --> 00:00:37,470
going to list out the current packages that we have

17
00:00:37,470 --> 00:00:38,523
on the system.

18
00:00:42,990 --> 00:00:44,480
Okay, so we see we have the corn shell

19
00:00:44,480 --> 00:00:49,380
and we have the very secure file transfer protocol.

20
00:00:49,380 --> 00:00:50,250
So what we're going to do

21
00:00:50,250 --> 00:00:53,520
is we're going to make those available locally,

22
00:00:53,520 --> 00:00:55,140
and we're also going to make those available centrally

23
00:00:55,140 --> 00:00:56,700
to other servers.

24
00:00:56,700 --> 00:00:59,313
The first thing we need to do is to create repo.

25
00:01:00,450 --> 00:01:02,520
So that's going to be the create repo command.

26
00:01:02,520 --> 00:01:06,063
I'm going to use this folder as the location.

27
00:01:07,680 --> 00:01:09,120
Okay.

28
00:01:09,120 --> 00:01:10,413
That was quick and easy.

29
00:01:11,310 --> 00:01:13,590
So all this does is it designates that directory

30
00:01:13,590 --> 00:01:15,423
as a yum repository.

31
00:01:16,920 --> 00:01:19,260
So we're going to actually configure this repository.

32
00:01:19,260 --> 00:01:20,697
So we're going to do sudo.

33
00:01:20,697 --> 00:01:21,870
We're going to vim.

34
00:01:21,870 --> 00:01:23,910
We want to edit this text

35
00:01:23,910 --> 00:01:25,010
and we're going to do yum

36
00:01:27,600 --> 00:01:28,433
dot repost

37
00:01:29,730 --> 00:01:31,020
dot D.

38
00:01:31,020 --> 00:01:33,780
We're going to call this one local repo.

39
00:01:33,780 --> 00:01:36,630
Okay, so this dot repo is going to designate it

40
00:01:36,630 --> 00:01:37,803
as that type of file.

41
00:01:38,880 --> 00:01:42,240
And this first line is going to be for the identification

42
00:01:42,240 --> 00:01:44,133
of that actual repository.

43
00:01:46,860 --> 00:01:48,570
And that's going to have the human readable name

44
00:01:48,570 --> 00:01:51,720
for us to identify ourselves

45
00:01:51,720 --> 00:01:52,553
local

46
00:01:53,730 --> 00:01:54,563
that's great.

47
00:01:55,680 --> 00:01:56,640
Okay.

48
00:01:56,640 --> 00:01:57,720
Then we're going to do the base URL,

49
00:01:57,720 --> 00:01:59,643
how to actually locate this file.

50
00:02:04,980 --> 00:02:05,813
Packages,

51
00:02:07,950 --> 00:02:10,560
going to enable this so we have to actually let the system know

52
00:02:10,560 --> 00:02:13,683
that it's able to be used security feature.

53
00:02:16,050 --> 00:02:21,050
GPG check stands for the good new privacy guard.

54
00:02:21,270 --> 00:02:24,150
And what that does is it creates a fingerprint.

55
00:02:24,150 --> 00:02:28,080
If you're thinking like shaw one from the integrity side.

56
00:02:28,080 --> 00:02:30,540
So we'll know if we're actually getting the right repository

57
00:02:30,540 --> 00:02:31,500
instead of a wrong one

58
00:02:31,500 --> 00:02:35,130
or something that could be manipulated by threat actors.

59
00:02:35,130 --> 00:02:37,380
All right, so that's it for that.

60
00:02:37,380 --> 00:02:38,520
Going to right quit this.

61
00:02:38,520 --> 00:02:40,533
And let's go ahead and clean the cache.

62
00:02:44,580 --> 00:02:47,010
It's always good practice to clear the cache

63
00:02:47,010 --> 00:02:49,500
just to make sure everything is nice and neat

64
00:02:49,500 --> 00:02:52,710
whenever we're ready to initiate our repositories.

65
00:02:52,710 --> 00:02:55,053
And so we're going to do the yum repo list.

66
00:02:55,890 --> 00:02:58,890
Just need to verify that the one we just created,

67
00:02:58,890 --> 00:03:03,890
our local repo, is actually listed under the repo list.

