2008/01/08

Oracle Database PL/SQL User's Guide and Reference

非常不错的PL/SQL的介绍,文字虽然不多,但是足可以让你对PL/SQL的基本功能和语法有了大致的了解。抽象水平非常高啊~~~

下回打印一份随身携带阅读!

2007/07/13

2007/06/21

Installation Debian/Ubuntu over SSH

By using the debootstrap, it is possible for us to install the Debian or Ubuntu inside an Linux machine without a booting from Floppy/CD/USB/Net. It is really funny.

2007/05/07

Yahoo! UI Library (YUI)

Yahoo! UI Library (YUI) an BSD licensed JavaScript UI library released by Yahoo!.

I play with it for a while, at the first glance, it looks like a Dojo Toolkit. But unlike the Dojo, all the functions are very well documented with JSDoc. For all the sub-modules, full/debug/min versions are provided for purposes. But it only provides a subset features of Dojo. :)

So YUI is:
  • Well documented;
  • Well organized object hierarchy;
  • Less features

2007/05/06

Perl 5.8 PerlIO feature

With the new PerlIO feature and Unicode support in Perl 5.8, it is possible to do the internal encoding change with only a few lines of code.

Please check the code below. It will be able to read the GBK input from STDIN and convert it to UTF-8 to STDOUT. :)


#!/usr/bin/perl -W

use encoding "gbk", STDOUT => "utf8";
while(<>){print};


Power and Simple. :D

又长了一岁~~~

又长了一岁,为自己庆祝一下! :D

2007/04/09

Waltzing with Bears

最近每天坐在城铁上,就会翻看几页 《与熊共舞》 其中第14章,风险发现的详细过程 ,里面对企业里使人们对风险三缄其口的原因。 说起来这确实是很普遍存在的。

因为在这些企业里,有一些根深蒂固的不成文的规定:
  1. 不要成为有消极想法的人;
  2. 不要指出问题,除非你有解决办法;
  3. 不要说任何事可能是一个问题,除非你能证明它是;
  4. 不要做拆台的人;
  5. 不要明确指出问题,
说起来大致如此......

2007/02/28

Erlang 的运行时更新

Erlang 作为电信级开发语言,在设计之初就有了在运行时自动更新程序,也就是不停机打patch的能力。 首先这种功能对于电信级别的程序来说,是非常必要的,如果不能做到这个5个9基本上就是空谈了。

然而对于传统的使用C/C++或者Java开发的程序而言,全面支持这种能力是非常复杂的,这种复杂性主要是有由于C/C++ 语言的自身特性所决定的。由C语言开发的程序的运行态,在地址空间中一般都具有4个以上的sections:
  1. text/代码段 就是程序本身
  2. data/数据段 用来保存全局变量,静态变量,以及未初始化的变量;
  3. stack/程序堆栈 用来保存当前线程的临时变量 对于C/C++ 来说它保存了程序的运行状态;
  4. heap/堆 用来保存程序运行中分配的临时变量;

text 在连接程序完成之后就确定的,对于同一份源程序产生的都是完全一样的。
data 在程序的连接完成之后,它在内存中的位置也已经确定,但是内容可能会随运行态改变。
stack 和 heap 则是完全动态的,而一个运行程序的stack数量和他所具有的thread数量相对应。基本上可以认为这两个段不能够采用认可以预定义——简单替换的方式进行更新,它们的内容对于非运行系统而言是不可知的。

因此为一个处在正在运行中的应用打补丁,需要:
  1. 不改变text代码段中的函数的入口地址。因为在stack中会保存这些函数的入口地址,如果改变了它们的地址,必将导致程序跑飞。
  2. 不能改变text代码段中所有已有函数的参数或者调用方式。
  3. 不能在中间增加数据段中全局变量。因为这将改变已有的全局变量的地址,使代码引用错误的变量。
  4. 不能简单替换数据段中的变量内容,即不能随意修改源程序中非const全局变量的内容。
然而对于C/C++程序而言,如果需要不停机打patch,这是最基本的要求。而在实际工作中,很难要求所有的fix都满足上面的要求! 其实也能做,但是代价太高了~~~。

Erlang 只有代码段,没有数据段,所有数据都动态,实现这样的功能确实要简单很多。而且 Erlang 又是已虚拟机的方式运行,替换代码段的难度又有所降低。

对于 Erlang 而言,运行时程序更新,这样的功能就算是水到渠成吧!

