<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HenryBLOGultom &#187; CentOS</title>
	<atom:link href="http://henry.gultom.or.id/index.php/archives/category/centos/feed/" rel="self" type="application/rss+xml" />
	<link>http://henry.gultom.or.id</link>
	<description>Gtoms singkatan dari gultom, family name atau marga yang kusandang sejak lahir. Dari kuliah sampai bekerja aku selalu dipanggil Gul atau Tom. Tinggal di Jakarta dan bekerja di perusahaan Internet Services Provider &#38; Telco Swasta.</description>
	<lastBuildDate>Mon, 06 Sep 2010 04:47:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Installation Digium TE121BF, Asterisk, Dahdi, Libpri, Xen(domU)</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/09/02/installation-digium-te121bf-asterisk-dahdi-libpri-xendomu/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/09/02/installation-digium-te121bf-asterisk-dahdi-libpri-xendomu/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 13:20:36 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[Asterisk]]></category>
		<category><![CDATA[CentOS]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[dahdi]]></category>
		<category><![CDATA[digium]]></category>
		<category><![CDATA[libpri]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1438</guid>
		<description><![CDATA[	Tujuan instalasi ini adalah membuat PBX berbasis software dengan Asterisk dan Digium Digital Telephony Card, untuk disambungkan ke perangkat Telkom E1 ISDN PRA.&#160; Hasil akhir instalasi ini digunakan untuk call centre dan help desk sebuah perusahaan customer services&#160; di&#160; Tangerang.

	Kebutuhannya :
1. Server Linux menggunakan Centos 5.5 berjalan dalam model Virtual server menggunakan Xen Server(dom0).
2. Server [...]]]></description>
			<content:encoded><![CDATA[	<p>Tujuan instalasi ini adalah membuat <span class="caps">PBX</span> berbasis software dengan <a href="http://www.asterisk.org/">Asterisk</a> dan <a href="http://www.digium.com/en/products/digital/">Digium Digital Telephony Card</a>, untuk disambungkan ke perangkat <a href="http://www.telkom.co.id/produk-layanan/telkom-solution/korporat/informasi-produk-layanan/data-internet/telkom-isdn-pra.html">Telkom <span class="caps">E1 ISDN PRA</span></a>.&#160; Hasil akhir instalasi ini digunakan untuk call centre dan help desk sebuah perusahaan customer services&#160; di&#160; Tangerang.</p>

	<p>Kebutuhannya :<br />
1. Server Linux menggunakan <a href="http://www.centos.org/">Centos 5.5</a> berjalan dalam model Virtual server menggunakan Xen Server(dom0).<br />
2. Server Asterisk dan perangkat Digium Digital Telephony Card berjalan dalam Centos 5.5 Xen(domU.)<br />
3. Digium Digital Telephony Card menggunakan <a href="http://store.digium.com/productview.php?product_code=TE121B">Digium <span class="caps">TE121BF </span></a>dengan fasilitas utama T1/E1/J1/PRI <span class="caps">PCI</span>-Express x1 card and hardware echo cancellation<br />
4. Perangkat dan instalasi Telkom <span class="caps">E1 ISDN PRA</span><br />
5. Helpdesk menggunakan <a href="http://en.wikipedia.org/wiki/Softphone">softphone</a> dan <a href="http://www.cisco.com/en/US/prod/collateral/voicesw/ps6788/phones/ps10499/qa_c67-552213-00.html">Cisco <span class="caps">SPA 502G</span></a> 1-Line <span class="caps">IP </span>Phone</p>

	<p>Untuk point 1,2,3, dan testing di 5 dikerjakan oleh saya, dan point 4 dikerjakan oleh pihak Telkom.</p>

	<p>Point 1 servernya sudah berjalan dan berisi <span class="caps">DNS</span>,Email,Webserver,Proxy,Database,Fileserver semua berjalan dalam model virtual server, untuk keperluan instalasi ini diperlukan domU baru dan tantangannya menempatkan <a href="http://store.digium.com/productview.php?product_code=TE121B">Digium <span class="caps">TE121BF</span></a> hanya di domU, jadi tidak di dom0, istilahnya dalam Xen adalah <a href="http://wiki.xensource.com/xenwiki/Assign_hardware_to_DomU_with_PCIBack_as_module">pciback</a>.</p>

	<p>Digium <span class="caps">TE121BF PC</span>Iexpress card dibeli melalui Digium distributor di <a href="http://jcmex.com">Malaysia</a> sekitar US$800, Layanan Telkom <span class="caps">E1 ISDN PRA</span> untuk sambungan baru ke kantor perusahaan ini kena biaya pasang sekitar Rp 10 juta, Cisco <span class="caps">SPA 502G</span> sekitar US$106, yang lainnya free memakai software opensource Linux.</p>

	<p>Okay selesai bicara teori dan sekarang praktek dan saya mau bagi ilmunya melalui dokumenasi yang sempat saya buatkan.</p>

	<p><span id="more-1438"></span></p>

	<p>Point 1.&#160; Server Linux menggunakan Centos 5.5 sudah terinstall dan berjalan dalam model Virtual server menggunakan Xen Server(dom0).&#160; Tinggal create guest domain baru atau domU baru untuk instalasi keperluan Asterisk&#160; diatas. Pembuatan domU dikerjakan oleh Xen melalui dom0.</p>

	<p>Setelah domU untuk server Asterisk dibuat, kita matikan dahulu Server (jangan lupa matikan terlebih  dahulu satu persatu domU sebelum shutdown mesin). Kemudian pasang Digium  <span class="caps">TE121BF</span> card, buka casing dan pada motherboard, pasang card tersebut  pada slot <span class="caps">PCI</span>Express tipe x1 yang lebih kecil dibandingkan slot <span class="caps">PCI</span> tipe  normal dan tipe x4/16. Setelah terpasang kita hidupkan kembali server.</p>

	<p>Setelah server up, kita masuk ke dom0 dan cek keberadaan card dengan lspci :</p>

	<p>[root@ID41-ND201 ~]# lspci<br />
00:00.0 Host bridge: Intel Corporation 4 Series Chipset <span class="caps">DRAM </span>Controller (rev 02)<br />
00:01.0 <span class="caps">PCI</span> bridge: Intel Corporation 4 Series Chipset <span class="caps">PCI </span>Express Root Port (rev 02)<br />
00:1a.0 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #4<br />
00:1a.1 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #5<br />
00:1a.2 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #6<br />
00:1a.7 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB2 EHCI </span>Controller #2<br />
00:1b.0 Audio device: Intel Corporation 82801JI (ICH10 Family) <span class="caps">HD </span>Audio Controller<br />
00:1c.0 <span class="caps">PCI</span> bridge: Intel Corporation 82801JI (ICH10 Family) <span class="caps">PCI </span>Express Port 1<br />
00:1c.2 <span class="caps">PCI</span> bridge: Intel Corporation 82801JI (ICH10 Family) <span class="caps">PCI </span>Express Port 3<br />
00:1c.4 <span class="caps">PCI</span> bridge: Intel Corporation 82801JI (ICH10 Family) <span class="caps">PCI </span>Express Port 5<br />
00:1c.5 <span class="caps">PCI</span> bridge: Intel Corporation 82801JI (ICH10 Family) <span class="caps">PCI </span>Express Port 6<br />
00:1d.0 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #1<br />
00:1d.1 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #2<br />
00:1d.2 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB UHCI </span>Controller #3<br />
00:1d.7 <span class="caps">USB </span>Controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">USB2 EHCI </span>Controller #1<br />
00:1e.0 <span class="caps">PCI</span> bridge: Intel Corporation 82801 <span class="caps">PCI </span>Bridge (rev 90)<br />
00:1f.0 <span class="caps">ISA</span> bridge: Intel Corporation 82801JIB (ICH10) <span class="caps">LPC </span>Interface Controller<br />
00:1f.2 <span class="caps">SATA</span> controller: Intel Corporation 82801JI (ICH10 Family) <span class="caps">SATA AHCI </span>Controller<br />
00:1f.3 SMBus: Intel Corporation 82801JI (ICH10 Family) SMBus Controller<br />
01:00.0 <span class="caps">VGA</span> compatible controller: nVidia Corporation <span class="caps">G73 </span>[GeForce 7300 GT] (rev a1)<br />
03:00.0 <span class="caps">PCI</span> bridge: Texas Instruments <acronym title="A">XIO2000</acronym>/<acronym title="A">XIO2200</acronym> <span class="caps">PCI </span>Express-to-PCI Bridge (rev 03)<br />
<strong>04:08.0 Ethernet controller: Digium, Inc. Wildcard <span class="caps">TE121</span> single-span T1/E1/J1 card (PCI-Express) (rev 11)</strong><br />
05:00.0 <span class="caps">IDE</span> interface: JMicron Technology Corp. <span class="caps">JMB368 IDE</span> controller<br />
06:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd. <span class="caps">RTL8111</span>/8168B <span class="caps">PCI </span>Express Gigabit Ethernet controller (rev 02)<br />
07:00.0 Ethernet controller: D-Link System Inc <span class="caps">RTL8139 </span>Ethernet (rev 10)<br />
07:01.0 Ethernet controller: D-Link System Inc <span class="caps">DGE</span>-530T Gigabit Ethernet Adapter (rev 11) (rev 11)</p>

	<p>Tanda yang di bold adalah identifikasi card yang tadi sudah terpasang. Berarti Centos 5.5 mendeteksi baik card ini.</p>

	<p>Masih dalam dom0 kita akan konfigurasikan agar card ini masuk ke domU asterisk yang sudah saya buat sebelumnya atau konfigurasi pciback module.</p>

	<p>Tambahkan options pciback hide=(0000:04:08.0) pada modprobe.conf vi /etc/modprobe.conf</p>

	<p>[root@ID41-ND201 ~]# cat /etc/modprobe.conf<br />
alias scsi_hostadapter ahci<br />
alias scsi_hostadapter1 ata_piix<br />
remove snd-hda-intel { /usr/sbin/alsactl store 0 >/dev/null 2>&#038;1 || : ; }; /sbin/modprobe <del>r&#8212;ignore</del>remove snd-hda-intel<br />
alias eth0 r8169<br />
alias snd-card-0 snd-hda-intel<br />
options snd-card-0 index=0<br />
alias eth1 3c59x<br />
alias eth2 8139too<br />
alias eth3 skge<br />
alias eth skge<br />
options pciback hide=(0000:04:08.0)<br />
Kemudian buat file initrd agar maload pciback module sebelum modules lain:</p>

	<p>[root@ID41-ND201 ~]# mkinitrd <del>f&#8212;preload=pciback /boot/initrd</del>$(uname -r).img $(uname -r)</p>

	<p>Saya tambahkan pci = [ &#8216;04:08.0&#8217; ]&#160; pada file konfigurasi domU</p>

	<p>[root@ID41-ND201 ~]# vi /etc/xen/domU-ID41-ND015<br />
name = &#8220;domU-ID41-ND015&#8221;<br />
memory = &#8220;384&#8221;<br />
pci = [ &#8216;04:08.0&#8217; ]<br />
disk = [&#8216;tap:aio:/dev/vg0/domU-ID41-ND015,xvda,w&#8217;,<br />
&#8216;tap:aio:/dev/vg0/domU-ID41-ND015-swap,xvdb,w&#8217;,<br />
&#8216;tap:aio:/dev/vg0/domU-ID41-ND015-opt,xvdc,w&#8217;]<br />
vif = [ &#8216;mac=00:16:3E:5B:5D:62,bridge=id41br&#8217; ]<br />
bootloader=&#8221;/usr/bin/pygrub&#8221;<br />
vcpus=1<br />
on_reboot = &#8216;restart&#8217;<br />
on_crash = &#8216;restart&#8217;</p>

	<p>Selesai pada dom0(ID41-ND201) saya pindah ke domU.</p>

	<p>[root@ID41-ND201 ~]# xm console domU-ID41-ND015</p>

	<p>Edit /boot/grub/menu.lst&#160; untuk menambahkan <strong>swiotlb=force</strong> hal ini untuk menghindari kernel panic pada domU Asterisk(domU-ID41-ND015)&#160; saat dijalankan.</p>

	<p>[root@ID41-ND015 ~]# vi /boot/grub/grub.conf<br />
default=0<br />
timeout=5<br />
splashimage=(hd0,0)/boot/grub/splash.xpm.gz<br />
hiddenmenu<br />
title CentOS (2.6.18-194.11.1.el5xen)<br />
root (hd0,0)<br />
kernel /boot/vmlinuz-2.6.18-194.11.1.el5xen ro root=LABEL=/ console=xvc00<br />
<strong>swiotlb=force</strong><br />
initrd /boot/initrd-2.6.18-194.11.1.el5xen.img<br />
title CentOS (2.6.18-194.11.1.el5)<br />
root (hd0,0)<br />
kernel /boot/vmlinuz-2.6.18-194.11.1.el5 ro root=LABEL=/ console=xvc0<br />
initrd /boot/initrd-2.6.18-194.11.1.el5.img<br />
title CentOS (2.6.18-194.8.1.el5xen)</p>

	<p>Kemudian kembali ke dom0 dan restart server.</p>

	<p>[root@ID41-ND201 ~]# reboot</p>

	<p>Setelah login saya masuk ke domU kembali<br />
[root@ID41-ND201 ~]# xm console domU-ID41-ND015<br />
<span class="caps">INIT</span>: version 2.86 reloading</p>

	<p>CentOS release 5.5 (Final)<br />
Kernel 2.6.18-194.11.1.el5xen on an x86_64</p>

	<p><span class="caps">ID41</span>-ND015.xxxx.com login:<br />
CentOS release 5.5 (Final)<br />
Kernel 2.6.18-194.11.1.el5xen on an x86_64</p>

	<p>[root@ID41-ND015 ~]# lspci<br />
00:00.0 Ethernet controller: Digium, Inc. Wildcard <span class="caps">TE121</span> single-span T1/E1/J1 card (PCI-Express) (rev 11)<br />
[root@ID41-ND015 ~]#</p>

	<p>Horeee&#8230;......pciback module berjalan di domU.</p>

	<p>Setelah ini tinggal konfigurasi point 2 dan 3&#160; Instalasi Asterisk&#174; / <span class="caps">DAHDI </span>/ Libpri</p>

	<p>[root@ID41-ND015 ~]# wget http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-1.6.2.11.tar.gz<br />
[root@ID41-ND015 ~]# tar <del>zxvf asterisk</del>1.6.2.11.tar.gz<br />
[root@ID41-ND015 ~] # cd asterisk-1.6.2.11<br />
[root@ID41-ND015 ~]# ./configure<br />
[root@ID41-ND015 ~] # make menuselect<br />
[root@ID41-ND015 ~]# make<br />
[root@ID41-ND015 ~]# make install<br />
[root@ID41-ND015 ~]# make samples</p>

	<p>[root@ID41-ND015 ~]# wget http://downloads.asterisk.org/pub/telephony/libpri/libpri-1.2.8.tar.gz<br />
[root@ID41-ND015 ~] # tar <del>zxvf libpri</del>1.2.8.tar.gz<br />
[root@ID41-ND015 ~] # cd libpri-1.2.8<br />
[root@ID41-ND015 ~] # make<br />
[root@ID41-ND015 ~] # make install</p>

	<p>[root@ID41-ND015 ~]# wget http://downloads.asterisk.org/pub/telephony/dahdi-linux-complete/dahdi-linux-complete-2.4.0+2.4.0.tar.gz<br />
[root@ID41-ND015 ~] # tar <del>zxvf dahdi</del>linux-complete-2.4.0+2.4.0.tar.gz<br />
[root@ID41-ND015 ~] # cd dahdi-linux-complete-2.4.0+2.4.0<br />
[root@ID41-ND015 ~] # make<br />
[root@ID41-ND015 ~] # make install</p>

	<p>Beberapa settingan untuk bisa berhubungan dengan layanan Telkom <span class="caps">E1 ISDN PRA</span><br />
[root@ID41-ND015 ~]# vi /etc/asterisk/chan_dahdi.conf<br />
[trunkgroups]<br />
national:&#160;&#160;&#160; National <span class="caps">ISDN 2 </span>(default)<br />
dms100:&#160;&#160;&#160;&#160;&#160; Nortel <span class="caps">DMS100</span><br />
4ess:&#160;&#160;&#160;&#160;&#160;&#160;&#160; AT&#038;T 4ESS<br />
5ess:&#160;&#160;&#160;&#160;&#160;&#160;&#160; Lucent 5ESS<br />
euroisdn:&#160;&#160;&#160; EuroISDN (common in Europe)<br />
ni1:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Old National <span class="caps">ISDN 1</span><br />
qsig:&#160;&#160;&#160;&#160;&#160;&#160;&#160; Q.SIG<br />
usecallerid=yes<br />
callwaiting=yes<br />
usecallingpres=yes<br />
callwaitingcallerid=yes<br />
threewaycalling=yes<br />
transfer=yes<br />
canpark=yes<br />
cancallforward=yes<br />
callreturn=yes<br />
echocancel=yes<br />
echocancelwhenbridged=yes<br />
group=1<br />
callgroup=1<br />
pickupgroup=1<br />
signalling = pri_cpe<br />
switchtype = euroisdn<br />
context = incoming<br />
channel => 1-15,17-31</p>

	<p>[root@ID41-ND015 asterisk]# vi /etc/dahdi/system.conf<br />
loadzone = us<br />
defaultzone=us</p>

	<p>span = 1,1,0,ccs,hdb3<br />
bchan = 1-15,17-31<br />
dchan = 16<br />
echocanceller = mg2,1-15,17-31</p>

	<p>[root@ID41-ND015 dahdi]# vi /etc/dahdi/modules<br />
wcte12xp<br />
[root@ID41-ND015 ~]# /etc/init.d/asterisk start</p>

	<p>[root@ID41-ND015 asterisk]# ps axf |grep asterisk<br />
1939 pts/1&#160;&#160;&#160; T&#160;&#160;&#160;&#160;&#160; 0:00&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; <em> less /var/log/asterisk/event</em>log<br />
2620 pts/1&#160;&#160;&#160; S+&#160;&#160;&#160;&#160; 0:00&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; _ grep asterisk<br />
3956 ?&#160;&#160;&#160;&#160;&#160;&#160;&#160; S&#160;&#160;&#160;&#160;&#160; 0:00 /bin/sh /usr/sbin/safe_asterisk<br />
3966 ?&#160;&#160;&#160;&#160;&#160;&#160;&#160; Sl&#160;&#160;&#160;&#160; 0:02&#160; _ /usr/sbin/asterisk -f -vvvg -c<br />
[root@ID41-ND015 asterisk]#</p>

	<p>[root@ID41-ND015 asterisk]#&#160; dahdi_cfg -vv<br />
[root@ID41-ND015 dahdi]# /etc/init.d/dahdi start</p>

	<p>[root@ID41-ND015 asterisk]# lsmod |grep dahdi<br />
dahdi_echocan_mg2&#160;&#160;&#160;&#160;&#160; 39688&#160; 30<br />
dahdi_voicebus&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 79424&#160; 1 wcte12xp<br />
dahdi&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 238384&#160; 67 dahdi_echocan_mg2,wcte12xp,dahdi_voicebus<br />
crc_ccitt&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 35265&#160; 1 dahdi<br />
[root@ID41-ND015 asterisk]#</p>

	<p>[root@ID41-ND015 ~]# dahdi_tool</p>

	<p><span class="caps">DAHDI </span>Tool&#169;2002-2008 Digium, Inc.</p>

	<p>+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+ <span class="caps">DAHDI </span>Telephony Interfaces +&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160; Alarms&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Span&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160; <span class="caps">RED</span>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Wildcard <span class="caps">TE121 </span>Card 0&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ^&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; :&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; #&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; v&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; +&#8212;&#8212;&#8212;&#8212;+&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; +&#8212;&#8212;&#8212;+&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; | Select |&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; | Quit |&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; +&#8212;&#8212;&#8212;&#8212;+&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; +&#8212;&#8212;&#8212;+&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
|&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; |<br />
+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+</p>

	<p>Span 1: 31 total channels, 31 configured&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; F1=Details <span class="caps">F10</span>=Quit</p>

	<p>quit.</p>

	<p>Alarm masih <span class="caps">RED</span> karena kabel dari Telkom <span class="caps">ISDN</span> belum selesai di pasang.</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/09/dahdi1.png"><img class="alignleft size-full wp-image-1446" title="dahdi tools" src="http://henry.gultom.or.id/wp-content/uploads/2010/09/dahdi1.png" alt="" width="450" height="340" /></a></p>

	<p>[root@ID41-ND015 asterisk]# less /var/log/asterisk/queue_log<br />
1279525356|1279525345.6|NONE|Agent/1234|AGENTLOGIN|SIP/henryg-00000006<br />
1279525383|1279525371.7|queue-customer-service|NONE|ENTERQUEUE||henryg<br />
1279525383|1279525371.7|queue-customer-service|Agent/1234|CONNECT|0|1279525383.8|0<br />
1279525403|1279525371.7|queue-customer-service|Agent/1234|COMPLETECALLER|0|20|1<br />
1279525406|1279525345.6|NONE|Agent/1234|AGENTLOGOFF|SIP/henryg-00000006|50<br />
1279692470|NONE|NONE|NONE|QUEUESTART|</p>

	<p>[root@ID41-ND015 log]# cat messages |grep dahdi</p>

	<p>Aug 30 20:51:29 <span class="caps">ID41</span>-ND015 kernel: dahdi: Telephony Interface Registered on major 196<br />
Aug 30 20:51:29 <span class="caps">ID41</span>-ND015 kernel: dahdi: Version: 2.3.0.1<br />
Aug 30 20:51:32 <span class="caps">ID41</span>-ND015 kernel: dahdi: Registered tone zone 0 (United States / North America)<br />
Aug 30 20:56:37 <span class="caps">ID41</span>-ND015 kernel: dahdi: Telephony Interface Unloaded<br />
Aug 30 20:56:37 <span class="caps">ID41</span>-ND015 kernel: dahdi: Telephony Interface Registered on major 196<br />
Aug 30 20:56:37 <span class="caps">ID41</span>-ND015 kernel: dahdi: Version: 2.3.0.1<br />
Aug 30 20:57:17 <span class="caps">ID41</span>-ND015 kernel: dahdi: Telephony Interface Unloaded<br />
Aug 30 20:57:17 <span class="caps">ID41</span>-ND015 kernel: dahdi: Telephony Interface Registered on major 196<br />
Aug 30 20:57:17 <span class="caps">ID41</span>-ND015 kernel: dahdi: Version: 2.3.0.1<br />
Aug 30 20:57:19 <span class="caps">ID41</span>-ND015 kernel: dahdi_echocan_mg2: Registered echo canceler &#8216;MG2&#8217;<br />
Aug 30 20:57:19 <span class="caps">ID41</span>-ND015 kernel: dahdi: Registered tone zone 0 (United States / North America)</p>

	<p>Sampai disini selesai, dokumentasi selanjutnya pembuatan <a href="http://www.asteriskguru.com/tutorials/dialplan_applications.html">Dialplan</a> dan testing ke Telkom <span class="caps">ISDN PRA</span> yang sampai artikel ini ditulis pihak Telkom belum selesai mengerjakannya.</p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/09/02/installation-digium-te121bf-asterisk-dahdi-libpri-xendomu/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Install DNS,DHCP,Webserver,Proxy,FTP,DDOS protection,IDS</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/08/27/installing-dns-dhcp-webserver-proxy-ftp-hids-ddosprotection/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/08/27/installing-dns-dhcp-webserver-proxy-ftp-hids-ddosprotection/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 04:03:47 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Squid]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[webserver]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1419</guid>
		<description><![CDATA[	Kelebihan Linux adalah dapat menempatkan beberapa services runing bersamaan dalam satu server. Tujuan membuat satu server linux berisi DNS, DHCP, Webserver, Proxy, FTP, IDS, DDOS protection, MRTG, Webmin adalah :
- Centos 5.5 sebagai sistem operasi Linux yang free dan mudah diinstall.
- DNS menggunakan BIND ISC untuk nameserver(primary DNS) domain perusahaan ini. Primary DNS disini menghandle [...]]]></description>
			<content:encoded><![CDATA[	<p>Kelebihan Linux adalah dapat menempatkan beberapa services runing bersamaan dalam satu server. Tujuan membuat satu server linux berisi <span class="caps">DNS</span>, DHCP, Webserver, Proxy, <span class="caps">FTP</span>, IDS, <span class="caps">DDOS</span> protection, <span class="caps">MRTG</span>, Webmin adalah :<br />
<p style="padding-left: 30px;">- Centos 5.5 sebagai sistem operasi Linux yang free dan mudah diinstall.</p><br />
<p style="padding-left: 30px;">- <span class="caps">DNS</span> menggunakan <span class="caps">BIND ISC</span> untuk nameserver(primary <span class="caps">DNS</span>) domain perusahaan ini. Primary <span class="caps">DNS</span> disini menghandle NS,MX,Web perusahaan. Untuk settingan MX di pointing ke server mail server perusahaan ini beda mesin menggunakan Zimbra.</p><br />
<p style="padding-left: 30px;">- <span class="caps">DHCP</span> menggunakan <span class="caps">DHCP</span> dari <span class="caps">ISC</span> berfungsi untuk pemberian intenet address ototmatis ke seluruh komputer karyawan di perusahaan ini yang sudah tersambung dalam jaringan local area network(LAN)</p><br />
<p style="padding-left: 30px;">- Webserver mengunakan Apache, berfungsi sebagai tempat file-file website domain perusahaan yang dapat diakses menggunakan www atau http, Apache juga dapat diset untuk meng host domain-domain lain yang dimiliki perusahaan ini.</p><br />
<p style="padding-left: 30px;">- Proxy menggunakan <span class="caps">SQUID</span> sebagai cache proxy gateway akses browsing semua komputer karyawan. Untuk access filtering digunakan <span class="caps">SQUIDGUARD</span> dan Shalla&#8217;s Blacklists</p><br />
<p style="padding-left: 30px;">- <span class="caps">IDS</span> sebagai security intrusion detection dalam hal ini menggunakan The Advanced Intrusion Detection Environment (AIDE)</p><br />
<p style="padding-left: 30px;">- <span class="caps">DDOS</span> protection untuk menghadapin serangan baik dari incoming dan outgoing. Untuk ini digunakan <acronym title="Advanced Policy-based Firewall">APF</acronym>, <acronym title="Brute Force Detection">BFD</acronym>, mod_dosevasive, dan mod_security.</p><br />
<p style="padding-left: 30px;">- <span class="caps">FTP</span> menggunakan <span class="caps">VSFTP</span> yang berfungsi sebagai file transfer ke webserver prusahaan jika untuk mengupdate website perusahaan.</p><br />
<p style="padding-left: 30px;">- <span class="caps">MRTG</span> menggunakan mrtg untuk visual monitoring bandiwdth management baik pada server ini, server lain,dan router. Data dari mrtg bisa di capture dan diberikan ke <span class="caps">ISP</span> jika didapat kapasitas Bandwidth yang disewa jauh dibawah rata-rata.</p><br />
Cukup bicara teori, sekarang dilanjutkan ke instalasi dan konfigurasi, yang dalam artikel ini sistem operasi Linux Centos 5.5 sudah diinstall minimalis.</p>