68
00:03:04,440 --> 00:03:07,740
And if you can see, about four lines down,

69
00:03:07,740 --> 00:03:09,930
that our local repository was successfully created.

70
00:03:09,930 --> 00:03:11,880
Okay, so next thing we're going to go ahead

71
00:03:11,880 --> 00:03:13,189
and just try to install this, right?

72
00:03:13,189 --> 00:03:14,070
We're going to use a yes option.

73
00:03:14,070 --> 00:03:15,930
That gives us yes to all the prompts.

74
00:03:15,930 --> 00:03:17,920
We'll go ahead and enable the repo

75
00:03:18,810 --> 00:03:20,210
as part of the installation.

76
00:03:21,080 --> 00:03:23,523
I'm going to designate the local repo.

77
00:03:24,781 --> 00:03:26,313
I'm going to install KSH.

78
00:03:28,620 --> 00:03:32,070
Now again, typically we don't have to do the enable command

79
00:03:32,070 --> 00:03:33,210
because if you look at our folder,

80
00:03:33,210 --> 00:03:35,010
we had it enabled by default.

81
00:03:35,010 --> 00:03:37,560
But in some systems, for security purposes,

82
00:03:37,560 --> 00:03:40,890
we'll have these repos disabled so that'll be a way

83
00:03:40,890 --> 00:03:42,540
if we were in that particular environment

84
00:03:42,540 --> 00:03:45,900
to turn it on just for that installation.

85
00:03:45,900 --> 00:03:48,390
Okay, we see it went through successfully.

86
00:03:48,390 --> 00:03:50,340
So the next thing we're going to do is actually

87
00:03:50,340 --> 00:03:52,530
set this up for a central repository.

88
00:03:52,530 --> 00:03:55,020
But we we have to have an Apache server running

89
00:03:55,020 --> 00:03:57,990
to be able to handle the http request.

90
00:03:57,990 --> 00:04:00,040
So we're going to just going to do sudo then yum

91
00:04:00,040 --> 00:04:03,720
and we're going to yes to those options.

92
00:04:03,720 --> 00:04:06,813
And we're going to install the http daemon.

93
00:04:10,710 --> 00:04:11,543
All right.

94
00:04:13,813 --> 00:04:16,500
I'm going to go back to our system control

95
00:04:16,500 --> 00:04:18,632
just to turn this service on.

96
00:04:21,420 --> 00:04:22,253
Okay.

97
00:04:23,340 --> 00:04:25,500
Let's just make sure this is

98
00:04:25,500 --> 00:04:26,343
running for us.

99
00:04:33,180 --> 00:04:34,013
All right.

100
00:04:34,013 --> 00:04:34,846
We see it's running.

101
00:04:36,420 --> 00:04:37,620
So what we need to do next

102
00:04:37,620 --> 00:04:41,880
is to designate the Apache service as a repository.

103
00:04:41,880 --> 00:04:43,050
First thing we need do is link this.

104
00:04:43,050 --> 00:04:46,260
We'll do a soft link or symbolic link,

105
00:04:46,260 --> 00:04:47,283
the packages.

106
00:04:50,460 --> 00:04:52,010
And the location of this is WWW

107
00:04:53,040 --> 00:04:53,873
HTML

108
00:04:54,900 --> 00:04:55,733
packages.

109
00:04:56,850 --> 00:04:59,430
Okay, so now we have a soft link to the packages file.

110
00:04:59,430 --> 00:05:03,600
So whenever someone tries to access the ACML packages

111
00:05:03,600 --> 00:05:06,960
which our ACTP server will be responding to

112
00:05:06,960 --> 00:05:08,850
they'll be able to access the information that's linked

113
00:05:08,850 --> 00:05:11,940
to the packages file that we established earlier

114
00:05:11,940 --> 00:05:13,410
that continues the corn shell

115
00:05:13,410 --> 00:05:16,200
and the very secure file transfer protocol daemon.

116
00:05:16,200 --> 00:05:17,950
Let's go and create the repository.

117
00:05:30,570 --> 00:05:31,403
All right.

118
00:05:32,520 --> 00:05:33,543
And then again,

119
00:05:34,470 --> 00:05:35,580
we're going to have to go through

120
00:05:35,580 --> 00:05:38,043
and create that configuration file.