2007/02/11

关于 Erlang

在国内小程序员的圈子里,高水平的不多,但是跟风的水平还是不低的,C/C++, VB, Delphi, Java, C#, Perl, Python, PHP, Lua, JavaScript, Rudy, Haskell, Erlang...... 随风而来。不才也跟了一把风 Erlang 了一把! 说起这个 Erlang 真正令我感兴趣的地方是——它是由 Ericsson 开发出来的用于电信级应用程序开发的语言。说来惭愧现在也算是在电信圈子里面(当然不在Ericsson) 讨生活的菜鸟吧! 不由自主地对别人如何做同样的东西有兴趣。 算起来也在上面画了N个小时了,有点感受也记录下来总也不算是枉费了这些时间。

首先,Erlang 诞生于于1980年代,在 Ericsson Computer Science Laboratory,虽然没有官方的说明,当时我个人感觉,Erlang的根本源于LISP,虽然语法上作了一些变化,但是语言的本质上确是不可回避的LISP风骨:函数语言,自动内存管理,原子概念,LIST/表操作,不一而足,虽然从语法上作了一些改变,摒弃了繁复的"()", 引入了 "->", ",", ";", "." 这样只是更加突出了函数的定义和使用时的方便性。

其次,为了函数语言能够在工程实践中具有实际应用,Erlang在语言层次上引入了许多辅助的功能。1)Erlang从语法层次上定义了一种引入副作用(side effect)的方法进程间消息的发送—— Pid ! Message , 与接收 Receive。这与 Erlang 虚拟机的轻量级进程相结合,无疑是提供了一个颇具工程价值的强悍的函数式语言;2)引入的模块(module),函数输出/输入定义(export/import),引入宏; 3)增强的 Term 匹配; 4)引入异常处理机制(try/catch),5)引入 tuple 以及 record 数据类型。
不过坦白的讲,除了第一点进程间消息的发送与接受具有些实质上的意义之外,异常及其处理机制,tuple数据类型,感觉上却有些画蛇添足之感,这些变化只是让程序设计的复杂性有所增加,并没有什么实质性的提高。
特别是异常这样的东西,很有可能是受了这些年 C++/Java语言的毒害吧,就结构化程序而言,我们还可以异常可以简化程序的正常流程,增加可读性。可是对于函数式语言除了需要多些try/catch这样的另类语法,我们又得到了什么呢?赫赫,只能是仁者见仁智者见智了!

还有,Erlang/OTP 为程序开发人员提供了一个相当完善的,可以李可使用的程序库 OTP。在当前的这个软件开发时代。一个高质量,高易用性的 library 对于语言的发展有着非常大的推动作用,Java语言,也正是凭借着功能丰富,充分文档化的Java API在当今程序设计领域占据着重要地位的。对于一个电信设备专用语言而言,OTP已经为我们提供了,SNMP Agent, CORBA, CORBA IDL, CORBA Event, 数据库。确实极大的方便了设备开发人员的工作。

再就是 Erlang 的 soft real-time 特性。 以及 Erlang 的虚拟机。基本上可以认为Erlang编译出来的程序式平台无关的, Erlang设计的程序可以运行在Linux/Windows/Solaris平台。 这样就可以构造 Linux + Erlang 德超强组合。也算是开拓了电信设备设计的一种新思路吧!

Ericsson 会把这样的东西放出来还真是很有意思的,就如同在 Erlang 的 FAQ 中写的

10.4. Why is Ericsson giving away Erlang?
(The following is my personal impression. I don't speak for Ericsson!)

Nothing to lose: Ericsson's core business is telecommunications products, selling programming tools is not really a business Ericsson is interested in.