	<p>[root@ns1 gtoms]# uname -a<br />
Linux ns1.xyz.co.id 2.6.18-194.11.1.el5 #1 <span class="caps">SMP </span>Tue Aug 10 19:09:06 <span class="caps">EDT 2010</span> i686 i686 i386 <span class="caps">GNU</span>/Linux</p>

	<p>[root@ns1 gtoms]# cat /etc/redhat-release<br />
CentOS release 5.5 (Final)<br />
<span id="more-1419"></span></p>

	<p>[root@ns1 gtoms]# /sbin/ifconfig<br />
eth0 Link encap:Ethernet HWaddr 00:50:BA:C3:71:D2<br />
inet addr:202.137.2x.2xx Bcast:202.137.20.223 Mask:255.255.255.240<br />
inet6 addr: fe80::250:baff:fec3:71d2/64 Scope:Link<br />
<span class="caps">UP BROADCAST RUNNING MULTICAST MTU</span>:1500 Metric:1<br />
RX packets:1028 errors:0 dropped:0 overruns:0 frame:0<br />
TX packets:757 errors:0 dropped:0 overruns:0 carrier:0<br />
collisions:0 txqueuelen:1000<br />
RX bytes:93229 (91.0 KiB) TX bytes:143908 (140.5 KiB)<br />
Interrupt:209 Base address:0&#215;2000</p>

	<p>eth1 Link encap:Ethernet HWaddr 00:13:D4:01:65:1F<br />
inet addr:192.168.0.2 Bcast:192.168.0.255 Mask:255.255.255.0<br />
<span class="caps">UP BROADCAST MULTICAST MTU</span>:1500 Metric:1<br />
RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br />
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0<br />
collisions:0 txqueuelen:1000<br />
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)</p>

	<p>lo Link encap:Local Loopback<br />
inet addr:127.0.0.1 Mask:255.0.0.0<br />
inet6 addr: ::1/128 Scope:Host<br />
<span class="caps">UP LOOPBACK RUNNING MTU</span>:16436 Metric:1<br />
RX packets:1124 errors:0 dropped:0 overruns:0 frame:0<br />
TX packets:1124 errors:0 dropped:0 overruns:0 carrier:0<br />
collisions:0 txqueuelen:0<br />
RX bytes:1981916 (1.8 MiB) TX bytes:1981916 (1.8 MiB)<br />
<strong><br />
Instalasi Domain Name Server&#160; sebagai Primary Nameserver</strong></p>

	<p>[root@ns1 selinux]# yum install bind-chroot<br />
Loaded plugins: fastestmirror<br />
Loading mirror speeds from cached hostfile<br />
addons: centos.idrepo.or.id<br />
base: centos.idrepo.or.id<br />
extras: centos.idrepo.or.id<br />
updates: centos.idrepo.or.id<br />
Setting up Install Process<br />
Package 30:bind-chroot-9.3.6-4.P1.el5_4.2.i386 already installed and latest version<br />
Nothing to do<br />
[root@ns1 gtoms]#</p>

	<p>[root@ns1 gtoms]# chmod 755 /var/named/<br />
[root@ns1 gtoms]# chmod 775 /var/named/chroot/<br />
[root@ns1 gtoms]# chmod 775 /var/named/chroot/var/<br />
[root@ns1 gtoms]# chmod 775 /var/named/chroot/var/named/<br />
[root@ns1 gtoms]# chmod 775 /var/named/chroot/var/run/<br />
[root@ns1 gtoms]# chmod 777 /var/named/chroot/var/run/named/<br />
[root@ns1 gtoms]# cd /var/named/chroot/var/named/<br />
[root@ns1 named]# ln -s ../../ chroot<br />
[root@ns1 named] cp /usr/share/doc/bind-9.3.6/sample/var/named/named.local /var/named/chroot/var/named/named.local<br />
[root@ns1 named] cp /usr/share/doc/bind-9.3.6/sample/var/named/named.root /var/named/chroot/var/named/named.root<br />
[root@ns1 named] touch /var/named/chroot/etc/named.conf.local</p>

	<p>[root@ns1 named]# nano /var/named/chroot/etc/named.conf<br />
key &#8220;rndckey&#8221; {<br />
algorithm hmac-md5;<br />
secret &#8220;PatIBVa6D1zrSKnEOBsO4siZyJO0cytbujld1boBT7W8RrVee5dsCkGSID79&#8221;;<br />
};</p>

	<p>options {<br />
listen-on port 53 { 127.0.0.1; 192.168.0.2; 202.137.2x.2xx; };<br />
listen-on-v6 port 53 { ::1; };<br />
directory &#8220;/var/named/chroot/var/named&#8221;;<br />
dump-file &#8220;/var/named/chroot/var/named/data/cache_dump.db&#8221;;<br />
statistics-file &#8220;/var/named/chroot/var/named/data/named_stats.txt&#8221;;<br />
memstatistics-file &#8220;/var/named/chroot/var/named/data/named_mem_stats.txt&#8221;;<br />
allow-query { localhost; };<br />
recursion yes;<br />
};<br />
logging {<br />
channel default_debug {<br />
file &#8220;data/named.run&#8221;;<br />
severity dynamic;<br />
};<br />
};</p>

	<p>zone &#8220;.&#8221; <span class="caps">IN </span>{<br />
type hint;<br />
file &#8220;named.root&#8221;;<br />
};</p>

	<p>zone &#8220;xyz.co.id&#8221; <span class="caps">IN </span>{<br />
type master;<br />
file &#8220;data/xyz.co.id.zone&#8221;;<br />
allow-update { none; };<br />
};</p>

	<p>[root@ns1 named]# nano /var/named/chroot/var/named/data/xyz.co.id</p>

	<p>$ORIGIN .<br />
$TTL 86400 ; 1 day</p>

	<p>xyz.co.id <span class="caps">IN SOA</span> ns1.xyz.co.id. admin.xyz.co.id. (<br />
2010082100<br />
7200<br />
7200<br />
1209600<br />
86400 )<br />
NS ns1.xyz.co.id.<br />
NS ns2.xyz.co.id.<br />
<span class="caps">A 202</span>.137.2x.2xx<br />
<span class="caps">MX 10</span> mail.xyz.co.id.</p>

	<p>$ORIGIN xyz.co.id.</p>

	<p>webmail <span class="caps">A 202</span>.137.2x.2zz<br />
ns1 <span class="caps">A 202</span>.137.2x.2xx<br />
ns2 <span class="caps">A 202</span>.137.2x.2yy<br />
mail <span class="caps">A 202</span>.137.2x.2zz<br />
www <span class="caps">A 202</span>.137.2x.2xx<br />
mail2 <span class="caps">A 202</span>.137.2x.2yy<br />
xyz.co.id. <span class="caps">IN TXT </span>&#8220;PT. xyz&#8221;<br />
<em><span class="caps">IP 202</span>.137.2x.2zz dengan mail.xyz.co.id merupakan server mailserver menggunakan Zimbra 6.0.6 berada beda mesin dengan server ini.</em></p>

	<p>[root@ns1 named]# /etc/init.d/named start<br />
Starting named: [ <span class="caps">OK </span>]</p>

	<p>[root@ns1 etc]# tail -f /var/log/messages<br />
Aug 21 11:31:35 ns1 named[3766]: starting <span class="caps">BIND 9</span>.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2 -u named -t /var/named/chroot<br />
Aug 21 11:31:35 ns1 named[3766]: adjusted limit on open files from 1024 to 1048576<br />
Aug 21 11:31:35 ns1 named[3766]: found 2 CPUs, using 2 worker threads<br />
Aug 21 11:31:35 ns1 named[3766]: using up to 4096 sockets<br />
Aug 21 11:31:35 ns1 named[3766]: loading configuration from &#8216;/etc/named.conf&#8217;<br />
Aug 21 11:31:35 ns1 named[3766]: using default <span class="caps">UDP</span>/IPv4 port range: [1024, 65535]<br />
Aug 21 11:31:35 ns1 named[3766]: using default <span class="caps">UDP</span>/IPv6 port range: [1024, 65535]<br />
Aug 21 11:31:35 ns1 named[3766]: listening on IPv6 interface lo, ::1#53<br />
Aug 21 11:31:35 ns1 named[3766]: listening on IPv4 interface lo, 127.0.0.1#53<br />
Aug 21 11:31:35 ns1 named[3766]: listening on IPv4 interface eth1, 192.168.0.2#53<br />
Aug 21 11:31:35 ns1 named[3766]: listening on IPv4 interface eth0, 202.137.2x.2xx#53<br />
Aug 21 11:31:35 ns1 named[3766]: command channel listening on 127.0.0.1#953<br />
Aug 21 11:31:35 ns1 named[3766]: command channel listening on ::1#953<br />
Aug 21 11:31:35 ns1 named[3766]: zone xyz.co.id/IN: loaded serial 2010082100<br />
Aug 21 11:31:35 ns1 named[3766]: running<br />
Aug 21 11:31:35 ns1 named[3766]: zone xyz.co.id/IN: sending notifies (serial 2010082100)<br />
<strong> </strong></p>

	<p><strong>Instalasi <span class="caps">DHCP </span>Server</strong></p>

	<p>[root@ns1 data]# yum install dhcp<br />
Loaded plugins: fastestmirror<br />
Loading mirror speeds from cached hostfile<br />
addons: centos.idrepo.or.id<br />
base: centos.idrepo.or.id<br />
extras: centos.idrepo.or.id<br />
updates: centos.idrepo.or.id<br />
Setting up Install Process<br />
Resolving Dependencies&#8212;> Running transaction check&#8212;-> Package dhcp.i386 12:3.0.5-23.el5_5.1 set to be updated&#8212;> Finished Dependency Resolution<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;cut&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Total download size: 867 k<br />
Is this ok [y/N]: y<br />
Downloading Packages:<br />
dhcp-3.0.5-23.el5_5.1.i386.rpm | 867 kB 00:00<br />
Running rpm_check_debug<br />
Running Transaction Test<br />
Finished Transaction Test<br />
Transaction Test Succeeded<br />
Running Transaction<br />
Installing : dhcp 1/1</p>

	<p>Installed:<br />
dhcp.i386 12:3.0.5-23.el5_5.1</p>

	<p>Complete!<br />
[root@ns1 data]#</p>

	<p>[root@ns1 data]# nano /etc/dhcpd.conf</p>

	<p>authoritative;<br />
ddns-update-style interim;<br />
ignore client-updates;</p>

	<p>subnet 192.168.0.0 netmask 255.255.255.0 {<br />
option routers 192.168.0.2;<br />
option subnet-mask 255.255.255.0;<br />
option domain-name &#8220;xyz.co.id&#8221;;<br />
option domain-name-servers 192.168.0.2,202.137.2x.2xx;<br />
range dynamic-bootp 192.168.0.9 192.168.0.254;<br />
default-lease-time 43200;<br />
max-lease-time 604800;</p>

	<p>}</p>

	<p><em>Range IP untuk seluruh komputer karyawan 192.168.0.9 192.168.0.254</em></p>

	<p>[root@ns1 data]# /etc/init.d/dhcpd start<br />
Starting dhcpd: [ <span class="caps">OK </span>]</p>

	<p>[root@ns1 data]# tail -f /var/log/messages<br />
Aug 21 11:44:36 ns1 dhcpd: Internet Systems Consortium <span class="caps">DHCP </span>Server V3.0.5-RedHat<br />
Aug 21 11:44:36 ns1 dhcpd: Copyright 2004-2006 Internet Systems Consortium.<br />
Aug 21 11:44:36 ns1 dhcpd: All rights reserved.<br />
Aug 21 11:44:36 ns1 dhcpd: For info, please visit http://www.isc.org/sw/dhcp/<br />
Aug 21 11:44:36 ns1 dhcpd: Wrote 0 leases to leases file.<br />
Aug 21 11:44:36 ns1 dhcpd:<br />
Aug 21 11:44:36 ns1 dhcpd: No subnet declaration for eth0 (202.137.2x.2xx).<br />
Aug 21 11:44:36 ns1 dhcpd: ** Ignoring requests on eth0. If this is not what<br />
Aug 21 11:44:36 ns1 dhcpd: you want, please write a subnet declaration<br />
Aug 21 11:44:36 ns1 dhcpd: in your dhcpd.conf file for the network segment<br />
Aug 21 11:44:36 ns1 dhcpd: to which interface eth0 is attached. **<br />
Aug 21 11:44:36 ns1 dhcpd:<br />
Aug 21 11:44:36 ns1 dhcpd: Listening on <span class="caps">LPF</span>/eth1/00:13:d4:01:65:1f/192.168.0/24<br />
Aug 21 11:44:36 ns1 dhcpd: Sending on <span class="caps">LPF</span>/eth1/00:13:d4:01:65:1f/192.168.0/24<br />
Aug 21 11:44:36 ns1 dhcpd: Sending on Socket/fallback/fallback-net</p>

	<p>3766 ? Ssl 0:00 /usr/sbin/named -u named -t /var/named/chroot<br />
3928 ? Ss 0:00 /usr/sbin/dhcpd<br />
[root@ns1 gtoms]#</p>

	<p><strong><br />
Instalasi Webserver menggunakan Apache</strong></p>

	<p>[root@ns1 gtoms]# yum install httpd<code> </code>httpd-devel mysql-server php php-mysql php-mbstring php-mcrypt</p>

	<p>[root@ns1 gtoms]# nano /etc/httpd/conf/httpd.conf</p>

	<p>Listen 202.137.2x.2xx:80</p>

	<p>NameVirtualHost *:80</p>

	<p><VirtualHost *:80><br />
ServerAdmin webmaster@xyz.co.id<br />
DocumentRoot /home/webxyz<br />
ServerName xyz.co.id<br />
ServerAlias www.xyz.co.id<br />
</VirtualHost></p>

	<p><VirtualHost *:80><br />
ServerAdmin webmaster@xyz.co.id<br />
DocumentRoot /var/www/html/stat<br />
ServerName xyz.co.id/stat<br />
ServerAlias www.xyz.co.id/stat<br />
</VirtualHost></p>

	<p><Directory "/home/webxyz"><br />
Options Indexes FollowSymLinks MultiViews<br />
AllowOverride All<br />
Order allow,deny<br />
Allow from all<br />
</Directory></p>

	<p><strong>Instalasi <span class="caps">SQUID</span> sebagai cache proxy server </strong></p>

	<p>[root@ns1 gtoms]# yum install squid<br />
[root@ns1 gtoms]# cd /etc/squid</p>

	<p>[root@ns1 squid] nano squid.conf</p>

	<p>[root@ns1 squid]# /usr/sbin/squid -z</p>

	<p>Banyak konfigurasi di file squid.conf tinggal disesuaikan sesuai kebutuhan salah satunya squid si setting transparant proxy, dan jika ingin menggunakan Squidguard jangan lupa menambahkan url_rewrite_program /usr/bin/squidguard -c /etc/squid/squidguard.conf jika sudah menginstall squidguard.</p>

	<p><strong>Instalasi <span class="caps">SQUIDGUARD</span> sebagai content filtering.</strong></p>

	<p>[root@ns1 gtoms]# wget http://www.excaliburtech.net/wp-content/uploads/2009/02/squidguard-1.4-3.i386.rpm&#8212;2010-08-21 18:49:02&#8212;http://www.excaliburtech.net/wp-content/uploads/2009/02/squidguard-1.4-3.i386.rpm<br />
Resolving www.excaliburtech.net&#8230; 72.66.114.15<br />
Connecting to www.excaliburtech.net|72.66.114.15|:80&#8230; connected.<br />
<span class="caps">HTTP</span> request sent, awaiting response&#8230; 200 OK<br />
Length: 119416 (117K) [application/x-rpm]<br />
Saving to: `squidguard-1.4-3.i386.rpm&#8217;<br />
2010-08-21 18:49:05 (54.0 KB/s) &#8211; `squidguard-1.4-3.i386.rpm&#8217; saved [119416/119416]</p>

	<p>[root@ns1 gtoms]# rpm <del>ivh squidguard</del>1.4-3.i386.rpm<br />
Preparing&#8230; ########################################### [100%]<br />
1:squidguard ########################################### [100%]</p>

	<p>[root@ns1 gtoms]# locate squidguard<br />
/etc/logrotate.d/squidguard<br />
/etc/squid/squidguard.conf<br />
/home/gtoms/squidguard-1.4-3.i386.rpm<br />
/usr/bin/squidguard<br />
/usr/libexec/webmin/blue-theme/squidguard<br />
/usr/libexec/webmin/blue-theme/squidguard/images<br />
/usr/libexec/webmin/blue-theme/squidguard/images/icon.gif<br />
/usr/share/doc/squidguard-1.4<br />
/usr/share/doc/squidguard-1.4/LDAPFlow.txt<br />
/usr/share/doc/squidguard-1.4/authentication.html<br />
/usr/share/doc/squidguard-1.4/authentication.txt<br />
/usr/share/doc/squidguard-1.4/configuration.html<br />
/usr/share/doc/squidguard-1.4/configuration.txt<br />
/usr/share/doc/squidguard-1.4/configure.html<br />
/usr/share/doc/squidguard-1.4/configure.txt<br />
/usr/share/doc/squidguard-1.4/expressionlist.html<br />
/usr/share/doc/squidguard-1.4/expressionlist.txt<br />
/usr/share/doc/squidguard-1.4/extended.html<br />
/usr/share/doc/squidguard-1.4/extended.txt<br />
/usr/share/doc/squidguard-1.4/faq.html<br />
/usr/share/doc/squidguard-1.4/faq.txt<br />
/usr/share/doc/squidguard-1.4/features.html<br />
/usr/share/doc/squidguard-1.4/features.txt<br />
/usr/share/doc/squidguard-1.4/index.html<br />
/usr/share/doc/squidguard-1.4/install.html<br />
/usr/share/doc/squidguard-1.4/install.txt<br />
/usr/share/doc/squidguard-1.4/installation.html<br />
/usr/share/doc/squidguard-1.4/installation.txt<br />
/usr/share/doc/squidguard-1.4/ldap-ad-tips.html<br />
/usr/share/doc/squidguard-1.4/ldap-ad-tips.txt<br />
/usr/share/doc/squidguard-1.4/ldap.html<br />
/usr/share/doc/squidguard-1.4/ldap.txt<br />
/usr/share/doc/squidguard-1.4/runtimeops.html<br />
/usr/share/doc/squidguard-1.4/runtimeops.txt<br />
/usr/share/doc/squidguard-1.4/sample.conf<br />
/usr/share/doc/squidguard-1.4/squidguard-simple.cgi<br />
/usr/share/doc/squidguard-1.4/squidguard.cgi<br />
/usr/share/doc/squidguard-1.4/squidguard.gif<br />
/usr/share/doc/squidguard-1.4/troubleshoot.html<br />
/usr/share/doc/squidguard-1.4/troubleshoot.txt</p>

	<p><strong>Sebelum mengkonfigurasi squidguard.conf&#160; install dahulu Shalla&#8217;s Blacklists</strong></p>

	<p>[root@ns1 gtoms]# wget http://www.shallalist.de/Downloads/shallalist.tar.gz&#8212;2010-08-21 19:02:00&#8212;http://www.shallalist.de/Downloads/shallalist.tar.gz<br />
Resolving www.shallalist.de&#8230; 78.47.242.85<br />
Connecting to www.shallalist.de|78.47.242.85|:80&#8230; connected.<br />
<span class="caps">HTTP</span> request sent, awaiting response&#8230; 200 OK<br />
Length: 9670277 (9.2M) [application/x-tar]<br />
Saving to: `shallalist.tar.gz&#8217;</p>

	<p>11% [============> ] 1,126,182 119K/s eta 80s</p>

	<p>[root@ns1 gtoms]# mkdir /var/lib/squidguard/db</p>

	<p>[root@ns1 gtoms]# mv shallalist.tar.gz /var/lib/squidguard/db</p>

	<p>[root@ns1 gtoms]# cd /var/lib/squidguard/db</p>

	<p>[root@ns1 db]# gzip -d shallalist.tar.gz</p>

	<p>[root@ns1 db]# tar xfv shallalist.tar<br />
BL/<br />
BL/porn/<br />
BL/porn/domains<br />
BL/porn/urls<br />
BL/gamble/<br />
BL/gamble/domains<br />
BL/gamble/urls<br />
BL/chat/<br />
BL/chat/domains<br />
BL/chat/urls<br />
BL/automobile/<br />
BL/automobile/cars/<br />
BL/automobile/cars/domains<br />
BL/automobile/cars/urls<br />
BL/automobile/bikes/<br />
BL/automobile/bikes/domains<br />
BL/automobile/bikes/urls<br />
BL/automobile/boats/<br />
BL/automobile/boats/domains<br />
BL/automobile/boats/urls<br />
BL/automobile/planes/<br />
BL/automobile/planes/urls<br />
BL/automobile/planes/domains<br />
BL/recreation/<br />
BL/recreation/humor/<br />
BL/recreation/humor/domains<br />
BL/recreation/humor/urls<br />
BL/recreation/martialarts/<br />
BL/recreation/martialarts/urls<br />
BL/recreation/martialarts/domains<br />
BL/recreation/sports/<br />
BL/recreation/sports/domains<br />
BL/recreation/sports/urls<br />
BL/recreation/travel/<br />
BL/recreation/travel/urls<br />
BL/recreation/travel/domains<br />
BL/recreation/wellness/<br />
BL/recreation/wellness/domains<br />
BL/recreation/wellness/urls<br />
BL/recreation/restaurants/<br />
BL/recreation/restaurants/urls<br />
BL/recreation/restaurants/domains<br />
BL/webradio/<br />
BL/webradio/domains<br />
BL/webradio/urls<br />
BL/webmail/<br />
BL/webmail/domains<br />
BL/webmail/urls<br />
BL/warez/<br />
BL/warez/urls<br />
BL/warez/domains<br />
BL/shopping/<br />
BL/shopping/domains<br />
BL/shopping/urls<br />
BL/adv/<br />
BL/adv/domains<br />
BL/adv/urls<br />
BL/movies/<br />
BL/movies/urls<br />
BL/movies/domains<br />
BL/science/<br />
BL/science/chemistry/<br />
BL/science/chemistry/urls<br />
BL/science/chemistry/domains<br />
BL/science/astronomy/<br />
BL/science/astronomy/domains<br />
BL/science/astronomy/urls<br />
BL/hobby/<br />
BL/hobby/pets/<br />
BL/hobby/pets/domains<br />
BL/hobby/pets/urls<br />
BL/hobby/cooking/<br />
BL/hobby/cooking/domains<br />
BL/hobby/cooking/urls<br />
BL/hobby/gardening/<br />
BL/hobby/gardening/urls<br />
BL/hobby/gardening/domains<br />
BL/hobby/games-online/<br />
BL/hobby/games-online/domains<br />
BL/hobby/games-online/urls<br />
BL/hobby/games-misc/<br />
BL/hobby/games-misc/domains<br />
BL/hobby/games-misc/urls<br />
BL/violence/<br />
BL/violence/domains<br />
BL/violence/urls<br />
BL/music/<br />
BL/music/domains<br />
BL/music/urls<br />
BL/hacking/<br />
BL/hacking/domains<br />
BL/hacking/urls<br />
BL/isp/<br />
BL/isp/urls<br />
BL/isp/domains<br />
BL/drugs/<br />
BL/drugs/domains<br />
BL/drugs/urls<br />
BL/aggressive/<br />
BL/aggressive/domains<br />
BL/aggressive/urls<br />
BL/news/<br />
BL/news/urls<br />
BL/news/domains<br />
BL/redirector/<br />
BL/redirector/urls<br />
BL/redirector/domains<br />
BL/spyware/<br />
BL/spyware/domains<br />
BL/spyware/urls<br />
BL/dating/<br />
BL/dating/urls<br />
BL/dating/domains<br />
BL/finance/<br />
BL/finance/banking/<br />
BL/finance/banking/urls<br />
BL/finance/banking/domains<br />
BL/finance/other/<br />
BL/finance/other/domains<br />
BL/finance/other/urls<br />
BL/finance/moneylending/<br />
BL/finance/moneylending/domains<br />
BL/finance/moneylending/urls<br />
BL/finance/insurance/<br />
BL/finance/insurance/urls<br />
BL/finance/insurance/domains<br />
BL/finance/realestate/<br />
BL/finance/realestate/domains<br />
BL/finance/realestate/urls<br />
BL/finance/trading/<br />
BL/finance/trading/domains<br />
BL/finance/trading/urls<br />
BL/dynamic/<br />
BL/dynamic/urls<br />
BL/dynamic/domains<br />
BL/COPYRIGHT<br />
BL/jobsearch/<br />
BL/jobsearch/urls<br />
BL/jobsearch/domains<br />
BL/tracker/<br />
BL/tracker/domains<br />
BL/tracker/urls<br />
BL/models/<br />
BL/models/domains<br />
BL/models/urls<br />
BL/forum/<br />
BL/forum/domains<br />
BL/forum/urls<br />
BL/webtv/<br />
BL/webtv/urls<br />
BL/webtv/domains<br />
BL/downloads/<br />
BL/downloads/urls<br />
BL/downloads/domains<br />
BL/ringtones/<br />
BL/ringtones/domains<br />
BL/ringtones/urls<br />
BL/searchengines/<br />
BL/searchengines/domains<br />
BL/searchengines/urls<br />
BL/socialnet/<br />
BL/socialnet/urls<br />
BL/socialnet/domains<br />
BL/updatesites/<br />
BL/updatesites/domains<br />
BL/updatesites/urls<br />
BL/weapons/<br />
BL/weapons/domains<br />
BL/weapons/urls<br />
BL/webphone/<br />
BL/webphone/domains<br />
BL/webphone/urls<br />
BL/global_usage<br />
BL/religion/<br />
BL/religion/domains<br />
BL/religion/urls<br />
BL/sex/<br />
BL/sex/lingerie/<br />
BL/sex/lingerie/urls<br />
BL/sex/lingerie/domains<br />
BL/sex/education/<br />
BL/sex/education/urls<br />
BL/sex/education/domains<br />
BL/imagehosting/<br />
BL/imagehosting/domains<br />
BL/imagehosting/urls<br />
BL/podcasts/<br />
BL/podcasts/domains<br />
BL/podcasts/urls<br />
BL/hospitals/<br />
BL/hospitals/domains<br />
BL/hospitals/urls<br />
BL/military/<br />
BL/military/urls<br />
BL/military/domains<br />
BL/politics/<br />
BL/politics/domains<br />
BL/politics/urls<br />
BL/remotecontrol/<br />
BL/remotecontrol/urls<br />
BL/remotecontrol/domains<br />
BL/fortunetelling/<br />
BL/fortunetelling/domains<br />
BL/fortunetelling/urls<br />
BL/library/<br />
BL/library/domains<br />
BL/library/urls<br />
BL/costtraps/<br />
BL/costtraps/urls<br />
BL/costtraps/domains<br />
BL/homestyle/<br />
BL/homestyle/domains<br />
BL/homestyle/urls<br />
BL/education/<br />
BL/education/schools/<br />
BL/education/schools/domains<br />
BL/education/schools/urls<br />
BL/government/<br />
BL/government/domains<br />
BL/government/urls<br />
BL/alcohol/<br />
BL/alcohol/domains<br />
BL/alcohol/urls<br />
BL/radiotv/<br />
BL/radiotv/domains<br />
BL/radiotv/urls<br />
[root@ns1 db]#</p>

