Tuesday, November 22, 2016

How to Install Taiga Open Source Agile Project Manager & Kanban on CentOS 7

Taiga is a beautiful, open-source project management platform tailored for agile teams, Scrum sprints, and Kanban workflows. While official documentation primarily targeted Ubuntu, Taiga deploys smoothly on CentOS 7 with PostgreSQL, Python virtualenvs, and Nginx.

Architecture: taiga-back (Django / Python 3.5+) • taiga-front (AngularJS HTML5) • PostgreSQL 9.4+ • Nginx reverse proxy

1. Installing System Packages on CentOS 7

Install prerequisite development libraries and PostgreSQL:

yum install epel-release -y
yum install gcc gcc-c++ make automake git zlib-devel bzip2-devel openssl-devel   ncurses-devel sqlite-devel readline-devel tk-devel gdbm-devel db4-devel   libpcap-devel xz-devel libjpeg-turbo-devel libxml2-devel libxslt-devel   postgresql-server postgresql-devel redis nginx -y

2. PostgreSQL Setup

postgresql-setup initdb
systemctl start postgresql
systemctl enable postgresql

sudo -u postgres createuser -s taiga
sudo -u postgres createdb -O taiga taiga

3. Frontend & Backend Deployment

Deploy taiga-back inside an isolated Python virtual environment, execute database migrations via python manage.py migrate, unpack taiga-front-dist to /home/taiga/taiga-front-dist, and configure Nginx to proxy API endpoints to Gunicorn on port 8001.

Wednesday, November 9, 2016

How to Compile and Install the Latest qpdfview and Evince on Ubuntu & Debian

For Linux desktop users seeking a high-performance, lightweight PDF and DjVu document viewer with tabbed browsing, qpdfview (built with Qt5 and Poppler) is significantly faster and more customizable than default desktop readers like Evince.

Features: Tabbed reading • Continuous two-page layout • Low memory footprint • Poppler Qt5 rendering

Installation Steps (Ubuntu / Debian)

# 1. Install Qt5 and document format rendering development packages
sudo apt-get install qttools5-dev-tools libpoppler-qt5-dev libspectre-dev   libdjvulibre-dev libcups2-dev build-essential -y

# 2. Download and build latest qpdfview release
mkdir -p ~/src && cd ~/src
wget https://launchpad.net/qpdfview/trunk/0.4.17/+download/qpdfview-0.4.17.tar.gz
tar -zxf qpdfview-0.4.17.tar.gz
cd qpdfview-0.4.17

# 3. Generate Makefile and compile with all plugins enabled
lrelease qpdfview.pro
qmake qpdfview.pro
make -j$(nproc)
sudo make install

Wednesday, October 26, 2016

How to Install a Private Git Server with CGIT Web Frontend on CentOS 7

Self-hosting a lightweight Git web interface like CGIT written in C provides near-instant page loads, minimal RAM footprint, and syntax-highlighted code browsing compared to heavyweight alternatives like GitLab.

Stack: CentOS 7 • CGIT • fcgiwrap • Nginx • highlight syntax engine

1. Installing Prerequisites and fcgiwrap

CGIT operates as a FastCGI binary. Install fcgiwrap to interface between Nginx and the CGIT binary:

yum install epel-release -y
yum install fcgi-devel highlight git autoconf automake libtool -y

cd /usr/src
git clone https://github.com/gnosek/fcgiwrap.git
cd fcgiwrap
autoreconf -i
./configure --prefix=/usr
make && make install

2. Compiling CGIT from Source

cd /usr/src
git clone https://git.zx2c4.com/cgit
cd cgit
git submodule init
git submodule update
make get-git
make && make install

3. Nginx FastCGI Integration

Configure Nginx to route CGIT requests to the fcgiwrap socket:

location / {
    fastcgi_pass unix:/var/run/fcgiwrap.sock;
    fastcgi_param SCRIPT_FILENAME /var/www/htdocs/cgit/cgit.cgi;
    fastcgi_param PATH_INFO $uri;
    fastcgi_param QUERY_STRING $args;
    fastcgi_param HTTP_HOST $server_name;
    include fastcgi_params;
}