Stimulate adoption: Erlang is a great language for many sorts of systems. Releasing a good, free development environment is likely to make Erlang catch on faster.

Generate goodwill: Giving away cool software can only improve Ericsson's image, especially given the current level of media attention around "open software".

2007/02/03

Common Lisp HyperSpec

曾经在研究生阶段上过一门计算机系开设的人工智能基础的课程。
在课程的最后还用clisp完成了一个寻找最佳乘车路线的程序作为课程设计。
当时对clisp真的没什么感觉,就是一堆的括号 (((((...).(...)))))
CLISP 就是 Common List 是 ANSI X3J13 标准化之后的Lisp语言
这也算是我对Lisp的一点儿初步的认识吧!

说起来 LISP 也算是自成一派的人工智能语言, 函数语言的基础。
Lisp之根源中文版
,以及英文原版 The Root of Lisp 可以算是Lisp入门必读了吧!

看到Lisp就会感觉到人类智慧的伟大!
于lisp相比 XML就有点儿太丑陋了!

2007/01/31

Bash新手指南

今天又看到了 BASH 的新手指南,网络上中文的东西越来越多了!
只不过又是翻译作品,希望今后有越来越多的中文原创!

2007/01/30

VIM syntax for JavaScript 0.7.2 released

Today I do update the JavaScript syntax script for VIM to 0.7.2.

Until now PRC 2007.01.30-21:37 my script got:
Rating 332/99, Downloaded by 1684

I do like more feature, but I like the accuracy much more. :D
Without the context based parser, it can't highlight the JavaScript properly.

2007/01/17

Hack the IDLE.DLL of Yahoo Messenger

Yahoo Messenger is very nice IM software. But it used the very old window HOOK functions to detect the user idle time through IDLE.DLL. The idle.dll is a 6k DLL file which created with Microsoft VC 7.1 and linked with MSVCR71.DLL. In this way, the IDLE.DLL will be injected to all the user applications, and hook the message queue of all applications, and it will also injects the MSVCR71.DLL into the user applications. Please refer MSDN for details about the Windows HOOK function.

Yahoo Messenger 是一个很不错的IM软件。但是它是用了一个非常陈旧的Windows Hook功能,因此制造了一个idle.dll 用来来检测用户的发呆时间。这个IDLE.DLL 文件看起来并不大,只有6k,其实它是一个用VC7.1编译产生的动态链接库并且动态链接到MSVCR71.DLL。 由于HOOK函数需要把 IDLE.DLL 注入到所有的用户程序中,MSVCR71.DLL 也会被注入到所有的用户程序中。 而且这个IDLE.DLL 会进入所有用户程序的消息循环。在所有的程序中都有这个 idle.dll 实在是让人不爽。 ;)

Let's check the IDLE.DLL
下面就让我们看看这 IDLE.DLL


C:\Program Files\Yahoo!\Messenger>dumpbin /exports idle.dll
Microsoft (R) COFF/PE Dumper Version 8.00.50727.42
Copyright (C) Microsoft Corporation. All rights reserved.


Dump of file idle.dll

File Type: DLL

Section contains the following exports for idle.dll

00000000 characteristics
450867C8 time date stamp Thu Sep 14 04:19:20 2006
0.00 version
1 ordinal base
3 number of functions
3 number of names

ordinal hint RVA name

1 0 00001016 ?IdleUIGetLastInputTime@@YAKXZ
2 1 000010C3 ?IdleUIInit@@YAHXZ
3 2 0000111C ?IdleUITerm@@YAXXZ

