Jump to content

Fedora

From MukeWiki

Fedora



The Fedora Special Interest Groups (SIGs) are teams within the Fedora Project that are less formal than official subprojects. The SIGs are sometimes a first stage in the development of new projects within the Fedora Project.

The Fedora Minimal Core SIG is a group of people interested in maintaining Fedora's minimal package set. This is the Core group in the comps file, and any packages installed by the Anaconda installer by default. Stakeholders: Cloud SIG, Server SIG, Embedded SIG, etc.

SELinux

/etc/selinux/config

SELINUX=disabled   # after remove selinux-policy package is automatically set to disabled

Add selinux=0 option in your kernel command line (see #GRUB 2).

$ sestatus
SELinux status:                 disabled

Packages

# Fedora installed as Fedora Workstation (x86_64)

$ dnf remove \*PackageKit\* \*abrt\* \*virtual\* \*libvirt\* \*qemu\* \*openjdk\* # remove ~ 980 M (~ 300 packages)
$ dnf remove ibus-anthy ibus-chewing ibus-hangul ibus-libpinyin ibus-m17n ibus-setup ibus-typing-booster
$ reboot   # and disable SELinux
$ dnf remove orca yelp\* firefox-langpacks mediawriter baobab showtime decibels hunspell\*.noarch --exclude hunspell-en-US
$ dnf remove gnome-shell-extension\* gnome-user-docs gnome-tour gnome-backgrounds fedora-workstation-backgrounds
$ dnf remove gnome-calendar gnome-characters gnome-contacts gnome-maps gnome-software gnome-text-editor gnome-weather
$ dnf remove ModemManager lrzsz NetworkManager-adsl NetworkManager-openconnect NetworkManager-ppp NetworkManager-vpnc NetworkManager-wwan
$ dnf remove \*b43\* \*pcsc\* \*usb_modeswitch\* \*sane\* \*hplip\* -x linux-firmware   # unnecessary \*firmware\*
$ dnf remove jomolhari\* paktype\* sil\* \*cjk\* \*arabic\*
# https://rpmfusion.org/Configuration
$ dnf install https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm
$ dnf install https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm
$ dnf clean all; rm -rf /var/cache/libdnf5/; dnf upgrade
$ dnf install dconf-editor gnome-extensions-app gnome-tweaks gnome-usage
$ dnf install gcc-c++ gcc-gfortran binutils make cmake meson cppcheck clang clang-devel clang-tools-extra java java-devel
$ dnf install git git-tools rpm-build diffutils patch emacs ShellCheck shfmt openssl jq yq inotify-tools iotop-c
$ dnf install libX11-devel libXpm-devel libXft-devel libXext-devel openssl-devel mesa-libGL-devel glew-devel ftgl-devel pcre-devel libxml2-devel libuuid-devel giflib-devel krb5-devel systemd-devel zlib-devel lz4-devel tbb-devel xxhash-devel libzstd-devel
$ dnf install gtk3-devel gtk4-devel python-devel gl2ps-devel libAfterImage-devel gsl-devel sqlite-devel json-devel libcurl-devel
$ dnf install mod_fcgid fcgi-devel readline-devel fuse-devel perl-Image-ExifTool perl-Tk perl-Digest-MD5 perl-Pod-Usage perl-IO-Zlib perl-Archive-Extract-zip-Archive-Zip perl-sigtrap perl-Unicode-Normalize
$ dnf install ntfs-3g wol 7zip unrar qpdf cpdf ImageMagick libtiff-tools pdf2svg python-img2pdf catdoc odt2txt xclip gcolor3 ncdu # foliate genisoimage elinks
$ dnf install audacious audacious-plugins mediainfo
# https://rpmfusion.org/Howto/Multimedia
$ dnf swap ffmpeg-free ffmpeg --allowerasing
$ dnf install @multimedia --setopt="install_weak_deps=False" --exclude=PackageKit-gstreamer-plugin
$ dnf install vlc
# Print and Scan
$ dnf install sane-backends sane-backends-libs sane-airscan libsane-airscan
$ dnf install avahi avahi-glib avahi-libs avahi-tools
$ dnf install cups cups-client cups-filesystem cups-filters cups-libs
$ dnf install cups-browsed cups-filters-driverless cups-ipptool
$ dnf install hplip hplip-common hplip-libs   # optional
$ dnf install httpd mod_ssl certbot python-certbot-apache python3-augeas   vsftpd   mariadb-server   # fail2ban
$ dnf install php php-common php-pear php-xml php-mysqlnd php-intl php-gd php-mbstring php-pear-Net-Curl php-pecl-mcrypt ImageMagick-perl
fonts

