SUSE Family

openSUSE Leap, SUSE Enterprise Linux Server (SLES), SLES Micro

openSUSE Leap as a daily workstation

openSUSE Leap as a daily workstation

First initial tweaks

hostname

hostname --set-hostname <hostname>

disable IPv6 stack

adjust GRUB timeoute

NTP client config

DNS resolver config

repositories check

Install additional utilities

zypper install \
    tmux \
    htop \
    ncdu \
    traceroute \
    tcpdump \
    

Install KDE GDE

zypper install -t pattern kde_plasma
zypper install -t pattern kde_plasma kde_apps
systemctl set-default graphical.target
openSUSE Leap as a daily workstation

Nextcloud Desktop on @openSUSE v16

Install

zypper install nextcloud-desktop
openSUSE Leap as a daily workstation

KeePassXC @openSUSE v16

Install

zypper install keepassxc
openSUSE Leap as a daily workstation

Browser FireFox and extensions

Install

zypper install MozillaFirefox

Extensions

- KeePassXC by KeePassXC Team
    https://addons.mozilla.org/en-US/firefox/addon/keepassxc-browser/

- uBlock Origin by Raymond Hill
    https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/

- DownThemAll! by Nils Maier
    https://addons.mozilla.org/en-US/firefox/addon/downthemall/

- Fifefox Multi-Account Containers by Firefox
    https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/

- SAML Tracer

- FoxyProxy
openSUSE Leap as a daily workstation

Mail client Thunderbird and extensions

Install

zypper install \
    MozillaThunderbird \
    MozillaThunderbird-openpgp-librnp

Extensions

- aa
    https://

openSUSE Leap as a daily workstation

Disable unnecessary services for openSUSE

ant1mba2 (MacBookAir5,1)

systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon
systemctl disable --now switcheroo-control.service
systemctl disable --now pcscd.service
systemctl disable --now pcscd.socket

systemctl disable --now packagekit.service
systemctl mask packagekit

# Thunderbolt 1
systemctl disable --now bolt
systemctl mask bolt

# not neede LibreOffice packages
zypper remove \
    libreoffice-pyuno \
    libreoffice-math \
    libreoffice-impress \
    libreoffice-base \
    libreoffice-draw

# does it worth to remove ?
   -18.6 MiB  |  -   18.6 MiB  released by packages that will be removed

ant1lt580 (Lenovo T580)

systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon

zypper remove discover6-notifier

zypper addlock discover6-notifier

dxb2lib1 (thin)

systemctl disable --now ModemManager.service
systemctl disable --now avahi-daemon


zypper remove discover6-notifier

zypper addlock discover6-notifier
openSUSE Leap as a daily workstation

User pass change (break the glass)

On boot, stop the GRUB loader pressing E

image.png

add to the end of the line, where linux is declared

image.png

    init=/bin/bash

press CTRL+X or F10 to boot

Mount, set simple password and remember it, touch file to make SElinux happy, sync, remount and initiate clean reboot.

image.png

actually not like this, but

mount -o remount,rw /
passwd <user>

# option 1
restorecon -v /etc/shadow

# option 2
setfattr -n security.selinux -v system_u:object_r:shadow_t:s0 /etc/shadow
getfattr -n security.selinux /etc/shadow

sync
mount -o remount,ro /

/usr/sbin/reboot -f

Once system is loaded, login and set complex password

image.png

Idea behind simple and complex passwords is that usually simple pass need to be typed (in hypervisor terminal/console) manually.

Once there is access over SSH, complex password can be generated and pasted from password manager.

SLES v15 minor version upgrade

(not in order)

Install tmux AND launch it

sudo su
SUSEConnect -p PackageHub/15.6/x86_64

zypper install tmux

exit

tmux

Upate update tools

zypper patch --updatestack-only

Upgrade of minor versions (SP = Service Packs) are sequential, i.e. :

Check for registered/known products. Should not contain any duplicates.

ls -latr /etc/products.d/

Unregister and register (to forget previous products)

export regcode="aaaaaaaaaaaa"

SUSEConnect --de-register
registercloudguest --clean
SUSEConnect --clean

SUSEConnect \
    --regcode ${regcode} \
    -p SLES/15.6/x86_64

Enable services needed for upgrade (of installed packeges)

suseconnect -p sle-module-basesystem/15.6/x86_64
SUSEConnect -p sle-module-containers/15.6/x86_64
SUSEConnect -p sle-module-server-applications/15.6/x86_64
SUSEConnect -p sle-module-public-cloud/15.6/x86_64
SUSEConnect -p sle-module-python3/15.6/x86_64
SUSEConnect -p sle-module-systems-management/15.6/x86_64
SUSEConnect -p PackageHub/15.6/x86_64

confirm update

Replace version

# export releasever="15-SP6"
export releasever="15-SP7"


# sed -i 's/15-SP5/15-SP6/g' /etc/zypp/repos.d/*.repo
# sed -i 's/15_SP5/15_SP6/g' /etc/zypp/repos.d/*.repo

sed -i 's/15-SP6/15-SP7/g' /etc/zypp/repos.d/*.repo
sed -i 's/15_SP6/15_SP7/g' /etc/zypp/repos.d/*.repo

fgrep -irn ${releasever} /etc/zypp/repos.d/*.repo

Swtich and refresh

# export releasever="15-SP6"
export releasever="15-SP7"
zypper --releasever=${releasever} refresh -f -s

Dist Upgrade

# export releasever="15-SP6"
export releasever="15-SP7"

zypper \
    --verbose \
    dist-upgrade \
    --releasever=${releasever} \
    --no-allow-vendor-change \
    --no-recommends \
    --download-only

zypper \
    --verbose \
    --releasever=${releasever} \
    dist-upgrade \
    --no-allow-vendor-change \
    --no-recommends \

issue:(leave obsolute 'docker' package)

 Solution 1: install docker-buildx-0.29.0-150000.238.1.x86_64 from vendor SUSE LLC <https://www.suse.com/>

Verify

zypper --releasever=${releasever} repos -u

Refresh

export releasever="15-SP7"
zypper --releasever=${releasever} refresh -f -s

Error

'Containers Module 15 SP5 x86_64,
Desktop Applications Module 15 SP5 x86_64,
Development Tools Module 15 SP5 x86_64,
Public Cloud Module 15 SP5 x86_64'

Activate

suseconnect -p sle-module-containers/15.6/x86_64
suseconnect -p sle-module-development-tools/15.6/x86_64
suseconnect -p sle-module-public-cloud/15.6/x86_64
zypper services -u

remove service

zypper removeservice

zypper \
    --releasever=15-SP6 \
    dist-upgrade \
    --no-allow-vendor-change \
    --no-recommends \
    --download-in-heaps

zypper \
    --releasever=${releasever} \
    dist-upgrade \
    --no-allow-vendor-change \
    --no-recommends \
    --download-in-heaps

Verify

hostnamectl

Register machine again

SUSEConnect -r ${regcode}

Refresh

zypper --releasever=${releasever} refresh -f -s

Clean old one, once confident

ls -la /etc/zypp/repos.d/*15_SP6*
rm -rf /etc/zypp/repos.d/*15_SP6*


ls -la /etc/zypp/repos.d/*15_SP5*
rm -rf /etc/zypp/repos.d/*15_SP5*

Update

zypper update

more