|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| « ATAS « | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Sunday, August 16, 2015
Linux Command Line in Indonesia
Wednesday, August 12, 2015
Install SSL di Ubuntu dan Mengaktifkan HTTPS
Hari
ini mau tulis tentang cara install ssl di ubuntu dan mengaktifkan
httpsnya. Ini saya lakukan di ubuntu 13.04, menggunakan web server
apache2.
Oke langsung aja ya,
Langkah 1 ; Install openssl, kalau belum diinstall
sudo apt-get install openssl
Langkah 2 ; Generate private key
openssl genrsa -des3 -out server.key 1024 (Setelah enter maka akan disuruh input pass phrase min 4 digit)
Langkah 3 ; Generate CSR (Certificate Signing Request)
openssl req -new -key server.key -out server.csr (Setelah enter maka akan disuruh input pass phrase yg tadi diinput saat buat private key)
Pada langkah ketiga akan ditanya :
- Country Name (CN)
- Country Name (CN)
- State or Province Name
- Locality Name (city)
- Organization Name (company)
- Organization Unit Name (section)
- Common Name (IP server or FQDN)
- Email address
- Challange Password
Langkah 4 ; Hapus passphrase from key
cp server.key server.key.org
openssl rsa -in server.key.org -out server.key
Langkah 5 ; Generate self-signed certificate
openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt
Langkah 6 : Copy ke forlder ssl yang ada di /etc/apache2
sudo mkdir /etc/apache2/ssl <bikin folder ssl, karena sebelumnya belum ada>
sudo cp server.key /etc/apache2/ssl
sudo cp server.crt /etc/apache2/ssl
Langkah 7 ; Enable ssl
sudo a2enmod ssl
Langkah 8 ; Buat file link di sites-enable
sudo ln -s /etc/apache2/sites-enabel/000-default-ssl /etc/apache2/sites-available/default-ssl
Langkah 9 ; Buat folder root untuk ssl
sudo mkdir /var/www-ssl
buat file index.html, jadi kita bisa tau kalau document root mengarah ke folder ini.
<html>
<h1> Server SSL </h1>
</html>
buat file index.html, jadi kita bisa tau kalau document root mengarah ke folder ini.
<html>
<h1> Server SSL </h1>
</html>
Langkah 10 ; Sebelum melakukan edit, sebaiknya backup file yang ada di folder sites-available
sudo cp /etc/apache2/sites-available/default /etec/apache2/sites-available/default_back
sudo cp /etc/apache2/sites-available/default-ssl /etec/apache2/sites-available/default-ssl_back
Langkah 11 ; Edit file default-ssl
sudo vim /etc/apache2/sites-available/default-ssl
Perhatikan baris SSLEngine, SSLCertificateFile, SSLCertificateKeyFile pada bagian di bawah ini