	<p>[root@ns1 db]# cd BL</p>

	<p>[root@ns1 BL] cp -R * /var/lib/squidguard/db</p>

	<p>[root@ns1 BL]# nano /etc/squid/squidguard.conf<br />
<blockquote>dbhome /var/lib/squidguard/db<br />
logdir /var/log/squid</blockquote><br />
<blockquote>dest whitelist {<br />
domainlist whitelist/domains<br />
urllist whitelist/urls<br />
}</p>

	<p>dest adv {<br />
domainlist adv/domains<br />
urllist adv/urls<br />
}</p>

	<p>acl {<br />
default {</p>

	<p>pass whitelist&#160;&#160;&#160; !adv</p>

	<p>redirect http://www.xyz.co.id/redirect.html<br />
}</p>
	<p>}</blockquote><br />
[root@ns1 BL]# /usr/bin/squidguard -C all</p>

	<p>[root@ns1 db]# chmod -R 777 *</p>

	<p>[root@ns1 db]# chown -R squid:squid /var/lib/squidguard/db/*</p>

	<p>[root@ns1 squid]# nano /etc/squid/squid.conf</p>

	<p>url_rewrite_program /usr/bin/squidguard -c /etc/squid/squidguard.conf<br />
url_rewrite_children 8</p>

	<p>[root@ns1 squid]# /usr/sbin/squid -k reconfigure</p>

	<p>[root@ns1 db]# tail -f /var/log/squid/cache.log</p>

	<p>2010/08/22 08:52:43| Reconfiguring Squid Cache (version 2.6.STABLE21)...<br />
2010/08/22 08:52:43| <span class="caps">FD 10 </span>Closing <span class="caps">HTTP</span> connection<br />
2010/08/22 08:52:43| <span class="caps">FD 12 </span>Closing <span class="caps">ICP</span> connection<br />
2010/08/22 08:52:43| Initialising <span class="caps">SSL</span>.<br />
2010/08/22 08:52:43| User-Agent logging is disabled.<br />
2010/08/22 08:52:43| Referer logging is disabled.<br />
2010/08/22 08:52:43| <span class="caps">DNS </span>Socket created at 0.0.0.0, port 52827, <span class="caps">FD 9</span><br />
2010/08/22 08:52:43| Adding nameserver 202.137.2x.2xx from squid.conf<br />
2010/08/22 08:52:43| helperOpenServers: Starting 8 &#8216;squidguard&#8217; processes<br />
2010/08/22 08:52:43| Accepting transparently proxied <span class="caps">HTTP</span> connections at 0.0.0.0, port 3128, <span class="caps">FD 19</span>.<br />
2010/08/22 08:52:43| Accepting <span class="caps">ICP</span> messages at 0.0.0.0, port 3130, <span class="caps">FD 20</span>.<br />
2010/08/22 08:52:43| <span class="caps">WCCP </span>Disabled.<br />
2010/08/22 08:52:43| Loaded Icons.<br />
2010/08/22 08:52:43| Ready to serve requests.</p>

	<p><strong>Instalasi <span class="caps">FTP </span>Server menggunakan <span class="caps">VSFTP</span></strong></p>

	<p>[root@ns1 gtoms]# yum install vsftpd</p>

	<p>Disini tinggal mengkonfigurasi user untuk akses ke webserver.</p>

	<p><strong>Instalasi <span class="caps">MRTG </span></strong></p>

	<p>[root@ns1 gtoms]# yum install mrtg net-snmp net-snmp-utils<br />
Loaded plugins: fastestmirror<br />
Loading mirror speeds from cached hostfile<br />
addons: centos.idrepo.or.id<br />
base: centos.idrepo.or.id<br />
epel: bali.idrepo.or.id<br />
extras: centos.idrepo.or.id<br />
updates: centos.idrepo.or.id<br />
addons | 951 <span class="caps">B 00</span>:00<br />
base | 2.1 kB 00:00<br />
epel | 3.4 kB 00:00<br />
extras | 2.1 kB 00:00<br />
updates | 1.9 kB 00:00<br />
Setting up Install Process<br />
Package 1:net-snmp-5.3.2.2-9.el5_5.1.i386 already installed and latest version&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;cut&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Installed:<br />
mrtg.i386 0:2.14.5-2 net-snmp-utils.i386 1:5.3.2.2-9.el5_5.1</p>

	<p>Complete!<br />
[root@ns1 gtoms]#</p>

	<p>[root@ns1 gtoms]# nano /etc/snmp/snmpd.conf</p>

	<p>com2sec local localhost public<br />
com2sec mynetwork 192.168.0.0/24 public<br />
group MyRWGroup v1 local<br />
group MyRWGroup v2c local<br />
group MyRWGroup usm local<br />
group MyROGroup v1 mynetwork<br />
group MyROGroup v2c mynetwork<br />
group MyROGroup usm mynetwork<br />
view all included .1 80<br />
access MyROGroup &#8220;&#8221; any noauth exact all none none<br />
access MyRWGroup &#8220;&#8221; any noauth exact all all none<br />
syslocation PT. xyz, Jakarta<br />
syscontact Root <IT@xyz.co.id></p>

	<p>[root@ns1 gtoms]# /etc/init.d/snmpd start<br />
Starting snmpd: [ <span class="caps">OK </span>]<br />
[root@ns1 gtoms]#</p>

	<p>[root@ns1 gtoms]# tail -f /var/log/messages<br />
Aug 21 21:13:50 ns1 yum: Installed: 1:net-snmp-utils-5.3.2.2-9.el5_5.1.i386<br />
Aug 21 21:13:53 ns1 yum: Installed: mrtg-2.14.5-2.i386<br />
Aug 21 21:22:54 ns1 snmpd[7612]: Creating directory: /var/net-snmp<br />
Aug 21 21:22:54 ns1 snmpd[7612]: <span class="caps">NET</span>-SNMP version 5.3.2.2</p>

	<p>[root@ns1 gtoms]# /usr/bin/snmpwalk <del>v 1 -c public localhost IP</del><span class="caps">MIB</span>::ipAdEntIfIndex<br />
IP-MIB::ipAdEntIfIndex.127.0.0.1 = <span class="caps">INTEGER</span>: 1<br />
IP-MIB::ipAdEntIfIndex.192.168.0.2 = <span class="caps">INTEGER</span>: 3<br />
IP-MIB::ipAdEntIfIndex.202.137.2x.2xx = <span class="caps">INTEGER</span>: 2<br />
[root@ns1 gtoms]#</p>

	<p>[root@ns1 gtoms]# /usr/bin/cfgmaker&#8212;global &#8216;WorkDir: /var/www/mrtg&#8217;&#8212;output /etc/mrtg/mrtg.cfg public@localhost</p>

	<p>[root@ns1 gtoms]# /usr/bin/indexmaker&#8212;output=/var/www/mrtg/index.html /etc/mrtg/mrtg.cfg</p>

	<p>[root@ns1 mrtg]# nano /etc/cron.d/mrtg</p>

	<p>*/5 * * * * root <span class="caps">LANG</span>=C LC_ALL=C /usr/bin/mrtg /etc/mrtg/mrtg.cfg&#8212;lock-file /var/lock/mrtg/mrtg_l&#8212;confcache-file /var/lib/mrtg/mrtg.ok</p>

	<p>[root@ns1 mrtg]# nano /etc/httpd/conf.d/mrtg.conf<br />
Alias /mrtg /var/www/mrtg</p>

	<p><Location /mrtg><br />
Order deny,allow<br />
Deny from all<br />
Allow from 127.0.0.1<br />
Allow from ::1<br />
</Location></p>

	<p>[root@ns1 mrtg]# /etc/init.d/httpd restart<br />
Stopping httpd: [ <span class="caps">OK </span>]<br />
Starting httpd: [ <span class="caps">OK </span>]</p>

	<p>Untuk mengkases melalui browser ke http://iphostname/mrtg/</p>

	<p><strong>Memonitor server/router lain kedalam <span class="caps">MRTG</span></strong></p>

	<p>Jika menggunakan device router/modem tinggal mengaktifkan snmp, jika server lain linux ingin di monitor tinggal menginstall snmp, contoh disini pada server lain dengan <span class="caps">IP 202</span>.137.2x.2zz :</p>

	<p>[root@mail gtoms]# yum install net-snmp net-snmp-utils<br />
Setting up Install Process<br />
Parsing package install arguments<br />
Resolving Dependencies&#8212;> Running transaction check&#8212;-> Package net-snmp.i386 1:5.3.2.2-9.el5_5.1 set to be updated&#8212;> Processing Dependency: libsensors.so.3 for package: net-snmp&#8212;> Processing Dependency: net-snmp-libs = 1:5.3.2.2-9.el5_5.1 for package: net-snmp&#8212;-> Package net-snmp-utils.i386 1:5.3.2.2-9.el5_5.1 set to be updated&#8212;> Running transaction check&#8212;-> Package net-snmp-libs.i386 1:5.3.2.2-9.el5_5.1 set to be updated&#8212;-> Package lm_sensors.i386 0:2.10.7-9.el5 set to be updated&#8212;> Finished Dependency Resolution<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-cutt&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Installed: net-snmp-utils.i386 1:5.3.2.2-9.el5_5.1<br />
Dependency Installed: lm_sensors.i386 0:2.10.7-9.el5 net-snmp.i386 1:5.3.2.2-9.el5_5.1<br />
Updated: net-snmp-libs.i386 1:5.3.2.2-9.el5_5.1<br />
Complete!<br />
[root@mail gtoms]#</p>

	<p>[root@mail gtoms]# nano /etc/snmp/snmpd.conf</p>

	<p>com2sec local localhost public<br />
com2sec mynetwork 192.168.0.0/24 public<br />
group MyRWGroup v1 local<br />
group MyRWGroup v2c local<br />
group MyRWGroup usm local<br />
group MyROGroup v1 mynetwork<br />
group MyROGroup v2c mynetwork<br />
group MyROGroup usm mynetwork<br />
view all included .1 80<br />
access MyROGroup &#8220;&#8221; any noauth exact all none none<br />
access MyRWGroup &#8220;&#8221; any noauth exact all all none<br />
syslocation Zimbra Mailserver <span class="caps">XYZ</span>, Jakarta<br />
syscontact Root <IT@xyz.co.id></p>

	<p>[root@mail gtoms]# /etc/init.d/snmpd start<br />
Starting snmpd: [ <span class="caps">OK </span>]<br />
[root@mail gtoms]#</p>

	<p>Kembali ke server <span class="caps">MRTG</span> nya</p>

	<p>[root@ns1 gtoms]# /usr/bin/cfgmaker&#8212;global &#8216;WorkDir: /var/www/mrtg&#8217;&#8212;output /etc/mrtg/mrtg.cfg public@202.137.2x.2zz</p>

	<p>[root@ns1 mrtg]# /usr/bin/cfgmaker&#8212;global &#8216;WorkDir: /var/www/mrtg&#8217;&#8212;output /etc/mrtg/mrtg.cfg public@192.168.0.1</p>

	<p><strong>Instalasi Webmin </strong></p>

	<p>[root@ns1 gtoms]# rpm <del>U webmin</del>1.510-1.noarch.rpm<br />
warning: webmin-1.510-1.noarch.rpm: Header <span class="caps">V3 DSA</span> signature: <span class="caps">NOKEY</span>, key ID 11f63c51<br />
Operating system is CentOS Linux<br />
Webmin install complete. You can now login to https://ns1.xyz.co.id:10000/<br />
as root with your root password.<br />
[root@ns1 gtoms]#</p>

	<p><strong>Instalasi <span class="caps">IDS</span> mengunakan The Advanced Intrusion Detection Environment (AIDE)</strong></p>

	<p>Untuk mengkonfigurasi <span class="caps">AIDE</span>, SELINUX harus enabled.</p>

	<p>[root@ns1 gtoms]# yum install aide</p>

	<p>[root@ns1 gtoms]# /usr/sbin/aide&#8212;init</p>

	<p>[root@ns1 gtoms]# cp /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz<br />
[root@ns1 gtoms]# /usr/sbin/aide&#8212;check</p>

	<p>[root@ns1 gtoms]# aide&#8212;check<br />
<span class="caps">AIDE</span>, version 0.13.1</p>
	<p>### All files match <span class="caps">AIDE</span> database. Looks okay!</p>

	<p>[root@ns1 gtoms]# vi /etc/cron.weekly/aide.cron</p>

	<p>#!/bin/bash<br />
/usr/sbin/aide&#8212;check | /bin/mail -s &#8220;Weekly Aide Data&#8221; IT@zyx.co.id</p>

	<p><strong>Instalasi <span class="caps">DDOS</span> protection</strong></p>

	<p><strong><span class="caps">APF </span>&#8212;Advanced Policy-based Firewall</strong></p>

	<p>[root@ns1 gtoms]# wget http://rfxnetworks.com/downloads/apf-current.tar.gz<br />
[root@ns1 gtoms]# tar xfz apf-current.tar.gz<br />
[root@ns1 apf-current]# cd apf-*<br />
[root@ns1 apf-current]# ./install.sh</p>

	<p>[root@ns1 apf-current]# vi /etc/apf/conf.apf<br />
<span class="caps">DEVEL</span>_MODE=&#8221;0&#8221;<br />
IG_TCP_CPORTS=&#8221;21,22,25,53,80,110,143,443,3306&#8221;<br />
IG_UDP_CPORTS=&#8221;53,111&#8221;<br />
<span class="caps">USE</span>_AD=&#8221;1&#8221;</p>

	<p>[root@ns1 apf-current]# vi /etc/apf/ad/conf.antidos<br />
sesuaikan sendiri &#8230;.</p>

	<p><strong><span class="caps">BFD </span>&#8212;Brute Force Detection </strong><br />
[root@ns1 gtoms]# wget http://rfxnetworks.com/downloads/bfd-current.tar.gz<br />
[root@ns1 gtoms]# tar xfz bfd-current.tar.gz<br />
[root@ns1 bfd-current]# cd bfd-*<br />
[root@ns1 bfd-current]# ./install.sh</p>

	<p>[root@ns1 bfd-current]# vi /usr/local/bfd/conf.bfd</p>

	<p><span class="caps">ALERT</span>=&#8221;1&#8221;<br />
<span class="caps">EMAIL</span>_USR=&#8221;IT@xyz.co.id&#8221;</p>

	<p>[root@ns1 bfd-current]# vi /usr/local/bfd/ignore.hosts<br />
sesuaikan sendiri &#8230;.</p>

	<p><strong>DDoS Deflate </strong><br />
[root@ns1 gtoms]# wget http://www.inetbase.com/scripts/ddos/install.sh<br />
[root@ns1 gtoms]# sh install.sh</p>

	<p>[root@ns1 gtoms]#vi&#160; /usr/local/ddos/ddos.conf<br />
sesuaikan sendiri &#8230;.</p>

	<p>[root@ns1 gtoms]# /usr/local/ddos/ddos.sh -c</p>

	<p><strong>RootKit&#8212;Spyware and Junkware detection and removal tool </strong></p>

	<p>[root@ns1 gtoms]# wget http://sourceforge.net/projects/rkhunter/files/rkhunter/1.3.6/rkhunter-1.3.6.tar.gz/download<br />
[root@ns1 gtoms]# tar xfz&#160; rkhunter-1.3.6.tar.gz<br />
[root@ns1 gtoms]# cd rkhunter-1.3.6<br />
[root@ns1 rkhunter-1.3.6]# ./installer.sh<br />
[root@ns1 rkhunter-1.3.6]# run rkhunter<br />
[root@ns1 rkhunter-1.3.6]# rkhunter -c</p>

	<p><strong>Install Mod_dosevasive untuk Apache</strong></p>

	<p>[root@ns1 gtoms]# wget http://www.zdziarski.com/projects/mod_evasive/mod_evasive_1.10.1.tar.gz</p>

	<p>[root@ns1 gtoms]# tar -zxvf mod_evasive_1.10.1.tar.gz</p>

	<p>[root@ns1 gtoms]# cd mod_evasive_1.10.1</p>

	<p>[root@ns1 mod_evasive_1.10.1]# $APACHE_ROOT/bin/apxs -cia mod_evasive20.c</p>

	<p>[root@ns1 mod_evasive_1.10.1]# vi /usr/local/apache/conf/httpd.conf</p>

	<p><IfModule mod_evasive20.c><br />
DOSHashTableSize 3097<br />
<span class="caps">DOS</span>PageCount 2<br />
<span class="caps">DOS</span>SiteCount 50<br />
<span class="caps">DOS</span>PageInterval 1<br />
<span class="caps">DOS</span>SiteInterval 1<br />
<span class="caps">DOS</span>BlockingPeriod 300<br />
</IfModule></p>

	<p>[root@ns1 mod_evasive_1.10.1]# /usr/loca/apache/bin/apachectl restart</p>

	<p><strong>Install Mod_security</strong></p>

	<p>[root@ns1 gtoms]# http://www.modsecurity.org/download/modsecurity-apache-1.9.2.tar.gz</p>

	<p>[root@ns1 gtoms]# tar <del>zxvf modsecurity</del>apache-1.9.2.tar.gz</p>

	<p>[root@ns1 gtoms]# cd modsecurity-apache-1.9.2</p>

	<p>[root@ns1 modsecurity-apache-1.9.2]# /usr/local/apache/bin/apxs -cia mod_security.c</p>

	<p>Buat sebuah file dengan nama mod_security.conf didalam folder /usr/local/apache/conf</p>

	<p>[root@ns1 modsecurity-apache-1.9.2]# vi /usr/local/apache/conf/mod_security.conf</p>

	<p>Rules yang dapat kita buat bisa merujuk ke http://www.modsecurity.org/documentation/quick-examples.html</p>

	<p>Kita masukkan path&#160; mod_security.conf kedalam file httpd.conf</p>

	<p>[root@ns1 modsecurity-apache-1.9.2]# vi /usr/local/apache/conf/httpd.conf</p>

	<p>/usr/local/apache/conf/mod_security.conf</p>

	<p>[root@ns1 modsecurity-apache-1.9.2]# /usr/local/apache/bin/apachectl stop</p>

	<p>[root@ns1 modsecurity-apache-1.9.2]# /usr/local/apache/bin/apachectl start</p>

	<p>Selesai,Tinggal memonitor.</p>

	<p><em>henry@gultom.or.id</em></p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/08/27/installing-dns-dhcp-webserver-proxy-ftp-hids-ddosprotection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing Lotus Domino Server 8.5</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/08/15/installing-lotus-domino-server-8-5/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/08/15/installing-lotus-domino-server-8-5/#comments</comments>
		<pubDate>Sun, 15 Aug 2010 11:01:57 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[Lotus Domino Server]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[domino server]]></category>
		<category><![CDATA[ibm]]></category>
		<category><![CDATA[lotus]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1361</guid>
		<description><![CDATA[	  Untuk urusan messaging, collaboration,calendar, scheduling, dan applications, IBM masih mempunyai Lotus Domino. Produk mailservernya IBM ini masih bersaing ketat dengan Microsoft Exchange. Tapi bagi saya IBM Lotus Domino Server dan Microsoft Exchange Server sangat disukai oleh perusahaan yang memiliki bujet IT besar.

	Okay kali ini saya dokumentasikan instalasi Lotus Domino Server 8.5 pada platform [...]]]></description>
			<content:encoded><![CDATA[	<p><strong> </strong><strong><strong> </strong></strong>Untuk urusan messaging, collaboration,calendar, scheduling, dan applications, <a href="http://www.ibm.com"><span class="caps">IBM</span></a> masih mempunyai <a href="http://www-01.ibm.com/software/lotus/products/">Lotus Domino</a>. Produk mailservernya <span class="caps">IBM</span> ini masih bersaing ketat dengan Microsoft Exchange. Tapi bagi saya <span class="caps">IBM </span>Lotus Domino Server dan Microsoft Exchange Server sangat disukai oleh perusahaan yang memiliki bujet IT besar.</p>

	<p>Okay kali ini saya dokumentasikan instalasi Lotus Domino Server 8.5 pada platform Linux Centos 5.5(Final). Loh kok Linux ? Kata Project Managernya lebih murah daripada pakai platform Windows Server, jadi dalam implementasi ini tidak perlu membeli lisensi untuk sistem operasi servernya, dan tetap untuk Lotus Dominonya harus beli.</p>

	<p>Tahapannya :<br />
<p style="padding-left: 30px;">- Install sistem operasi Linux Centos 5.5(Final)</p><br />
<p style="padding-left: 30px;">- Setting dan install required Linux packages untuk Domino 8.5</p><br />
<p style="padding-left: 30px;">- Copy file setup dari Domino 8.5 CD yaitu Domino85Linux.tar ke server.</p><br />
<p style="padding-left: 30px;">- Instalasi Lotus Domino 8.5 Server ke Linux Centos 5.5</p><br />
Berikut proses instalasi yang sempat saya dokumentasikan.</p>

	<p><span id="more-1361"></span></p>

	<p><strong>Install sistem operasi Linux Centos 5.5(Final)</strong></p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/08/installcentos55.png"><img class="alignleft size-full wp-image-1362" title="installcentos55" src="http://henry.gultom.or.id/wp-content/uploads/2010/08/installcentos55.png" alt="" width="250" height="187" /></a>Disini instalasi Centos 5.5 sudah selesai.</p>

	<p>[root@mail gtoms]# uname -a<br />
Linux mail.xxxxxxx.com 2.6.18-194.el5 #1 <span class="caps">SMP </span>Fri Apr 2 14:58:35 <span class="caps">EDT 2010</span> i686 i686 i386 <span class="caps">GNU</span>/Linux</p>

	<p>[root@mail ~]# cat /etc/redhat-release<br />
CentOS release 5.5 (Final)</p>

	<p><strong>Setting dan install required Linux packages untuk Domino 8.5</strong></p>

	<p>[root@mail gtoms]# yum install glibc libgcc libstdc++ libXp</p>

	<p>Loaded plugins: fastestmirror</p>

	<p>Loading mirror speeds from cached hostfile</p>

	<p>addons: centos.idrepo.or.id</p>

	<p>base: centos.idrepo.or.id</p>

	<p>extras: centos.idrepo.or.id</p>

	<p>updates: centos.idrepo.or.id</p>

	<p>Setting up Install Process</p>

	<p>Package libgcc-4.1.2-48.el5.i386 already installed and latest version</p>

	<p>Package libstdc++-4.1.2-48.el5.i386 already installed and latest version</p>

	<p>Resolving Dependencies<br />
&#8212;> Running transaction check<br />
&#8212;> Processing Dependency: glibc = 2.5-49 for package: nscd<br />
&#8212;-> Package glibc.i686 0:2.5-49.el5_5.4 set to be updated<br />
&#8212;> Processing Dependency: glibc-common = 2.5-49.el5_5.4 for package: glibc<br />
&#8212;-> Package libXp.i386 0:1.0.0-8.1.el5 set to be updated<br />
&#8212;> Running transaction check<br />
&#8212;-> Package glibc-common.i386 0:2.5-49.el5_5.4 set to be updated<br />
&#8212;-> Package nscd.i386 0:2.5-49.el5_5.4 set to be updated<br />
&#8212;> Finished Dependency Resolution</p>

	<p>Dependencies Resolved<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Installed:</p>

	<p>libXp.i386 0:1.0.0-8.1.el5</p>

	<p>Updated:</p>

	<p>glibc.i686 0:2.5-49.el5_5.4</p>

	<p>Dependency Updated:</p>

	<p>glibc-common.i386 0:2.5-49.el5_5.4&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; nscd.i386 0:2.5-49.el5_5.4</p>

