Tuesday, December 12, 2017

Windows 10 God Mode Folder on Desktop

If you have created a "God Mode" folder on your desktop - think twice before deciding to keep it there.
It turns out that some applications will refuse to perform their basic functionalities (like: open file, browse etc) and will crash - only because the folder sits on your desktop.


As always, had to learn that the hard way....

*If you don't know what the "God Mode" folder is - then probably you don't have one . This folder  usually is created explicitly by the user using some undocumented features of the Windows OS.




Windows 10 missing sticky notes and microsoft store problem

After installing Windows 10 I realized that the Microsoft Store was missing also the sticky note app was not there either...

The solution came from power-shell.
I guess Microsoft has adopted linux-like approach in getting updates and missing packages.

So here what I did:

 1. Enter Windows Power-Shell (as Admin)
 2. Get-Appxpackage -Allusers > res.txt
 3. Add-AppxPackage -register "C:\Program Files\WindowsApps\[packageFullName]\AppxManifest.xml" -DisableDevelopmentMode

Here the res.txt file is needed to find missing package's full name.

[Microsoft.MicrosoftStickyNotes]
[Microsoft.WindowsStore]

We use that name to download and install the package (step 3).

Tuesday, April 4, 2017

Creating web services with NetBeans

Creating web services with NetBeans

Here I will provide a description of an (finally successful) attempt to create secure web service, using Net Beans and Apache Tomcat. However I will try to describe step by step all the problems that I encountered along the way, and how overcame this obstacles.
So let's begin.

All the pitfalls will be numbered and  marked with brackets [].

First we need to install NetBeans 8 with  Apache Tomcat, and right in the beginning we encounter a curious problem [1] - Tomcat won't start from inside of the Netbeans! Bummer! Not a good start....

[1] To overcome this first obstacle we should set "NO Proxy" in NetBeans Tools->Options->General settings and vuola Tomcat miraculously starts!! (must be  a bug or something...)

OK, so far so good (like in the joke: "I Intend To Live Forever... So Far So good!!")

Next, we add some parameters to tomcat environment, so that we can debug sent - received soap messages (or do you expect everyting to work properly from the 1st attempt?).
So we add at Netbeans ->Servers->  TomCat - > properties -> platform -> VM Options

-Dcom.sun.xml.ws.transport.http.HttpAdapter.dump=true
-Dcom.sun.xml.internal.ws.transport.http.HttpAdapter.dump=true

(
  by the way, for a client, there is another variation

 -Dcom.sun.xml.ws.transport.http.client.HttpTransportPipe.dum‌p=true
 -Dcom.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.dump=true

)

If you use standalone Tomcat then for vm-options go to setevn.bat that you create and put besides catalina.bat (tomcat's bin folder)

For example:

rem contents of the setevn.bat 
set JAVA_HOME=C:\Program Files\Java\jdk1.8.0_77
set JAVA_OPTS="-Dcom.sun.xml.ws.transport.http.HttpAdapter.dump=true"
"-Dcom.sun.xml.internal.ws.transport.http.HttpAdapter.dump=true"



catalina start -security  (run tomcat with security manager)

To create Tomcat that will run as a service - we have slightly different approach

(set system variable)
set JAVA_HOME=C:\Program Files\Java\jdk1.8.0_77 

Then in dos prompt: 

cd C:\apache-tomcat-8.5.6\bin
service.bat install tomcat8

tomcat8w.exe 

also in java tab / java options set (tight secrity policy): 
-Dcom.sun.xml.ws.transport.http.HttpAdapter.dump=true
-Dcom.sun.xml.internal.ws.transport.http.HttpAdapter.dump=true
-Djava.security.manager
-Djava.security.policy=C:\apache-tomcat-8.5.6\conf\catalina.policy

You think we have finished? Not at all!! 

There will be also settings for https, certificates in server.xml , database passwords etc  but all that in due time... for now lets just create an unsecured service.
(by the way I would enable security manager at the very last stage - as there is a load of setting that should be performed in order for the application  to continue to operate with security manager![7])
Also, when deploying the application with security manager, app's context.xml should be copied to tomcat's conf/catalina folder, and renamed to appname.xml - otherwise the application won't deploy [3] (don't ask me why...)