minimum (optimal) needed fonts; lgc fonts family with Unicode coverage restricted to Latin, Greek and Cyrillic (no cjk for Chinese, Japanese and Korean)

$ dnf install liberation*fonts gnu-free*fonts   # gnu-free-mono-fonts uses Emacs

fonts needed only for legacy applications (xmms, xpdf, xdvi) xorg-x11-fonts-75dpi; ISO8859-1 (Latin-1 — Western European), ISO8859-2 (Latin-2 — Eastern European), ISO8859-5 (Cyrillic)

$ dnf install xorg-x11-fonts-ISO8859-1-75dpi     # needed for ROOT CERN

Hardware


# ASUS ROG STRIX B550-I GAMING
Intel Corporation Ethernet Controller I225-V   igc               none firmware
Intel Corporation Wi-Fi 6 AX200                iwlwifi           iwlwifi-mvm-firmware
ID 8087:0029 Intel Corp. AX200 Bluetooth       btusb (generic)   linux-firmware
$ sudo dmesg | grep -iE 'igc|iwlwifi|btusb|firmware'

# Super I/O chip Nuvoton NCT6798D-R, loaded kernel module nct6775, none firmware
# ASUS PRIME A520M-E
Realtek Semiconductor Co., Ltd. RTL8111/8168/8211/8411 PCI Express Gigabit Ethernet Controller
                                               r8169             linux-firmware
$ sudo dmesg | grep -iE 'r8169|firmware'

# Super I/O chip Nuvoton NCT6798D-R, loaded kernel module nct6775, none firmware
Dell XPS 13 7390, Late 2019
Intel Corporation Wi-Fi 6 AX200                iwlwifi           iwlwifi-mvm-firmware
ID 8087:0029 Intel Corp. AX200 Bluetooth       btusb (generic)   linux-firmware
$ sudo dmesg | grep -iE 'iwlwifi|btusb|firmware'
ASUS TUF GAMING B850M-PLUS WIFI7
Realtek Semiconductor Co., Ltd. RTL8125 2.5GbE Controller                 r8169     linux-firmware
MEDIATEK Corp. MT7925 802.11be 160MHz 2x2 PCIe Wireless Network Adapter   mt7925e   mt7xxx-firmware
ID 13d3:3602 IMC Networks Wireless_Device                 btusb depend on btmtk     mt7xxx-firmware
$ sudo dmesg | grep -iE 'r8169|mt7925e|btusb|btmtk|bluetooth|firmware'

# Super I/O chip Nuvoton NCT6701D-R, currently kernel 7.2 without kernel module
NOTE NCT6701D = 0xD806, temporary solution [2] or [3]

fwupd

This project is configured by default to download firmware from the Linux Vendor Firmware Service (LVFS).

$ fwupdmgr get-devices     # display all devices detected by fwupd
$ fwupdmgr refresh         # download the latest metadata from LVFS
$ fwupdmgr get-updates     # display updates available for any devices on the system
$ fwupdmgr update          # download and apply all updates for your system (be careful)

Bluetooth dual boot pairing problem

Export your Windows Bluetooth LE (low energy) keys into Linux: https://gist.github.com/Mygod/f390aabf53cf1406fc71166a47236ebf

$ python export-ble-infos.py -s /mnt/win_c/Windows/System32/config/SYSTEM

To co script vytvoril (napr. subor bluetooth/84:C5:26:92:9C:B8/C9:E4:BB:E6:D3:8A/info) jednoducho skopirovat do /var/lib/bluetooth/ dir a restartnut bluetooth.service. See also [4] or [5].