	<p>Complete!</p>

	<p>[root@mail gtoms]#</p>

	<p>[root@mail gtoms]# yum install compat-libstdc++-296 compat-libstdc++-33</p>

	<p>Loaded plugins: fastestmirror</p>

	<p>Loading mirror speeds from cached hostfile</p>

	<p>addons: centos.idrepo.or.id</p>

	<p>base: centos.idrepo.or.id</p>

	<p>extras: centos.idrepo.or.id</p>

	<p>updates: centos.idrepo.or.id</p>

	<p>Setting up Install Process</p>

	<p>Resolving Dependencies<br />
&#8212;> Running transaction check<br />
&#8212;-> Package compat-libstdc++-296.i386 0:2.96-138 set to be updated<br />
&#8212;-> Package compat-libstdc++-33.i386 0:3.2.3-61 set to be updated<br />
&#8212;> Finished Dependency Resolution</p>

	<p>Dependencies Resolved<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-skip&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Installed:</p>

	<p>compat-libstdc++-296.i386 0:2.96-138&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; compat-libstdc++-33.i386 0:3.2.3-61</p>

	<p>Complete!</p>

	<p>[root@mail gtoms]#</p>

	<p>[root@mail gtoms]# yum&#160; install glib libpng pango unixODBC<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Installed:</p>

	<p>glib.i386 1:1.2.10-20.el5&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; unixODBC.i386 0:2.2.11-7.1</p>

	<p>Updated:</p>

	<p>libpng.i386 2:1.2.10-7.1.el5_5.3&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; pango.i386 0:1.14.9-8.el5.centos</p>

	<p>Complete!</p>

	<p>[root@mail gtoms]#</p>

	<p><strong>Langkah berikut ini penting agar instalasi setup files Domino 8.5 lancar :</strong></p>

	<p>[root@mail gtoms]# chmod 1777 /tmp</p>

	<p>[root@mail gtoms]# ls -ald /tmp</p>

	<p>drwxrwxrwt 3 root root 4096 Aug 14 16:03 /tmp</p>

	<p>[root@mail gtoms]# cat /etc/fstab</p>

	<p>/dev/VolGroup00/LogVol00 /&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ext3&#160;&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 1 1</p>

	<p><span class="caps">LABEL</span>=/boot&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /boot&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ext3&#160;&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 1 2</p>

	<p>tmpfs&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /dev/shm&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; tmpfs&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 0 0</p>

	<p>devpts&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /dev/pts&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; devpts&#160; gid=5,mode=620&#160; 0 0</p>

	<p>sysfs&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /sys&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; sysfs&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 0 0</p>

	<p>proc&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /proc&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; proc&#160;&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 0 0</p>

	<p>/dev/VolGroup00/LogVol01 swap&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; swap&#160;&#160;&#160; defaults&#160;&#160;&#160;&#160;&#160;&#160;&#160; 0 0</p>

	<p><strong>pastikan&#160; /etc/fstab tidak ada noexec dan nosuid options untuk /tmp.</strong></p>

	<p>[root@mail gtoms]# /usr/sbin/adduser notes</p>

	<p>[root@mail gtoms]# passwd notes</p>

	<p>Changing password for user notes.</p>

	<p>New <span class="caps">UNIX</span> password:</p>

	<p>Retype new <span class="caps">UNIX</span> password:</p>

	<p>passwd: all authentication tokens updated successfully.</p>

	<p>[root@mail gtoms]#</p>

	<p>[root@mail gtoms]# mkdir /local</p>

	<p>[root@mail gtoms]# mkdir /local/notesdata</p>

	<p>[root@mail gtoms]# chown notes: /local/notesdata</p>

	<p>Disini nanti kita perlu tiga ID files untuk&#160; Domino server: Organization certifier,Administrator ID, Server ID without a password. Hal ini bisa di set menggunakan Domino Administrator client.</p>

	<p><strong>Instalasi Lotus Domino 8.5 Server</strong></p>

	<p>Mount <span class="caps">CDROM</span> berisi Domino 8.5 CD dan copy file Domino85Linux.tar ke folder /opt</p>

	<p>Letak file instalasi di folder /opt</p>

	<p>[root@mail gtoms]# cd /opt</p>

	<p>[root@mail opt]#</p>

	<p>[root@mail opt]# ls</p>

	<p>Domino85Linux.tar</p>

	<p>[root@mail opt]# tar xvf&#160; Domino85Linux.tar</p>

	<p>linux/domino/</p>

	<p>linux/domino/tools/</p>

	<p>linux/domino/tools/checkminimumos.pl</p>

	<p>linux/domino/tools/install.nls</p>

	<p>linux/domino/tools/PathUtil.pl</p>

	<p>linux/domino/tools/MoveExistingRevision.pl</p>

	<p>linux/domino/tools/checksoftlink.pl</p>

	<p>linux/domino/tools/Lsetup.pl</p>

	<p>linux/domino/tools/os390_script_full.dat</p>

	<p>linux/domino/tools/ShScript.pm</p>

	<p>linux/domino/tools/install.pl</p>

	<p>linux/domino/tools/install.sh</p>

	<p>linux/domino/tools/GetUserId.pl</p>

	<p>linux/domino/tools/SysCmd.pl</p>

	<p>linux/domino/tools/checkos.dat</p>

	<p>linux/domino/tools/ChangeDataSubPermissions.pl</p>

	<p>linux/domino/tools/CheckOwnerGroup.pl</p>

	<p>linux/domino/tools/PerlUtil.pl</p>

	<p>linux/domino/tools/media.inf</p>

	<p>linux/domino/tools/setup.jar</p>

	<p>linux/domino/tools/InstBE.pl</p>

	<p>linux/domino/tools/tty.nls</p>

	<p>linux/domino/tools/CreateSoftLink.pl</p>

	<p>linux/domino/tools/ChangeJavaPermissions.pl</p>

	<p>linux/domino/tools/checkos.pl</p>

	<p>linux/domino/tools/tty.pl</p>

	<p>linux/domino/tools/nui.cfg</p>

	<p>linux/domino/tools/uxrmfile.txt</p>

	<p>linux/domino/tools/InstBE.nls</p>

	<p>linux/domino/tools/uxrmfile64.txt</p>

	<p>linux/domino/tools/ProcessLangFiles.pl</p>

	<p>linux/domino/tools/CdPath.pl</p>

	<p>linux/domino/tools/GetGroupId.pl</p>

	<p>linux/domino/tools/AddSolarisDrivers.pl</p>

	<p>linux/domino/tools/CfgData.pm</p>

	<p>linux/domino/tools/GetPreviousRevision.pl</p>

	<p>linux/domino/tools/setupLinux.bin</p>

	<p>linux/domino/remote_script.dat</p>

	<p>linux/domino/install</p>

	<p>linux/domino/unix_response.dat</p>

	<p>linux/notes/</p>

	<p>linux/notes/repository/</p>

	<p>linux/notes/repository/notes.linux.kit/</p>

	<p>linux/notes/repository/notes.linux.kit/build_contents.xml</p>

	<p>linux/notes/repository/notes.linux.kit/felement.xml</p>

	<p>linux/notes/repository/notes.linux.kit/fe.zip</p>

	<p>linux/notes/repository/notes.linux.kit/build_fitness.xml</p>

	<p>[root@mail opt]#</p>

	<p>[root@mail opt]# cd linux</p>

	<p>[root@mail linux]# ls</p>

	<p>domino&#160; notes</p>

	<p>[root@mail linux]# cd domino</p>

	<p>[root@mail domino]# ls</p>

	<p>install&#160; remote_script.dat&#160; tools&#160; unix_response.dat</p>

	<p>[root@mail domino]# ./install</p>

	<p>Lotus Domino for Unix Install Program<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
You have to set environment variable <span class="caps">DISPLAY</span> to run in graphic mode</p>

	<p>Answer Yes to continue in console mode</p>

	<p>Answer No to exit application.</p>

	<p>Do you want to continue installation in console mode?[Yes]</p>

	<p>Continuing in console mode</p>

	<p>InstallShield Wizard</p>

	<p>Initializing InstallShield Wizard&#8230;</p>

	<p>Preparing Java&#8482; Virtual Machine&#8230;</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>...................................</p>

	<p>..............................<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Welcome to the InstallShield Wizard for Lotus Domino</p>

	<p>The InstallShield Wizard will install Lotus Domino on your computer.</p>

	<p>To continue, choose Next.</p>

	<p>Lotus Domino</p>

	<p><span class="caps">IBM</span></p>

	<p>http://www.lotus.com</p>

	<p>Press 1 for Next, 3 to Cancel or 4 to Redisplay [1] 1<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Software Licensing Agreement</p>

	<p>Press Enter to display the license agreement on your screen. Please</p>

	<p>read the agreement carefully before installing the Program. After</p>

	<p>reading the agreement, you will be given the opportunity to accept it</p>

	<p>or decline it. If you choose to decline the agreement, installation</p>

	<p>will not be completed and you will not be able to use the Program.</p>

	<p>International License Agreement for Evaluation of Programs</p>

	<p>Part 1 &#8211; General Terms</p>

	<p><span class="caps">BY DOWNLOADING</span>, INSTALLING, <span class="caps">COPYING</span>, ACCESSING, <span class="caps">OR USING</span></p>

	<p>THE <span class="caps">PROGRAM YOU AGREE TO THE TERMS OF THIS AGREEMENT</span>. IF <span class="caps">YOU</span></p>

	<p>ARE <span class="caps">ACCEPTING THESE TERMS ON BEHALF OF ANOTHER PERSON OR A</span></p>

	<p>COMPANY <span class="caps">OR OTHER LEGAL ENTITY</span>, YOU <span class="caps">REPRESENT AND WARRANT</span></p>

	<p>THAT <span class="caps">YOU HAVE FULL AUTHORITY TO BIND THAT PERSON</span>, COMPANY,</p>

	<p><span class="caps">OR LEGAL ENTITY TO THESE TERMS</span>. IF <span class="caps">YOU DO NOT AGREE TO</span></p>

	<p>THESE <span class="caps">TERMS</span>,</p>
 &#8211; <span class="caps">DO NOT DOWNLOAD</span>, INSTALL, <span class="caps">COPY</span>, ACCESS, <span class="caps">OR USE THE</span>

	<p>PROGRAM; <span class="caps">AND</span></p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>
 &#8211; <span class="caps">PROMPTLY RETURN THE PROGRAM TO THE PARTY FROM WHOM YOU</span>

	<p>ACQUIRED IT. <span class="caps">IF YOU DOWNLOADED THE PROGRAM</span>, CONTACT <span class="caps">THE</span></p>

	<p>PARTY <span class="caps">FROM WHOM YOU ACQUIRED IT</span>.</p>

	<p>&#8220;IBM&#8221; is International Business Machines Corporation or one</p>

	<p>of its subsidiaries.</p>

	<p>&#8220;License Information&#8221; (&#8220;LI&#8221;) is a document that provides</p>

	<p>information specific to a Program. The Program&#8217;s LI is</p>

	<p>available in a file in the Program&#8217;s directory, by the use</p>

	<p>of a system command, or as a booklet which accompanies the</p>

	<p>Program. The LI may also be found at</p>

	<p>http://www.ibm.com/software/sla/ .</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>&#8220;Program&#8221; is the following, including the original and all</p>

	<p>whole or partial copies: 1) machine-readable instructions</p>

	<p>and data, 2) components, 3) audio-visual content (such as</p>

	<p>images, text, recordings, or pictures), 4) related licensed</p>

	<p>materials, and 5) license use documents or keys, and</p>

	<p>documentation.</p>

	<p>&#8220;You&#8221; and &#8220;Your&#8221; refer either to an individual person or to</p>

	<p>a single legal entity.</p>

	<p>This Agreement includes Part 1 &#8211; General Terms, Part 2 &#8211;<br />
Country-unique Terms (if any), and License Information and</p>

	<p>is the complete agreement between You and <span class="caps">IBM</span> regarding the</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>use of the Program. It replaces any prior oral or written</p>

	<p>communications between You and <span class="caps">IBM</span> concerning Your use of</p>

	<p>the Program. The terms of Part 2 and License Information</p>

	<p>may replace or modify those of Part 1.</p>

	<p>1. Entitlement</p>

	<p>License</p>

	<p>The Program is owned by <span class="caps">IBM</span> or an <span class="caps">IBM</span> supplier, and is</p>

	<p>copyrighted and licensed, not sold.</p>

	<p><span class="caps">IBM</span> grants You a nonexclusive license to use the Program</p>

	<p>when You lawfully acquire it.</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>You may 1) use the Program only for internal evaluation,</p>

	<p>testing, or demonstration purposes, on a trial or</p>

	<p>&#8220;try-and-buy&#8221; basis; and 2) make and install a reasonable</p>

	<p>number of copies, including a backup copy, of the Program</p>

	<p>to support such use. The terms of this license apply to</p>

	<p>each copy You make. You will reproduce all copyright</p>

	<p>notices and all other legends of ownership on each copy, or</p>

	<p>partial copy, of the Program.</p>

	<p><span class="caps">THE PROGRAM MAY CONTAIN A DISABLING DEVICE THAT WILL</span></p>

	<p>PREVENT <span class="caps">IT FROM BEING USED AFTER THE EVALUATION PERIOD</span></p>

	<p>ENDS. <span class="caps">YOU WILL NOT TAMPER WITH THIS DISABLING DEVICE OR THE</span></p>

	<p>PROGRAM. <span class="caps">YOU SHOULD TAKE PRECAUTIONS TO AVOID ANY LOSS OF</span></p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p><span class="caps">DATA THAT MIGHT RESULT WHEN THE PROGRAM CAN NO LONGER BE</span></p>

	<p>USED.</p>

	<p>You will 1) maintain a record of all copies of the Program</p>

	<p>and 2) ensure that anyone who uses the Program (accessed</p>

	<p>either locally or remotely) does so only for Your</p>

	<p>authorized use and complies with the terms of this</p>

	<p>Agreement.</p>

	<p>You may not 1) use, copy, modify or distribute the Program</p>

	<p>except as provided in this Agreement; 2) reverse assemble,</p>

	<p>reverse compile, or otherwise translate the Program except</p>

	<p>as specifically permitted by law without the possibility of</p>

	<p>contractual waiver; or 3) sublicense, rent, or lease the</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>Program.</p>

	<p>The evaluation period begins when You agree to the terms of</p>

	<p>this Agreement and ends 1) as of the duration or date</p>

	<p>specified in the License Information, or 2) when the</p>

	<p>Program automatically disables itself. There is no charge</p>

	<p>for the use of the Program for the duration of the</p>

	<p>evaluation period. Unless <span class="caps">IBM</span> specifies in the License</p>

	<p>Information that You may retain the Program, You will</p>

	<p>destroy the Program and all copies made of it within ten</p>

	<p>days of the end of the evaluation period. If <span class="caps">IBM</span> specifies</p>

	<p>that You may retain the Program, and You elect to do so,</p>

	<p>the Program will be then subject to a different license</p>

	<p>agreement, that will be provided to You at that time. In</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>addition, a charge may apply.</p>

	<p><span class="caps">IBM</span> may terminate Your license if You fail to comply with</p>

	<p>the terms of this Agreement. If <span class="caps">IBM</span> does so, You must</p>

	<p>destroy all copies of the Program.</p>

	<p>2. No Warranty</p>

	<p><span class="caps">SUBJECT TO ANY STATUTORY WARRANTIES WHICH CANNOT BE</span></p>

	<p>EXCLUDED, <span class="caps">IBM MAKES NO WARRANTIES OR CONDITIONS EITHER</span></p>

	<p>EXPRESS <span class="caps">OR IMPLIED</span>, INCLUDING <span class="caps">BUT NOT LIMITED TO</span>, THE</p>

	<p><span class="caps">IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY</span>,</p>

	<p><span class="caps">FITNESS FOR A PARTICULAR PURPOSE</span>, AND <span class="caps">NON</span>-INFRINGEMENT,</p>

	<p><span class="caps">REGARDING THE PROGRAM OR TECHNICAL SUPPORT</span>, IF <span class="caps">ANY</span>.</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>The exclusion also applies to any of <span class="caps">IBM</span>&#8217;s Program</p>

	<p>developers and suppliers.</p>

	<p>Manufacturers, suppliers, or publishers of non-IBM Programs</p>

	<p>may provide their own warranties.</p>

	<p><span class="caps">IBM</span> does not provide technical support, unless <span class="caps">IBM</span></p>

	<p>specifies otherwise.</p>

	<p>3. Limitation of Liability</p>

	<p>Circumstances may arise where, because of a default on</p>

	<p><span class="caps">IBM</span>&#8217;s part or other liability, You are entitled to recover</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>damages from <span class="caps">IBM</span>. In each such instance, regardless of the</p>

	<p>basis on which You may be entitled to claim damages from</p>

	<p><span class="caps">IBM</span>, (including fundamental breach, negligence,</p>

	<p>misrepresentation, or other contract or tort claim), <span class="caps">IBM</span> is</p>

	<p>liable for no more than 1) damages for bodily injury</p>

	<p>(including death) and damage to real property and tangible</p>

	<p>personal property and 2) the amount of any other actual</p>

	<p>direct damages up to the charges for the Program that is</p>

	<p>the subject of the claim.</p>

	<p>This limitation of liability also applies to <span class="caps">IBM</span>&#8217;s Program</p>

	<p>developers and suppliers. It is the maximum for which they</p>

	<p>and <span class="caps">IBM</span> are collectively responsible.</p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p><span class="caps">UNDER NO CIRCUMSTANCES IS IBM</span>, ITS <span class="caps">PROGRAM DEVELOPERS OR</span></p>

	<p>SUPPLIERS <span class="caps">LIABLE FOR ANY OF THE FOLLOWING</span>, EVEN <span class="caps">IF INFORMED</span></p>

	<p>OF <span class="caps">THEIR POSSIBILITY</span>:</p>

	<p>1. <span class="caps">LOSS OF</span>, OR <span class="caps">DAMAGE TO</span>, DATA;</p>

	<p>2. <span class="caps">SPECIAL</span>, INCIDENTAL, <span class="caps">OR INDIRECT DAMAGES</span>, OR <span class="caps">FOR ANY</span></p>

	<p>ECONOMIC <span class="caps">CONSEQUENTIAL DAMAGES</span>; OR</p>

	<p>3. <span class="caps">LOST PROFITS</span>, BUSINESS, <span class="caps">REVENUE</span>, GOODWILL, OR</p>

	<p><span class="caps">ANTICIPATED SAVINGS</span>.</p>

	<p><span class="caps">SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION</span></p>

	<p>OF <span class="caps">INCIDENTAL OR CONSEQUENTIAL DAMAGES</span>, SO <span class="caps">THE ABOVE</span></p>

	<p>Press Enter to continue viewing the license agreement, or, Enter 1 to</p>

	<p>accept the agreement, 2 to decline it or 99 to go back to the previous</p>

	<p>screen.</p>

	<p>==skip==============</p>

	<p>1</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Selecting the option below allows you to install additional or upgrade existing</p>

	<p>Server Partitions. The existing Program directory must be specified in order</p>

	<p>for new Server Partitions to be created, but it will not be upgraded. Existing</p>

	<p>Data directories do not need to be listed. Only those Data directories</p>

	<p>specified will be upgraded or added. If you wish to add more than one Partition</p>

	<p>to your existing Domino server, check the box when asked if you want to install</p>

	<p>a Partitioned server. Otherwise you will only be able to upgrade or install one</p>

	<p>Data directory. Warning: If you do not have an existing Domino Server on your</p>

	<p>system, please do not check the box below for the option to add data</p>

	<p>directories only.</p>

	<p>[ ] 1 &#8211; Install Data&#160; Directories Only for Partitioned Domino Server</p>

	<p>To select an item enter its number, or 0 when you are finished: [0]</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Lotus Domino Install Location</p>

	<p>Please specify a directory or press Enter to accept the default directory.</p>

	<p>Program Files Directory Name [/opt/ibm/lotus]</p>

	<p>Server with more than one partition</p>

	<p>Answer Yes to install partitioned server</p>

	<p>Answer No&#160; to install non-partitioned server</p>

	<p>Partitioned Server: [No]</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Lotus Domino Install Location</p>

	<p>Please specify a directory or press Enter to accept the default directory.</p>

	<p>Data Files Directory Name [/local/notesdata]</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Input Unix/Linux user name and group name panel</p>

	<p>User Name [notes]</p>

	<p>Group Name [notes]</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Select Server Setup</p>

	<p>After the installation completes, for new installation server setup will be</p>

	<p>launched and for upgrade the server will be restarted automatically.</p>

	<p>The default value is &#8220;Manual Server Setup&#8221; which does not launch server setup</p>

	<p>or restart the server after installation.</p>

	<p>Select &#8220;Local Server Setup&#8221; to launch server setup after a new server</p>

	<p>installation or to restart the server after a server upgrade.</p>

	<p>Select &#8220;Remote Server Setup&#8221; to launch server setup in listen mode for new</p>

	<p>server installations. You will then be able to connect to the server with the</p>

	<p>Remote Server Setup tool.</p>

	<p>[ ] 1 &#8211; Local</p>

	<p>[ ] 2 &#8211; Remote</p>

	<p>[X] 3 &#8211; Manual</p>

	<p>To select an item enter its number, or 0 when you are finished: [0] 2</p>

	<p>[ ] 1 &#8211; Local</p>

	<p>[X] 2 &#8211; Remote</p>

	<p>[ ] 3 &#8211; Manual</p>

	<p>To select an item enter its number, or 0 when you are finished: [0]</p>

	<p>Choose the setup type that best suits your needs.</p>

	<p>[ ] 1 &#8211; Domino Utility Server</p>

	<p>Installs a Domino server that provides application services only. Note</p>

	<p>that it does not include support for messaging services. See full</p>

	<p>licensing text for details.</p>

	<p>[ ] 2 &#8211; Domino Messaging Server</p>

	<p>Installs a Domino server that provides messaging services. Note that it</p>

	<p>does not include support for application services or Domino clusters.</p>

	<p>[X] 3 &#8211; Domino Enterprise Server</p>

	<p>Installs a Domino server that provides both messaging and application</p>

	<p>services.</p>

	<p>[ ] 4 &#8211; Customize Domino Server</p>

	<p>Allows you to select the features you want to install.</p>

	<p>To select an item enter its number, or 0 when you are finished: [0] 0</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>Lotus Domino will be installed in the following location:</p>

	<p>Program Files:&#160;&#160;&#160;&#160;&#160;&#160;&#160; /opt/ibm/lotus</p>

	<p>Data Files:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; /local/notesdata</p>

	<p>Domino Kit Type:&#160;&#160;&#160;&#160;&#160; EnterpriseServer</p>

	<p>Unix Install Options:</p>

	<p>User Name: notes</p>

	<p>Group Name: notes</p>

	<p>Install Data Only: No</p>

	<p>Start Server Setup: Yes (Remote)</p>

	<p>with the following features:</p>

	<p>Program Files</p>

	<p>Billing Support</p>

	<p>Clustering Support</p>

	<p>Data Files</p>

	<p>Required Templates</p>

	<p>Administration Templates</p>

	<p>Press <span class="caps">ENTER</span> to read the text [Type q to quit]</p>

	<p>Optional Templates</p>

	<p>Certificate Management</p>

	<p>Web Services Data Files</p>

	<p>Readme &#8211; <span class="caps">NSF </span>File</p>

	<p>Dojo</p>

	<p>XPages</p>

	<p>Domino Enterprise Connection Services</p>

	<p>Domino Offline Services</p>

	<p>Lotus iNotes</p>

	<p>Sametime Integration</p>

	<p>Resource Modeling Engine</p>

	<p>Help</p>

	<p>for a total size:</p>

	<p>1051.5 MB</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]</p>

	<p>Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]</p>

	<p>Installing Lotus Domino. Please wait&#8230;</p>

	<p>|&#8212;&#8212;&#8212;&#8212;&#8212;-|&#8212;&#8212;&#8212;&#8212;&#8212;-|&#8212;&#8212;&#8212;&#8212;&#8212;-|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;|</p>

	<p>0%&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 25%&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 50%&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 75%&#160;&#160;&#160;&#160;&#160;&#160;&#160; 100%</p>

	<p>|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||</p>

	<p>Creating uninstaller&#8230;</p>

	<p>Configuring Domino Server from</p>

	<p>Unix user name : notes</p>

	<p>Unix group name : notes</p>

	<p>Domino program directory: /opt/ibm/lotus</p>

	<p>Domino data directory: /local/notesdata</p>

	<p>You will be prompted for the password of the notesdata owner.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p>The InstallShield Wizard has successfully installed Lotus Domino. Choose Finish</p>

	<p>to exit the wizard.</p>

	<p>Press 3 to Finish or 4 to Redisplay [3]</p>

	<p>Press 3 to Finish or 4 to Redisplay [3]</p>

	<p><span class="caps">WARNING</span>: the maximum number of file handles (ulimit -n)</p>

	<p>allowed for Domino is 1024.</p>

	<p>See Release Notes and set the allowable maximum to 20000.</p>

	<p>/proc/sys/kernel/sem has been set to &#8220;250&#160;&#160;&#160;&#160;&#160;&#160; 256000&#160; 32&#160;&#160;&#160;&#160;&#160; 1024&#8221;.</p>

	<p>/proc/sys/net/ipv4/tcp_fin_timeout has been set to &#8220;15&#8221;.</p>

	<p>/proc/sys/net/ipv4/tcp_max_syn_backlog has been set to &#8220;16384&#8221;.</p>

	<p>/proc/sys/net/ipv4/tcp_tw_reuse has been set to &#8220;1&#8221;.</p>

	<p>/proc/sys/net/ipv4/ip_local_port_range has been set to &#8220;1024&#160;&#160;&#160; 65535&#8221;.</p>

	<p>08/14/2010 05:36:06 PM&#160; Created new log file as /local/notesdata/log.nsf</p>

	<p>08/14/2010 05:36:06 PM&#160; <span class="caps">IBM </span>Lotus Domino does not have a production license.&#160; A temporary evaluation license has been enrolled for you to use for 90 days.</p>

	<p>08/14/2010 05:36:06 PM&#160; <span class="caps">WARNING</span>:&#160; You are using a temporary license.&#160; You have 89 days left in the trial license period.</p>

	<p>./java -ss512k -Xoss5M -cp jhall.jar:cfgdomserver.jar:Notes.jar lotus.domino.setup.WizardManagerDomino -data /local/notesdata -listen</p>

	<p>Remote server setup enabled on port 8585.</p>

	<p>The Domino setup server is now in listening mode.</p>

	<p>A remote client can now connect to this server and configure Domino.</p>

	<p>To connect to this server, launch the Remote Domino Setup program from a command-prompt as follows:</p>

	<p>From a Domino administrator client: serversetup -remote</p>

	<p>From a Domino server: server -remote</p>

	<p>To end this server, launch the Remote Domino Setup program from a command-prompt as follows:</p>

	<p>From a Domino administrator client: serversetup -q mail.xxxxxx.com</p>

	<p>From a Domino server: server -q mail.xxxxxx.com</p>

	<p>For more information, see the printed guide Setting Up Domino Networks and Servers.<br />
<img src="http://gultom.or.id/images/remotedomino.jpg" alt="" /></p>

	<p>Sampai disini instalasi Domino Server berhasil. Selanjutnya menggunakan Windows client untuk remote setup console menggunakan Domino Administrator, karena saya remote ke server ini menggunanakan Putty.</p>

	<p>Untuk menjalankan Domino</p>

	<p>su notes</p>

	<p>cd /local/notesdata &#038;& /opt/ibm/lotus/bin/server</p>

	<p>show server</p>

	<p>Test konek ke Domino server melalui Lotus Notes.</p>

	<p>Beberapa untuk&#160; setting Startup scripts, Domino Administrator, dan sebagainya, belum disertakan dalam&#160; tutorial ini.</p>

	<p>Henry Gultom (henry@gultom.or.id)</p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/08/15/installing-lotus-domino-server-8-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux APC UPS with apcupsd</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/07/15/linux-apc-ups-with-apcupsd/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/07/15/linux-apc-ups-with-apcupsd/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 07:05:01 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[Other]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[apcupsd]]></category>
		<category><![CDATA[ups]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1269</guid>
		<description><![CDATA[	Saya punya APC Back-UPS CS 650 digunakan pada salah satu server virtual untuk kebutuhan sehari-hari.&#160; Sebagai tools power management dan controlling UPS saya menggunakan apcupsd APC UPS software yang bisa diinstall pada linux Centos 5.4, dengan apcupsd saya dapat mengetahui masalah seperti power failure,battery dan sebagainya.