Sunday, October 2, 2016

How to Build a Low-Latency HLS & RTMP Live Streaming Server on Linux (Nginx RTMP Module)

Setting up your own live video streaming infrastructure on a Linux VPS or dedicated server provides full control over bitrate, privacy, and latency without third-party platform restrictions. This complete guide walks through configuring an Nginx RTMP + HLS media server on CentOS 7, publishing from OBS Studio / FFmpeg, and embedding the stream in modern web browsers.

Architecture: Nginx with nginx-rtmp-module • HLS fragmenting (Apple HTTP Live Streaming) • Broadcaster: OBS / FFmpeg • Player: HTML5 HLS.js

Part 1: Compiling Nginx with RTMP Support (CentOS 7)

Install development packages and compile Nginx with the RTMP module:

yum install gcc-c++ pcre-devel zlib-devel openssl-devel git -y
cd /usr/src
git clone https://github.com/arut/nginx-rtmp-module.git
wget http://nginx.org/download/nginx-1.12.2.tar.gz
tar -zxf nginx-1.12.2.tar.gz
cd nginx-1.12.2

./configure --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx   --conf-path=/etc/nginx/nginx.conf --pid-path=/var/run/nginx.pid   --with-http_ssl_module --with-http_v2_module   --add-module=/usr/src/nginx-rtmp-module

make && make install

Part 2: Configuring RTMP and HLS Ingestion

Add the RTMP server block to /etc/nginx/nginx.conf:

rtmp {
    server {
        listen 1935;
        chunk_size 4096;

        application live {
            live on;
            hls on;
            hls_path /var/www/hls;
            hls_fragment 3;
            hls_playlist_length 60;
            # Restrict streaming publishing to your IP:
            allow publish 127.0.0.1;
            allow publish YOUR.OFFICE.IP;
            deny publish all;
        }
    }
}

Configure HTTP delivery for the HLS .m3u8 playlists and .ts video segments in /etc/nginx/conf.d/stream.conf:

server {
    listen 80;
    server_name stream.example.com;

    location /hls {
        types {
            application/vnd.apple.mpegurl m3u8;
            video/mp2t ts;
        }
        root /var/www;
        add_header Cache-Control no-cache;
        add_header Access-Control-Allow-Origin *;
    }
}

Part 3: Broadcasting and Playback

In OBS Studio, set the Stream URL to rtmp://YOUR-SERVER-IP/live and choose a Stream Key (e.g. mystream). In your web page, point your HLS video player to http://YOUR-SERVER-IP/hls/mystream.m3u8 for instant, cross-browser live playback.

Thursday, September 22, 2016

How to Compile the Zulip Desktop Client from Source on Ubuntu 16.04 (Xenial)

Building the Zulip desktop client from source on Ubuntu 16.04 LTS (Xenial Xerus) requires resolving Qt5 WebKit, multimedia, and GStreamer Phonon audio backend dependencies.

Stack: Ubuntu 16.04 LTS • Qt 5.x • CMake • Zulip Desktop 0.5.x

Build and Installation Commands

# 1. Install Qt5 development libraries and phonon GStreamer backends
sudo apt-get install git cmake qt5-default libqt5svg5-dev libqt5webkit5-dev   qtmultimedia5-dev libjson0-dev phonon-backend-gstreamer phonon4qt5-backend-gstreamer -y

# 2. Download and build Zulip Desktop
wget https://github.com/zulip/zulip-desktop/archive/0.5.1.tar.gz
tar -zxf 0.5.1.tar.gz
cd zulip-desktop-0.5.1
mkdir build && cd build
cmake .. -DBUILD_WITH_QT5=On
make
sudo make install

# 3. Register Desktop launcher
cd /usr/share/applications
sudo ln -s /usr/local/share/applications/Zulip.desktop .

Friday, September 16, 2016

[Solved] Fixing Broken DomainKeys and DKIM Signatures Sent via PHP mail()

When sending emails through PHP's native mail() function on a server configured with SPF, DomainKeys, and DKIM (such as Plesk), desktop mail clients (Outlook, Thunderbird) may sign outbound emails correctly, but emails dispatched from web scripts fail DKIM verification with invalid domain signatures.

