- Manage system services using systemctl (start, stop, enable, disable, mask, unmask).
- Analyze boot time performance using systemd-analyze.
- Filter and inspect system logs using journalctl.
# Service Control & Boot Analysis
systemctl status httpd
systemctl start httpd
systemctl enable httpd
systemctl is-enabled httpd
systemctl is-active httpd
systemd-analyze blame
# Log Filtering (RHCSA Core)
journalctl -u sshd
journalctl -b
journalctl -p err
- Create Physical Volumes (PV), Volume Groups (VG), and Logical Volumes (LV).
- Format LVs with ext4 and configure persistent mounting via /etc/fstab.
- Perform Live Expansion (lvextend).
- Clean up LVM components safely.
# 1. Physical & Volume Group Creation
pvcreate /dev/nvme0n2
vgcreate test-vg /dev/nvme0n2
# 2. Logical Volume Creation & Formatting
lvcreate -L 2G -n test-lv test-vg
mkfs.ext4 /dev/test-vg/test-lv
mkdir /test-data
mount /dev/test-vg/test-lv /test-data
# 3. Expansion & Full Cleanup
lvextend -L 4G -r /dev/test-vg/test-lv
umount -l /test-data
lvremove -f /dev/test-vg/test-lv
vgremove test-vg
pvremove /dev/nvme0n2- Perform local user account creation, group assignment, and password management.
- Manage group creation, renaming, and deletion.
- Configure directory ownership, special permissions (SGID), and ACLs.
- User Management & Primary Group Assignment:
Created user1 with a home directory, verified its identity, created a primary group Security, and set the user's password.
sudo useradd -m user1 ls /home id user1 sudo groupadd Security sudo usermod -g Security user1 id user1 sudo passwd user1
- Group Operations: Demonstrated group creation, renaming (DevOps to Sec), and deleting redundant groups.
sudo groupadd DevOps
sudo groupmod -n Sec DevOps
sudo groupdel Sec
- Directory Ownership & SGID Configuration: Created /data/project, assigned group ownership to devops, and applied the SGID bit (2770) so new files inherit the group identity.
sudo mkdir -p /data/project
sudo chown -R root:devops /data/project
sudo chmod 2770 /data/project- Access Control Lists (ACL): Configured granular read and execute permissions (r-x) for otheruser using setfacl.
sudo setfacl -m u:otheruser:rx /data/project
getfacl /data/project- Master package search and detailed inspection using dnf.
- Install and verify packages (such as nginx) on RHEL.
- Identify package providers for specific configuration files using dnf provides.
- Remove packages safely using the dnf package manager.
dnf search nginx
dnf info nginx
dnf provides /etc/nginx/nginx.conf sudo dnf install -y nginxdnf list installed | grep nginxsudo dnf remove -y nginx- Hostname: mohamed-server
- OS: Red Hat Enterprise Linux 10.0 (Coughlan)
- Kernel: Linux 6.12.0-55.9.1.el10_0.x86_64
- Hypervisor: VMware, Inc.
- Interface Name: ens160
- IP Address: 192.168.1.100/24
- Subnet Mask: 255.255.255.0
- Broadcast Address: 192.168.1.255
- MAC Address: 00:0c:29:27:b1:2a
sudo nmcli con mod ens160 ipv4.addresses 192.168.1.100/24 ipv4.method manual
sudo nmcli con up ens160Timezone Set: Africa/Algiers (Set via timedatectl) Time Daemon: chronyd installed and enabled via systemctl. NTP Verification: Verified active time synchronization using chronyc sources -v and chronyc tracking.
sudo firewall-cmd --add-service=ntp --permanent
sudo firewall-cmd --reload
sudo firewall-cmd --list-servicesThis repository contains a step-by-step practical implementation for configuring a custom web server directory and non-standard HTTP port on Red Hat Enterprise Linux (RHEL) using SELinux policy management tools.
