<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.dersllc.com/index.php?action=history&amp;feed=atom&amp;title=DevNet</id>
	<title>DevNet - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.dersllc.com/index.php?action=history&amp;feed=atom&amp;title=DevNet"/>
	<link rel="alternate" type="text/html" href="http://wiki.dersllc.com/index.php?title=DevNet&amp;action=history"/>
	<updated>2026-05-05T14:10:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.3</generator>
	<entry>
		<id>http://wiki.dersllc.com/index.php?title=DevNet&amp;diff=52&amp;oldid=prev</id>
		<title>Admin at 19:43, 2 June 2023</title>
		<link rel="alternate" type="text/html" href="http://wiki.dersllc.com/index.php?title=DevNet&amp;diff=52&amp;oldid=prev"/>
		<updated>2023-06-02T19:43:56Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;http://wiki.dersllc.com/index.php?title=DevNet&amp;amp;diff=52&amp;amp;oldid=51&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>http://wiki.dersllc.com/index.php?title=DevNet&amp;diff=51&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;= Spacewalk Documentation = == Lockdown Scripts ==  #raw  printf &quot; Locking Down CentOS 7:                                                      &quot;  /bin/bash /tmp/status.sh &amp;     echo &#039;CCE-27053-8 - Set Password Hashing Algorithm in /etc/libuser.conf&#039; &gt;&gt; /root/ks-lockdown.log  sed -i &#039;s~crypt_style.*~crypt_style = sha512~&#039; /etc/libuser.conf     yum -y remove vasclnt &amp;&gt; /dev/null  yum -y install clamav &amp;&gt; /dev/null    echo &#039;Installing oscap&#039; &gt;&gt; /root/ks-lockdown.log  yum -y...&quot;</title>
		<link rel="alternate" type="text/html" href="http://wiki.dersllc.com/index.php?title=DevNet&amp;diff=51&amp;oldid=prev"/>
		<updated>2023-06-02T19:40:52Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= Spacewalk Documentation = == Lockdown Scripts ==  #raw  printf &amp;quot; Locking Down CentOS 7:                                                      &amp;quot;  /bin/bash /tmp/status.sh &amp;amp;     echo &amp;#039;CCE-27053-8 - Set Password Hashing Algorithm in /etc/libuser.conf&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log  sed -i &amp;#039;s~crypt_style.*~crypt_style = sha512~&amp;#039; /etc/libuser.conf     yum -y remove vasclnt &amp;amp;&amp;gt; /dev/null  yum -y install clamav &amp;amp;&amp;gt; /dev/null    echo &amp;#039;Installing oscap&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log  yum -y...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Spacewalk Documentation =&lt;br /&gt;
== Lockdown Scripts ==&lt;br /&gt;
 #raw&lt;br /&gt;
 printf &amp;quot; Locking Down CentOS 7:                                                      &amp;quot;&lt;br /&gt;
 /bin/bash /tmp/status.sh &amp;amp; &lt;br /&gt;
 &lt;br /&gt;
 echo &amp;#039;CCE-27053-8 - Set Password Hashing Algorithm in /etc/libuser.conf&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log&lt;br /&gt;
 sed -i &amp;#039;s~crypt_style.*~crypt_style = sha512~&amp;#039; /etc/libuser.conf &lt;br /&gt;
 &lt;br /&gt;
 yum -y remove vasclnt &amp;amp;&amp;gt; /dev/null&lt;br /&gt;
 yum -y install clamav &amp;amp;&amp;gt; /dev/null&lt;br /&gt;
 &lt;br /&gt;
 echo &amp;#039;Installing oscap&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log&lt;br /&gt;
 yum -y --nogpgcheck install spacewalk-oscap scap-security-guide &amp;amp;&amp;gt;&amp;gt;  /root/ks-lockdown.log&lt;br /&gt;
 sed -i &amp;#039;/&amp;lt;platform idref=&amp;quot;cpe:\/o:redhat:enterprise_linux:7&amp;quot;\/&amp;gt;/a \ \ &amp;lt;platform idref=&amp;quot;cpe:\/o:centos:centos:7&amp;quot; \/&amp;gt;&amp;#039;  /usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml&lt;br /&gt;
 #sed -i &amp;#039;s~idref=&amp;quot;audit_rules_privileged_commands&amp;quot; selected=&amp;quot;.*&amp;quot;~idref=&amp;quot;audit_rules_privileged_commands&amp;quot; selected=&amp;quot;false&amp;quot;~&amp;#039;  /usr/share/xml/scap/ssg/content/ssg-centos7-xccdf.xml&lt;br /&gt;
 /usr/bin/oscap xccdf eval --profile stig-rhel7-server-upstream --remediate /usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml &amp;amp;&amp;gt;&amp;gt;  /root/ks-lockdown.log&lt;br /&gt;
 sed -i &amp;quot;s/MACs/\\nMACs/&amp;quot; /etc/ssh/sshd_config &lt;br /&gt;
 /usr/bin/oscap xccdf eval --profile stig-rhel7-server-upstream --oval-results --results ssg-rhel7-xccdf.xml.result.xml  /usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml &amp;amp;&amp;gt;&amp;gt;  /root/ks-lockdown.log&lt;br /&gt;
 /usr/bin/oscap xccdf generate report --oval-template ssg-rhel7-oval.xml.result.xml ssg-rhel7-xccdf.xml.result.xml &amp;gt; /root/stig-report-xccdf-oval.html&lt;br /&gt;
 &lt;br /&gt;
 echo &amp;#039;CVE-2004-1653&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log&lt;br /&gt;
 cat /etc/ssh/sshd_config | grep -q &amp;quot;\#AllowTcpForwarding yes&amp;quot; &amp;amp;&amp;amp; sed -i &amp;#039;s/\#AllowTcpForwarding yes/AllowTcpForwarding no/&amp;#039; /etc/ssh/sshd_config || sed -i &amp;#039;$a\CVE-2004-1653 (1 of 2) Already complete&amp;#039; /root/ks-lockdown.log&lt;br /&gt;
 cat /etc/ssh/sshd_config | grep -q &amp;quot;AllowTcpForwarding yes&amp;quot; &amp;amp;&amp;amp; sed -i &amp;#039;s/AllowTcpForwarding yes/AllowTcpForwarding no/&amp;#039; /etc/ssh/sshd_config || sed -i &amp;#039;$a\CVE-2004-1653 (2 of 2)Already complete&amp;#039; /root/ks-lockdown.log&lt;br /&gt;
 &lt;br /&gt;
 echo &amp;#039;CVE-2007-2243&amp;#039; &amp;gt;&amp;gt; /root/ks-lockdown.log&lt;br /&gt;
 cat /etc/ssh/sshd_config | grep -q &amp;quot;\#ChallengeResponseAuthentication yes&amp;quot; &amp;amp;&amp;amp; sed -i &amp;#039;s/\#ChallengeResponseAuthentication yes/ChallengeResponseAuthentication no/&amp;#039; /etc/ssh/sshd_config || sed -i &amp;#039;$a\CVE-2007-2243 (1 of 2) Already complete&amp;#039; /root/ks-lockdown.log &lt;br /&gt;
 cat /etc/ssh/sshd_config | grep -q &amp;quot;ChallengeResponseAuthentication yes&amp;quot; &amp;amp;&amp;amp; sed -i &amp;#039;s/ChallengeResponseAuthentication yes/ChallengeResponseAuthentication no/&amp;#039; /etc/ssh/sshd_config || sed -i &amp;#039;$a\CVE-2007-2243 (2 of 2) Already complete&amp;#039; /root/ks-lockdown.log &lt;br /&gt;
 &lt;br /&gt;
 STATUSPID=`ps -ef | grep status| egrep -v grep | head -1 | awk &amp;#039;{print $2}&amp;#039;`&lt;br /&gt;
 kill $STATUSPID&lt;br /&gt;
 printf &amp;quot;\b\b\b\b\b\b\b\b&amp;quot;&lt;br /&gt;
 echo -e &amp;quot;[  \e[1;32mOK\e[0;39m  ]&amp;quot;&lt;br /&gt;
 #end raw&lt;br /&gt;
&lt;br /&gt;
 https://copr-be.cloud.fedoraproject.org/results/openscapmaint/openscap-latest/epel-7-x86_64/&lt;br /&gt;
&lt;br /&gt;
= Spacewalk Installation Instructions =&lt;br /&gt;
== Installing Spacewalk ==&lt;br /&gt;
&lt;br /&gt;
[https://fedorahosted.org/spacewalk/wiki/HowToInstall How-to]&lt;br /&gt;
&lt;br /&gt;
== Joining a Client (Centos 6) to Spacewalk ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;On the Client as root, run:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 mkdir reg-rpms&lt;br /&gt;
 cd reg-rpms&lt;br /&gt;
 wget http://spacewalk/pub/register/rhn-check-2.2.7-1.el6.noarch.rpm http://spacewalk/pub/register/rhn-client-tools-2.2.7-1.el6.noarch.rpm  http://spacewalk/pub/register/rhn-setup-2.2.7-1.el6.noarch.rpm http://spacewalk/pub/register/rhncfg-5.10.73-1.el6.noarch.rpm http://spacewalk/pub/register/rhncfg-actions-5.10.73-1.el6.noarch.rpm http://spacewalk/pub/register/rhncfg-client-5.10.73-1.el6.noarch.rpm http://spacewalk/pub/register/rhnsd-5.0.14-1.el6.x86_64.rpm http://spacewalk/pub/register/yum-rhn-plugin-2.2.7-1.el6.noarch.rpm http://spacewalk/pub/register/m2crypto-0.20.2-9.el6.x86_64.rpm http://spacewalk/pub/register/python-dmidecode-3.10.13-3.el6_4.x86_64.rpm http://spacewalk/pub/register/python-gudev-147.1-4.el6_0.1.x86_64.rpm http://spacewalk/pub/register/python-hwdata-1.7.3-1.el6.noarch.rpm &lt;br /&gt;
 yum -y localinstall rhn-setup-2.2.7-1.el6.noarch.rpm rhnsd-5.0.14-1.el6.x86_64.rpm rhn-check-2.2.7-1.el6.noarch.rpm rhn-client-tools-2.2.7-1.el6.noarch.rpm yum-rhn-plugin-2.2.7-1.el6.noarch.rpm m2crypto-0.20.2-9.el6.x86_64.rpm python-dmidecode-3.10.13-3.el6_4.x86_64.rpm python-hwdata-1.7.3-1.el6.noarch.rpm python-gudev-147.1-4.el6_0.1.x86_64.rpm&lt;br /&gt;
 cd ..&lt;br /&gt;
 rm -rf reg-rpms&lt;br /&gt;
 mkdir keys&lt;br /&gt;
 cd keys&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-7 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-7 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release5 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2014 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2012 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2010 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2008&lt;br /&gt;
 rpm --import *&lt;br /&gt;
 cd ..&lt;br /&gt;
 rm -rf keys/&lt;br /&gt;
 mkdir -p /etc/sysconfig/rhn/allowed-actions/script&lt;br /&gt;
 touch /etc/sysconfig/rhn/allowed-actions/script/run&lt;br /&gt;
 mkdir -p /etc/sysconfig/rhn/allowed-actions/configfiles&lt;br /&gt;
 touch /etc/sysconfig/rhn/allowed-actions/configfiles/all&lt;br /&gt;
 mkdir -p /usr/share/rhn/&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/RHN-ORG-TRUSTED-SSL-CERT -O /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT   &lt;br /&gt;
 perl -npe &amp;#039;s/RHNS-CA-CERT/RHN-ORG-TRUSTED-SSL-CERT/g&amp;#039; -i /etc/sysconfig/rhn/*&lt;br /&gt;
 rhnreg_ks --serverUrl=https://spacewalk.devnet.prv/XMLRPC --sslCACert=/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT --activationkey=1-97d994ea86b8f4ce665d6ef01546834b,1-centos6&lt;br /&gt;
&lt;br /&gt;
== Joining a Client (Centos 7) to Spacewalk ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;On the Client as root, run:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
 mkdir reg-rpms&lt;br /&gt;
 cd reg-rpms&lt;br /&gt;
 wget http://spacewalk/pub/register/centos7/jabberpy-0.5-0.27.el7.noarch.rpm http://spacewalk/pub/register/centos7/osad-5.11.57-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/python-hwdata-1.7.3-4.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhncfg-5.10.83-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhncfg-actions-5.10.83-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhncfg-client-5.10.83-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhn-check-2.3.16-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhn-client-tools-2.3.16-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhnsd-5.0.15-1.el7.x86_64.rpm http://spacewalk/pub/register/centos7/rhn-setup-2.3.16-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/yum-rhn-plugin-2.3.3-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/osa-common-5.11.57-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/rhnlib-2.5.75-1.el7.noarch.rpm http://spacewalk/pub/register/centos7/systemd-sysv-208-20.el7.x86_64.rpm http://spacewalk/pub/register/centos7/systemd-208-20.el7.x86_64.rpm http://spacewalk/pub/register/centos7/python-2.7.5-16.el7.x86_64.rpm http://spacewalk/pub/register/centos7/libnl-1.1.4-3.el7.x86_64.rpm http://spacewalk/pub/register/centos7/libxml2-python-2.9.1-5.el7_0.1.x86_64.rpm http://spacewalk/pub/register/centos7/m2crypto-0.21.1-15.el7.x86_64.rpm http://spacewalk/pub/register/centos7/pygobject2-2.28.6-11.el7.x86_64.rpm http://spacewalk/pub/register/centos7/pyOpenSSL-0.13.1-3.el7.x86_64.rpm http://spacewalk/pub/register/centos7/python-dmidecode-3.10.13-11.el7.x86_64.rpm http://spacewalk/pub/register/centos7/python-ethtool-0.8-5.el7.x86_64.rpm http://spacewalk/pub/register/centos7/usermode-1.111-5.el7.x86_64.rpm http://spacewalk/pub/register/centos7/python-gudev-147.2-7.el7.x86_64.rpm http://spacewalk/pub/register/centos7/libxml2-python-2.9.1-5.el7_1.2.x86_64.rpm&lt;br /&gt;
 yum -y localinstall jabberpy-0.5-0.27.el7.noarch.rpm python-hwdata-1.7.3-4.el7.noarch.rpm rhncfg-actions-5.10.83-1.el7.noarch.rpm rhn-check-2.3.16-1.el7.noarch.rpm rhnsd-5.0.15-1.el7.x86_64.rpm yum-rhn-plugin-2.3.3-1.el7.noarch.rpm osad-5.11.57-1.el7.noarch.rpm rhncfg-5.10.83-1.el7.noarch.rpm rhncfg-client-5.10.83-1.el7.noarch.rpm rhn-client-tools-2.3.16-1.el7.noarch.rpm rhn-setup-2.3.16-1.el7.noarch.rpm systemd-sysv-208-20.el7.x86_64.rpm rhnlib-2.5.75-1.el7.noarch.rpm osa-common-5.11.57-1.el7.noarch.rpm libnl-1.1.4-3.el7.x86_64.rpm m2crypto-0.21.1-15.el7.x86_64.rpm pygobject2-2.28.6-11.el7.x86_64.rpm pyOpenSSL-0.13.1-3.el7.x86_64.rpm python-dmidecode-3.10.13-11.el7.x86_64.rpm python-ethtool-0.8-5.el7.x86_64.rpm usermode-1.111-5.el7.x86_64.rpm python-gudev-147.2-7.el7.x86_64.rpm libxml2-python-2.9.1-5.el7_1.2.x86_64.rpm&lt;br /&gt;
 cd ..&lt;br /&gt;
 rm -rf reg-rpms&lt;br /&gt;
 mkdir keys&lt;br /&gt;
 cd keys&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-7 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-7 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release5 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release6 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2014 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2012 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2010 http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-spacewalk-2008&lt;br /&gt;
 rpm --import *&lt;br /&gt;
 cd ..&lt;br /&gt;
 rm -rf keys/&lt;br /&gt;
 mkdir -p /etc/sysconfig/rhn/allowed-actions/script&lt;br /&gt;
 touch /etc/sysconfig/rhn/allowed-actions/script/run&lt;br /&gt;
 mkdir -p /etc/sysconfig/rhn/allowed-actions/configfiles&lt;br /&gt;
 touch /etc/sysconfig/rhn/allowed-actions/configfiles/all&lt;br /&gt;
 mkdir -p /usr/share/rhn/&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/RHN-ORG-TRUSTED-SSL-CERT -O /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT   &lt;br /&gt;
 perl -npe &amp;#039;s/RHNS-CA-CERT/RHN-ORG-TRUSTED-SSL-CERT/g&amp;#039; -i /etc/sysconfig/rhn/*&lt;br /&gt;
 rhnreg_ks --serverUrl=https://spacewalk.devnet.prv/XMLRPC --sslCACert=/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT --activationkey=1-centos7&lt;br /&gt;
&lt;br /&gt;
== Building RPM&amp;#039;s ==&lt;br /&gt;
https://fedoraproject.org/wiki/How_to_create_an_RPM_package#Preparing_your_system&lt;br /&gt;
&lt;br /&gt;
== Finding GPG key ID and fingerprint ==&lt;br /&gt;
 gpg --with-fingerprint RPM-GPG-KEY-redhat-release5&lt;br /&gt;
&lt;br /&gt;
Output (First highlighted area is the ID and the Second is the fingerprint):&lt;br /&gt;
 pub  1024D/&amp;lt;span style=&amp;quot;background:#FFFF00&amp;quot;&amp;gt;37017186&amp;lt;/span&amp;gt; 2006-12-06 Red Hat, Inc. (release key) &amp;lt;security@redhat.com&amp;gt;&lt;br /&gt;
      Key fingerprint = &amp;lt;span style=&amp;quot;background:#FFFF00&amp;quot;&amp;gt;47DB 2877 89B2 1722 B6D9  5DDE 5326 8101 3701 7186&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Import GPG key on Servers ==&lt;br /&gt;
=== Centos 6 ===&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-6&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-6&lt;br /&gt;
 rpm --import RPM-GPG-KEY-EPEL-6 RPM-GPG-KEY-CentOS-6&lt;br /&gt;
 rm -f RPM-GPG-KEY-EPEL-6 RPM-GPG-KEY-CentOS-6&lt;br /&gt;
&lt;br /&gt;
=== Centos 7 ===&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-7&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-CentOS-7&lt;br /&gt;
 rpm --import RPM-GPG-KEY-EPEL-7 RPM-GPG-KEY-CentOS-7&lt;br /&gt;
 rm -f RPM-GPG-KEY-EPEL-7 RPM-GPG-KEY-CentOS-7&lt;br /&gt;
&lt;br /&gt;
=== RHEL 5 ===&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release5&lt;br /&gt;
 rpm --import RPM-GPG-KEY-redhat-release5&lt;br /&gt;
 rm -f RPM-GPG-KEY-redhat-release5&lt;br /&gt;
&lt;br /&gt;
=== RHEL 6 ===&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-redhat-release6&lt;br /&gt;
 wget http://spacewalk.devnet.prv/pub/keys/RPM-GPG-KEY-EPEL-6&lt;br /&gt;
 rpm --import RPM-GPG-KEY-redhat-release6 RPM-GPG-KEY-EPEL-6&lt;br /&gt;
 rm -f RPM-GPG-KEY-redhat-release6 RPM-GPG-KEY-EPEL-6&lt;br /&gt;
&lt;br /&gt;
== Configure PXE Booting ==&lt;br /&gt;
=== Change PXE Menu Names ===&lt;br /&gt;
vi /etc/cobbler/pxe/pxeprofile.template&lt;br /&gt;
 #set $new_name = $profile_name.replace(&amp;#039;:1:SpacewalkDefaultOrganization&amp;#039;, &amp;#039; &amp;#039;)&lt;br /&gt;
 #set $new_menu_label = $menu_label.replace(&amp;#039;:1:SpacewalkDefaultOrganization&amp;#039;, &amp;#039; &amp;#039;)&lt;br /&gt;
 LABEL $new_name&lt;br /&gt;
         MENU PASSWD&lt;br /&gt;
         kernel $kernel_path&lt;br /&gt;
         $new_menu_label&lt;br /&gt;
         $append_line&lt;br /&gt;
         ipappend 2&lt;br /&gt;
Update PXE files&lt;br /&gt;
 cobbler sync&lt;br /&gt;
 cat /var/lib/tftpboot/pxelinux.cfg/default&lt;br /&gt;
&lt;br /&gt;
=== Add Password, Background, and WindowsDeployment to PXE Menu ===&lt;br /&gt;
vi /etc/cobbler/pxe/pxedefault.template&lt;br /&gt;
 DEFAULT vesamenu.c32&lt;br /&gt;
 PROMPT 0&lt;br /&gt;
 MENU TITLE DevNet Image Central&lt;br /&gt;
 MENU BACKGROUND /devnetSplash.png&lt;br /&gt;
 MENU MARGIN 1&lt;br /&gt;
 MENU ROWS 15&lt;br /&gt;
 MENU COLOR BORDER       30;44     #ffffffff #00000000 std&lt;br /&gt;
 MENU COLOR TITLE        1;36;44   #ffffffff #00000000 std&lt;br /&gt;
 MENU COLOR UNSEL        37;44     #ffffffff #00000000 std&lt;br /&gt;
 MENU COLOR TIMEOUT_MSG  37;40     #ffffffff #00000000 std&lt;br /&gt;
 MENU MASTER PASSWD $1$YVi/j0hL$a6SdxIUHZCA7jFisNZh6O/&lt;br /&gt;
 TIMEOUT 80&lt;br /&gt;
 TOTALTIMEOUT 6000&lt;br /&gt;
 ONTIMEOUT $pxe_timeout_profile&lt;br /&gt;
 LABEL local&lt;br /&gt;
         MENU LABEL (Boot Local System)&lt;br /&gt;
         MENU DEFAULT&lt;br /&gt;
         LOCALBOOT 0  &lt;br /&gt;
 $pxe_menu_items&lt;br /&gt;
 LABEL WindowsDeployment&lt;br /&gt;
         MENU LABEL Windows Deployment&lt;br /&gt;
         MENU PASSWD&lt;br /&gt;
         PXE tftp://10.81.49.27/pxelinux.0 &lt;br /&gt;
 MENU end&lt;br /&gt;
== Setup Pam Authentication w/ VAS ==&lt;br /&gt;
* Put the following in /etc/pam.d/rhn-satellite&lt;br /&gt;
 #%PAM-1.0&lt;br /&gt;
 auth        required      pam_env.so&lt;br /&gt;
 auth        sufficient    pam_vas3.so&lt;br /&gt;
 auth        required      pam_deny.so&lt;br /&gt;
 account     sufficient    pam_vas3.so&lt;br /&gt;
 account     requisite     pam_vas3.so echo_return&lt;br /&gt;
 account     required      pam_unix.so broken_shadow&lt;br /&gt;
* Add the following line to /etc/rhn/rhn.conf&lt;br /&gt;
 pam_auth_service = rhn-satellite&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
=== Client Yum Errors ===&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Error: Cannot retrieve repository metadata (repomd.xml) for repository: &amp;lt;channel&amp;gt; Please verify its path and try again.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
* Client Side:     Check /etc/sysconfig/rhn/up2date and make sure that the spacewalk URL is Fully Qualified.&lt;br /&gt;
* Spacewalk Side:  Check /var/cache/rhn/repodata/&amp;lt;channel&amp;gt;/&lt;br /&gt;
** If noyumrepo.txt exists log into the Web GUI and manage channels. Make sure that the channel Checksum Type is not set to &amp;#039;None&amp;#039;.&lt;br /&gt;
=== Kickstart Errors ===&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Installing error populating transaction, retrying (1/10)&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;error populating transaction after 10 retries: failure: getPackage/&amp;lt;package name&amp;gt; from &amp;lt;repo name&amp;gt;: [Errno 256] No more mirrors to try.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
* Spacewalk Side:  Try running the following command:&lt;br /&gt;
 chmod -R 777 /var/satellite/redhat/1/&lt;br /&gt;
&lt;br /&gt;
= Spacewalk Scripts =&lt;br /&gt;
==cleanupPackages==&lt;br /&gt;
==convertISOtoKickstartTree==&lt;br /&gt;
==createKickstartISO==&lt;br /&gt;
==exportAllChannels==&lt;br /&gt;
==findAndGetKickstartTree==&lt;br /&gt;
==getCompletedActionId==&lt;br /&gt;
==getServerIds==&lt;br /&gt;
==makeKickstartTree==&lt;br /&gt;
==pushConfigurationChannelFiles==&lt;br /&gt;
==reposync==&lt;br /&gt;
==spacewalkCreds==&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>