Labels

Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Saturday, June 16, 2012

Configuring Apache for JBoss

Supported Platforms

Apache for JBoss Prerequisites

1. JBoss 6 server configured for App & running on port 8080

2. Latest version of Apache 2.2 including OpenSSL should be downloaded from following link http://httpd.apache.org/download.cgi
Note: Download appropriate version suitable for your operating system.

3. Download mod_jk2.so file from apache sites mentioned below & place it in D:\Apache2.2\modules

a. http://www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/

b. http://tomcat.apache.org/connectors-doc/

4. (Optional) Valid SSL certificate files available for your server in case you want to enable HTTPS.
e.g. App.cert & App.key file (file name differs as per your configuration)

Note: Please refer online installation guide for installing Apache2.2 on Linux / Unix. http://httpd.apache.org/docs/2.2/install.html


Installing Apache using MSI Installer in windows.

1. Execute httpd-2.2.20-win32-x86-openssl-0.9.8r.msi.

2. Click Next, Select “I Accept…” and click Next.
clip_image002[4] clip_image004[4]

3. Click Next, Enter Domain Name, Server Name & Support Email Address, Select “for All Users,..” option and then click Next.
clip_image006[4] clip_image008[4]

4. Select Custom & click Next, Open Dropdown next to “Apache HTTP Server 2.2.10” & Select “This Feature, and all subfeatures, will be installed on local Hard drive”, Click Change.
clip_image010[4] clip_image012[4]

5. Change the Path of Apache install directory to non system drive, Click OK, Click Next.
clip_image014[4] clip_image016[4]

6. Click Install,
clip_image018[4] clip_image020[4]

7. Click yes/allow for any security or firewall alerts that may popup.
clip_image022[4] clip_image024[4]

8. Click Finish on the “Installation Wizard Completed” Window.


Configuring apache for JBoss on http with Compression.

By Default Apache starts listening on port 80

1. Open file httpd.conf in editor & add following content after line “<IfModule !mpm_winnt_module>”

   1: ######## APP JBoss START ######### 
   2:  
   3: #Include conf/mod_jk/mod-jk.conf 
   4:  
   5: <IfModule worker.c> 
   6:  
   7: Startservers 6 
   8:  
   9: MAxClients 150 
  10:  
  11: MinSpareThreads 25 
  12:  
  13: MaxSpareThreads 75 
  14:  
  15: ThreadsPerChild 25 
  16:  
  17: MaxRequestsPerChild 0 
  18:  
  19: </IfModule> 
  20:  
  21: LoadModule jk_module modules/mod_jk2.so 
  22:  
  23: JkWorkersFile conf/mod_jk/workers.properties 
  24:  
  25: JkLogFile logs/mod_jk_error.log 
  26:  
  27: JkLogLevel error 
  28:  
  29: JkLogStampFormat "[%a %b %d %H:%M:%S %Y]" 
  30:  
  31: JkRequestLogFormat "%w %V %T" 
  32:  
  33: # JBoss site Start # 
  34:  
  35: <VirtualHost *:80> 
  36:  
  37: ServerAdmin support@JBoss.com 
  38:  
  39: ErrorLog "|bin/rotatelogs logs/App_error.%d.%m.%Y.log 10M" 
  40:  
  41: customLog "|bin/rotatelogs logs/App_Access.%d.%m.%Y.log 10M" common 
  42:  
  43: JkMount /* loadbalancer 
  44:  
  45: LoadModule deflate_module modules/mod_deflate.so 
  46:  
  47: SetOutputFilter DEFLATE 
  48:  
  49: SetInputFilter DEFLATE 
  50:  
  51: AddOutputFilterByType DEFLATE text/html text/plain text/xml text/x-js text/css application/x-javascript 
  52:  
  53: AddInputFilter DEFLATE text/html text/plain text/xml text/x-js text/css application/x-javascript 
  54:  
  55: SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png)$ no-gzip dont-vary 
  56:  
  57: SetEnvIfNoCase Request_URI \.(?:pdf|exe|zip)$ no-gzip dont-vary 
  58:  
  59: #SetEnvIfNoCase Request_URI \.(?:css|js)$ no-gzip dont-vary 
  60:  
  61: DeflateFilterNote Input instream 
  62:  
  63: DeflateFilterNote Output outstream 
  64:  
  65: DeflateFilterNote Ratio ratio 
  66:  
  67: LogFormat '%{outstream}n/%{instream}n (%{ratio}n%%) :- "%r"' App_small_deflate 
  68:  
  69: CustomLog "|bin/rotatelogs logs/App_small_deflate.%d.%m.%Y.log 10M" App_small_deflate 
  70:  
  71: <FilesMatch "\.(ico|jpg|jpeg|png|gif|js|css|swf)$"> 
  72:  
  73: Header set Cache-Control "public" 
  74:  
  75: Header set Expires "Thu, 31 Mar 2015 20:00:00 GMT" 
  76:  
  77: </FilesMatch> 
  78:  
  79: </VirtualHost> 
  80:  
  81: ######## APP JBoss STOP #########