System config

mc fix ssh (fish) seconds

/usr/libexec/mc/fish/ls in function fish_list_perl

my $mloctime= strftime("%m-%d-%Y %H:%M", localtime $mtime);
# replce by
my $mloctime= strftime("%m-%d-%Y %H:%M:%S", localtime $mtime);

kvm: disabled by bios

/etc/modprobe.d/kvm-blacklist.conf

blacklist kvm
blacklist kvm_intel
blacklist kvm_amd

$ lsmod | grep kvm
kvm                   585728  0
$ modprobe -r kvm


Wget

  • disable HSTS policy (wget --no-hsts, no more ~/.wget-hsts)

/etc/wgetrc

hsts = off

PulseAudio

/etc/pulse/default.pa

# .ifexists module-esound-protocol-unix.so
# load-module module-esound-protocol-unix
# .endif

GRUB 2

$ grub2-mkconfig -o /boot/grub2/grub.cfg
$ grub2-set-default 2     # 0 - Fedora, 1 - Fedora recovery, 2 - Windows
$ grub2-editenv list

/etc/default/grub

GRUB_TIMEOUT=5
GRUB_DISTRIBUTOR="$(sed 's, release .*$,,g' /etc/system-release)"
GRUB_DEFAULT=saved
GRUB_DISABLE_SUBMENU=true
GRUB_TERMINAL_OUTPUT="console"
GRUB_CMDLINE_LINUX="rhgb quiet selinux=0 ipv6.disable=1"
GRUB_DISABLE_RECOVERY="true"
2024-10, ToDo
https://thelinuxforum.com/articles/712-how-to-add-remove-kernel-boot-parameters-arguments-and-grub-boot-entries-on-fedora-rhel-almalinux-rocky-linux-centos-stream
GRUB 2 default boot entry

2023-02

$ grub2-editenv list
boot_success=1
boot_indeterminate=0
saved_entry=23ab04fdeb0e4e589bb30befde0cb2f1-6.1.10-200.fc37.x86_64

Subor /etc/default/grub obsahuje (by default) directive GRUB_DEFAULT=saved, a teda, GRUB 2 nahra directive saved_entry=23ab04fdeb0e4e589bb30befde0cb2f1-6.1.10-200.fc37.x86_64 zo suboru /boot/grub2/grubenv, ktora obsahuje (by default) meno posledneho instalovaneho kernel balika, co je definovane UPDATEDEFAULT=yes a DEFAULTKERNEL=kernel-core directives v subore /etc/sysconfig/kernel.

/etc/sysconfig/kernel

# UPDATEDEFAULT specifies if kernel-install should make new kernels the default
UPDATEDEFAULT=yes

# DEFAULTKERNEL specifies the default kernel package type
DEFAULTKERNEL=kernel-core

INFO upgrade kernel balika vobec "nesaha" na subor /boot/grub2/grub.cfg, ale len doplni subor 23ab04fdeb0e4e589bb30befde0cb2f1-6.1.10-200.fc37.x86_64.conf (entry polozku) v dir /boot/loader/entries/. V pripade UPDATEDEFAULT=yes prepise v subore /boot/grub2/grubenv hodnotu saved_entry na aktualny kernel.

Zamena default boot hodnoty (aktualny kernel balik) na Windows
$ readlink -f /etc/grub2.cfg
/boot/grub2/grub.cfg
$ awk -F\' '$1=="menuentry " {print $2}' /boot/grub2/grub.cfg
$ grep -P "^menuentry" /boot/grub2/grub.cfg | cut -d "'" -f2   # grep "menuentry" /boot/grub2/grub.cfg
Windows Boot Manager (on /dev/nvme0n1p1)
moznost 1 (not recommended)

Simple way of setting the default entry, but they are prone to error if/when grub2-mkconfig is re-run. These include directly setting the default in /boot/grub2/grub.cfg or setting GRUB_DEFAULT to either a number or an entry title in /etc/default/grub. Neither of these methods is recommended (more info).

