Mostrando entradas con la etiqueta server. Mostrar todas las entradas
Mostrando entradas con la etiqueta server. Mostrar todas las entradas

miércoles, 29 de enero de 2025

Remmina solucion de problemas. Cannot connect to the "192.168.xxx.xxx" RDP Server. Freerdp. Depurador d remmina

 1. Configuración

1.1 ~/.config/freerdp/server   

carpeta que contiene los certificados para conectarse. Los nombres son : 192.168.XXX.XXX_3389.pem

1.2 ~/.config/freerdp/known_hosts2

fichero que contiene la IP, huella del certificado y otro dato mas del servidor al que queremos conectar.

1.3 ~/.local/share/remmina

Nos da las configuraciones de los servidores. Los nombres de ficheros que contiene son: 
group_rdp_connexió-ràpida_192-168-xxx-xxx.remmina

Si creamos una configuración, hay que darle solo estos parámetros:


Hay que darle solo estos datos:


y se guarda en esta carpeta carpeta indicada

Si mostramos el contenido de un fichero vemos:

password=XXXXXXXXX
gateway_username=
notes_text=
vc=
preferipv6=0
serialname=
ssh_tunnel_loopback=0
tls-seclevel=
sound=off
printer_overrides=
name=Win11-ximo
console=0
colordepth=99
security=
precommand=
disable_fastpath=0
left-handed=0
multitransport=0
postcommand=
group=
server=192.168.xxx.xxx
ssh_tunnel_command=
glyph-cache=0
ssh_tunnel_enabled=0
disableclipboard=0
labels=
audio-output=
parallelpath=
monitorids=
cert_ignore=0
gateway_server=
serialpermissive=0
protocol=RDP
old-license=0
disconnect-prompt=0
ssh_tunnel_password=
resolution_mode=2
assistance_mode=0
pth=
disableautoreconnect=0
loadbalanceinfo=
clientbuild=
clientname=
resolution_width=0
drive=
username=ximo
relax-order-checks=0
base-cred-for-gw=0
profile-lock=0
network=none
rdp2tcp=
gateway_domain=
serialdriver=
rdp_reconnect_attempts=
gateway_password=
domain=edificio.municipio Quitar esto para que funcione !!!!!
restricted-admin=0
ssh_tunnel_certfile=
exec=
multimon=0
serialpath=
enable-autostart=0
smartcardname=
usb=
ssh_tunnel_passphrase=
disablepasswordstoring=0
shareprinter=0
shareparallel=0
quality=0
span=0
parallelname=
ssh_tunnel_auth=0
keymap=
ssh_tunnel_username=
execpath=
shareserial=0
resolution_height=0
rdp_mouse_jitter=No
useproxyenv=0
sharesmartcard=0
freerdp_log_filters=
microphone=
timeout=
ssh_tunnel_privatekey=
gwtransp=http
ssh_tunnel_server=
ignore-tls-errors=1
dvc=
gateway_usage=0
disable-smooth-scrolling=0
no-suppress=0
websockets=0
freerdp_log_level=INFO
window_width=640
window_height=480
viewmode=1
window_maximize=0

Se muestran los parámetros que hay que tener mas cuidado pues los otros los da el sistema automáticamente.