Server 

1. Create new Web Project
2. Import METRO 2.0 library
    (actually you only need webservices-rt.jar to be packaged with final .war file - other libraries are  
    already present in tomcat - and may even cause problems with conflicting loader paths[4])
3. Add xsds that describe your messages
4. Create jax-b xsd binding (right click on packge - new jax-b binding)
5. Java Binding xsd and java code will be generated
6. Make sure in binding xsd's you have (originals may still refer to qualified )
    attributeFormDefault="unqualified"
    elementFormDefault="unqualified" [5]
 
    So that in generated package-info.java there is no reference to  elementFormDefault = javax.xml.bind.annotation.XmlNsForm.QUALIFIED
    Otherwise otherwise extra tag (name space) will be added inside your messages sent by the client
    (ns2:XXXX) and server would not understand the message!!![5]

7. Right click on project-> new -> Web service
8. In design view add operation, as parameters and returning results use object created by the jax-b
    binding procedure

Client

  1. Create new project (java application)
  2. Import METRO 2.0 library  (also may be JAX-WS 2.2.6)
  3. Create a main class
  4. Right click on project-> New -> Web Service Client (give the wsdl url of the web service)
  5. Right click - Insert Code - Web service call (select which operation to call)
  6. Because the generated java code is imperfect a meta tag should be added [6]
      @XmlRootElement(name="XX")
       public static class XX {
       otherwise marshalig /unmarshaling will not work! 
  7.  client input data could be in xml that would be umarshaled and send as parameter of ws call.
  8.  the reply can also be marshaled (if needed)


The unsecured part is ready to be tested! Fingers crossed - hope it works!

Next goal is to secure our communication channel!

To that end, first we should create proper keystores for the client and server, also we need to create truststores for both of them, which will store public keys of entities that are trusted.

Generate server keystore

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -genkey -keyalg RSA -alias mytomcat -dname "CN=Name, OU=Unit, O=Org, L=PlanetEarth, S=MyCity, C=FU" -keystore c:/certs/mytomcatkeystore.jks -validity 36000 -storepass changeit -keypass changeit -ext san=ip:X.X.X.X,ip:127.0.0.1,dns:www.mycompany.com

Export certificate (public key)

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -export -keystore c:/certs/mytomcatkeystore.jks -alias mytomcat -file c:/certs/myserver.cer -storepass changeit

Import into client's trust store 

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -importcert -file e:/certs/myserver.cer -keystore c:/certs/myclinetTrustStore.jks -alias "ClientT" -storepass changeit

Same for the client,

Generate clinent keystore

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -genkey -keyalg RSA -alias ourclient -dname "CN=Name, OU=Unit, O=Org, L=PlanetEarth, S=MyCity, C=FU" -keystore c:/certs/ourclientkeystore.jks -validity 36000 -storepass changeit -keypass changeit

Export certificate (public key)

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -export -keystore c:/certs/ourclientkeystore.jks -alias ourclient  -file c:/certs/ourclinet.cer -storepass changeit

Import into server's trust store 

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -importcert -file e:/certs/ourclinet.cer -keystore c:/certs/mytomcattruststore.jks -alias "TheClient" -storepass changeit

but also

Generate client certificate for web browser

"c:/Program Files/Java/jdk1.8.0_77/bin/keytool.exe" -importkeystore -srckeystore  c:/certs/myclient.jks -destkeystore c:/certs/myclient1.p12 -srcstoretype JKS -deststoretype PKCS12 - srcstorepass changeit -deststorepass changeit -srcalias MyClient -destalias MyClient1 -srckeypass changeit -destkeypass changeit -noprompt

After creating a key store we should set up tom cat to use it.
So back to tomcat settings.
Go to the tomcat/conf/server.xml

enable 8443 connector:

 <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
              maxThreads="150" SSLEnabled="true"
 keystoreFile="conf/mytomcatkeystore.jks" clientAuth="true"  scheme="https" secure="true"
 truststoreFile="file:///c:/apache-tomcat-8.5.6/conf/mytomcattruststore.jks" truststorePass="changeit" SSLProtocol="TLSv1.2"
 allowUnsafeLegacyRenegotiation="true"
/>

and also comment out this line [8]

<Listener className="org.apache.catalina.core.AprLifecycleListener" SSLEngine="on" />

so that it becomes

<!--<Listener className="org.apache.catalina.core.AprLifecycleListener" SSLEngine="on" />-->

also, optionally (if you use database)

edit catalina.properties file, and add to the end of it the following line

mydatabse.password=changeit

so that, in your application's context.xml you could refer to database connection password as

 <Resource name="jdbc/DB" auth="Container"
              type="javax.sql.DataSource" driverClassName="oracle.jdbc.OracleDriver"
              url="jdbc:oracle:thin:@X.X.x.x:1521:xxxx"
              username="myuser" password="${mydatabse.password}" />

And now server is ready. 

On the client side (say you have java client)

the following chunk of code should be ran before ws call

public static void init(){
       System.setProperty("javax.net.ssl.trustStore","c:\\myclinetTrustStore.jks");
       System.setProperty("javax.net.ssl.trustStorePassword","changeit"); 
       System.setProperty("https.protocols", "TLSv1.2");
       System.setProperty("javax.net.ssl.keyStore","c:\\myclient.jks"); 
       System.setProperty("javax.net.ssl.keyStorePassword","changeit"); 
       System.setProperty("javax.net.debug","ssl,record,keygen,handshake"); 
    }

Code generation with python

Here I will preset a small code generator I am using to generate java, html, jsp, xsd and other codes.

I am using Python27 and Jinja2-2.7.2 

My Files:  

InputData.txt

:This is field list
field1:field1 description
field2:field2 description
field3:field3 description
field4:field4 description
field5:field5 description
field6:field6 description
field7:field7 description

CodeGenerator.py

import jinja2
import codecs
templateLoader = jinja2.FileSystemLoader( searchpath="." )
templateEnv = jinja2.Environment( loader=templateLoader )

TEMPLATE_FILE = "CodeGenerator.jinja"
template = templateEnv.get_template( TEMPLATE_FILE )


COLUMNS       = [tuple(line.split(':')) for line in codecs.open( "InputData.txt", "r", "utf-8" )]

COLUMNS       = map(lambda s: (s[0],(s[0].strip().title(),s[1].strip())), COLUMNS)
#title() copy of the string in which first characters of all the words are capitalized.
#strip()  copy of the string, all chars have been stripped from the beginning and the end
#lambda s --> (field1,(Field1,field1 description))

#ignore the first line
COLUMNS.pop(0)

#add variables to work with
templateVars = { "table" : "MyTableName",
                 "description" : "A simple code generator",
                 "columns" : COLUMNS
               }

outputText = template.render( templateVars )
f = open('Generated.txt', 'w')
outputText = outputText.encode('utf-8')
f.write(outputText)
f.close()
print outputText

CodeGenerator.jinja

//------------------model------------------------
//Generated code for model 
import java.io.Serializable;
public class {{table|capitalize}}_Model implements Serializable{
{%for columnName,columnTitle in columns%}
private String {{columnName|lower}};{%endfor%}

{% for columnName,columnTitle in columns %}
public void set{{columnName|capitalize}}(String {{columnName|lower}}){ 
  this.{{columnName|lower}}={{columnName|lower}};
}
public String get{{columnName|capitalize}}(){ 
  return this.{{columnName|lower}};
}
{% endfor %}
public {{table|capitalize}}_Model({% for columnName,columnTitle in columns %}String {{columnName|lower}}{% if not loop.last %},{% endif %}{% endfor %}){
        {% for columnName,columnTitle in columns %}
this.{{columnName|lower}}={{columnName|lower}}; {% endfor %}
    }
public String toString(){

return {% for columnName,columnTitle in columns %}"{{columnName|lower}}:" + this.{{columnName|lower}}{% if not loop.last %}+{% endif %}{% endfor %};

