SUSE Family
openSUSE Leap, SUSE Enterprise Linux Server (SLES), SLES Micro
- openSUSE Leap as a daily workstation
- First initial tweaks
- Nextcloud Desktop on @openSUSE v16
- KeePassXC @openSUSE v16
- Browser FireFox and extensions
- Mail client Thunderbird and extensions
- Disable unnecessary services for openSUSE
- User pass change (break the glass)
- SLES v15 minor version upgrade
openSUSE Leap as a daily workstation
First initial tweaks
hostname
hostname --set-hostname <hostname>
disable IPv6 stack
adjust GRUB timeoute
NTP client config
DNS resolver config
repositories check
Install additional utilities
zypper install \
tmux \
htop \
ncdu \
traceroute \
tcpdump \
Install KDE GDE
zypper install -t pattern kde_plasma
zypper install -t pattern kde_plasma kde_apps
systemctl set-default graphical.target
Nextcloud Desktop on @openSUSE v16
Install
zypper install nextcloud-desktop
KeePassXC @openSUSE v16
Install
zypper install keepassxc
Browser FireFox and extensions
Install
zypper install MozillaFirefox
Extensions
- KeePassXC by KeePassXC Team
https://addons.mozilla.org/en-US/firefox/addon/keepassxc-browser/
- uBlock Origin by Raymond Hill
https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/
- DownThemAll! by Nils Maier
https://addons.mozilla.org/en-US/firefox/addon/downthemall/
- Fifefox Multi-Account Containers by Firefox
https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/
- SAML Tracer
- FoxyProxy
Mail client Thunderbird and extensions
Install
zypper install \
MozillaThunderbird \
MozillaThunderbird-openpgp-librnp
Extensions
- aa
https://
Disable unnecessary services for openSUSE
ant1mba2 (MacBookAir5,1)
systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon
systemctl disable --now switcheroo-control.service
systemctl disable --now pcscd.service
systemctl disable --now pcscd.socket
systemctl disable --now packagekit.service
systemctl mask packagekit
# Thunderbolt 1
systemctl disable --now bolt
systemctl mask bolt
# not neede LibreOffice packages
zypper remove \
libreoffice-pyuno \
libreoffice-math \
libreoffice-impress \
libreoffice-base \
libreoffice-draw
# does it worth to remove ?
-18.6 MiB | - 18.6 MiB released by packages that will be removed
ant1lt580 (Lenovo T580)
systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon
zypper remove discover6-notifier
zypper addlock discover6-notifier
dxb2lib1 (thin)
systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon
zypper remove discover6-notifier
zypper addlock discover6-notifier
User pass change (break the glass)
On boot, stop the GRUB loader pressing E
add to the end of the line, where linux is declared
init=/bin/bash
press CTRL+X or F10 to boot
Mount, set simple password and remember it, touch file to make SElinux happy, sync, remount and initiate clean reboot.
actually not like this, but
mount -o remount,rw /
passwd <user>
# option 1
restorecon -v /etc/shadow
# option 2
setfattr -n security.selinux -v system_u:object_r:shadow_t:s0 /etc/shadow
getfattr -n security.selinux /etc/shadow
sync
mount -o remount,ro /
/usr/sbin/reboot -f
Once system is loaded, login and set complex password
Idea behind simple and complex passwords is that usually simple pass need to be typed (in hypervisor terminal/console) manually.
Once there is access over SSH, complex password can be generated and pasted from password manager.
SLES v15 minor version upgrade
(not in order)
Install tmux AND launch it
sudo su
SUSEConnect -p PackageHub/15.6/x86_64
zypper install tmux
exit
tmux
Upate update tools
zypper patch --updatestack-only
Upgrade of minor versions (SP = Service Packs) are sequential, i.e. :
- v15.5--15.6
- v15.6--15.7
Check for registered/known products. Should not contain any duplicates.
ls -latr /etc/products.d/
Unregister and register (to forget previous products)
export regcode="aaaaaaaaaaaa"
SUSEConnect --de-register
registercloudguest --clean
SUSEConnect --clean
SUSEConnect \
--regcode ${regcode} \
-p SLES/15.6/x86_64
Enable services needed for upgrade (of installed packeges)
suseconnect -p sle-module-basesystem/15.6/x86_64
SUSEConnect -p sle-module-containers/15.6/x86_64
SUSEConnect -p sle-module-server-applications/15.6/x86_64
SUSEConnect -p sle-module-public-cloud/15.6/x86_64
SUSEConnect -p sle-module-python3/15.6/x86_64
SUSEConnect -p sle-module-systems-management/15.6/x86_64
SUSEConnect -p PackageHub/15.6/x86_64
Replace version
# export releasever="15-SP6"
export releasever="15-SP7"
# sed -i 's/15-SP5/15-SP6/g' /etc/zypp/repos.d/*.repo
# sed -i 's/15_SP5/15_SP6/g' /etc/zypp/repos.d/*.repo
sed -i 's/15-SP6/15-SP7/g' /etc/zypp/repos.d/*.repo
sed -i 's/15_SP6/15_SP7/g' /etc/zypp/repos.d/*.repo
fgrep -irn ${releasever} /etc/zypp/repos.d/*.repo
Swtich and refresh
# export releasever="15-SP6"
export releasever="15-SP7"
zypper --releasever=${releasever} refresh -f -s
Dist Upgrade
# export releasever="15-SP6"
export releasever="15-SP7"
zypper \
--verbose \
dist-upgrade \
--releasever=${releasever} \
--no-allow-vendor-change \
--no-recommends \
--download-only
zypper \
--verbose \
--releasever=${releasever} \
dist-upgrade \
--no-allow-vendor-change \
--no-recommends \
issue:(leave obsolute 'docker' package)
Solution 1: install docker-buildx-0.29.0-150000.238.1.x86_64 from vendor SUSE LLC <https://www.suse.com/>
Verify
zypper --releasever=${releasever} repos -u
Refresh
export releasever="15-SP7"
zypper --releasever=${releasever} refresh -f -s
Error
'Containers Module 15 SP5 x86_64,
Desktop Applications Module 15 SP5 x86_64,
Development Tools Module 15 SP5 x86_64,
Public Cloud Module 15 SP5 x86_64'
Activate
suseconnect -p sle-module-containers/15.6/x86_64
suseconnect -p sle-module-development-tools/15.6/x86_64
suseconnect -p sle-module-public-cloud/15.6/x86_64
zypper services -u
remove service
zypper removeservice
zypper \
--releasever=15-SP6 \
dist-upgrade \
--no-allow-vendor-change \
--no-recommends \
--download-in-heaps
zypper \
--releasever=${releasever} \
dist-upgrade \
--no-allow-vendor-change \
--no-recommends \
--download-in-heaps
Verify
hostnamectl
Register machine again
SUSEConnect -r ${regcode}
Refresh
zypper --releasever=${releasever} refresh -f -s
Clean old one, once confident
ls -la /etc/zypp/repos.d/*15_SP6*
rm -rf /etc/zypp/repos.d/*15_SP6*
ls -la /etc/zypp/repos.d/*15_SP5*
rm -rf /etc/zypp/repos.d/*15_SP5*
Update
zypper update