The Trap: Setting a raw From: string inside $additional_headers causes the sendmail wrapper to misidentify the originating signing domain d=$DOMAIN.

The Problematic Call

// This breaks DKIM signatures by overriding the sender envelope incorrectly:
mail($to, $subject, $message, "From: Name <user@domain.com>");

The Solution

Explicitly pass the envelope sender using the -f flag in the 5th parameter ($additional_parameters):

// Correct invocation with verified envelope sender:
mail($to, $subject, $message, "", "-f user@domain.com");

Verification Tip: Send a test email to check-auth@verifier.port25.com. The automated robot will reply within seconds with a detailed SPF, DKIM, DomainKeys, and SpamAssassin diagnostic report.

Wednesday, September 14, 2016

[Solved] Postfix SASL Authentication Failure: realm changed: authentication aborted in Plesk

When enabling STARTTLS on a Plesk server running Postfix, mail clients like Mozilla Thunderbird may connect normally, while Microsoft Outlook clients repeatedly fail with authentication popups and the following mail log errors:

Environment: Plesk • Postfix with STARTTLS • Cyrus SASL Authentication
postfix/smtpd[1929]: warning: SASL authentication failure: realm changed: authentication aborted
postfix/smtpd[1929]: warning: SASL DIGEST-MD5 authentication failed: authentication failure

Root Cause & Solution

Outlook struggles with DIGEST-MD5 SASL negotiation over TLS on certain Cyrus SASL configurations. Restricting the SASL mechanism list to CRAM-MD5, PLAIN, and LOGIN resolves the negotiation conflict:

  1. Edit /usr/lib64/sasl2/smtpd.conf and update mech_list:
    mech_list: CRAM-MD5 PLAIN LOGIN
  2. Edit /etc/postfix/main.cf and confirm security options:
    smtpd_sasl_security_options = noanonymous
  3. Restart services:
    service postfix restart
    service saslauthd restart

Tuesday, September 13, 2016

Setting Up Vim with Python 2/3 Support and Code Completion on Ubuntu 16.04

Configuring Vim as a fast, keyboard-driven Python IDE significantly boosts developer productivity. When following standard Vim Python configuration guides on Ubuntu 16.04 (Xenial Xerus), several key adjustments are required to achieve clean PEP 8 indentation, accurate syntax highlighting, and YouCompleteMe code autocompletion.

Stack: Ubuntu 16.04 LTS • Vim 7.4 / 8.0 • Python PEP 8 indentation rules

1. Enforcing Clean PEP 8 Indentation

Add the following configuration to your ~/.vimrc to ensure 4-space indentations, soft tabs, and trailing whitespace highlighting:

" PEP 8 standard formatting for Python buffers
augroup python_indent
    autocmd!
    autocmd FileType python setlocal tabstop=4
    autocmd FileType python setlocal softtabstop=4
    autocmd FileType python setlocal shiftwidth=4
    autocmd FileType python setlocal textwidth=79
    autocmd FileType python setlocal expandtab
    autocmd FileType python setlocal autoindent
    autocmd FileType python setlocal fileformat=unix
augroup END

2. Installing YouCompleteMe on Ubuntu 16.04

Install prerequisite development libraries before compiling the YCM C-extension:

sudo apt-get install build-essential cmake python-dev python3-dev -y
cd ~/.vim/bundle/YouCompleteMe
./install.py --clang-completer

Saturday, August 6, 2016

How to Fix VMware ESXi 6.0 Root Account Lockout and Brute-Force Restrictions

Starting with version 6.0, VMware ESXi introduced an automated security lockout feature that locks the root account after consecutive failed login attempts. On hypervisors exposed to public networks, malicious automated SSH bots frequently trigger this threshold, inadvertently locking legitimate administrators out of the vSphere Client and Web UI.