Summary

1000 .data
1000 .rdata
1000 .reloc
1000 .rsrc
1000 .text
1000 Y_IDLE


It has 3 C++ functions defined, and a customized data section "Y_IDLE", I think it is the shared data section which used to store the latest user active time stamp. While what's the function protocol for these 3 function? I found a very good documentation for the C++ name mangling of different compilers at URL http://www.agner.org/optimize/ Calling conventions for different C++ compilers and operating systems
它定义了三个输出函数,同时自定义了一个程序段 Y_IDLE 相比这应该是一个数据段,用来记录从各个应用程序收集到的最新的用户消息发出的时间。 而这三个函数应该是用C++的命名规则输出的,但是这三个函数的原型是什么呢?幸好发现了一个非常好的文档,详细地描述了各种编译器的 C++ name mangling 也就是符号标的转换规则。参见 http://www.agner.org/optimize/ Calling conventions for different C++ compilers and operating systems


In fact, from the Windows 2000, WIN_VER>=0x500 there is a new function GetLastInputInfo in user32.dll, it will provide the Last user input time stamp quickly.
其实从Window2000开始,微软在 User32.dll 就提供了一个新的函数 GetLastInputInfo 它就可以用来返回用户的最后输入的时间。



/**
* This is used to hack the Yahoo Messenger.
* compiled with VC7.1 as:
* cl -W3 -O1sy -LD -MD -D_WIN32_WINNT=0x0500 idle.cpp -Feidle.dll User32.lib
*/

#include

#pragma section("Y_IDLE",read,write)
__declspec(allocate("Y_IDLE"))
int Y_IDLE = 0;

#define DllExport __declspec( dllexport )

DllExport DWORD IdleUIGetLastInputTime()
{
LASTINPUTINFO lii;
lii.cbSize = sizeof(lii);
GetLastInputInfo(&lii);
return lii.dwTime;
}

DllExport INT IdleUIInit()
{
return TRUE;
}

DllExport VOID IdleUITerm()
{
return;
}



This will be able to create a new IDLE.DLL
这样就可以知道一个新的 idle.dll , 而且它也再也不会被注入到其他的程序中了。
替换原来的 IDLE.DLL 还真不错~~~~ 工作正常。


写在后面


在找到 IDLE.DLL 输出函数的原型还真花了些时间。后来才发现其实微软已经给我们提供了一个很方便的工具,那就是随Platform SDK 分发的 Dependency Walker (depends.exe) 里面有一个 Undecorate C++ functions 的功能,我们只需要用Dependency Walker 打开 IDLE.DLL 就可以看到输出函数的原型了。


其实

2006/12/25

最简化的Nmake Makefile


!include <win32.mak>

## Link with MSVCRT and MSVCP
#.cpp.exe:
# cl -nologo -MD -W3 -O1y -EHsc -I. $**

.cpp.exe:
cl -nologo -W3 -O1y -EHsc -I. $**

clean:
del /q /f *.exe *.obj

最简化的GNUMakefile


## GNU Makefile with MinGW/MSYS
## MinGW 下面简化的Makefile 需要 MSYS
## It can be invoked like `mingw32-make hello.exe`
## This will compile the hello.cpp to hello.exe

CXXFLAGS=-I. -O3

## 没有下面这条指令, 后缀通配指令不能识别 .cpp.exe
.SUFFIXES: .exe

.cpp.exe:
g++ -Wall $(CXXFLAGS) -o $@ $<


.PHONY : clean
clean:
rm -f *.exe *.obj *.o

2006/12/09

到这里都一年了~~~

算起来到这里已经一年多了, 中间断断续续当然了也包括一些可观的原因,一共也没有放多少东西上来。
总算还有两片篇幅较长的原创,也算是聊以自慰了。

再接再厉好了!希望自己能够百尺竿头更进一步~~~

2006/12/01

"Hello World" XUL application with XULRunner

Today, I do spend some hours with the XULRunner -- a Mozilla runtime package which can be used to bootstrap XUL+XPCOM applications that are as rich as Firefox and Thunderbird. I will create a "Hello World" XUL application step by step, just to remind myself. I will be very glad if it is also helpful for you. :)
今天,闲暇无事,花了几个小时玩耍了一下 XULRunner -- 一个 Mozill 运行库,以及 XUL+XPCOM 应用程序的启动器,利用它可以构建 Firefox 和 Thunderbird 一样的应用程序。我用它写了一个简单的 "Hello World" XUL 应用程序,在这里我把程序创建的过程一步一步地记录下来,主要是对自己的学习做一个笔记。希望它也能对其他人有所帮助。

About XULRunner

XULRunner is a Mozilla runtime package that can be used to bootstrap XUL+XPCOM applications that are as rich as Firefox and Thunderbird. It will provide mechanisms for installing, upgrading, and uninstalling these applications. XULRunner will also provide libxul, a solution which allows the embedding of Mozilla technologies in other projects and products. [Ref: http://developer.mozilla.org/en/docs/XULRunner]
Main features
  • XPCOM
  • Networking
  • Gecko rendering engine
  • DOM editing and transaction support (no UI)
  • Cryptography
  • XBL (XBL2 planned)
  • XUL
  • SVG
  • XSLT
  • XML Extras (XMLHttpRequest, DOMParser, etc.)
  • Web Services (SOAP)
  • Auto-update support (not yet complete)
  • Type ahead find toolbar
  • History implementation (the places implementation in the 1.9 cycle)
  • Accessibility support
  • IPC services for communication between gecko-based apps (not yet complete)
  • Storage/sqlite interfaces (not yet turned on by default)

Installation

For current 1.8.0.x release, XULRunner only available in ZIP format, you can download it and unzip at any place you want.
Refer: http://developer.mozilla.org/en/docs/XULRunner:Deploying_XULRunner_1.8

Skeletons of a XUL Application

I name my "Hello World" application as HelloWorldApp or helloworldapp,

/HelloWorldApp
/chrome
- app files ...
chrome.manifest
/defaults
/preferences
prefs.js
application.ini
All the folders/files are necessary for a XUL application, "app files..." will be variant, it depends on your application itself.

Define the XUL application.ini

This is the application.ini of the helloworldapp:

[App]
; This field specifies your organization's name. This field is recommended,
; but optional.
Vendor=MozillaTest
;
; This field specifies your application's name. This field is required.
Name=HelloWorldApp
;
; This field specifies your application's version. This field is optional.
Version=0.0.1
;
; This field specifies your application's build ID (timestamp).
; This field is required.
BuildID=20061030
;
; This field specifies a compact copyright notice for your application. This
; field is optional.
Copyright=Copyright (c) 2004 Mozilla.org
;
; This ID is just an example. Every XUL app ought to have it's own unique ID.
; You can use the microsoft "guidgen" or "uuidgen" tools, or go on
; irc.mozilla.org and /msg botbot uuid. This field is optional.
ID={CAB1E5C0-1E38-44c3-B153-754AD72E898B}

[Gecko]
;
; This field is required. It specifies the minimum Gecko version that this
; application requires.
MinVersion=1.8
;
; This field is optional. It specifies the maximum Gecko version that this
; application requires. It should be specified if your application uses
; unfrozen interfaces.
MaxVersion=1.9

You must specify the [App] name. It will be used for XULRunner to find the relevant prefs.js .
App::name 必须要指定,因为它将影响 XULRunner 如何读取 prefs.js 。

Define the prefs.js (helloworldapp-prefs.js) / 定义应用程序的 Preferences.

After the application.ini is defined, it is necessary to have a -prefs.js under ${APP_ROOT}/defaults/preferences
Here is the helloworldapp-prefs.js
定义了 application.ini 之后, 下一步就是指定 -prefs.js , 在这里我们的 是 helloworldapp, 因此我们需要在 ${APP_ROOT}/defaults/preferences目录下面建一个 helloworldapp-prefs.js JavaScript 文件,文件的内容如下:
pref("toolkit.defaultChromeURI", "chrome://helloworldapp/content/helloworld.xul");
pref("general.useragent.extra.helloworldapp", "HelloWorld/0.1");
It define "toolkit.defaultChromeURI" to "chrome://helloworldapp/content/helloworld.xul" .
其中最主要的部分就是定义了,"toolkit.defaultChromeURI" , 它就是 XUL 程序的缺省启动页面。

Setting up chrome.manifest / 设定 chrome.manifest

This file performs the mapping between a chrome:// url and your application files:

这个文件主要用来实现 XUL 程序中使用的 chrome:// scheme 和你自己编写的应用程序文件的对应。


This is the chrome.manifest of "Hello World" application.

Hello World 程序的 chrome.manifest 文件的内容如下:

content helloworldapp file:helloworldapp/
This institution tells XULRunner to look at ${APP_ROOT}/chrome/hellowworldapp/ when it encounters a chrome://helloworldapp/content/ URI. The change of the application name and folder name will impact the URI looking up of XULRunner.
通过这个指令,我们告诉 XULRunner,当程序中 URI 为 chrome:://helloworldapp/content/ 的时候,就到 ${APP_ROOT}/chrome/hellowworldapp/ -- 应用程序的chrome目录下面的helloworldapp 目录下面去寻找相应的文件。 我们也可以相应的改变 上面的语句中的 application name 以及目录的名字,但是这个改变将影响 XULRunner 如何解释以 chrome:// 为类型的 URI 的定位。 进一步的内容可以参考 ITArt 同志的Blog http://itart.wordpress.com/2005/12/05/mozext-ch3/ 第3.6章。

Chromes / 全金属外壳

To make it easy for the development, we are using the plain folder/files for the chrome.
为了方便进行开发和调试,在这直接使用文件和目录来保存 chrome 文件。

Most XUL applications are distributed as a .jar file, rather than a subfolder of chrome/ with all the files scattered about. When you do want to deploy it as a jar:

  1. Zip up your /chrome/applicationName folder, put the applicationName.zip in the /chrome directory.
  2. Rename applicationName.zip to applicationName.jar
  3. Change the chrome.manifest to point to applicationName.jar:
    content applicationName jar:applicationName.jar!/
The "jar:" protocol tells XULRunner that this is a jar file. With "jar:filename.jar!/uri/folder/", XULRunner will look for the resource under the give folder "/uri/folder/" in the JAR file.
"jar:" 协议,用来通知 XULRunner 所需要要得资源文件都被包裹在 JAR 文件中。"jar:filename.jar!/uri/folder/" 为 XULRunner 指名相应的资源需要去 filename.jar 文件的 /uri/folder/ 目录下面寻找。

Build the GUI with XUL / 使用XUL来构建 GUI

In the perfs.js, the toolkit.defaultChromeURI was defined as "chrome://helloworldapp/content/helloworld.xul", it will be the default GUI of this Hello World application.
在 perfs.js 中, 我们将 toolkit.defaultChromeURI 定义为 "chrome://helloworldapp/content/helloworld.xul", 它就是我们这个Hello World 应用程序的缺省 GUI.

The XULRunner looks up the URI -- "chrome://helloworldapp/content/helloworld.xul" at the ${APP_ROOT}/chrome/helloworld/helloworld.xul . So helloworld.xul will be the main GUI file.
对于 URI -- "chrome://helloworldapp/content/helloworld.xul", XULRunner 将会翻译成 ${APP_ROOT}/chrome/helloworld/helloworld.xul 并且试图使用这个XUL文件作为主 GUI 文件。


<?xml version="1.0"?>
<?xml-stylesheet href="chrome://global/skin/" type="text/css"?>

<window
id = "helloworldapp"
title = "Hello World!"
width = "300" height = "200"
xmlns = "http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul">
<button label="Hello World" onclick="window.alert('Hello World!');"/>
</window>
This is a very simple XUL file which defined a frame window, and there is only a button on it. When the button is clicked, there will be a prompt alert. It just works like HTML.
这是一个非常简单的XUL文件,它只定义了一个主窗口,在主窗口中只有一个按钮控建,我们还定义了一个onclick事件的JavaScript程序,当按钮被点击就会弹出一个警告窗口,这一部分就和普通的HTML没有什么区别。

Ready and Go / 预备跑

Ok, it is time to go. Open a Command Processor window, cd into the ${APP_ROOT}, assuming the ${APP_ROOT} is "HelloWorld", and it is located within the XULRunner's folder, for me, the XULRunner is installed at "e:\devel\xulrunner". We can launch the Hello World application in this way.
好了,该出发了! 请打开一个命令行窗口,并且进入 XULRunner的安装目录, 比如说 XULRunner 被安装在 e:\devel\xulrunner ,HelloWorld应用程序的目录就在 XULRunner的安装目录中。我们就可以按照下面的命令来运行 HelloWorld。
e:\devel\xulrunner>xulrunner.exe HelloWorld\application.ini 
in other words:
${XULRUNNER_HOME}\xulrunner.exe ${APP_ROOT}\application.ini
当然也可以使用上面的方法来运行,这里 ${XULRUNNER_HOME} 和 ${APP_ROOT} 应该被替换成她们实际的全路径名。

We got it, isn't it?


Have Fun~~~

2006/10/25

FireFox 2 发布了!

Congratulation!

不过看起来,FireFox 用的内存越来越多了, :( 只打开了, Blogger一个网页就已经用了60M多内存了. 加内存吧~~~~

2006/10/24

802.1X is working under my Ubuntu Linux

Finally the my Ubuntu linux is authenticated with the Windows IAS 802.1x RADIUS server. Thanks Xsupplicant, thanks Open1x project to provide us a such great too.
今天, 我的 Ubuntu Linux 终于可以通过公司的 802.1X 端口认证了。非常感谢 Xsupplicant, 感谢 Open1X 小组为我们提供的工具。

Before configure your Linux box, you should be look at your windows configuration carefully. In fact M$ windows didn't support too much authentication methods. For Windows 2000 with the Wireless authentication patch, it do only support 3 type of EAP, (PEAP, MD5-Challenge, and Smart-card or Certificate). The MD5-Challenge is too weak, and the smart-card isn't deployed widely. So the PEAP is the proper, maybe only choice for Windows.
在开始配置你的 Linux 前,我们需要仔细察看 Windows 中802.1X的协议设置。实际上,在 Window 系统中,对以太网卡并不支持很多的认证方法。对于应用了微软无线认证补丁的 Windows 2000 中只支持三种 EAP 方法(PEAP, MD5-Challenge, and Smart-card or Certificate)。实际上基于 MD5 的认证方式实在是太脆弱了,而 Smart-Card 的应用实际上也不广泛。因此 PEAP 实际上是可以使用的唯一选择。

Under the Linux, there are some tricks for the Xsupplicant configurations. See the sample PEAP-example.conf below:


# This is an example configuration file for xsupplicant versions after 0.8b.

### GLOBAL SECTION

# network_list: defines all of the networks in this file which
# should be kept in memory and used.Comma delimited list or "all"
# for keeping all defined configurations in memory. For efficiency,
# keep only the networks you might roam to in memory.
# To avoid errors, make sure your default network is always
# in the network_list. In general, you will want to leave this set to
# "all".

network_list = all
#network_list = default, test1, test2

# default_netname: some users may actually have a network named "default".
# since "default" is a keyword in the network section below, you can
# change which is to be used as the replacement for this keyword

default_netname = default
#default_netname = my_defaults

# When running in daemon, or non-foreground mode, you may want to have the
# output of the program. So, define a log file here. Each time XSupplicant
# is started, this file will be replaced. So, there is no need to roll the
# log file.
logfile = /var/log/xsupplicant.log

# The auth_period, held_period, and max_starts modify the timers in the state
# machine. (Please reference the 802.1x spec for info on how they are used.)
# For most people, there is no reason to define these values, as the defaults
# should work.