Priama zamena directive GRUB_DEFAULT=saved v subore /etc/default/grub na GRUB_DEFAULT="Windows Boot Manager (on /dev/nvme0n1p1)".

$ grub2-mkconfig -o /boot/grub2/grub.cfg
$ grub2-editenv list
boot_success=1
boot_indeterminate=0
saved_entry=23ab04fdeb0e4e589bb30befde0cb2f1-6.1.10-200.fc37.x86_64
moznost 2 (recommended)

Directive GRUB_DEFAULT=saved v subore /etc/default/grub zostava default, nezmenena.

$ grub2-set-default "Windows Boot Manager (on /dev/nvme0n1p1)"   # pripadne poradove cislo
$ grub2-editenv list
boot_success=1
boot_indeterminate=0
saved_entry=Windows Boot Manager (on /dev/nvme0n1p1)

Tato zamena bude fungovat len do chvile, kedy prebehne upgrade na novsi kernel, ktory prepise hodnotu saved_entry (subor /boot/grub2/grubenv) na novsiu verziu kernel. V pripade ak potrebujeme permanentne boot-vat do Windows, zamiename UPDATEDEFAULT=yes na UPDATEDEFAULT=no v subore /etc/sysconfig/kernel.

Na rozdiel od prvej moznosti, nie je potrebne volat grub2-mkconfig, a teda, ani samotny subor /boot/grub2/grub.cfg sa nijako nemeni.

POZOR na directive GRUB_SAVEDEFAULT v subore /etc/default/grub. By default, sa tato directive v subore vobec nenachadza, resp. nie je nastavena, co je ekvivalent GRUB_SAVEDEFAULT=false. If GRUB_SAVEDEFAULT is set to true, then, when an entry is selected, save it as a new default entry for use by future runs of GRUB. So, maybe, you need be sure that GRUB_SAVEDEFAULT is not set to true. GRUB_SAVEDEFAULT is only useful if GRUB_DEFAULT is saved (more info).

dalej
GRUB_CMDLINE_LINUX_DEFAULT="nouveau.modeset=0 rdblacklist=nouveau"   # nVidia driver
GRUB_CMDLINE_LINUX_DEFAULT="nouveau.modeset=0 rd.driver.blacklist=nouveau video=vesa:off vga=normal"

GRUB_THEME="/boot/grub2/themes/system/theme.txt"

GRUB_GFXMODE=1280x1024
GRUB_FONT=/boot/grub2/DejaVuSansMono18.pf2
GRUB_GFXPAYLOAD_LINUX=keep
GRUB_BACKGROUND=/usr/share/backgrounds/path/image.png
  • Neodporuca sa menit parameter GRUB_DEFAULT=saved, namiesto toho spustit prikaz grub2-set-default, ktory vygeneruje, modifikuje subor /boot/grub2/grubenv
  • Pouzivanie parametra vga=788 sa povazuje za zastarale a neodporuca sa, namiesto neho sa preferuje pouzitie paramametra GRUB_GFXMODE=1280x1024
  • Ake GRUB_GFXMODE podporuje graficka karta mozno zistit po vchode do console z GRUB2 menu
  1. stlacit "c" pre vchod do GRUB2 console
  2. spustit nasledujuce prikazy v console
grub> set pager=1
grub> insmod vbe
grub> vbeinfo
  • GRUB_FONT mozno vygenerovat pomocou grub2-mkfont
    $ grub2-mkfont --size=18 --output=/boot/grub2/DejaVuSansMono18.pf2 /usr/share/fonts/dejavu/DejaVuSansMono.ttf
  • install the bootloader (grub2 to hard drive) without chroot
$ fdisk -l
Device     Boot     Start       End  Sectors  Size Id Type
/dev/sda1  *         2048  81922047 81920000 39.1G 83 Linux => root directory (with /boot dir)
/dev/sda2        81922048 143362047 61440000 29.3G 83 Linux
/dev/sda3       143362048 234440703 91078656 43.4G 83 Linux