Security Best Practices: Enforce SSH key-based authentication • Restrict ESXi management firewall to designated administrative IPs.

1. Unlocking the Root Account via Local Console (DCUI)

Log in via the physical or out-of-band Direct Console User Interface (DCUI), navigate to Troubleshooting Options, enable the ESXi Shell, and reset the lockout counter:

# Check failed login attempt count
pam_tally2 --user root

# Reset failed attempt counter and unlock account
pam_tally2 --user root --reset

2. Permanent Hardening: Restrict Management Access

To eliminate unauthorized brute-force attempts permanently:

  1. Disable SSH password logins in /etc/ssh/sshd_config:
    PasswordAuthentication no
  2. Restrict the ESXi management firewall rule for the vSphere Client (port 443 / 902) to your office or VPN gateway IPs:
    esxcli network firewall ruleset set --ruleset-id vSphereClient --allowed-all false
    esxcli network firewall ruleset allowedip add --ruleset-id vSphereClient --ip-address 203.0.113.10

Thursday, August 4, 2016

Essential Techniques to Block Browser Fingerprinting, Canvas Tracking, and Audio APIs

Standard "Private Browsing" or "Incognito" modes prevent local history from saving to disk, but they do little to protect your identity from sophisticated web trackers. Modern tracking networks rely on device fingerprinting—measuring system fonts, GPU rendering quirks via HTML5 Canvas, WebGL parameters, audio latency, and installed plugins to create a persistent hardware signature across sessions.

Auditing Tools: Test your browser uniqueness at EFF Panopticlick (Cover Your Tracks) and BrowserLeaks.

Key Tracking Vectors and Countermeasures

  • HTML5 Canvas Fingerprinting: Trackers draw invisible shapes and text behind the scenes; minute GPU driver rendering variations produce a unique hash.

    Defense: Install privacy tools like Canvas Defender or Firefox's native privacy.resistFingerprinting = true in about:config.

  • AudioContext API Tracking: Variations in audio buffer processing across system sound cards provide another identifiable vector.

    Defense: Block non-consensual Web Audio processing through extension policies.

  • System Font Enumeration: Tracking scripts measure font rendering metrics across hundreds of installed fonts.

    Defense: Restrict font queries to standard platform fonts (layout.css.font-visibility.standard = 1 in modern Firefox).

  • WebRTC IP Leakage: WebRTC STUN requests can expose real public and private LAN IPs even when connected behind a VPN proxy.

    Defense: Set media.peerconnection.enabled = false.

Tuesday, July 19, 2016

How to Configure Docker with the Btrfs Storage Driver on CentOS 7

On CentOS 7, Docker initially defaulted to the devicemapper storage driver in loop-lvm mode, which suffered from high I/O latency, severe disk fragmentation, and occasional filesystem deadlocks. Configuring Docker to use the Btrfs storage driver provides native copy-on-write subvolumes, instant snapshots, and superior performance for virtualized hosts.

Prerequisites: Dedicated block device or partition formatted as Btrfs (e.g. /dev/sdb1).

1. Create and Mount the Btrfs Filesystem

# Format partition as Btrfs
mkfs.btrfs -f /dev/sdb1

# Mount at Docker root directory
mkdir -p /var/lib/docker
mount -t btrfs /dev/sdb1 /var/lib/docker

Add the mount to /etc/fstab for persistence across reboots:

/dev/sdb1  /var/lib/docker  btrfs  defaults,compress=lzo  0 0

2. Configure Docker Daemon

Specify the Btrfs driver in /etc/docker/daemon.json:

{
  "storage-driver": "btrfs"
}

Start Docker and verify the active storage engine:

systemctl start docker
docker info | grep "Storage Driver"

Tuesday, March 8, 2016

How to Use Persian and Eastern Arabic Numerals for Zotero Citations in Microsoft Word

When writing academic papers and theses in Persian or Arabic using Microsoft Word, the Zotero plugin often renders citation reference numbers (e.g. [1], [2]) using Western Arabic numerals (1, 2, 3), even when Word's numeral display setting is configured to Context under File → Options → Advanced.