<IfModule mod_ssl.c>
<VirtualHost 192.168.0.135:443>
ServerAdmin webmaster@localhost
DocumentRoot /var/www-ssl
<Directory />
Options FollowSymLinks
AllowOverride None
</Directory>
<Directory /var/www/>
Options Indexes FollowSymLinks MultiViews
AllowOverride None
Order allow,deny
allow from all
</Directory>
ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
<Directory "/usr/lib/cgi-bin">
AllowOverride None
Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
Order allow,deny
Allow from all
</Directory>
ErrorLog ${APACHE_LOG_DIR}/error.log
# Possible values include: debug, info, notice, warn, error, crit,
# alert, emerg.
LogLevel warn
CustomLog ${APACHE_LOG_DIR}/ssl_access.log combined
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
# A self-signed (snakeoil) certificate can be created by installing
# the ssl-cert package. See
# /usr/share/doc/apache2.2-common/README.Debian.gz for more info.
# If both key and certificate are stored in the same file, only the
# SSLCertificateFile directive is needed.
# SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem
# SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key
SSLCertificateFile /etc/apache2/ssl/server.crt
SSLCertificateKeyFile /etc/apache2/ssl/server.key
# Server Certificate Chain:
# Point SSLCertificateChainFile at a file containing the
# concatenation of PEM encoded CA certificates which form the
# certificate chain for the server certificate. Alternatively
# the referenced file can be the same as SSLCertificateFile
# when the CA certificates are directly appended to the server
# certificate for convinience.
#SSLCertificateChainFile /etc/apache2/ssl.crt/server-ca.crt
# Certificate Authority (CA):
# Set the CA certificate verification path where to find CA
# certificates for client authentication or alternatively one
# huge file containing all of them (file must be PEM encoded)
# Note: Inside SSLCACertificatePath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCACertificatePath /etc/ssl/certs/
#SSLCACertificateFile /etc/apache2/ssl.crt/ca-bundle.crt
# Certificate Revocation Lists (CRL):
# Set the CA revocation path where to find CA CRLs for client
# authentication or alternatively one huge file containing all
# of them (file must be PEM encoded)
# Note: Inside SSLCARevocationPath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCARevocationPath /etc/apache2/ssl.crl/