OJO Para que funcione en windows 11 hay que quitar el domain=ZZZZZZZZZZZZZZZZ

que es el error que sale 

cannot connect to the "192.168.xxx.xxx" RDP Server


Si es windows v7 el servidor tiene estos parámetros

[remmina]
password=
gateway_username=
notes_text=
vc=
window_height=727
preferipv6=0
ssh_tunnel_loopback=0
serialname=
tls-seclevel=0
sound=local
printer_overrides=
name=192.168.xxx.xxx -Windows 7 Ximo
console=0
colordepth=99
security=
precommand=
disable_fastpath=0
postcommand=
left-handed=0
multitransport=0
group=
server=192.168.xxx.xxx
ssh_tunnel_certfile=
glyph-cache=0
ssh_tunnel_enabled=0
disableclipboard=0
labels=
audio-output=
parallelpath=
monitorids=
cert_ignore=0
gateway_server=
serialpermissive=0
protocol=RDP
old-license=0
disconnect-prompt=0
ssh_tunnel_password=
resolution_mode=2
assistance_mode=0
pth=
loadbalanceinfo=
disableautoreconnect=0
clientbuild=
clientname=
resolution_width=0
drive=/media/ximo/126b1584-0fd8-4183-95a2-21b2729538b9/DATOS_XIMO
relax-order-checks=0
base-cred-for-gw=0
gateway_domain=
profile-lock=0
rdp2tcp=
gateway_password=
serialdriver=
rdp_reconnect_attempts=
domain=edificio.ayuntamiento
smartcardname=
exec=
serialpath=
multimon=0
username=ximo
enable-autostart=0
usb=
shareprinter=0
network=autodetect
restricted-admin=0
ssh_tunnel_passphrase=
quality=2
span=0
disablepasswordstoring=0
parallelname=
shareparallel=0
ssh_tunnel_auth=0
rdp_mouse_jitter=No
keymap=
ssh_tunnel_username=
viewmode=1
execpath=
resolution_height=0
useproxyenv=0
timeout=
freerdp_log_filters=
shareserial=0
dvc=
microphone=
ssh_tunnel_privatekey=
ssh_tunnel_server=
gwtransp=http
ignore-tls-errors=1
sharesmartcard=0
disable-smooth-scrolling=0
window_maximize=0
keyboard_grab=0
window_width=1487
no-suppress=0
gateway_usage=0
websockets=0
freerdp_log_level=INFO
ssh_tunnel_command=


2. Funcionamiento

Cada vez que creamos una conexión , nos propone un certificado y debemos aceptarlo.

Pero si no nos deja conectar debemos borrar el certificado en base a su IP en la carpeta ~/.config/freerdp/server  y del fihero ~/.config/freerdp/known_hosts2


3. Freerdp al rescate

Si no funciona podemos ejecutar en una shellls

xfreerdp /v:server_IP /u:user /p:"password" /dynamic-resolution

y  nos dice

Certificate details for 192.168.xxx.xxx:3389 (RDP-Server):
	Common Name: A03-INF-011.edificio.municipio
	Subject:     CN = A03-INF-011.edificio.municipio
	Issuer:      CN = A03-INF-011.edificio.municipio
	Thumbprint:  e1:9c:xx:39:xx:33:5f:b0:xx:08:c2:6d:xxY:c7:f5:a0:b4:18:c3:95:8a:11:df:15:d4:67:70:55:ce:97:4b:aa
The above X.509 certificate could not be verified, possibly because you do not have
the CA certificate in your certificate store, or the certificate has expired.
Please look at the OpenSSL documentation on how to add a private CA to the store.
Do you trust the above certificate? (Y/T/N)

Si le contestamos que Y, nos deja entrar en la máquina

4. Depuración de remmina

Vamos a la pantalla indicada y nos sale la consola para hacer depuración




jueves, 2 de diciembre de 2021

(FALLA) Instalar certificado LetsEncrypt en Apache Ubuntu server

0. Introducción

Se ha seguido esta web de Digital Ocean y Devanswers 

1. Identificar el dominio

Para tener un dominio virtual hay que tener un servidor de DNS que reconozca a dicho dominio para que lo redireccione.

En el caso que no lo tengamos, para hacer las pruebas el punto 2 debemos modificar el fichero /etc/hosts para que pueda ver ese nombre, tanto en el servidor local como en cada una de las máquinas que quieran acceder a dicho servidor.

En ese caso se definirán los dominios o hosts (webprop.es y www.webprop.es)

NOTA: Para que letsencrypt pueda darte un certificado, debes tener el dominio registrado, es decir, que cualquiera, desde cualquier sitio pueda hacer un ping a tu dominio y que esté localizable. Para ello se puedes probar el google cloud DNS que tiene un período de pruebas. Yo no lo he probado, pero algunos dicen que funciona.

Para poder gestionar el dominio debes:

a. Crear el dominio y registrarlo

b. En tu firewall debes redirigir este dominio a la máquina y puerto correcto

c. En tu servidor interno de DNS debes redirigir el dominio a tu máquina y puerto internos correcto para que no vaya al exterior y vuelva a entrar


2. Localizar los ficheros de configuración

Fichero nº1:

Veamos el primer fichero de configuración (según Rich Bowen) , para ello ejecutamos

httpd -V

Y si no la encuentra, ejecutar esta otra

apache2ctl -V

Y contesta esto

Server version: Apache/2.4.29 (Ubuntu)

Server built:   2021-09-28T22:27:27

Server's Module Magic Number: 20120211:68

Server loaded:  APR 1.6.3, APR-UTIL 1.6.1

Compiled using: APR 1.6.3, APR-UTIL 1.6.1

Architecture:   64-bit

Server MPM:     event

  threaded:     yes (fixed thread count)

    forked:     yes (variable process count)

Server compiled with....