	Berikut proses instalasi dan konfigurasi apcupsd pada Linux Centos 5.4 [...]]]></description>
			<content:encoded><![CDATA[	<p>Saya punya <span class="caps">APC </span><a href="http://www.apc.com/resource/include/techspec_index.cfm?base_sku=bk650ei">Back-UPS <span class="caps">CS 650</span></a> digunakan pada salah satu server virtual untuk kebutuhan sehari-hari.&#160; Sebagai tools power management dan controlling <span class="caps">UPS</span> saya menggunakan<a href="http://www.apcupsd.org/"> apcupsd</a> APC <span class="caps">UPS</span> software yang bisa diinstall pada linux <a href="http://www.centos.org/">Centos</a> 5.4, dengan apcupsd saya dapat mengetahui masalah seperti power failure,battery dan sebagainya.</p>

	<p>Berikut proses instalasi dan konfigurasi apcupsd pada Linux Centos 5.4 :</p>

	<p>yum install apcups*</p>

	<p>vi /etc/apcupsd/apcupsd.conf<br />
<span class="caps">UPSCABLE</span> usb<br />
<span class="caps">UPSTYPE</span> usb<br />
<span class="caps">DEVICE</span><br />
LOCKFILE /var/lock<br />
<span class="caps">SCRIPTDIR </span>/etc/apcupsd<br />
<span class="caps">PWRFAILDIR </span>/etc/apcupsd<br />
<span id="more-1269"></span><span class="caps">NOLOGINDIR </span>/etc<br />
<span class="caps">ONBATTERYDELAY 6</span><br />
BATTERYLEVEL 5<br />
<span class="caps">MINUTES 3</span><br />
TIMEOUT 0<br />
<span class="caps">ANNOY 300</span><br />
ANNOYDELAY 60<br />
<span class="caps">NOLOGON</span> disable<br />
<span class="caps">KILLDELAY 0</span><br />
NETSERVER on<br />
<span class="caps">NISIP 0</span>.0.0.0<br />
<span class="caps">NISPORT 3551</span><br />
EVENTSFILE /var/log/apcupsd.events<br />
<span class="caps">EVENTSFILEMAX 10</span><br />
UPSCLASS standalone<br />
<span class="caps">UPSMODE</span> disable<br />
<span class="caps">STATTIME 0</span><br />
STATFILE /var/log/apcupsd.status<br />
<span class="caps">LOGSTATS</span> off<br />
<span class="caps">DATATIME 0</span></p>

	<p>Sebelum saya menjalankan apcupsd, kabel <span class="caps">USB</span> dari <span class="caps">UPS APC</span> di colokkan(plug in) ke slot <span class="caps">USB</span> pada server :<br />
<blockquote>#/etc/init.d/apcupsd start<br />
Starting <span class="caps">UPS</span> monitoring:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; [&#160; OK&#160; ]</p>

	<p>Log messages :</p>

	<p>Jul 15 11:57:11 <span class="caps">ID41</span>-ND201 apcupsd[2383]: apcupsd 3.14.2 (15 September 2007) redhat startup succeeded<br />
Jul 15 11:57:12 <span class="caps">ID41</span>-ND201 apcupsd[2383]: <span class="caps">NIS</span> server startup succeeded</p>

	<ol>
		<li>/etc/init.d/apcupsd status<br />
apcupsd (pid&#160; 2383) is running&#8230;<br />
<span class="caps">APC</span>&#160;&#160;&#160;&#160;&#160; : 001,043,1054<br />
<span class="caps">DATE</span>&#160;&#160;&#160;&#160; : Thu Jul 15 11:57:15 <span class="caps">WIT 2010</span><br />
HOSTNAME : <span class="caps">ID41</span>-ND201.xxxx<br />
<span class="caps">RELEASE</span>&#160; : 3.14.2<br />
<span class="caps">VERSION</span>&#160; : 3.14.2 (15 September 2007) redhat<br />
<span class="caps">UPSNAME</span>&#160; : <span class="caps">ID41</span>-ND201.xxxx<br />
<span class="caps">CABLE</span>&#160;&#160;&#160; : <span class="caps">USB </span>Cable<br />
<span class="caps">MODEL</span>&#160;&#160;&#160; : Back-UPS <span class="caps">CS 650</span><br />
UPSMODE&#160; : Stand Alone<br />
<span class="caps">STARTTIME</span>: Thu Jul 15 11:57:09 <span class="caps">WIT 2010</span><br />
STATUS&#160;&#160; : <span class="caps">ONLINE</span><br />
LINEV&#160;&#160;&#160; : 216.0 Volts<br />
<span class="caps">LOADPCT</span>&#160; :&#160; 24.0 Percent Load Capacity<br />
<span class="caps">BCHARGE</span>&#160; : 100.0 Percent<br />
<span class="caps">TIMELEFT </span>:&#160; 25.0 Minutes<br />
<span class="caps">MBATTCHG </span>: 5 Percent<br />
<span class="caps">MINTIMEL </span>: 3 Minutes<br />
<span class="caps">MAXTIME</span>&#160; : 0 Seconds<br />
<span class="caps">OUTPUTV</span>&#160; : 230.0 Volts<br />
<span class="caps">SENSE</span>&#160;&#160;&#160; : Medium<br />
<span class="caps">DWAKE</span>&#160;&#160;&#160; : 000 Seconds<br />
<span class="caps">DSHUTD</span>&#160;&#160; : 000 Seconds<br />
<span class="caps">LOTRANS</span>&#160; : 180.0 Volts<br />
<span class="caps">HITRANS</span>&#160; : 266.0 Volts<br />
<span class="caps">RETPCT</span>&#160;&#160; : 000.0 Percent<br />
<span class="caps">ITEMP</span>&#160;&#160;&#160; : 29.2 C Internal<br />
<span class="caps">ALARMDEL </span>: Always<br />
<span class="caps">BATTV</span>&#160;&#160;&#160; : 13.5 Volts<br />
<span class="caps">LINEFREQ </span>: 50.0 Hz<br />
<span class="caps">LASTXFER </span>: Low line voltage<br />
<span class="caps">NUMXFERS </span>: 0<br />
<span class="caps">TONBATT</span>&#160; : 0 seconds<br />
<span class="caps">CUMONBATT</span>: 0 seconds<br />
<span class="caps">XOFFBATT </span>: N/A<br />
<span class="caps">SELFTEST </span>: NO<br />
<span class="caps">STATFLAG </span>: 0&#215;07000008 Status Flag<br />
<span class="caps">SERIALNO </span>: QB0645339457<br />
<span class="caps">BATTDATE </span>: 2006-11-05<br />
<span class="caps">NOMOUTV</span>&#160; : 230<br />
<span class="caps">NOMINV</span>&#160;&#160; : 230<br />
<span class="caps">NOMBATTV </span>:&#160; 12.0<br />
<span class="caps">FIRMWARE </span>: 817.v4.I <span class="caps">USB FW</span>:v4<br />
<span class="caps">APCMODEL </span>: Back-UPS <span class="caps">CS 650</span><br />
END <span class="caps">APC</span>&#160; : Thu Jul 15 11:57:16 <span class="caps">WIT 2010</span></li>
	</ol>

	<ol>
		<li>ps axf |grep apcupsd<br />
2507 pts/4&#160;&#160;&#160; S+&#160;&#160;&#160;&#160; 0:00&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; _ grep apcupsd<br />
2383 ?&#160;&#160;&#160;&#160;&#160;&#160;&#160; Ssl&#160;&#160;&#160; 0:00 /sbin/apcupsd -f /etc/apcupsd/apcupsd.conf</blockquote><br />
Selesai.</li>
	</ol>
 &#8211; <a href="http://www.apcupsd.com/manual/manual.html">apcupsd Online Manual</a>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/07/15/linux-apc-ups-with-apcupsd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setup Public Key Infrastructure dengan Dog Tag Certificate System</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/05/30/setup-public-key-infrastructure-dengan-dog-tag-certificate-system/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/05/30/setup-public-key-infrastructure-dengan-dog-tag-certificate-system/#comments</comments>
		<pubDate>Sun, 30 May 2010 08:44:50 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[Certificate Authority]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Dog Tag]]></category>
		<category><![CDATA[Red Hat]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1171</guid>
		<description><![CDATA[	Asimetrik Kriptografi sangat penting dalam menjaga keamanan dalam berkomunikasi di internet. Sistem Asimetrik Kriptografi menggunakan kunci public dan kunci private. Keduanya diperlukan dalam transaksi dan digital signature di internet.  Sebelumnya saya menggunakan EJBCA maka kali ini saya menggunakan Dog Tag Certificate System keluaran Red Hat inc.

	Dogtag memiliki features seperti : Certificate issuance, revocation, dan [...]]]></description>
			<content:encoded><![CDATA[	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/subsystem.png"><img class="alignleft size-medium wp-image-1199" title="subsystem" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/subsystem-300x286.png" alt="" width="300" height="286" /></a>Asimetrik Kriptografi sangat penting dalam menjaga keamanan dalam berkomunikasi di internet. Sistem Asimetrik Kriptografi menggunakan kunci public dan kunci private. Keduanya diperlukan dalam transaksi dan digital signature di internet.  Sebelumnya saya menggunakan <span class="caps">EJBCA</span> maka kali ini saya menggunakan Dog Tag Certificate System keluaran Red Hat inc.</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/logo2.png"><img class="alignleft size-full wp-image-1189" title="logo2" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/logo2.png" alt="" width="137" height="71" /></a>Dogtag memiliki features seperti : Certificate issuance, revocation, dan retrieval, Certificate Revocation List (CRL) generation dan publishing, Certificate profiles, Simple Certificate Enrollment Protocol (SCEP), Local Registration Authority (LRA) for organizational authentication and policies, Encryption key archival and recovery, dan Smartcard lifecycle management Token profiles,Token enrollment, on-hold, key recovery, and format, Face-to-face enrollment with the security officer workstation interface.</p>

	<p>Disamping dipakai untuk smart card, Dog Tag Certification system juga dipakai oleh Militer Amerika  Serikat untuk mengidentifikasi semua tentaranya.&#160; Pernah kan, lihat film perang Hollywood kalau tentara Amerika Serikat itu selalu memakai 2 kalung dilehernya yang dinamakan Dog Tag seperti gambar logo diatas,&#160; Indentitas/Data didalam kalung(dog tag) tersebut berisi nama, Social Security number, blood type dan religion. Jadi jika tentaranya mati, satu dog tag nya diambil dan satu lagi tetap tinggal di lehernya.&#160; Satu kalung yang diambil itu untuk&#160; update data identitas tentara tersebut disemua sistem komputer militer Amerika Serikat. Dog Tag dapat dipakai juga sebagai&#160; password/identitas tentara jika sedang mengunakan fasilitas militer dan sebagainya.</p>

	<p>Dogtag Certificate System memiliki  6 subsystems :<br />
-Certificate Authority (CA) &#8211; implemented in Java<br />
-Data Recovery Manager (DRM) &#8211; implemented in Java<br />
-Online Status Procotol Protocol Manager (OCSP) &#8211; implemented in Java<br />
-Token Key Service (TKS) &#8211; implemented in Java<br />
-Registration Authority (RA) &#8211; implemented in Perl<br />
-Token Processing System (TPS) &#8211; implemented in C and C++</p>

	<p>Pembuatan Public Key Infrastructure dengan Dog Tag Certificate System kali ini terdiri dari Instalasi dan Konfigurasi dengan environment :</p>

	<p>-Sistem operasi pada server : Centos 5.4<br />
-389 Directory Server (Open Source <span class="caps">LDAP</span>)<br />
-Dog Tag Certificate System 1.3 (repo <span class="caps">EPEL</span>)<br />
-Java,Tomcat Web Server,Perl,Ant,Apache,mod_nss</p>

	<p>Berikut proses instalasi dan konfigurasi, saya menggunakan Centos 5.4 32 bit dan sudah terinstall dengan baik :</p>

	<p><strong>Instalasi Tools : </strong></p>

	<p>[root@i ~]# rpm <del>ev tomcat</del>native.i386</p>

	<p>[root@i ~]# yum install db4-devel gzip rpm rpm-build subversion tar wget zip</p>

	<p>[root@i ~]# yum install perl</p>

	<p>[root@i ~]#  yum install ant</p>

	<p>[root@i ~]# yum install ant-junit</p>

	<p>[root@i ~]# java -version<br />
java version &#8220;1.6.0&#8221;<br />
OpenJDK  Runtime Environment (build 1.6.0-b09)<br />
OpenJDK Client <span class="caps">VM </span>(build 1.6.0-b09, mixed mode)</p>

	<p><em>Jika belum terinstall bisa install menggunakan yum install java-1.6.0-openjdk.</em></p>

	<p><em><span id="more-1171"></span><br />
</em></p>

	<p>[root@i ~]# ant -version<br />
Apache Ant version 1.6.5 compiled on January 6 2007</p>

	<p><strong><br />
Install Apache untuk <span class="caps">MOD</span>_NSS dan <span class="caps">PKI</span>-RA</strong></p>

	<p>[root@i ~]# yum install httpd</p>

	<p><strong>Secara default Centos 5.4 terinstall mod_nss versi lama dan harus diupgrade untuk <span class="caps">MOD</span>_NSS </strong></p>

	<p>[root@i ~]# rpm <del>Uvh mod_nss</del>1.0.8-2.el5idm.i386.rpm</p>

	<p>[root@i ~]# rpm -qa mod_nss<br />
mod_nss-1.0.8-2.el5idm</p>

	<p><strong>Mengambil repo <span class="caps">EPEL</span> untuk Centos 5.4</strong></p>

	<p>[root@i ~]# rpm <del>Uvh http://download.fedora.redhat.com/pub/epel/5/i386/epel</del>release-5-3.noarch.rpm</p>

	<p><strong>Instalasi Directory Server menggunakan 389-ds </strong></p>

	<p>[root@i ~]# yum upgrade&#8212;enablerepo=epel-testing</p>

	<p>[root@i ~]# yum install 389-ds&#8212;enablerepo=epel-testing</p>

	<p><strong>Konfigurasi Directory Server :</strong></p>

	<p>[root@i ~]# setup-ds-admin.pl<br />
============================================<br />
This program will set up the 389 Directory and Administration Servers.<br />
It is recommended that you have &#8220;root&#8221; privilege to set up the software.<br />
Tips for using this program: &#8211; Press &#8220;Enter&#8221; to choose the default and go to the next screen &#8211; Type &#8220;Control-B&#8221; then &#8220;Enter&#8221; to go back to the previous screen &#8211; Type &#8220;Control-C&#8221; to cancel the setup program<br />
Would you like to continue with set up? [yes]:<br />
==========================================<br />
<span class="caps">BY SETTING UP AND USING THIS SOFTWARE YOU ARE CONSENTING TO BE BOUND BY</span><br />
AND <span class="caps">ARE BECOMING A PARTY TO THE AGREEMENT FOUND IN THE</span><br />
LICENSE.TXT <span class="caps">FILE</span>. IF <span class="caps">YOU DO NOT AGREE TO ALL OF THE TERMS</span><br />
OF <span class="caps">THIS AGREEMENT</span>, PLEASE <span class="caps">DO NOT SET UP OR USE THIS SOFTWARE</span>.<br />
Do you agree to the license terms? [no]: yes<br />
============================================<br />
Your system has been scanned for potential problems, missing patches,<br />
etc.  The following output is a report of the items found that need to<br />
be addressed before running this software in a production<br />
environment.<br />
389 Directory Server system tuning analysis version 10-AUGUST-2007.<br />
<span class="caps">NOTICE </span>: System is i686-unknown-linux2.6.18-164.el5 (1 processor).</p>

	<p><span class="caps">NOTICE </span>: The net.ipv4.tcp_keepalive_time is set to 7200000 milliseconds<br />
(120 minutes).  This may cause temporary server congestion from lost<br />
client connections.</p>

	<p><span class="caps">WARNING</span>: There are only 1024 file descriptors (hard limit) available, which<br />
limit the number of simultaneous connections.</p>

	<p><span class="caps">WARNING</span>: There are only 1024 file descriptors (soft limit) available, which<br />
limit the number of simultaneous connections.</p>

	<p>Would you like to continue? [no]: yes<br />
==============================================<br />
Choose a setup type:</p>

	<p>1. Express<br />
Allows you to quickly set up the servers using the most<br />
common options and pre-defined defaults. Useful for quick<br />
evaluation of the products.</p>

	<p>2. Typical<br />
Allows you to specify common defaults and options.</p>

	<p>3. Custom<br />
Allows you to specify more advanced options. This is<br />
recommended for experienced server administrators only.<br />
To accept the default shown in brackets, press the Enter key.<br />
Choose a setup type [2]: 2<br />
======================================<br />
Enter the fully qualified domain name of the computer<br />
on which you&#8217;re setting up server software. Using the form<br />
<hostname>.<domainname><br />
Example: eros.example.com.<br />
To accept the default shown in brackets, press the Enter key.<br />
Computer name [i.xxxxom.or.id]:<br />
=======================================================<br />
The servers must run as a specific user in a specific group.<br />
It is strongly recommended that this user should have no privileges<br />
on the computer (i.e. a non-root user).  The setup procedure<br />
will give this user/group some permissions in specific paths/files<br />
to perform server-specific operations.</p>

	<p>If you have not yet created a user and group for the servers,<br />
create this user and group using your native operating<br />
system utilities.</p>

	<p>System User [nobody]:<br />
System Group [nobody]:</p>

	<p>==================================================<br />
Server information is stored in the configuration directory server.<br />
This information is used by the console and administration server to<br />
configure and manage your servers.  If you have already set up a<br />
configuration directory server, you should register any servers you<br />
set up or create with the configuration server.  To do so, the<br />
following information about the configuration server is required: the<br />
fully qualified host name of the form<br />
<hostname>.<domainname>(e.g. hostname.example.com), the port number<br />
(default 389), the suffix, the DN and password of a user having<br />
permission to write the configuration information, usually the<br />
configuration directory administrator, and if you are using security<br />
(TLS/SSL).  If you are using <span class="caps">TLS</span>/SSL, specify the <span class="caps">TLS</span>/SSL (LDAPS) port<br />
number (default 636) instead of the regular <span class="caps">LDAP</span> port number, and<br />
provide the CA certificate (in <span class="caps">PEM</span>/ASCII format).</p>

	<p>If you do not yet have a configuration directory server, enter &#8216;No&#8217; to<br />
be prompted to set up one.</p>

	<p>Do you want to register this software with an existing<br />
configuration directory server? [no]:</p>

	<p>==============================================<br />
Please enter the administrator ID for the configuration directory<br />
server.  This is the ID typically used to log in to the console.  You<br />
will also be prompted for the password.</p>

	<p>Configuration directory server<br />
administrator <span class="caps">ID </span>[admin]:<br />
Password:<br />
Password (confirm):<br />
The passwords do not match.  Please try again.</p>

	<p>Password (confirm):</p>

	<p>==============================================<br />
The information stored in the configuration directory server can be<br />
separated into different Administration Domains.  If you are managing<br />
multiple software releases at the same time, or managing information<br />
about multiple domains, you may use the Administration Domain to keep<br />
them separate.</p>

	<p>If you are not using administrative domains, press Enter to select the<br />
default.  Otherwise, enter some descriptive, unique name for the<br />
administration domain, such as the name of the organization<br />
responsible for managing the domain.</p>

	<p>Administration Domain [xxxxom.or.id]:</p>

	<p>=============================================<br />
The standard directory server network port number is 389.  However, if<br />
you are not logged as the superuser, or port 389 is in use, the<br />
default value will be a random unused port number greater than 1024.<br />
If you want to use port 389, make sure that you are logged in as the<br />
superuser, that port 389 is not in use.</p>

	<p>Directory server network port [389]:</p>

	<p>=============================================<br />
Each instance of a directory server requires a unique identifier.<br />
This identifier is used to name the various<br />
instance specific files and directories in the file system,<br />
as well as for other uses as a server instance identifier.</p>

	<p>Directory server identifier [i]:</p>

	<p>==========================================<br />
The suffix is the root of your directory tree.  The suffix must be a valid DN.<br />
It is recommended that you use the dc=domaincomponent suffix convention.<br />
For example, if your domain is example.com,<br />
you should use dc=example,dc=com for your suffix.<br />
Setup will create this initial suffix for you,<br />
but you may have more than one suffix.<br />
Use the directory server utilities to create additional suffixes.</p>

	<p>Suffix [dc=xxxxom, dc=or, dc=id]:</p>

	<p>=========================================<br />
Certain directory server operations require an administrative user.<br />
This user is referred to as the Directory Manager and typically has a<br />
bind Distinguished Name (DN) of cn=Directory Manager.<br />
You will also be prompted for the password for this user.  The password must<br />
be at least 8 characters long, and contain no spaces.<br />
Press Control-B or type the word &#8220;back&#8221;, then Enter to back up and start over.</p>

	<p>Directory Manager <span class="caps">DN </span>[cn=Directory Manager]:<br />
Password:<br />
Password (confirm):</p>

	<p>===============================================<br />
The Administration Server is separate from any of your web or application<br />
servers since it listens to a different port and access to it is<br />
restricted.</p>

	<p>Pick a port number between 1024 and 65535 to run your Administration<br />
Server on. You should <span class="caps">NOT</span> use a port number which you plan to<br />
run a web or application server on, rather, select a number which you<br />
will remember and which will not be used for anything else.</p>

	<p>Administration port [9830]:</p>

	<p>===============================================<br />
The interactive phase is complete.  The script will now set up your<br />
servers.  Enter No or go Back if you want to change something.</p>

	<p>Are you ready to set up your servers? [yes]:<br />
Creating directory server . . .<br />
Your new DS instance &#8216;i&#8217; was successfully created.<br />
Creating the configuration directory server . . .<br />
Beginning Admin Server creation . . .<br />
Creating Admin Server files and directories . . .<br />
Updating adm.conf . . .<br />
Updating admpw . . .<br />
Registering admin server with the configuration directory server . . .<br />
Updating adm.conf with information from configuration directory server . . .<br />
Updating the configuration for the httpd engine . . .<br />
Starting admin server . . .<br />
The admin server was successfully started.<br />
Admin server was successfully created, configured, and started.<br />
Exiting . . .<br />
Log file is &#8216;/tmp/setup8XSC5y.log&#8217;<br />
[root@i ~]#</p>

	<p>Untuk mengadministrasi menggunakan 389-ds console bisa menggunakan Windows <span class="caps">XP </span>Profesional dan Linux.<br />
Jika mengunakan Fedora 12 Desktop menggunakan fedora-idm-console :</p>

	<p>#yum install fedora-idm-console</p>

	<p>#yum install xorg-x11-deprecated-libs</p>

	<p>Untuk Login mengunakan :</p>

	<p>cn=Directory Manager<br />
Password : xxxxxxxxx<br />
Administration <span class="caps">URL </span>: http://i.xxxxom.or.id:9830</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/389windowsconsole2.jpg"><img class="alignnone size-medium wp-image-1175" title="389windowsconsole2" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/389windowsconsole2-300x226.jpg" alt="" width="300" height="226" /></a></p>

	<p><strong>Instalasi Dog Tag Certificate System mengunakan repo <span class="caps">EPEL</span></strong></p>

	<p>[root@i ~]# yum&#8212;enablerepo=epel-testing install dogtag-pki<br />
<em> </em><br />
&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>

	<p><em>Installed:<br />
dogtag-pki.noarch 0:1.3.0-2.el5<br />
</em>Complete!<br />
[root@i ~]#</p>

	<p><strong>Konfigurasi Dog Tag Certificate System</strong></p>

	<p>Ada 6 subsystems (CA/SubCA,KRA/DRM,RA,TKS,TPS,OCSP)&#160; yang dapat kita konfigurasi yaitu dengan menggunakan  <span class="caps">PKICREATE</span> keenam subsystems harus kita konfigurasi satu persatu, pada instalasi ini semua berada di satu server, untuk pengembangan bisa kita buat berbeda server pada masing-masing subsystems:</p>