2. Create folder with name mod_jk in D:\Apache2.2\conf & create following file with name workers.properties with the code mentioned below.


workers.properties



   1: #Define list of workers that will be used 
   2:  
   3: # for mapping requests 
   4:  
   5: worker.list=loadbalancer,App,status 
   6:  
   7: # Define App 
   8:  
   9: # modify the host as your host IP or DNS name. 
  10:  
  11: worker.App.port=8009 
  12:  
  13: worker.App.host=localhost 
  14:  
  15: worker.App.type=ajp13 
  16:  
  17: worker.App.lbfactor=1 
  18:  
  19: worker.App.local_worker=1 (1) 
  20:  
  21: worker.App.cachesize=100 
  22:  
  23: # # Load-balancing behaviour 
  24:  
  25: worker.loadbalancer.type=lb 
  26:  
  27: worker.loadbalancer.balance_workers=App 
  28:  
  29: worker.loadbalancer.sticky_session=1 
  30:  
  31: worker.loadbalancer.local_worker_only=1 
  32:  
  33: worker.list=loadbalancer 
  34:  
  35: # Status worker for managing load balancer 
  36:  
  37: worker.status.type=status

3. Download mod_jk2.so file from apache site & place it in D:\Apache2.2\modules.

4. Open a command Prompt, Run as administrator if required, and type commands in following sequence.

a. Change directory to Apache executable.


   1: cd Apache2.2\bin 

b. Test the syntax in configuration files


   1: httpd.exe –t

c. Stop service


   1: httpd.exe -k stop

d. Start service


   1: httpd.exe -k start

e. Make sure that there is no errors in the output of these commands
clip_image026[4]

f. Refer the screenshot above for desired outputs.