/dev/sdb1            2048  524290047  524288000   250G 83 Linux
/dev/sdb2       524290048 1953525167 1429235120 681.5G 83 Linux
$ mount /dev/sda1 /mnt      (with /mnt/boot dir)
$ mount /dev/sdaX /mnt/boot (only if root directory without /boot dir)
$ grub2-install --boot-directory=/mnt/boot /dev/sda (or try with option --recheck)
$ grub2-mkconfig -o /boot/grub2/grub.cfg (only if needed)

Disk partitions

2024-02
# blockdev --getalignoff /dev/sda   # '0' if the partition is aligned

Automatic trim (using the discard mount option) trims freed blocks on sync after any file is deleted, whereas manual trim (using fstrim) trims all the free space at once. There is no need for the discard (mount) flag if you run fstrim periodically. Don't use discard mount option, prefer fstrim.

# fstrim --all --verbose
# systemctl status fstrim.timer
$ findmnt
$ findmnt --types ext4,tmpfs
$ cat /proc/mounts
$ blkid
$ cat /usr/lib/systemd/system/tmp.mount

The biggest issue with atime is SSD write cycles. An SSD has a life that is measured in number of write cycles. With atime enabled, every read results in a write, to update the atime. When a write takes place on an SSD, a whole block must be read, changed and rewritten.

$ findmnt --target /home 
TARGET SOURCE         FSTYPE OPTIONS
/home  /dev/nvme0n1p4 ext4   rw,relatime

Prefer noatime mount option (maximum performance) before the default relatime mount option (compromise). From mount(8), noatime works for all inode types (directories too), so it implies nodiratime.

/etc/fstab

UUID=a1b2c3d4-a1b2   /            ext4    defaults,noatime     1 1
UUID=a1b2c3d4-a1b2   /boot        ext4    defaults,noatime     1 2
UUID=a1b2-a1b2       /boot/efi    vfat    umask=0077,shortname=winnt 0 2
UUID=a1b2c3d4-a1b2   /home        ext4    defaults,noatime     1 2
UUID=a1b2c3d4-a1b2   /mnt/free    ext4    defaults,noatime     1 2
UUID=a1b2c3d4e5f6    /mnt/win_c   ntfs    default,ro   0 0

# nfs
strela-stor.jinr.ru:/vol/vol1/strela   /strela-stor   nfs   defaults,noatime 0 0

Fonts

Adding new fonts (as admin) into system dir /usr/local/share/fonts/ or /usr/share/fonts/ or (as user) into ~/.local/share/fonts/ user dir (using dir ~/.fonts/ is obsolete, deprecated). Then update the fontconfig font cache by fc-cache -v command (fc-cache on x64 architecture is fc-cache-64 command).

Disable bitmap fonts

V pripade ak pouzivame (LibreOffice), resp. sme donuteni (Linux + Firefox + MS Outlook + Calibri fonts) pouzivat Microsoft fonts, mozu fonts vyzerat "nepekne", resp. nie su korektne renderovane [6], [7]. MS fonts pouzivaju tzv. embedded bitmaps a pre korektne zobrazovanie v Linux je ich potrebne zakazat, [8].

$ fc-match --verbose Cantarell | grep embeddedbitmap   # or any other fonts
embeddedbitmap: True(s)
$ wget https://raw.githubusercontent.com/musinsky/config/master/fontconfig/20-no-bitmap-all-fonts.conf \
  -P /etc/fonts/conf.d/
$ fc-cache
$ fc-match --verbose Cantarell | grep embeddedbitmap
embeddedbitmap: False(w)

NOTE Vo Fedora sa nachadza subor /etc/fonts/conf.d/25-no-bitmap-fedora.conf, ten vsak zakazuje embeddedbitmap len pre specificke (azijske) fonts.

