[{"content":"If you set up HTTPS once and forgot about it, that era is over. Certificate lifetimes are being cut in stages, domain checks are getting stricter, and Let\u0026#8217;s Encrypt is moving even faster than the industry deadline. Here\u0026#8217;s what\u0026#8217;s changing, when, and what to do about it.\nCertificate lifetimes are shrinking In April 2025 the CA/Browser Forum, the group that sets the rules for publicly trusted certificates, passed Ballot SC-081v3. It cuts the maximum lifetime of a TLS certificate in three steps:\nIssued on or afterMaximum lifetimeBefore March 15, 2026398 daysMarch 15, 2026 (already in effect)200 daysMarch 15, 2027100 daysMarch 15, 202947 days The same ballot also limits how long a certificate authority can reuse your proof of domain ownership. By 2029 that drops to just 10 days, so your domain will be re-validated at almost every renewal. Renewing by hand, or validating by email, stops being practical. Automation becomes the only realistic option.\nLet\u0026#8217;s Encrypt is ahead of schedule Let\u0026#8217;s Encrypt announced its own timeline to move from 90-day to 45-day certificates:\nMay 13, 2026: the opt-in tlsserver profile started issuing 45-day certificates. February 10, 2027: the default profile switches to 64-day certificates, with domain validation reused for only 10 days. February 16, 2028: the default profile moves to 45-day certificates, with validation reused for only 7 hours. If you want to go further, six-day certificates (160 hours) are already generally available through the shortlived profile.\nOther changes you may have missed OCSP is gone at Let\u0026#8217;s Encrypt. OCSP URLs were removed from certificates on May 7, 2025 and the OCSP servers were shut down on August 6, 2025. Revocation is now published only through CRLs, so remove any OCSP Must-Staple settings. New root certificates. On May 13, 2026, Let\u0026#8217;s Encrypt began issuing from its new \u0026#8220;Generation Y\u0026#8221; roots. They\u0026#8217;re cross-signed by the older roots, so most sites won\u0026#8217;t notice, unless you\u0026#8217;ve pinned a specific intermediate certificate. No more client authentication certificates. Let\u0026#8217;s Encrypt certificates no longer support client authentication. If you used them for mutual TLS (mTLS), you need another solution. What to do now Automate renewals. Use an ACME client such as Certbot or acme.sh, or your host\u0026#8217;s built-in tool, and stop renewing by hand. Use a client that supports ARI (ACME Renewal Information), so it knows exactly when to renew. Remove pinned intermediates and any OCSP Must-Staple configuration. Test a renewal on a staging server before the next deadline. Monitor the result, because automation fails too. Automation isn\u0026#8217;t enough on its own Auto-renewal fails quietly more often than people think. A DNS change, a server move, or a web server that got the new certificate but was never reloaded, and nothing tells you. With certificates lasting weeks instead of a year, a silent failure turns into a browser warning fast.\nThat\u0026#8217;s why I built CertAvert (full disclosure: it\u0026#8217;s my project). It checks your certificate from the outside, the same way a visitor\u0026#8217;s browser does. There\u0026#8217;s nothing to install and no server access needed: you sign up, type your domain, and it emails you before the certificate expires. The dashboard also flags certificates browsers won\u0026#8217;t trust, such as a hostname mismatch or a missing intermediate.\nThe free plan monitors up to 3 domains with no time limit and no card needed. Not ready to sign up? Run a one-off check with the free SSL checker and see when your certificate expires right now.\nCheck your certificate free Start monitoring free By 2029, certificates will need renewing roughly eight times a year instead of once. Automate the renewals, then monitor them, so you find out before your visitors do.\n","keywords":["ssl","certificate","lifetime"],"permalink":"https://techtutelage.net/ssl-certificate-lifetime-changes-2029/","summary":"SSL certificate lifetimes drop to 200, 100 and then 47 days by 2029, and Let’s Encrypt moves to 45 days. What changes when, and how to stay ahead.","title":"SSL Certificates Are Expiring Faster: Every Change Through 2029"},{"content":"SSL certificate problems are easy to miss and painful when they happen. A single expired or misconfigured certificate can cause browser warnings, failed connections, and loss of trust.\nThe problem isn’t that certificates are hard — it’s that they’re easy to forget.\nWhy SSL Certificates Fail in Practice Most certificate issues happen for simple reasons:\nCertificates expire quietly Low-traffic or old domains are forgotten Certificates are replaced but not fully updated Hostnames don’t match the certificate These issues usually show up after users are affected.\nWhat Should Be Monitored To avoid surprises, certificate monitoring should check:\nWhen a certificate expires Whether browsers trust it Whether the hostname matches the certificate Expiration alone is not enough.\nA Simple Way to Stay Ahead of Problems Instead of tracking dates manually, certificates can be checked automatically.\nA monitoring tool can connect to a domain, read the active SSL certificate, detect expiration or common errors, and alert you before users notice anything.\nThis works especially well for domains you don’t look at every day.\nThe Tool I Use: CertAvert I built CertAvert to keep certificate checks simple and automatic.\nCertAvert monitors SSL/TLS certificates, alerts before certificates expire, detects issues like hostname mismatches and untrusted certificates, and shows domain status in a clear dashboard.\nThe free plan includes monitoring for up to 3 domains.\nWhen This Is Useful This approach is useful if you:\nManage several domains Have older or low-traffic sites Want alerts instead of manual checks Prefer simple tools over complex monitoring systems Final Thoughts SSL certificate failures are preventable if they’re monitored consistently. Automated checks remove guesswork and reduce the chance of unexpected outages.\nIf you want a simple way to monitor certificates, you can find CertAvert at: https://certavert.com\n","keywords":["ssl","certificate","monitoring"],"permalink":"https://techtutelage.net/avoiding-ssl-certificate-problems-before-they-break-your-site/","summary":"Why SSL certificates fail (expiry, revocation, hostname mismatch) and how to monitor them automatically so they never break your site or your users’ trust.","title":"Avoiding SSL Certificate Problems Before They Break Your Site"},{"content":" If you\u0026#8217;re looking for a simple way to set up a WireGuard VPN, wireguard-manager is a great tool. It\u0026#8217;s a shell-based script that helps you install, configure, and manage WireGuard on Linux.\nWhy Use wireguard-manager? Quick setup Minimal dependencies Supports server and client management Works on most Debian-based Linux (Debian, Ubuntu, etc.) Features Install WireGuard with a single script Add and remove clients easily Generate QR codes for mobile setup Auto-start WireGuard on boot Getting Started Clone the repo: git clone https://github.com/techtute/wireguard-manager.git cd wireguard-manager 2. Run the wireguard-manager script:\nbash wireguard-manager.sh 3. Follow the menu prompts to install and manage your VPN.\nVideo Guide Check out this video for a step-by-step guide on using the script to build a VPN server on AWS:\nConclusion If you want a no-fuss VPN setup, this tool gets the job done fast. Try it out from the GitHub repo and follow the video to get started on AWS.\n","keywords":["wireguard","manager"],"permalink":"https://techtutelage.net/easy-vpn-setup-with-wireguard-manager/","summary":"Set up a WireGuard VPN in minutes with wireguard-manager, a free script for Debian and Ubuntu: install, add or remove clients and generate mobile QR codes.","title":"Easy VPN Setup with WireGuard Manager"},{"content":"Welcome to my OpenStack Beginners Guide series! If you\u0026#8217;re looking to dive into cloud computing, this series is designed to help you every step of the way. From setting up your environment to launching and managing instances, I\u0026#8217;ve got you covered.\nEach episode focuses on a crucial part of the OpenStack journey. Follow along and build your own cloud infrastructure with ease. Be sure to check out the videos linked below for in-depth tutorials.\nEpisode 1: Installing VirtualBox and Ubuntu Server The first step in your OpenStack journey is setting up a proper environment. In this episode, I guide you through installing VirtualBox and Ubuntu Server, which will serve as the foundation for your OpenStack setup.\nWhat You\u0026#8217;ll Learn:\nHow to install VirtualBox Setting up Ubuntu Server as a virtual machine Preparing your system for OpenStack installation Episode 2: Installing OpenStack and Launching an Instance Now that we have our environment ready, it\u0026#8217;s time to install OpenStack! In this episode, we go step by step through the installation process and launch our very first instance.\nKey Highlights:\nInstalling OpenStack on Ubuntu Server Understanding OpenStack services Launching and accessing your first instance Episode 3: Configuring Basic Networking for SSH \u0026amp; Internet Access Networking is crucial in OpenStack, and this episode will show you how to set up networking to ensure smooth SSH access and internet connectivity for your instances.\nTopics Covered:\nSetting up private and public networking Configuring Floating IPs for external access Enabling SSH from any computer on your local network Episode 4: Obtain \u0026amp; Upload an OpenStack Compatible Image + SSH with Key Pair Not all images work with OpenStack by default, so in this episode, we explore how to obtain an OpenStack-compatible image, upload it, and launch an instance using SSH key pairs.\nKey Takeaways:\nWhere to find OpenStack-compatible images Uploading an image to OpenStack Using key pairs for secure SSH access Episode 5: OpenStack Command Line (CLI) Essentials Graphical interfaces are great, but mastering the OpenStack CLI gives you more flexibility and control. In this episode, I cover essential CLI commands and tips for efficiently navigating OpenStack’s command-line interface.\nWhat You\u0026#8217;ll Learn:\nSetting up OpenStack CLI on your system Running basic OpenStack commands Finding useful CLI commands quickly Final Thoughts This OpenStack Beginners Guide series is designed to help you get comfortable with cloud computing. Whether you\u0026#8217;re a beginner or just looking to sharpen your skills, these videos provide hands-on learning to set up and manage your OpenStack environment.\nDon\u0026#8217;t forget to subscribe to my YouTube channel to stay updated on new tutorials! If you have any questions or want me to cover specific topics, drop a comment on the videos. Happy learning!\n","keywords":["openstack","tutorial","for","beginners"],"permalink":"https://techtutelage.net/mastering-openstack-a-beginners-guide-video-series/","summary":"A 5-part OpenStack video series for beginners: install it on Ubuntu in VirtualBox, launch instances, set up networking and SSH, upload images, use the CLI.","title":"Mastering OpenStack: A Beginner’s Guide Video Series"},{"content":"In Linux, navigating the file system is an essential skill. A key concept to master is the difference between relative and absolute paths. These paths determine how you specify the location of files and directories in your system. Let’s break it down with clear explanations and examples to help you get started.\nWhat is a Path? A path is the route or address used to locate files and directories in the file system. There are two types of paths in Linux:\nAbsolute Path Relative Path 1. Absolute Path An absolute path specifies the location of a file or directory starting from the root directory (/). It always begins with a / and provides the complete location, regardless of the current working directory.\nKey Points: Starts from the root (/) of the file system. Always points to the same location, no matter where you are in the directory structure. Example: Assume the file notes.txt is located in /home/user/documents/.\nEven if you\u0026#8217;re in another directory, this path will always point to the same file.\nAbsolute path: /home/user/documents/notes.txt Command to access the file: cat /home/user/documents/notes.txt 2. Relative Path A relative path specifies the location of a file or directory relative to the current working directory. It does not begin with a / and depends on where you are in the file system. One crucial command to keep in mind is pwd (Print Working Directory), which shows your current location in the directory hierarchy. Knowing your current directory is essential when working with paths, especially relative ones, as it determines how you reference files and directories. Use pwd frequently to stay oriented in the file system and avoid errors caused by assuming you\u0026#8217;re in the wrong location.\nKey Points: Does not start with /. Relative to the current directory. Use pwd command often to stay oriented in the file system. Special Notations: .: Refers to the current directory. ..: Refers to the parent directory. Example: Assume you are in /home/user/ and want to access notes.txt in /home/user/documents/.\nRelative path: documents/notes.txt Command to access the file: cat documents/notes.txt If you move to /home/user/documents/ and run the same command, you\u0026#8217;ll need to adjust the relative path:\ncat notes.txt Absolute vs. Relative Path Comparison FeatureAbsolute PathRelative PathStarts FromRoot directory (/)Current directory (pwd)UsageAlways consistentDepends on current locationExample/home/user/file.txt../file.txt Common Use Cases Navigating with cd: Absolute Path: cd /home/user/documents Relative Path: cd documents Copying Files with cp: Absolute Path: cp /home/user/file.txt /tmp/ Relative Path: cp file.txt ../backup/ When to Use Absolute vs. Relative Paths Absolute Paths:\nUse when you need a fixed reference, such as in scripts or when working from various directories. Relative Paths:\nUse for convenience when working interactively and navigating within a known directory structure. Final Thoughts Understanding the difference between relative and absolute paths is fundamental to navigating and managing files in Linux. Practice using both, and you’ll quickly become efficient at finding your way through the file system.\nHave any tips or examples for working with Linux paths? Share them in the comments below!\n","keywords":["relative","vs","absolute","path","linux"],"permalink":"https://techtutelage.net/getting-started-with-linux-understanding-relative-and-absolute-paths/","summary":"Understand absolute and relative paths in Linux with clear examples: what /, ., .. and ~ mean, how to use them with cd and cp, and when to use each one.","title":"Getting Started with Linux: Understanding Relative and Absolute Paths"},{"content":"The Linux command line, often referred to as the shell or terminal, is a powerful tool for interacting with your system. While it might seem intimidating at first, mastering a few basic commands can unlock a world of possibilities. Whether you\u0026#8217;re a beginner or just need a refresher, here are 10 essential Linux commands to get started.\n1. ls \u0026#8211; List Directory Contents The ls command shows the files and directories in the current location.\nBasic Use: ls Detailed View: ls -l Include Hidden Files: ls -a Combine Flags: ls -la 2. cd \u0026#8211; Change Directory Navigate through the file system with cd.\nMove to a Directory: cd folder_name Go Back One Step: cd .. Return to Home Directory: cd 3. pwd \u0026#8211; Print Working Directory Displays your current directory location in the file system.\nUsage: pwd 4. mkdir \u0026#8211; Make a Directory Create new folders with mkdir.\nBasic Use: mkdir folder_name 5. rm \u0026#8211; Remove Files or Directories Delete files or folders (use with caution!).\nRemove File: rm file_name Remove Directory: rm -r folder_name 6. cp \u0026#8211; Copy Files or Directories Duplicate files or folders with cp.\nCopy File: cp source_file target_file Copy Folder: cp -r source_folder target_folder 7. mv \u0026#8211; Move or Rename Files Use mv to move files or rename them.\nMove File: mv file_name /target_directory Rename File: mv old_name new_name 8. cat \u0026#8211; View File Contents Quickly display the contents of a file.\nUsage: cat file_name 9. sudo \u0026#8211; Execute Commands as Root Run commands with administrative privileges.\nUsage: sudo command 10. man \u0026#8211; Manual Pages Learn more about any command by using man.\nView Help for ls: man ls Bonus Tips Tab Completion: Start typing a command or file name and press Tab to auto-complete. Arrow Keys: Use the up/down arrow keys to scroll through previous commands. clear: Use ctrl + l or type clear to clean up your terminal screen. Final Thoughts These 10 commands are just the tip of the iceberg, but they provide a strong foundation for navigating the Linux command line. Practice them regularly, and you\u0026#8217;ll soon feel more comfortable working in this versatile environment.\nWhat Linux commands have you found most helpful? Share your experiences below!\n","keywords":["basic","linux","commands"],"permalink":"https://techtutelage.net/getting-started-with-linux-command-line-10-commands-everyone-must-know/","summary":"New to the Linux command line? Learn the 10 essential commands (ls, cd, pwd, mkdir, rm, cp, mv, cat, sudo and man) with simple examples and bonus tips.","title":"Getting Started with Linux Command Line: 10 Commands Everyone Must Know"},{"content":" Installing Virt-Manager on macOS can be challenging. While Linux users enjoy a straightforward setup, macOS users face a series of challenges that can turn a simple installation into a marathon of configuration and troubleshooting. But don’t worry – there\u0026#8217;s a workaround that’s surprisingly easy and doesn’t require you to wrestle with macOS’s limited support for Virt-Manager. Instead, we can run Virt-Manager remotely on a Linux server and use X11Forwarding to access the graphical interface on a Mac or Windows PC.\nLet’s explore why setting up Virt-Manager on macOS is so tricky, how the workaround works, and what you need to get started.\nWhy Installing Virt-Manager on macOS Is Difficult Virt-Manager, the popular GUI for managing virtual machines, is built to work with Linux systems and the QEMU/KVM hypervisor, both of which are tightly integrated into Linux environments. While tools like Homebrew make it possible to install a variety of Linux software on macOS, Virt-Manager poses unique challenges due to its heavy reliance on Linux-specific dependencies, system calls, and virtualization requirements that aren’t natively supported in macOS.\nFor most users, these technical hurdles make Virt-Manager on macOS impractical. However, the solution below allows you to avoid these obstacles altogether.\nThe Workaround: Run Virt-Manager from a Linux Server with X11Forwarding Rather than installing Virt-Manager directly on your Mac, you can set up a Linux server with QEMU/KVM and access Virt-Manager remotely using X11 Forwarding. This way, the Linux server handles all the virtual machine operations, and you just access the graphical interface from your Mac or Windows computer. Here’s an overview of how it works:\nSet Up a Linux Server: Start with a Linux server configured with QEMU/KVM and Virt-Manager. This can be an actual physical server or a virtual private server (VPS). Install XQuartz on macOS (or an X11-compatible program for Windows): XQuartz is an X11 server for macOS that enables graphical applications running on other systems to display on your Mac. For Windows, you’ll need an X11 substitute like Xming. Use SSH with X11 Forwarding: By connecting to the Linux server over SSH with X11 Forwarding enabled, you can open Virt-Manager on the remote server and have its interface display on your Mac. Run Virt-Manager Remotely: Once you’re connected with X11 Forwarding, you’ll be able to manage virtual machines seamlessly as though you were on the Linux machine itself. If this sounds appealing, check out my step-by-step video tutorial.\n","keywords":["virt-manager","macos"],"permalink":"https://techtutelage.net/how-to-run-virt-manager-on-macos-or-windows/","summary":"Virt-Manager doesn’t run natively on macOS. The easy workaround: run it on a Linux server and display it on your Mac or Windows PC with X11 forwarding.","title":"How to Run Virt-Manager on macOS (or Windows)"},{"content":" When working with text files on Mac and Linux, the \u0026#8220;grep\u0026#8221; command is your go-to tool for finding specific strings of text. Whether you\u0026#8217;re searching through logs, configuration files, or code, grep makes it easy to locate exactly what you\u0026#8217;re looking for. Here’s a quick guide to using grep effectively.\n1. Basic Search To search for a specific term in a file, the basic grep command looks like this:\ngrep \"search_term\" filename This command scans through filename and returns all lines containing \"search_term\".\n2. Case-Insensitive Search By default, grep is case-sensitive, which means \"Search_term\" and \"search_term\" would be treated as different strings. If you want to ignore case differences, add the -i flag:\ngrep -i \"search_term\" filename With this option, \"search_term\", \"Search_term\", and \"SEARCH_TERM\" will all match.\n3. Searching Multiple Files If you need to search for a term across multiple files at once, you can list the files separated by spaces:\ngrep \"search_term\" file1 file2 grep will display matches from both file1 and file2, making it easy to see where the term appears across different files.\n4. Recursive Search in Directories Sometimes, you need to search through an entire directory of files. The -r option allows you to search recursively:\ngrep -r \"search_term\" /path/to/directory This command will search through all files in the specified directory and its subdirectories, returning any matches it finds.\n5. Displaying Line Numbers To see exactly where in the file your search term appears, you can use the -n option to include line numbers in the output:\ngrep -n \"search_term\" filename This is especially useful when you\u0026#8217;re dealing with large files and want to quickly jump to the relevant section.\n6. Searching for Whole Words If you want to search for a whole word and avoid partial matches (e.g., finding \"the\" but not \"there\"), use the -w option:\ngrep -w \"word\" filename This ensures that grep only matches complete words.\n7. Excluding Matches Sometimes, you might want to find lines that don\u0026#8217;t contain a specific term. For that, use the -v option:\ngrep -v \"search_term\" filename This command returns all lines in filename that do not include \"search_term\".\n8. Combining Options for Powerful Searches You can combine multiple grep options to refine your search even further. For example, to perform a case-insensitive search for a whole word and include line numbers, you would use:\ngrep -iwn \"search_term\" filename This command searches for the whole word \"search_term\", ignores case, and shows line numbers for each match.\n9. Piping Log Output to grep One of the most powerful uses of grep is to filter output from other commands. For instance, if you want to search through the output of a log file as it’s being generated, you can use the tail command in combination with grep:\nLinux:\ntail -f /var/log/syslog | grep \"error\" Mac:\nlog stream | grep \"error\" This command continuously monitors the /var/log/syslog file and pipes the output to grep, which filters it to show only lines containing \"error\".\nConclusion The grep command is an incredibly versatile tool in your Linux toolkit. Whether you\u0026#8217;re doing simple searches, combining multiple options for more complex queries, or piping output from other commands, grep can help you find the information you need quickly and efficiently. With these tips, you\u0026#8217;ll be able to leverage grep for a wide range of tasks, making your workflow smoother and more productive.\nHave any tips or examples for using the grep command in Linux? Share them in the comments below!\n","keywords":["grep","command"],"permalink":"https://techtutelage.net/mastering-grep-a-quick-guide-to-searching-text-in-files/","summary":"Learn grep with practical examples: case-insensitive, recursive and whole-word searches, line numbers, excluding matches and filtering logs on Linux and Mac.","title":"Mastering grep: A Quick Guide to Searching Text in Files on macOS and Linux"},{"content":" If you’ve ever tried to SSH into your Linux cloud instance only to be met with the dreaded Permission Denied (publickey) error, you know how frustrating it can be. But don’t worry—if you’re seeing this error, you’re in the right place. I’m going to show you how to regain access to your instance, step by step. And for those who prefer a visual guide, check out the linked YouTube video where we demonstrate this on an Oracle Cloud Ubuntu instance.\nStep 1: Setting Up a Temporary Instance First, create a new temporary Linux instance in the same region and availability domain as your locked instance. This temporary instance will be your recovery tool, helping you access and fix the issue with your original instance.\nStep 2: Detaching and Reattaching the Boot Volume Once your temporary instance is ready, head to your cloud provider’s console. Locate the boot volume of your locked instance—the disk that contains all your system files. Detach this boot volume from the locked instance. Think of this like disconnecting a drive from a computer that you no longer have access to.\nNow, attach the detached boot volume to your temporary instance, allowing you to access and modify its contents. Make sure to attach it in read/write mode, so you can make the necessary changes.\nStep 3: Accessing the Disk After attaching the boot volume, SSH into the temporary instance using a valid key. With access to the temporary instance, you\u0026#8217;ll mount the disk, which allows you to browse its contents just like you would with a drive on your computer.\nNavigate to the directory where the SSH keys are stored. This is the critical part where you’ll fix the key issue.\nStep 4: Replacing the SSH Key Once inside the right folder, you’ll find the file that holds the old, non-functional public key. Open this file and replace the old key with your new, working public key. Save your changes—this step is akin to updating a password to regain access.\nStep 5: Reattaching the Boot Volume to the Original Instance With the new key in place, unmount the disk from the temporary instance. Then, return to your cloud provider’s console, detach the boot volume from the temporary instance, and reattach it to your original locked instance. This is like reconnecting the drive to the computer that was previously inaccessible.\nStep 6: Rebooting and Logging In Finally, reboot your original instance. Now, with the updated key, you should be able to SSH into your instance without encountering the Permission Denied (publickey) error.\nEncountering the Permission Denied (publickey) error doesn’t mean all is lost. By following these steps, you can quickly regain access to your Linux instance. For a detailed visual walkthrough, check out my YouTube video.\n","keywords":["lost","ssh","key","cloud","instance"],"permalink":"https://techtutelage.net/how-to-recover-a-linux-cloud-instance-with-a-lost-or-corrupted-ssh-key/","summary":"Locked out with ‘Permission denied (publickey)’? Recover your Linux cloud instance by attaching its boot volume to a temp server and replacing the SSH key.","title":"How to Recover a Linux Cloud Instance with a Lost or Corrupted SSH Key"},{"content":" Keeping your Minecraft Bedrock server updated is crucial for performance and security, but managing updates can be a hassle. That\u0026#8217;s why I’ve developed a Bedrock Server Auto-Update Script designed to complement my Bedrock Server Install Script. This tool automates the update process, saving you time and effort.\nKey Features Automatic Detection and Easy Selection The script scans your file system to find existing Bedrock server installations. If multiple installations are found, a user-friendly selection menu allows you to choose the correct directory. If only one installation is detected, the script proceeds directly with the update. Effortless Updates After confirming your choice, the script retrieves the latest Bedrock server version from the official source. It compares this version with your current one. If an update is necessary, it automatically downloads and installs the new version. Backup and Restore To ensure safety, the script creates a backup of your current server directory before applying the update. This allows you to restore your previous setup if needed. Seamless Update Execution The script stops your server, applies the update, and then restores important configuration files. Once the update is complete, it restarts the server, minimizing downtime and ensuring everything is running smoothly. Integration with Install Script This Auto-Update Script works seamlessly with my Bedrock Server Install Script. While the install script sets up your server initially, the auto-update script keeps it up-to-date with the latest features and security patches, offering a comprehensive solution for server management. Get Started To streamline your Bedrock server management, visit my GitHub repository for both the Bedrock Server Install Script and the Auto-Update Script. Follow the provided instructions to set up and maintain your server effortlessly.\nExplore the Bedrock Auto-Update Script on GitHub\nWith these tools, you can keep your Minecraft Bedrock server in top shape with minimal effort and maximum efficiency. Enjoy automated updates and spend more time enjoying your game!\n","keywords":["minecraft","bedrock","server","auto","update"],"permalink":"https://techtutelage.net/minecraft-bedrock-server-maintenance-auto-update/","summary":"Keep your Minecraft Bedrock server up to date automatically. This free script finds your install, backs it up, checks for the latest version and updates it.","title":"Minecraft Bedrock Server Auto-Update Script"},{"content":"Matrix is an open, decentralized chat protocol, and Synapse is its reference server. These are the commands from the video, in order: install Docker, generate the Synapse configuration, enable TLS and registration, start the server, and create an admin user.\nWARNING: Please note that this guide is a summary of the commands used in the video tutorial. It's not a step-by-step tutorial itself. For detailed instructions, please refer to the video tutorial. Install Docker Add Docker\u0026#8217;s official GPG key:\napt-get update apt-get install ca-certificates curl install -m 0755 -d /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc chmod a+r /etc/apt/keyrings/docker.asc Add Docker repository to apt sources:\necho \\ \"deb \u0026#91;arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \\ $(. /etc/os-release \u0026amp;\u0026amp; echo \"$VERSION_CODENAME\") stable\" | \\ tee /etc/apt/sources.list.d/docker.list \u003e /dev/null apt-get update Install Docker and other required packages:\napt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose docker-compose-plugin nano Install Matrix with Docker Create docker-compose.yml\nnano docker-compose.yml Paste the lines below in the docker-compose.yml\nversion: '3' services: matrix: image: matrixdotorg/synapse:latest ports: - \"8008:8008\" - \"8448:8448\" volumes: - ./data:/data environment: - SYNAPSE_SERVER_NAME=\u0026lt;REPLACE.WITH.YOUR_DOMAIN_NAME\u003e - SYNAPSE_REPORT_STATS=no restart: always Generate Matrix container configuration\ndocker-compose run --rm matrix generate Edit the homeserver.yml file in data directory and add the following configuration for TLS and registration:\n- port: 8448 tls: true type: http x_forwarded: true resources: - names: \u0026#91;client, federation] compress: false tls_certificate_path: \"/data/cert.pem\" tls_private_key_path: \"/data/key.pem\" enable_registration: true enable_registration_without_verification: true Upload your SSL/TLS key and full chain files to data directory and change permissions so your container has rights to access the two files. Start your Matrix server:\ndocker-compose up -d Useful Commands Create admin user:\nregister_new_matrix_user -c /data/homeserver.yaml Restart Matrix container:\ndocker-compose restart matrix Access your container CLI:\ndocker exec -it \u0026lt;container_id\u003e /bin/bash ","keywords":["matrix","synapse","docker"],"permalink":"https://techtutelage.net/how-to-set-up-matrix-synapse-server-with-docker/","summary":"Commands to self-host a Matrix Synapse chat server: install Docker, deploy Synapse with Docker Compose and create users. Follow along with the video.","title":"How to Set Up Matrix/Synapse Server with Docker"},{"content":" Java is a widely-used programming language and platform that powers numerous applications and systems worldwide. Installing Java on Debian-based Linux distributions like Ubuntu, Debian, and their derivatives is a straightforward process, but it involves a few essential steps. In this guide, I\u0026#8217;ll walk you through the process of installing Java on your Debian-based Linux system.\nStep 1: Checking Java Version. Before installing Java, it\u0026#8217;s essential to check if Java is already installed on your system and determine its version. You can do this by running the following command in your terminal:\njava -version This command will display the installed Java version, if any.\nStep 2: Find Available Java Versions. When navigating the available OpenJDK and OpenJRE versions on Debian-based Linux distributions, it\u0026#8217;s important to note that both OpenJDK and OpenJRE are accessible options for Java installation. OpenJDK constitutes the entire Java Development Kit (JDK), encompassing both the runtime environment (JRE) and development tools, while OpenJRE solely pertains to the Java Runtime Environment.\nTo explore the spectrum of available OpenJDK and OpenJRE versions, execute the following command:\napt-cache search openjdk This command generates a list of available OpenJDK and OpenJRE packages, presenting you with a selection to install either the JDK or JRE. While the JRE suffices for executing Java applications, opting for the JDK is advisable for development purposes or scenarios where access to development tools might be necessary.\nIf you are unsure about precise requirements or anticipate future development needs, installing the JDK offers a more comprehensive solution.\nStep 3: Installing Default JDK (Java Development Kit) To install the default Java Development Kit, execute the following command. To install the default Java Runtime Environment replace \u0026#8220;jdk\u0026#8221; in the command below with \u0026#8220;jre\u0026#8220;:\nsudo apt install default-jdk This command installs the default JDK package. You can confirm successful installation of java by running the \u0026#8220;java -version\u0026#8221; command in your terminal.\nStep 4: Installing Specific version of JDK or JRE. To install a specific version, such as OpenJDK 17, use the following command. Same as above, replace \u0026#8220;jdk\u0026#8221; in the command below with \u0026#8220;jre\u0026#8221; if you prefer to install OpenJRE 17 instead:\nsudo apt install openjdk-17-jdk Step 5: Configuring Java Versions After installing multiple Java versions. You may need to configure which version should be used as the default. Use the following command to configure Java versions:\nsudo update-alternatives --config java This command allows you to select the default Java Runtime Environment.\nStep 6: Configuring Java Compiler. Similarly, if you have installed multiple versions of JDK you can configure the default Java compiler using the following command:\nsudo update-alternatives --config javac Step 7: Downloading and Installing Oracle JDK (Optional)\nIn instances where the specific version of Java Development Kit (JDK) you require isn\u0026#8217;t available in the default repository, you can obtain it directly from Oracle\u0026#8217;s website and install it manually. Here\u0026#8217;s how you can do it:\nwget https://download.oracle.com/java/22/latest/jdk-22_linux-x64_bin.deb\nsudo dpkg -i jdk-22_linux-x64_bin.deb\nsudo apt -f install These commands download the Oracle JDK package and install it using dpkg.\nStep 8: Setting JAVA_HOME (Optional) Setting the JAVA_HOME environment variable is optional but can be useful for specifying the Java installation directory. You can set JAVA_HOME in your ~/.bashrc (for user specific setup) file or /etc/environment (for system wide setup) file by opening either file:\nnano ~/.bashrc or,\nnano /etc/environment And adding the following line. You can get the path for the desired Java version by running the \u0026#8220;sudo update-alternatives \u0026#8211;config java\u0026#8221; command.\nexport JAVA_HOME=/path/to/java Save the file and reload for the changes to take effect.\nsource ~/.bashrc or,\nsource /etc/environment Conclusion: By following the steps outlined in this guide, you can successfully install Java on your Debian-based Linux system using various methods. Whether you opt for OpenJDK or Oracle JDK, you now have the knowledge to set up Java according to your preferences and requirements. Java\u0026#8217;s versatility and wide range of applications make it an essential tool for developers and users alike on Linux platforms.\n","keywords":["install","java","debian","ubuntu"],"permalink":"https://techtutelage.net/how-to-install-java-on-debian-based-linux/","summary":"Install Java on Ubuntu, Debian and other Debian-based Linux: check your version, choose an OpenJDK or JRE package, install it and set the default.","title":"How to Install Java on Debian-based Linux"},{"content":" Feeling worn out from setting up your Minecraft Bedrock Edition server on Ubuntu or Debian Linux? I get it. That’s why I’ve crafted a nifty script to make your life easier. Let’s break down how this tool can transform setting up your server into a walk in the park.\nKey Features User, Port, and Installation Directory Setup The script initializes variables for the server name, port, user under which the Minecraft server will run, and the directory where the server will be installed. This customization ensures that your server is set up exactly as you need it. Sudo Privilege Check It checks that the script is being run with sudo privileges to perform the necessary system-level operations, ensuring everything is set up correctly. Operating System Check The script verifies that it’s running on a supported Ubuntu or Debian Linux system to ensure compatibility and smooth operation. Existing Installation Check Before proceeding, it checks for any existing Minecraft server installation to prevent accidental overwrites, safeguarding your previous setup. Dependency Installation The script updates package lists and installs required dependencies such as wget, unzip, and supervisor, ensuring that all necessary tools are available. Minecraft Server Download and Setup It retrieves the latest Minecraft Bedrock Edition server from the official website, downloads it, extracts it to the installation directory, and sets up the necessary permissions for a seamless setup. Supervisor Configuration Configures Supervisor to monitor and control the Minecraft server process, making sure it runs as a background service for continuous operation. Firewall Configuration Checks if iptables is installed and ensures that UDP ports specified in the variables are open to allow Minecraft server traffic, ensuring smooth connectivity. Final Checks and Confirmation The script verifies that the Minecraft server is successfully running and listening on the designated UDP port, providing feedback about the installation status. Customization Required Note: While this script automates the basic setup of your Minecraft server, additional configuration may be required to tailor server settings to your preferences. You’ll need to manually adjust settings in the server.properties file and other configuration files to fit your specific needs.\nGet Started To simplify your Bedrock server setup, visit my GitHub repository for the Bedrock Server Install Script. Follow the provided instructions to get your server up and running effortlessly.\nExplore the Bedrock Install Script on GitHub\nFor ongoing server maintenance, don’t forget to check out my Bedrock Server Update Script. Together, these tools provide a comprehensive solution for managing your Minecraft Bedrock server with ease.\nWith these scripts, setting up and maintaining your Bedrock server becomes a breeze. Enjoy a hassle-free experience and spend more time enjoying your game!\n","keywords":["minecraft","bedrock","server","ubuntu"],"permalink":"https://techtutelage.net/automated-setup-guide-installing-minecraft-bedrock-server-on-ubuntu-debian/","summary":"A free script that installs a Minecraft Bedrock Edition server on Ubuntu or Debian in minutes: sets the user, port and directory, and runs it as a service.","title":"Auto-Install a Minecraft Bedrock Server on Ubuntu/Debian"},{"content":" Learn the essential skills of connecting to a remote server using SSH. In this tutorial I will guide you through the entire process, covering SSH password authentication, key-based authentication, and connecting to a non-default port.\nQuick reference: common SSH commands These are the standard OpenSSH commands for the topics covered in the video. The video may use slightly different options (for example, a different key type), so follow the video if anything differs. Replace user, server and the file names with your own.\nConnect with a password: ssh user@server Create a key pair: ssh-keygen -t ed25519 Copy your public key to the server: ssh-copy-id user@server Connect with a specific private key: ssh -i ~/.ssh/id_ed25519 user@server Connect on a non-default port (for example 2222): ssh -p 2222 user@server Related guides: Enable SSH password authentication, Configure MFA for SSH and Recover an instance with a lost SSH key.\n","keywords":["openssh","tutorial"],"permalink":"https://techtutelage.net/openssh-step-by-step-tutorial/","summary":"Learn to connect to a remote server with OpenSSH: password authentication, key-based login with SSH keys and connecting on a non-default port. Video guide.","title":"OpenSSH Step-by-Step Tutorial"},{"content":" X11 forwarding is a powerful feature of SSH that enables users to run graphical applications on a remote server while displaying the interface on their local machine. This tutorial will guide you through the process of setting up X11 forwarding, ensuring you can seamlessly interact with graphical applications on a remote server.\nStep 1: Install and Start an X Server on Your Local Machine: Linux: Most Linux distributions come with X11 server installed by default. If not, install package \u0026#8220;xorg\u0026#8221; using your package manager. macOS: Download and install XQuartz from XQuartz website. Windows: Download and install Xming from Xming website. Step 2: Enable X11 Forwarding in Your SSH Server: In the \u0026#8220;/etc/ssh/sshd_config\u0026#8221; file on the remote server, make sure you have the following line uncommented and set to \u0026#8220;Yes\u0026#8221; to ensure X11 forwarding is allowed:\nX11Forwarding yes After you have confirmed that X11 forwarding is enabled restart ssh server service.\nsudo systemctl restart ssh Step 3: Connect to the remote ssh server with -Y or -X option for X11Forwarding: The -X option sets up X11 forwarding with a higher level of security. When you use -X, it enables X11 forwarding but restricts the permissions that the remote X11 client has on your local machine. This means that the remote X11 client can\u0026#8217;t easily capture or manipulate your local X11 server\u0026#8217;s data.\nssh -X username@remote_server_ip The -Y option is similar to -X but relaxes some of the security restrictions. It allows the remote X11 client more permissions on your local X11 server. While this option can be more convenient, it also introduces some security risks. It is essential to use it only when connecting to trusted servers.\nssh -Y username@remote_server_ip After connecting to the remote server successfully, test X11 forwarding by running a graphical application. Remember before attempting to use X11 forwarding, ensure that the X Server application installed in \u0026#8220;Step 1\u0026#8221; is running on your local machine.\nSecurity Note: While X11 forwarding is convenient, it may pose security risks. Use it only on trusted networks and avoid forwarding X11 connections from untrusted sources.\nThis should get you started with X11 forwarding. Enjoy running graphical applications on your remote server while the display is shown on your local machine!\n","keywords":["x11","forwarding","ssh"],"permalink":"https://techtutelage.net/setting-up-and-using-x11-forwarding-for-remote-graphical-applications/","summary":"Run graphical apps from a remote server over SSH: install an X server (XQuartz, Xming), enable X11Forwarding in sshd_config and connect with ssh -X or -Y.","title":"Set Up X11 Forwarding for Remote Graphical Applications"},{"content":"Graylog is a robust open-source log management solution designed to simplify the process of collecting, indexing, and analyzing log data. In this step-by-step guide, we will delve into the installation of Graylog 5 on a Debian system. By the end of this tutorial, you\u0026#8217;ll have a fully operational Graylog instance ready to streamline your log management workflow.\nStep 1: Before diving into Graylog installation, ensure that your system has the required dependencies. The commands provided will install essential packages and tools needed for the subsequent steps.\nsudo apt install apt-transport-https openjdk-11-jre-headless uuid-runtime pwgen dirmngr gnupg wget Step 2: Install MongoDB Graylog relies on MongoDB as its backend database. The commands in this step download and install MongoDB version 5.0, configure the repository, and set up the MongoDB service.\nwget -qO - https://www.mongodb.org/static/pgp/server-5.0.asc | sudo apt-key add - echo \"deb http://repo.mongodb.org/apt/debian buster/mongodb-org/5.0 main\" | sudo tee /etc/apt/sources.list.d/mongodb-org-5.0.list sudo apt update sudo apt install -y mongodb-org sudo systemctl daemon-reload sudo systemctl enable mongod.service sudo systemctl restart mongod.service sudo systemctl status mongod Step 3: Install Elasticsearch Elasticsearch serves as the storage and retrieval engine for Graylog. This step involves installing Elasticsearch version 7.x, configuring its settings, and ensuring it starts as a system service.\nwget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add - echo \"deb https://artifacts.elastic.co/packages/oss-7.x/apt stable main\" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list sudo apt update sudo apt install elasticsearch-oss sudo tee -a /etc/elasticsearch/elasticsearch.yml \u003e /dev/null \u0026lt;\u0026lt; EOT cluster.name: graylog action.auto_create_index: false EOT # OPTIONAL: Adjust JVM Memory Limits nano /etc/elasticsearch/jvm.options sudo systemctl daemon-reload sudo systemctl enable elasticsearch.service sudo systemctl restart elasticsearch.service sudo systemctl status elasticsearch.service Step 4: Test Elasticsearch (Optional) Verify the correct installation and functionality of Elasticsearch by using the provided optional command. This step is crucial to ensure that Elasticsearch is running and accessible on the specified port.\napt install curl curl http://localhost:9200/ Step 5: Install Graylog Download and install the Graylog repository, update the package list, and install the Graylog server. This step sets the foundation for the Graylog instance on your Debian system.\nwget https://packages.graylog2.org/repo/packages/graylog-5.2-repository_latest.deb sudo dpkg -i graylog-5.2-repository_latest.deb sudo apt update sudo apt install graylog-server Step 6: Configure Graylog Generate a secure password for Graylog, configure its settings, and adjust JVM memory limits if needed. This step ensures that Graylog is properly configured and secured. It also involves editing the server configuration file to bind Graylog to the specified IP address.\nGenerate \u0026#8220;password_secret\u0026#8221;.\npwgen -N 1 -s 96 Generate \u0026#8220;root_password_sha2\u0026#8221;, this generates hashed value of your \u0026#8220;admin\u0026#8221; user password.\necho -n \"Enter Password: \" \u0026amp;\u0026amp; head -1 \u0026lt;/dev/stdin | tr -d '\\n' | sha256sum | cut -d\" \" -f1 Copy and paste the generated \u0026#8220;password_secret\u0026#8221; and hashed admin password \u0026#8220;root_password_sha2\u0026#8221; into \u0026#8220;server.conf\u0026#8221; sudo nano /etc/graylog/server/server.conf Add the line below to \u0026#8220;server.conf\u0026#8221; to allow access to Graylog from hosts other than local host.\nhttp_bind_address = 0.0.0.0 OPTIONALLY: Adjust JVM Memory Limits.\nnano /etc/default/graylog-server Ensure Graylog is running and is set to start as a system service.\nsudo systemctl daemon-reload sudo systemctl enable graylog-server.service sudo systemctl start graylog-server.service sudo systemctl status graylog-server.service Congratulations! You\u0026#8217;ve successfully installed Graylog 5 on Debian. You can now access the Graylog web interface by navigating to http://\u0026lt;your-server-ip\u003e:9000/ in your web browser. Replace \u0026lt;your-server-ip\u003e with the actual IP address or hostname of your Graylog server.\nSecurity Considerations: While Graylog is now accessible, it\u0026#8217;s important to note that exposing services to all network interfaces may have security implications. To enhance security, it is strongly recommended to set up a reverse proxy with SSL/TLS for encrypted and secure connections.\n","keywords":["install","graylog","debian"],"permalink":"https://techtutelage.net/installing-graylog-5-on-debian-a-step-by-step-guide/","summary":"Install Graylog 5 on Debian step by step: dependencies, MongoDB, Elasticsearch and the Graylog server, configured and ready to start collecting logs.","title":"Installing Graylog 5 on Debian: A Step-by-Step Guide"},{"content":" On macOS, the root user is usually disabled by default for security reasons. Enabling the root user should be done with caution, and it\u0026#8217;s typically not recommended unless you have a specific need. Here\u0026#8217;s how to check if the root user is enabled and how to enable or disable it if needed.\nChecking if the Root User is Enabled:\nMake sure you are logged-in as a user with administrator level privileges. Open the \u0026#8220;Terminal\u0026#8221; application, which you can find in the \u0026#8220;Utilities\u0026#8221; folder within the \u0026#8220;Applications\u0026#8221; folder.\nIn the Terminal window, type the following command and press Enter:\nsudo dscl . -read /Users/root AuthenticationAuthority If the above command will display \u0026#8220;No such key: AuthenticationAuthority\u0026#8221; this means that your root user is currently disabled. If root user is enabled you will see output similar to this \u0026#8220;AuthenticationAuthority: ;ShadowHash;HASHLIST:\u0026lt;SALTED-SHA512-PBKDF2,SRP-RFC5054-4096-SHA512-PBKDF2\u0026gt; ;SecureToken; ;Kerberosv5;;root\u0026#8221;\nEnabling the Root User:\nIf you need to enable the root user, type the following command and press Enter:\ndsenableroot You will be prompted to enter your password to confirm the action. After entering your password, you will be prompted to create a new password for root. Once you confirm the root password you should receive message similar to this \u0026#8220;dsenableroot:: ***Successfully enabled root user.\u0026#8221; and the root user will be enabled.\nDisabling the Root User:\nIt\u0026#8217;s important to disable the root user when you no longer need it to enhance the security of your system. To disable the root user, type the following command and press Enter:\ndsenableroot -d You will be prompted to enter your password to confirm the action. After entering your password, you will see a message similar to this \u0026#8220;dsenableroot:: ***Successfully disabled root user.\u0026#8221; and the root user will be disabled.\nPlease use the root user account with caution, as it has elevated privileges and can make significant changes to your system. Enabling the root user should only be done if you have a specific need, and you should disable it as soon as you are done with the task that required its use.\n","keywords":["enable","root","user","mac"],"permalink":"https://techtutelage.net/enable-root-user-on-mac-os/","summary":"Check whether the root user is enabled on macOS, then enable or disable it from the Terminal with dsenableroot. Plus why you should be careful doing it.","title":"Enable the Root User on macOS"},{"content":"In the ever-evolving landscape of cloud computing, Oracle Cloud stands as a formidable contender, offering a comprehensive suite of services to meet the demands of modern businesses. One of the most enticing aspects of Oracle Cloud is its Free Tier, which allows users to experience the benefits of cloud computing without any upfront costs. In this article, we will delve into what Oracle Cloud\u0026#8217;s Free Tier offers and explore some compelling use cases that highlight its potential.\nUnderstanding Oracle Cloud\u0026#8217;s Free Tier\nOracle Cloud\u0026#8217;s Free Tier is an enticing entry point for individuals and organizations looking to leverage cloud computing without the burden of initial expenses. Here\u0026#8217;s a brief overview of what you can expect from Oracle Cloud\u0026#8217;s Free Tier:\nAlways Free Services: Oracle Cloud\u0026#8217;s Free Tier offers a range of \u0026#8220;Always Free\u0026#8221; services that remain free for as long as you use them. These include Compute, Block Volumes, Object Storage, Autonomous Database, and much more. Generous Usage Limits: While these services are free, Oracle Cloud provides generous usage limits that make them practical for various use cases. For instance, the Compute service grants you up to four virtual machines with 6 GB of memory and 50 GB disk space each, which can be utilized for web hosting, development, and testing. Global Data Centers: Oracle Cloud\u0026#8217;s Free Tier operates across multiple global data centers, ensuring low-latency access and data redundancy. Flexible Platform: Users can choose from various cloud infrastructure and application services, including virtual machines, databases, and storage solutions. Now, let\u0026#8217;s explore some compelling use cases for Oracle Cloud\u0026#8217;s Free Tier services:\n1. Development and Testing: For developers and small teams, the Free Tier is an excellent platform for creating, testing, and deploying applications. You can provision virtual machines, set up development environments, and experiment with different configurations without worrying about costs.\n2. Website Hosting: Running a personal blog or a small business website? Oracle Cloud\u0026#8217;s Free Tier is a great choice for hosting static websites or content management systems like WordPress. You can leverage the Object Storage service to store and serve your website files efficiently.\n3. Learning and Training: If you\u0026#8217;re looking to expand your cloud computing skills or train your team, the Free Tier is a fantastic resource. You can practice setting up databases, deploying applications, and exploring various cloud services without financial constraints.\n4. Data Storage and Backup: The Object Storage service in the Free Tier allows you to store up to 20 GB of data, making it a viable option for backups, data archives, or as a remote storage solution for personal files.\n5. Autonomous Database Testing: Oracle\u0026#8217;s Autonomous Database is a powerful, self-driving database service. With the Free Tier, you can test its capabilities, performance, and security features, making it suitable for small-scale applications or proof-of-concept projects.\n6. Internet of Things (IoT) Prototyping: If you\u0026#8217;re interested in IoT, Oracle Cloud\u0026#8217;s Free Tier can be used to prototype IoT solutions. You can connect devices, collect data, and explore IoT services without worrying about infrastructure costs.\nTo explore more in-depth tutorials and practical demonstrations of Oracle Cloud\u0026#8217;s Free Tier services, be sure to check out my YouTube channel. I\u0026#8217;ve created a series of informative videos that will help you make the most of Oracle Cloud\u0026#8217;s Free Tier offerings.\nIn these tutorials, you\u0026#8217;ll find step-by-step guides, tips, and best practices for using Oracle Cloud\u0026#8217;s Free Tier for various use cases, including web hosting, VPN, object storage. Whether you\u0026#8217;re new to cloud computing or looking to enhance your skills, these videos are designed to assist you in maximizing the potential of Oracle Cloud\u0026#8217;s Free Tier.\nDon\u0026#8217;t miss out on the opportunity to expand your knowledge and leverage the power of Oracle Cloud\u0026#8217;s Free Tier to its fullest extent. Subscribe to my channel, and stay updated with the latest insights and tutorials in the world of cloud computing.\n","keywords":["oracle","cloud","free","tier"],"permalink":"https://techtutelage.net/exploring-oracle-clouds-free-tier-unleash-the-power-of-cloud-computing/","summary":"What Oracle Cloud’s Free Tier includes, how the Always Free services work, and practical use cases for running websites, apps and labs at no cost.","title":"Exploring Oracle Cloud’s Free Tier: Unleash the Power of Cloud Computing"},{"content":"Enabling MFA (Multi-Factor Authentication) is strongly recommended if you have enabled user password SSH authentication. MFA adds an extra layer of security by requiring an additional form of authentication beyond just the password. This helps mitigate the risk of unauthorized access in case the password is compromised or stolen. In this tutorial I will show you how to set up MFA using “libpam-google-authenticator” to require MFA for a specific user on an Ubuntu server.\u0026nbsp;To begin, go ahead and switch to root, or to another user with sudo privileges, and install “libpam-google-authenticator”\nsudo apt-get install libpam-google-authenticator Once you have “libpam-google-authenticator” installed switch to the user you want to enable MFA for and run:\nsudo google-authenticator Follow the onscreen instructions. The prompt \u0026#8220;Do you want authentication tokens to be time-based (y/n)\u0026#8221; refers to whether you want the MFA tokens to be generated based on time intervals. Time-based tokens change every few seconds and are considered more secure so answer “Y”. This will generate the secret key and display a QR code.\nNext go to your mobile device, login to your app store and download an app called “Google Authenticator” Click on the \u0026#8220;+\u0026#8221; and select “Enter a setup key” to enter the newly generated secret key manually, or select\u0026nbsp; “Scan a QR code” to scan the generated QR code instead.\u0026nbsp;\nThis will add the authentication token to your Authenticator app, once you have the token added to your app, enter the 6 digit token into the “Enter code from app (-1 to skip):” prompt in your terminal window, and hit “Enter” If your code is successfully confirmed, you will be presented with “emergency scratch codes”. Put these someplace safe! These codes serve as an alternative method of authentication in case the primary MFA method (such as a mobile device or authenticator app) is unavailable or lost.\nFollow the onscreen instructions and answer the questions based on your preference, below are recommended settings, but you don’t have to follow them.\nDo you want me to update your \"/home/new_user/.google_authenticator\" file? (y/n) y Do you want to disallow multiple uses of the same authentication token? This restricts you to one login about every 30s, but it increases your chances to notice or even prevent man-in-the-middle attacks (y/n) y By default, a new token is generated every 30 seconds by the mobile app. In order to compensate for possible time-skew between the client and the server, we allow an extra token before and after the current time. This allows for a time skew of up to 30 seconds between authentication server and client. If you experience problems with poor time synchronization, you can increase the window from its default size of 3 permitted codes (one previous code, the current code, the next code) to 17 permitted codes (the 8 previous codes, the current code, and the 8 next codes). This will permit for a time skew of up to 4 minutes between client and server. Do you want to do so? (y/n) y If the computer that you are logging into isn't hardened against brute-force login attempts, you can enable rate-limiting for the authentication module. By default, this limits attackers to no more than 3 login attempts every 30s. Do you want to enable rate-limiting? (y/n) y After the installation process has completed switch back to root, or another user with sudo privileges and open the PAM configuration file.\nsudo nano /etc/pam.d/sshd Add the following line at the top of the file to enforce MFA for the specific user:\nauth required pam_google_authenticator.so Save the changes and exit the editor. Then open the SSH configuration file.\nsudo nano /etc/ssh/sshd_config Locate the line that starts with ChallengeResponseAuthentication or KbdInteractiveAuthentication and set it to yes. If the line is commented out, uncomment it and change its value, if it does not exist add it to the file.\nChallengeResponseAuthentication yes or\nKbdInteractiveAuthentication yes Save the changes and exit the editor. Restart the SSH service to apply the changes:\nsudo service ssh restart At this point MFA Authentication for your user should be all set. Remember to test the setup before fully relying on it. Ensure you have backup codes and alternative means of accessing the server in case of any issues with MFA.\nTo see this tutorial in action check out the video version of it on YouTube!\n","keywords":["ssh","mfa","google","authenticator"],"permalink":"https://techtutelage.net/configure-mfa-multi-factor-authentication-on-ssh-with-google-authenticator/","summary":"Add multi-factor authentication to SSH on Ubuntu with libpam-google-authenticator: set up the app, configure PAM and sshd_config, and require MFA per user.","title":"Configure MFA for SSH with Google Authenticator"},{"content":" Most major cloud providers such as AWS, OCI, Google Cloud, disable SSH password authentication method by default, allowing the users to only use private/public key pair for authentication. Even though using private/public keys is a much safer method, sometimes you may need to be able to access your server using username and a password. To enable SSH password authentication, you need to make a few changes to the SSH server configuration file. Here\u0026#8217;s a step-by-step guide:\nConnect to your SSH server as a user with administrative privileges. This can be done either by logging in directly or using a remote management tool like SSH or PuTTY. To connect with ssh run the command below in your terminal window.\nssh -i PATH/TO/PRIVATE.KEY USER@SERVER_ADDRESS Once connected to your server, open the SSH server configuration file \u0026#8220;sshd_config\u0026#8221;. The location may vary depending on the operating system you are using, in most Linux distributions it is located in \u0026#8220;/etc/ssh/\u0026#8221;. To open the file with nano run the following command.\nnano /etc/ssh/sshd_config To allow password authentication globally for all users (NOT RECOMMENDED!). In \u0026#8220;sshd_config\u0026#8221; Search for the line that begins with \u0026#8220;PasswordAuthentication\u0026#8221;. If password authentication is disabled, it will be set to \u0026#8220;no\u0026#8221;. To enable password authentication all you need to do is change the value to \u0026#8220;yes\u0026#8221;. Save and close the file, then restart your ssh service by running the following command.\nservice ssh restart To only allow password authentication for specific user (RECOMMENDED!). Leave the \u0026#8220;PasswordAuthentication\u0026#8221; directive set to \u0026#8220;no\u0026#8221;. Go to the bottom of \u0026#8220;sshd_config\u0026#8221; file and add the following two lines.\nMatch User USERNAME_HERE PasswordAuthentication yes Save and close the file, then restart your ssh service by running the following command.\nservice ssh restart This will make an exception to the global SSH configuration and it will enable password authentication for the listed user.\nTo see this tutorial in action check out my video tutorial on YouTube!\n","keywords":["enable","ssh","password","authentication"],"permalink":"https://techtutelage.net/enable-ssh-password-authentication/","summary":"Cloud servers disable SSH password login by default. Here’s how to enable PasswordAuthentication in sshd_config, restart SSH and log in with a password.","title":"Enable SSH Password Authentication"},{"content":" 3 Ways to keep Oracle from reclaiming \u0026#8220;your\u0026#8221; Always Free Instances If you are reading this article chances are that you have probably received the following warning email from Oracle, and you are wondering how to prevent it from happening in the future.\nOracle Cloud Infrastructure Customer,\nOracle Cloud Infrastructure (OCI) will be reclaiming idle Always Free compute resources from Always Free customers. Reclaiming idle resources allows OCI to efficiently provide services to Always Free customers. Your account has been identified as having one or more compute instances that have been idle for the past 7 days. These idle instances will be stopped one week from today, May 30,2023. If your idle Always Free compute instance is stopped, you can restart it as long as the associated compute shape is available in your region. You can keep idle compute instances from being stopped by converting your account to Pay As You Go (PAYG). With PAYG, you will not be charged as long as your usage for all OCI resources remains within the Always Free limits.\nAs the email suggests the easiest way would be to convert your account to Pay As You Go. This will be my first recommendation as well! With Pay As You Go account you still get to use all the Always Free services such as 4CPUs, 24GB of Memory, 200GB Block storage, Free Reserved IP, etc. Plus you don\u0026#8217;t have to worry about your instances becoming idle and being reclaimed. On top of it, you will rarely see the infamous \u0026#8220;Out of Capacity\u0026#8221; error when you try to build new instance, and you will have access to Oracle Support team.\nYour second option is to stop over-allocating resources. If you are only going to host a proof of concept web app, that will barely generate any traffic, you probably don\u0026#8217;t need the 4CPUs and 24G memory. Go with the 1 CPU and 6G memory and chances are you will meet the 15% utilization requirement, and your instance will never become idle.\nIf none of the above works for you, the only option left is to put some load on your instance and make it meet the requirements posed by Oracle, which at the time of writing this article are:\nCPU utilization for the 95th percentile is less than 15% Network utilization is less than 15% Memory utilization is less than 15%\u0026nbsp;(applies to\u0026nbsp;A1 shapes\u0026nbsp;only) You can get the current requirements here.\nThere are many ways to put load on your instance and of course the best way would be to have a natural load, unfortunately not all of us can do that. The good news is that if you are unable to do it naturally there are many free tools available to help you.\nThe tool that we will use in this tutorial is called \u0026#8220;stress-ng\u0026#8221;. Stress-ng is a command-line tool that can be used to induce stress on a computer system\u0026#8217;s various hardware components such as CPU, memory, disk, etc. In our case we will use it to simulate CPU usage, and memory allocation so we can meet Oracle\u0026#8217;s requirements and keep our instance from becoming idle. We are also going to use a tool called \u0026#8220;supervisorctl\u0026#8221; that will help us manage the \u0026#8220;stress-ng\u0026#8221; process, and to ensure it is always running on our system.\nBefore we begin I want to give you a fair WARNING: There is a good chance that this setup violates Oracle\u0026#8217;s Always Free Tier Terms of Services and implementing this solution may get your OCI account suspended or terminated. If you are willing to take this risk keep reading, otherwise follow my top recommendation and upgrade to Pay As You Go account. The first thing that we need to do is ssh to our instance switch to root and install \u0026#8220;stress-ng\u0026#8221; and \u0026#8220;supervisorctl\u0026#8221;.\nsudo su - apt update apt install supervisor stress-ng After we have both tools installed we can go ahead and run the following commands to send some load to our CPUs and Memory:\nThe command below will put 15% load on each of the 4 CPUs available, we can tweak the numbers below as we wish to meet our requirements.\nstress-ng --cpu 4 --cpu-load 15 The line below will take 15% of our total memory and hold it. So if we are already using let\u0026#8217;s say 2% of our total memory running this command will cause 17% memory utilization. \u0026nbsp;Again we can tweak these numbers as we wish to meet our requirements.\nstress-ng --vm 1 --vm-bytes 15% --vm-hang 0 To terminate these commands all we need to do is press Ctrl-c.\nOnce we have adjusted these commands to fit our needs. We need to create supervisor configuration file. The supervisor configuration file will ensure that stress-ng is always running on our instance. To create the file we run the following command.\nnano /etc/supervisor/conf.d/stress.conf Copy and paste the following config to your \u0026#8220;stress.conf\u0026#8221; this is just an example make sure to tweak it to meet your requirements. The config below will create two programs \u0026#8220;cpu_stress\u0026#8221; and \u0026#8220;memory_stress\u0026#8221; the two programs will run the two \u0026#8220;stress-ng\u0026#8221; commands we ran above simultaneously, it will auto start them on boot and auto-restart them if they crash or get killed.\n\u0026#91;program:cpu_stress] command=/usr/bin/stress-ng --cpu 4 --cpu-load 15 directory=/usr/bin/ user=root autostart=true autorestart=true redirect_stderr=true stdout_logfile=/var/log/stress.log \u0026#91;program:memory_stress] command=/usr/bin/stress-ng --vm 1 --vm-bytes 15%% --vm-hang 0 directory=/usr/bin/ user=root autostart=true autorestart=true redirect_stderr=true stdout_logfile=/var/log/stress.log To get supervisor to start the two programs we have we first need to reload the configuration file we do that by running the following command. Run the command below anytime you make changes to this config file or create new file!\nsupervisorctl reread Next we can go ahead and reload the \u0026#8220;supervisorctl\u0026#8221; to start the two programs.\nsupervisorctl reload You can check the status of the programs by running\nsupervisorctl status For more details and to see this set up in action check out my video on YouTube:\n","keywords":["oracle","always","free","idle","instance"],"permalink":"https://techtutelage.net/how-to-keep-oracle-from-reclaiming-your-always-free-tier-instances/","summary":"Got Oracle’s idle-instance warning email? Three ways to keep your Always Free OCI compute instances from being stopped and reclaimed for low usage.","title":"How to Keep Oracle from Reclaiming Your Always Free Instances"},{"content":" The ionCube PHP Encoder is a widely used tool that allows developers to protect their PHP files with powerful encryption and security features. To use ionCube-encoded files on a web server, the ionCube Loader must be installed and made available to PHP. To install ionCube Loader on your server go ahead and download the latest version available for your operating system. You can download it from the link below:\nhttps://www.ioncube.com/loaders.php\nOn Linux server with ARM architecture you can download it by running the below command, if you need 32-bit and 64-bit version you can get the link from the link above.\nwget https://downloads.ioncube.com/loader_downloads/ioncube_loaders_lin_aarch64.zip Once you have ionCube Loader package downloaded you will have to unzip it\nunzip ioncube_loaders_lin_aarch64.zip Once you unzip the package, a directory called \u0026#8220;ioncube/\u0026#8221; will get created on your system. In that directory you will find all available ionCube Loader php extensions, the version of each extension corresponds to the version of php it needs to run, (e.g. ioncube_loader_lin_8.1.so is extension for php8.1) Run the following command to find out your current PHP version\nphp -v Next you need to figure out your default PHP extensions directory you can do that by running the following command\nphp -i | grep extension_dir Once you know your PHP version and path to the PHP extensions default directory, copy that extensions file supported by your PHP version to the default extensions directory.\ncp ioncube/ioncube_loader_lin_8.1.so /usr/lib/php/20210902 Next login to your Hestia Control Panel and open \u0026#8220;php.ini\u0026#8221; file. Server Settings -\u0026gt; php8.1-fpm add the following line anywhere in the file. Make sure you replace the path with your default extensions path.\nzend_extension=/usr/lib/php/20210902/ioncube_loader_lin_8.1.so Go ahead and save the changes to the \u0026#8220;php.ini\u0026#8221;, that will restart your web server and at that point you should have ionCube PHP Encoder successfully installed and loaded on you Hestia server. To confirm installation run php -v For more detailed explanation, with visuals go ahead and check out my video tutorial on YouTube .\n","keywords":["install","ioncube","loader","hestia"],"permalink":"https://techtutelage.net/how-to-install-ioncube-php-encoder-on-hestia/","summary":"Install the ionCube Loader on a HestiaCP server so PHP can run ionCube-encoded files: download the right package (incl. ARM64), add it to php.ini, restart.","title":"How to Install the ionCube Loader on HestiaCP"},{"content":" Uninstall Java from MacOS step-by-step guide. Start by opening terminal window in your Mac, and executing the following command to get currently installed version of Java.\njava --version If you have Java installed on your system you should get output that looks similar to the one below.\njava 20 2023-03-21 Java(TM) SE Runtime Environment (build 20+36-2344) Java HotSpot(TM) 64-Bit Server VM (build 20+36-2344, mixed mode, sharing) If Java is not present on your system, you will get the following output.\nThe operation couldn’t be completed. Unable to locate a Java Runtime. Please visit http://www.java.com for information on installing Java. Once you have confirmed that you have Java on your system you can go ahead and complete the steps below to uninstall it. First you need to find the installation directory. Default directory on Mac OS is \u0026#8220;/Library/Java/JavaVirtualMachines\u0026#8221;. Just to be sure run the following command to confirm.\n/usr/libexec/java_home -V The output you get should look similar to the one below. As you can see on my system I have Java 20 and Java 17. Yours may or may not look the same. Regardless of what version you have here you will be able to see the installation path \u0026#8220;/Library/Java/JavaVirtualMachines/\u0026#8221;.\nMatching Java Virtual Machines (2): 20 (x86_64) \"Oracle Corporation\" - \"Java SE 20\" /Library/Java/JavaVirtualMachines/jdk-20.jdk/Contents/Home 17.0.6 (x86_64) \"Oracle Corporation\" - \"Java SE 17.0.6\" /Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home /Library/Java/JavaVirtualMachines/jdk-20.jdk/Contents/Home To remove Java all you have to do is run the following command, replace the version number with the one you would like to remove from your system, when prompted enter your password.\nsudo rm -rf /Library/Java/JavaVirtualMachines/jdk-17.jdk In the example above Java 17 will be removed from the system, to remove Java 20 replace \u0026#8220;jdk-17.jdk\u0026#8221; with \u0026#8220;jdk-20.jdk\u0026#8221;.\nWARNING: Do not attempt to uninstall Java by removing the Java tools from \u0026#8220;/usr/bin\u0026#8221; !!!\n","keywords":["uninstall","java","mac"],"permalink":"https://techtutelage.net/how-to-uninstall-java-from-mac-os/","summary":"Completely uninstall Java from macOS: check your installed version, find the JDK in /Library/Java/JavaVirtualMachines and remove it from the Terminal.","title":"How to Uninstall Java from macOS"},{"content":" Learn how to install and configure WireGuard VPN on remote headless Ubuntu server. For this particular example I am using Always Free Oracle Cloud instance, but these instructions should work on any Ubuntu server.\nInstall WireGuard Start with updating the package sources list with the latest version of packages in the repositories and install WireGuard.\napt update apt install wireguard WireGuard installation will create a directory /etc/wireguard. To set the default file creation permission to 600, navigate to /etc/wireguard and change the umask to 077.\ncd /etc/wireguard umask 077 Configure WireGuard Server Next generate public and private key pair for the WireGuard server.\nwg genkey | tee server-privatekey | wg pubkey \u003e server-publickey Get the content of the two files, by running the following command\ntail -n +1 server-privatekey server-publickey Store the output of the command in a place handy for copy and paste, as you will need to use it later.\n==\u003e server-privatekey \u0026lt;== GK+wX0XxaUY9rlQOHCdF3teRZttWXADMVZ5eLfQa80c= ==\u003e server-publickey \u0026lt;== vaXI0PRL35MNjlfZSQSrTBVzmJZhGtPv9OmeFZW0hF0= Next create wg0.conf file. This file will be your WireGuard server configuration file. You can create the file by executing the following command.\nnano wg0.conf Next paste the following configuration settings into the wg0.conf file. Make sure to replace the \u0026#8220;PrivateKey\u0026#8221; value with the private key you generated earlier.\n\u0026#91;Interface] Address = 10.16.0.1/32 ListenPort = 51820 PrivateKey = GK+wX0XxaUY9rlQOHCdF3teRZttWXADMVZ5eLfQa80c= You can go ahead and save the changes and close the wg0.conf file (Ctrl-x press Y press Enter). Then you can go ahead and add the WireGuard service to systemd so it starts automatically on boot. Start the WireGuard service and check its status to make sure it is running.\nsystemctl enable wg-quick@wg0 systemctl start wg-quick@wg0 systemctl status wg-quick@wg0 If everything is working you should get an output similar to this\n● wg-quick@wg0.service - WireGuard via wg-quick(8) for wg0 Loaded: loaded (/lib/systemd/system/wg-quick@.service; enabled; vendor preset: enabled) Active: active (exited) since Mon 2023-03-13 04:02:58 UTC; 13ms ago Docs: man:wg-quick(8) man:wg(8) https:\u0026#47;\u0026#47;www.wireguard.com/ https://www.wireguard.com/quickstart/ https://git.zx2c4.com/wireguard-tools/about/src/man/wg-quick.8 https://git.zx2c4.com/wireguard-tools/about/src/man/wg.8 Process: 2662 ExecStart=/usr/bin/wg-quick up wg0 (code=exited, status=0/SUCCESS) Main PID: 2662 (code=exited, status=0/SUCCESS) CPU: 31ms Configure Client Once you have confirmed that WireGuard service is up and running, it is time to set up the first client. Start by creating a directory named after the client, and generating private and public key pair for the client. You can do it by running the following commands.\nmkdir /etc/wireguard/mac cd /etc/wireguard/mac wg genkey | tee mac-privatekey | wg pubkey \u003e mac-publickey Same as you did with the server\u0026#8217;s key pair get the content of the two files and put it in a place handy for copy and paste, as you will need to use it later.\ntail -n +1 mac-privatekey mac-publickey Content of public and private client keys\n==\u003e mac-privatekey \u0026lt;== cMLgt4BVDe+qtm+50QGVrPULXSYKU120yfSoywlv1nI= ==\u003e mac-publickey \u0026lt;== S/rtqRg8TSscZfgLluwOcidGH8iKjtZEVjj68QtiCkM= Create client configuration file wg0-mac.conf\nnano wg0-mac.conf Copy and paste the following configuration settings into the wg0-mac.conf file. Make sure to replace the \u0026#8220;PrivateKey\u0026#8221; value with the client\u0026#8217;s private key you generated in the previous step, and the \u0026#8220;PublicKey\u0026#8221; under [Peer] with the server\u0026#8217;s public key you generated earlier, also replace the value of \u0026#8220;Endpoint\u0026#8221; under [Peer] with your server\u0026#8217;s public IP or domain name. Your wg0-mac.conf file should look similar to this\n\u0026#91;Interface] PrivateKey = cMLgt4BVDe+qtm+50QGVrPULXSYKU120yfSoywlv1nI= Address = 10.16.0.2/24 DNS = 1.1.1.1, 8.8.8.8 \u0026#91;Peer] PublicKey = vaXI0PRL35MNjlfZSQSrTBVzmJZhGtPv9OmeFZW0hF0= AllowedIPs = 0.0.0.0/0 Endpoint = 158.101.116.201:51820 You can go ahead and save the changes and close the wg0-mac.conf file (Ctrl-x press Y press Enter). The next thing you need to do is, add your client to the server configuration file to allow for connection. To do that open the wg0.conf file.\nnano /etc/wireguard/wg0.conf Add the following configuration to the wg0.conf file, make sure to replace \u0026#8220;PublicKey\u0026#8221; with your client\u0026#8217;s public key.\n\u0026#91;Peer] PublicKey = S/rtqRg8TSscZfgLluwOcidGH8iKjtZEVjj68QtiCkM= AllowedIPs = 10.16.0.2/32 At this point your wg0.conf configuration file should look similar to this\n\u0026#91;Interface] Address = 10.16.0.1/32 ListenPort = 51820 PrivateKey = GK+wX0XxaUY9rlQOHCdF3teRZttWXADMVZ5eLfQa80c= \u0026#91;Peer] PublicKey = S/rtqRg8TSscZfgLluwOcidGH8iKjtZEVjj68QtiCkM= AllowedIPs = 10.16.0.2/32 Next, restart your WireGuard service and take a look at it with \u0026#8220;wg\u0026#8221; command.\nsystemctl restart wg-quick@wg0 wg You should see an output similar to the one below. You can see that your server has wg0 interface that is listening on port 51820, and you are allowing connections to one client with public key and IP that should match the public key and IP of your client.\ninterface: wg0 public key: vaXI0PRL35MNjlfZSQSrTBVzmJZhGtPv9OmeFZW0hF0= private key: (hidden) listening port: 51820 peer: S/rtqRg8TSscZfgLluwOcidGH8iKjtZEVjj68QtiCkM= allowed ips: 10.16.0.2/32 Firewall Rules and Configuration Next, you will have to make sure that your system has iptables installed. You can do it by running the following command\napt install iptables -y If iptables exists on your system you will get output similar to the one below, if it doesn\u0026#8217;t exist the above command will install it for you.\nReading package lists... Done Building dependency tree... Done Reading state information... Done iptables is already the newest version (1.8.7-1ubuntu5). iptables set to manually installed. 0 upgraded, 0 newly installed, 0 to remove and 45 not upgraded. After you confirm that you have iptables you will need to collect the name of your public facing network interface. You can do it by running the command below\nip link As you can see from the output below I have loopback interface \u0026#8220;lo\u0026#8221;, and WireGuard interface the \u0026#8220;wg0\u0026#8221;, which leaves me with \u0026#8220;enp0s3\u0026#8221; to be my public facing interface. If you have left more than one interface after you rule out \u0026#8220;lo\u0026#8221; and \u0026#8220;wg0\u0026#8221; you will need to do some more digging, but if you are like me and only have three, whichever is left is most likely your public facing interface. Take a note of it as you will need it in the next step.\n1: lo: \u0026lt;LOOPBACK,UP,LOWER_UP\u003e mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 2: enp0s3: \u0026lt;BROADCAST,MULTICAST,UP,LOWER_UP\u003e mtu 9000 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000 link/ether 02:00:17:09:39:e8 brd ff:ff:ff:ff:ff:ff 5: wg0: \u0026lt;POINTOPOINT,NOARP,UP,LOWER_UP\u003e mtu 8920 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000 link/none Now that you have confirmed that iptables is installed, and you have the name of your public facing interface. Go ahead, open your server configuration file wg0.conf and enter the following configuration in the [Interface] section of the file. Make sure to replace every occurrence of \u0026#8220;enp0s3\u0026#8221; with the name of your public facing interface (\u0026#8220;enp0s3\u0026#8221; appears six times in the lines below).\nPreUp = sysctl -w net.ipv4.ip_forward=1 PostUp = iptables -I INPUT -p udp --dport 51820 -j ACCEPT; iptables -t nat -I POSTROUTING 1 -s 10.16.0.0/24 -o enp0s3 -j MASQUERADE; iptables -I INPUT 1 -i wg0 -j ACCEPT; iptables -I FORWARD 1 -i enp0s3 -o wg0 -j ACCEPT; iptables -I FORWARD 1 -i wg0 -o enp0s3 -j ACCEPT PostDown = iptables -D INPUT -p udp --dport 51820 -j ACCEPT; iptables -t nat -D POSTROUTING 1 -s 10.16.0.0/24 -o enp0s3 -j MASQUERADE; iptables -D INPUT 1 -i wg0 -j ACCEPT; iptables -D FORWARD 1 -i enp0s3 -o wg0 -j ACCEPT; iptables -D FORWARD 1 -i wg0 -o enp0s3 -j ACCEPT This configuration will allow IP forwarding, it will open UDP port 51820, make sure all outgoing packets are translated via the VPN, it will allow all traffic on wg0 interface, and allow packets to forward between the public Interface and the WireGuard every time WireGuard service is started as well as it will reverse everything mentioned above when WireGuard service is stopped.\nNOTE: If your server is behind additional firewall or a solution that acts as a firewall such as AWS Security Group, OCI Network Security Group, etc. make sure to have port 51820 UDP open there as well.\nAt this point your wg0.conf file should be complete and it should look similar to this\n\u0026#91;Interface] Address = 10.16.0.1/32 ListenPort = 51820 PrivateKey = GK+wX0XxaUY9rlQOHCdF3teRZttWXADMVZ5eLfQa80c= PreUp = sysctl -w net.ipv4.ip_forward=1 PostUp = iptables -I INPUT -p udp --dport 51820 -j ACCEPT; iptables -t nat -I POSTROUTING 1 -s 10.16.0.0/24 -o enp0s3 -j MASQUERADE; iptables -I INPUT 1 -i wg0 -j ACCEPT; iptables -I FORWARD 1 -i enp0s3 -o wg0 -j ACCEPT; iptables -I FORWARD 1 -i wg0 -o enp0s3 -j ACCEPT PostDown = iptables -D INPUT -p udp --dport 51820 -j ACCEPT; iptables -t nat -D POSTROUTING 1 -s 10.16.0.0/24 -o enp0s3 -j MASQUERADE; iptables -D INPUT 1 -i wg0 -j ACCEPT; iptables -D FORWARD 1 -i enp0s3 -o wg0 -j ACCEPT; iptables -D FORWARD 1 -i wg0 -o enp0s3 -j ACCEPT \u0026#91;Peer] PublicKey = S/rtqRg8TSscZfgLluwOcidGH8iKjtZEVjj68QtiCkM= AllowedIPs = 10.16.0.2/32 Next restart WireGuard service to apply all the changes, and if you don\u0026#8217;t get any errors you are ready to test your VPN server by connecting to it with your client.\nsystemctl restart wg-quick@wg0 Connect Client to WireGuard VPN Server To test the connection you can download the client configuration file on your client, and load it into the WireGuard Client application by clicking on import tunnel from a file and providing the path to the client\u0026#8217;s configuration file.\nOr click on the + in the bottom right corner of WireGuard Client application and select Add Empty Tunnel.\nRemove the pre-existing \u0026#8220;PrivateKey\u0026#8221; from Add Empty Tunnel window and paste the content of your client\u0026#8217;s configuration file wg0-mac.conf. You can get the content of the file by running the following command\ncat /etc/wireguard/mac/wg0-mac.conf Once you paste the client\u0026#8217;s configuration in the WireGuard Client App give your tunnel a name go ahead and click \u0026#8220;Save\u0026#8221;\nOnce you have your tunnel saved you can go ahead and Activate your VPN At this point the status of your connection should change to \u0026#8220;Active\u0026#8221;, turn green and you should see the data flowing.\nTo confirm that your VPN is working as expected, on your client open a web browser of your choice and search Google for \u0026#8220;what\u0026#8217;s my IP\u0026#8221;. The result should show the public IP address of your VPN server.\nConfigure Additional Clients To add additional clients repeat every step of the Configure Client section, make sure to assign the new clients an IP address that has not been assigned to another client.\nClient Configuration on Mobile Device In addition to creating an empty tunnel and pasting all the configuration in it like we did earlier, or downloading the configuration file, mobile devices have the option to set up a new tunnel by scanning a QR code. To get a tool that will allow you to generate client configuration QR code run the following commands\napt-get install qrencode -y After you have \u0026#8220;qrencode\u0026#8221; installed you can use your client\u0026#8217;s configuration file to generate QR code by running the following command.\nqrencode -t ansiutf8 -l L \u0026lt; /etc/wireguard/mac/wg0-mac.conf The output of this command should produce QR code that you can scan with your WireGuard mobile app.\n","keywords":["install","wireguard","ubuntu","server"],"permalink":"https://techtutelage.net/install-wireguard-vpn-on-ubuntu-server/","summary":"Install and configure a WireGuard VPN on a headless Ubuntu server: generate keys, set firewall rules and connect desktop and mobile clients. Video included.","title":"Install WireGuard VPN on Ubuntu Server"},{"content":" Open the Terminal window of your mac by clicking the Launchpad icon in the Dock, then type Terminal in the search field, and click on Terminal. Once you have the terminal open make sure the USB device you are planning to use is unplugged, run the following command to get a list of all drives currently attached to your mac.\nsudo diskutil list You should get output similar to what you see below.\n/dev/disk0 (internal, physical): #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *500.3 GB disk0 1: EFI ⁨EFI⁩ 209.7 MB disk0s1 2: Apple_APFS ⁨Container disk1⁩ 499.9 GB disk0s2 /dev/disk1 (synthesized): #: TYPE NAME SIZE IDENTIFIER 0: APFS Container Scheme - +499.9 GB disk1 Physical Store disk0s2 1: APFS Volume ⁨Macintosh HD - Data⁩ 347.4 GB disk1s1 2: APFS Volume ⁨Preboot⁩ 660.9 MB disk1s2 3: APFS Volume ⁨Recovery⁩ 1.1 GB disk1s3 4: APFS Volume ⁨VM⁩ 2.1 GB disk1s4 5: APFS Volume ⁨Macintosh HD⁩ 15.4 GB disk1s5 6: APFS Snapshot ⁨com.apple.os.update-...⁩ 15.4 GB disk1s5s1 /dev/disk3 (external, physical): #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *15.8 GB disk3 1: EFI ⁨EFI⁩ 209.7 MB disk3s1 2: Microsoft Basic Data ⁨USB⁩ 15.6 GB disk3s2 Take a note of what storage devices you have currently connected, then plug in the USB device you intend to use and run the \u0026#8220;diskutil list\u0026#8221; command again.\nsudo diskutil list This time your list should include the newly connected USB device. As you can see below our new device is \u0026#8220;/dev/disk3\u0026#8221;. This extra step might seem unnecessary, but trust me it is worth doing it. I can\u0026#8217;t tell you how many times I\u0026#8217;ve wiped the wrong USB because I was pretty darn sure it was \u0026#8220;/dev/disk2\u0026#8221;, that I intended to use ;).\n/dev/disk0 (internal, physical): #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *500.3 GB disk0 1: EFI ⁨EFI⁩ 209.7 MB disk0s1 2: Apple_APFS ⁨Container disk1⁩ 499.9 GB disk0s2 /dev/disk1 (synthesized): #: TYPE NAME SIZE IDENTIFIER 0: APFS Container Scheme - +499.9 GB disk1 Physical Store disk0s2 1: APFS Volume ⁨Macintosh HD - Data⁩ 347.4 GB disk1s1 2: APFS Volume ⁨Preboot⁩ 660.9 MB disk1s2 3: APFS Volume ⁨Recovery⁩ 1.1 GB disk1s3 4: APFS Volume ⁨VM⁩ 2.1 GB disk1s4 5: APFS Volume ⁨Macintosh HD⁩ 15.4 GB disk1s5 6: APFS Snapshot ⁨com.apple.os.update-...⁩ 15.4 GB disk1s5s1 /dev/disk2 (external, physical): #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *15.4 GB disk2 1: EFI ⁨EFI⁩ 209.7 MB disk2s1 2: Microsoft Basic Data ⁨USB⁩ 15.2 GB disk2s2 /dev/disk3 (external, physical): #: TYPE NAME SIZE IDENTIFIER 0: GUID_partition_scheme *15.8 GB disk3 1: EFI ⁨EFI⁩ 209.7 MB disk3s1 2: Microsoft Basic Data ⁨USB⁩ 15.6 GB disk3s2 Now that you know that you want to make bootable USB on \u0026#8220;/dev/disk3\u0026#8221; You can go ahead and download the source. For this example I will use .iso file with Debian 11, any other Linux system should work as well. To download it I will use the command below. You can obtain your .iso in your preferred way, just make sure to remember your download location.\ncurl -L -O https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/debian-11.6.0-amd64-netinst.iso Once you have your .iso file you can go ahead and make some final preparations before you make the USB bootable. First go ahead, and unmount it. Even though it is not required, it is a good practice to unmount your USB.\nsudo diskutil unmountDisk /dev/disk3 At this point you should be ready to make your USB bootable, to do it run the following command. Make sure to replace ./debian-11.6.0-amd64-netinst.iso with the path to your .iso file, and /dev/disk3 with the path to the USB you intend to turn to a bootable USB.\nsudo dd if=./debian-11.6.0-amd64-netinst.iso of=/dev/disk3 bs=1m The whole process could take a while depending on the size of the .iso you are using, and the speed of your computer. Once you are done you should see similar output.\n388+0 records in 388+0 records out 406847488 bytes transferred in 94.024237 secs (4327049 bytes/sec) Also your Mac will give you the following warning, you can go ahead and click on Eject.\nYour Bootable USB should be ready to use now!\n","keywords":["create","bootable","usb","from","iso","mac"],"permalink":"https://techtutelage.net/how-to-create-bootable-usb-from-iso-on-mac-using-terminal/","summary":"Create a bootable USB drive from an ISO on macOS using only Terminal: find the disk with diskutil, unmount it and write the image with dd. No extra apps.","title":"How to Create a Bootable USB from an ISO on Mac Using Terminal"},{"content":" Get your Always Free Oracle Cloud Server ready To get your OCI server ready for hosting a WordPress site you will need to complete the following steps. Log in to your Oracle Cloud Console, launch a new instance, open ports 80 and 443 in your default security list, reserve free public IP and assign the IP to your virtual server. If you need help with any of it you can use my video tutorial above to follow along.\nCreate public DNS record The exact process in this step will depend on who your Domain Name provider is. Luckily the concept is the same, and all you need to do is create an A record that points your domain to the reserved IP you have assigned to your virtual server on Oracle Cloud. In my video tutorial I am creating a DNS record with Namecheap, the process should be similar with other providers.\nOpen ports 80 HTTP and 443 HTTPS in iptables Iptables is by default installed and active on Ubuntu server on Oracle Cloud, and you will need to take an extra step and open ports 80 and 443 on it as well. You can do it by running the following commands.\niptables -I INPUT -p tcp -m tcp --dport 80 -j ACCEPT iptables -I INPUT -p tcp -m tcp --dport 443 -j ACCEPT iptables-save \u0026gt; /etc/iptables/rules.v4 Install Prerequisites (PHP, MariaDB, PHP modules, etc.) You will need to run the commands below to update your system, and install the listed packages as they are required by WordPress.\napt update \u0026amp;\u0026amp; apt -y upgrade apt install apache2 ghostscript libapache2-mod-php mariadb-server php php-bcmath php-curl php-imagick php-intl php-json php-mbstring php-mysql php-xml php-zip wget unzip Configure MariaDB Database Connect to MariaDB database server.\nsudo mysql -u root -p Once you connect successfully to the database server, create WordPress database and user. You can do it by running the following commands. Make sure to replace \u0026#8220;password1\u0026#8221; with a stronger, more secure password.\nCREATE DATABASE wp_db; CREATE USER wp_user@localhost IDENTIFIED BY 'password1'; GRANT SELECT,INSERT,UPDATE,DELETE,CREATE,DROP,ALTER ON wp_db.* TO wp_user@localhost; FLUSH PRIVILEGES; quit Install WordPress The next step would be to download, install, and set appropriate file permissions on latest WordPress. To do that, run the following commands.\nwget https://wordpress.org/latest.zip unzip latest.zip mv wordpress/ /var/www/html/ chown www-data:www-data -R /var/www/html/wordpress/ chmod -R 755 /var/www/html/wordpress/ Configure Apache Virtual Host Create new vhost in \u0026#8220;/etc/apache2/sites-available/\u0026#8221; by running the command below.\nnano /etc/apache2/sites-available/wordpress.conf Add the content from the box below to your wordpress.conf make sure to replace the ServerName directive with your domain name. That will be the same name you created public record for in the \u0026#8220;Create public DNS record\u0026#8221; step.\n\u0026lt;VirtualHost *:80\u0026gt; DocumentRoot /var/www/html/wordpress/ ServerName wp.techtutelage.net \u0026lt;Directory /var/www/html/wordpress/\u0026gt; Options FollowSymLinks AllowOverride All Require all granted \u0026lt;/Directory\u0026gt; ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined \u0026lt;/VirtualHost\u0026gt; Once you have your vhost file created go ahead and disable the default virtual host, enable the virtual host you just created, along with the Apache rewrite module by running the following commands.\na2dissite 000-default a2ensite wordpress a2enmod rewrite service apache2 reload Complete WordPress Installation At this point you should be able to access your WordPress installation page in your web browser. Once there you can follow along the installation wizard. If you need assistance you can use my video tutorial and follow along.\nGet Free Let\u0026#8217;s Encrypt SSL Certificate The easiest way to get free Let\u0026#8217;s Encrypt Certificate and secure your WordPress site is to use apache plugin \u0026#8220;python3-certbot-apache\u0026#8221;. To get the plugin and install certificates run the following commands.\napt install python3-certbot-apache certbot --apache Follow the onscreen instructions to complete SSL certificate creation and installation.\nFor more details and to see this setup in action check out my video on YouTube:\n","keywords":["host","wordpress","for","free","oracle","cloud"],"permalink":"https://techtutelage.net/host-wordpress-for-free-on-always-free-oracle-cloud-server/","summary":"Host WordPress for free on an Always Free Oracle Cloud server: DNS, iptables, Apache, PHP, MariaDB and a free Let’s Encrypt SSL certificate, step by step.","title":"Host WordPress for Free on an Always Free Oracle Cloud Server"},{"content":" Install the latest version of Java JDK To install the latest version of JDK on macOS follow the steps outlined below:\nFirst, check to see if you already have Java installed on your system. To do so, open the terminal window of your mac by clicking the Launchpad icon in the Dock, then type Terminal in the search field, and click on Terminal. Once you have the terminal open run the following command.\njava --version If Java is not installed on your system, you will see a message that looks something like this.\nThe operation couldn’t be completed. Unable to locate a Java Runtime. Please visit http://www.java.com for information on installing Java. Otherwise you will see a message similar to the message below, in this case we can see that the system has Java 17 installed.\njava 17.0.4.1 2022-08-18 LTS Java(TM) SE Runtime Environment (build 17.0.4.1+1-LTS-2) Java HotSpot(TM) 64-Bit Server VM (build 17.0.4.1+1-LTS-2, mixed mode, sharing) To download and install the latest version of Java, in your browser go to Java Downloads Oracle. Select the latest version of Java (currently 19), the operating system (macOS), and the architecture of your Mac. If you are on Intel based Mac select x64 DMG Installer, if you are on Apple Silicon select Arm 64 DMG Installer.\nOnce you have the Installer .dmg file downloaded, double-click on it to open then double click on the JDK package to start the installation. In the installation window click\u0026nbsp;Continue and\u0026nbsp;Install. A window will appear and it will ask you for user name and password. Enter the Administrator user name and password and click\u0026nbsp;Install Software. Once the software is installed a confirmation window will display, click on Cancel. You will be prompted to delete the installer, at this point you can go ahead and delete it if you want to save disk space.\nGo back to the terminal window and run\njava --version This time the result should show that you have installed the latest version of Java.\njava 19.0.2 2023-01-17 Java(TM) SE Runtime Environment (build 19.0.2+7-44) Java HotSpot(TM) 64-Bit Server VM (build 19.0.2+7-44, mixed mode, sharing) Change the default version of Java First get a list of all the installed Java versions on your Mac by running the following command\n/usr/libexec/java_home -V The result should look similar to this\nMatching Java Virtual Machines (2): 19.0.2 (x86_64) \"Oracle Corporation\" - \"Java SE 19.0.2\" /Library/Java/JavaVirtualMachines/jdk-19.jdk/Contents/Home 17.0.6 (x86_64) \"Oracle Corporation\" - \"Java SE 17.0.6\" /Library/Java/JavaVirtualMachines/jdk-17.jdk/Contents/Home To temporarily switch the default Java version to 17 (only for the current terminal session). Run the following command.\nexport JAVA_HOME='/usr/libexec/java_home -v 17' To make the change permanent run\nexport JAVA_HOME=$(/usr/libexec/java_home -v 17) Remove/Uninstall Java from Mac Note: Never uninstall Java by removing the Java tools from /usr/bin First, open your Terminal window and run the following commands\ncd /Library/Java/JavaVirtualMachines ls -l /Library/Java/JavaVirtualMachines This will show you the versions of Java currently installed on your Mac. drwxr-xr-x 3 root wheel 96 Mar 12 01:56 jdk-17.jdk drwxr-xr-x 3 root wheel 96 Mar 12 21:39 jdk-19.jdk To uninstall Java, all you need to do is remove the directory for the version you want uninstalled by executing the following command.\nsudo rm -rf jdk-19.jd ","keywords":["change","default","java","version","mac"],"permalink":"https://techtutelage.net/install-uninstall-and-change-default-java-jdk-version-on-macos/","summary":"Install the latest Java JDK on macOS, switch the default Java version with JAVA_HOME and uninstall JDKs you no longer need, all from the Terminal.","title":"Install and Set the Default Java JDK Version on macOS"},{"content":"Run a Minecraft Java Edition server for free on an Oracle Cloud Always Free instance. Below are the commands from the video, in the order they are used: open port 25565, install Java, download the server, accept the EULA, and keep it running inside a screen session.\nThe commands listed below were used in the video above: Add the line below to \u0026#8220;/etc/iptables/rules.v4\u0026#8221;\n-A INPUT -p tcp -m state --state NEW -m tcp --dport 25565 -j ACCEPT Reload iptables config\niptables-restore \u0026lt; /etc/iptables/rules.v4 Install Java Runtime 17\nadd-apt-repository ppa:openjdk-r/ppa apt update apt install openjdk-17-jre-headless Create installation/home directory for Minecraft Server\nmkdir /opt/minecraft \u0026amp;\u0026amp; cd /opt/minecraft Download Minecraft Server (v1.19 at time of the recording replace version with latest)\nwget https://launcher.mojang.com/v1/objects/e00c4052dac1d59a1188b2aa9d5a87113aaf1122/server.jar mv server.jar minecraft_server.1.19.jar To avoid server shutdown when ssh connection to the server is closed start screen session named \u0026#8220;Minecraft\u0026#8221;\nscreen -S \"Minecraft\" Start Minecraft Server (Will fail, need to accept EULA)\njava -Xmx8G -Xms2G -jar minecraft_server.1.19.jar nogui To accept EULA go to \u0026#8220;/opt/minecraft/eula.txt\u0026#8221; set eula=true\nStart Minecraft Server.\njava -Xmx8G -Xms2G -jar minecraft_server.1.19.jar nogui Detach from screen session Minecraft Ctrl + A + D\nTo list open screen sessions run\nscreen -list To attach to screen session run. Replace SessionID with your session id\nscreen -r SessionID If you find this tutorial helpful, you can support me by subscribing to my channel and leaving a comment. SUBSCRIBE ","keywords":["free","minecraft","server","oracle","cloud"],"permalink":"https://techtutelage.net/free-minecraft-server-on-oracle-cloud-free-tier/","summary":"Run a free Minecraft Java server on Oracle Cloud’s Always Free tier: open port 25565, install Java 17 and keep the server running in a screen session.","title":"Free Minecraft Server on Oracle Cloud Free Tier"},{"content":"OCFS2 (Oracle Cluster File System 2) is a shared-disk cluster file system: it lets several Linux servers mount the same block volume and read and write to it at the same time. The commands below set it up on Ubuntu compute instances on Oracle Cloud, exactly as shown in the video.\nWARNING!!!: This is not a tutorial. This article contains only the commands executed in the above video. For full step-by-step tutorial watch the video above!\nBelow you can find all commands used in the video. IMPORTANT: Each command must be executed on every node that will be a part of the cluster! Open /etc/iptables/rules.v4 and add rule to open port 7777. iptables-restore \u0026lt; /etc/iptables/rules.v4 \u0026#8211; Reload iptables config file. apt install ocfs2-tools \u0026#8211; Install ocfs2. uname -r \u0026#8211; Get kernel version. apt install linux-modules-extra-X \u0026#8211; Install kernel modules (make sure to replace X with your kernel version number). o2cb add-cluster ocfs2 \u0026#8211; Create /etc/ocfs2/cluster.conf file and sets cluster named ocfs2. o2cb add-node ocfs2 NODE_NAME \u0026#8211;ip PRIVATE_IP \u0026#8211; Adds node to the cluster.conf run once for each node on every node. cat /etc/ocfs2/cluster.conf \u0026#8211; Examine cluster configuration file. dpkg-reconfigure ocfs2-tools \u0026#8211; Configure the cluster settings. service o2cb start \u0026#8211; Start the cluster. systemctl enable o2cb \u0026#8211; Make service start on boot. systemctl enable ocfs2 \u0026#8211; Make service start on boot sysctl kernel.panic=30 \u0026#8211; Run this to set for kernel to work properly per Oracle sysctl kernel.panic_on_oops=1 \u0026#8211; Run this to set for kernel to work properly per Oracle Open /etc/sysctl.conf and append the two lines below to the end of the file. kernel.panic=30 kernel.panic_on_oops=1 mkfs.ocfs2 -L \u0026#8220;my_ocfs2_vol\u0026#8221; /dev/sdb \u0026#8211; Format your block storage. mkdir /sharedstorage \u0026#8211; Make mount point Add the line below to /etc/fstab per Oracle replace /dev/sdb with UUID /dev/sdb /sharedstorage ocfs2 _netdev,defaults 0 0 blkid \u0026#8211; Get UUID mount -a \u0026#8211; Reload fstab and remount everything listed in it. o2cb register-cluster ocfs2 \u0026#8211; Register cluster.\n","keywords":["ocfs2","oracle","cloud","block","volume"],"permalink":"https://techtutelage.net/attach-a-block-volume-to-multiple-ubuntu-compute-instances-on-oracle-cloud-with-cluster-aware-ocfs2/","summary":"Commands to attach one Oracle Cloud block volume to multiple Ubuntu instances using the cluster-aware OCFS2 file system. Follow along with the video.","title":"Attach a Block Volume to Multiple Ubuntu Instances on Oracle Cloud with OCFS2"},{"content":" To install Homebrew on your macOS start by opening your Terminal. You can find Terminal in the Utilities folder within the Applications folder, or you can use Spotlight Search (Cmd + Space) to search for \u0026#8220;Terminal\u0026#8221;. Once you have the Terminal open you can install Homebrew by running the following command.\n/bin/bash -c \"$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\" This command will download and run the Homebrew installation script. The script will prompt you to enter your password. After you enter it, wait for the installation to complete. Homebrew will be installed in the /usr/local directory for macOS Intel, and /opt/homebrew\u0026nbsp;for Apple Silicon. After the installation, you can verify if Homebrew is correctly installed by typing the following command in the Terminal.\nbrew --version This command will display the version of Homebrew installed on your Mac.\nThat\u0026#8217;s it! Homebrew is now installed on your Mac. If you want to learn how to use Homebrew to install, remove and update packages and software on your system, go ahead and watch my detailed tutorial on YouTube. https://youtu.be/QfGIjQCrG3M\n","keywords":["install","homebrew","macos"],"permalink":"https://techtutelage.net/how-to-install-homebrew-on-macos/","summary":"Install Homebrew on macOS with one Terminal command, learn where it installs on Apple Silicon vs Intel Macs and verify it works with brew –version.","title":"How to Install Homebrew on macOS"}]