 -D APR_HAS_SENDFILE

 -D APR_HAS_MMAP

 -D APR_HAVE_IPV6 (IPv4-mapped addresses enabled)

 -D APR_USE_SYSVSEM_SERIALIZE

 -D APR_USE_PTHREAD_SERIALIZE

 -D SINGLE_LISTEN_UNSERIALIZED_ACCEPT

 -D APR_HAS_OTHER_CHILD

 -D AP_HAVE_RELIABLE_PIPED_LOGS

 -D DYNAMIC_MODULE_LIMIT=256

 -D HTTPD_ROOT="/etc/apache2"

 -D SUEXEC_BIN="/usr/lib/apache2/suexec"

 -D DEFAULT_PIDLOG="/var/run/apache2.pid"

 -D DEFAULT_SCOREBOARD="logs/apache_runtime_status"

 -D DEFAULT_ERRORLOG="logs/error_log"

 -D AP_TYPES_CONFIG_FILE="mime.types"

 -D SERVER_CONFIG_FILE="apache2.conf"

Donde podemos adivinar que el fichero de configuración del httpd es /etc/apache2/apache2.conf

que se ha obtenido al unir las 2 cadenas marcadas en color azul y rojo

Este fichero lo utilizaríamos si quisiésemos tener más de un nombre de dominio junto diferentes IPs para un mismo servidor y se acutaría creando diferentes entradas de <VirtualHost IP:80> en este fichero, indicacando diferentes IPs para cada servidor virtual, por ejemplo 

<VirtualHost 172.20.30.40:80>

Para el caso de querer tener un solo dominio, me parece más sencillo utilizar el segundo fichero que expongo a continuación

Fichero nº2:

Vamos a la carpeta /etc/apache2/sites-available  y en mi caso hago un ls y veo que hay 2 ficheros: 000-default.conf y default-ssl.conf siendo el primero el que nos interesa.

Supongamos que queremos definir untenmos un dominio llamado webprop.es para ello editamos el fichero 000-default.conf y le dejamos este contenido

sudo nano /etc/apache2/sites-available/000-default.conf
<VirtualHost *:80>
    ServerAdmin webmaster@webprop.es
    ServerName webprop.es
    ServerAlias www.webprop.es
    DocumentRoot /var/www/webprop.es/public_html
    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined
</VirtualHost>
Ojo: en la primera línea vemos que para cualquier IP le asignamos el dominio que definimos posteriormente (webprop)

Salvamos con CTRL + O y salimos conCTRL + X,

Ahora creamos un directorio

sudo mkdir -p /var/www/webprop.es/public_html

Creamos un fichero index.html (que és el que nos dará la bienvenida al apuntar con el navegador (http://webprop.es/) para probar

sudo nano /var/www/webprop.es/public_html/index.html
<html>
   <head>
     <title>Welcome!</title>
   </head>
   <body>
      <h1>Welcome to webprop.es! Hava a nice day!</h2>
   </body>
</html>
Salvamos con CTRL + O y salimos conCTRL + X,


Ahora comprobamos errores

apachectl configtest

y nos da errores

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message

Para definir la directiva ServerName globalmente tenenos que modificar el fichero 1 ( /etc/apache2/apache2.conf) :

sudo nano /etc/apache2/apache2.conf
Y le añadimos esta línea al final

ServerName webprop.es

Salvamos con CTRL + O y salimos conCTRL + X,

Reiniciamos el servidor apache y si le damos otra vez a comprobar errores (apachectl configtest) vemos que ya no tenemos errores.


3. Instalar Certbot

Añadimos al repositorio

  • sudo add-apt-repository ppa:certbot/certbot

Instalamos el paquete Apache Certbot

  • sudo apt install python-certbot-apache

4. Obtener un certificado SSL

OJO: Como requisito previo, debemos tener abierto el firewall en el puerto 80 para este dominio  !!!!!!!
Esto conlleva muchas vulnerabilidades, por tanto, dejarlo solamente abierto por el tiempo necesario para que LetsEncrypt pueda verificar que el servidor existe !