5. Incase if you get any popup like given below then click “Allow access” after checking all Networks.
clip_image027

6. Configuration completed at this stage;

7. Try accessing your server using port 80.

8. In case of any error, please refer the apache2.2\log folder for further diagnostics.






Configuring Service Mode for JBoss


Introduction
Following document explain the steps to configure JBoss to run in a service mode. To Proceed with the document one should have the Administration level of knowledge on Windows Environment.
Steps to Configure Service
Prerequisites
App application Installed on windows & configured to run on JBoss version 6.0
Assumption
For Single Server deployed with the name ‘default’ and App.bat file is available under jboss6\bin folder which is previously used to run the application.
For Multiple Server deployed with the name ‘A1’, ‘App2’ and so on.
App1.bat, App2.bat, etc. files are available under jboss6\bin folder which is previously used to run the application.
For single server Setup
Create copy of the <Jboss>\bin\service.bat into another file with name ‘service_App.bat’
Configuration
  1. Edit File service_App.bat & change following Properties.
    1. Search for
      set "SVCNAME=JBAS60SVC"
      Change it to
      set "SVCNAME=App_Jboss"
    2. Search for
      set SVCDISP=JBoss Application Server 6.0
      Change it to
      set SVCDISP=App JBoss Server 6.0
    3. Search for
      set SVCDESC=JBoss Application Server 6.0.0 GA/Platform: Windows %PROCESSOR_ARCHITECTURE%
      Change it to
      set SVCDESC=App JBoss Server 6.0.0 GA/Platform: Windows %PROCESSOR_ARCHITECTURE%
    4. Search for
      jbosssvc.exe -imwdc %SVCNAME% "%DIRNAME%" "%SVCDISP%" "%SVCDESC%" service.bat
      Change it to
      jbosssvc.exe -imwdc %SVCNAME% "%DIRNAME%" "%SVCDISP%" "%SVCDESC%" service_App.bat
    5. Search for (this will appear twice)
      call run.bat < .r.lock >> run.log 2>&1
      Change it to (Change both instance)
      call App.bat -c App -b 0.0.0.0 < .r.lock 2>&1
      If the server is running on specific IP then change it with following
      call App.bat -c App -b <IP_ADDRESS> < .r.lock 2>&1
    6. Search for (this will appear twice)
      call shutdown -S < .s.lock >> shutdown.log 2>&1
      Change it to (Change both instance)
      call shutdown --host=127.0.0.1 --port=1090 -S < .s.lock >> shutdown.log 2>&1
      If the server is running on specific IP then change it with following
      call shutdown --host=<IP_ADDRESS> --port=1090 -S < .s.lock >> shutdown.log 2>&1
  2. Edit file App.bat and verify if following properties are set to correct path, if not then set it to the correct path. If the property does not exist, then add the same.
    1. set JBOSS_HOME=D:\jboss6
    2. set JBOSS_CLASSPATH=%RUN_CLASSPATH%;D:\jboss6\server\App\conf\properties;
    3. set "JAVA_HOME=D:\jdk1.6.0_25"
Install Service
  1. Open Command Prompt (Run as Administrator if applicable) and change directory to <jboss>\bin\
  2. Execute following command.
    service_App.bat install
  3. Open Windows services, Service with the name “App JBoss Server 6.0”should be visible now. Try refresh if the services management snap in is already open.
  4. Start service; wait for some time to get the service initialize.
  5. View <Jboss_home>/server/App/logs/boot.log and check for any errors.
  6. Service installation is completed at this point.
Uninstall Service
  1. Open Command Prompt (Run as Administrator if applicable) and change directory to <jboss>\bin\
  2. Execute following command.
    service_App.bat uninstall
  3. Open Windows services, Service with the name “App JBoss Server 6.0”should have been disappeared now. Try refresh if the services management snap in is already open.
For Multiple server setup
Create copy of the <Jboss>\bin\service.bat into another file with name ‘service_App1.bat’, ‘service_App2.bat’ and so on.
Configuration for first server.
  1. Edit File service_App1.bat & change following Properties.
    1. Search for
      set "SVCNAME=JBAS60SVC"
      Change it to
      set "SVCNAME=App1_Jboss"
    2. Search for
      set SVCDISP=JBoss Application Server 6.0
      Change it to
      set SVCDISP=App1 JBoss Server 6.0
    3. Search for
      set SVCDESC=JBoss Application Server 6.0.0 GA/Platform: Windows %PROCESSOR_ARCHITECTURE%
      Change it to
      set SVCDESC=App1 JBoss Server 6.0.0 GA/Platform: Windows %PROCESSOR_ARCHITECTURE%
    4. Search for
      jbosssvc.exe -imwdc %SVCNAME% "%DIRNAME%" "%SVCDISP%" "%SVCDESC%" service.bat
      Change it to
      jbosssvc.exe -imwdc %SVCNAME% "%DIRNAME%" "%SVCDISP%" "%SVCDESC%" service1_App.bat
    5. Search for (this will appear twice)
      call run.bat < .r.lock >> run.log 2>&1
      Change it to (Change both instance)
      call App1.bat -c App -b 0.0.0.0 < .r.lock 2>&1
      If the server is running on specific IP then change it with following
      call App1.bat -c App -b <IP_ADDRESS> < .r.lock 2>&1
    6. Search for (this will appear twice)
      call shutdown -S < .s.lock >> shutdown.log 2>&1
      Change it to (Change both instance)
      call shutdown --host=127.0.0.1 --port=1090 -S < .s.lock >> shutdown.log 2>&1
      If the server is running on specific IP then change it with following
      call shutdown --host=<IP_ADDRESS> --port=1090 -S < .s.lock >> shutdown.log 2>&1
  2. Edit file App.bat and verify if following properties are set to correct path, if not then set it to the correct path. If the property does not exist, then add the same.
    1. set JBOSS_HOME=D:\jboss6
    2. set JBOSS_CLASSPATH=%RUN_CLASSPATH%;D:\jboss6\server\App1\conf\properties;
    3. set "JAVA_HOME=D:\jdk1.6.0_25"
Install First Service
  1. Open Command Prompt (Run as Administrator if applicable) and change directory to <jboss>\bin\
  2. Execute following command.
    service_App1.bat install
  3. Open Windows services, Service with the name “App1 JBoss Server 6.0”should be visible now. Try refresh if the services management snap in is already open.
  4. Start service; wait for some time to get the service initialize.
  5. View <Jboss_home>/server/App1/logs/boot.log and check for any errors.
  6. Service installation is completed at this point.
Configuration for next servers
Follow steps 1 to 8 in previous section by replacing App1 with App2, wherever is applicable and go on by incrementing the number.

Configuring HTTPS on JBoss

Note: We are assuming here that Jboss6.1 and Jdk1.6.0.27 installed in D: drive and server is running on port 8080.

Step: 1. Creating keystore and private key

  • Open a command prompt with run as administrator.
  • Change directory to D:\jdk1.6.0_27\bin
  • Enter below mentioned command with replacing <changeit> to your password as per your choice.

keytool -genkey -alias jbosskey -keypass <changeit> -keyalg RSA –validity 365 -keystore server.keystore

(Eg: keytool -genkey -alias jbosskey -keypass password -keyalg RSA –validity 365 -keystore server.keystore)

clip_image002

  • Hit enter.
  • Please enter password which you used in first command.
  • Retype the same password again.
  • What is your first and last name?
    Enter your jboss server DNS name or Alias name as per your choice.
  • Enter organizational unit name.
  • Enter organization name.
  • Enter your city name.
  • Enter state name.
  • Enter country code.
  • Enter Y to Agree.

clip_image004

  • You will see “server.keystore” inside D:\jdk1.6.0_27\bin
  • Please enter below command for verifying keystore.
    keytool -list -keystore server.keystore
  • Enter the password.
  • You will see output like below screen shot.
    clip_image006

Generating and storing the Self sing certificate.

Note: replace <changeit> with your “server.keystore" password which you mentioned during "server.keystore" creation

  • Enter following command.

keytool -export -alias jbosskey -keypass <changeit> -file server.crt -keystore server.keystore

Eg: keytool -export -alias jbosskey -keypass password -file server.crt -keystore server.keystore

clip_image008

  • You will see “server.crt” inside D:\jdk1.6.0_27\bin

Note: replace <changeit> with your "server.keystore" password which you mentioned during "server.keystore" creation

  • Enter following command.

keytool -import -alias jbosscert -keypass changeit -file server.crt -keystore server.keystore

Eg: keytool -import -alias jbosscert -keypass password -file server.crt -keystore server.keystore

Note:You receive a warning that it already exists in the keystore. Ignore it. It is because Java expects separate keystore and trustore files and we are using only one.

clip_image010

  • Please enter below command for verifying keystore.
    keytool -list -keystore server.keystore
  • Enter the password.
  • You should see a TrustedCertEntry named jbosscert in the listing like in below screen shot.

clip_image012

  • Copy “server.keystore” from D:\jdk1.6.0_27\bin to D:\jboss6.1\server\default\conf\ folder.

Step: 2. Enable HTTPS for JBoss

  • Edit server.xml file using text editor(Recommended notepad++) D:\jboss6.1\server\default\deploy\jbossweb.sar folder
  • Search for line SSL/TLS Connector and it will look like as below.

<!-- SSL/TLS Connector configuration using the admin devl guide keystore

<Connector protocol="HTTP/1.1" SSLEnabled="true"

port="${jboss.web.https.port}" address="${jboss.bind.address}"

scheme="https" secure="true" clientAuth="false"

keystoreFile="${jboss.server.home.dir}/conf/chap8.keystore"

keystorePass="rmi+ssl" sslProtocol = "TLS" />

-->

  • Uncomment the line, just cut the --> arrow and paste it to first line like shown in below line and edit the code and enter keystore password which you used for creating keystore.

<!-- SSL/TLS Connector configuration using the admin devl guide keystore -->

<Connector protocol="HTTP/1.1" SSLEnabled="true"

port="443" address="${jboss.bind.address}"

scheme="https" secure="true" clientAuth="false"

keystoreFile="${jboss.server.home.dir}/conf/server.keystore"

keystorePass="password" sslProtocol="TLS" />

Step: 3. Enable Re direction from HTTP to HTTPS on JBoss

  • Edit server.xml file using text editor(Recommended notepad++) D:\jboss6.1\server\swift\deploy\jbossweb.sar folder
  • Search for line A HTTP/1.1 Connector on port 8080 and it will look like as below.

