<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.kitsnet.us/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psmode</id>
	<title>KitsNet - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.kitsnet.us/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psmode"/>
	<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/wiki/Special:Contributions/Psmode"/>
	<updated>2026-10-07T02:13:27Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2704</id>
		<title>KitsNet Operations:Services:LDAP:Authentication Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2704"/>
		<updated>2026-09-27T18:22:35Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
KitsNet applications such as MediaWiki and Grafana authenticate users against the KNADA Active Directory domain using LDAP/LDAPS.&lt;br /&gt;
A failed login does ‘’‘not’’’ necessarily indicate an LDAP server, TLS, CA, or application configuration problem. In particular, an expired KNADA user password may be presented by applications only as a generic authentication failure.&lt;br /&gt;
=== Recommended Diagnostic Order ===&lt;br /&gt;
When one or more LDAP-authenticated applications reject a user’s credentials, use the following sequence before changing application configuration.&lt;br /&gt;
==== Check the affected KNADA user account ====&lt;br /&gt;
On a Samba AD domain controller, such as frangelico:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo samba-tool user show USERNAME&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Review the account state and password information for indications that the password has expired or that the account is otherwise restricted.&lt;br /&gt;
==== Test the user’s password directly over LDAPS ====&lt;br /&gt;
From a system with the KNADA CA installed:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ldapwhoami \&lt;br /&gt;
  -x \&lt;br /&gt;
  -H ldaps://frangelico.knada.lan.kitsnet.us:636 \&lt;br /&gt;
  -D &#039;USERNAME@knada.lan.kitsnet.us&#039; \&lt;br /&gt;
  -W&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful authentication returns the authenticated LDAP identity.&lt;br /&gt;
If this fails, do not immediately assume that TLS or LDAP connectivity is broken. Check the user’s password expiration and account state first.&lt;br /&gt;
==== Test Kerberos authentication ====&lt;br /&gt;
A direct Kerberos test provides an additional check of the user’s KNADA credential:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
kdestroy 2&amp;gt;/dev/null || true&lt;br /&gt;
kinit USERNAME@KNADA.LAN.KITSNET.US&lt;br /&gt;
klist&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful kinit followed by a valid TGT in klist confirms that the user’s password is accepted by Active Directory.&lt;br /&gt;
==== Verify application service-account LDAP access ====&lt;br /&gt;
Applications normally use a service account to search Active Directory before authenticating the individual user.&lt;br /&gt;
For the Wiki, the service account is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
CN=svc-wiki-ldap,CN=Users,DC=knada,DC=lan,DC=kitsnet,DC=us&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Verify that the application service account can:&lt;br /&gt;
establish an LDAPS connection;&lt;br /&gt;
validate the KNADA server certificate;&lt;br /&gt;
bind successfully;&lt;br /&gt;
search the KNADA directory.&lt;br /&gt;
A successful service-account bind proves that the application’s LDAP infrastructure is substantially healthy, but it does ‘’‘not’’’ prove that an individual user’s password is valid.&lt;br /&gt;
==== Verify TLS and CA trust only if necessary ====&lt;br /&gt;
The current KNADA LDAP CA is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
O=KitsNet&lt;br /&gt;
OU=KNADA LDAP&lt;br /&gt;
CN=KitsNet KNADA LDAP CA 2026&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
SHA-256 fingerprint:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
A1:26:57:8E:37:05:52:65:2E:26:7E:48:B0:66:7A:5D:04:4F:C8:BB:A3:4E:E8:B7:12:97:A1:3F:A3:28:15:4F&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
The application-specific CA bundle used by Wiki and other Swarm services contains three certificates:&lt;br /&gt;
Historical Frangelico Samba-generated CA&lt;br /&gt;
Historical Emperador Samba-generated CA&lt;br /&gt;
Current KitsNet KNADA LDAP CA 2026&lt;br /&gt;
When inspecting a multi-certificate PEM bundle, note that:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
openssl x509 -in bundle.pem -noout -subject -issuer&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
displays only the ‘’‘first certificate’’’ in the file.&lt;br /&gt;
Do not conclude that the bundle lacks the current CA based solely on that command. Split or enumerate all certificates in the bundle before diagnosing it as stale.&lt;br /&gt;
=== September 2026 Incident ===&lt;br /&gt;
In September 2026, KNADA authentication failed simultaneously in MediaWiki and Grafana.&lt;br /&gt;
Initial investigation verified:&lt;br /&gt;
IPv4 and IPv6 connectivity to both KNADA domain controllers;&lt;br /&gt;
LDAP and LDAPS availability;&lt;br /&gt;
successful TLS certificate validation;&lt;br /&gt;
correct application CA bundles;&lt;br /&gt;
successful Wiki service-account binds to both Frangelico and Emperador;&lt;br /&gt;
successful LDAP directory searches from the running Wiki container.&lt;br /&gt;
The actual cause was that the affected user’s KNADA password had expired.&lt;br /&gt;
Neither MediaWiki nor Grafana clearly reported the password-expired condition to the user. Both presented the condition as a generic login/authentication failure.&lt;br /&gt;
This incident established the following troubleshooting rule:&lt;br /&gt;
‘’‘When multiple LDAP-authenticated applications reject the same user’s otherwise known-good credentials, check that user’s AD password/account state before changing LDAP, TLS, CA, or application configuration.’’’&lt;br /&gt;
=== Host CA Trust Note ===&lt;br /&gt;
During the same investigation, it was discovered that several Rocky Linux systems did not have the current KNADA LDAP CA installed in their system trust store.&lt;br /&gt;
This was corrected separately through the KitsNet Ansible CA-distribution process.&lt;br /&gt;
That host-trust issue was a valid configuration defect, but it was ‘’‘not’’’ the cause of the MediaWiki and Grafana login failures in this incident because those applications already used their own correct KNADA CA bundles.&lt;br /&gt;
&lt;br /&gt;
[[Category:LDAP]]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2703</id>
		<title>KitsNet Operations:Services:LDAP:Authentication Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2703"/>
		<updated>2026-09-27T18:22:16Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== LDAP Authentication Troubleshooting ==&lt;br /&gt;
KitsNet applications such as MediaWiki and Grafana authenticate users against the KNADA Active Directory domain using LDAP/LDAPS.&lt;br /&gt;
A failed login does ‘’‘not’’’ necessarily indicate an LDAP server, TLS, CA, or application configuration problem. In particular, an expired KNADA user password may be presented by applications only as a generic authentication failure.&lt;br /&gt;
=== Recommended Diagnostic Order ===&lt;br /&gt;
When one or more LDAP-authenticated applications reject a user’s credentials, use the following sequence before changing application configuration.&lt;br /&gt;
==== Check the affected KNADA user account ====&lt;br /&gt;
On a Samba AD domain controller, such as frangelico:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo samba-tool user show USERNAME&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Review the account state and password information for indications that the password has expired or that the account is otherwise restricted.&lt;br /&gt;
==== Test the user’s password directly over LDAPS ====&lt;br /&gt;
From a system with the KNADA CA installed:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ldapwhoami \&lt;br /&gt;
  -x \&lt;br /&gt;
  -H ldaps://frangelico.knada.lan.kitsnet.us:636 \&lt;br /&gt;
  -D &#039;USERNAME@knada.lan.kitsnet.us&#039; \&lt;br /&gt;
  -W&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful authentication returns the authenticated LDAP identity.&lt;br /&gt;
If this fails, do not immediately assume that TLS or LDAP connectivity is broken. Check the user’s password expiration and account state first.&lt;br /&gt;
==== Test Kerberos authentication ====&lt;br /&gt;
A direct Kerberos test provides an additional check of the user’s KNADA credential:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
kdestroy 2&amp;gt;/dev/null || true&lt;br /&gt;
kinit USERNAME@KNADA.LAN.KITSNET.US&lt;br /&gt;
klist&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful kinit followed by a valid TGT in klist confirms that the user’s password is accepted by Active Directory.&lt;br /&gt;
==== Verify application service-account LDAP access ====&lt;br /&gt;
Applications normally use a service account to search Active Directory before authenticating the individual user.&lt;br /&gt;
For the Wiki, the service account is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
CN=svc-wiki-ldap,CN=Users,DC=knada,DC=lan,DC=kitsnet,DC=us&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Verify that the application service account can:&lt;br /&gt;
establish an LDAPS connection;&lt;br /&gt;
validate the KNADA server certificate;&lt;br /&gt;
bind successfully;&lt;br /&gt;
search the KNADA directory.&lt;br /&gt;
A successful service-account bind proves that the application’s LDAP infrastructure is substantially healthy, but it does ‘’‘not’’’ prove that an individual user’s password is valid.&lt;br /&gt;
==== Verify TLS and CA trust only if necessary ====&lt;br /&gt;
The current KNADA LDAP CA is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
O=KitsNet&lt;br /&gt;
OU=KNADA LDAP&lt;br /&gt;
CN=KitsNet KNADA LDAP CA 2026&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
SHA-256 fingerprint:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
A1:26:57:8E:37:05:52:65:2E:26:7E:48:B0:66:7A:5D:04:4F:C8:BB:A3:4E:E8:B7:12:97:A1:3F:A3:28:15:4F&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
The application-specific CA bundle used by Wiki and other Swarm services contains three certificates:&lt;br /&gt;
Historical Frangelico Samba-generated CA&lt;br /&gt;
Historical Emperador Samba-generated CA&lt;br /&gt;
Current KitsNet KNADA LDAP CA 2026&lt;br /&gt;
When inspecting a multi-certificate PEM bundle, note that:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
openssl x509 -in bundle.pem -noout -subject -issuer&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
displays only the ‘’‘first certificate’’’ in the file.&lt;br /&gt;
Do not conclude that the bundle lacks the current CA based solely on that command. Split or enumerate all certificates in the bundle before diagnosing it as stale.&lt;br /&gt;
=== September 2026 Incident ===&lt;br /&gt;
In September 2026, KNADA authentication failed simultaneously in MediaWiki and Grafana.&lt;br /&gt;
Initial investigation verified:&lt;br /&gt;
IPv4 and IPv6 connectivity to both KNADA domain controllers;&lt;br /&gt;
LDAP and LDAPS availability;&lt;br /&gt;
successful TLS certificate validation;&lt;br /&gt;
correct application CA bundles;&lt;br /&gt;
successful Wiki service-account binds to both Frangelico and Emperador;&lt;br /&gt;
successful LDAP directory searches from the running Wiki container.&lt;br /&gt;
The actual cause was that the affected user’s KNADA password had expired.&lt;br /&gt;
Neither MediaWiki nor Grafana clearly reported the password-expired condition to the user. Both presented the condition as a generic login/authentication failure.&lt;br /&gt;
This incident established the following troubleshooting rule:&lt;br /&gt;
‘’‘When multiple LDAP-authenticated applications reject the same user’s otherwise known-good credentials, check that user’s AD password/account state before changing LDAP, TLS, CA, or application configuration.’’’&lt;br /&gt;
=== Host CA Trust Note ===&lt;br /&gt;
During the same investigation, it was discovered that several Rocky Linux systems did not have the current KNADA LDAP CA installed in their system trust store.&lt;br /&gt;
This was corrected separately through the KitsNet Ansible CA-distribution process.&lt;br /&gt;
That host-trust issue was a valid configuration defect, but it was ‘’‘not’’’ the cause of the MediaWiki and Grafana login failures in this incident because those applications already used their own correct KNADA CA bundles.&lt;br /&gt;
&lt;br /&gt;
[[Category:LDAP]]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2702</id>
		<title>KitsNet Operations:Services:LDAP:Authentication Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2702"/>
		<updated>2026-09-27T18:20:25Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== LDAP Authentication Troubleshooting ==&lt;br /&gt;
KitsNet applications such as MediaWiki and Grafana authenticate users against the KNADA Active Directory domain using LDAP/LDAPS.&lt;br /&gt;
A failed login does ‘’‘not’’’ necessarily indicate an LDAP server, TLS, CA, or application configuration problem. In particular, an expired KNADA user password may be presented by applications only as a generic authentication failure.&lt;br /&gt;
=== Recommended Diagnostic Order ===&lt;br /&gt;
When one or more LDAP-authenticated applications reject a user’s credentials, use the following sequence before changing application configuration.&lt;br /&gt;
==== 1. Check the affected KNADA user account ====&lt;br /&gt;
On a Samba AD domain controller, such as frangelico:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo samba-tool user show USERNAME&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Review the account state and password information for indications that the password has expired or that the account is otherwise restricted.&lt;br /&gt;
==== 2. Test the user’s password directly over LDAPS ====&lt;br /&gt;
From a system with the KNADA CA installed:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ldapwhoami \&lt;br /&gt;
  -x \&lt;br /&gt;
  -H ldaps://frangelico.knada.lan.kitsnet.us:636 \&lt;br /&gt;
  -D &#039;USERNAME@knada.lan.kitsnet.us&#039; \&lt;br /&gt;
  -W&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful authentication returns the authenticated LDAP identity.&lt;br /&gt;
If this fails, do not immediately assume that TLS or LDAP connectivity is broken. Check the user’s password expiration and account state first.&lt;br /&gt;
==== 3. Test Kerberos authentication ====&lt;br /&gt;
A direct Kerberos test provides an additional check of the user’s KNADA credential:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
kdestroy 2&amp;gt;/dev/null || true&lt;br /&gt;
kinit USERNAME@KNADA.LAN.KITSNET.US&lt;br /&gt;
klist&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful kinit followed by a valid TGT in klist confirms that the user’s password is accepted by Active Directory.&lt;br /&gt;
==== 4. Verify application service-account LDAP access ====&lt;br /&gt;
Applications normally use a service account to search Active Directory before authenticating the individual user.&lt;br /&gt;
For the Wiki, the service account is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
CN=svc-wiki-ldap,CN=Users,DC=knada,DC=lan,DC=kitsnet,DC=us&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Verify that the application service account can:&lt;br /&gt;
establish an LDAPS connection;&lt;br /&gt;
validate the KNADA server certificate;&lt;br /&gt;
bind successfully;&lt;br /&gt;
search the KNADA directory.&lt;br /&gt;
A successful service-account bind proves that the application’s LDAP infrastructure is substantially healthy, but it does ‘’‘not’’’ prove that an individual user’s password is valid.&lt;br /&gt;
==== 5. Verify TLS and CA trust only if necessary ====&lt;br /&gt;
The current KNADA LDAP CA is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
O=KitsNet&lt;br /&gt;
OU=KNADA LDAP&lt;br /&gt;
CN=KitsNet KNADA LDAP CA 2026&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
SHA-256 fingerprint:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
A1:26:57:8E:37:05:52:65:2E:26:7E:48:B0:66:7A:5D:04:4F:C8:BB:A3:4E:E8:B7:12:97:A1:3F:A3:28:15:4F&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