}

}
//------------------model------------------------
//
//------------------jsp example-----------------
{% for columnName,columnTitle in columns %}
<s:label  cssStyle ="margin-top:5px;color:blue;" value="{{columnTitle[1]}} :" id="{{columnName}}_label"/>
<s:textfield label="{{columnTitle[1]}}" name="myBean.{{columnName}}" />
{% endfor %}
//------------------jsp example-----------------

Sunday, July 31, 2016

IReport issues with Java 8

So IReport does not work  properly with Java 8... and I had to find that out the hard way ;-)

Here I have some tips for those of you who still use IReport (3 to 5)


When running with java 8 IReport3 will not show 'library' window contents  - where you usually expect to find 'buttons' like totals, page number, current date etc. and as far as I remember IReport5 will not launch at all.
You can check which java version is used by the IReport if you go Help->About->System Properties. There you can find 'java.version' variable.

So for ireport3 the workaround is to use ireport.bat file which is located in the ireport3 root directory.
Just add to the bat file something like path="C:\Program Files\Java\jdk1.6.0_26"
so that proper java will be used to launch IReport.

For irepor 5 you can edit  ireport.conf file (e.g. iReport-5.6.0\etc\ireport.conf)
and add  jdkhome="C:\Program Files\Java\jdk1.6.0_26"   

Note that you should have java6 jdk also installed on your system for the above to work.

That's it for today... 

Monday, January 25, 2016

Thunderbird Ldap address autocomplete problem...

Recently I installed Thunderbird (email client) and hooked it up to Ldap.

I set up the LDAP server as follows:

Port(default)   :  389
Base DN          :  dc=organization, dc=com
Bind  DN         :  myuser@organization.com
Filter(default) :  (objectclass=*)


The Problem:

1. Whenever I tried  to compose a new mail - the auto-complete feature of the "To" field either wasn't working at all or brought limited number of names from the Ldap server - without bringing the name that I was looking for.

On the other hand within the address book everything worked fine (searching / finding etc).

Very strange behavior...

2. Another thing I noticed was, that whenever I tried to create local replica of LDAP catalog - download failed.

Solution:

Solution I found for those two problems was to change the default port to 3268 which is apparently port for searching in Global Catalog.

Tuesday, August 25, 2015

Is My Intranet Web Server Down?

O.K.
Without further delay -  here is a python script that will e-mail you in case a Http server you are monitoring is down (based on failed ping or failed http connection) :

http_ping.py

-------------------------------------------------------------------------------------------------------------------
import smtplib
from email.mime.text import MIMEText
import optparse, subprocess, os, sys
import re, time, datetime
from optparse import OptionParser
from os import stat
from os.path import abspath
from stat import ST_SIZE
import httplib
import sys

SLEEP_TIME = 60
email_from = ""
email_to = ""
smtp_server=""
ssl=False
smtp_user=None
smtp_password=None

def runProcess(exe):
    FNULL = open(os.devnull, 'w')
    p = subprocess.call(exe, stdout=FNULL, stderr=FNULL)

    if p == 0:
        return True
    else:
        return False

def sendAlert(state, host, debug,what):
    subject = ""
    statetext = ""

    if state == 0:
        statetext = "up"
    elif state == 1:
        statetext = "down"

    subject = "Host %s is %s" % (host, statetext)

    ts = time.time()
    f_ts = str(datetime.datetime.fromtimestamp(ts).strftime('%Y-%m-%d %H:%M:%S'))

    text = "Host " + host + " went " + statetext + " at " + f_ts + " based on " + what

    msg = MIMEText(text)
    msg[ 'From' ] = email_from
    msg[ 'To' ] = ", " + email_to
    msg[ 'Subject' ] = subject
    try:
       