Free fonts family (typeface)

Pozor nie vsetky fonty, ktore deklaruju, ze plne podporuju znaky pre konkretny jazyk, ich v skutocnosti aj podporuju, napr. problemy s ceskou diakritikou pre niektore fonty z Google Fonts.

Cantarell

Default fonts pre GNOME3 prostredie, nahradzaju predchadzajuce DejaVu fonts. GNOME Cantarell povodne podporovali len Latin jazyky, neskor pridana podpora aj pre napr. Cyrillic alebo Greek. GNOME Cantarell nativne neobsahuju italics or oblique glyphs, na rozdiel od Google Cantarell. Neobsahuju mono fonty. GNOME v Ubuntu (by default) pouziva vlastne Ubuntu fonts.

$ dnf install abattis-cantarell-fonts abattis-cantarell-vf-fonts   # installed by default on Fedora
$ fc-list | grep -i cantarell
Exo 2

Cca od roku 2020 sa fonty nachadzaju priamo aj v repo pre Fedoru. Exo 2 neobsahuju mono fonty a len ciastocna podpora pre grecke znaky.

$ dnf install ndiscover-exo-2-fonts
$ fc-list | grep -i exo
Roboto

Roboto family fonts: Roboto (google-roboto-fonts), Roboto Condensed (google-roboto-condensed-fonts), Roboto Mono (google-roboto-mono-fonts) and Roboto Slab (google-roboto-slab-fonts).

$ dnf install google-roboto-fonts google-roboto-condensed-fonts \
              google-roboto-mono-fonts google-roboto-slab-fonts
$ fc-list | grep -i roboto
2024-12 fonts


MS Word supports 4 styles per font: regular, bold, italic and bold italic. So if you have more styles, you should split it into subfamilies. Also you may need to modify fsSelection for Bold/Italic styles source.

Network

# 'muke.saske.sk' is DNS name (FQDN), 'saske.sk' is DNS domain name and 'muke' is hostname

$ sudo hostnamectl hostname muke   # hostnamectl(1)rpm
$ cat /etc/hostname
muke
$ dig -t NS saske.sk   # dig(1)rpm
;; ANSWER SECTION:
saske.sk.		86400	IN	NS	ns1.saske.sk.
saske.sk.		86400	IN	NS	ns2.saske.sk.
saske.sk.		86400	IN	NS	ns3.saske.sk.
$ dig +short ns1.saske.sk ns2.saske.sk ns3.saske.sk
147.213.192.3
147.213.196.3
147.213.192.31

Services and Daemons

  • Although it is still possible to use the chkconfig a service utilities to manage services that have init scripts installed in the /etc/rc.d/init.d/ directory, it is advised that you use the systemctl utility
$ systemctl stop NetworkManager.service
$ systemctl disable NetworkManager.service
$ chkconfig --levels 35 network on            # obsolete (not prefer) way
$ service network start                       # obsolete (not prefer) way
  • systemctl control the systemd system and service manager, that uses services files located in /usr/lib/systemd/system/ for services, and /etc/systemd/system/ for configuration
$ systemctl
$ systemctl action service_name.service       # action = enable, disable, start, stop, restart, is-enabled, is-active, status, cat
$ systemctl list-units --type=service
$ systemctl status chronyd.service

$ systemctl enable mariadb.service
Created symlink '/etc/systemd/system/mysql.service' → '/usr/lib/systemd/system/mariadb.service'.
Created symlink '/etc/systemd/system/mysqld.service' → '/usr/lib/systemd/system/mariadb.service'.
Created symlink '/etc/systemd/system/multi-user.target.wants/mariadb.service' → '/usr/lib/systemd/system/mariadb.service'.
$ systemctl start mariadb.service     # /var/log/mariadb/   (750, mysql:mysql)