The application-specific CA bundle used by Wiki and other Swarm services contains three certificates:&lt;br /&gt;
Historical Frangelico Samba-generated CA&lt;br /&gt;
Historical Emperador Samba-generated CA&lt;br /&gt;
Current KitsNet KNADA LDAP CA 2026&lt;br /&gt;
When inspecting a multi-certificate PEM bundle, note that:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
openssl x509 -in bundle.pem -noout -subject -issuer&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
displays only the ‘’‘first certificate’’’ in the file.&lt;br /&gt;
Do not conclude that the bundle lacks the current CA based solely on that command. Split or enumerate all certificates in the bundle before diagnosing it as stale.&lt;br /&gt;
=== September 2026 Incident ===&lt;br /&gt;
In September 2026, KNADA authentication failed simultaneously in MediaWiki and Grafana.&lt;br /&gt;
Initial investigation verified:&lt;br /&gt;
IPv4 and IPv6 connectivity to both KNADA domain controllers;&lt;br /&gt;
LDAP and LDAPS availability;&lt;br /&gt;
successful TLS certificate validation;&lt;br /&gt;
correct application CA bundles;&lt;br /&gt;
successful Wiki service-account binds to both Frangelico and Emperador;&lt;br /&gt;
successful LDAP directory searches from the running Wiki container.&lt;br /&gt;
The actual cause was that the affected user’s KNADA password had expired.&lt;br /&gt;
Neither MediaWiki nor Grafana clearly reported the password-expired condition to the user. Both presented the condition as a generic login/authentication failure.&lt;br /&gt;
This incident established the following troubleshooting rule:&lt;br /&gt;
‘’‘When multiple LDAP-authenticated applications reject the same user’s otherwise known-good credentials, check that user’s AD password/account state before changing LDAP, TLS, CA, or application configuration.’’’&lt;br /&gt;
=== Host CA Trust Note ===&lt;br /&gt;
During the same investigation, it was discovered that several Rocky Linux systems did not have the current KNADA LDAP CA installed in their system trust store.&lt;br /&gt;
This was corrected separately through the KitsNet Ansible CA-distribution process.&lt;br /&gt;
That host-trust issue was a valid configuration defect, but it was ‘’‘not’’’ the cause of the MediaWiki and Grafana login failures in this incident because those applications already used their own correct KNADA CA bundles.&lt;br /&gt;
[[Category:LDAP]]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2701</id>
		<title>KitsNet Operations:Services:LDAP:Authentication Troubleshooting</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:LDAP:Authentication_Troubleshooting&amp;diff=2701"/>
		<updated>2026-09-27T18:19:22Z</updated>

		<summary type="html">&lt;p&gt;Psmode: Created page with &amp;quot;== LDAP Authentication Troubleshooting == KitsNet applications such as MediaWiki and Grafana authenticate users against the KNADA Active Directory domain using LDAP/LDAPS. A failed login does ‘’‘not’’’ necessarily indicate an LDAP server, TLS, CA, or application configuration problem. In particular, an expired KNADA user password may be presented by applications only as a generic authentication failure. === Recommended Diagnostic Order === When one or more LD...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== LDAP Authentication Troubleshooting ==&lt;br /&gt;
KitsNet applications such as MediaWiki and Grafana authenticate users against the KNADA Active Directory domain using LDAP/LDAPS.&lt;br /&gt;
A failed login does ‘’‘not’’’ necessarily indicate an LDAP server, TLS, CA, or application configuration problem. In particular, an expired KNADA user password may be presented by applications only as a generic authentication failure.&lt;br /&gt;
=== Recommended Diagnostic Order ===&lt;br /&gt;
When one or more LDAP-authenticated applications reject a user’s credentials, use the following sequence before changing application configuration.&lt;br /&gt;
==== 1. Check the affected KNADA user account ====&lt;br /&gt;
On a Samba AD domain controller, such as frangelico:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo samba-tool user show USERNAME&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Review the account state and password information for indications that the password has expired or that the account is otherwise restricted.&lt;br /&gt;
==== 2. Test the user’s password directly over LDAPS ====&lt;br /&gt;
From a system with the KNADA CA installed:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
ldapwhoami \&lt;br /&gt;
  -x \&lt;br /&gt;
  -H ldaps://frangelico.knada.lan.kitsnet.us:636 \&lt;br /&gt;
  -D &#039;USERNAME@knada.lan.kitsnet.us&#039; \&lt;br /&gt;
  -W&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful authentication returns the authenticated LDAP identity.&lt;br /&gt;
If this fails, do not immediately assume that TLS or LDAP connectivity is broken. Check the user’s password expiration and account state first.&lt;br /&gt;
==== 3. Test Kerberos authentication ====&lt;br /&gt;
A direct Kerberos test provides an additional check of the user’s KNADA credential:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
kdestroy 2&amp;gt;/dev/null || true&lt;br /&gt;
kinit USERNAME@KNADA.LAN.KITSNET.US&lt;br /&gt;
klist&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
A successful kinit followed by a valid TGT in klist confirms that the user’s password is accepted by Active Directory.&lt;br /&gt;
==== 4. Verify application service-account LDAP access ====&lt;br /&gt;
Applications normally use a service account to search Active Directory before authenticating the individual user.&lt;br /&gt;
For the Wiki, the service account is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
CN=svc-wiki-ldap,CN=Users,DC=knada,DC=lan,DC=kitsnet,DC=us&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
Verify that the application service account can:&lt;br /&gt;
establish an LDAPS connection;&lt;br /&gt;
validate the KNADA server certificate;&lt;br /&gt;
bind successfully;&lt;br /&gt;
search the KNADA directory.&lt;br /&gt;
A successful service-account bind proves that the application’s LDAP infrastructure is substantially healthy, but it does ‘’‘not’’’ prove that an individual user’s password is valid.&lt;br /&gt;
==== 5. Verify TLS and CA trust only if necessary ====&lt;br /&gt;
The current KNADA LDAP CA is:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
O=KitsNet&lt;br /&gt;
OU=KNADA LDAP&lt;br /&gt;
CN=KitsNet KNADA LDAP CA 2026&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
SHA-256 fingerprint:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
A1:26:57:8E:37:05:52:65:2E:26:7E:48:B0:66:7A:5D:04:4F:C8:BB:A3:4E:E8:B7:12:97:A1:3F:A3:28:15:4F&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
The application-specific CA bundle used by Wiki and other Swarm services contains three certificates:&lt;br /&gt;
Historical Frangelico Samba-generated CA&lt;br /&gt;
Historical Emperador Samba-generated CA&lt;br /&gt;
Current KitsNet KNADA LDAP CA 2026&lt;br /&gt;
When inspecting a multi-certificate PEM bundle, note that:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
openssl x509 -in bundle.pem -noout -subject -issuer&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
displays only the ‘’‘first certificate’’’ in the file.&lt;br /&gt;
Do not conclude that the bundle lacks the current CA based solely on that command. Split or enumerate all certificates in the bundle before diagnosing it as stale.&lt;br /&gt;
=== September 2026 Incident ===&lt;br /&gt;
In September 2026, KNADA authentication failed simultaneously in MediaWiki and Grafana.&lt;br /&gt;
Initial investigation verified:&lt;br /&gt;
IPv4 and IPv6 connectivity to both KNADA domain controllers;&lt;br /&gt;
LDAP and LDAPS availability;&lt;br /&gt;
successful TLS certificate validation;&lt;br /&gt;
correct application CA bundles;&lt;br /&gt;
successful Wiki service-account binds to both Frangelico and Emperador;&lt;br /&gt;
successful LDAP directory searches from the running Wiki container.&lt;br /&gt;
The actual cause was that the affected user’s KNADA password had expired.&lt;br /&gt;
Neither MediaWiki nor Grafana clearly reported the password-expired condition to the user. Both presented the condition as a generic login/authentication failure.&lt;br /&gt;
This incident established the following troubleshooting rule:&lt;br /&gt;
‘’‘When multiple LDAP-authenticated applications reject the same user’s otherwise known-good credentials, check that user’s AD password/account state before changing LDAP, TLS, CA, or application configuration.’’’&lt;br /&gt;
=== Host CA Trust Note ===&lt;br /&gt;
During the same investigation, it was discovered that several Rocky Linux systems did not have the current KNADA LDAP CA installed in their system trust store.&lt;br /&gt;
This was corrected separately through the KitsNet Ansible CA-distribution process.&lt;br /&gt;
That host-trust issue was a valid configuration defect, but it was ‘’‘not’’’ the cause of the MediaWiki and Grafana login failures in this incident because those applications already used their own correct KNADA CA bundles.&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Services&amp;diff=2696</id>
		<title>KitsNet Services</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Services&amp;diff=2696"/>
		<updated>2026-09-22T12:58:07Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
This page provides the hierarchical index of KitsNet service documentation.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;categorytree mode=&amp;quot;pages&amp;quot; depth=&amp;quot;5&amp;quot; hideroot=&amp;quot;on&amp;quot; showcount=&amp;quot;off&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet Services&lt;br /&gt;
&amp;lt;/categorytree&amp;gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2695</id>
		<title>KitsNet Operations:Services:Mail Gateway:No-Subscription Warning Suppression</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2695"/>
		<updated>2026-09-22T12:54:52Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__FORCETOC__&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
This local customization suppresses Proxmox Mail Gateway (PMG) &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warnings in the web interface without pretending that the system has a valid subscription and without changing PMG mail filtering, repository configuration, licensing state, or subscription data.&lt;br /&gt;
&lt;br /&gt;
The customization is intended for the KitsNet PMG host &#039;&#039;&#039;dusse&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Initially tested with:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component&lt;br /&gt;
! Version&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-mailgateway&lt;br /&gt;
| 9.1&lt;br /&gt;
|-&lt;br /&gt;
| pmg-api&lt;br /&gt;
| 9.1.2&lt;br /&gt;
|-&lt;br /&gt;
| pmg-gui&lt;br /&gt;
| 5.2.2&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-widget-toolkit&lt;br /&gt;
| 5.2.8&lt;br /&gt;
|-&lt;br /&gt;
| pmg-mobile-quarantine-ui&lt;br /&gt;
| 0.5.3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Files Installed ==&lt;br /&gt;
&lt;br /&gt;
; Main patcher&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT/DPKG wrapper&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT hook&lt;br /&gt;
: &amp;lt;code&amp;gt;/etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; Log&lt;br /&gt;
: &amp;lt;code&amp;gt;/var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Files Modified by the Patcher ==&lt;br /&gt;
&lt;br /&gt;
=== Proxmox Widget Toolkit ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modification:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Proxmox.Utils.checked_command()&amp;lt;/code&amp;gt; is changed so that the requested command executes immediately instead of displaying the generic &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warning.&lt;br /&gt;
&lt;br /&gt;
=== PMG GUI ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modifications:&lt;br /&gt;
&lt;br /&gt;
* The PMG dashboard subscription-warning panel is hidden.&lt;br /&gt;
* The explicit subscription check performed while changing into a logged-in/user view is suppressed.&lt;br /&gt;
&lt;br /&gt;
The actual PMG &#039;&#039;&#039;Subscription&#039;&#039;&#039; configuration page remains available and continues to report the real subscription state.&lt;br /&gt;
&lt;br /&gt;
== Normal Use ==&lt;br /&gt;
&lt;br /&gt;
The patch is normally reapplied automatically after Debian/Proxmox package operations by the APT post-invoke hook.&lt;br /&gt;
&lt;br /&gt;
No routine manual action should be required.&lt;br /&gt;
&lt;br /&gt;
== Manual Check ==&lt;br /&gt;
&lt;br /&gt;
To verify that all expected KitsNet modifications are currently present:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected successful output:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
OK: all KitsNet PMG subscription-suppression patches are present.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A nonzero return code means one or more expected modifications are absent.&lt;br /&gt;
&lt;br /&gt;
== Manual Apply / Reapply ==&lt;br /&gt;
&lt;br /&gt;
To apply or reapply the customization manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The patcher is &#039;&#039;&#039;idempotent&#039;&#039;&#039;. Running it when all patches are already present does not make additional changes.&lt;br /&gt;
&lt;br /&gt;
== After Applying the Patch ==&lt;br /&gt;
&lt;br /&gt;
Browser JavaScript may remain cached.&lt;br /&gt;
&lt;br /&gt;
After applying or reapplying the patch, hard-refresh PMG browser sessions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+R&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Do this for both:&lt;br /&gt;
&lt;br /&gt;
* administrator sessions&lt;br /&gt;
* quarantine / ordinary-user sessions&lt;br /&gt;
&lt;br /&gt;
== Automatic Reapplication After Updates ==&lt;br /&gt;
&lt;br /&gt;
APT runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
after package operations.&lt;br /&gt;
&lt;br /&gt;
That wrapper runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and records the result in:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The wrapper always exits successfully so that a cosmetic local PMG GUI customization can never cause an APT or Proxmox package upgrade to fail.&lt;br /&gt;
&lt;br /&gt;
== Safe Failure Behavior ==&lt;br /&gt;
&lt;br /&gt;
The patcher only modifies files when the expected source-code structures are found exactly.&lt;br /&gt;
&lt;br /&gt;
If a future Proxmox release changes the relevant JavaScript enough that the known patterns no longer match, the patcher:&lt;br /&gt;
&lt;br /&gt;
* makes no speculative modification&lt;br /&gt;
* reports the mismatch&lt;br /&gt;
* returns an error&lt;br /&gt;
* records the problem in the log when run automatically&lt;br /&gt;
* allows the package upgrade itself to complete normally&lt;br /&gt;
&lt;br /&gt;
This is intentional.&lt;br /&gt;
&lt;br /&gt;
After a major PMG or &amp;lt;code&amp;gt;proxmox-widget-toolkit&amp;lt;/code&amp;gt; update, inspect the new source before changing the patcher to match the new implementation.&lt;br /&gt;
&lt;br /&gt;
== Checking the Log ==&lt;br /&gt;
&lt;br /&gt;
Recent results:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Search the system journal for automatic-patch warnings:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo journalctl -t kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Backups ==&lt;br /&gt;
&lt;br /&gt;
Whenever the patcher modifies one of the PMG JavaScript files, it creates a timestamped backup alongside that file.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Earlier manual backups may also exist with names such as:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
*.kitsnet-nosub-backup-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These backups are intended for troubleshooting and rollback.&lt;br /&gt;
&lt;br /&gt;
== Removing / Disabling Automatic Reapplication ==&lt;br /&gt;
&lt;br /&gt;
To stop automatically reapplying the customization after package updates, remove or rename the APT hook:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo rm /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does &#039;&#039;&#039;not&#039;&#039;&#039; restore the original JavaScript files. It only disables the automatic post-package invocation.&lt;br /&gt;
&lt;br /&gt;
== Restoring Stock Proxmox Files ==&lt;br /&gt;
&lt;br /&gt;
The cleanest way to restore current package-provided versions is normally to reinstall the packages that own the modified files.&lt;br /&gt;
&lt;br /&gt;
First identify the installed package versions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
dpkg-query -W proxmox-widget-toolkit pmg-gui&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable the KitsNet APT hook before reinstalling packages, otherwise the patch will be reapplied immediately:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mv /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub \&lt;br /&gt;
    /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub.disabled&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then reinstall the affected packages using the normal Proxmox/Debian package-management procedure.&lt;br /&gt;
&lt;br /&gt;
Afterward, hard-refresh the browser.&lt;br /&gt;
&lt;br /&gt;
== What This Patch Does NOT Do ==&lt;br /&gt;
&lt;br /&gt;
This customization does &#039;&#039;&#039;not&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* install or emulate a Proxmox subscription&lt;br /&gt;
* alter the PMG API subscription result&lt;br /&gt;
* enable the enterprise repository&lt;br /&gt;
* disable repository warnings unless separately customized&lt;br /&gt;
* change SpamAssassin, ClamAV, SMTP, quarantine, filtering, or delivery&lt;br /&gt;
* alter licensing or support entitlement&lt;br /&gt;
* modify the PMG mobile quarantine bundle unless explicitly extended&lt;br /&gt;
&lt;br /&gt;
== Known Separate Warning ==&lt;br /&gt;
&lt;br /&gt;
The yellow dashboard message:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Non production-ready repository enabled!&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
is a separate repository-status warning. It is not part of the no-subscription suppression described here.&lt;br /&gt;
&lt;br /&gt;
== Source Markers ==&lt;br /&gt;
&lt;br /&gt;
The installed JavaScript modifications are intentionally marked with &#039;&#039;&#039;KITSNET&#039;&#039;&#039; comments so they are easy to locate.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
KITSNET: suppress no-subscription warning&lt;br /&gt;
&lt;br /&gt;
KITSNET: hide no-subscription dashboard panel&lt;br /&gt;
&lt;br /&gt;
KITSNET: suppress subscription check when changing views&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Quick Reference ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Task&lt;br /&gt;
! Command&lt;br /&gt;
|-&lt;br /&gt;
| Check patch status&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Apply / reapply&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| View log&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Hard-refresh browser&lt;br /&gt;
| &amp;lt;code&amp;gt;Ctrl+Shift+R&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance Note ==&lt;br /&gt;
&lt;br /&gt;
This is a local KitsNet customization to package-managed JavaScript files.&lt;br /&gt;
&lt;br /&gt;
Proxmox updates are expected to replace those files. The patcher and APT hook exist specifically so the customization can be safely and repeatably reapplied after updates.&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2694</id>
		<title>KitsNet Operations:Services:Mail Gateway:No-Subscription Warning Suppression</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2694"/>
		<updated>2026-09-22T12:54:15Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
This local customization suppresses Proxmox Mail Gateway (PMG) &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warnings in the web interface without pretending that the system has a valid subscription and without changing PMG mail filtering, repository configuration, licensing state, or subscription data.&lt;br /&gt;
&lt;br /&gt;
The customization is intended for the KitsNet PMG host &#039;&#039;&#039;dusse&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Initially tested with:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component&lt;br /&gt;
! Version&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-mailgateway&lt;br /&gt;
| 9.1&lt;br /&gt;
|-&lt;br /&gt;
| pmg-api&lt;br /&gt;
| 9.1.2&lt;br /&gt;
|-&lt;br /&gt;
| pmg-gui&lt;br /&gt;
| 5.2.2&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-widget-toolkit&lt;br /&gt;
| 5.2.8&lt;br /&gt;
|-&lt;br /&gt;
| pmg-mobile-quarantine-ui&lt;br /&gt;
| 0.5.3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Files Installed ==&lt;br /&gt;
&lt;br /&gt;
; Main patcher&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT/DPKG wrapper&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT hook&lt;br /&gt;
: &amp;lt;code&amp;gt;/etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; Log&lt;br /&gt;
: &amp;lt;code&amp;gt;/var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Files Modified by the Patcher ==&lt;br /&gt;
&lt;br /&gt;
=== Proxmox Widget Toolkit ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modification:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Proxmox.Utils.checked_command()&amp;lt;/code&amp;gt; is changed so that the requested command executes immediately instead of displaying the generic &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warning.&lt;br /&gt;
&lt;br /&gt;
=== PMG GUI ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modifications:&lt;br /&gt;
&lt;br /&gt;
* The PMG dashboard subscription-warning panel is hidden.&lt;br /&gt;
* The explicit subscription check performed while changing into a logged-in/user view is suppressed.&lt;br /&gt;
&lt;br /&gt;
The actual PMG &#039;&#039;&#039;Subscription&#039;&#039;&#039; configuration page remains available and continues to report the real subscription state.&lt;br /&gt;
&lt;br /&gt;
== Normal Use ==&lt;br /&gt;
&lt;br /&gt;
The patch is normally reapplied automatically after Debian/Proxmox package operations by the APT post-invoke hook.&lt;br /&gt;
&lt;br /&gt;
No routine manual action should be required.&lt;br /&gt;
&lt;br /&gt;
== Manual Check ==&lt;br /&gt;
&lt;br /&gt;
To verify that all expected KitsNet modifications are currently present:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected successful output:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
OK: all KitsNet PMG subscription-suppression patches are present.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A nonzero return code means one or more expected modifications are absent.&lt;br /&gt;
&lt;br /&gt;
== Manual Apply / Reapply ==&lt;br /&gt;
&lt;br /&gt;
To apply or reapply the customization manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The patcher is &#039;&#039;&#039;idempotent&#039;&#039;&#039;. Running it when all patches are already present does not make additional changes.&lt;br /&gt;
&lt;br /&gt;
== After Applying the Patch ==&lt;br /&gt;
&lt;br /&gt;
Browser JavaScript may remain cached.&lt;br /&gt;
&lt;br /&gt;
After applying or reapplying the patch, hard-refresh PMG browser sessions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+R&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Do this for both:&lt;br /&gt;
&lt;br /&gt;
* administrator sessions&lt;br /&gt;
* quarantine / ordinary-user sessions&lt;br /&gt;
&lt;br /&gt;
== Automatic Reapplication After Updates ==&lt;br /&gt;
&lt;br /&gt;
APT runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
after package operations.&lt;br /&gt;
&lt;br /&gt;
That wrapper runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and records the result in:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The wrapper always exits successfully so that a cosmetic local PMG GUI customization can never cause an APT or Proxmox package upgrade to fail.&lt;br /&gt;
&lt;br /&gt;
== Safe Failure Behavior ==&lt;br /&gt;
&lt;br /&gt;
The patcher only modifies files when the expected source-code structures are found exactly.&lt;br /&gt;
&lt;br /&gt;
If a future Proxmox release changes the relevant JavaScript enough that the known patterns no longer match, the patcher:&lt;br /&gt;
&lt;br /&gt;
* makes no speculative modification&lt;br /&gt;
* reports the mismatch&lt;br /&gt;
* returns an error&lt;br /&gt;
* records the problem in the log when run automatically&lt;br /&gt;
* allows the package upgrade itself to complete normally&lt;br /&gt;
&lt;br /&gt;
This is intentional.&lt;br /&gt;
&lt;br /&gt;
After a major PMG or &amp;lt;code&amp;gt;proxmox-widget-toolkit&amp;lt;/code&amp;gt; update, inspect the new source before changing the patcher to match the new implementation.&lt;br /&gt;
&lt;br /&gt;
== Checking the Log ==&lt;br /&gt;
&lt;br /&gt;
Recent results:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Search the system journal for automatic-patch warnings:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo journalctl -t kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Backups ==&lt;br /&gt;
&lt;br /&gt;
Whenever the patcher modifies one of the PMG JavaScript files, it creates a timestamped backup alongside that file.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Earlier manual backups may also exist with names such as:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
*.kitsnet-nosub-backup-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These backups are intended for troubleshooting and rollback.&lt;br /&gt;
&lt;br /&gt;
== Removing / Disabling Automatic Reapplication ==&lt;br /&gt;
&lt;br /&gt;
To stop automatically reapplying the customization after package updates, remove or rename the APT hook:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo rm /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does &#039;&#039;&#039;not&#039;&#039;&#039; restore the original JavaScript files. It only disables the automatic post-package invocation.&lt;br /&gt;
&lt;br /&gt;
== Restoring Stock Proxmox Files ==&lt;br /&gt;
&lt;br /&gt;
The cleanest way to restore current package-provided versions is normally to reinstall the packages that own the modified files.&lt;br /&gt;
&lt;br /&gt;
First identify the installed package versions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
dpkg-query -W proxmox-widget-toolkit pmg-gui&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable the KitsNet APT hook before reinstalling packages, otherwise the patch will be reapplied immediately:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mv /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub \&lt;br /&gt;
    /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub.disabled&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then reinstall the affected packages using the normal Proxmox/Debian package-management procedure.&lt;br /&gt;
&lt;br /&gt;
Afterward, hard-refresh the browser.&lt;br /&gt;
&lt;br /&gt;
== What This Patch Does NOT Do ==&lt;br /&gt;
&lt;br /&gt;
This customization does &#039;&#039;&#039;not&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* install or emulate a Proxmox subscription&lt;br /&gt;
* alter the PMG API subscription result&lt;br /&gt;
* enable the enterprise repository&lt;br /&gt;
* disable repository warnings unless separately customized&lt;br /&gt;
* change SpamAssassin, ClamAV, SMTP, quarantine, filtering, or delivery&lt;br /&gt;
* alter licensing or support entitlement&lt;br /&gt;
* modify the PMG mobile quarantine bundle unless explicitly extended&lt;br /&gt;
&lt;br /&gt;
== Known Separate Warning ==&lt;br /&gt;
&lt;br /&gt;
The yellow dashboard message:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Non production-ready repository enabled!&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
is a separate repository-status warning. It is not part of the no-subscription suppression described here.&lt;br /&gt;
&lt;br /&gt;
== Source Markers ==&lt;br /&gt;
&lt;br /&gt;
The installed JavaScript modifications are intentionally marked with &#039;&#039;&#039;KITSNET&#039;&#039;&#039; comments so they are easy to locate.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
KITSNET: suppress no-subscription warning&lt;br /&gt;
&lt;br /&gt;
KITSNET: hide no-subscription dashboard panel&lt;br /&gt;
&lt;br /&gt;
KITSNET: suppress subscription check when changing views&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Quick Reference ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Task&lt;br /&gt;
! Command&lt;br /&gt;
|-&lt;br /&gt;
| Check patch status&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Apply / reapply&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| View log&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Hard-refresh browser&lt;br /&gt;
| &amp;lt;code&amp;gt;Ctrl+Shift+R&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance Note ==&lt;br /&gt;
&lt;br /&gt;
This is a local KitsNet customization to package-managed JavaScript files.&lt;br /&gt;
&lt;br /&gt;
Proxmox updates are expected to replace those files. The patcher and APT hook exist specifically so the customization can be safely and repeatably reapplied after updates.&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2693</id>
		<title>KitsNet Operations:Services:Mail Gateway:No-Subscription Warning Suppression</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Services:Mail_Gateway:No-Subscription_Warning_Suppression&amp;diff=2693"/>
		<updated>2026-09-22T12:54:03Z</updated>

		<summary type="html">&lt;p&gt;Psmode: Created page with &amp;quot;__NOTOC__ = KitsNet PMG No-Subscription Warning Suppression =  == Purpose ==  This local customization suppresses Proxmox Mail Gateway (PMG) &amp;#039;&amp;#039;&amp;#039;&amp;quot;No valid subscription&amp;quot;&amp;#039;&amp;#039;&amp;#039; warnings in the web interface without pretending that the system has a valid subscription and without changing PMG mail filtering, repository configuration, licensing state, or subscription data.  The customization is intended for the KitsNet PMG host &amp;#039;&amp;#039;&amp;#039;dusse&amp;#039;&amp;#039;&amp;#039;.  Initially tested with:  {| class=&amp;quot;wiki...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
= KitsNet PMG No-Subscription Warning Suppression =&lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
This local customization suppresses Proxmox Mail Gateway (PMG) &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warnings in the web interface without pretending that the system has a valid subscription and without changing PMG mail filtering, repository configuration, licensing state, or subscription data.&lt;br /&gt;
&lt;br /&gt;
The customization is intended for the KitsNet PMG host &#039;&#039;&#039;dusse&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Initially tested with:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Component&lt;br /&gt;
! Version&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-mailgateway&lt;br /&gt;
| 9.1&lt;br /&gt;
|-&lt;br /&gt;
| pmg-api&lt;br /&gt;
| 9.1.2&lt;br /&gt;
|-&lt;br /&gt;
| pmg-gui&lt;br /&gt;
| 5.2.2&lt;br /&gt;
|-&lt;br /&gt;
| proxmox-widget-toolkit&lt;br /&gt;
| 5.2.8&lt;br /&gt;
|-&lt;br /&gt;
| pmg-mobile-quarantine-ui&lt;br /&gt;
| 0.5.3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Files Installed ==&lt;br /&gt;
&lt;br /&gt;
; Main patcher&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT/DPKG wrapper&lt;br /&gt;
: &amp;lt;code&amp;gt;/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; APT hook&lt;br /&gt;
: &amp;lt;code&amp;gt;/etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
; Log&lt;br /&gt;
: &amp;lt;code&amp;gt;/var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Files Modified by the Patcher ==&lt;br /&gt;
&lt;br /&gt;
=== Proxmox Widget Toolkit ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modification:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Proxmox.Utils.checked_command()&amp;lt;/code&amp;gt; is changed so that the requested command executes immediately instead of displaying the generic &#039;&#039;&#039;&amp;quot;No valid subscription&amp;quot;&#039;&#039;&#039; warning.&lt;br /&gt;
&lt;br /&gt;
=== PMG GUI ===&lt;br /&gt;
&lt;br /&gt;
File:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Modifications:&lt;br /&gt;
&lt;br /&gt;
* The PMG dashboard subscription-warning panel is hidden.&lt;br /&gt;
* The explicit subscription check performed while changing into a logged-in/user view is suppressed.&lt;br /&gt;
&lt;br /&gt;
The actual PMG &#039;&#039;&#039;Subscription&#039;&#039;&#039; configuration page remains available and continues to report the real subscription state.&lt;br /&gt;
&lt;br /&gt;
== Normal Use ==&lt;br /&gt;
&lt;br /&gt;
The patch is normally reapplied automatically after Debian/Proxmox package operations by the APT post-invoke hook.&lt;br /&gt;
&lt;br /&gt;
No routine manual action should be required.&lt;br /&gt;
&lt;br /&gt;
== Manual Check ==&lt;br /&gt;
&lt;br /&gt;
To verify that all expected KitsNet modifications are currently present:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected successful output:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
OK: all KitsNet PMG subscription-suppression patches are present.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A nonzero return code means one or more expected modifications are absent.&lt;br /&gt;
&lt;br /&gt;
== Manual Apply / Reapply ==&lt;br /&gt;
&lt;br /&gt;
To apply or reapply the customization manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The patcher is &#039;&#039;&#039;idempotent&#039;&#039;&#039;. Running it when all patches are already present does not make additional changes.&lt;br /&gt;
&lt;br /&gt;
== After Applying the Patch ==&lt;br /&gt;
&lt;br /&gt;
Browser JavaScript may remain cached.&lt;br /&gt;
&lt;br /&gt;
After applying or reapplying the patch, hard-refresh PMG browser sessions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Ctrl+Shift+R&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Do this for both:&lt;br /&gt;
&lt;br /&gt;
* administrator sessions&lt;br /&gt;
* quarantine / ordinary-user sessions&lt;br /&gt;
&lt;br /&gt;
== Automatic Reapplication After Updates ==&lt;br /&gt;
&lt;br /&gt;
APT runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-apt-hook&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
after package operations.&lt;br /&gt;
&lt;br /&gt;
That wrapper runs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/local/sbin/kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
and records the result in:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The wrapper always exits successfully so that a cosmetic local PMG GUI customization can never cause an APT or Proxmox package upgrade to fail.&lt;br /&gt;
&lt;br /&gt;
== Safe Failure Behavior ==&lt;br /&gt;
&lt;br /&gt;
The patcher only modifies files when the expected source-code structures are found exactly.&lt;br /&gt;
&lt;br /&gt;
If a future Proxmox release changes the relevant JavaScript enough that the known patterns no longer match, the patcher:&lt;br /&gt;
&lt;br /&gt;
* makes no speculative modification&lt;br /&gt;
* reports the mismatch&lt;br /&gt;
* returns an error&lt;br /&gt;
* records the problem in the log when run automatically&lt;br /&gt;
* allows the package upgrade itself to complete normally&lt;br /&gt;
&lt;br /&gt;
This is intentional.&lt;br /&gt;
&lt;br /&gt;
After a major PMG or &amp;lt;code&amp;gt;proxmox-widget-toolkit&amp;lt;/code&amp;gt; update, inspect the new source before changing the patcher to match the new implementation.&lt;br /&gt;
&lt;br /&gt;
== Checking the Log ==&lt;br /&gt;
&lt;br /&gt;
Recent results:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Search the system journal for automatic-patch warnings:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo journalctl -t kitsnet-pmg-nosub-patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Backups ==&lt;br /&gt;
&lt;br /&gt;
Whenever the patcher modifies one of the PMG JavaScript files, it creates a timestamped backup alongside that file.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&lt;br /&gt;
/usr/share/javascript/pmg-gui/js/pmgmanagerlib.js.kitsnet-prepatch-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Earlier manual backups may also exist with names such as:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
*.kitsnet-nosub-backup-YYYYMMDD-HHMMSS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These backups are intended for troubleshooting and rollback.&lt;br /&gt;
&lt;br /&gt;
== Removing / Disabling Automatic Reapplication ==&lt;br /&gt;
&lt;br /&gt;
To stop automatically reapplying the customization after package updates, remove or rename the APT hook:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo rm /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This does &#039;&#039;&#039;not&#039;&#039;&#039; restore the original JavaScript files. It only disables the automatic post-package invocation.&lt;br /&gt;
&lt;br /&gt;
== Restoring Stock Proxmox Files ==&lt;br /&gt;
&lt;br /&gt;
The cleanest way to restore current package-provided versions is normally to reinstall the packages that own the modified files.&lt;br /&gt;
&lt;br /&gt;
First identify the installed package versions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
dpkg-query -W proxmox-widget-toolkit pmg-gui&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable the KitsNet APT hook before reinstalling packages, otherwise the patch will be reapplied immediately:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mv /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub \&lt;br /&gt;
    /etc/apt/apt.conf.d/99-kitsnet-pmg-nosub.disabled&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then reinstall the affected packages using the normal Proxmox/Debian package-management procedure.&lt;br /&gt;
&lt;br /&gt;
Afterward, hard-refresh the browser.&lt;br /&gt;
&lt;br /&gt;
== What This Patch Does NOT Do ==&lt;br /&gt;
&lt;br /&gt;
This customization does &#039;&#039;&#039;not&#039;&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* install or emulate a Proxmox subscription&lt;br /&gt;
* alter the PMG API subscription result&lt;br /&gt;
* enable the enterprise repository&lt;br /&gt;
* disable repository warnings unless separately customized&lt;br /&gt;
* change SpamAssassin, ClamAV, SMTP, quarantine, filtering, or delivery&lt;br /&gt;
* alter licensing or support entitlement&lt;br /&gt;
* modify the PMG mobile quarantine bundle unless explicitly extended&lt;br /&gt;
&lt;br /&gt;
== Known Separate Warning ==&lt;br /&gt;
&lt;br /&gt;
The yellow dashboard message:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Non production-ready repository enabled!&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
is a separate repository-status warning. It is not part of the no-subscription suppression described here.&lt;br /&gt;
&lt;br /&gt;
== Source Markers ==&lt;br /&gt;
&lt;br /&gt;
The installed JavaScript modifications are intentionally marked with &#039;&#039;&#039;KITSNET&#039;&#039;&#039; comments so they are easy to locate.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
KITSNET: suppress no-subscription warning&lt;br /&gt;
&lt;br /&gt;
KITSNET: hide no-subscription dashboard panel&lt;br /&gt;
&lt;br /&gt;
KITSNET: suppress subscription check when changing views&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Quick Reference ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Task&lt;br /&gt;
! Command&lt;br /&gt;
|-&lt;br /&gt;
| Check patch status&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch --check&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Apply / reapply&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo /usr/local/sbin/kitsnet-pmg-nosub-patch&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| View log&lt;br /&gt;
| &amp;lt;code&amp;gt;sudo tail -100 /var/log/kitsnet-pmg-nosub-patch.log&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Hard-refresh browser&lt;br /&gt;
| &amp;lt;code&amp;gt;Ctrl+Shift+R&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance Note ==&lt;br /&gt;
&lt;br /&gt;
This is a local KitsNet customization to package-managed JavaScript files.&lt;br /&gt;
&lt;br /&gt;
Proxmox updates are expected to replace those files. The patcher and APT hook exist specifically so the customization can be safely and repeatably reapplied after updates.&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Linux:Tips_and_Tricks&amp;diff=2692</id>
		<title>Linux:Tips and Tricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Linux:Tips_and_Tricks&amp;diff=2692"/>
		<updated>2026-09-18T21:40:06Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NONUMBERHEADINGS__&lt;br /&gt;
====Find files modified in past N days====&lt;br /&gt;
&amp;lt;code&amp;gt;find &#039;&#039;path&#039;&#039; -mtime -&#039;&#039;N&#039;&#039; -ls&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
[psmode@wort ~]$ find /kvm/ -mtime -3 -ls&lt;br /&gt;
102090127      4 drwxr-xr-x   7  root     root         4096 Jan  3 09:46 /kvm/&lt;br /&gt;
  2038539      4 drwxr-xr-x   2  root     kitsnet_adm     4096 Jan  3 09:13 /kvm/socat-kvm&lt;br /&gt;
  2038573      4 -rw-r--r--   1  root     root               5 Jan  3 09:13 /kvm/socat-kvm/uv040&lt;br /&gt;
101237691      8 -rw-r--r--   1  root     kitsnet_adm     6370 Jan  3 09:46 /kvm/uv034.xml&lt;br /&gt;
102163845     12 -rw-r--r--   1  root     root            9096 Jan  3 09:46 /kvm/uv039.xml&lt;br /&gt;
102090129     12 -rw-r--r--   1  root     root            8303 Jan  3 09:46 /kvm/uv040.xml&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Search files modified in past N days ====&lt;br /&gt;
&amp;lt;code&amp;gt;find &#039;&#039;path&#039;&#039; -mtime -&#039;&#039;N&#039;&#039; -type f -exec grep &#039;&#039;pattern&#039;&#039;  {} /dev/null \;&amp;lt;/code&amp;gt;&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
[psmode@ciroc ~]$ sudo find /etc -mtime -9 -type f -exec grep mailroom1  {} /dev/null \;&lt;br /&gt;
/etc/httpd/conf/httpd.conf:    DocumentRoot &amp;quot;/var/www/virt-html/mailroom1.kitsnet.us&amp;quot;&lt;br /&gt;
/etc/httpd/conf/httpd.conf:    ServerName mailroom1.kitsnet.us&lt;br /&gt;
/etc/httpd/conf/httpd.conf:#RewriteCond %{SERVER_NAME} =mailroom1.kitsnet.us&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Shell script debugging modes====&lt;br /&gt;
A good explanation of the debugging modes is given by [https://www.tecmint.com/enable-shell-debug-mode-linux/ How To Enable Shell Script Debugging Mode in Linux]. Basically, there are three modes&lt;br /&gt;
&lt;br /&gt;
*&amp;lt;code&amp;gt;-v&amp;lt;/code&amp;gt; (short for verbose) – tells the shell to show all lines in a script while they are read, it activates verbose mode.&lt;br /&gt;
*&amp;lt;code&amp;gt;-n&amp;lt;/code&amp;gt; (short for noexec or no execution) – instructs the shell read all the commands, however doesn’t execute them. This options activates syntax checking mode.&lt;br /&gt;
*&amp;lt;code&amp;gt;-x&amp;lt;/code&amp;gt; (short for xtrace or execution trace) – tells the shell to display all commands and their arguments on the terminal while they are executed. This option enables shell tracing mode.&lt;br /&gt;
&lt;br /&gt;
Which may be invoked by any of three different ways:&lt;br /&gt;
&lt;br /&gt;
#Modifying the first line of a shell script: &amp;lt;code&amp;gt;#!/bin/sh &#039;&#039;option(s)&#039;&#039;&amp;lt;/code&amp;gt;&lt;br /&gt;
#Invoking shell with debugging options: &amp;lt;code&amp;gt;$ /bin/bash &#039;&#039;option(s)&#039;&#039; &#039;&#039;script_name&#039;&#039; &#039;&#039;argument1 ... argumentN&#039;&#039;&amp;lt;/code&amp;gt;   &lt;br /&gt;
#Using set shell built-in command in the middle of the script: &amp;lt;code&amp;gt;$ set -&#039;&#039;option&#039;&#039;&amp;lt;/code&amp;gt; to enable or &amp;lt;code&amp;gt;$ set +&#039;&#039;option&#039;&#039;&amp;lt;/code&amp;gt; to disable&lt;br /&gt;
&lt;br /&gt;
====Network Diagnostics====&lt;br /&gt;
See also [https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/networking_guide/sec-configuring_ip_networking_with_nmcli Red Hat 7 Networking Guide 3.3. Configuring IP Networking with nmcli] and [https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/index RED HAT ENTERPRISE LINUX 8 Configuring and managing networking] and [https://docs.rockylinux.org/guides/network/basic_network_configuration/ Network Configuration - Rocky Linux 9] and [https://opensource.com/article/22/8/migrate-networkmanager-keyfiles-configuration How I migrated to NetworkManager keyfiles for configuration]&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# ip address&lt;br /&gt;
# ip link&lt;br /&gt;
# ip route&lt;br /&gt;
# ip -6 route&lt;br /&gt;
# firewall-cmd --list-all --zone=... (replace ... with whatever zones you are working with)&lt;br /&gt;
# nmcli connection show &lt;br /&gt;
# nmcli connection show --active&lt;br /&gt;
# nmcli device status&lt;br /&gt;
# nmcli connection show &amp;lt;device&amp;gt;&lt;br /&gt;
# sysctl -a | grep -E &#039;forwarding&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====How to use diff and patch====&lt;br /&gt;
The diff utility can be used to generate a patch file. Basically, the differences are put togetehr with syntax from the patch utility so that the resulting file can be used to turn another copy of the original file into the desired final state file. A good reference article is [https://www.pair.com/support/kb/paircloud-diff-and-patch/ available online] The high level syntax is:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# diff -u file1.html file2.html &amp;gt; patchfile.patch&lt;br /&gt;
# patch file1.html patchfile.patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;To reverse the patch, use:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
# patch -p0 -R -i patchfile.patch&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Explore filesystem utilization====&lt;br /&gt;
I have installed [https://dev.yorhel.nl/ncdu NCurses Disk Usage] (ncdu ) on all KitsNet Linux systems.&lt;br /&gt;
&lt;br /&gt;
====Time coordination with chrony====&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
yum install -y chrony                    # to install  &lt;br /&gt;
systemctl enable chronyd                 # to enable  &lt;br /&gt;
systemctl start chronyd                  # to start  &lt;br /&gt;
chronyc tracking                         # To get information about the main time reference&lt;br /&gt;
chronyc sources -v                       # equivalent information to the ntpq&lt;br /&gt;
ntpdate pool.ntp.org                     # To quickly synchronize a server&lt;br /&gt;
timedatectl                              # display time and synchronization status&lt;br /&gt;
chronyc -m &#039;burst 3/3&#039; &#039;makestep 0.1 3&#039;  # sync time using timesources NOW&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;If for some reason the clock is thrown off (e.g. after VM migration), you can force an immediate resync, but &amp;lt;code&amp;gt;makestep&amp;lt;/code&amp;gt; just allows the clock to be corrected by step instead of slow slew. You should add the &amp;lt;code&amp;gt;burst&amp;lt;/code&amp;gt; command to make a new set of measurements.&lt;br /&gt;
&lt;br /&gt;
====How to mount a multi-partition disk image in Linux====&lt;br /&gt;
&lt;br /&gt;
You can use &#039;&#039;&#039;kpartx&#039;&#039;&#039; or &#039;&#039;&#039;partx&#039;&#039;&#039; to create loop devices for the partitions on the image, and then mount them. So either:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;$ sudo kpartx -v -a file.iso&lt;br /&gt;
 add map loop0p1 (253:17): 0 8382464 linear 7:1 2048&lt;br /&gt;
 $ mount /dev/mapper/loop0p1 ./mnt_point&lt;br /&gt;
 ...  do something with the partition  ...&lt;br /&gt;
 $ umount ./mnt_point&lt;br /&gt;
 $ kpartx -d -v file.iso&lt;br /&gt;
 del devmap : loop0p1&lt;br /&gt;
 loop deleted : /dev/loop0&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
or:&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
$ sudo partx -a -v file.iso&lt;br /&gt;
partition: none, disk: file.iso, lower: 0, upper: 0&lt;br /&gt;
Trying to use &#039;/dev/loop0&#039; for the loop device&lt;br /&gt;
/dev/loop0: partition table type &#039;dos&#039; detected&lt;br /&gt;
range recount: max partno=1, lower=0, upper=0&lt;br /&gt;
/dev/loop0: partition #1 added&lt;br /&gt;
$ mount /dev/loop0p1 ./mnt_point&lt;br /&gt;
...  do something with the partition  ...&lt;br /&gt;
$ umount /dev/loop0p1 ./mnt_point&lt;br /&gt;
$ sudo partx -d -v /dev/loop0&lt;br /&gt;
partition: none, disk: /dev/loop0, lower: 0, upper: 0&lt;br /&gt;
/dev/loop0: partition #1 removed&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====DHCP Lease Renewal====&lt;br /&gt;
&lt;br /&gt;
[https://www.cyberciti.biz/faq/howto-linux-renew-dhcp-client-ip-address/ Linux Force DHCP Client (dhclient) to Renew IP Address] covers this in greater detail for a number of platforms and environments. For KitsNet, the two methods that work are based on &amp;lt;code&amp;gt;dhclient&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;nmcli&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====dhclient=====&lt;br /&gt;
The &amp;lt;kbd&amp;gt;-r&amp;lt;/kbd&amp;gt; flag explicitly releases the current lease, and once the lease has been released, the client exits. For example, open terminal application and type the command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;$ sudo dhclient -r&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now obtain fresh IP address using DHCP on Linux:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;$ sudo dhclient&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=====nmcli=====&lt;br /&gt;
The NetworkManager daemon attempts to make networking configuration and operation as painless and automatic as possible by managing the primary network connection and other network interfaces, like Ethernet, WiFi, and Mobile Broadband devices command-line tool for controlling NetworkManager. The &amp;lt;code&amp;gt;nmcli&amp;lt;/code&amp;gt; is a command-line tool for controlling NetworkManager and getting its status. To renew IP address using nmcli for connection named ‘nixcraft_5G’ (use ‘&amp;lt;code&amp;gt;nmcli con&amp;lt;/code&amp;gt;‘ command to get list of all connections):&lt;br /&gt;
 nmcli con&lt;br /&gt;
 nmcli con down id &#039;nixcraft_5G&#039;&lt;br /&gt;
 nmcli con up id &#039;nixcraft_5G&#039;&lt;br /&gt;
 # Attempt to update device with changes to the currently active &lt;br /&gt;
 # connection made since it was last applied and then try it again&lt;br /&gt;
 nmcli device reapply &#039;nixcraft_5G&#039;&lt;br /&gt;
&lt;br /&gt;
====GRUB2====&lt;br /&gt;
[[Media:Grub.pdf|the GNU GRUB manual - The GRand Unified Bootloader, version 2.12]], originally downloaded from [https://www.gnu.org/software/grub/manual/grub/grub.pdf here]&lt;br /&gt;
&lt;br /&gt;
=====Booting into Rescue mode or Emergency Mode=====&lt;br /&gt;
[https://www.thegeekdiary.com/how-to-boot-into-rescue-mode-or-emergency-mode-through-systemd-in-centos-rhel-7-and-8/ How to Boot into Rescue Mode or Emergency Mode Through Systemd in CentOS/RHEL 7 and 8]&amp;lt;blockquote&amp;gt;Rescue mode is equivalent to single user mode and requires the root password. Rescue mode allows you to repair your system in situations when it is unable to complete a regular booting process. Rescue mode will try to mount all local file systems and start some important system services, but it does not activate network interfaces neither allow multiple users to be logged in.&lt;br /&gt;
&lt;br /&gt;
Emergency mode provides the most minimal environment possible and allows you to repair your system even in situations when the system is unable to enter rescue mode. In emergency mode, the system mounts the root file system as read-only, does not attempt to mount any other local file systems, does not activate network interfaces.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#During bootup, when the GRUB2 menu shows up, press the &amp;lt;code&amp;gt;&#039;&#039;&#039;e&#039;&#039;&#039;&amp;lt;/code&amp;gt; key for edit.&lt;br /&gt;
#Add a parameter to the end of the linux16 line. For rescue mode add &amp;lt;code&amp;gt;systemd.unit=rescue.target&amp;lt;/code&amp;gt;, for emergency mode add &amp;lt;code&amp;gt;systemd.unit=emergency.target&amp;lt;/code&amp;gt;&lt;br /&gt;
#Press &amp;lt;code&amp;gt;&#039;&#039;&#039;Ctrl+x&#039;&#039;&#039;&amp;lt;/code&amp;gt; to boot the system with the parameter.&lt;br /&gt;
&lt;br /&gt;
===== Change Default Boot Selection (or, how to downgrade the OS) =====&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
sudo grubby --info=ALL | grep ^kernel               #which versions are on the menu&lt;br /&gt;
sudo grubby --grub2 --default-title                 #which is the current default&lt;br /&gt;
sudo grubby --set-default &amp;quot;/boot/vmlinuz-5.14.0-362.13.1.el9_3.x86_64&amp;quot;  #Set the default to this by path&lt;br /&gt;
sudo grubby --set-default 0                         #reset the default to the top (most recent) choice)&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== MegaRAID ====&lt;br /&gt;
Copy of [[Media:51530-00 RevP MegaRAID SAS SW UserGd.pdf|MegaRAID SAS Software User Guide]] (August 2014) from Avago Technologies&lt;br /&gt;
&lt;br /&gt;
===== CLI =====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Handy CLI Commands&lt;br /&gt;
!Task&lt;br /&gt;
!Command&lt;br /&gt;
|-&lt;br /&gt;
|Show VD reconstruction/migration status&lt;br /&gt;
|&amp;lt;code&amp;gt;storcli64 /c0 /vall show migrate&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Show VD rebuild status&lt;br /&gt;
|&amp;lt;code&amp;gt;storcli64 /c0 /eall /sall show rebuild&amp;lt;/code&amp;gt;&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;storcli64 -PDRbld -ShowProg -PhysDrv[&#039;&#039;252:3&#039;&#039;] -a0&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Show PD detailed status&lt;br /&gt;
|&amp;lt;code&amp;gt;storcli64 -pdlist -aALL&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Silence alarm&lt;br /&gt;
|&amp;lt;code&amp;gt;storcli64 /c0 set alarm=silence&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Show VD detailed status&lt;br /&gt;
|&amp;lt;code&amp;gt;storcli64 -LDInfo -Lall -a0&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
it seems that either &amp;lt;code&amp;gt;&#039;&#039;&#039;-&#039;&#039;&#039;&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;&#039;&#039;&#039;/&#039;&#039;&#039;&amp;lt;/code&amp;gt; may be used to introduce command switches.&lt;br /&gt;
&lt;br /&gt;
===== Replacing a failed or failing disk =====&lt;br /&gt;
See [https://www.advancedclustering.com/act_kb/replacing-a-disk-with-megacli/ REPLACING AN LSI RAID DISK WITH MEGACLI]&lt;br /&gt;
&lt;br /&gt;
# Check is the status of the VD and of the PDs&lt;br /&gt;
#Set the original disk offline if an error has not already cause the controller to set it offline: &amp;lt;code&amp;gt;storcli64 -pdoffline -physdrv[&#039;&#039;252:3&#039;&#039;] -a0&amp;lt;/code&amp;gt;&lt;br /&gt;
#Mark the failed disk as missing: &amp;lt;code&amp;gt;storcli64 -pdmarkmissing -physdrv[&#039;&#039;252:3&#039;&#039;] -aAll&amp;lt;/code&amp;gt;&lt;br /&gt;
#Mark the failed disk as prepared for removal: &amp;lt;code&amp;gt;storcli64 -pdprprmv -physdrv[&#039;&#039;252:3&#039;&#039;] -a0&amp;lt;/code&amp;gt;&lt;br /&gt;
#Replace the faulty disk (in other systems, pdlocate can be helpful)&lt;br /&gt;
#If you don’t use hot spares you will need to add the disk to the array and start the rebuild manually: &amp;lt;code&amp;gt;storcli64 -PdReplaceMissing -PhysDrv[&#039;&#039;252:3&#039;&#039;] -Array0 -row0 -a0&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;storcli64 -PDRbld -Start -PhysDrv[&#039;&#039;252:3&#039;&#039;] -a0&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Systemctl====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Commands to show and manipulate services&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
|-&lt;br /&gt;
|List all the &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; service which are in &amp;lt;code&amp;gt;state=active&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;sub=running&amp;lt;/code&amp;gt;&lt;br /&gt;
|&amp;lt;code&amp;gt;systemctl list-units --type=service --state=running&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|List all the &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; serice which are in &amp;lt;code&amp;gt;state=active&amp;lt;/code&amp;gt; and sub either running or exited&lt;br /&gt;
|&amp;lt;code&amp;gt;systemctl list-units --type=service --state=active&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|To enable and start a service at the same time&lt;br /&gt;
|&amp;lt;code&amp;gt;systemctl enable --now &#039;&#039;service&#039;&#039;&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Show enabled units&lt;br /&gt;
|&amp;lt;code&amp;gt;systemctl list-unit-files --state=enabled&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Manual SMTP session ====&lt;br /&gt;
Not exactly an Linux tip, but close enough. I got tired of re-inventing this, so I asked ChatGPT. Additional information is available from [https://mailtrap.io/blog/smtp-commands-and-responses/ SMTP Commands and Response Codes Guide]&lt;br /&gt;
&lt;br /&gt;
* Open a terminal and type: &amp;lt;code&amp;gt;telnet &amp;lt;SMTP_server_address&amp;gt; 25&amp;lt;/code&amp;gt;&lt;br /&gt;
* Once connected, you&#039;ll see a response from the server. Typically, it will start with something like&amp;lt;code&amp;gt;220 &amp;lt;SMTP_server_address&amp;gt; ESMTP&amp;lt;/code&amp;gt;&lt;br /&gt;
* Enter the following commands to send an email:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;text&amp;quot;&amp;gt;&lt;br /&gt;
HELO &amp;lt;smtp_client_domain&amp;gt;&lt;br /&gt;
MAIL FROM:&amp;lt;sender_email_address&amp;gt;&lt;br /&gt;
RCPT TO:&amp;lt;recipient_email_address&amp;gt;&lt;br /&gt;
DATA&lt;br /&gt;
Subject: Your subject here&lt;br /&gt;
Your email body here.&lt;br /&gt;
.&lt;br /&gt;
QUIT&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* After typing &amp;lt;code&amp;gt;DATA&amp;lt;/code&amp;gt;, you&#039;ll be prompted to enter the body of your email. After composing your message, end it with a period . on a new line.&lt;br /&gt;
* Finally, type &amp;lt;code&amp;gt;QUIT&amp;lt;/code&amp;gt; to close the connection.&lt;br /&gt;
&lt;br /&gt;
==== Monitoring utilities on wort ====&lt;br /&gt;
Aside from systat, iostat, top and glances, wort has some additional utilities installed that can be used to capture information about disk IO performance amongst other things.&lt;br /&gt;
&lt;br /&gt;
* [https://htop.dev/ htop] is an interactive process viewer&lt;br /&gt;
* [https://github.com/dstat-real/dstat/blob/master/README.adoc dstat] has been forked to [https://github.com/scottchiefbaker/dool dool] because RedHat hijacked the name&lt;br /&gt;
** Try &amp;lt;code&amp;gt;dstat -tcdD total,nvme0n1,sda,sdb,sdc,sdd,sde,sdf  --disk-wait --disk-util 30&amp;lt;/code&amp;gt;&lt;br /&gt;
* [https://pcp.io/ pcp] (Performance Co-Pilot) supports [https://access.redhat.com/articles/2450251 storage performance analysis] and other things&lt;br /&gt;
&lt;br /&gt;
==== After installtion of microcode_ctl, initramfs hasn&#039;t been re-generated for all the installed kernel packages ====&lt;br /&gt;
Need to run &amp;lt;code&amp;gt;dracut&amp;lt;/code&amp;gt; against all installed kernels to make sure they all get the updated microocde. &amp;lt;syntaxhighlight lang=&amp;quot;shell&amp;quot;&amp;gt;&lt;br /&gt;
find  /lib/modules -name &amp;quot;*.dep&amp;quot; | awk -v FS=/ &#039; {system(&amp;quot;sudo dracut -f --kver &amp;quot; $4)}&#039;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Bash functions with parameters instead of alias ====&lt;br /&gt;
See https://askubuntu.com/questions/666130/bash-alias-with-parameters for background. Basically, aliases cannot part out parameters positionally as with a shell script; bash just expands the alias and anything else on the command line is parsed subsequently. So doing clever things like using a parameter twice in the exmpansion is not going to work with just an alias. If a script is not wanted, an alias is the way to go.&lt;br /&gt;
&lt;br /&gt;
Here is one used to do XML dumps of VMs to a file named for the VM:&amp;lt;syntaxhighlight lang=&amp;quot;shell&amp;quot;&amp;gt;&lt;br /&gt;
dxml() { virsh dumpxml $1 &amp;gt; $1.xml ;}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;As with bash scripts, the &amp;lt;code&amp;gt;$@&amp;lt;/code&amp;gt; macro can be used to substiture for &amp;quot;rest of line&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Rescue physical disk ===&lt;br /&gt;
Once physical disks start throwing bad blocks consistently, it may be best to take an image of the disk and use that to restore to a new volume. However, traditional usage od the &amp;lt;code&amp;gt;dd&amp;lt;/code&amp;gt; command will probably not work, since it will give up at the first read error. The best tool for the job is thus &amp;lt;code&amp;gt;[https://www.gnu.org/software/ddrescue/ ddrescue]&amp;lt;/code&amp;gt; . This tool implmenets direct, non-cached reads, multiple passes,  selectable retries a logging mechaism, generation of a graphical map, detailed progress and more. Until i can make it more generic, here is the script used to rescue the SD card on the PictureFrame Raspberry Pi; the SD card was 12 years old by the time it failed.&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
# CONFIGURATION&lt;br /&gt;
SOURCE_DEVICE=&amp;quot;/dev/sdf&amp;quot;            # Replace with your source device&lt;br /&gt;
DEST_IMAGE=&amp;quot;/mnt/rpi/pictureframe/rescue-sdf.img&amp;quot;             # Output disk image&lt;br /&gt;
LOGFILE=&amp;quot;/mnt/rpi/pictureframe/rescue-sdf.log&amp;quot;                # Persistent log file&lt;br /&gt;
MAX_RETRIES=5                       # Number of retry passes&lt;br /&gt;
BLOCK_SIZE=&amp;quot;512&amp;quot;                    # Use small blocks to isolate errors&lt;br /&gt;
&lt;br /&gt;
# COLORS (optional for nice output)&lt;br /&gt;
GREEN=&amp;quot;\e[32m&amp;quot;&lt;br /&gt;
YELLOW=&amp;quot;\e[33m&amp;quot;&lt;br /&gt;
RED=&amp;quot;\e[31m&amp;quot;&lt;br /&gt;
RESET=&amp;quot;\e[0m&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Check if running as root&lt;br /&gt;
if [ &amp;quot;$EUID&amp;quot; -ne 0 ]; then&lt;br /&gt;
  echo -e &amp;quot;${RED}Please run as root.${RESET}&amp;quot;&lt;br /&gt;
  exit 1&lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
# Confirm device&lt;br /&gt;
echo -e &amp;quot;${YELLOW}About to recover from: ${SOURCE_DEVICE}&amp;quot;&lt;br /&gt;
echo -e &amp;quot;Output image: ${DEST_IMAGE}&amp;quot;&lt;br /&gt;
echo -e &amp;quot;Log file: ${LOGFILE}${RESET}&amp;quot;&lt;br /&gt;
read -rp &amp;quot;Continue? [y/N]: &amp;quot; confirm&lt;br /&gt;
[[ &amp;quot;$confirm&amp;quot; != &amp;quot;y&amp;quot; &amp;amp;&amp;amp; &amp;quot;$confirm&amp;quot; != &amp;quot;Y&amp;quot; ]] &amp;amp;&amp;amp; exit 0&lt;br /&gt;
&lt;br /&gt;
# Initial fast pass: skip errors for speed&lt;br /&gt;
echo -e &amp;quot;${GREEN}Starting initial fast copy pass...${RESET}&amp;quot;&lt;br /&gt;
ddrescue -f -n -b &amp;quot;$BLOCK_SIZE&amp;quot; &amp;quot;$SOURCE_DEVICE&amp;quot; &amp;quot;$DEST_IMAGE&amp;quot; &amp;quot;$LOGFILE&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Retry pass: go over bad areas&lt;br /&gt;
echo -e &amp;quot;${YELLOW}Retrying failed sectors up to $MAX_RETRIES times...${RESET}&amp;quot;&lt;br /&gt;
ddrescue -d -r&amp;quot;$MAX_RETRIES&amp;quot; -b &amp;quot;$BLOCK_SIZE&amp;quot; &amp;quot;$SOURCE_DEVICE&amp;quot; &amp;quot;$DEST_IMAGE&amp;quot; &amp;quot;$LOGFILE&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Done&lt;br /&gt;
echo -e &amp;quot;${GREEN}Recovery completed. Image saved to ${DEST_IMAGE}${RESET}&amp;quot;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
The utility [https://sourceforge.net/projects/ddrescueview/ ddrescueview] may be used to visualize the map generated in the log file from the run.&lt;br /&gt;
&lt;br /&gt;
[[File:Rescue-sdf-vierw.png|thumb|left|Visualization of rescued volume with some unrecoverable blocks]]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:LAN:absolut:CAPsMAN_Troubleshooting_Guide&amp;diff=2690</id>
		<title>KitsNet Network:LAN:absolut:CAPsMAN Troubleshooting Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:LAN:absolut:CAPsMAN_Troubleshooting_Guide&amp;diff=2690"/>
		<updated>2026-09-18T21:38:28Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
This guide documents troubleshooting procedures for the KitsNet wireless&lt;br /&gt;
infrastructure using MikroTik CAPsMAN.&lt;br /&gt;
&lt;br /&gt;
Controller: &#039;&#039;&#039;absolut (CHR)&#039;&#039;&#039;  &lt;br /&gt;
Edge router: &#039;&#039;&#039;courvoisier&#039;&#039;&#039;  &lt;br /&gt;
CAP devices: &#039;&#039;&#039;able&#039;&#039;&#039;, &#039;&#039;&#039;baker&#039;&#039;&#039;  &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Quick Diagnostic Checklist ==&lt;br /&gt;
&lt;br /&gt;
When wireless problems occur, check the following first:&lt;br /&gt;
&lt;br /&gt;
# Are the CAP devices connected to CAPsMAN?&lt;br /&gt;
# Are radios provisioned correctly?&lt;br /&gt;
# Are datapaths correct?&lt;br /&gt;
# Are clients completing WPA authentication?&lt;br /&gt;
# Are DHCP leases being issued?&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Verify CAP Registration ==&lt;br /&gt;
&lt;br /&gt;
On the CAPsMAN controller (absolut):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man remote-cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected output:&lt;br /&gt;
&lt;br /&gt;
* able – Run&lt;br /&gt;
* baker – Run&lt;br /&gt;
&lt;br /&gt;
If a CAP is missing:&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* wrong controller IP&lt;br /&gt;
* CAP locked to another controller&lt;br /&gt;
* CAP discovery blocked&lt;br /&gt;
* certificate mismatch&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Verify Radios and Provisioning ==&lt;br /&gt;
&lt;br /&gt;
Check radio provisioning:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man interface print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected radios:&lt;br /&gt;
&lt;br /&gt;
* able 2.4 GHz&lt;br /&gt;
* able 5 GHz&lt;br /&gt;
* baker 2.4 GHz&lt;br /&gt;
* baker 5 GHz&lt;br /&gt;
&lt;br /&gt;
If radios are missing:&lt;br /&gt;
&lt;br /&gt;
Check provisioning rules:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man provisioning print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common causes:&lt;br /&gt;
&lt;br /&gt;
* incorrect radio MAC match&lt;br /&gt;
* wrong provisioning rule order&lt;br /&gt;
* configuration name mismatch&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Check Client Associations ==&lt;br /&gt;
&lt;br /&gt;
On the controller:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man registration-table print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This shows connected wireless clients.&lt;br /&gt;
&lt;br /&gt;
Important fields:&lt;br /&gt;
&lt;br /&gt;
* signal strength&lt;br /&gt;
* TX/RX rate&lt;br /&gt;
* interface name&lt;br /&gt;
&lt;br /&gt;
If clients are not appearing:&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* WPA authentication failure&lt;br /&gt;
* incorrect security profile&lt;br /&gt;
* wrong SSID configuration&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Diagnosing 4-Way Handshake Failures ==&lt;br /&gt;
&lt;br /&gt;
Symptoms:&lt;br /&gt;
&lt;br /&gt;
* clients see the SSID but cannot connect&lt;br /&gt;
* repeated authentication attempts&lt;br /&gt;
* log entries referencing handshake failures&lt;br /&gt;
&lt;br /&gt;
Check controller log:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/log print where message~&amp;quot;handshake&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Cause !! Description&lt;br /&gt;
|-&lt;br /&gt;
| Security profile mismatch&lt;br /&gt;
| SSID uses wrong WPA2/WPA3 configuration&lt;br /&gt;
|-&lt;br /&gt;
| Datapath misconfiguration&lt;br /&gt;
| bridge or VLAN incorrect&lt;br /&gt;
|-&lt;br /&gt;
| CAP not synchronized&lt;br /&gt;
| radio using stale configuration&lt;br /&gt;
|-&lt;br /&gt;
| client compatibility issue&lt;br /&gt;
| older devices cannot use WPA3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Recommended test:&lt;br /&gt;
&lt;br /&gt;
Temporarily force WPA2 only.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Cannot Discover Controller ==&lt;br /&gt;
&lt;br /&gt;
Check CAP configuration:&lt;br /&gt;
&lt;br /&gt;
On the CAP:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Important values:&lt;br /&gt;
&lt;br /&gt;
* enabled: yes&lt;br /&gt;
* discovery interface correct&lt;br /&gt;
* caps-man-addresses correct&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
caps-man-addresses: 192.168.15.x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test connectivity:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ping 192.168.15.x&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Locked to Wrong Controller ==&lt;br /&gt;
&lt;br /&gt;
CAPs can be locked to a specific controller.&lt;br /&gt;
&lt;br /&gt;
Check:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If necessary unlock:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap set lock-to-caps-man=no&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Certificate Problems ==&lt;br /&gt;
&lt;br /&gt;
If certificates are used for CAP authentication:&lt;br /&gt;
&lt;br /&gt;
Check controller certificate:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man manager print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check CAP certificate usage:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common issues:&lt;br /&gt;
&lt;br /&gt;
* certificate not copied during migration&lt;br /&gt;
* CA mismatch&lt;br /&gt;
* expired certificate&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Datapath Problems ==&lt;br /&gt;
&lt;br /&gt;
Datapaths determine how traffic flows.&lt;br /&gt;
&lt;br /&gt;
Check datapaths:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man datapath print detail&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Important field:&lt;br /&gt;
&lt;br /&gt;
* local-forwarding&lt;br /&gt;
&lt;br /&gt;
Interpretation:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Value !! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| yes&lt;br /&gt;
| traffic stays on CAP&lt;br /&gt;
|-&lt;br /&gt;
| no&lt;br /&gt;
| traffic tunnels to controller&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For KitsNet architecture:&lt;br /&gt;
&lt;br /&gt;
* client traffic should be &#039;&#039;&#039;local-forwarded&#039;&#039;&#039;&lt;br /&gt;
* controller should not carry client traffic&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP Problems ==&lt;br /&gt;
&lt;br /&gt;
If clients connect but cannot obtain an IP address:&lt;br /&gt;
&lt;br /&gt;
Check DHCP leases.&lt;br /&gt;
&lt;br /&gt;
On Courvoisier (Guest network):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/ip dhcp-server lease print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On Radix (main network):&lt;br /&gt;
&lt;br /&gt;
Check LAN DHCP server.&lt;br /&gt;
&lt;br /&gt;
If no leases appear:&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* datapath bridging incorrect&lt;br /&gt;
* VLAN mismatch&lt;br /&gt;
* firewall blocking broadcast&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Signal and RF Issues ==&lt;br /&gt;
&lt;br /&gt;
Check client signal:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man registration-table print stats&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Key metrics:&lt;br /&gt;
&lt;br /&gt;
* signal&lt;br /&gt;
* tx-rate&lt;br /&gt;
* rx-rate&lt;br /&gt;
&lt;br /&gt;
Poor signal can cause authentication failures.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Offline ==&lt;br /&gt;
&lt;br /&gt;
If a CAP disappears entirely:&lt;br /&gt;
&lt;br /&gt;
Check device:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/system resource print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify:&lt;br /&gt;
&lt;br /&gt;
* device powered&lt;br /&gt;
* Ethernet link up&lt;br /&gt;
* bridge port active&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Fast Recovery Commands ==&lt;br /&gt;
&lt;br /&gt;
Force CAP reconnection:&lt;br /&gt;
&lt;br /&gt;
On CAP:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap disable&lt;br /&gt;
/interface wireless cap enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart CAPsMAN:&lt;br /&gt;
&lt;br /&gt;
On controller:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man manager set enabled=no&lt;br /&gt;
/caps-man manager set enabled=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Emergency Fallback ==&lt;br /&gt;
&lt;br /&gt;
If CAPsMAN fails completely, a CAP can run standalone.&lt;br /&gt;
&lt;br /&gt;
On CAP:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap disable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then configure local wireless interfaces.&lt;br /&gt;
&lt;br /&gt;
This restores temporary connectivity until CAPsMAN is repaired.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Monitoring Commands ==&lt;br /&gt;
&lt;br /&gt;
Useful commands during operations:&lt;br /&gt;
&lt;br /&gt;
Controller:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man remote-cap print&lt;br /&gt;
/caps-man interface print&lt;br /&gt;
/caps-man registration-table print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CAP device:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
/interface wireless print&lt;br /&gt;
/log print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Preventative Practices ==&lt;br /&gt;
&lt;br /&gt;
To reduce wireless failures:&lt;br /&gt;
&lt;br /&gt;
* keep RouterOS versions synchronized&lt;br /&gt;
* maintain symmetric CAP provisioning&lt;br /&gt;
* avoid overlapping channels&lt;br /&gt;
* document datapath design&lt;br /&gt;
* test migrations on one CAP first&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Related Documentation ==&lt;br /&gt;
&lt;br /&gt;
* Wireless Architecture&lt;br /&gt;
* CAPsMAN Migration Procedure&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:LAN:absolut:CAPsMAN_Operational_Commands_Cheat_Sheet&amp;diff=2689</id>
		<title>KitsNet Network:LAN:absolut:CAPsMAN Operational Commands Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:LAN:absolut:CAPsMAN_Operational_Commands_Cheat_Sheet&amp;diff=2689"/>
		<updated>2026-09-18T21:37:55Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
This page contains the most commonly used RouterOS commands for operating&lt;br /&gt;
the KitsNet CAPsMAN wireless infrastructure.&lt;br /&gt;
&lt;br /&gt;
Controller: &#039;&#039;&#039;absolut&#039;&#039;&#039;  &lt;br /&gt;
CAP devices: &#039;&#039;&#039;able&#039;&#039;&#039;, &#039;&#039;&#039;baker&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The commands below are intended for quick diagnostics and operational use.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Controller Health ==&lt;br /&gt;
&lt;br /&gt;
Verify CAPsMAN service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man manager print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected:&lt;br /&gt;
&lt;br /&gt;
* enabled: yes&lt;br /&gt;
&lt;br /&gt;
Restart CAPsMAN service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man manager set enabled=no&lt;br /&gt;
/caps-man manager set enabled=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Connectivity ==&lt;br /&gt;
&lt;br /&gt;
List CAP devices connected to the controller:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man remote-cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed view:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man remote-cap print detail&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected:&lt;br /&gt;
&lt;br /&gt;
* able – Run&lt;br /&gt;
* baker – Run&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Radio Interfaces ==&lt;br /&gt;
&lt;br /&gt;
View radios managed by CAPsMAN:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man interface print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Useful fields:&lt;br /&gt;
&lt;br /&gt;
* radio-mac&lt;br /&gt;
* channel&lt;br /&gt;
* configuration&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Client Associations ==&lt;br /&gt;
&lt;br /&gt;
Show connected wireless clients:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man registration-table print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Extended statistics:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man registration-table print stats&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Important metrics:&lt;br /&gt;
&lt;br /&gt;
* signal&lt;br /&gt;
* tx-rate&lt;br /&gt;
* rx-rate&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Provisioning Rules ==&lt;br /&gt;
&lt;br /&gt;
Check provisioning configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man provisioning print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Provisioning determines:&lt;br /&gt;
&lt;br /&gt;
* which SSIDs appear on each radio&lt;br /&gt;
* how CAP radios are configured&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Wireless Configurations ==&lt;br /&gt;
&lt;br /&gt;
List configuration profiles:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man configuration print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Each configuration includes:&lt;br /&gt;
&lt;br /&gt;
* SSID&lt;br /&gt;
* channel&lt;br /&gt;
* security profile&lt;br /&gt;
* datapath&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Datapath Verification ==&lt;br /&gt;
&lt;br /&gt;
View datapaths:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man datapath print detail&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Key field:&lt;br /&gt;
&lt;br /&gt;
* local-forwarding&lt;br /&gt;
&lt;br /&gt;
Interpretation:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Value !! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| yes&lt;br /&gt;
| client traffic stays on CAP&lt;br /&gt;
|-&lt;br /&gt;
| no&lt;br /&gt;
| client traffic tunnels to controller&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For KitsNet architecture:&lt;br /&gt;
&lt;br /&gt;
* traffic should normally be &#039;&#039;&#039;local-forwarded&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Security Profiles ==&lt;br /&gt;
&lt;br /&gt;
List security settings:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man security print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check for:&lt;br /&gt;
&lt;br /&gt;
* WPA2 / WPA3 settings&lt;br /&gt;
* passphrase configuration&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Channel Configuration ==&lt;br /&gt;
&lt;br /&gt;
View channel definitions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man channel print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These define:&lt;br /&gt;
&lt;br /&gt;
* frequency&lt;br /&gt;
* channel width&lt;br /&gt;
* band&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Log Monitoring ==&lt;br /&gt;
&lt;br /&gt;
Look for wireless errors:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/log print where topics~&amp;quot;caps&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Search authentication failures:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/log print where message~&amp;quot;handshake&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Device Commands ==&lt;br /&gt;
&lt;br /&gt;
Run these on &#039;&#039;&#039;able&#039;&#039;&#039; or &#039;&#039;&#039;baker&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Check CAP configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart CAP mode:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap disable&lt;br /&gt;
/interface wireless cap enable&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify wireless interfaces:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== DHCP Verification ==&lt;br /&gt;
&lt;br /&gt;
Main WLAN DHCP (Radix):&lt;br /&gt;
&lt;br /&gt;
Verify clients receive leases from Radix.&lt;br /&gt;
&lt;br /&gt;
Guest WLAN DHCP (Courvoisier):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/ip dhcp-server lease print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== RF Diagnostics ==&lt;br /&gt;
&lt;br /&gt;
Check signal quality:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man registration-table print stats&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Typical signal values:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Signal !! Quality&lt;br /&gt;
|-&lt;br /&gt;
| -40 dBm&lt;br /&gt;
| excellent&lt;br /&gt;
|-&lt;br /&gt;
| -55 dBm&lt;br /&gt;
| very good&lt;br /&gt;
|-&lt;br /&gt;
| -65 dBm&lt;br /&gt;
| acceptable&lt;br /&gt;
|-&lt;br /&gt;
| -75 dBm&lt;br /&gt;
| poor&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== CAP Discovery ==&lt;br /&gt;
&lt;br /&gt;
Verify CAP discovery configuration:&lt;br /&gt;
&lt;br /&gt;
On CAP:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface wireless cap print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check:&lt;br /&gt;
&lt;br /&gt;
* discovery interface&lt;br /&gt;
* caps-man-addresses&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Quick Status Dashboard ==&lt;br /&gt;
&lt;br /&gt;
These commands give a quick operational snapshot.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/caps-man remote-cap print&lt;br /&gt;
/caps-man interface print&lt;br /&gt;
/caps-man registration-table print&lt;br /&gt;
/caps-man datapath print&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Safe Recovery Steps ==&lt;br /&gt;
&lt;br /&gt;
If wireless service fails:&lt;br /&gt;
&lt;br /&gt;
1. Restart CAPsMAN&lt;br /&gt;
2. Restart CAP radios&lt;br /&gt;
3. Verify CAP connectivity&lt;br /&gt;
4. Check DHCP leases&lt;br /&gt;
5. Review logs&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Related Documentation ==&lt;br /&gt;
&lt;br /&gt;
* Wireless Architecture&lt;br /&gt;
* CAPsMAN Migration Procedure&lt;br /&gt;
* CAPsMAN Troubleshooting Guide&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network&amp;diff=2686</id>
		<title>KitsNet Network</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network&amp;diff=2686"/>
		<updated>2026-09-18T21:36:07Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NONUMBERHEADINGS__&lt;br /&gt;
Landing page for Network-related material&lt;br /&gt;
&lt;br /&gt;
===Diagrams===&lt;br /&gt;
&lt;br /&gt;
* [http://wiki.kitsnet.us/instaweb/KitsNet_Network.html Network diagram]&lt;br /&gt;
* [[KitsNet Network:Diagram2]]&lt;br /&gt;
&lt;br /&gt;
===Wide Area Network===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Network:WAN}}&lt;br /&gt;
&lt;br /&gt;
===Local Area Network===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Network:LAN}}&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=File:KitsNet_Network_Diagram.png&amp;diff=2685</id>
		<title>File:KitsNet Network Diagram.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=File:KitsNet_Network_Diagram.png&amp;diff=2685"/>
		<updated>2026-09-18T21:32:54Z</updated>

		<summary type="html">&lt;p&gt;Psmode: DrawioEditor&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:Diagram2&amp;diff=2684</id>
		<title>KitsNet Network:Diagram2</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Network:Diagram2&amp;diff=2684"/>
		<updated>2026-09-18T20:54:19Z</updated>

		<summary type="html">&lt;p&gt;Psmode: Created page with &amp;quot;&amp;lt;drawio filename=&amp;quot;KitsNet Network Diagram&amp;quot; editmode=&amp;quot;inline&amp;quot; alignment=&amp;quot;center&amp;quot; alt=&amp;quot;v2.0&amp;quot; /&amp;gt;&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;drawio filename=&amp;quot;KitsNet Network Diagram&amp;quot; editmode=&amp;quot;inline&amp;quot; alignment=&amp;quot;center&amp;quot; alt=&amp;quot;v2.0&amp;quot; /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Builds:Linux:galliano&amp;diff=2672</id>
		<title>KitsNet Operations:Builds:Linux:galliano</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Builds:Linux:galliano&amp;diff=2672"/>
		<updated>2026-09-18T20:35:22Z</updated>

		<summary type="html">&lt;p&gt;Psmode: (username removed) (log details removed)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[KitsNet Operations:Retired Builds:Linux:galliano]]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations&amp;diff=2663</id>
		<title>KitsNet Operations</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations&amp;diff=2663"/>
		<updated>2026-09-18T20:31:01Z</updated>

		<summary type="html">&lt;p&gt;Psmode: __NONUMBERHEADINGS__ is the correct directive&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NONUMBERHEADINGS__&lt;br /&gt;
=== External Packages ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:External Packages}}&lt;br /&gt;
&lt;br /&gt;
=== System Build Documents ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Builds|hideredirects=yes}}&lt;br /&gt;
&lt;br /&gt;
=== Monitoring the Environment ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Monitoring}}&lt;br /&gt;
&lt;br /&gt;
=== Hardware and Physical Assets ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:HW}}&lt;br /&gt;
&lt;br /&gt;
=== Planning ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Planning}}&lt;br /&gt;
&lt;br /&gt;
=== Retired System Build Documents ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Retired Builds}}&lt;br /&gt;
&lt;br /&gt;
=== Network stuff ===&lt;br /&gt;
[http://wiki.kitsnet.us/instaweb/KitsNet_Network.html Network diagram]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations&amp;diff=2662</id>
		<title>KitsNet Operations</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations&amp;diff=2662"/>
		<updated>2026-09-18T20:29:21Z</updated>

		<summary type="html">&lt;p&gt;Psmode: Added __NONUMBEREDHEADINGS__&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NONUMBEREDHEADINGS__&lt;br /&gt;
=== External Packages ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:External Packages}}&lt;br /&gt;
&lt;br /&gt;
=== System Build Documents ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Builds|hideredirects=yes}}&lt;br /&gt;
&lt;br /&gt;
=== Monitoring the Environment ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Monitoring}}&lt;br /&gt;
&lt;br /&gt;
=== Hardware and Physical Assets ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:HW}}&lt;br /&gt;
&lt;br /&gt;
=== Planning ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Planning}}&lt;br /&gt;
&lt;br /&gt;
=== Retired System Build Documents ===&lt;br /&gt;
{{Special:Prefixindex/KitsNet_Operations:Retired Builds}}&lt;br /&gt;
&lt;br /&gt;
=== Network stuff ===&lt;br /&gt;
[http://wiki.kitsnet.us/instaweb/KitsNet_Network.html Network diagram]&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2661</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2661"/>
		<updated>2026-09-18T20:21:52Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%; max-width:none; margin:0;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:.75rem 1rem; margin:0 0 .8rem 0; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.8rem; font-weight:600; line-height:1.15;&amp;quot;&amp;gt;KitsNet&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin-top:.2rem; color:#4b5563; line-height:1.4;&amp;quot;&amp;gt;&lt;br /&gt;
Architecture, build standards, operations, services, networking, and system records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.7rem; align-items:stretch;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VIRTUALIZATION&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KVM|KVM Infrastructure]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KVM architecture, guest creation, operating procedures, and OS-specific Wort build and change records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;LINUX PLATFORM&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[Linux|Linux]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet Linux standards, the [[Linux:Samba AD Factory|AD Factory]], Samba AD DC builds, AD authentication, Veeam integration, and Linux techniques.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SYSTEM RECORDS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Operations|KitsNet Operations]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Operational procedures plus the detailed build, configuration, maintenance, monitoring, and change record for individual KitsNet systems and VMs.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SERVICE ARCHITECTURE&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Services|KitsNet Services]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Higher-level documentation for KitsNet services: what each service does, how it is structured, and which systems implement it.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;NETWORK&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Network|KitsNet Network]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Routing, switching, addressing, DNS, DHCP, wireless, firewalling, remote access, and network topology.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 290px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VMS / OPENVMS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[VMS|VMS]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet VMS and OpenVMS systems, configuration, operating procedures, and system-specific documentation.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.45rem; margin-top:.8rem; padding:.65rem .75rem; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc; font-size:.92rem;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Linux:Tips and Tricks|&#039;&#039;&#039;Linux Tips &amp;amp;amp; Tricks&#039;&#039;&#039;]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:AllPages|All pages]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:RecentChanges|Recent changes]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Our Home|Our Home]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[https://wiki.kitsnet.us/internet Internet Connectivity Status]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2660</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2660"/>
		<updated>2026-09-18T20:20:50Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%; max-width:none; margin:0;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:.75rem 1rem; margin:0 0 .8rem 0; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.8rem; font-weight:600; line-height:1.15;&amp;quot;&amp;gt;KitsNet&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin-top:.2rem; color:#4b5563; line-height:1.4;&amp;quot;&amp;gt;&lt;br /&gt;
Architecture, build standards, operations, services, networking, and system records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.7rem; align-items:stretch;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VIRTUALIZATION&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KVM|KVM Infrastructure]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KVM architecture, guest creation, operating procedures, and OS-specific Wort build and change records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;LINUX PLATFORM&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[Linux|Linux]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet Linux standards, the [[Linux:Samba AD Factory|AD Factory]], Samba AD DC builds, AD authentication, Veeam integration, and Linux techniques.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SYSTEM RECORDS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Operations|KitsNet Operations]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Operational procedures plus the detailed build, configuration, maintenance, monitoring, and change record for individual KitsNet systems and VMs.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SERVICE ARCHITECTURE&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Services|KitsNet Services]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Higher-level documentation for KitsNet services: what each service does, how it is structured, and which systems implement it.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;NETWORK&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Network|KitsNet Network]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Routing, switching, addressing, DNS, DHCP, wireless, firewalling, remote access, and network topology.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VMS / OPENVMS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[VMS|VMS]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet VMS and OpenVMS systems, configuration, operating procedures, and system-specific documentation.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.45rem; margin-top:.8rem; padding:.65rem .75rem; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc; font-size:.92rem;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Linux:Tips and Tricks|&#039;&#039;&#039;Linux Tips &amp;amp;amp; Tricks&#039;&#039;&#039;]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:AllPages|All pages]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:RecentChanges|Recent changes]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Our Home|Our Home]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[https://wiki.kitsnet.us/internet Internet Connectivity Status]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2659</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=Main_Page&amp;diff=2659"/>
		<updated>2026-09-18T20:18:43Z</updated>

		<summary type="html">&lt;p&gt;Psmode: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;max-width:1080px; margin:0 auto;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:.75rem 1rem; margin:0 0 .8rem 0; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.8rem; font-weight:600; line-height:1.15;&amp;quot;&amp;gt;KitsNet&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;margin-top:.2rem; color:#4b5563; line-height:1.4;&amp;quot;&amp;gt;&lt;br /&gt;
Architecture, build standards, operations, services, networking, and system records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.7rem; align-items:stretch;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VIRTUALIZATION&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KVM|KVM Infrastructure]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KVM architecture, guest creation, operating procedures, and OS-specific Wort build and change records.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;LINUX PLATFORM&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[Linux|Linux]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet Linux standards, the [[Linux:Samba AD Factory|AD Factory]], Samba AD DC builds, AD authentication, Veeam integration, and Linux techniques.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SYSTEM RECORDS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Operations|KitsNet Operations]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Operational procedures plus the detailed build, configuration, maintenance, monitoring, and change record for individual KitsNet systems and VMs.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;SERVICE ARCHITECTURE&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Services|KitsNet Services]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Higher-level documentation for KitsNet services: what each service does, how it is structured, and which systems implement it.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;NETWORK&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[KitsNet Network|KitsNet Network]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
Routing, switching, addressing, DNS, DHCP, wireless, firewalling, remote access, and network topology.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;flex:1 1 250px; border:1px solid #d8dee9; border-radius:8px; padding:.8rem .9rem; background:#fff;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:.72rem; letter-spacing:.07em; color:#64748b; font-weight:700;&amp;quot;&amp;gt;VMS / OPENVMS&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:1.18rem; font-weight:600; margin:.15rem 0 .3rem 0;&amp;quot;&amp;gt;[[VMS|VMS]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;line-height:1.4; color:#374151;&amp;quot;&amp;gt;&lt;br /&gt;
KitsNet VMS and OpenVMS systems, configuration, operating procedures, and system-specific documentation.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;display:flex; flex-wrap:wrap; gap:.45rem; margin-top:.8rem; padding:.65rem .75rem; border:1px solid #d8dee9; border-radius:8px; background:#f8fafc; font-size:.92rem;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Linux:Tips and Tricks|&#039;&#039;&#039;Linux Tips &amp;amp;amp; Tricks&#039;&#039;&#039;]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:AllPages|All pages]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Special:RecentChanges|Recent changes]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[[Our Home|Our Home]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;color:#9ca3af;&amp;quot;&amp;gt;•&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;white-space:nowrap;&amp;quot;&amp;gt;[https://wiki.kitsnet.us/internet Internet Connectivity Status]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
	<entry>
		<id>https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Planning:Projects&amp;diff=2600</id>
		<title>KitsNet Operations:Planning:Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.kitsnet.us/w/index.php?title=KitsNet_Operations:Planning:Projects&amp;diff=2600"/>
		<updated>2026-09-16T20:26:57Z</updated>

		<summary type="html">&lt;p&gt;Psmode: Internal IPv6 done&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable sortable col-1-center col-7-center col-8-center col-9-center&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Priority Tier&lt;br /&gt;
!New Server&lt;br /&gt;