#auth_period = 30
#held_period = 30
#max_starts = 3

### NETWORK SECTION
# The general format of the network section is a network name followed
# by a group of variables.

# Network names may contain the following characters: a-z, A-Z, 0-9, '-',
# '_', '\', '/'
# Those interested in having an SSID with ANY character in it can use
# the ssid tag within the network clause. Otherwise, your ssid will
# be the name of the network.

## The default network is not a network itself. These values are
## the default used for any network parameters not overridden
## in another section. If it's not in your network configuration
## and not in your default, it won't work!!

default
{
# type: the type of this network. wired or wireless, if this value is not
# set, xsupplicant will attempt to determine if the interface is wired or
# wireless. In general, you should only need to define this when
# xsupplicant incorrectly identifies your network interface.
type = wire # For your Ethernet card.

# wireless_control: If this profile is forced to wired, this will not do
# anything. However, if the interface is forced, or detected to be wireless
# XSupplicant will take control of re/setting WEP keys when the machine
# first starts, and when it jumps to a different AP. In general, you won't
# need to define, or set this value.
# wireless_control = yes

# allow_types: describes which EAP types this network will allow. The
# first type listed will be requested if the server tries to use something
# not in this list.
# allow_types = eap_tls, eap_md5, eap_gtc, eap-otp
allow_types = all

# identity: what to respond with when presented with an EAP Id Request
# Typically, this is the username for this network. If this is a string
# that does not contain any spaces, or unusual characters, it can be listed
# plain. Otherwise, it should be enclosed in quotes.
identity = "DOMAIN\USERID" # For window based 802.1X RADIUS, it should be DOMAIN\USER

# Force xsupplicant to send it's packets to this destination MAC address.
# In most cases, this isn't needed, and shouldn't be defined.
#dest_mac = 00:aA:bB:cC:dD:eE

eap-peap {
inner_id = USERID # Only UserID
# As in tls, define either a root certificate or a directory
# containing root certificates. If the path contains spaces, or unusual
# characters, enclose it in quotes.

# Trusted root cert can be exported from windows
# as DER format, and translate to PEM format by using openssl
# under Linux:
# openssl x509 -inform DER .cer -outform PEM -out root.crt
root_cert = /path/to/root/certificate
root_dir = "/path /to /root /certificate /dir"
crl_dir = /path/to/dir/with/crl
chunk_size = 1398
random_file = /dev/random # /dev/random will work for most case.

# If you don't know the CN name of your RADIUS server,
# You can make the cnexact = no
# While the RADIUS server name can be saw in "Xsupplicant -d A" mode
cncheck = myradius.radius.com
cnexact = yes # Should it be an exact match?
session_resume = yes

#Currently 'all' is just mschapv2
#If no allow_types is defined, all is assumed
allow_types = all # where all = MSCHAPv2, MD5, OTP, GTC, SIM
#allow_types = eap_mschapv2

eap-mschapv2 {
# ntpwdhash was generated by using "xsup_ntpwdhash " command
ntpwdhash = E653E6452753C97E46792567DFF599B6
# Don't put your password here, use the ntpwdhash instead.
#password = "phase2 mschapv2 pass"
}
}
}

# TIP:
#
# 1. Use the foregroup mode to debug your configure.
# It will show you all the things.
# /usr/sbin/xsupplicant -i eth0 -d A -f
#
# 2. Remove all the unnecessary data cleaned

2006/10/23

802.1X under Linux

The IS department reqired the 802.1X port authentication in the new campus, it really hurt me -- as a Linux fun. After I swithed to my Ubuntu, the network port will be blocked after 30 minutes.

Oh, I found the xsupplicant of Open1X project, it looks like a feasible way to have my Linux box running under the company's 802.1X network.

But there are still some problems need to be solved. Let's do it tomorrow. :) ...

BlockChain 相关电子书

@copyright of Sam Chadwick   - https://thehub.thomsonreuters.com/groups/bitcoin/blog/2017/09/10/blockchain-paper Blockchain Papers A c...