-Set up a custom document root directory (/web/secure). -Reconfigure Apache (httpd) to run on a non-standard port (8282). -Apply persistent SELinux file context rules and network port labeling. -Enable user home directory web access via SELinux Booleans.
mkdir -p /web/secure
echo "RHCSA TEST PAGE" > /web/secure/index.htmlsemanage fcontext -a -t httpd_sys_content_t "/web/secure(/.*)?"
restorecon -Rv /web/secureChange Listen 80 to Listen 8282. Update DocumentRoot and block to /web/secure.
semanage port -a -t http_port_t -p tcp 8282
setsebool -P httpd_enable_homedirs on
systemctl restart httpd
curl http://localhost:8282
Invalid Port Type Error: When executing semanage port, use http_port_t instead of httpd_port_t. File Context Application: Remember to execute restorecon after semanage fcontext to apply context labeling to existing files on disk.
-Manage active zone configurations (public). -Allow standard web services (http) and non-standard custom ports (8282/tcp). -Implement Firewalld Rich Rules for conditional traffic control based on source IP addresses. -Persist and apply runtime firewall updates.
firewall-cmd --add-service=http --permanent
firewall-cmd --add-port=8282/tcp --permanent
firewall-cmd --add-rich-rule='rule family="ipv4" source address="10.0.0.5" service name="http" drop' --permanent
irewall-cmd --add-rich-rule='rule family="ipv4" source address="192.168.1.55" service name="ssh" drop' --permanent
firewall-cmd --add-rich-rule='rule family="ipv4" source address="192.168.1.55" service name="ssh" accept' --permanent
firewall-cmd --reload
firewall-cmd --list-all
firewall-cmd --list-rich-rules
sudo dd if=/dev/zero of=/swapfile bs=1M count=1024
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
swapon --showsudo nano /etc/fstab
# add the line:
/swapfile none swap defaults 0 0sudo swapoff -v /swapfile
sudo rm /swapfile
sudo nano /etc/fstab # remove the /swapfile lineThis lab demonstrates the deployment and configuration of Virtual Data Optimizer (VDO) via LVM on Red Hat Enterprise Linux 10 (RHEL 10). VDO provides inline data reduction through Zero-block Elimination, Deduplication, and Compression, optimizing storage utilization for enterprise workloads.
- OS: Red Hat Enterprise Linux 10 (RHEL 10)
- Physical Target Disk: /dev/nvme0n2 (10 GB)
- Volume Group (VG): vg-vdo
- Logical Volume (LV): lv-vdo
- Physical LV Allocation (-L): 5 GB
- Virtual LV Provisioning (-V): Filesystem:ystem:** ext4
- Mount Point: /data/vdo-storage
Initialize the physical volume and create the dedicated LVM volume group on the NVMe drive:
pvcreate /dev/nvme0n2
vgcreate vg-vdo /dev/nvme0n2Step 2: Native LVM VDO Provisioning Provision a VDO-enabled logical volume using LVM native Integration (--type vdo). A 20GB virtual volume is presented to the system backed by 5GB of physical allocation:
vcreate --type vdo -n lv-vdo -L 5G -V 20G vg-vdo
Step 3: Filesystem Formatting & Mount Setup Format the VDO logical volume with the ext4 filesystem and prepare the mount directory:
mkfs.ext4 /dev/vg-vdo/lv-vdo
mkdir -p /data/vdo-storage
Step 4: Persistent Mounting Configuration Configure /etc/fstab for persistent mounting across system reboots:
/dev/vg-vdo/lv-vdo /data/vdo-storage ext4 defaults 0 0
Apply systemd re-configuration and mount the volume:
systemctl daemon-reload
mount -a
📊 Verification & Status Monitoring Check Filesystem Usage Verify that the operating system reports the 20GB virtual capacity at /data/vdo-storage:
df -h /data/vdo-storage
Verify VDO Deduplication & Compression Metrics Inspect VDO pool operational statistics and space saving raèèètio:
vdostats --human-readable



































/1.png)
/2.png)
/3.png)
/4.png)