Goal: Automatically convert Zotero bibliography and in-text citation numbers into Persian / Eastern Arabic digits (۱, ۲, ۳).

The Solution: Modifying the CSL Locale Style

Zotero determines numeral localization through its Citation Style Language (CSL) locale definition. You can enforce native localized digits across your document:

  1. In Zotero, navigate to Preferences → Advanced → Config Editor.
  2. Search for extensions.zotero.export.bibliographyLocale and set it to fa-IR (or your target RTL language code).
  3. Alternatively, edit the CSL style file (.csl) by adding the xml:lang="fa-IR" attribute to the root <style> element:
    <style xmlns="http://purl.org/net/xbiblio/csl" version="1.0" xml:lang="fa-IR">
  4. Return to Word and click Zotero Refresh. All bracketed citations will update to Eastern Arabic / Persian numerals smoothly.

Tuesday, February 2, 2016

Installing ShareLaTeX with Docker and CSF Firewall on Linux (CentOS & Ubuntu)

Self-hosting ShareLaTeX (now Overleaf Community Edition) enables collaborative scientific paper writing with full data privacy. Deploying ShareLaTeX via its official Docker container is straightforward, but servers protected by ConfigServer Security & Firewall (CSF) require specific iptables routing configurations to allow containerized network traffic without exposing internal services.

Components: Docker Engine • ShareLaTeX Container • CSF Firewall iptables rules

1. Deploying the Container

docker run -d   -v ~/sharelatex_data:/var/lib/sharelatex   --name=sharelatex   -p 3000:80   sharelatex/sharelatex

2. Resolving CSF Firewall and Docker Bridging Conflicts

By default, CSF disables Docker's automated iptables forwarding rules, cutting off outbound container traffic and external port mapping. Add the following exceptions to /etc/csf/csfpost.sh to restore seamless Docker connectivity:

#!/bin/bash
# Allow bridge network traffic for Docker containers
iptables -A FORWARD -i docker0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o docker0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -s 172.17.0.0/16 -o eth0 -j MASQUERADE

Make /etc/csf/csfpost.sh executable and restart CSF:

chmod +x /etc/csf/csfpost.sh
csf -r

Wednesday, January 6, 2016

How to Install and Use zerofree on CentOS, RHEL, and Fedora to Compact VM Disks

When shrinking dynamic virtual machine disk images (such as VirtualBox VDI, VMware VMDK, or QEMU QCOW2), zeroing out unused filesystem blocks is essential for effective host compression. Because Enterprise Linux distributions (CentOS 6/7, RHEL) do not ship zerofree in their default package repositories, compiling from source is the quickest solution.

Environment: CentOS 6/7 • RHEL • Fedora • Ext3 / Ext4 Filesystems

1. Installing Build Headers and Compiling zerofree

Install the e2fsprogs development headers and compile:

yum install e2fsprogs-devel gcc make -y
cd /usr/src
wget http://frippery.org/uml/zerofree-1.0.3.tgz
tar -zxf zerofree-1.0.3.tgz
cd zerofree-1.0.3
make
cp zerofree /usr/bin/

2. Zeroing Out Unallocated Blocks

Important: Always remount the target filesystem in read-only mode prior to executing zerofree to prevent filesystem corruption:

# Remount filesystem as read-only:
mount -o remount,ro /

# Run zerofree on the target block partition:
zerofree -v /dev/sda1

Once complete, shut down the VM and run your hypervisor's disk compacting command (e.g. VBoxManage modifymedium --compact disk.vdi) on the host machine.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...