!Based on&lt;br /&gt;
!Activity&lt;br /&gt;
!Imperatives&lt;br /&gt;
!Notes&lt;br /&gt;
!Target Quarter&lt;br /&gt;
!Actual Start&lt;br /&gt;
!Actual End&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|1&lt;br /&gt;
|N/A&lt;br /&gt;
|[[KVM:host:Wort Operations|Wort]]&lt;br /&gt;
|Upgrade to RL 9&lt;br /&gt;
|&lt;br /&gt;
* Hypervisor at RL 9 could improve guest RL 9 performance&lt;br /&gt;
* Hypervisor gets all patches&lt;br /&gt;
|&lt;br /&gt;
* MegaRAID disks not discoverable by Zabbix-Aget2 due to known bug in old version. Cannot upgrade agent until Zabbix server is upgraded.&lt;br /&gt;
|24q4.1&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|9&lt;br /&gt;
|N/A&lt;br /&gt;
|[[KVM:host:Wort Operations|Wort]]&lt;br /&gt;
|CPU upgrade to 5800X&lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
*Swap 3600X to Kaliber OR&lt;br /&gt;
*&amp;lt;s&amp;gt;Take Lafite&#039;s CPU after upgrading it with [https://www.amazon.com/AMD-Ryzen-5700X3D-16-Thread-Processor/dp/B0CQ4H4H7X/ref=asc_df_B0CQ4H4H7X/?tag=hyprod-20&amp;amp;linkCode=df0&amp;amp;hvadid=691748717271&amp;amp;hvpos=&amp;amp;hvnetw=g&amp;amp;hvrand=7035893699707595636&amp;amp;hvpone=&amp;amp;hvptwo=&amp;amp;hvqmt=&amp;amp;hvdev=c&amp;amp;hvdvcmdl=&amp;amp;hvlocint=&amp;amp;hvlocphy=9073502&amp;amp;hvtargid=pla-2275433404761&amp;amp;psc=1&amp;amp;mcid=4551c53272fc349e92b6c0640e115a34&amp;amp;gad_source=4 5800X3D]&amp;lt;/s&amp;gt;&lt;br /&gt;
|24q4.9&lt;br /&gt;
|24q4&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|4&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:zaya|Zaya]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:zoco|Zoco]]&lt;br /&gt;
|Upgrade to RL 9&lt;br /&gt;
and [https://www.zabbix.com/roadmap Zabbix 7.0 LTS]&lt;br /&gt;
|&lt;br /&gt;
* Planned release date for Zabbix 7.4 is 2025q2&lt;br /&gt;
* Planned release date for Zabbix 8.0 LTS is 2025q4&lt;br /&gt;
*See Get Zabbix at https://www.zabbix.com/download?zabbix=7.0&amp;amp;os_distribution=rocky_linux&amp;amp;os_version=9&amp;amp;components=server_frontend_agent&amp;amp;db=mysql&amp;amp;ws=apache&lt;br /&gt;
*See Zabbix upgrade procedures at https://www.zabbix.com/documentation/current/en/manual/installation/upgrade&lt;br /&gt;
|&lt;br /&gt;
|25q2.1&lt;br /&gt;
|25.q1&lt;br /&gt;
|25.q2&lt;br /&gt;
|-&lt;br /&gt;
|5&lt;br /&gt;
|Zuidam&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:zaya|Zaya]]&lt;br /&gt;
|Upgrade to RL 10&lt;br /&gt;
and [https://www.zabbix.com/roadmap Zabbix 8.0 LTS]&lt;br /&gt;
|&lt;br /&gt;
*[https://www.zabbix.com/life_cycle_and_release_policy Zabbix Life Cycle and Release Policy]&lt;br /&gt;
**Planned release date for Zabbix 8.0 LTS is 2026q3&lt;br /&gt;
* See Zabbix upgrade procedures at https://www.zabbix.com/documentation/current/en/manual/installation/upgrade&lt;br /&gt;
|&lt;br /&gt;
|26q3.1&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|9&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:delamain|Delamain]]&lt;br /&gt;
|[[KitsNet Operations:Retired Builds:Linux:quadsec|Quadsec]]&lt;br /&gt;
|Upgrade to RL 10&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
*vnstat and glances not yet available&lt;br /&gt;
*installed v7 zabbix-agent2 from rehl 9 release&lt;br /&gt;
|25q3.2&lt;br /&gt;
|25q2&lt;br /&gt;
|25q2 &lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:barcardi|Barcardi]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:hendrick|Hendrick]]&lt;br /&gt;
|Upgrade to RL 9&lt;br /&gt;
|&lt;br /&gt;
*Samba Factory should be on RL 9 to build Samba for RL9 systems&lt;br /&gt;
|&lt;br /&gt;
|24q4.2&lt;br /&gt;
|24q3&lt;br /&gt;
|24q4 &lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:galliano|Galliano]]&lt;br /&gt;
|[[KitsNet Operations:Retired Builds:Linux:chivas|Chivas]]&lt;br /&gt;
|Upgrade to RL 9 and MediaWiki 1.39.12 LTS&lt;br /&gt;
|&lt;br /&gt;
*MediaWiki 1.35 LTS became end-of-life 21 December 2023.&lt;br /&gt;
*See https://www.mediawiki.org/wiki/Manual:Moving_a_wiki&lt;br /&gt;
|&lt;br /&gt;
|25q1.2&lt;br /&gt;
|25q1&lt;br /&gt;
|25q2&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:frangelico|Frangelico]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:camus|Camus]]&lt;br /&gt;
|Upgrade to RL 9 &lt;br /&gt;
|&lt;br /&gt;
*After Hendrick. At same time as Cristal&lt;br /&gt;
|Samba upgrade entirely separate, though work included installing a slightly higher version of Samba and joining to the doman.&lt;br /&gt;
|24q4.2&lt;br /&gt;
|24q3&lt;br /&gt;
|24q4 &lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:emperador|Emperador]]&lt;br /&gt;
|[[KitsNet Operations:Retired Builds:Linux:cristal|Cristal]]&lt;br /&gt;
|Upgrade to RL 9&lt;br /&gt;
|&lt;br /&gt;
*After Hendrick. At same time as Camus&lt;br /&gt;
|Samba upgrade entirely separate&lt;br /&gt;
|24q4.2&lt;br /&gt;
|24q3&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:frangelico|Frangelico]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:camus|Camus]]&lt;br /&gt;
|Upgrade to latest Samba&lt;br /&gt;
|&lt;br /&gt;
*&amp;lt;s&amp;gt;Fix Mac password changing issue (hopefully)&amp;lt;/s&amp;gt;&lt;br /&gt;
|*Need to create Protected Users security group (https://www.samba.org/samba/history/samba-4.17.0.html)&lt;br /&gt;
*Fucntional level (https://www.samba.org/samba/history/samba-4.20.0.html and https://wiki.samba.org/index.php/AD_Schema_Version_Support)&amp;lt;syntaxhighlight lang=&amp;quot;shell-session&amp;quot;&amp;gt;&lt;br /&gt;
To raise the domain functional level of an existing domain, after&lt;br /&gt;
updating the smb.conf and restarting Samba run&lt;br /&gt;
samba-tool domain schemaupgrade --schema=2019&lt;br /&gt;
samba-tool domain functionalprep --function-level=2016&lt;br /&gt;
samba-tool domain level raise --domain-level=2016 --forest-level=2016&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
|25q1.2&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:emperador|Emperador]]&lt;br /&gt;
|[[KitsNet Operations:Retired Builds:Linux:cristal|Cristal]]&lt;br /&gt;
|Upgrade to latest Samba&lt;br /&gt;
|&lt;br /&gt;
*&amp;lt;s&amp;gt;Fix Mac password changing issue (hopefully)&amp;lt;/s&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|25q1.2&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1 &lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:cinzano|Cinzano]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:ballantine|Ballantine]]&lt;br /&gt;
|Upgrade to RL 9 and eFa 5.0&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|25q1.3&lt;br /&gt;
|25q1&lt;br /&gt;
|25q2&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:tito|Tito]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:campari|Campari]]&lt;br /&gt;
|Upgrade to RL 9 and latest Samba&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
* SSO access is via Samba itself, including automatic directory creation&lt;br /&gt;
|25q2.3&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:hennessy|Hennessy]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:martell|Martell]]&lt;br /&gt;
|Upgrade to RL 9 and latest Samba&lt;br /&gt;
|&lt;br /&gt;
*Frequent error messages regarding chdir actions appear with execution of Windows backup operations. Supposed to be addressed with newer Samba version.&lt;br /&gt;
|&lt;br /&gt;
*Setup as an AD member server along with NFS exports&lt;br /&gt;
*VM NIC needs be built over kvm-bkup bridge&lt;br /&gt;
|25q2.3&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:sinfire|Sinfire]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:fireball|Fireball]]&lt;br /&gt;
|Upgrade to RL 9 and latest Samba&lt;br /&gt;
|&lt;br /&gt;
|Did get Emby upgrade as well&lt;br /&gt;
|25q2.3&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|4&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:empress|Empress]]&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:okeefe|Okeefe]]&lt;br /&gt;
|Upgrade to RL 10&lt;br /&gt;
|&lt;br /&gt;
|ConsoleWorks server v5.6-4u0 does not really support Rocky LInux 10. Some hacking of TDI scripts was required. &lt;br /&gt;
| 25q2,z&lt;br /&gt;
| 25q2&lt;br /&gt;
| 25q2&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|4&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:maddog|Maddog]]&lt;br /&gt;
|[[KitsNet Operations:Retired Builds:Linux:ripple|ripple]]&lt;br /&gt;
|Upgrade to RL 9 &lt;br /&gt;
|&lt;br /&gt;
|simh build/run server for VAX&lt;br /&gt;
|25q2.4&lt;br /&gt;
|25q2&lt;br /&gt;
|25q2&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|&lt;br /&gt;
| [[KitsNet Network:WAN:radix|Radix]]&lt;br /&gt;
| Upgrade to OpenWrt 24.10 stable version &lt;br /&gt;
|&lt;br /&gt;
*Currently OpenWrt 22.03.05 stable version&lt;br /&gt;
|Updated to 24.1.2&lt;br /&gt;
|25q4.2&lt;br /&gt;
|25q3&lt;br /&gt;
|25q4&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|9&lt;br /&gt;
|&lt;br /&gt;
|DONQ&lt;br /&gt;
|&amp;lt;s&amp;gt;decommission AlphaServer&amp;lt;/s&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
*VSI shutdown hobbyist program for Alpha and HP licenses won&#039;t run on VSI OpenVMS for Alpha&lt;br /&gt;
|&amp;lt;s&amp;gt;Could consider VAX-only VAXcluster&amp;lt;/s&amp;gt;&lt;br /&gt;
Dealt with license issue&lt;br /&gt;
|24q4.z&lt;br /&gt;
|24q4&lt;br /&gt;
|24q4&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|6&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|Establish docker farm&lt;br /&gt;
|&lt;br /&gt;
*Could recast most servers as Docker containers&lt;br /&gt;
|ChatGPT design and deployment plan built&lt;br /&gt;
|26q1.6&lt;br /&gt;
|26q1&lt;br /&gt;
|26q3&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|5&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:fox|fox]]&lt;br /&gt;
[[KitsNet Operations:Builds:Linux:anchor|anchor]]&lt;br /&gt;
|&lt;br /&gt;
|HA NAS storage for Docker farm&lt;br /&gt;
|&lt;br /&gt;
* Needed as portable HA storage solution for container instances&lt;br /&gt;
|ChatGPT design and deployment plan built based on one set of vdisks on KVM host being presented by one of two NFS servers with coordinated failover. This will support continuous availability so as to support server maintenance operations, without doubling storage requirements. &lt;br /&gt;
|26q1.5&lt;br /&gt;
|26q1&lt;br /&gt;
|26q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|3&lt;br /&gt;
|&lt;br /&gt;
|[[KVM:host:Wort Operations|Wort]]&lt;br /&gt;
|Storage expansion&lt;br /&gt;
|&lt;br /&gt;
* Only about 1 TB remains available and Docker farm will need at least that much&lt;br /&gt;
* T0 pool is too small at 512MB as most has been used&lt;br /&gt;
|&lt;br /&gt;
* &amp;lt;s&amp;gt;Expansion of T0 to 2TB NVMe likely to cost about $170 with Samsung 990 EVO Plus 2TB .&amp;lt;/s&amp;gt; T0 expansion cancelled due to drive cost explosion&lt;br /&gt;
&lt;br /&gt;
* T1 expansion will aim for a matched pair of 4TB Seagate Seagate Iron Wolf Pro drives&lt;br /&gt;
* T3 expansion used surplut WD Red Pro&lt;br /&gt;
|26q1.3&lt;br /&gt;
|26q1&lt;br /&gt;
|26q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
|[[KVM:host:Wort Operations|Wort]]&lt;br /&gt;
|Storage expansion cabinet&lt;br /&gt;
|&lt;br /&gt;
* Current plans call for using up all available drive slots but one &lt;br /&gt;
* Design accounted for cabinet based on Jonsbo N4 - need to buy this before product is retired&lt;br /&gt;
* Could only implement single SAS link between cabinets due to available port shortage in main cabinet&lt;br /&gt;
|Current wort will need added:&lt;br /&gt;
&lt;br /&gt;
* Dual Mini SAS SFF-8088 to SAS36P SFF-8087 Adapter in PCI Bracket&lt;br /&gt;
* SFF-8087 to SFF-8087 internal SAS cables (2)&lt;br /&gt;
&lt;br /&gt;
External cables&lt;br /&gt;
&lt;br /&gt;
* SFF-8088 to SFF-8088 external SAS cables (2)&lt;br /&gt;
&lt;br /&gt;
The new cabinet will be the Jonsbo N4 outfitted with:&lt;br /&gt;
&lt;br /&gt;
* Dual Mini SAS SFF-8088 to SAS36P SFF-8087 Adapter in PCI Bracket&lt;br /&gt;
* Mini SAS to 4 SATA Cable, 36 Pin SFF 8087 Host/Controller to 7 Pin SATA Target/Backplane connection&lt;br /&gt;
* modest power supply&lt;br /&gt;
|26q2.4&lt;br /&gt;
|26q1&lt;br /&gt;
|26q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|1&lt;br /&gt;
|Lafite&lt;br /&gt;
|Lafite&lt;br /&gt;
|Windows 11 &lt;br /&gt;
|&lt;br /&gt;
*Windows 10 EOL October 2025&lt;br /&gt;
|Need to upgrade before Kaliber so I can support Mandy&lt;br /&gt;
|24q2.1&lt;br /&gt;
|24q4&lt;br /&gt;
|24q4&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|N/A&lt;br /&gt;
|Kaliber&lt;br /&gt;
|Windows 11&lt;br /&gt;
|&lt;br /&gt;
*Windows 10 EOL October 2025&lt;br /&gt;
|Upgrade storage to 1TB NVMe prior to upgrade&lt;br /&gt;
Profiles hosted off of C: drive blocked upgrade&lt;br /&gt;
Still need to reinstall RGB utilities&lt;br /&gt;
|25q2.2&lt;br /&gt;
|25q1&lt;br /&gt;
|25q3&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|N/A&lt;br /&gt;
|Sriracha &lt;br /&gt;
|Windows 11&lt;br /&gt;
|&lt;br /&gt;
*Windows 10 EOL October 2025&lt;br /&gt;
|Might move this up or down&lt;br /&gt;
|25q2.2&lt;br /&gt;
|25q4&lt;br /&gt;
|25q4&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|1&lt;br /&gt;
|N/A&lt;br /&gt;
|[[KVM:host:Wort Operations|Wort]]&lt;br /&gt;
|New chasis&lt;br /&gt;
|&lt;br /&gt;
*new case will allow for 12 drives without need for second case&lt;br /&gt;
|&lt;br /&gt;
*Jonsbo n5 chasis&lt;br /&gt;
*RAID expander card&lt;br /&gt;
*For T3b volume  &lt;br /&gt;
**add fourth disk&lt;br /&gt;
**&amp;lt;s&amp;gt;convert Raid 5 to RAID 10&amp;lt;/s&amp;gt;&lt;br /&gt;
*Cannot start unitl n5 case delivered. Scheduled for 3rd week of January 2025&lt;br /&gt;
|25q1.1&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|1&lt;br /&gt;
| N/A&lt;br /&gt;
|Lafite&lt;br /&gt;
|Replumb loop&lt;br /&gt;
|&lt;br /&gt;
* add drain port and reroute piping for better circulation through reservoir&lt;br /&gt;
|&lt;br /&gt;
|24q4.1&lt;br /&gt;
|25q1&lt;br /&gt;
|25q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|Absolut&lt;br /&gt;
|&lt;br /&gt;
|Standalone CAPSMAN&lt;br /&gt;
|&lt;br /&gt;
*Will allow for removal of the Wireless package from Courvoisier and free up storage space&lt;br /&gt;
*Upcoming RouterOS updates my not fit without this relief&lt;br /&gt;
|New deployment plan developed with ChatGPT&lt;br /&gt;
| 26q1.2&lt;br /&gt;
|25q3&lt;br /&gt;
|26q1&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|5&lt;br /&gt;
|[[KitsNet Network:WAN:radix|Radix]]&lt;br /&gt;
|&lt;br /&gt;
|Tailscale VPN &lt;br /&gt;
|&lt;br /&gt;
* Supported VPN solution for full remote access. Improvement over SSH and will allow devices full KitsNet access remotely.&lt;br /&gt;
|&lt;br /&gt;
|26q2.5&lt;br /&gt;
|26q3&lt;br /&gt;
|26q3&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|4&lt;br /&gt;
|&lt;br /&gt;
|[[KitsNet Network:WAN:radix|Radix]]&lt;br /&gt;
|Internal IPv6 support&lt;br /&gt;
| &lt;br /&gt;
*The LAN simply uses automatic configuration at Layer 2. Before we can implement external support for IPv6, IPv6 on the LAN needs to be cleaned up and fully implemented.&lt;br /&gt;
|Need to setup a full internal support of IPv6 router announcements, explicit DHCP support of the ULA and delegated prefix, DUID (???) and more. This will also include implementation of RA Guard to block the Apple TV and HomePod Mini to advertising themselves as IPv6 routers. I have a deployment design and a multi-stage implementation plan supplied by ChatGPT.&lt;br /&gt;
|26q1.4&lt;br /&gt;
|26q3&lt;br /&gt;
|26q3&lt;br /&gt;
|-&lt;br /&gt;
|5&lt;br /&gt;
|&lt;br /&gt;
|[[KitsNet Network:WAN:radix|Radix]]&lt;br /&gt;
|External IPv6 support&lt;br /&gt;
|&lt;br /&gt;
*Implement NAT66 and DDNS updates so that KitsNet services may be addressed vi IPV4 or IPv6.&lt;br /&gt;
|Dependant upon Internal IPv6 support&lt;br /&gt;
|26q2.5&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|- style=&amp;quot;background: #90ee90;&amp;quot; |&lt;br /&gt;
|2&lt;br /&gt;
|[[KitsNet Operations:Builds:Linux:cinzano|Cinzano]]&lt;br /&gt;
|&lt;br /&gt;
|Migrate from eFa-Project to Promox Mail Gateway&lt;br /&gt;
|&lt;br /&gt;
*eFa-Project went end of life in 2025. Maintainer has shut it down&lt;br /&gt;
*[https://www.proxmox.com/en/products/proxmox-mail-gateway/overview Promox Mail Gateway] is closest to a drop-in replacement&lt;br /&gt;
*will deploy as Debian VM appliance&lt;br /&gt;
|&lt;br /&gt;
|26q2.2&lt;br /&gt;
|26q2&lt;br /&gt;
|26q3&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Psmode</name></author>
	</entry>
</feed>