Ejecutamos

sudo certbot --apache
o también podemos indicarle el dominio directamente

sudo certbot --apache -d webprop.es

Nos pide un email y luego nos pide que estemos de acuerdo

Please read the Terms of Service at
https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must
agree in order to register with the ACME server at
https://acme-v02.api.letsencrypt.org/directory
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(A)gree/(C)ancel:

A continuación nos sugiere que recibamos información al respecto

Would you be willing to share your email address with the Electronic Frontier
Foundation, a founding partner of the Let's Encrypt project and the non-profit
organization that develops Certbot? We'd like to send you email about our work
encrypting the web, EFF news, campaigns, and ways to support digital freedom.

Ahora nos dice que dominios queremos activar

Which names would you like to activate HTTPS for?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: webprop.es
2: www.webprop.es
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel):

Aceptamos todos y SI NO HEMOS CREADO UN DOMINIO REGISTRADO, NOS DA ESTOS ERRORES:

Obtaining a new certificate
Performing the following challenges:
http-01 challenge for webprop.es
http-01 challenge for www.webprop.es
Enabled Apache rewrite module
Waiting for verification...
Cleaning up challenges
Failed authorization procedure. www.webprop.es (http-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for www.webprop.es - check that a DNS record exists for this domain, webprop.es (http-01): urn:ietf:params:acme:error:dns :: DNS problem: NXDOMAIN looking up A for webprop.es - check that a DNS record exists for this domain

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: www.webprop.es
   Type:   None
   Detail: DNS problem: NXDOMAIN looking up A for www.webprop.es -
   check that a DNS record exists for this domain

   Domain: webprop.es
   Type:   None
   Detail: DNS problem: NXDOMAIN looking up A for webprop.es - check
   that a DNS record exists for this domain

Por tanto hay que tener los dominios registrados, y abierto el puerto 80 en el firewall, ya que si no le hemos hecho puede responder que hay un conncetion time-out por no poder acceder al puerto 80. En este caso contesta favorablemente
Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
-------------------------------------------------------------------------------
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
-------------------------------------------------------------------------------
Select the appropriate number [1-2] then [enter] (press 'c' to cancel):
Pero yo le he contestado la opción 2 y me contesta

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator apache, Installer apache
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for webprop.es
Enabled Apache rewrite module
Waiting for verification...
Cleaning up challenges
Created an SSL vhost at /etc/apache2/sites-available/000-default-le-ssl.conf
Enabled Apache socache_shmcb module
Enabled Apache ssl module
Deploying Certificate to VirtualHost /etc/apache2/sites-available/000-default-le-ssl.conf
Enabling available site: /etc/apache2/sites-available/000-default-le-ssl.conf

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2
Enabled Apache rewrite module
Redirecting vhost in /etc/apache2/sites-enabled/000-default.conf to ssl vhost in /etc/apache2/sites-available/000-default-le-ssl.conf

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations! You have successfully enabled https://webprop.es

You should test your configuration at:
https://www.ssllabs.com/ssltest/analyze.html?d=webprop.es
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/webprop.es/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/webprop.es/privkey.pem
   Your cert will expire on 2022-03-07. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot again
   with the "certonly" option. To non-interactively renew *all* of
   your certificates, run "certbot renew"
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
   Donating to EFF:                    https://eff.org/donate-le
Pero mi gozo en un pozo, pues no me deja utilizar el puerto 8443, solo el puerto 80 y 443

Veamos como solucionar el entuerto 

5. Deshacer el entuerto

1. Debemos ver si al menos los certificados se han descargado, para ello hacemos:

sudo certbot certificates
y nos muestra
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
  Certificate Name: webprop.es
    Domains: webprop.es
    Expiry Date: 2022-03-07 12:30:51+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/webprop.es/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/webprop.es/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Con lo que nuestros certificados parecen totalmente generados
Si vamos al directorio  /etc/letsencrypt/live/webprop.es , vemos que están estos ficheros:
  • cert.pem
  • chain.pem
  • fullchain.pem
  • privkey.pem
  2. Tenemos que advertir que ha cambiado la configuración del Tomcat, en concreto:

