Friday, May 29, 2015

Using OwnCloud with an NTFS file share [Updated]

Trying to use NTFS with your OwnCloud server? You may be running into some challenges.

My setup

I'm running OwnCloud 8 server in a Linux Mint VM (VMware Workstation) for personal use. It uses a USB 3.0 2TB drive formatted as NTFS and it works pretty darn well.

I won't be going over how to setup OwnCloud server in Ubuntu - if you're interested in that, here's a great guide by our friends over at Noobs Lab (I highly recommend using MySQL or any other database solution over the included SQLite.. you will have major performance issues if you use SQLite)

The reason I wanted to go this route with my configuration is because I can have a small (~20GB) Ubuntu Server utilizing a larger external drive that can be easily read by both my Linux Server, as well as my Windows host machine. Smaller VMs means more internal space on my host machine!

At first I thought I could simply "pass through" my drive to the VM for hosting my personal cloud, similar to how I configured my Plex Server. Unfortunately the system was having trouble recognizing the pass-through (even though file syncing actually worked when manually copying files to the share.. very strange). I would see an error similar to the one below:



Data directory (/mnt/hgfs/owncloud/data) is readable by other users.

Please change the permissions to 0770 so that the directory cannot be listed by other users.

I was unable to change the permissions on the NTFS mount when it was configured this way.

Through researching the issue and the options available, I decided the easiest method to continue to use NTFS with this setup is to create a Windows share on my owncloud data folder, and mount it as a CIFS share to the OwnCloud server.

What you'll need

  1. Host machine with VMware Workstation (or similar software)

  2. OwnCloud server in a Ubuntu-based Virtual Machine (~20gb vm)

  3. External USB 3.0 Drive formatted as NTFS

  4. Patience and determination!
On to the how-to:

I should preface this section: this setup works for me and my needs, which is a single-user personal setup. This is not recommended for a multi-user, production configuration.

  1. Remove any VMware Workstation-based pass through you have configured for the NTFS drive. This may require you to power off the VM and delete the pass through.

  2. On the host side (in my case, Windows 8.1 Windows 10) create a local user account dedicated for owning the share. This will be used later when we mount it to Linux. In my example, ocadmin

  3. On the host side, create a normal share on the folder you'll be using as the owncloud data folder (right click, properties, Sharing tab, Share...) and give full permissions to the user account you created. This should create a share location similar to \\hostname\data

  4. Now login to the OwnCloud server, edit your /etc/fstab using vi, or gedit, or what have you. At the bottom of the file, add an entry that looks like this://<ip of host>/data </location/to/put/share> cifs uid=www-data,username=ocadmin,password=<your password>,iocharset=utf8,file_mode=0770,dir_mode=0770,sec=ntlm 0 0Tips:<ip of host> This is the IP of the machine running Workstation
    </location/to/put/share> This is where the share will be mounted to the Linux OwnCloud server. This could be your Linux Home folder, desktop, documents folder.. the options are endless... endless
    www-data is the default OwnCloud server account running the owncloud service
    ocadmin/password is the local host machine account we careated earlier

  5. Now we need to make OwnCloud aware of the location we want it to use for storing files. Edit the config.php file to include the you typed above.sudo vi /var/www/owncloud/config/config.phpModify the 'datadirectory' field to your new location so it reads something like:'datadirectory' => '/var/www/owncloud/data',

    Save and close this file.

  6. Now in the terminal, type sudo mount -a and ensure there are no errors mounting the share we configured in fstab.

  7. Give your Linux system a quick reboot and you should no longer receive the errors at the top of this post when accessing your OwnCloud URL.
[Update, May 13 2016]

If you've followed this method and are planning on an upgrade from OC8 to OC9, be sure to read the OC Upgrade documentation very carefully as it states, "When using an NFS mount for the data directory, do not change its ownership from the default. The simple act of mounting the drive will set proper permissions for ownCloud to write to the directory. Changing ownership as above could result in some issues if the NFS mount is lost."

Did this post help you? Let me know in the comments!
Share:

Wednesday, May 27, 2015

VMware Labs Hidden Gem



I discovered a hidden gem this morning: docs.hol.vmware.com 

If you don't know what VMware HOL is, it stands for Hands On Labs. It's an amazing platform that delivers technical guided product training right through your browser. Oh did I mention that it's free? If you're interetested in learning how to setup and deploy vSphere, NSX, AirWatch, Workspace Portal etc.. HOL is something you'll want to bookmark.