        #if ssl/tls smtp
        if ssl:
            s = smtplib.SMTP_SSL(smtp_server)
            if debug: print "SSL SERVER:" +  smtp_server
        #if not encrypted
        else:
            s = smtplib.SMTP(smtp_server)
            if debug: print "PLAIN SMTP SERVER:" +  smtp_server
        if debug:
            s.set_debuglevel(True)
        #if authentication required
        if smtp_user!=None and smtp_password!=None:
            if debug: print "user and pass are set"
            s.login(smtp_user,smtp_password)
        s.sendmail(email_from, [email_to], msg.as_string())
        s.quit()
    except Exception as e:
        if debug: print "error sending email:"
        #if debug: print msg
        if debug: print e

def main():
    usage = "usage: %prog [options] arg"
    parser = OptionParser(usage)
    parser.add_option('-d', '--debug', action='store_true', dest='debug', default=False, help='enable debugging')
    parser.add_option('-e', '--encrypted', action='store_true', dest='ssl', default=False, help='ssl/tls smtp')
    parser.add_option('-p', '--ping', action='store', dest='host', default=None, help='specify host to ping')
    parser.add_option('-s', '--smtp', action='store', dest='smtp', default=None, help='Specify Mail Server (SMTP)')
    parser.add_option('-t', '--to', action='store', dest='mail_to', default=None, help='Specify Mail Receiver addresses')
   
   
    parser.add_option('-f', '--from', action='store', dest='mail_from', default='Http Ping', help='Specify Mail Sender address')
   
    parser.add_option('-u', '--smtp_user', action='store', dest='smtp_user', default=None, help='SMTP user (optional)')
    parser.add_option('-w', '--smtp_password', action='store', dest='smtp_password', default=None, help='SMTP password (optional)')
    parser.add_option('-z', '--sleepTime', action='store', dest='sleep', default=60, help='sleep time(optional)')
   

    if len(sys.argv) == 1:
        parser.print_help()
        sys.exit( 1 )
    (options, args) = parser.parse_args()

    if options.host == None:
        parser.print_help()
        sys.exit( 1 )

    if options.smtp == None:
        parser.print_help()
        sys.exit( 1 )

    if options.mail_to == None:
        parser.print_help()
        sys.exit( 1 )
    global  SLEEP_TIME,email_from,email_to,ssl,smtp_server
    SLEEP_TIME = int(options.sleep)
    email_from = options.mail_from
    email_to   = options.mail_to
    smtp_server=options.smtp
    ssl=options.ssl
   
   
    try:
        upflag = True
        while(True):
            if options.debug: print "pinging host: " + str(options.host)
            pingresult = runProcess(["ping", options.host])
            http_ping_result = False
            try:
                conn = httplib.HTTPConnection(options.host)
                conn.request('HEAD', '/')
                url = 'http://{0}/{1}'.format(options.host,"")
                if options.debug: print '    Trying: {0}'.format(url)
                response = conn.getresponse()
                if options.debug: print '    Got: ', response.status, response.reason
                conn.close()
                if response.status == 200:
                    if options.debug: print ("Got Response 200 " +" everything is ok")
                    http_ping_result = True   
            except:
                e = sys.exc_info()[0]
                print ' Problem in connection  ' + str(e)   
                http_ping_result = False
           
            if pingresult == False or http_ping_result==False:
                what=""
                if pingresult == False: what =what + "ping "           
                if http_ping_result == False: what =what + " http"           
                if options.debug: print "ping failed" + str(pingresult)
                if upflag == True:
                    if options.debug: print "send down email"
                    sendAlert(1,options.host,options.debug,what)
                   
                upflag = False
            else:
                if options.debug: print "ping was successful..."
                if upflag == False:
                    if options.debug: print "send up email"
                    sendAlert(0,options.host,options.debug,what)
                upflag = True
           
            if options.debug: print "sleeping for "+str(SLEEP_TIME) +"s"
            time.sleep(SLEEP_TIME)
    except (KeyboardInterrupt, SystemExit):
        #raise
        print "Exiting"
    except Exception as e:
        exc_type, exc_obj, exc_tb = sys.exc_info()
        fname = os.path.split(exc_tb.tb_frame.f_code.co_filename)[1]
        print(exc_type, fname, exc_tb.tb_lineno)
        exit ( 1 )
    exit( 1 )

if __name__ == '__main__':
    main()
---------------------------------------------------------------------------------------------------------------------
usage example: 

http_ping.py -d -p my.Server.com -s my.mail.server.com -t my.mail@my.mail.com -z 30