Wednesday, 16 August 2023
Google Domains Exits Beta... And Promptly Gets Divested!
Thursday, 17 November 2022
Autofs with SMB
"autofs" software for Ubuntu and other Linux systems mounts file systems and network shares on demand and there are a couple key benefits to using autofs compared to fstab and other methods and I've posted before about Autofs and a couple tricks with NFS shares.
- File share does not have to be available on boot so faster boot times and fewer failures after restart
- File share is unmounted when not in use reducing system resources on client and server side
- Consistent abstraction of mounts is easier to maintain across systems
Giant caveat that Linux does not segregate permissions once a share is mounted. This is fine for single-user systems and also fine where systems are un-attended (i.e. servers) but really a big problem on multi-user systems that user a and user b can both access share Z once it is mounted and it is as the connected user.
The Ubuntu standard "autofs" package includes an "auto.smb" which dynamically configures the shares in most cases so long as credentials are available and some basic pre-work is done. This should work for generic needs but for file share specific configurations use the auto.misc instead
Required packages to work with SMB shares (i.e. on Windows) and mounting with the stock CIFS driver (i.e. same old driver in Linux).
apt install autofs smbclient cifs-utils
The auto.smb file itself doesn't have to be configured, if you look in the file it advises what configuration to add to "auto.master" and how to setup credentials.
# edit /etc/auto.master and add this line
/cifs /etc/auto.smb --timeout=300
# create /etc/creds with restricted permissions
sudo mkdir -m 700 /etc/creds
# edit a file with the server name like /etc/creds/MYNAS
username=myuser
password=reallygoodpassword
# restart autofs
sudo systemctl restart autofs
As any user you should be able to list shares and access contents of any available share the configured user has access to.
# shows all shares on the server (not hidden ones)
ls /cifs/MYNAS
# access files as normal within a share
ls /cifs/MYNAS/MyShare
If file shares or the contents do not appear, check "mount" and system logs for hints what may be wrong. Biggest caveat I had had was that cifs-utils really are required and I'm pretty sure smbutils as well - out of the box autofs with the stock system drivers and packages may have been able to do SMB1 but SMB1 should be disabled on any file servers so yeah, need to get "cifs-utils" package which includes tools to work with the newer SMB2 and SMB3 protocols.
Tuesday, 24 May 2022
Another Round?
We eventually saw Google change their tack with The Return of the Google Apps Free Accounts. It was pretty unnerving to lose services which had been free for over a decade. Really the services are free anyhow: Email in Gmail, custom domains in Google DNS, cloud storage in Drive, basic web hosting in Sites and Blogger. Why wasn't there are a better migration tool? Google has been eroding the GA free for years and all we really needed was a migration tool to get like 80% migrated to Gmail etc and this push could have been more successful. But then again, how many users signed up for GA a decade ago and are still using it? I know we're free-loaders but really the "free" services are doing for Google what they're supposed to: Get users hooked on Google's suite of services.
</rant>
Dom617b
Sunday, 20 March 2022
The Party For Grandfathers' Free Google Apps Is Over
With the end of Google Apps free accounts I've been looking at what services end up where and Google is pretty well covering personal use with maybe a few asterisks particularly around email.
TL;DR
Setup Email Forwarding in Google Domains by adding up to 100 email aliases.
Send an email from your alias in Gmail
- Generate your app password
- Add an email alias
- Confirm the address
- Change the "From" address
- Optionally set this address as default sending address once confirmed.
Use Google Sites or Blogger and add custom URLs and they will generate the DNS entries as needed.
<Rant>
Google Domains "is out of Beta" ... Uh what? I've been using Google Domains for a few years already and didn't realise it was a "Beta". It did mean they sent out promo codes to all their existing "beta" customers so we can get 20-30% off their regular price registrations
I took the opportunity to register a test domain to test out some of the changes for when the GA free accounts go away shortly. As far as DNS registration and hosting goes it's a pretty good offering. Not the cheapest, but does include WHOIS privacy, integration with website services, and up to 100 email addresses forwarded for free.
The website services is a handy integration including with free services both on Google Sites and on Blogger (i.e. this site). It automatically creates DNS records when you create custom domain. Maybe it's more intuitive for a lay person than an IT pro because on Blogger you click the option for "custom domain" and type in whatever you want and if it's in a domain under your account it just registers it? I guess? Not clear it doesn't tell you a lot which is maybe point - it's all very easy.