  2.1. En el fichero /etc/apache/etc/apache2/sites-available/000-default.conf ha añadido líneas de configuración al final de la etiqueta <VirtualHost *:80> que debemos eliminar o comentar
RewriteEngine on
RewriteCond %{SERVER_NAME} =www.csv.tavernesvalldigna.es [OR]
RewriteCond %{SERVER_NAME} =csv.tavernesvalldigna.es
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]

Con lo que nos queda

<VirtualHost *:80>
        # The ServerName directive sets the request scheme, hostname and port that
        # the server uses to identify itself. This is used when creating
        # redirection URLs. In the context of virtual hosts, the ServerName
        # specifies what hostname must appear in the request's Host: header to
        # match this virtual host. For the default virtual host (this file) this
        # value is not decisive as it is used as a last resort host regardless.
        # However, you must set it for any further virtual host explicitly.
        #ServerName www.example.com

#       ServerAdmin webmaster@localhost
#       DocumentRoot /var/www/html


        ServerAdmin webmaster@webprop.es
        ServerName webprop.es
ServerAlias webprop.es
DocumentRoot /var/www/webprop.es/public_html
# Available loglevels: trace8, ..., trace1, debug, info, notice, warn, # error, crit, alert, emerg. # It is also possible to configure the loglevel for particular # modules, e.g. #LogLevel info ssl:warn ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined # For most configuration files from conf-available/, which are # enabled or disabled at a global level, it is possible to # include a line for only one particular virtual host. For example the # following line enables the CGI configuration for this host only # after it has been globally disabled with "a2disconf". #Include conf-available/serve-cgi-bin.conf #Added by CertBot #RewriteEngine on #RewriteCond %{SERVER_NAME} =www.csv.tavernesvalldigna.es [OR] #RewriteCond %{SERVER_NAME} =csv.tavernesvalldigna.es #RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent] </VirtualHost>

2.2 También ha credo el fichero /etc/apache/etc/apache2/sites-available/000-default-le-ssl.conf que debemos borrar.

2.3 Parece ser que el fichero conf/server.xml no ha cambiado.

Vamos ahora a la siguiente entrada del blog para arreglar el asunto.



miércoles, 27 de mayo de 2020

Ubuntu Server. Definir IP estática

Cuando se copian máquinas virtuales de Ubuntu Server 18.04, parece ser que la configuración de la dirección IP ya no se puede cambiar por el entorno gráfico, ya que cuando se reinicia se pierde la configuración de la IP.

Para ello he tenido que recurrir al blog de Gorka Izquierdo.

En resumidas cuentas hay que hacer lo siguiente:

1. Buscar en /etc/netplan un fichero que termine en .yaml

En mi caso se llama 50-cloud-init.yaml. su contenido es:

    ethernets:
        ens192:                        # verificar nombre arjeta de red con ifconfig   
            addresses:
                - 192.168.28.201/24    # IP estática a asignar
            gateway4: 192.168.28.100   # IP del gateway o puerta de enlace
            nameservers:
                addresses:
                    - 192.168.28.207   # IPs de los DNS
                    - 192.168.28.210
                search:
                    - mi.dominio
    version: 2


2. Ejecutar ifconfig para obtener el nombre de la tarjeta de red

Obtenenos el nombre de nuestra tarjeta de red, en este caso ens192


 ens192: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.28.201  netmask 255.255.255.0  broadcast 192.168.28.255
        inet6 fe80::250:56ff:feb5:3a1e  prefixlen 64  scopeid 0x20<link>
        ether 00:50:56:b5:3a:1e  txqueuelen 1000  (Ethernet)
        RX packets 7950  bytes 580000 (580.0 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 371  bytes 46630 (46.6 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        inet6 ::1  prefixlen 128  scopeid 0x10<host>
        loop  txqueuelen 1000  (Local Loopback)
        RX packets 842  bytes 218267 (218.2 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 842  bytes 218267 (218.2 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0


3. Editar el fichero con el editor nano

Este editor funciona con putty y hay que darle el nombre de la tarjeta de red, y las IPs a asignarle al servidor, del gateway y de los DNS


4. Activar la configuración

Hay  que aplicar cambios y reiniciar la red para ello ejecutamos estos 2 comandos


netplan apply

systemctl restart networking

y ya está.