$ systemctl enable httpd.service
Created symlink '/etc/systemd/system/multi-user.target.wants/httpd.service' → '/usr/lib/systemd/system/httpd.service'.
$ systemctl start httpd.service       # /var/log/httpd/   (700, root:root)
systemctl is-active --quiet service && echo service is running   # in bash script
  • TRIM Support (SSD disks)
$ systemctl enable fstrim.timer
$ systemctl cat fstrim.timer
  • user mask service
$ systemctl --user mask any.service
Created symlink /home/musinsky/.config/systemd/user/any.service → /dev/null.
chronyd
# Fedora 42: NTP (Network Time Protocol) with NTS (Network Time Security)
$ systemctl is-active chronyd.service    # package chrony
active

$ chronyc sourcestats
Name/IP Address            NP  NR  Span  Frequency  Freq Skew  Offset  Std Dev
==============================================================================
time2.uni-paderborn.de      7   3  103m     +0.047      0.491   -395us   454us
ernie.gerger-net.de        13  11   86m     -0.007      0.016    +57us    20us
srv3n.blesmrt.net           6   3   85m     -0.179      0.417  -2205us   190us
stratum2-1.NTP.TechFak.N>  12   6  172m     +0.074      0.057   +250us   119us
sshd

NOTE Povodne program scp pouzival SCP protokol, ktory je uz dnes zastaraly a neodporuca sa dalej pouzivat. Namiesto SCP sa dnes pouziva SFTP protokol, resp. program sftp. Od verzie OpenSSH 9.0 (2022-04-08) aj program scp pouziva (by default) odporucany SFTP protokol.

$ systemctl enable sshd.service
Created symlink '/etc/systemd/system/multi-user.target.wants/sshd.service' → '/usr/lib/systemd/system/sshd.service'.
$ systemctl start sshd.service
  • /etc/ssh/sshd_config
PermitRootLogin no     # disable root access
PermitRootLogin without-password
  • /etc/motd

Message of the day with ASCII Text Signature Generator (standard font + kerning) or with figlet(6)rpm command

figlet -k $(hostname -s) > /etc/motd

Warning problem with "passwordless" login on CentOS Stream release 8

$ tail /var/log/secure
Jan 24 17:27:43 old-work sshd[3696]: Authentication refused: bad ownership or modes for directory /home/musinsky
$ ls -l -d /home/musinsky
drwx------. 22 musinsky musinsky 12288 Jan 24 17:09 /home/musinsky   # (access 0700) Fedora 37, OK
drwxrwxr-x.  7 musinsky musinsky 4096  Jan 24 17:10 /home/musinsky   # (access 0775) CentOS Stream 8, problem

Change /home/musinsky directory permission to 755 (or 700), but not 775.

vsftpd
# systemctl enable vsftpd.service
Created symlink '/etc/systemd/system/multi-user.target.wants/vsftpd.service' → '/usr/lib/systemd/system/vsftpd.service'.
# systemctl start vsftpd.service 

/etc/vsftpd/vsftpd.conf

anonymous_enable=NO

listen=YES
# listen_ipv6=YES
user LS_COLORS

see /etc/DIR_COLORS

export LS_COLORS="$LS_COLORS:di=01;30"
user and autostart applications
  • disable evolution services
$ systemctl --user list-unit-files | grep evolution
$ systemctl --user mask evolution-addressbook-factory.service evolution-alarm-notify.service evolution-calendar-factory.service evolution-source-registry.service evolution-user-prompter.service
  • disable autostart desktop application

/etc/xdg/autostart/

Potrebujem zakazat napr. migrates user settings from GConf to dconf, zmazanim suboru rm /etc/xdg/autostart/gsettings-data-convert.desktop sa dana aplikacia ani jednoducho nespusti. Toto je vsak len "docasne" riesenie, kedze system po update (alebo nejakej inej zmene) moze tento subor znova vygenerovat.

Desktop Application Autostart Specification odporuca "when the .desktop file has the Hidden key set to true, the .desktop file MUST be ignored". Aby nam vsak system tento subor (aj s Hidden key) po nejakom case (napr. update) neprepisal, skopirujeme subor do $XDG_CONFIG_HOME = ~/.config/autostart/. Do skopirovaneho suboru potom pridame Hidden=true key.

$ cp /etc/xdg/autostart/gsettings-data-convert.desktop ~/.config/autostart/
$ echo -e "Hidden=true" >> ~/.config/autostart/gsettings-data-convert.desktop
  • disable GNOME Tracker (desktop autostart application)

/etc/xdg/autostart/tracker-{extract,miner-apps,miner-fs,miner-rss,store}.desktop

Jednotlive aplikacie mozem zakazat pomocou Hidden=true key (pripadne jednoducho zmazanim suborov, ale len docasne riesenie). Samotny tracker sice bude bezat, ale nebude nic indexovat. Najjednoduchsie je uplne zakazat tracker services, nebude spusteny a teda nebude ani indexovat (package tracker nemozem odinstalovat zo systemu !!! na F31 uz je to mozne !!!).

$ systemctl --user list-unit-files | grep tracker
$ systemctl --user mask tracker-extract-3.service tracker-miner-fs-3.service tracker-miner-fs-control-3.service tracker-miner-rss-3.service tracker-writeback-3.service tracker-xdg-portal-3.service
# 2026-05
$ systemctl --user mask localsearch-3.service localsearch-control-3.service localsearch-writeback-3.service
2024-08

https://github.com/Lennart1978/servicemaster

FirewallD

$ systemctl status firewalld.service
● firewalld.service - firewalld - dynamic firewall daemon
     Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; preset: enabled)

default settings (for all zones) in directory /usr/lib/firewalld/zones/

$ firewall-cmd --get-default-zone
FedoraWorkstation
$ firewall-cmd --set-default-zone=FedoraServer
$ dnf install cockpit # must be installed
$ firewall-cmd --permanent --zone=FedoraServer --add-service=http     # modify (or create) file /etc/firewalld/zones/FedoraServer.xml
$ firewall-cmd --permanent --zone=FedoraServer --add-service=ftp
$ firewall-cmd --permanent --zone=FedoraServer --add-service=mdns     # avahi

$ firewall-cmd --permanent --zone=FedoraServer --add-port=5555/tcp
$ firewall-cmd --permanent --zone=FedoraServer --add-port=5556/tcp

$ firewall-cmd --permanent --zone=FedoraServer --add-port=1714-1764/tcp
$ firewall-cmd --permanent --zone=FedoraServer --add-port=1714-1764/udp

$ firewall-cmd --reload
$ firewall-cmd --get-services     # list of all supported services
$ firewall-cmd --list-all-zones
$ firewall-cmd --get-zones
FedoraServer FedoraWorkstation block dmz drop external home internal public trusted work
$ firewall-cmd --get-active-zones
FedoraServer
  interfaces: eno1
$ firewall-cmd --zone=external --change-interface=em1
external: em1
$ firewall-cmd --zone=external --list-all
$ firewall-cmd --zone=external --add-port=1234/tcp
$ firewall-cmd --zone=external --remove-port=1234/tcp
# allow IP address
$ firewall-cmd --permanent --zone=FedoraServer --add-rich-rule="rule family="ipv4" source address="159.93.0.0/16" port protocol="tcp" port="7503" accept"

$ firewall-cmd --zone=external --add-rich-rule="rule family="ipv4" source address="147.213.192.75" accept"
# port forwarding
$ firewall-cmd --permanent --zone=FedoraServer --add-forward-port=port=443:proto=tcp:toport=7503
$ firewall-cmd --permanent --zone=FedoraServer --add-port=443/tcp

$ firewall-cmd --zone=external --add-forward-port=port=22:proto=tcp:toport=4321:toaddr=10.0.0.1