Email I was really struggling with because there seem to be a lot of variables. We're using plain old Gmail account and there's two parts to deal with custom domains: receiving and sending. The receiving side is simple - add an alias in Google Domains (or 100) and you're done.
Sending is far more complicated which I chalk up to "we can't have nice things". In Gmail you can add an alias with another Gmail account and that setup is pretty easy "mymail1@gmail.com" can be added in your settings as an alias for "mymail2@gmail.com". To use an alias with a custom domain you have to give a mail server and you can use the Gmail SMTP but you need an app password. And you can only use an app password if you have 2FA on your account. And if you don't have 2FA you can use "less secure authentication". But that's a feature apparently getting dropped soon so if we follow all the caveats, it means you have to use 2FA and app passwords. There's Google docs all over the place - the above link in the TLDR I think has the necessary info.
Compared to how easy it is to do one Gmail address as an alias for another this was a bit mind boggling to go through. I get it - Google wants to sell as many Workspace accounts as they can, and lots of other options just don't work in the 21st century because we ruined the Internet and Email with so much spam.
Sunday, 5 December 2021
Restoring from Gmail Backup
Migrating to a new Gmail email account is a lot easier using Google Takeout this Thurderbird Add-on ImportExportTools NG. I have been splitting up my email accounts so that I have several distinct accounts - more on that below. The gist was that in the past I was forwarding all mail into one account which I'm no longer doing but now I want to move all that old mail, ~30,000 emails, into a different mailbox. Recommendations online were to connect Thunderbird to the two accounts and move messages in batches but in practice Gmail times out these connections very quickly and the batches are way too small. Instead I ended up exporting my email and importing it - why Google does not offer an import of the format in which they export boggles the mind, and while it's possible I've simply missed proper screen where this can be done, somehow I think not. This seems to be one of those things that is easy enough, but not obvious and took a bit of searching.
The easiest process I found was to use the ImportExportTools Add-on:
- Spring cleaning time of your old email! Newsletters and automated notifications that were being filtered to a folder go 💥, gone.
- Go to Google Takeout and export mail. This produces a ZIP file which you can extract and there is a single large MBOX format file
- Install Thurderbird and the ImportExportTools NG add-on
- Import the MBOX as a local folder with ImportExportTools
- Re-Export the email from local folder to a directory of EML files with ImportExportTools
- Connect Thunderbird to your new email account
- Import with ImportExportTools "all messages from a directory" and import into your "All Mail" folder
- Wait. ... Wait ... Ponder if you should have done more aggressive cleaning... And wait. My mailbox I think it ran at least 3 hours? Not sure, but a lot time, many hours.
- Tada! Go into your Gmail account and try a few searches and see if you got everything you expected.
Sunday, 8 August 2021
Some Bits to Remember About Synology Standard Operating Procedures
- Open Control Panel
- Navigate to Shared Folder
- Select the share with the closed lock
- Encryption menu
- Mount
- Provide passphrase (if applicable)
Friday, 23 April 2021
Now Certified
Passed my Microsoft Azure Fundamentals certification this week and this is my first Microsoft exam. My primary resource was Microsoft Learn where there is a lot of material broken up into 30-60 minute lessons including some labs. Also used the practice tests and did those many times before writing the cert exam itself.
Tuesday, 30 March 2021
Passwords Passwords Everywhere
Monday, 8 March 2021
Azure Fundamentals, PowerShell, and More
- Learn Windows PowerShell in a Month of Lunches by Don Jones and Jeffery Hicks
- Learn PowerShell Scripting in a Month of Lunches by Don Jones and Jeffery Hicks
Sunday, 22 November 2020
New Website Name: Dom617b
Welcome to Dom617b!
At least if I've setup all the new names, redirects, and certificates. Otherwise, you're not seeing this for which I have only myself to blame. The process I think could have been simple and I'll add a few notes about where Google is tying in services.
- Go to Blogger Settings and change the name
- Disabling HTTPS first may have made things a little easier as it was initially hard to follow the redirects while that was still changing
- Change the Custom Domain to the new name
- Update DNS and with Google Domains this is at least partially integrated
- In Google Domains, verify that the "synthetic record" is registered
- OR setup DNS CNAME pointing to ghs.google.com
- Redirect old name to new and in Google Domains there is a forwarding feature
- Remove the old CNAME
- Add a forwarding entry with settings as applicable
- 301 Permanent redirect
- Redirect full path (i.e. oldsite/page.html -> newsite/page.html vs to newsite/)
- Enable HTTPS redirection
- Wait - like a day or two
- New name was resolving fine within a few minutes really
- Redirects were almost instant
- HTTPS was the slowest part
- In Blogger Settings turn on HTTPS and redirect to HTTPS if not already done
Its long past time to move on from the online handle I was using in high school so here I am Dom617b! The 617b is what I use when I can't get my own name or handle when registering for some site so that ties in to the old part, plus "617" kinda looks like "bit" in 1337 and "b" for binary, so it all comes together as a Nibble handle.