	<p>Contoh command yang dapat dipakai sebagai berikut :</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>ca<br />
-subsystem_type=ca<br />
-agent_secure_port=9443<br />
-ee_secure_port=9444<br />
-ee_secure_client_auth_port=9446<br />
-admin_secure_port=9445<br />
-unsecure_port=9180<br />
-tomcat_server_port=9701<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>ca<br />
<del>redirect logs=/var/log/pki</del>ca<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>subca<br />
-subsystem_type=ca<br />
-agent_secure_port=9543<br />
-ee_secure_port=9544<br />
-ee_secure_client_auth_port=9546<br />
-admin_secure_port=9545<br />
-unsecure_port=9580<br />
-tomcat_server_port=9801<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>subca<br />
<del>redirect logs=/var/log/pki</del>subca<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>kra<br />
-subsystem_type=kra<br />
-agent_secure_port=10443<br />
-ee_secure_port=10444<br />
-admin_secure_port=10445<br />
-unsecure_port=10180<br />
-tomcat_server_port=10701<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>kra<br />
<del>redirect logs=/var/log/pki</del>kra<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>ocsp<br />
-subsystem_type=ocsp<br />
-agent_secure_port=11443<br />
-ee_secure_port=11444<br />
-admin_secure_port=11445<br />
-unsecure_port=11180<br />
-tomcat_server_port=11701<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>ocsp<br />
<del>redirect logs=/var/log/pki</del>ocsp<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>tks<br />
-subsystem_type=tks<br />
-agent_secure_port=13443<br />
-ee_secure_port=13444<br />
-admin_secure_port=13445<br />
-unsecure_port=13180<br />
-tomcat_server_port=13701<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>tks<br />
<del>redirect logs=/var/log/pki</del>tks<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>ra<br />
-subsystem_type=ra<br />
-secure_port=12889<br />
-non_clientauth_secure_port=12890<br />
-unsecure_port=12888<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>ra<br />
<del>redirect logs=/var/log/pki</del>ra<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>tps<br />
-subsystem_type=tps<br />
-secure_port=7889<br />
-non_clientauth_secure_port=7890<br />
-unsecure_port=7888<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>tps<br />
<del>redirect logs=/var/log/pki</del>tps<br />
-verbose</p>

	<p>pkicreate -pki_instance_root=/var/lib<br />
<del>pki_instance_name=pki</del>tps1<br />
-subsystem_type=tps<br />
-secure_port=7989<br />
-non_clientauth_secure_port=7990<br />
-unsecure_port=7988<br />
-user=pkiuser<br />
-group=pkiuser<br />
<del>redirect conf=/etc/pki</del>tps1<br />
<del>redirect logs=/var/log/pki</del>tps1<br />
-verbose</p>

	<p><strong><br />
DEPLOY <span class="caps">PKI</span>-CA</strong></p>

	<p>[root@i /]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>ca<br />
>           -subsystem_type=ca<br />
>           -agent_secure_port=9443<br />
>           -ee_secure_port=9444<br />
>           -ee_secure_client_auth_port=9446<br />
>           -admin_secure_port=9445<br />
>           -unsecure_port=9180<br />
>           -tomcat_server_port=9701<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>ca<br />
>           <del>redirect logs=/var/log/pki</del>ca<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ca<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ca<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: 9446<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ca/CS.cfg<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 15:47:56 2010<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 9445<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 9180<br />
[2010-05-08 15:47:56] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 15:47:56] [debug]     Converting &#8216;/usr/share/pki/ca/conf/serverCertNick.conf&#8217; &gt; '/etc/pki-ca/serverCertNick.conf' ...<br />
[2010-05-08 15:47:56] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-ca/server.xml<br />
[2010-05-08 15:47:56] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: TOMCAT_SERVER_PORT with: 9701<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_RANDOM_NUMBER with: 1JqIAUMw2MlN8CTldWPn<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT with: 9444<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_ID with: pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: 9446<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-ca/CS.cfg<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: INSTALL_TIME with: Sat May  8 15:47:56 2010<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 9445<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT with: 9180<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 15:47:57] [debug]     Converting '/usr/share/pki/ca/conf/tomcat5.conf' > &#8216;/etc/pki-ca/tomcat5.conf&#8217; ...<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-ca/server.xml<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 9701<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: 1JqIAUMw2MlN8CTldWPn<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 9444<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: 9446<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ca/CS.cfg<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 15:47:56 2010<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 9445<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 9180<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 15:47:57] [debug]     Converting &#8216;/usr/share/pki/ca/webapps/ca/WEB-INF/velocity.properties&#8217; &gt; '/var/lib/pki-ca/webapps/ca/WEB-INF/velocity.properties' ...<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-ca/server.xml<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: TOMCAT_SERVER_PORT with: 9701<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_RANDOM_NUMBER with: 1JqIAUMw2MlN8CTldWPn<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT with: 9444<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_INSTANCE_ID with: pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: 9446<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-ca/CS.cfg<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: INSTALL_TIME with: Sat May  8 15:47:56 2010<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 9445<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_UNSECURE_PORT with: 9180<br />
[2010-05-08 15:47:57] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 15:47:57] [debug]     Converting '/usr/share/pki/ca/webapps/ca/WEB-INF/web.xml' > &#8216;/var/lib/pki-ca/webapps/ca/WEB-INF/web.xml&#8217; ...<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-ca/server.xml<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 9701<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: 1JqIAUMw2MlN8CTldWPn<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 9444<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: 9446<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ca/CS.cfg<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 9443<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 15:47:56 2010<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 9445<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 9180<br />
[2010-05-08 15:47:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 15:47:57] [debug] Processing <span class="caps">PKI</span> files and symbolic links for &#8216;/var/lib/pki-ca&#8217; ...<br />
[2010-05-08 15:47:57] [debug] Processing <span class="caps">PKI</span> security databases for &#8216;/var/lib/pki-ca&#8217; ...<br />
[2010-05-08 15:47:57] [debug] Processing <span class="caps">PKI</span> security modules for &#8216;/var/lib/pki-ca&#8217; ...<br />
[2010-05-08 15:47:57] [debug]     Attempting to add hardware security modules to system if applicable &#8230;<br />
[2010-05-08 15:47:57] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 15:47:57] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 15:47:57] [debug] Restorecon file context for /usr/share/java/pki<br />
[2010-05-08 15:47:57] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 15:47:57] [debug] restorecon file context for /usr/bin/dtomcat5-pki-ca<br />
[2010-05-08 15:47:57] [debug] Restorecon file context for /var/lib/pki-ca<br />
[2010-05-08 15:47:57] [debug] Restorecon file context for /var/run<br />
[2010-05-08 15:47:58] [debug] Setting selinux file context for &#8220;/var/log/pki-ca(/.*)?&#8221;</p>

	<p><span class="caps">PKI</span> instance creation completed &#8230;<br />
Stopping pki-ca:<br />
process already stopped<br />
===========================================<br />
Starting pki-ca:                                           [  <span class="caps">OK  </span>]<br />
pki-ca (pid 5165) is running &#8230;<br />
&#8216;pki-ca&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-ca-install.log)<br />
Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.</p>

	<p>Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:9445/ca/admin/console/config/login?pin=1JqIAUMw2MlN8CTldWPn<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-cad restart pki-ca<br />
[root@i /]#<br />
[root@i ~]# /sbin/service pki-cad restart pki-ca<br />
Stopping pki-ca: ...............................           [  <span class="caps">OK  </span>]<br />
============================================<br />
Starting pki-ca:                                           [  <span class="caps">OK  </span>]<br />
pki-ca (pid 6404) is running &#8230;<br />
Unsecure Port       = http://i.xxxxom.or.id:9180/ca/ee/ca<br />
Secure Agent Port   = https://i.xxxxom.or.id:9443/ca/agent/ca<br />
Secure <span class="caps">EE </span>Port      = https://i.xxxxom.or.id:9444/ca/ee/ca<br />
Secure Admin Port   = https://i.xxxxom.or.id:9445/ca/services<br />
<span class="caps">EE </span>Client Auth Port = https://i.xxxxom.or.id:9446/ca/eeca/ca<br />
<span class="caps">PKI </span>Console Port    = pkiconsole https://i.xxxxom.or.id:9445/ca<br />
Tomcat Port         = 9701 (for shutdown)<br />
<span class="caps">PKI </span>Instance Name:   pki-ca<br />
<span class="caps">PKI </span>Subsystem Type:  Root <span class="caps">CA </span>(Security Domain)<br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
======================================================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
======================================================================<br />
[root@i ~]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273308724664.png"><img class="alignnone size-medium wp-image-1176" title="Dogtag Certificate System_1273308724664" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273308724664-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273309644435.png"><img class="alignnone size-medium wp-image-1177" title="Certificate System_1273309644435" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273309644435-300x148.png" alt="" width="300" height="148" /></a></p>

	<p><strong><span class="caps">DEPLOY SUB CA</span></strong></p>

	<p>[root@i ~]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>subca<br />
>           -subsystem_type=ca<br />
>           -agent_secure_port=9543<br />
>           -ee_secure_port=9544<br />
>           -ee_secure_client_auth_port=9546<br />
>           -admin_secure_port=9545<br />
>           -unsecure_port=9580<br />
>           -tomcat_server_port=9801<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>subca<br />
>           <del>redirect logs=/var/log/pki</del>subca<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 9801<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: iBzt5I3F04LOKKJ6Zbzt<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 9544<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: 9546<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-subca/CS.cfg<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 16:07:58 2010<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 9545<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 9580<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 16:07:59] [debug]     Converting &#8216;/usr/share/pki/ca/conf/tomcat5.conf&#8217; &gt; '/etc/pki-subca/tomcat5.conf' ...<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-subca/server.xml<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: TOMCAT_SERVER_PORT with: 9801<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_RANDOM_NUMBER with: iBzt5I3F04LOKKJ6Zbzt<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT with: 9544<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_ID with: pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: 9546<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-subca/CS.cfg<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: INSTALL_TIME with: Sat May  8 16:07:58 2010<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 9545<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT with: 9580<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 16:07:59] [debug]     Converting '/usr/share/pki/ca/webapps/ca/WEB-INF/velocity.properties' > &#8216;/var/lib/pki-subca/webapps/ca/WEB-INF/velocity.properties&#8217; ...<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-subca/server.xml<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 9801<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: iBzt5I3F04LOKKJ6Zbzt<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 9544<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: 9546<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-subca/CS.cfg<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 16:07:58 2010<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 9545<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 9580<br />
[2010-05-08 16:07:59] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 16:07:59] [debug]     Converting &#8216;/usr/share/pki/ca/webapps/ca/WEB-INF/web.xml&#8217; &gt; '/var/lib/pki-subca/webapps/ca/WEB-INF/web.xml' ...<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-subca/server.xml<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: TOMCAT_SERVER_PORT with: 9801<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_RANDOM_NUMBER with: iBzt5I3F04LOKKJ6Zbzt<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT with: 9544<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_INSTANCE_ID with: pki-subca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: 9546<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-subca/CS.cfg<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ca<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 9543<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: INSTALL_TIME with: Sat May  8 16:07:58 2010<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 9545<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_UNSECURE_PORT with: 9580<br />
[2010-05-08 16:07:59] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 16:07:59] [debug] Processing PKI files and symbolic links for '/var/lib/pki-subca' ...<br />
[2010-05-08 16:08:00] [debug] Processing PKI security databases for '/var/lib/pki-subca' ...<br />
[2010-05-08 16:08:00] [debug] Processing PKI security modules for '/var/lib/pki-subca' ...<br />
[2010-05-08 16:08:00] [debug]     Attempting to add hardware security modules to system if applicable ...<br />
[2010-05-08 16:08:00] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so DOES NOT EXIST!<br />
[2010-05-08 16:08:00] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so DOES NOT EXIST!<br />
[2010-05-08 16:08:00] [debug] Restorecon file context for /usr/share/java/pki<br />
[2010-05-08 16:08:00] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 16:08:00] [debug] Setting selinux file context for /usr/bin/dtomcat5-pki-subca</p>

	<p>PKI instance creation completed ...</p>

	<p>Stopping pki-subca:<br />
process already stopped<br />
==========================================================<br />
Starting pki-subca:                                        [  <span class="caps">OK  </span>]<br />
pki-subca (pid 29931) is running &#8230;<br />
&#8216;pki-subca&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-subca-install.log)</p>

	<p>Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:9545/ca/admin/console/config/login?pin=T6TF1PtACWnLDIkzR9gI<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-cad restart pki-subca<br />
[root@i ~]#<br />
[root@i ~]# /sbin/service pki-cad restart pki-subca<br />
Stopping pki-subca: ...............................        [  <span class="caps">OK  </span>]<br />
========================================================<br />
Starting pki-subca:                                        [  <span class="caps">OK  </span>]<br />
pki-subca (pid 31171) is running &#8230;<br />
Unsecure Port       = http://i.xxxxom.or.id:9580/ca/ee/ca<br />
Secure Agent Port   = https://i.xxxxom.or.id:9543/ca/agent/ca<br />
Secure <span class="caps">EE </span>Port      = https://i.xxxxom.or.id:9544/ca/ee/ca<br />
Secure Admin Port   = https://i.xxxxom.or.id:9545/ca/services<br />
<span class="caps">EE </span>Client Auth Port = https://i.xxxxom.or.id:9546/ca/eeca/ca<br />
<span class="caps">PKI </span>Console Port    = pkiconsole https://i.xxxxom.or.id:9545/ca<br />
Tomcat Port         = 9801 (for shutdown)<br />
<span class="caps">PKI </span>Instance Name:   pki-subca<br />
<span class="caps">PKI </span>Subsystem Type:  Subordinate CA<br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
=====================================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
=====================================================<br />
[root@i ~]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273421324056.png"><img class="alignnone size-medium wp-image-1178" title="Dogtag Certificate System_1273421324056" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273421324056-300x199.png" alt="" width="300" height="199" /></a></p>

	<p><strong><span class="caps">DEPLOY PKI</span>-KRA</strong></p>

	<p>[root@i etc]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>kra<br />
>           -subsystem_type=kra<br />
>           -agent_secure_port=10443<br />
>           -ee_secure_port=10444<br />
>           -admin_secure_port=10445<br />
>           -unsecure_port=10180<br />
>           -tomcat_server_port=10701<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>kra<br />
>           <del>redirect logs=/var/log/pki</del>kra<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-kra<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-kra<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-kra/CS.cfg<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: kra<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:36:44 2010<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 10445<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 10180<br />
[2010-05-08 17:36:44] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:36:44] [debug]     Converting &#8216;/usr/share/pki/kra/conf/serverCertNick.conf&#8217; &gt; '/etc/pki-kra/serverCertNick.conf' ...<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-kra/server.xml<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: TOMCAT_SERVER_PORT with: 10701<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_RANDOM_NUMBER with: f7wZwxm4UZA8kCJIQTQ0<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_PORT with: 10444<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-kra<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_INSTANCE_ID with: pki-kra<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-kra/CS.cfg<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: kra<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:36:44] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:36:44 2010<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 10445<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_UNSECURE_PORT with: 10180<br />
[2010-05-08 17:36:44] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:36:44] [debug]     Converting '/usr/share/pki/kra/conf/tomcat5.conf' > &#8216;/etc/pki-kra/tomcat5.conf&#8217; ...<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-kra/server.xml<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 10701<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: f7wZwxm4UZA8kCJIQTQ0<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 10444<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-kra/CS.cfg<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:36:44 2010<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 10445<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 10180<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:36:45] [debug]     Converting &#8216;/usr/share/pki/kra/webapps/kra/WEB-INF/velocity.properties&#8217; &gt; '/var/lib/pki-kra/webapps/kra/WEB-INF/velocity.properties' ...<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-kra/server.xml<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: TOMCAT_SERVER_PORT with: 10701<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_RANDOM_NUMBER with: f7wZwxm4UZA8kCJIQTQ0<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_PORT with: 10444<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_INSTANCE_ID with: pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-kra/CS.cfg<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: kra<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:36:44 2010<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 10445<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_UNSECURE_PORT with: 10180<br />
[2010-05-08 17:36:45] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:36:45] [debug]     Converting '/usr/share/pki/kra/webapps/kra/WEB-INF/web.xml' > &#8216;/var/lib/pki-kra/webapps/kra/WEB-INF/web.xml&#8217; ...<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-kra/server.xml<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 10701<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: f7wZwxm4UZA8kCJIQTQ0<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 10444<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-kra/CS.cfg<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: kra<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 10443<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:36:44 2010<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 10445<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 10180<br />
[2010-05-08 17:36:45] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:36:45] [debug] Processing <span class="caps">PKI</span> files and symbolic links for &#8216;/var/lib/pki-kra&#8217; ...<br />
[2010-05-08 17:36:45] [debug] Processing <span class="caps">PKI</span> security databases for &#8216;/var/lib/pki-kra&#8217; ...<br />
[2010-05-08 17:36:45] [debug] Processing <span class="caps">PKI</span> security modules for &#8216;/var/lib/pki-kra&#8217; ...<br />
[2010-05-08 17:36:45] [debug]     Attempting to add hardware security modules to system if applicable &#8230;<br />
[2010-05-08 17:36:45] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:36:45] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:36:45] [debug] Restorecon file context for /usr/share/java/pki<br />
[2010-05-08 17:36:45] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 17:36:45] [debug] restorecon file context for /usr/bin/dtomcat5-pki-kra<br />
[2010-05-08 17:36:45] [debug] Restorecon file context for /var/lib/pki-kra<br />
[2010-05-08 17:36:45] [debug] Restorecon file context for /var/run<br />
[2010-05-08 17:36:46] [debug] Setting selinux file context for &#8220;/var/log/pki-kra(/.*)?&#8221;</p>

	<p><span class="caps">PKI</span> instance creation completed &#8230;<br />
Stopping pki-kra:<br />
process already stopped<br />
=======================================<br />
Starting pki-kra:                                          [  <span class="caps">OK  </span>]<br />
pki-kra (pid 10994) is running &#8230;<br />
&#8216;pki-kra&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-kra-install.log)<br />
Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:10445/kra/admin/console/config/login?pin=f7wZwxm4UZA8kCJIQTQ0<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-krad restart pki-kra<br />
[root@i etc]#</p>

	<p>[root@i etc]# /sbin/service pki-krad restart pki-kra<br />
Stopping pki-kra: ..                                       [  <span class="caps">OK  </span>]<br />
========================================================<br />
Starting pki-kra:                                          [  <span class="caps">OK  </span>]<br />
pki-kra (pid 11937) is running &#8230;</p>

	<p>Unsecure Port     = http://i.xxxxom.or.id:10180/kra/ee/kra<br />
Secure Agent Port = https://i.xxxxom.or.id:10443/kra/agent/kra<br />
Secure <span class="caps">EE </span>Port    = https://i.xxxxom.or.id:10444/kra/ee/kra<br />
Secure Admin Port = https://i.xxxxom.or.id:10445/kra/services<br />
<span class="caps">PKI </span>Console Port  = pkiconsole https://i.xxxxom.or.id:10445/kra<br />
Tomcat Port       = 10701 (for shutdown)<br />
<span class="caps">PKI </span>Instance Name:   pki-kra<br />
<span class="caps">PKI </span>Subsystem Type:  <span class="caps">DRM</span><br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
======================================================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
======================================================================<br />
[root@i etc]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_12733151732841.png"><img class="alignnone size-medium wp-image-1180" title="Dogtag Certificate System_1273315173284" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_12733151732841-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273315509654.png"><img class="alignnone size-medium wp-image-1181" title="Certificate System_1273315509654" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273315509654-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><strong><span class="caps">DEPLOY PKI</span>-OCSP</strong></p>

	<p>[root@i etc]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>ocsp<br />
>           -subsystem_type=ocsp<br />
>           -agent_secure_port=11443<br />
>           -ee_secure_port=11444<br />
>           -admin_secure_port=11445<br />
>           -unsecure_port=11180<br />
>           -tomcat_server_port=11701<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>ocsp<br />
>           <del>redirect logs=/var/log/pki</del>ocsp<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ocsp<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ocsp<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ocsp/CS.cfg<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ocsp<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:45:32 2010<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 11445<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 11180<br />
[2010-05-08 17:45:32] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:45:32] [debug]     Converting &#8216;/usr/share/pki/ocsp/conf/serverCertNick.conf&#8217; &gt; '/etc/pki-ocsp/serverCertNick.conf' ...<br />
[2010-05-08 17:45:32] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-ocsp/server.xml<br />
[2010-05-08 17:45:32] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:32] [debug]         replacing: TOMCAT_SERVER_PORT with: 11701<br />
[2010-05-08 17:45:32] [debug]         replacing: PKI_RANDOM_NUMBER with: hA0oT8qGoqBjsHGEqqv7<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT with: 11444<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_ID with: pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-ocsp/CS.cfg<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:45:32 2010<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 11445<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT with: 11180<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:45:33] [debug]     Converting '/usr/share/pki/ocsp/conf/tomcat5.conf' > &#8216;/etc/pki-ocsp/tomcat5.conf&#8217; ...<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-ocsp/server.xml<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 11701<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: hA0oT8qGoqBjsHGEqqv7<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 11444<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ocsp/CS.cfg<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:45:32 2010<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 11445<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 11180<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:45:33] [debug]     Converting &#8216;/usr/share/pki/ocsp/webapps/ocsp/WEB-INF/velocity.properties&#8217; &gt; '/var/lib/pki-ocsp/webapps/ocsp/WEB-INF/velocity.properties' ...<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-ocsp/server.xml<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: TOMCAT_SERVER_PORT with: 11701<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_RANDOM_NUMBER with: hA0oT8qGoqBjsHGEqqv7<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT with: 11444<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_INSTANCE_ID with: pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-ocsp/CS.cfg<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:45:32 2010<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 11445<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_UNSECURE_PORT with: 11180<br />
[2010-05-08 17:45:33] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:45:33] [debug]     Converting '/usr/share/pki/ocsp/webapps/ocsp/WEB-INF/web.xml' > &#8216;/var/lib/pki-ocsp/webapps/ocsp/WEB-INF/web.xml&#8217; ...<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-ocsp/server.xml<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 11701<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: hA0oT8qGoqBjsHGEqqv7<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 11444<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-ocsp<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:45:33] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-ocsp/CS.cfg<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: ocsp<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 11443<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:45:32 2010<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 11445<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 11180<br />
[2010-05-08 17:45:34] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:45:34] [debug] Processing <span class="caps">PKI</span> files and symbolic links for &#8216;/var/lib/pki-ocsp&#8217; ...<br />
[2010-05-08 17:45:34] [debug] Processing <span class="caps">PKI</span> security databases for &#8216;/var/lib/pki-ocsp&#8217; ...<br />
[2010-05-08 17:45:35] [debug] Processing <span class="caps">PKI</span> security modules for &#8216;/var/lib/pki-ocsp&#8217; ...<br />
[2010-05-08 17:45:35] [debug]     Attempting to add hardware security modules to system if applicable &#8230;<br />
[2010-05-08 17:45:35] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:45:35] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:45:35] [debug] Restorecon file context for /usr/share/java/pki<br />
[2010-05-08 17:45:35] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 17:45:35] [debug] restorecon file context for /usr/bin/dtomcat5-pki-ocsp<br />
[2010-05-08 17:45:35] [debug] Restorecon file context for /var/lib/pki-ocsp<br />
[2010-05-08 17:45:35] [debug] Restorecon file context for /var/run<br />
[2010-05-08 17:45:35] [debug] Setting selinux file context for &#8220;/var/log/pki-ocsp(/.*)?&#8221;</p>

	<p><span class="caps">PKI</span> instance creation completed &#8230;<br />
Stopping pki-ocsp:<br />
process already stopped<br />
========================================================<br />
Starting pki-ocsp:                                         [  <span class="caps">OK  </span>]<br />
pki-ocsp (pid 12804) is running &#8230;<br />
&#8216;pki-ocsp&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-ocsp-install.log)</p>

	<p>Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:11445/ocsp/admin/console/config/login?pin=hA0oT8qGoqBjsHGEqqv7<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-ocspd restart pki-ocsp<br />
[root@i etc]#</p>

	<p>[root@i etc]# /sbin/service pki-ocspd restart pki-ocsp<br />
Stopping pki-ocsp: ...                                     [  <span class="caps">OK  </span>]<br />
========================================================<br />
Starting pki-ocsp:                                         [  <span class="caps">OK  </span>]<br />
pki-ocsp (pid 13741) is running &#8230;<br />
Unsecure Port     = http://i.xxxxom.or.id:11180/ocsp/ee/ocsp<br />
Secure Agent Port = https://i.xxxxom.or.id:11443/ocsp/agent/ocsp<br />
Secure <span class="caps">EE </span>Port    = https://i.xxxxom.or.id:11444/ocsp/ee/ocsp<br />
Secure Admin Port = https://i.xxxxom.or.id:11445/ocsp/services<br />
<span class="caps">PKI </span>Console Port  = pkiconsole https://i.xxxxom.or.id:11445/ocsp<br />
Tomcat Port       = 11701 (for shutdown)<br />
<span class="caps">PKI </span>Instance Name:   pki-ocsp<br />
<span class="caps">PKI </span>Subsystem Type:  <span class="caps">OCSP</span><br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
==============================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
==============================================</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Online-Certificate-Status-Authority_1273316402981.png"><img class="alignnone size-medium wp-image-1182" title="Online Certificate Status Authority_1273316402981" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Online-Certificate-Status-Authority_1273316402981-300x237.png" alt="" width="300" height="237" /></a></p>