<Connector protocol="HTTP/1.1" port="${jboss.web.http.port}" address="${jboss.bind.address}"

redirectPort="${jboss.web.https.port}" />

  • Edit the code as shown in below.

<Connector protocol="HTTP/1.1" port="8080" address="${jboss.bind.address}"

redirectPort="443" />

  • Edit web.xml file using text editor(Recommended notepad++) D:\jboss6.1\server\default\deploy\jbossweb.sar folder
  • Add the following code at bottom but before </web-app> as show in below.

/<security-constraint>

<web-resource-collection>

<web-resource-name>Protected Context</web-resource-name>

<url-pattern>/*</url-pattern>

</web-resource-collection>

<!-- auth-constraint goes here if you requre authentication -->

<user-data-constraint>

<transport-guarantee>CONFIDENTIAL</transport-guarantee>

</user-data-constraint>

</security-constraint>/

</web-app>

  • Restart the Jboss Server; you are done with the configuration Swift server on SSL with redirection.

Installing a Certificate from a Certificate Authority

To obtain and install a Certificate from a Certificate Authority (like verisign.com, thawte.com or trustcenter.de), read the previous section and then follow these instructions:

Create a local Certificate Signing Request (CSR)

In order to obtain a Certificate from the Certificate Authority of your choice you have to create a so called Certificate Signing Request (CSR). That CSR will be used by the Certificate Authority to create a Certificate that will identify your website as "secure". To create a CSR follow these steps:

  • Create a local Certificate (as described in the previous section):
·         keytool -genkey -alias tomcat -keyalg RSA \
    -keystore <your_keystore_filename>

Note: In some cases you will have to enter the domain of your website (i.e. www.myside.org) in the field "first- and lastname" in order to create a working Certificate.


  • The CSR is then created with:
·         keytool -certreq -keyalg RSA -alias tomcat -file certreq.csr \
    -keystore <your_keystore_filename>

Now you have a file called certreq.csr that you can submit to the Certificate Authority (look at the documentation of the Certificate Authority website on how to do this). In return you get a Certificate.

Importing the Certificate

Now that you have your Certificate you can import it into you local keystore. First of all you have to import a so called Chain Certificate or Root Certificate into your keystore. After that you can proceed with importing your Certificate.


  • Download a Chain Certificate from the Certificate Authority you obtained the Certificate from.
    For Verisign.com commercial certificates go to: http://www.verisign.com/support/install/intermediate.html
    For Verisign.com trial certificates go to: http://www.verisign.com/support/verisign-intermediate-ca/Trial_Secure_Server_Root/index.html
    For Trustcenter.de go to: http://www.trustcenter.de/certservices/cacerts/en/en.htm#server
    For Thawte.com go to: http://www.thawte.com/certs/trustmap.html
  • Import the Chain Certificate into your keystore
·         keytool -import -alias root -keystore <your_keystore_filename> \
    -trustcacerts -file <filename_of_the_chain_certificate>


  • And finally import your new Certificate
·         keytool -import -alias tomcat -keystore <your_keystore_filename> \
    -file <your_certificate_filename>

Saturday, December 31, 2011

Enable Liveupdate Tab Symantec Antivirus Client from Registry


Enable Liveupdate Tab Symantec Antivirus Client from Registry






Scenario: Live update has been disabled by System Administrator but you need to enable it.

It is damn easy if you have got Administrative Privileges on that machine, Let us start the tweak.




HowToDo:

Step1: Open Registry Editor

  1. Open Run window and type regedit and then hit Enter



  1. Go to “C:\Windows\System32” and search for “regedt32.exe”, double click the same -> if you love to use Mouse
  2. Open Command Prompt and there type “regedit”  > Do this if you don’t want to leave any hints of  the commands you executed.

 Step2:  Navigate to the following path:

HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\PatternManager

Inside Pattern manager you will see one “LockUpdatePattern” REG_DWORD Entry

Just double click on it and change the vale to 0(Zero) to Enable the Liveupdate Tab

 
 Note: If you have a 32bit client installed in a 64bit machine, then you have to navigate as follows.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\INTEL\LANDesk\VirusProtect6\CurrentVersion\PatternManager

Enable the “LockUpdatePattern” REG_DWORD by changing its vale to 0(Zero)


Congratulations you did it… Now just update your Antivirus to latest definition.

No need to be available in Office Network to get latest updates.