Ciao
Dom617b
Saturday, 26 September 2020
Home NAS Part 3: Encryption
The Synology DSM supports creating encrypted file shares and I want to use this for backups as these can contain personal files. Initial setup seems pretty flexible as you can create a share with encryption or enable encryption on an existing share and you can use key files or pass phrases and there's a feature called a Key Manager with good documentation for DSM for all of these.
My setup is to use a removable device as a key store.
It starts with setting up the Key Manager from the Control Panel under Shared Folders. From here you initialize the Key Manager and pick the USB device (otherwise internal) and set a passphrase for the Key Manager.
Then start creating shared folders that use encryption and you can pick the key manager. This also lets you pick if you want encrypted folders to be enabled automatically on boot which would require leaving your external key manager device connected.
After that, you need to keep copies of your key store and keys somewhere safe in case you lose key store device.
Once all setup you can start using that file share and it is pretty much seamless. In Windows I removed the old file history backup target and re-added the new encrypted share. On the Synology I removed the cloud backup targets, moving the files to the new location, and re-adding the cloud targets using the new location.
Stay safe 🔐
Saturday, 5 September 2020
Home NAS part 2: No Regrets? Let's Get Setup
Following actually picking and buying a NAS in Home NAS Part 1 the initial setup of the Synology is of course very easy. If you don't get distracted by all the buttons and spend days and days with "what's it do? what's this do? what's this do?"
First of all I should have gotten one of these 2 bay NAS *ages* ago and even the cheapest model would be fine. So I'll start with the list of things that are overkill in my setup.
- Dual-LAN. I just don't have enough concurrent devices to ever possibly saturate my network and since everything is WiFi even if I did, that would still be below 1 Gb that a single link would do. But it does afford a backup in case of failing cable or network port so I'm still using it.
- NVMe cache. If I can't even fill up the WiFis how could I possibly saturate the drives? I at least held back from the 2xNVMe which would add write caching as well as read caching. Current reported cache usage on the 500 GB NVMe? ~350 MB. While theoretically possible I might one day get a performance boost, does seem unlikely, don't it? It does reduce drive activity so I'll keep it in the theory that maybe the drives themselves will last longer.
- 4 TB drives. Okay so I just went with a drive size I had in budget. After copying all the data I wanted on there, usage is ~450 GB (are we seeing a pattern yet?). Truthfully, the bottom-end purchase price isn't that far off and it does forestall having to ever buy new drives except as replacements. Of all the overkill things, this is the least controversial under the heading "storage is cheap"
- Memory upgrade. Basically like the storage, I was building the spec and saw "oh, can upgrade memory, that sounds cool" and bought a DIMM for it. I think in theory I might eventually use some of that memory and the computing power in the device if I run Plex from there. Mostly I was paranoid that I wouldn't be able to get a compatible part in the future.
- The DS720+ itself comes with a 4 core CPU. I... Well it's just faster okay? We are not taking any further questions at this time.
Sunday, 2 August 2020
Home NAS part 1: Biting the Bullet
Tuesday, 7 July 2020
Windows Terminal Is The Best
Tabs? Yes
Launches PowerShell? Yes
Does "cmd.exe" sux? Yes
RunAs Radio Windows Linux Subsystem with Tara Raj and Sarah Cooley also put me onto WSL which I now always advocate rather than running a VM (unless you really need one) or Cygwin (nobody needs Cygwin). The slick thing with Terminal was that it dynamically added a profile for WSL after I installed it!
Between these couple utilities, WSL and Terminal, many of us can shed all our Linux stuff; virtual machines, Cygwin, Putty, Term, WinSCP, etc. And be better for it.
Ciao 😎
Popular Posts
-
For anyone who's had to cleanup some mail problems with Postfix configuration (or more often with other things, like anti-spam, tied in ...
-
In the course of troubleshooting the office Jabber server the other day, I came across some interesting info about the various caches that O...
-
For everyone who uses cron, you are familiar with the job schedule form: min hr day-of-month month day-of-week <command> A problem...