121
00:05:39,062 --> 00:05:41,280
I'll do sudo vim

122
00:05:41,280 --> 00:05:42,990
and put in etc

123
00:05:42,990 --> 00:05:44,223
yum repos,

124
00:05:46,800 --> 00:05:47,920
call it internal

125
00:05:50,130 --> 00:05:50,963
repo.

126
00:05:52,470 --> 00:05:54,507
Okay (indistinct).

127
00:05:56,850 --> 00:06:00,310
The name of it's going to be the ID internal repo

128
00:06:04,980 --> 00:06:05,930
human readable name

129
00:06:08,550 --> 00:06:09,520
internal

130
00:06:10,830 --> 00:06:11,663
repository

131
00:06:13,740 --> 00:06:14,573
base URL.

132
00:06:14,573 --> 00:06:16,470
Now it's going to be different from before

133
00:06:16,470 --> 00:06:18,520
'cause we're going to use the http protocol,

134
00:06:21,251 --> 00:06:22,210
the local host

135
00:06:23,940 --> 00:06:24,773
packages

136
00:06:33,450 --> 00:06:36,003
do our good new privacy guard check.

137
00:06:37,470 --> 00:06:38,303
That's equal to

138
00:06:39,502 --> 00:06:40,950
(indistinct).

139
00:06:40,950 --> 00:06:41,850
Escape

140
00:06:41,850 --> 00:06:42,741
quit

141
00:06:42,741 --> 00:06:45,420
(indistinct).

142
00:06:45,420 --> 00:06:46,860
Yum

143
00:06:46,860 --> 00:06:47,793
clean all.

144
00:06:53,940 --> 00:06:56,790
Now it's time to see if we actually got that thing going.

145
00:07:03,330 --> 00:07:06,270
All right, looks like that was successfully created

146
00:07:06,270 --> 00:07:07,830
internal repo

147
00:07:07,830 --> 00:07:10,590
internal repository four down.

148
00:07:10,590 --> 00:07:12,690
Now there'll be one more configuration that we have set.

149
00:07:12,690 --> 00:07:13,590
It's going to be sudo

150
00:07:14,520 --> 00:07:17,223
set enforce to zero.

151
00:07:18,120 --> 00:07:21,690
And what that does is it disables the se Linux.

152
00:07:21,690 --> 00:07:23,859
It's an access control mechanism

153
00:07:23,859 --> 00:07:27,240
that would otherwise prevent access the web hosted packages.

154
00:07:27,240 --> 00:07:29,640
So it's just something that we have to care of.

155
00:07:29,640 --> 00:07:31,320
Now, let's see if we're able to access it from the web.

156
00:07:31,320 --> 00:07:32,620
So we're going to do Firefox.

157
00:07:33,810 --> 00:07:35,050
I'm going to do HTTP

158
00:07:37,350 --> 00:07:38,948
local host

159
00:07:38,948 --> 00:07:40,440
(indistinct)

160
00:07:40,440 --> 00:07:41,273
and we're going to go packages.

161
00:07:41,273 --> 00:07:43,440
And we should see this open our web browser

162
00:07:43,440 --> 00:07:44,540
and have a list of the

163
00:07:47,340 --> 00:07:48,813
packages on display.

164
00:07:49,860 --> 00:07:51,240
All right.

165
00:07:51,240 --> 00:07:52,950
We see our corn shell there

166
00:07:52,950 --> 00:07:55,800
and our very secure file transfer protocol.

167
00:07:55,800 --> 00:07:59,193
So now this is accessible via the ATTP protocol.

168
00:08:00,570 --> 00:08:02,013
All right, we'll close that.

169
00:08:02,880 --> 00:08:05,880
And for security purposes, we're going to put this back to one.

170
00:08:08,580 --> 00:08:09,720
Okay, that's that.

171
00:08:09,720 --> 00:08:12,000
We went through how to configure repositories

172
00:08:12,000 --> 00:08:15,450
both locally and centralized for other service to access.

173
00:08:15,450 --> 00:08:17,250
So thank you for sticking me through this walkthrough,

174
00:08:17,250 --> 00:08:19,050
and I'll see you in the next lesson.

