linux 防止ARP超时 nano /etc/systemd/system/keep-arp.service [Unit] Description=Send periodic gratuitous ARP to prevent MAC aging (auto-IP) After=network.target [Service] Type=simple ExecStart=/bin/bash -c 'while true; do \ IP=$(ip -4 addr show ens192 | grep -oP "(?<=inet\\s)\\d+(\\.\\d+){3}" | head
linux debian update sudo apt install screen -y sudo screen apt autoremove -y && sudo screen apt update && sudo screen apt dist-upgrade -y && sudo screen apt upgrade -y
linux Postgresql database "DatabaseName" has a collation version mismatch su - postgres psql \c DatabaseName ALTER DATABASE DatabaseName REFRESH COLLATION VERSION; REINDEX DATABASE DatabaseName;
树莓派 Linux 持续ping网关防止wifi掉线 nano /etc/systemd/system/network-ping-gateway.service 添加以下内容 # Save in /etc/systemd/system/network-ping-gateway.service [Unit] Description=Ping default network gateway service After=network-online.target [Service] ExecStart=/bin/bash -c 'read _ _ gateway _ < <(ip route list match 0/0); ping "$gateway"'
debian debian11设置无密码sudo 在/etc/sudoers.d/下新建文件 nano /etc/sudoers.d/passwordless 内容如下,替换username和/usr/bin/su为需要的用户名和程序 username ALL=(ALL) NOPASSWD: /usr/bin/su
linux Debian使用MAC地址作为DHCP客户端IP 编辑 /etc/dhcp/dhclient.conf nano /etc/dhcp/dhclient.conf 增加 send dhcp-client-identifier = hardware;
linux Ubuntu 20.04 lightdm 关闭休眠 禁用systemd休眠状态 sudo systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target 修改lightdm的Time before suspend sudo -u lightdm dbus-launch gsettings set org.gnome.settings-daemon.plugins.power sleep-inactive-ac-timeout 0 sudo -u lightdm dbus-launch gsettings set org.gnome.settings-daemon.plugins.power sleep-inactive-battery-
linux apt限制同时下载数量 Queue-Mode 设置选项 默认值为 host 对每个host发起一个连接。当设为access时,对每个URI类型发起一个连接。由于大部分为http,因此也大致满足要求 永久设置 echo 'Acquire::Queue-Mode "access";' >/etc/apt/apt.conf.d/75download 临时设置 apt -o Acquire::Queue-mode=access upgrade
centos centos 8 自动更新 安装dnf-automatic dnf install dnf-automatic 编辑/etc/dnf/automatic.conf apply_updates = yes 启动定时器 systemctl enable --now dnf-automatic.timer
树莓派 树莓派启动优化 关闭蓝牙 编辑/boot/config.txt添加 dtoverlay=disable-bt 或pi3B+对应选项 关闭蓝牙串口服务 sudo systemctl disable hciuart 关闭avahi sudo systemctl disable avahi-daemon 关闭启动时彩虹屏幕 编辑/boot/config.txt添加 # Disable the rainbow splash screen disable_splash=1
linux 树莓派4 OTG 以太网设置 编辑/boot/config.txt增加 dtoverlay=dwc2,dr_mode=peripheral 编辑/boot/cmdline.txt增加 modules-load=dwc2,g_ether 编辑/etc/modprobe.d/g_ether.conf写入 options g_ether use_eem=0 dev_addr=1a:55:89:a2:69:41 host_addr=1a:55:89:a2:69:42 idVendor=0x04b3 idProduct=
linux 树莓派Kiosk(展台模式)设置 安装Raspbian Buster lite 启用SSH boot分区下新建名称为ssh的空文本 添加WiFi信息 boot分区下新建wpa_supplicant.conf country=CN ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev update_config=1 network={ ssid="NETWORK-NAME" psk="NETWORK-PASSWORD" } 设置自动启动 sudo raspi-config 菜单中选择 Boot Options Desktop CLI Console Autologin 更换自动登录用户 nano /etc/systemd/system/