#SSLCARevocationFile /etc/apache2/ssl.crl/ca-bundle.crl
# Client Authentication (Type):
# Client certificate verification type and depth. Types are
# none, optional, require and optional_no_ca. Depth is a
# number which specifies how deeply to verify the certificate
# issuer chain before deciding the certificate is not valid.
#SSLVerifyClient require
#SSLVerifyDepth 10
# Access Control:
# With SSLRequire you can do per-directory access control based
# on arbitrary complex boolean expressions containing server
# variable checks and other lookup directives. The syntax is a
# mixture between C and Perl. See the mod_ssl documentation
# for more details.
#<Location />
#SSLRequire ( %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
# and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
# and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
# and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
# and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20 ) \
# or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
#</Location>
# SSL Engine Options:
# Set various options for the SSL engine.
# o FakeBasicAuth:
# Translate the client X.509 into a Basic Authorisation. This means that
# the standard Auth/DBMAuth methods can be used for access control. The
# user name is the `one line' version of the client's X.509 certificate.
# Note that no password is obtained from the user. Every entry in the user
# file needs this password: `xxj31ZMTZzkVA'.
# o ExportCertData:
# This exports two additional environment variables: SSL_CLIENT_CERT and
# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
# server (always existing) and the client (only existing when client
# authentication is used). This can be used to import the certificates
# into CGI scripts.
# o StdEnvVars:
# This exports the standard SSL/TLS related `SSL_*' environment variables.
# Per default this exportation is switched off for performance reasons,
# because the extraction step is an expensive operation and is usually
# useless for serving static content. So one usually enables the
# exportation for CGI and SSI requests only.
# o StrictRequire:
# This denies access when "SSLRequireSSL" or "SSLRequire" applied even
# under a "Satisfy any" situation, i.e. when it applies access is denied
# and no other module can change it.
# o OptRenegotiate:
# This enables optimized SSL connection renegotiation handling when SSL
# directives are used in per-directory context.
#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
<Directory /usr/lib/cgi-bin>
SSLOptions +StdEnvVars
</Directory>
# SSL Protocol Adjustments:
# The safe and default but still SSL/TLS standard compliant shutdown
# approach is that mod_ssl sends the close notify alert but doesn't wait for
# the close notify alert from client. When you need a different shutdown
# approach you can use one of the following variables:
# o ssl-unclean-shutdown:
# This forces an unclean shutdown when the connection is closed, i.e. no
# SSL close notify alert is send or allowed to received. This violates
# the SSL/TLS standard but is needed for some brain-dead browsers. Use
# this when you receive I/O errors because of the standard approach where
# mod_ssl sends the close notify alert.
# o ssl-accurate-shutdown:
# This forces an accurate shutdown when the connection is closed, i.e. a
# SSL close notify alert is send and mod_ssl waits for the close notify
# alert of the client. This is 100% SSL/TLS standard compliant, but in
# practice often causes hanging connections with brain-dead browsers. Use
# this only for browsers where you know that their SSL implementation
# works correctly.
# Notice: Most problems of broken clients are also related to the HTTP
# keep-alive facility, so you usually additionally want to disable
# keep-alive for those clients, too. Use variable "nokeepalive" for this.
# Similarly, one has to force some clients to use HTTP/1.0 to workaround
# their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
# "force-response-1.0" for this.
BrowserMatch "MSIE [2-6]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
# MSIE 7 and newer should be able to use keepalive
BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
</VirtualHost></IfModule>
Langkah 12 ; Edit file ports.conf, untuk menambahkan virtualhostnyaPerhatikan baris SSLEngine, SSLCertificateFile, SSLCertificateKeyFile pada bagian di bawah ini
<IfModule mod_ssl.c>
<VirtualHost 192.168.0.135:443>
ServerAdmin webmaster@localhost
DocumentRoot /var/www-ssl
<Directory />
Options FollowSymLinks
AllowOverride None
</Directory>
<Directory /var/www/>
Options Indexes FollowSymLinks MultiViews
AllowOverride None
Order allow,deny
allow from all
</Directory>
ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
<Directory "/usr/lib/cgi-bin">
AllowOverride None
Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
Order allow,deny
Allow from all
</Directory>
ErrorLog ${APACHE_LOG_DIR}/error.log
# Possible values include: debug, info, notice, warn, error, crit,
# alert, emerg.
LogLevel warn
CustomLog ${APACHE_LOG_DIR}/ssl_access.log combined
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
# A self-signed (snakeoil) certificate can be created by installing
# the ssl-cert package. See
# /usr/share/doc/apache2.2-common/README.Debian.gz for more info.
# If both key and certificate are stored in the same file, only the
# SSLCertificateFile directive is needed.
# SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem
# SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key
SSLCertificateFile /etc/apache2/ssl/server.crt
SSLCertificateKeyFile /etc/apache2/ssl/server.key
# Server Certificate Chain:
# Point SSLCertificateChainFile at a file containing the
# concatenation of PEM encoded CA certificates which form the
# certificate chain for the server certificate. Alternatively
# the referenced file can be the same as SSLCertificateFile
# when the CA certificates are directly appended to the server
# certificate for convinience.
#SSLCertificateChainFile /etc/apache2/ssl.crt/server-ca.crt
# Certificate Authority (CA):
# Set the CA certificate verification path where to find CA
# certificates for client authentication or alternatively one
# huge file containing all of them (file must be PEM encoded)
# Note: Inside SSLCACertificatePath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCACertificatePath /etc/ssl/certs/
#SSLCACertificateFile /etc/apache2/ssl.crt/ca-bundle.crt
# Certificate Revocation Lists (CRL):
# Set the CA revocation path where to find CA CRLs for client
# authentication or alternatively one huge file containing all
# of them (file must be PEM encoded)
# Note: Inside SSLCARevocationPath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCARevocationPath /etc/apache2/ssl.crl/