	<p><strong><span class="caps">DEPLOY PKI</span>-TKS</strong></p>

	<p>[root@i etc]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>tks<br />
>           -subsystem_type=tks<br />
>           -agent_secure_port=13443<br />
>           -ee_secure_port=13444<br />
>           -admin_secure_port=13445<br />
>           -unsecure_port=13180<br />
>           -tomcat_server_port=13701<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>tks<br />
>           <del>redirect logs=/var/log/pki</del>tks<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-tks/CS.cfg<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: tks<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:59:57 2010<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 13445<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 13180<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:59:57] [debug]     Converting &#8216;/usr/share/pki/tks/conf/serverCertNick.conf&#8217; &gt; '/etc/pki-tks/serverCertNick.conf' ...<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-tks/server.xml<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: TOMCAT_SERVER_PORT with: 13701<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_RANDOM_NUMBER with: uiHRXQPOplP0aRJouePc<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_PORT with: 13444<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_INSTANCE_ID with: pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-tks/CS.cfg<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: tks<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:59:57] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:59:57 2010<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 13445<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_UNSECURE_PORT with: 13180<br />
[2010-05-08 17:59:57] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:59:57] [debug]     Converting '/usr/share/pki/tks/conf/tomcat5.conf' > &#8216;/etc/pki-tks/tomcat5.conf&#8217; ...<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-tks/server.xml<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 13701<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: uiHRXQPOplP0aRJouePc<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 13444<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-tks<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:59:57] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-tks/CS.cfg<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: tks<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:59:57 2010<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 13445<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 13180<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:59:58] [debug]     Converting &#8216;/usr/share/pki/tks/webapps/tks/WEB-INF/velocity.properties&#8217; &gt; '/var/lib/pki-tks/webapps/tks/WEB-INF/velocity.properties' ...<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_SERVER_XML_CONF with: /etc/pki-tks/server.xml<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: TOMCAT_SERVER_PORT with: 13701<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_RANDOM_NUMBER with: uiHRXQPOplP0aRJouePc<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_FLAVOR with: pki<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_PORT with: 13444<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_INSTANCE_PATH with: /var/lib/pki-tks<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_INSTANCE_ID with: pki-tks<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Port Connector --&gt;<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  EE Secure Client Auth Port Connector --&gt;<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_CFG_PATH_NAME with: /etc/pki-tks/CS.cfg<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_SUBSYSTEM_TYPE with: tks<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_AGENT_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_GROUP with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: INSTALL_TIME with: Sat May  8 17:59:57 2010<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_UNSECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Unsecure Port Connector --&gt;<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_ADMIN_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Admin Secure Port Connector --&gt;<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_ADMIN_SECURE_PORT with: 13445<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_SECURE_PORT_SERVER_COMMENT with: &lt;!-- Port Separation:  Agent Secure Port Connector --&gt;<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_USER with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_UNSECURE_PORT with: 13180<br />
[2010-05-08 17:59:58] [debug]         replacing: PKI_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:59:58] [debug]     Converting '/usr/share/pki/tks/webapps/tks/WEB-INF/web.xml' > &#8216;/var/lib/pki-tks/webapps/tks/WEB-INF/web.xml&#8217; ...<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SERVER_XML_CONF with: /etc/pki-tks/server.xml<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">TOMCAT</span>_SERVER_PORT with: 13701<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: uiHRXQPOplP0aRJouePc<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_CONNECTOR_NAME with: Agent<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_MACHINE_NAME with: i.gultom.or.id<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_FLAVOR with: pki<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_OPEN_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT with: 13444<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_CONNECTOR_NAME with: EEClientAuth<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_PATH with: /var/lib/pki-tks<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_INSTANCE_ID with: pki-tks<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_CONNECTOR_NAME with: Admin<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_CONNECTOR_NAME with: Unsecure<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT with: -1<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_WEBAPPS_NAME with: webapps<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_CLIENT_AUTH_PORT_SERVER_COMMENT with: <!-- Port Separation:  EE Secure Client Auth Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_SERVER_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CFG_PATH_NAME with: /etc/pki-tks/CS.cfg<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SUBSYSTEM_TYPE with: tks<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_AGENT_SECURE_PORT with: 13443<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CLOSE_SEPARATE_PORTS_WEB_COMMENT with:<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_CERT_DB_PASSWORD with: (sensitive)<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_EE_SECURE_PORT_CONNECTOR_NAME with: EE<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_GROUP with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">INSTALL</span>_TIME with: Sat May  8 17:59:57 2010<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Unsecure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Admin Secure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_ADMIN_SECURE_PORT with: 13445<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_SECURE_PORT_SERVER_COMMENT with: <!-- Port Separation:  Agent Secure Port Connector --><br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_USER with: pkiuser<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_UNSECURE_PORT with: 13180<br />
[2010-05-08 17:59:58] [debug]         replacing: <span class="caps">PKI</span>_AGENT_CLIENTAUTH with: true<br />
[2010-05-08 17:59:58] [debug] Processing <span class="caps">PKI</span> files and symbolic links for &#8216;/var/lib/pki-tks&#8217; ...<br />
[2010-05-08 17:59:58] [debug] Processing <span class="caps">PKI</span> security databases for &#8216;/var/lib/pki-tks&#8217; ...<br />
[2010-05-08 17:59:59] [debug] Processing <span class="caps">PKI</span> security modules for &#8216;/var/lib/pki-tks&#8217; ...<br />
[2010-05-08 17:59:59] [debug]     Attempting to add hardware security modules to system if applicable &#8230;<br />
[2010-05-08 17:59:59] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:59:59] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so <span class="caps">DOES NOT EXIST</span>!<br />
[2010-05-08 17:59:59] [debug] Restorecon file context for /usr/share/java/pki<br />
[2010-05-08 17:59:59] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 17:59:59] [debug] restorecon file context for /usr/bin/dtomcat5-pki-tks<br />
[2010-05-08 17:59:59] [debug] Restorecon file context for /var/lib/pki-tks<br />
[2010-05-08 17:59:59] [debug] Restorecon file context for /var/run<br />
[2010-05-08 17:59:59] [debug] Setting selinux file context for &#8220;/var/log/pki-tks(/.*)?&#8221;</p>

	<p><span class="caps">PKI</span> instance creation completed &#8230;<br />
Stopping pki-tks:<br />
process already stopped<br />
===========================================<br />
Starting pki-tks:                                          [  <span class="caps">OK  </span>]<br />
pki-tks (pid 14607) is running &#8230;<br />
&#8216;pki-tks&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-tks-install.log)<br />
Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:13445/tks/admin/console/config/login?pin=uiHRXQPOplP0aRJouePc<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-tksd restart pki-tks<br />
[root@i etc]#</p>

	<p>[root@i etc] /sbin/service pki-tksd restart pki-tks<br />
Stopping pki-tks: ...                                      [  <span class="caps">OK  </span>]<br />
============================================<br />
Starting pki-tks:                                          [  <span class="caps">OK  </span>]<br />
pki-tks (pid 15512) is running &#8230;<br />
Unsecure Port     = http://i.xxxxom.or.id:13180/tks/ee/tks<br />
Secure Agent Port = https://i.xxxxom.or.id:13443/tks/agent/tks<br />
Secure <span class="caps">EE </span>Port    = https://i.xxxxom.or.id:13444/tks/ee/tks<br />
Secure Admin Port = https://i.xxxxom.or.id:13445/tks/services<br />
<span class="caps">PKI </span>Console Port  = pkiconsole https://i.xxxxom.or.id:13445/tks<br />
Tomcat Port       = 13701 (for shutdown)<br />
<span class="caps">PKI </span>Instance Name:   pki-tks<br />
<span class="caps">PKI </span>Subsystem Type:  <span class="caps">TKS</span><br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
============================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
============================================<br />
[root@i etc]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273316658991.png"><img class="alignnone size-medium wp-image-1183" title="Dogtag Certificate System_1273316658991" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Dogtag-Certificate-System_1273316658991-300x186.png" alt="" width="300" height="186" /></a></p>

	<p><strong><span class="caps">DEPLOY PKI</span>-RA</strong></p>

	<p>[root@i etc]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>ra<br />
>           -subsystem_type=ra<br />
>           -secure_port=12889<br />
>           -non_clientauth_secure_port=12890<br />
>           -unsecure_port=12888<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>ra<br />
>           <del>redirect logs=/var/log/pki</del>ra<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[2010-05-08 18:07:55] [debug]     Converting &#8216;/usr/share/pki/ra/setup/config.desktop&#8217; &gt; '/usr/share/applications/pki-ra-config.desktop' ...<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:07:55] [debug]         replacing:  with: pki<br />
[2010-05-08 18:07:55] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SUBSYSTEM_TYPE with: ra<br />
[2010-05-08 18:07:55] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 12890<br />
[2010-05-08 18:07:55] [debug]         replacing: PROCESS_ID with: 15745<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:07:55] [debug]         replacing: PKI_RANDOM_NUMBER with: 3l6C1izcFyoUtU28lKrr<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ID with: pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:07:55] [debug]         replacing: NSS_CONF with: /etc/pki-ra/nss.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:07:55] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:07:55] [debug]         replacing: TPS_DIR with: /usr/share/pki/ra<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:07:55] [debug]         replacing: PORT with: 12888<br />
[2010-05-08 18:07:55] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURE_PORT with: 12889<br />
[2010-05-08 18:07:55] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: REQUIRE_CFG_PL with: require "";<br />
[2010-05-08 18:07:55] [debug]         replacing: HTTPD_CONF with: /etc/pki-ra/httpd.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:07:55] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:07:55] [debug]     Converting '/usr/share/pki/ra/conf/httpd.conf' > &#8216;/etc/pki-ra/httpd.conf&#8217; ...<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:07:55] [debug]         replacing:  with: pki<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">USERID</span> with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SUBSYSTEM</span>_TYPE with: ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">NON</span>_CLIENTAUTH_SECURE_PORT with: 12890<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PROCESS</span>_ID with: 15745<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SERVER</span>_ROOT with: /var/lib/pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SERVER</span>_NAME with: i.gultom.or.id<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: 3l6C1izcFyoUtU28lKrr<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SYSTEM</span>_LIBRARIES with: /lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">INSTANCE</span>_ID with: pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_APACHE with: Apache2<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">NSS</span>_CONF with: /etc/pki-ra/nss.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_DIR with: /usr<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">OBJ</span>_EXT with: .so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">TPS</span>_DIR with: /usr/share/pki/ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">INSTANCE</span>_ROOT with: /var/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PORT</span> with: 12888<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">GROUPID</span> with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SECURE</span>_PORT with: 12889<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">TMP</span>_DIR with: /tmp<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SYSTEM</span>_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">REQUIRE</span>_CFG_PL with: require &#8220;&#8221;;<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">HTTPD</span>_CONF with: /etc/pki-ra/httpd.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">LIB</span>_PREFIX with: lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SECURITY</span>_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:07:55] [debug]     Converting &#8216;/usr/share/pki/ra/conf/nss.conf&#8217; &gt; '/etc/pki-ra/nss.conf'<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:07:55] [debug]         replacing:  with: pki<br />
[2010-05-08 18:07:55] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SUBSYSTEM_TYPE with: ra<br />
[2010-05-08 18:07:55] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 12890<br />
[2010-05-08 18:07:55] [debug]         replacing: PROCESS_ID with: 15745<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:07:55] [debug]         replacing: PKI_RANDOM_NUMBER with: 3l6C1izcFyoUtU28lKrr<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ID with: pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:07:55] [debug]         replacing: NSS_CONF with: /etc/pki-ra/nss.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:07:55] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:07:55] [debug]         replacing: TPS_DIR with: /usr/share/pki/ra<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:07:55] [debug]         replacing: PORT with: 12888<br />
[2010-05-08 18:07:55] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURE_PORT with: 12889<br />
[2010-05-08 18:07:55] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: REQUIRE_CFG_PL with: require "";<br />
[2010-05-08 18:07:55] [debug]         replacing: HTTPD_CONF with: /etc/pki-ra/httpd.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:07:55] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:07:55] [debug]     Converting '/usr/share/pki/ra/conf/perl.conf' > &#8216;/etc/pki-ra/perl.conf&#8217;<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:07:55] [debug]         replacing:  with: pki<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">USERID</span> with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SUBSYSTEM</span>_TYPE with: ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">NON</span>_CLIENTAUTH_SECURE_PORT with: 12890<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PROCESS</span>_ID with: 15745<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SERVER</span>_ROOT with: /var/lib/pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SERVER</span>_NAME with: i.gultom.or.id<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: 3l6C1izcFyoUtU28lKrr<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SYSTEM</span>_LIBRARIES with: /lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">INSTANCE</span>_ID with: pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_APACHE with: Apache2<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">NSS</span>_CONF with: /etc/pki-ra/nss.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_DIR with: /usr<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">OBJ</span>_EXT with: .so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">TPS</span>_DIR with: /usr/share/pki/ra<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">INSTANCE</span>_ROOT with: /var/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">PORT</span> with: 12888<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">GROUPID</span> with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SECURE</span>_PORT with: 12889<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">TMP</span>_DIR with: /tmp<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SYSTEM</span>_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">REQUIRE</span>_CFG_PL with: require &#8220;&#8221;;<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">HTTPD</span>_CONF with: /etc/pki-ra/httpd.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">FORTITUDE</span>_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">LIB</span>_PREFIX with: lib<br />
[2010-05-08 18:07:55] [debug]         replacing: <span class="caps">SECURITY</span>_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:07:55] [debug]     Converting &#8216;/usr/share/pki/ra/scripts/nss_pcache&#8217; &gt; '/var/lib/pki-ra/scripts/nss_pcache' ...<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:07:55] [debug]         replacing:  with: pki<br />
[2010-05-08 18:07:55] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SUBSYSTEM_TYPE with: ra<br />
[2010-05-08 18:07:55] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 12890<br />
[2010-05-08 18:07:55] [debug]         replacing: PROCESS_ID with: 15745<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:07:55] [debug]         replacing: PKI_RANDOM_NUMBER with: 3l6C1izcFyoUtU28lKrr<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ID with: pki-ra<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:07:55] [debug]         replacing: NSS_CONF with: /etc/pki-ra/nss.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:07:55] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:07:55] [debug]         replacing: TPS_DIR with: /usr/share/pki/ra<br />
[2010-05-08 18:07:55] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:07:55] [debug]         replacing: PORT with: 12888<br />
[2010-05-08 18:07:55] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURE_PORT with: 12889<br />
[2010-05-08 18:07:55] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:07:55] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:07:55] [debug]         replacing: REQUIRE_CFG_PL with: require "";<br />
[2010-05-08 18:07:55] [debug]         replacing: HTTPD_CONF with: /etc/pki-ra/httpd.conf<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:07:55] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:07:55] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:07:55] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:07:55] [debug] Processing PKI files and symbolic links for '/var/lib/pki-ra' ...<br />
[2010-05-08 18:07:55] [debug] Processing PKI security databases for '/var/lib/pki-ra' ...<br />
[2010-05-08 18:07:56] [debug] Processing PKI security modules for '/var/lib/pki-ra' ...<br />
[2010-05-08 18:07:56] [debug]     Attempting to add hardware security modules to system if applicable ...<br />
[2010-05-08 18:07:56] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so DOES NOT EXIST!<br />
[2010-05-08 18:07:57] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so DOES NOT EXIST!<br />
[2010-05-08 18:07:57] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 18:07:57] [debug] Restorecon file context for /var/lib/pki-ra<br />
[2010-05-08 18:07:57] [debug] Setting selinux file context for "/var/log/pki-ra(/.*)?"<br />
-------skip----------------------------------<br />
[2010-05-08 18:08:11] [debug] Restorecon /etc/pki-ra<br />
[2010-05-08 18:08:11] [debug] Restorecon file context for /usr/sbin/httpd.worker<br />
[2010-05-08 18:08:11] [debug] Setting selinux context pki_ra_port_t for 12890<br />
PKI instance creation completed ...<br />
Stopping pki-ra:<br />
process already stopped<br />
==========================================================<br />
Starting pki-ra: .                                         [  <span class="caps">OK  </span>]<br />
pki-ra (pid 15887) is running &#8230;<br />
&#8216;pki-ra&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-ra-install.log)<br />
Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:12890/ra/admin/console/config/login?pin=3l6C1izcFyoUtU28lKrr<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-rad restart pki-ra<br />
[root@i etc]#</p>

	<p>[root@i etc]# /sbin/service pki-rad restart pki-ra<br />
Stopping pki-ra: .                                         [  <span class="caps">OK  </span>]<br />
========================================================<br />
Starting pki-ra: .                                         [  <span class="caps">OK  </span>]<br />
pki-ra (pid 17771) is running &#8230;<br />
Unsecure Port              = http://i.xxxxom.or.id:12888<br />
Secure Clientauth Port     = https://i.xxxxom.or.id:12889<br />
Secure Non-Clientauth Port = https://i.xxxxom.or.id:12890<br />
<span class="caps">PKI </span>Instance Name:   pki-ra<br />
<span class="caps">PKI </span>Subsystem Type:  RA<br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
=================================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
=================================================<br />
[root@i etc]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273317627404.png"><img class="alignnone size-medium wp-image-1184" title="Certificate System_1273317627404" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273317627404-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273317644172.png"><img class="alignnone size-medium wp-image-1185" title="Certificate System_1273317644172" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273317644172-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><strong><span class="caps">DEPLOY PKI</span>-TPS</strong></p>

	<p>[root@i etc]# pkicreate -pki_instance_root=/var/lib<br />
>           <del>pki_instance_name=pki</del>tps<br />
>           -subsystem_type=tps<br />
>           -secure_port=7889<br />
>           -non_clientauth_secure_port=7890<br />
>           -unsecure_port=7888<br />
>           -user=pkiuser<br />
>           -group=pkiuser<br />
>           <del>redirect conf=/etc/pki</del>tps<br />
>           <del>redirect logs=/var/log/pki</del>tps<br />
>           -verbose&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;skip&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;[2010-05-08 18:19:02] [debug]     Converting &#8216;/usr/share/pki/tps/scripts/schemaMods.ldif&#8217; &gt; '/var/lib/pki-tps/scripts/schemaMods.ldif' ...<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:19:02] [debug]         replacing:  with: pki<br />
[2010-05-08 18:19:02] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: SUBSYSTEM_TYPE with: tps<br />
[2010-05-08 18:19:02] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 7890<br />
[2010-05-08 18:19:02] [debug]         replacing: PROCESS_ID with: 18670<br />
[2010-05-08 18:19:02] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:19:02] [debug]         replacing: PKI_RANDOM_NUMBER with: cDtRK8DGDN3kjvIhxiah<br />
[2010-05-08 18:19:02] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:19:02] [debug]         replacing: INSTANCE_ID with: pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:19:02] [debug]         replacing: NSS_CONF with: /etc/pki-tps/nss.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:19:02] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:19:02] [debug]         replacing: TPS_DIR with: /usr/share/pki/tps<br />
[2010-05-08 18:19:02] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:19:02] [debug]         replacing: PORT with: 7888<br />
[2010-05-08 18:19:02] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: SECURE_PORT with: 7889<br />
[2010-05-08 18:19:02] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:19:02] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: REQUIRE_CFG_PL with: require "/var/lib/pki-tps/cgi-bin/sow/cfg.pl";<br />
[2010-05-08 18:19:02] [debug]         replacing: HTTPD_CONF with: /etc/pki-tps/httpd.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:19:02] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:19:02] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:19:02] [debug]     Converting '/usr/share/pki/tps/conf/httpd.conf' > &#8216;/etc/pki-tps/httpd.conf&#8217; ...<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:19:02] [debug]         replacing:  with: pki<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">USERID</span> with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SUBSYSTEM</span>_TYPE with: tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">NON</span>_CLIENTAUTH_SECURE_PORT with: 7890<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">PROCESS</span>_ID with: 18670<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SERVER</span>_ROOT with: /var/lib/pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SERVER</span>_NAME with: i.gultom.or.id<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: cDtRK8DGDN3kjvIhxiah<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SYSTEM</span>_LIBRARIES with: /lib<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">INSTANCE</span>_ID with: pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_APACHE with: Apache2<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">NSS</span>_CONF with: /etc/pki-tps/nss.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_DIR with: /usr<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">OBJ</span>_EXT with: .so<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">TPS</span>_DIR with: /usr/share/pki/tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">INSTANCE</span>_ROOT with: /var/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">PORT</span> with: 7888<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">GROUPID</span> with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SECURE</span>_PORT with: 7889<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">TMP</span>_DIR with: /tmp<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SYSTEM</span>_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">REQUIRE</span>_CFG_PL with: require &#8220;/var/lib/pki-tps/cgi-bin/sow/cfg.pl&#8221;;<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">HTTPD</span>_CONF with: /etc/pki-tps/httpd.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">LIB</span>_PREFIX with: lib<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SECURITY</span>_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:19:02] [debug]     Converting &#8216;/usr/share/pki/tps/conf/nss.conf&#8217; &gt; '/etc/pki-tps/nss.conf' ...<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:19:02] [debug]         replacing:  with: pki<br />
[2010-05-08 18:19:02] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: SUBSYSTEM_TYPE with: tps<br />
[2010-05-08 18:19:02] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 7890<br />
[2010-05-08 18:19:02] [debug]         replacing: PROCESS_ID with: 18670<br />
[2010-05-08 18:19:02] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:19:02] [debug]         replacing: PKI_RANDOM_NUMBER with: cDtRK8DGDN3kjvIhxiah<br />
[2010-05-08 18:19:02] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:19:02] [debug]         replacing: INSTANCE_ID with: pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:19:02] [debug]         replacing: NSS_CONF with: /etc/pki-tps/nss.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:19:02] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:19:02] [debug]         replacing: TPS_DIR with: /usr/share/pki/tps<br />
[2010-05-08 18:19:02] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:19:02] [debug]         replacing: PORT with: 7888<br />
[2010-05-08 18:19:02] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: SECURE_PORT with: 7889<br />
[2010-05-08 18:19:02] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:19:02] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:19:02] [debug]         replacing: REQUIRE_CFG_PL with: require "/var/lib/pki-tps/cgi-bin/sow/cfg.pl";<br />
[2010-05-08 18:19:02] [debug]         replacing: HTTPD_CONF with: /etc/pki-tps/httpd.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:19:02] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:19:02] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:19:02] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:19:02] [debug]     Converting '/usr/share/pki/tps/conf/perl.conf' > &#8216;/etc/pki-tps/perl.conf&#8217; ...<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:19:02] [debug]         replacing:  with: pki<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">USERID</span> with: pkiuser<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SUBSYSTEM</span>_TYPE with: tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">NON</span>_CLIENTAUTH_SECURE_PORT with: 7890<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">PROCESS</span>_ID with: 18670<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SERVER</span>_ROOT with: /var/lib/pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SERVER</span>_NAME with: i.gultom.or.id<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">PKI</span>_RANDOM_NUMBER with: cDtRK8DGDN3kjvIhxiah<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">SYSTEM</span>_LIBRARIES with: /lib<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">INSTANCE</span>_ID with: pki-tps<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_APACHE with: Apache2<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">NSS</span>_CONF with: /etc/pki-tps/nss.conf<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">FORTITUDE</span>_DIR with: /usr<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">OBJ</span>_EXT with: .so<br />
[2010-05-08 18:19:02] [debug]         replacing: <span class="caps">TPS</span>_DIR with: /usr/share/pki/tps<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">INSTANCE</span>_ROOT with: /var/lib<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">FORTITUDE</span>_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">PORT</span> with: 7888<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">GROUPID</span> with: pkiuser<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">SECURE</span>_PORT with: 7889<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">TMP</span>_DIR with: /tmp<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">SYSTEM</span>_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">REQUIRE</span>_CFG_PL with: require &#8220;/var/lib/pki-tps/cgi-bin/sow/cfg.pl&#8221;;<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">HTTPD</span>_CONF with: /etc/pki-tps/httpd.conf<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">FORTITUDE</span>_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">FORTITUDE</span>_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">LIB</span>_PREFIX with: lib<br />
[2010-05-08 18:19:03] [debug]         replacing: <span class="caps">SECURITY</span>_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:19:03] [debug]     Converting &#8216;/usr/share/pki/tps/scripts/nss_pcache&#8217; &gt; '/var/lib/pki-tps/scripts/nss_pcache' ...<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_MODULE with: /etc/httpd/modules<br />
[2010-05-08 18:19:03] [debug]         replacing:  with: pki<br />
[2010-05-08 18:19:03] [debug]         replacing: USERID with: pkiuser<br />
[2010-05-08 18:19:03] [debug]         replacing: SUBSYSTEM_TYPE with: tps<br />
[2010-05-08 18:19:03] [debug]         replacing: NON_CLIENTAUTH_SECURE_PORT with: 7890<br />
[2010-05-08 18:19:03] [debug]         replacing: PROCESS_ID with: 18670<br />
[2010-05-08 18:19:03] [debug]         replacing: SERVER_ROOT with: /var/lib/pki-tps<br />
[2010-05-08 18:19:03] [debug]         replacing: SERVER_NAME with: i.gultom.or.id<br />
[2010-05-08 18:19:03] [debug]         replacing: PKI_RANDOM_NUMBER with: cDtRK8DGDN3kjvIhxiah<br />
[2010-05-08 18:19:03] [debug]         replacing: SYSTEM_LIBRARIES with: /lib<br />
[2010-05-08 18:19:03] [debug]         replacing: INSTANCE_ID with: pki-tps<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_APACHE with: Apache2<br />
[2010-05-08 18:19:03] [debug]         replacing: NSS_CONF with: /etc/pki-tps/nss.conf<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_DIR with: /usr<br />
[2010-05-08 18:19:03] [debug]         replacing: OBJ_EXT with: .so<br />
[2010-05-08 18:19:03] [debug]         replacing: TPS_DIR with: /usr/share/pki/tps<br />
[2010-05-08 18:19:03] [debug]         replacing: INSTANCE_ROOT with: /var/lib<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_LIB_DIR with: /etc/httpd<br />
[2010-05-08 18:19:03] [debug]         replacing: PORT with: 7888<br />
[2010-05-08 18:19:03] [debug]         replacing: GROUPID with: pkiuser<br />
[2010-05-08 18:19:03] [debug]         replacing: SECURE_PORT with: 7889<br />
[2010-05-08 18:19:03] [debug]         replacing: TMP_DIR with: /tmp<br />
[2010-05-08 18:19:03] [debug]         replacing: SYSTEM_USER_LIBRARIES with: /usr/lib<br />
[2010-05-08 18:19:03] [debug]         replacing: REQUIRE_CFG_PL with: require "/var/lib/pki-tps/cgi-bin/sow/cfg.pl";<br />
[2010-05-08 18:19:03] [debug]         replacing: HTTPD_CONF with: /etc/pki-tps/httpd.conf<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_NSS_MODULES with:<br />
LoadModule nss_module  /etc/httpd/modules/libmodnss.so<br />
[2010-05-08 18:19:03] [debug]         replacing: FORTITUDE_AUTH_MODULES with:<br />
LoadModule auth_basic_module /etc/httpd/modules/mod_auth_basic.so<br />
LoadModule authn_file_module /etc/httpd/modules/mod_authn_file.so<br />
LoadModule authz_user_module /etc/httpd/modules/mod_authz_user.so<br />
LoadModule authz_groupfile_module /etc/httpd/modules/mod_authz_groupfile.so<br />
LoadModule authz_host_module /etc/httpd/modules/mod_authz_host.so<br />
[2010-05-08 18:19:03] [debug]         replacing: LIB_PREFIX with: lib<br />
[2010-05-08 18:19:03] [debug]         replacing: SECURITY_LIBRARIES with: /usr/lib/dirsec<br />
[2010-05-08 18:19:03] [debug] Processing PKI files and symbolic links for '/var/lib/pki-tps' ...<br />
[2010-05-08 18:19:03] [debug] Processing PKI security databases for '/var/lib/pki-tps' ...<br />
[2010-05-08 18:19:03] [debug] Processing PKI security modules for '/var/lib/pki-tps' ...<br />
[2010-05-08 18:19:03] [debug]     Attempting to add hardware security modules to system if applicable ...<br />
[2010-05-08 18:19:03] [debug]         module name: lunasa  lib: /usr/lunasa/lib/libCryptoki2.so DOES NOT EXIST!<br />
[2010-05-08 18:19:03] [debug]         module name: nfast  lib: /opt/nfast/toolkits/pkcs11/libcknfast.so DOES NOT EXIST!<br />
[2010-05-08 18:19:03] [debug] Restorecon file context for /usr/share/pki<br />
[2010-05-08 18:19:03] [debug] Restorecon file context for /var/lib/pki-tps<br />
[2010-05-08 18:19:03] [debug] Setting selinux file context for "/var/log/pki-tps(/.*)?"<br />
libsepol.context_from_record: type pki_tps_log_t is not defined<br />
libsepol.context_from_record: could not create context structure<br />
-----------skip------------------------------<br />
[2010-05-08 18:19:17] [debug] Restorecon /etc/pki-tps<br />
[2010-05-08 18:19:17] [debug] Restorecon file context for /usr/sbin/httpd.worker<br />
[2010-05-08 18:19:17] [debug] Setting selinux context pki_tps_port_t for 7890<br />
PKI instance creation completed ...<br />
Stopping pki-tps:<br />
process already stopped<br />
==========================================================<br />
Starting pki-tps: .                                        [  <span class="caps">OK  </span>]<br />
pki-tps (pid 18818) is running &#8230;<br />
&#8216;pki-tps&#8217; must still be <span class="caps">CONFIGURED</span>!<br />
(see /var/log/pki-tps-install.log)<br />
Before proceeding with the configuration, make sure<br />
the firewall settings of this machine permit proper<br />
access to this subsystem.<br />
Please start the configuration by accessing:<br />
https://i.xxxxom.or.id:7890/tps/admin/console/config/login?pin=cDtRK8DGDN3kjvIhxiah<br />
After configuration, the server can be operated by the command:<br />
/sbin/service pki-tpsd restart pki-tps<br />
[root@i etc]#</p>