The labs themselves aside (which are awesome!), I stumbled upon the document space of the HOL. This section of VMware's HOL allows you to read through the step-by-step labs provided from HOL in either PDF or HTML format. The best part is you can easily save these PDFs to your local system for some offline reading. Perfect for catching up on how-tos for those VMware products you're planning on learning or deploying in the near future.

For more info on VMware HOL, check out their Twitter account here: @VMwareHOL

Have you used VMware HOL? Do you read lab how-tos to put yourself to sleep? Let me know in the comments!
Share:

Thursday, April 30, 2015

VMware releases vSphere security patches

Calling all non-vSphere 5.5 users. Check out today's new VMware releases which address JRE security vulnerabilities, as well as SKIP-TLS, FREAK, and POODLE.

More details in the release notes linked below.

VMware vCenter Server 5.0 U3d
VMware vCenter Server 5.1 U3a
VMware vSphere VUM 5.0 U3d
VMware vSphere VUM 5.1 U3a
VMware vCenter Orchestrator 5.1.3.1
VMware vCloud Networking and Security 5.5.4.1
Share:

Monday, April 27, 2015

Freeing my iPad of Social Media is the best thing I've done

Whether you're an Apple fan boy, or a die hard Android enthusiest, we can all agree tablets are great. I've recently come to realize, however, how much more I can enjoy my iPad when I exclude certain distractions from it. Namely, social media. 

Twitter, Facebook, Instagram - our digitial social lives are calling out for our attention ALL the time. I've come to realize the benefit of not only finding a time and place for social media, but also a platform for it.

Like most, my phone is with me pretty much wherever I go. And this is what I generally use for things like Twitter and Instagram (I ditched Facebook months ago - yet another hugely gratifying decision, but is a story for another day). My iPad is also with me quite often, but I tend to use it for different things.

For instance, though my iPad and iPhone are capable of the same applications, I much, much prefer to use my iPad for reading a book, checking out a comic book, or catching up on saved blog posts. There's something to be said about having that screen real estate for reading. It was far too often though that these activities would get distracted by social notifications. Not only notifications, but it's more peaceful reading a book now knowing I'm not subconciously looking for that next great quote to tweet, or that new blog post that should get shared.

I can enjoy a good news article or book way more now than before when I knew my social media was just around the corner.

Sure there are plenty of other ways to get distracted. Maybe you're more prone to spend hours on YouTube, or browse all the latest podcasts (who are you?). On the other hand, there's a good chance you have more self control than I. But the fact of the matter is, I can enjoy a good news article or book way more now than before when I knew my social media was just around the corner. I've even gone to disable the majority of notifications on my iPad to simmer down distractions.

Differentiating what my iPhone and iPad are used for has greatly improved my enjoyment of each device. Maybe you're different and you enjoy having all the same apps on your phone and your tablet. More power to you!

As silly as a post this is, it's something that has dramatically increased my productivity and media consumption enjoyment. Try it out. You'll probably be glad you did!
Share:

Thursday, April 2, 2015

Fast Lane Support for VMware's Premier Services customers

The latest version of the My VMware mobile application now allows VMware Premier Services customers to open up a Severity 1 SR and get connected to support in minutes. This new feature is called "Fast Lane Support" and is now live!






Check it out on iTunes: https://itunes.apple.com/us/app/my-vmware/id512689552?mt=8

Check it out on Google: https://play.google.com/store/apps/details?id=com.vmware.myvmware&hl=en
Share:

Thursday, March 12, 2015

VMware New Releases including vSphere 6.0 and Horizon View 6.1

Today was a busy day for VMware! In the midst of all the noise and chatter, it's easy to get overwhelmed with all the new information. Below is a compiled list of useful KB articles for vSphere 6.0, including upgrade and installation documents, as well as other new product release notes not to be overlooked. Enjoy!


vSphere Prereqs
=============
Important Information before upgrading to vSphere 6.0 (2110293)
Update sequence for vSphere 6.0 and its compatible VMware products (2109760)
List of recommended topologies for vSphere 6.0.x (2108548)

vCenter Installation
=====================
Installing vCenter Server 6.0 best practices (2107948)
Installing VMware vCenter Server 6.0 with an embedded Platform Services Controller on a Windows machine (2108799)
Installing VMware vCenter Server 6.0 with an external Platform Services Controller on a Windows machine (2108802)
Uninstalling vCenter Server 6.0.x resets the embedded VMware Postgres database (2108547)

vCenter Upgrade
================
Upgrading to vCenter Server 6.0 best practices (2109772)
Upgrading to vCenter Server 6.0 without migrating SQL database to vPostgres (2109321)
Upgrading to VMware vCenter Server 6.0 with an embedded Platform Services Controller from vCenter Server 5.5 installed using the simple install method (2109559)
Upgrading VMware vCenter Single Sign-on 5.5 to a VMware vCenter Server 6.0 Platform Services Controller 6.0 (2109560)
Upgrading VMware vCenter Server 5.5 to vCenter Server 6.0 with an external Platrfom Services Controller (2109562)