#SSLCARevocationFile /etc/apache2/ssl.crl/ca-bundle.crl
# Client Authentication (Type):
# Client certificate verification type and depth. Types are
# none, optional, require and optional_no_ca. Depth is a
# number which specifies how deeply to verify the certificate
# issuer chain before deciding the certificate is not valid.
#SSLVerifyClient require
#SSLVerifyDepth 10
# Access Control:
# With SSLRequire you can do per-directory access control based
# on arbitrary complex boolean expressions containing server
# variable checks and other lookup directives. The syntax is a
# mixture between C and Perl. See the mod_ssl documentation
# for more details.
#<Location />
#SSLRequire ( %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
# and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
# and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
# and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
# and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20 ) \
# or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
#</Location>
# SSL Engine Options:
# Set various options for the SSL engine.
# o FakeBasicAuth:
# Translate the client X.509 into a Basic Authorisation. This means that
# the standard Auth/DBMAuth methods can be used for access control. The
# user name is the `one line' version of the client's X.509 certificate.
# Note that no password is obtained from the user. Every entry in the user
# file needs this password: `xxj31ZMTZzkVA'.
# o ExportCertData:
# This exports two additional environment variables: SSL_CLIENT_CERT and
# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
# server (always existing) and the client (only existing when client
# authentication is used). This can be used to import the certificates
# into CGI scripts.
# o StdEnvVars:
# This exports the standard SSL/TLS related `SSL_*' environment variables.
# Per default this exportation is switched off for performance reasons,
# because the extraction step is an expensive operation and is usually
# useless for serving static content. So one usually enables the
# exportation for CGI and SSI requests only.
# o StrictRequire:
# This denies access when "SSLRequireSSL" or "SSLRequire" applied even
# under a "Satisfy any" situation, i.e. when it applies access is denied
# and no other module can change it.
# o OptRenegotiate:
# This enables optimized SSL connection renegotiation handling when SSL
# directives are used in per-directory context.
#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
<Directory /usr/lib/cgi-bin>
SSLOptions +StdEnvVars
</Directory>
# SSL Protocol Adjustments:
# The safe and default but still SSL/TLS standard compliant shutdown
# approach is that mod_ssl sends the close notify alert but doesn't wait for
# the close notify alert from client. When you need a different shutdown
# approach you can use one of the following variables:
# o ssl-unclean-shutdown:
# This forces an unclean shutdown when the connection is closed, i.e. no
# SSL close notify alert is send or allowed to received. This violates
# the SSL/TLS standard but is needed for some brain-dead browsers. Use
# this when you receive I/O errors because of the standard approach where
# mod_ssl sends the close notify alert.
# o ssl-accurate-shutdown:
# This forces an accurate shutdown when the connection is closed, i.e. a
# SSL close notify alert is send and mod_ssl waits for the close notify
# alert of the client. This is 100% SSL/TLS standard compliant, but in
# practice often causes hanging connections with brain-dead browsers. Use
# this only for browsers where you know that their SSL implementation
# works correctly.
# Notice: Most problems of broken clients are also related to the HTTP
# keep-alive facility, so you usually additionally want to disable
# keep-alive for those clients, too. Use variable "nokeepalive" for this.
# Similarly, one has to force some clients to use HTTP/1.0 to workaround
# their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
# "force-response-1.0" for this.
BrowserMatch "MSIE [2-6]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
# MSIE 7 and newer should be able to use keepalive
BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
</VirtualHost></IfModule>
sudo vim /etc/apache2/ports.conf
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default
# This is also true if you have upgraded from before 2.2.9-3 (i.e. from
# Debian etch). See /usr/share/doc/apache2.2-common/NEWS.Debian.gz and
# README.Debian.gz
NameVirtualHost *:80
Listen 80
<IfModule mod_ssl.c>
# If you add NameVirtualHost *:443 here, you will also have to change
# the VirtualHost statement in /etc/apache2/sites-available/default-ssl
# to <VirtualHost *:443>
# Server Name Indication for SSL named virtual hosts is currently not
# supported by MSIE on Windows XP.
NameVirtualHost 192.168.0.135:443
Listen 443
</IfModule>
notes ; itu ip 192.168.0.135 itu ip pc saya :senyum
Langkah 13 ; Cek semua yang dikonfigurasi tadi.
sudo apache2ctl configtest
Langkah 14 ; Restart Apache
sudo service apache2 restart
Dan
jika semua konfigurasi berhasil, buka browser dan ketik
https://192.168.0.135. Ingat ya, kita tidak deklarasi localhost pada
virtualhost. Jadi misalnya kalian mengetik https://localhost,
kemungkinan muncul ssl conncetion error seperti gambar 3.
gambar 1
Akan muncul seperti gambar 1, jika membuka https://192.168.0.135. Step selanjutnya browser akan menambahkan pada list certificatenya untuk selajutnya proses trust
gambar 2
Jika klik proceed anyway, maka akan masuk ke document rootnya. Dan akan muncul seperti gambar 2.
gambar 3
Muncul gambar 3 karena ipnya tidak sesuai dengan yang ada di virtualhost dan konfigurasi file ports.conf
Nah
pada gambar 1 muncul warning jika masuk https, karena proses certifiate
di atas memakai self signed. Jadi kalau tidak mau muncul warning di
atas, maka beli signature dari Versign vendor ssl lainnya.
Kalau kurang jelas bisa lihat ini.
Sunday, August 9, 2015
Install Kloxo Control Panel Di VPS ( Cent OS / RHEL – RedHat Linux)
, sekedar referensi saya telah sharing beberapa Webserver Control Panel disini : 6 Webserver Control Panel Gratis Untuk Linux BasedDan sekedar memberikan saran direkomendasikan untuk mempunyai RAM VPS sebesar 256MB tapi kalau 128MB ya bisa saja , karena saya juga sudah mencobanya di 128MB dan hasilnya juga lumayan Maksimum.