	<p>[root@i etc]#  /sbin/service pki-tpsd restart pki-tps<br />
Stopping pki-tps: ..........                               [  <span class="caps">OK  </span>]<br />
========================================================<br />
Starting pki-tps: .                                        [  <span class="caps">OK  </span>]<br />
pki-tps (pid 21265) is running &#8230;<br />
Unsecure Port              = http://i.xxxxom.or.id:7888/cgi-bin/so/enroll.cgi<br />
(ESC Security Officer Enrollment)<br />
Unsecure Port              = http://i.xxxxom.or.id:7888/cgi-bin/home/index.cgi<br />
(ESC Phone Home)<br />
Secure Clientauth Port     = https://i.xxxxom.or.id:7889/cgi-bin/sow/welcome.cgi<br />
(ESC Security Officer Workstation)<br />
Secure Clientauth Port     = https://i.xxxxom.or.id:7889/tus<br />
(TPS Roles &#8211; Operator/Administrator/Agent)<br />
Secure Non-Clientauth Port = https://i.xxxxom.or.id:7890/cgi-bin/so/enroll.cgi<br />
(ESC Security Officer Enrollment)<br />
Secure Non-Clientauth Port = https://i.xxxxom.or.id:7890/cgi-bin/home/index.cgi<br />
(ESC Phone Home)<br />
<span class="caps">PKI </span>Instance Name:   pki-tps<br />
<span class="caps">PKI </span>Subsystem Type:  <span class="caps">TPS</span><br />
Registered <span class="caps">PKI </span>Security Domain Information:<br />
==============================================<br />
Name:  GultomOr Domain<br />
<span class="caps">URL</span>:   https://i.xxxxom.or.id:9445<br />
============================================<br />
[root@i etc]#</p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273318620391.png"><img class="alignnone size-medium wp-image-1186" title="Certificate System_1273318620391" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/Certificate-System_1273318620391-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><a href="http://henry.gultom.or.id/wp-content/uploads/2010/05/TPS_1273318657212.png"><img class="alignnone size-medium wp-image-1187" title="TPS_1273318657212" src="http://henry.gultom.or.id/wp-content/uploads/2010/05/TPS_1273318657212-300x181.png" alt="" width="300" height="181" /></a></p>

	<p><span class="caps">LISTING SEMUA PORT DOGTAG </span>:</p>

	<p>[root@i etc]# netstat -nltup<br />
Active Internet connections (only servers)<br />
Proto Recv-Q Send-Q Local Address               Foreign Address             State       <span class="caps">PID</span>/Program name<br />
tcp        0      0 0.0.0.0:9830                0.0.0.0:*                   <span class="caps">LISTEN      3067</span>/httpd.worker<br />
tcp        0      0 0.0.0.0:909                 0.0.0.0:*                   <span class="caps">LISTEN      1575</span>/rpc.statd<br />
tcp        0      0 0.0.0.0:111                 0.0.0.0:*                   <span class="caps">LISTEN      1539</span>/portmap<br />
tcp        0      0 :::13443                    :::*                        <span class="caps">LISTEN      15512</span>/java<br />
tcp        0      0 :::9443                     :::*                        <span class="caps">LISTEN      6404</span>/java<br />
tcp        0      0 :::13444                    :::*                        <span class="caps">LISTEN      15512</span>/java<br />
tcp        0      0 :::10180                    :::*                        <span class="caps">LISTEN      11937</span>/java<br />
tcp        0      0 :::9444                     :::*                        <span class="caps">LISTEN      6404</span>/java<br />
tcp        0      0 ::ffff:127.0.0.1:13701      :::*                        <span class="caps">LISTEN      15512</span>/java<br />
tcp        0      0 :::13445                    :::*                        <span class="caps">LISTEN      15512</span>/java<br />
tcp        0      0 ::ffff:127.0.0.1:9701       :::*                        <span class="caps">LISTEN      6404</span>/java<br />
tcp        0      0 :::9445                     :::*                        <span class="caps">LISTEN      6404</span>/java<br />
tcp        0      0 :::389                      :::*                        <span class="caps">LISTEN      2970</span>/ns-slapd<br />
tcp        0      0 :::9446                     :::*                        <span class="caps">LISTEN      6404</span>/java<br />
tcp        0      0 :::9543                     :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 :::9544                     :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 ::ffff:127.0.0.1:9801       :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 :::9545                     :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 :::9546                     :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 :::10443                    :::*                        <span class="caps">LISTEN      11937</span>/java<br />
tcp        0      0 :::11180                    :::*                        <span class="caps">LISTEN      13741</span>/java<br />
tcp        0      0 :::10444                    :::*                        <span class="caps">LISTEN      11937</span>/java<br />
tcp        0      0 :::9580                     :::*                        <span class="caps">LISTEN      9933</span>/java<br />
tcp        0      0 ::ffff:127.0.0.1:10701      :::*                        <span class="caps">LISTEN      11937</span>/java<br />
tcp        0      0 :::10445                    :::*                        <span class="caps">LISTEN      11937</span>/java<br />
tcp        0      0 :::7888                     :::*                        <span class="caps">LISTEN      21265</span>/httpd.worker<br />
tcp        0      0 :::7889                     :::*                        <span class="caps">LISTEN      21265</span>/httpd.worker<br />
tcp        0      0 :::7890                     :::*                        <span class="caps">LISTEN      21265</span>/httpd.worker<br />
tcp        0      0 :::11443                    :::*                        <span class="caps">LISTEN      13741</span>/java<br />
tcp        0      0 :::11444                    :::*                        <span class="caps">LISTEN      13741</span>/java<br />
tcp        0      0 ::ffff:127.0.0.1:11701      :::*                        <span class="caps">LISTEN      13741</span>/java<br />
tcp        0      0 :::11445                    :::*                        <span class="caps">LISTEN      13741</span>/java<br />
tcp        0      0 :::22                       :::*                        <span class="caps">LISTEN      1840</span>/sshd<br />
tcp        0      0 :::12888                    :::*                        <span class="caps">LISTEN      17771</span>/httpd.worker<br />
tcp        0      0 :::12889                    :::*                        <span class="caps">LISTEN      17771</span>/httpd.worker<br />
tcp        0      0 :::12890                    :::*                        <span class="caps">LISTEN      17771</span>/httpd.worker<br />
tcp        0      0 :::13180                    :::*                        <span class="caps">LISTEN      15512</span>/java<br />
tcp        0      0 :::9180                     :::*                        <span class="caps">LISTEN      6404</span>/java<br />
udp        0      0 0.0.0.0:903                 0.0.0.0:*                               1575/rpc.statd<br />
udp        0      0 0.0.0.0:906                 0.0.0.0:*                               1575/rpc.statd<br />
udp        0      0 0.0.0.0:36701               0.0.0.0:*                               1920/avahi-daemon:<br />
udp        0      0 0.0.0.0:5353                0.0.0.0:*                               1920/avahi-daemon:<br />
udp        0      0 0.0.0.0:111                 0.0.0.0:*                               1539/portmap<br />
udp        0      0 :::59845                    :::*                                    1920/avahi-daemon:<br />
udp        0      0 :::5353                     :::*                                    1920/avahi-daemon:<br />
[root@i etc]#</p>

	<p>Selesai, tinggal mengatur konfigurasi lebih mendalam melalui pkiconsole dan web interface baik untuk user,agent,admin.&#160; Pada pembahasan lain akan saya buat integrasi menggunakan smart card yang dihubungkan dengan Enterprise Security Client dan Dog Tag.</p>

	<p>Red Hat Certificate System Documentation</p>

	<p><a href="https://www.redhat.com/docs/manuals/cert-system/">https://www.redhat.com/docs/manuals/cert-system/</a></p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/05/30/setup-public-key-infrastructure-dengan-dog-tag-certificate-system/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>menambah partisi ext3 secara online</title>
		<link>http://henry.gultom.or.id/index.php/archives/2010/05/11/menambah-partisi-ext3-secara-online/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2010/05/11/menambah-partisi-ext3-secara-online/#comments</comments>
		<pubDate>Tue, 11 May 2010 10:45:54 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[partition]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=1093</guid>
		<description><![CDATA[	Jika partisi pada harddisk anda penuh, bisa di resize secara online, artinya ditambah pada saat server sedang online atau produksi. Ini dilakukan pada sistem operasi linux yang memiliki partisi jenis ext3.

	Tujuan saya adalah menambah partisi root yang sebelumnya hanya 2 GB dan sudah penuh, untuk ini saya mau jadikan 4 GB.&#160; Caranya menggunakan fdisk dan [...]]]></description>
			<content:encoded><![CDATA[	<p>Jika partisi pada harddisk anda penuh, bisa di resize secara online, artinya ditambah pada saat server sedang online atau produksi. Ini dilakukan pada sistem operasi linux yang memiliki partisi jenis ext3.</p>

	<p>Tujuan saya adalah menambah partisi root yang sebelumnya hanya 2 GB dan sudah penuh, untuk ini saya mau jadikan 4 GB.&#160; Caranya menggunakan fdisk dan resize2fs,&#160; jangan takut kehilangan data, kalau mau backup dulu bisa juga, tapi dalam pekerjaan ini saya tidak backup.</p>

	<p>[root@ID41-ND013 gtoms]# /sbin/fdisk -l</p>

	<p>Disk /dev/xvda: 4294 MB, 4294967296 bytes<br />
255 heads, 63 sectors/track, 522 cylinders<br />
Units = cylinders of 16065 * 512 = 8225280 bytes</p>

	<p><span id="more-1093"></span></p>

	<p>Device Boot Start End Blocks Id System<br />
/dev/xvda1 * 1 261 2096451 83 Linux</p>

	<p>Disk /dev/xvdb: 1073 MB, 1073741824 bytes<br />
255 heads, 63 sectors/track, 130 cylinders<br />
Units = cylinders of 16065 * 512 = 8225280 bytes</p>

	<p>Disk /dev/xvdb doesn&#8217;t contain a valid partition table</p>

	<p>Disk /dev/xvdc: 2147 MB, 2147483648 bytes<br />
255 heads, 63 sectors/track, 261 cylinders<br />
Units = cylinders of 16065 * 512 = 8225280 bytes</p>

	<p>Disk /dev/xvdc doesn&#8217;t contain a valid partition table</p>

	<p>[root@ID41-ND013 gtoms]# /sbin/fdisk /dev/xvda</p>

	<p>Command (m for help): m<br />
Command action<br />
a toggle a bootable flag<br />
b edit bsd disklabel<br />
c toggle the dos compatibility flag<br />
d delete a partition<br />
l list known partition types<br />
m print this menu<br />
n add a new partition<br />
o create a new empty <span class="caps">DOS</span> partition table<br />
p print the partition table<br />
q quit without saving changes<br />
s create a new empty Sun disklabel<br />
t change a partition&#8217;s system id<br />
u change display/entry units<br />
v verify the partition table<br />
w write table to disk and exit<br />
x extra functionality (experts only)</p>

	<p>Command (m for help): p</p>

	<p>Disk /dev/xvda: 4294 MB, 4294967296 bytes<br />
255 heads, 63 sectors/track, 522 cylinders<br />
Units = cylinders of 16065 * 512 = 8225280 bytes</p>

	<p>Device Boot Start End Blocks Id System<br />
/dev/xvda1 * 1 261 2096451 83 Linux</p>

	<p>Command (m for help): d<br />
Selected partition 1</p>

	<p>Command (m for help): n<br />
Command action<br />
e extended<br />
p primary partition (1-4)<br />
p</p>
	<p>Partition number (1-4): 1<br />
First cylinder (1-522, default 1):<br />
Using default value 1<br />
Last cylinder or +size or +sizeM or +sizeK (1-522, default 522):<br />
Using default value 522</p>

	<p>Command (m for help): a<br />
Partition number (1-4): 1</p>

	<p>Command (m for help): w<br />
The partition table has been altered!</p>

	<p>Calling ioctl() to re-read partition table.</p>

	<p><span class="caps">WARNING</span>: Re-reading the partition table failed with error 16: Device or resource busy.<br />
The kernel still uses the old table.<br />
The new table will be used at the next reboot.<br />
Syncing disks.</p>

	<p>[root@ID41-ND013 gtoms]# reboot<br />
Broadcast message from root (pts/1) (Mon May 10 13:35:54 2010):</p>

	<p>The system is going down for reboot <span class="caps">NOW</span>!<br />
[root@ID41-ND013 gtoms]# Connection to 10.62.41.13 closed by remote host.<br />
Connection to 10.62.41.13 closed.</p>

	<p>[root@ID41-ND201 ~]# ssh 10.62.41.13 -l root<br />
root@10.62.41.13&#8217;s password:</p>

	<p>Setelah direboot bisa dicek partisi masih 2 GB</p>

	<p>[root@ID41-ND013 ~]# df<br />
Filesystem 1K-blocks Used Available Use% Mounted on<br />
/dev/xvda1 2030736 1783504 142412 93% /<br />
tmpfs 262144 0 262144 0% /dev/shm<br />
/dev/xvdc 2064208 68684 1890668 4% /opt</p>

	<p>Kita mulai resize partisi :</p>

	<p>[root@ID41-ND013 ~]# resize2fs /dev/xvda1<br />
resize2fs 1.39 (29-May-2006)<br />
Filesystem at /dev/xvda1 is mounted on /; on-line resizing required<br />
Performing an on-line resize of /dev/xvda1 to 1048233 (4k) blocks.<br />
The filesystem on /dev/xvda1 is now 1048233 blocks long.</p>

	<p>Cek kembali dan voila partisi sudah menjadi 4 <span class="caps">GB </span>:</p>

	<p>[root@ID41-ND013 ~]# df -h<br />
Filesystem Size Used Avail Use% Mounted on<br />
/dev/xvda1 3.9G 1.8G 2.0G 47% /<br />
tmpfs 256M 0 256M 0% /dev/shm<br />
/dev/xvdc 2.0G 68M 1.9G 4% /opt</p>

	<p>selesai.</p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2010/05/11/menambah-partisi-ext3-secara-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Instalasi Apache,Postfix FROM specific IPs,Bind,MySQL,Dovecot,DKIM,ISPConfig</title>
		<link>http://henry.gultom.or.id/index.php/archives/2009/08/31/instalasi-apache-postfix-bind-proftpd-mysqld-dovecot-dkim-mailgraph-pflogsumm-ispconfig/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2009/08/31/instalasi-apache-postfix-bind-proftpd-mysqld-dovecot-dkim-mailgraph-pflogsumm-ispconfig/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 19:11:27 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[ISPConfig]]></category>
		<category><![CDATA[Postfix]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[mailserver]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=744</guid>
		<description><![CDATA[	Instalasi Apache, Postfix FROM specific IPs, Bind, Proftpd, MySQL, Dovecot, Quota, DKIM, Mailgraph, pflogsumm,ISPConfig.

	Instalasi dan konfigurasi ini dilakukan pada salah satu server Qotexxx yang berada di Data Centre CalPOP Los Angeles. Pekerjaan dilakukan secara remote menggunakan putty ke server yang dalam kondisi awal sebagai berikut :

	Hardware server Intel&#174; Core&#8482;2 CPU 6300 @ 1.86GHz 32-bit, Memory [...]]]></description>
			<content:encoded><![CDATA[	<p><em>Instalasi Apache, Postfix <span class="caps">FROM</span> specific IPs, Bind, Proftpd, MySQL, Dovecot, Quota, <span class="caps">DKIM</span>, Mailgraph, pflogsumm,ISPConfig.</em></p>

	<p>Instalasi dan konfigurasi ini dilakukan pada salah satu server Qotexxx yang berada di Data Centre <a href="http://www.calpop.com/">CalPOP</a> Los Angeles. Pekerjaan dilakukan secara remote menggunakan putty ke server yang dalam kondisi awal sebagai berikut :</p>

	<p>Hardware server Intel&#174; Core&#8482;2 <acronym title="dual core">CPU</acronym> 6300 @ 1.86GHz 32-bit, Memory 2 GB, Sistem Operasi <a href="http://www.centos.org/">CentOS</a> 5.x&#160; 32-bit, berisi standart system instalasi dengan kernel 2.6.18-53.el5 dan&#160; ssh yang sudah terinstall baik. Ditambah 1 Allocated IP yang sudah up 216.240.142.1xx, dan daftar Addittional IP&#8217;s &#8211; 216.240.142.1xx-1xx yang belum dikonfigurasi. Guna addittional IP&#8217;s ini nanti untuk alokasi multi domain per IP, khususnya untuk pemakaian <span class="caps">SMTP</span> yang dalam hal ini menggunakan <a href="http://postfix.org">Postfix</a>.</p>

	<p>216.240.142.1xx- qotexxx.info<br />
216.240.142.1ss- qoteonlxxx.info<br />
216.240.142.1yy- qoteyyy.info<br />
216.240.142.1zz- qotesxxx.info<br />
216.240.142.1aa- qotesyy.info<br />
216.240.142.1bb- qotestxxx.info</p>

	<p>Kondisi basic installan sistem operasi dari data centre perlu di rapihkan dahulu, biasanya dapat instalasi yang kurang bersih dari pihak datacentre terhadap server tersebut. Setelah login mengunakan root, create new user baru dan disable login root melalui sshd_config dan kembali login menggunakan user biasa. Kemudian perhatikan service yang up dan matikan service yang tidak perlu seperti cupsd, sendmail,dsb. Setelah beres upgrade sistem operasi CentOS dengan yum update.</p>

	<p>Setelah kondisi rapih, reboot servernya untuk memastikan tidak ada masalah. Jika tidak up kordinasi dengan technical support CalPOP yang 24 jam.</p>

	<p>Berikut proses instalasi dan konfigurasi yang berhasil saya dokumentasikan dari putty saya.</p>

	<p><a href="http://henry.gultom.or.id/sandbox/instalasiApachePostfixBindProftpdMySQLDovecotDKIMMailgraphISPConfig.php"><strong>Dokumentasi Instalasi dan Konfigurasi.</strong></a></p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2009/08/31/instalasi-apache-postfix-bind-proftpd-mysqld-dovecot-dkim-mailgraph-pflogsumm-ispconfig/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Proyek di India</title>
		<link>http://henry.gultom.or.id/index.php/archives/2008/07/23/proyek-di-india/</link>
		<comments>http://henry.gultom.or.id/index.php/archives/2008/07/23/proyek-di-india/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 03:48:12 +0000</pubDate>
		<dc:creator>gtoms</dc:creator>
				<category><![CDATA[CentOS]]></category>
		<category><![CDATA[ISPConfig]]></category>
		<category><![CDATA[Postfix]]></category>
		<category><![CDATA[Project]]></category>
		<category><![CDATA[india]]></category>

		<guid isPermaLink="false">http://henry.gultom.or.id/?p=252</guid>
		<description><![CDATA[	Kebetulan aku ikut mailing list postfix-users@postfix.org dimana tempat ngumpulnya para pengguna Postfix di seluruh dunia. Penemu Postfix Wietse Venema&#8217;s juga ada dalam milist, beliau sangat aktif memberikan saran masukan dan sebagainya. Sehingga milist ini sangat bermanfaat dan hidup membahas permasalahan mailserver yang menggunakan postfix.

	Secara tidak sengaja aku menemukan salah satu postingan di milist tersebut yang [...]]]></description>
			<content:encoded><![CDATA[	<p>Kebetulan aku ikut mailing list <a href="http://www.postfix.org/lists.html">postfix-users@postfix.org</a> dimana tempat ngumpulnya para pengguna <a href="http://www.postfix.org/">Postfix </a>di seluruh dunia. Penemu Postfix <a href="http://en.wikipedia.org/wiki/Wietse_Venema">Wietse Venema&#8217;s</a> juga ada dalam milist, beliau sangat aktif memberikan saran masukan dan sebagainya. Sehingga milist ini sangat bermanfaat dan hidup membahas permasalahan mailserver yang menggunakan postfix.</p>

	<p>Secara tidak sengaja aku menemukan salah satu postingan di milist tersebut yang meminta/provide commercial installation &#038; support untuk mailservernya dengan 5 domain.</p>

	<p>Aku langsung kirim email ke yang bersangkutan dan berikut balasannya :</p>

	<p><em>I have few domains hosted. I need frontend from where I can add / remove email, change password &#038; check email. I am planning to host 5 domains initially.<br />
Outgoing emails would be authenticated by userID and password created through control panel. Mail server should be secured &#038; should not be open relay. I shall enable <span class="caps">SSH</span> so that you can access it remotely. I shall give you root access of the server.</em></p>

	<p><em>I have a budget of US$x00. Payment will be by paypal. 50% immediately &#038; balance 50% on completion.</em></p>

	<p><em>Let me know:<br />
1. Whether you have expertise to perform the above task.<br />
2. Whether terms and conditions are agreeable to you.</em></p>

	<p><em>Kindly reply<br />
K. Gandhi</em></p>

	<p>Setelah komunikasi melalui email dan yahoo messenger kita deal untuk harga dan requirement yang disepakati bersama. Client ku ini tinggal di Oshiwara, Mumbai, <a href="http://id.wikipedia.org/wiki/India">India</a>. Dan server yang akan di remote berada di Ohio <span class="caps">USA</span> dan dihost oleh xlhost.com merupakan server dedicated yang disewa clientku ini. Server dedicated ini sudah berisi sistem operasi Linux <a href="http://www.centos.org/">Centos</a> 5.2 dengan aplikasi ssh aktif dengan ip public/static sehingga bisa di remote. Spesifikasi servernya Intel Core 2 Duo <span class="caps">E4400</span>, 2.0GHz, 800MHz, 2MB <span class="caps">L2 </span>Cache 1GB <span class="caps">DDR2 RAM</span>, 80GB <span class="caps">SATA HDD</span>, 1000GB Transfer, 10Mbps Uplink, 5 <span class="caps">IP </span>Addresses.</p>

	<p>Waktu pekerjaan aku minta 2 hari karena aku tidak punya waktu 1 hari full untuk konsentrasi mengerjakan custom server nya, sehingga memakai sistem cicil dalam waktu-waktu istirahat dan tidurku.</p>

	<p>Proyek ini sukses dengan installasi pada&#160; OS: Centos 5.2 (Final) sbb : &#8211; <span class="caps">MTA</span>: Postfix &#8211; Domain Key (DKIM), for outgoing email &#8211; Control Panel:&#160; <span class="caps">ISP</span>Config &#8211; Statistics &#8211; MailGraph, Queuegraph &#8211; Antispam Spamassasin dan Anti virus Clamav &#8211; Dovecot( <span class="caps">POP3</span>, IMAP Server) &#8211; Squirrelmail webmail</p>

	<p>yang agak lama saat setting <a href="http://www.ispconfig.org/">ISPconfig</a>, untungnya ispconfig sangat cocok dengan Centos sehingga semua proses berjalan lancar tanpa ada kesulitan yang berarti. Setelah payment lewat paypal kuterima, aku baru tahu perusahaan clientku ini adalah <span class="caps">IKON </span>Infoservices Pvt Ltd yang berada di Mumbai India. Dari postfix dapat dollar deh.. :)</p>

	<p><img src="http://henry.gultom.or.id/images/ispconfigwisesoftwareindia.jpg" alt="" /></p>
 ]]></content:encoded>
			<wfw:commentRss>http://henry.gultom.or.id/index.php/archives/2008/07/23/proyek-di-india/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