linux selinux 常用命令 查看是否有被selinux阻挡 sudo cat /var/log/audit/audit.log | grep denied boolean 查看boolean状态 sudo sestatus -b sudo sestatus -b | grep -i sendmail 设置boolean sudo setsebool -P $boolean名 $1或0 常用boolean boolean名 意义 httpd_can_network_connect 允许httpd反向代理 httpd_can_sendmail 允许httpd发送邮件 semanager 安装semanager sudo yum install -y policycoreutils-python Centos 8 sudo
centos7 Centos 清理旧内核 Centos 7 sudo yum install yum-utils -y && sudo package-cleanup --oldkernels --count=1 -y Centos 8 dnf remove --oldinstallonly --setopt installonly_limit=1
centos Centos7 apache使用freeipa pki提供证书 安装apache和mod_nss sudo yum install httpd mod_nss -y 配置mod_nss sudo sh -c "echo 'Listen 443' >> /etc/httpd/conf.d/nssconfig.conf" sudo sh -c "echo 'NSSCipherSuite +aes_128_sha_256,+aes_256_sha_256,+ecdhe_ecdsa_aes_128_gcm_sha_
centos Centos 7 加入freeipa域 安装需要的软件包 yum install ipa-client -y 加入域 ipa-client-install --domain YOUR_DOMAIN_NAME 打开自动创建home文件夹 authconfig --enablemkhomedir --update
centos centos 7 安装polipo 下载 git clone https://github.com/jech/polipo.git cd polipo (可选)使用发布的版本 git checkout polipo-1.1.1 安装 make all su -c 'make install' 建立配置文件 mkdir /opt/polipo nano /opt/polipo/config 复制http://www.pps.univ-paris-diderot.fr/~jch/software/polipo/config.sample 内容并编辑 建立polipo账户
linux 安装delegate作为socks代理转http代理服务器 从ftp://ftp.delegate.org/pub/DeleGate/bin/linux/latest/ 下载最新的程序 wget ftp://ftp.delegate.org/pub/DeleGate/bin/linux/9.9.13/linux2.6-dg9_9_13.tar.gz 然后解压 tar -xf linux2.6-dg9_9_13.tar.gz cd linux2.6-dg9_9_13 将其中的DGROOT文件夹拷贝到$home并重命名为delegate mv DGROOT $home
centos centos 7 firewalld常用命令 将ip添加到zone sudo firewall-cmd --permanent --zone=work --add-source=192.168.0.0/24 将某个网口添加到zone sudo firewall-cmd --permanent --zone=work --add-interface=eth0 在某个zone打开端口 sudo firewall-cmd --permanent --zone=work --add-port=8080-8090/tcp 永久打开一个端口 firewall-cmd --permanent --add-port=8080/tcp 永久关闭一个端口 firewall-cmd --permanent --remove-port=
centos selinux允许nginx反向代理 查询nginx是否被selinux阻挡 sudo cat /var/log/audit/audit.log | grep nginx | grep denied 添加规则 sudo cat /var/log/audit/audit.log | grep nginx | grep denied | audit2allow -M mynginx sudo semodule -i mynginx.pp
centos systemd服务创建 在/etc/systemd/system中新建servicename.service文件。 按以下模板填入内容 [Unit] Description=servicedescription After=network.target [Service] Type=simple WorkingDirectory=/path/to/service User=http Group=http ExecStart=/usr/bin/service(startscript) ExecStop=/usr/bin/service(stopscript) Restart=always SyslogIdentifier=servicename [Install] WantedBy=multi-user.target 之后修改启动脚本/程序的selinux属性 semanage fcontext -a -t unconfined_exec_
linux sysvinit确保一个服务晚于另一个启动 在启动脚本中加入 # wait until mysql started MYSQL_OK=0 WHILE_CNT=0 while [ "$WHILE_CNT" -le 60 ] ; do if [[ `service mysql status` == *running* ]]; then MYSQL_OK=1; break; fi WHILE_CNT=`expr $WHILE_CNT + 1`; sleep 1 done 其中 `service mysql status` == *running* 可以改为任何条件