Kloxo adalah salah satu Webserver Control Panel yang dikembangkan oleh LXLABS yang sekarang situsnya telah beralih ( sebenarnya sudah lama ) ke lxcenter.org , Kloxo mempunyai banyak keunggulan selain ringan juga sangat kompatible dengan berbagai macam OS linux, serta sudah siap terintegrasi dengan Billing Hosting seperti WHMCS , BOXBILLING dan HostBill. Walaupun mungkin sudah banyak yang membahasnya saya mencoba membahas kembali disini , alasannya proses penginstallan untuk beberapa orang / user awam yang masih belum tahu banyak tentang Linux akan mendapat kesulitan dalam penginstallan. Jadi kalau kita mau buat VPS sebagai Webserver gak perlu yang namanya remote desktop dan sebagainya cukup install Control Panel saja
udah cukup biar gak berat- beratin server.Disini saya menggunakan CENTOS 5.8 ( final ) karena dengar dengar paling banyak digunakan dan stabil serta sudah banyak pembahasan di google, saya menyarankan bila sahabat memilih OS pilih CENT OS 5.8 ya
hehehe… biar lancar 
note : tanda # hanya sebagai tanda prefix saja, saat memasukkan Command jangan masukkan tanda # ke SSH console
PREPARE
- Koneksi internet yang stabil ( tidak terputus putus – cari sinyal yang bagus kalau perlu naek genteng sekalian )
- SSH Tools atau saya sarankan untuk menggunakan Putty karena lebih mudah . bisa sahabat dpatkan disini ,
putty - Minimal Diskspace yang diperlukan untuk Kloxo adalah 2GB jadi yah , jangan ampe punya VPS yang diskspace kurang dari 2GB
- WInSCP (optional) agar lebih mudah kalau nanti
ingin mengedit file bagi pengguna Windows based. (WinSCP dapat
terintegrasi dengan Putty) WInSCP ini layaknya FTP Client tapi jauh
lebih lengkap dan ttransparant , walaupun Opsional tapi ini sangat
berguna monggo Didownload dulu
di situsnya → http://winscp.net/eng/download.php - 3 cangkir kopi dan satu pak rokok serta banyak kesabaran , baca juga ini yah sebelum minum kopi
→ Manfaat dan Kerugian Minum Kopi.
Persiapkan segala yang diperlukan mulai dari Koneksi yang baik sampai kopi manisnya, langsung praktek .:
CONFIGURE
- Buka Console SSH ( putty ) dan masuk sebagai Root User ( username : root)
ssh root access console - Lakukan Perintah :
# yum update
Disini adalah berfungsi untuk mengupdate system OS sahabat , kalau tidak mau di update lewati langkah ini ( tapi saya sarankan lakukan ini untuk mengupdate beberapa repository di OS sahabat ) tunggu hingga selesai pengoperasian :). - Disable Sellinux – entah kenapa harus didisable tapi yang pasti
Kloxo mengharuskan disable Selinux pada System sahabat dengan command
berikut :
# su - root # setenforce 0
su – root disini adalah sebagai untuk mengakses directory utama user root atau /root/
dan setenforce 0 adalah untuk mendisable selinux.
untuk memastikan selinux disable ketikkan command berikut , kalau selinux tidak di disable maka sahabat akan membuang buang waktu untuk menginstall Kloxo bahkan akan terpaksa menginstall kloxo .
# /usr/sbin/sestatus
Kalau Selinux telah berhasil terdisable maka akan tampak pemberitahuan seperti ini :
SELinux status: disabled
selinux disable - Setelah itu pastikan port 7777/tcp dan 7778/tcp terbuka , dan
biasanya default CentOS masih tertutup maka kita harus membukanya, kalau
tidak kita buka menurut pengalaman beberapa kali install saya gagal
terus
. ketikkan perintah berikut di Console SSH :
# iptables -I INPUT -p tcp --dport 7777 -j ACCEPT # iptables -I INPUT -p tcp --dport 7778 -j ACCEPT #service iptables save service iptables restart
Berlanjut ke Pengisntallan
INSTALLATION
Lanjutkan ke Proses Installasi Kloxo , dan disini kita harus mengetahui mysql telah terinstal atau belum , sehingga bisa memberikan penginstallan yang benar terhadap Kloxo ,dengan command Berikut :
# yum grouplistTunggu hingga selesai , dan lihat di paket yang terinstall , apa saja. Dan biasanya Default Fresh Installation di CentOS paket mysql belum terintsall. Dan ikuti lngkah berikut apabila MySQL belum terinstall :

yum grouplist
- Pastikan sahabat masih berada di console SSH dengan user root , lakukan command berikut :
# yum install -y wget # wget http://download.lxcenter.org/download/kloxo/production/kloxo-installer.sh
- Walau kadang Wget sudah terinstall tapi kita usahakan menginstall
atau upgrade Wget Tools di CentOS / Linux kita , fungsi wget adalah
untuk mendapatkan file / download file dari direct Download Site.
wget install session - Setelah melakukan download kloxo-installer.sh, maka kita
lakukan proses penginstallan , ada 2 pilihan yaitu Kloxo hanya sebagai
single server ataukah sebagai Slave , berikut SSH command:Untuk
Menjadikan Kloxo sebagai Single Master :
# sh ./kloxo-installer.sh --type=master
Untuk menjadikan Kloxo sebagai Slave :
# sh ./kloxo-installer.sh --type=slave
Untuk sahabat yang kurang begitu paham jalankan saja sebagai Master :
Nb : pada screen shot diatas terlihat bahwa ke empat baris dari awal tertulis pemberitahuan tentang :
begin install
– installing as “root” [OK] –> bahwa proses install berupa user root
– Operating System Supported [OK] –> Os yang dipakai compatible dengan Kloxo
– SELinux Disabled [OK] –> bahwa SELinux telah disable / dinonaktifkan.
– Yum Installed [OK] –> Program Yum telah terinstall
Tekan Tombol apapun untuk melanjutkan , proses installasi. - Tunggu sampai Proses Selesai , akan tetapi saat nanti ada pemberitahuan InstallApp Software,
bisa sebagai pilihan kalau memang sahabat mempunyai diskspace yang
besar boleh diinstall , dan saya sarankan dan banyak yang menyarankan
pula jangan diinstall atau pilih “N” karena Script yang
tersedia sudah tidak uptodate atau kedaluwarssa dan merupakan software
lama, InstallApp adalah seperti halnya Softaculous AutoInstaller.
Seperti pada ScreenShot diatas setelah menyetujui Agreement
installapp Software
setelah selang beberapa proses penginstallan sahabat akan diberikan pertanyaan untuk mengisi password , dan isikan password sahabat , tapi ngetiknya pelan pelan ya
dan isikan dengan password yang mudah diingat.
Setelah sahabat isikan password maka penginstallan akan berlanjut lagi.
isi password
dan berikut adalah tampilan saat Kloxo telah selesai diinstal :
installasi kloxo telah berhasil - Setelah selesai maka Kloxo akan memberikan screen bahwa Kloxo telah
berhasil di install , serta untuk mengunjungi Admin Cpanel , bisa akses
ke :http://alamat_ip:7778Dan masuk menggunakan ,
username : admin
password : admin
Kloxo Panel Login http://ip_vps:7778
setelah sahabat memasuki area Kloxo maka sahabat akan disarankan untuk mengubah Password Control Panel Kloxo sahabat.
kloxo change password - Selesai sudah install Kloxo nya


Cek Versi Php dengan Command :
# php -vRangkuman install :
# yum update # setenforce 0 # iptables -I INPUT -p tcp --dport 7777 -j ACCEPT # iptables -I INPUT -p tcp --dport 7778 -j ACCEPT # yum install -y wget # wget http://download.lxcenter.org/download/kloxo/production/kloxo-installer.sh # sh ./kloxo-installer.sh --type=master atau untuk slave # sh ./kloxo-installer.sh --type=slave Akses ke halaman control panel admin dengan alamat : http://alamat_ip:7778 dan masuk menggunakan user & password = admin Setelah itu selesai penginstallanUPDATE..!!! berminat dengan kloxo yang lebih optimal akses disini : Kloxo MR - Alternativ Kloxo yang lebih optimal
Subscribe to:
Posts (Atom)