ESXi Installation
==================
Best practices to install or upgrade to VMware ESXi 6.0 (2109712)
Methods of installing ESXi 6.0 (2109708)

ESXi Upgrade
==============
Methods for upgrading to ESXi 6.0 (2109711)

Maintenance
============
Recovering from a failed upgrade of vCenter Server 5.1 or 5.5 to 6.0 (2108938)
Back up and restore the embedded PostgreSQL database (2091961)
How to backup and restore vCenter Server 6.0 external deployment models (2110294)

Release Notes
============
VMware vCenter Server 6.0

VMware vCenter Server Appliance 6.0

VMware vSphere ESXi 6.0

VMware vRealize Operations for Horizon 6.1.0

VMware vRealize Automation 6.2.1

VMware vRealize Orchestrator 6.0.1

vRealize Business Advanced\Enterprise 8.2.1

vRealize Business Standard 6.1.0

vRealize Code Stream 1.1.0

vRealize Infrastructure Navigator 5.8.4

vRealize Operations Manager 5.8.5

VMware vCloud Networking and Security 5.5.4

VMware vCenter Site Recovery Manager 6.0

VMware Virtual SAN 6.0

VMware vSphere Data Protection 6.0

VMware vSphere Replication 6.0

vCenter Host Gateway 6.0

VMware Integrated OpenStack v1.0

VMware Update Manager 6.0

vSphere Update Manager PowerCLI 6.0

VMware View 6.1

VMware Horizon Client for Windows 3.3

VMware Workspace Portal 2.1.1

VMware App Volumes 2.6
Share:

Monday, February 9, 2015

Workspace Portal, Access Policies, and Kerberos authentication

You've decided it's time to expand your Workspace Portal deployment from internal-only, to also allow external access. You've setup your Load Balancer, gotten your certificates in place, and now you're tasked with configuring internal and external authentication methods.

This post covers the configuration needed for Kerberos on internal connections, while allowing username/password authentication from external connections.

Access Policies


First, let's setup your access policies. Access Policies allow you to specify criteria that users must meet in order to access Workspace Portal. We're going to configure the Default Access Policy Set to include two policies: internal and external

For our internal connections, we're going to utilize Kerberos. Configuring Kerberos isn't covered in this post, so ensure you have it working first. Here are some helpful posts for setting it up:

Configuring Kerberos for Workspace
Kerberos SSO in Workspace 1.8 (basic config flow still applies to Workspace Portal 2.1)

For our external connections, we'll let our users utilize their Active Directory synced username and passwords for authentication. Ensure your Directory Sync rules from the Connector Service Admin page include all desired AD groups and that they're synced regularly.

First: ensure you've created both an internal and an external Network Range:

  1. Log into the Workspace Admin Portal > Settings > Network Ranges

  2. Click + Network Range to add our internal range. Configure this to the appropriate subnets used in your LAN.

  3. We'll use the default ALL RANGES entry for our external connections


Then, from the Policies tab, we'll edit the default_access_policy_set to correspond to these network ranges.

  1. Click + Access Policy and name it internal. Set it to use a Minimum Authentication Score of 1. 

  2. Then select the default 'web policy' which corresponds to our external network range. We'll set this to a Minimum Authentication Score of 2 as seen below:


NOTE: Be sure to re-arrange the policies so that internal is on top, and 'web policy' is on bottom and click Save.


Authentication method



Now, head to Settings > Authentiation Methods and order the options as seen here. Be sure to click each entry to edit the Authentication Score to match the below screenshot. Once again, order is important.



Notice that Kerberos is on top, with an authentication score of 1.



Set Kerberos as the Default Method



Password will be set to an authentication score of 2.


At this point, you should be able to verify that your user portal loads from both internal and external locations, as well as verify that your internal users aren't prompted for their credentials.


Troubleshooting



Scenario 1:

When launching Workspace Portal externally, the page times out and doesn't load, but internally it launches.


Scenario 2:

When launching Workspace Portal externally, the page loads, but internally, users are prompted for username and password (Kerberos fails to login the user)


   - In either case, verify the order of your Access Policies have Kerberos on top, password on bottom. Also verify that the scores are set appropriately, per the screenshots

Share: