<?xml version="1.0" encoding="utf-8"?>
<!-- generator="wordpress/2.2.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Bulbous, Not Tapered</title>
	<link>http://mikelococo.com</link>
	<description>Foo-Fu and other favorites...</description>
	<pubDate>Mon, 24 Mar 2008 04:12:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>
	<language>en</language>
			<item>
		<title>Fedora 8 on a Dell Latitude D620</title>
		<link>http://mikelococo.com/2008/03/fedora8-on-d620/</link>
		<comments>http://mikelococo.com/2008/03/fedora8-on-d620/#comments</comments>
		<pubDate>Mon, 24 Mar 2008 04:12:35 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2008/03/fedora8-on-d620/</guid>
		<description><![CDATA[Preface regarding comments and questions:  Mikelococo.com is not a general linux support forum, please visit someplace like fedoraforum.org for generic linux questions.  Comments that do not advance the community dialog regarding how to configure F8 on the D620 for optimal hardware support will be deleted in the moderation process.
Fedora 8 works quite well [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Preface regarding comments and questions</strong>:  Mikelococo.com is not a general linux support forum, please visit someplace like <a href="http://fedoraforum.org/">fedoraforum.org</a> for generic linux questions.  Comments that do not advance the community dialog regarding how to configure F8 on the D620 for optimal hardware support will be deleted in the moderation process.</p>
<p>Fedora 8 works quite well on the D620 right out of the box, and with a few tweaks can be just about fully supported.  This guide summarizes what I&#8217;ve done to get things working to my satisfaction.  It is not a step by step howto, but does attempt to link to more detailed resources when they are available.  The table below shows at a glance what is and isn&#8217;t working well on my system.  Green items worked immediately after install without manual intervention, yellow items were made fully functional after some manual configuration, red items have significant unsolved issues associated with them.</p>
<table border="0" cellpadding="3">
<tr>
<td bgcolor="#66ff66">Dual-core Processor</td>
<td bgcolor="#e9e9e9">Both cores are detected on the 2.17GHz Intel Core Duo processor, the 32bit i686 smp kernel is installed and just works.  Dynamic CPU frequency scaling works well and if you wish to monitor/change the scaling behavior there&#8217;s a gnome panel applet to do so. I haven&#8217;t tried the 64 bit build, but most reports I&#8217;ve read indicate that it works well.</td>
</tr>
<tr>
<td bgcolor="#66ff66">USB</td>
<td bgcolor="#f0f0f0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66ff66">PCMCIA Slot</td>
<td bgcolor="#e9e9e9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Touchpad/Track Stick</td>
<td bgcolor="#f0f0f0">Works, no config needed.  Install <a href="http://gsynaptics.sourceforge.jp/">gsynaptics</a> from Extras if you want to customize the trackpad behavior.</td>
</tr>
<tr>
<td bgcolor="#ffff66">Suspend to Ram</td>
<td bgcolor="#e9e9e9">How this works will depend on the options you ordered your laptop with and the video drivers you&#8217;re using. My understanding is that it will work fine out of the box with Intel graphics or if you&#8217;re using the open source NV drivers with your NVidia card, however both of these options have fairly poor 3D performance. With some tweaking, suspend can also be made to work when using the proprietary drivers that will allow you to have strong 3D performance with one of the Quadro cards offered in the D620. <a href="http://www.clasohm.com/blog/one-entry?entry_id=56860">Classohm.org has detailed instructions</a> (for the D800/F7, but they apply here as well). Since the NVidia cards offered in the D620 are PCI-E and not AGP, you can skip the AGP tweaks and just create the scripts in /etc/pm/config.d/. I&#8217;ve tested suspend with kernel 2.6.23.9-85/smp.</td>
</tr>
<tr>
<td bgcolor="#cccccc">Hibernate to Disk</td>
<td bgcolor="#f0f0f0">Untested, please report if this works out of the box or if you have a link with instructions on any required tweaking.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Ethernet</td>
<td bgcolor="#e9e9e9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Wireless Networking</td>
<td bgcolor="#f0f0f0">I didn&#8217;t have to jump through any hoops, other than to <a href="http://fedoraproject.org/wiki/Tools/NetworkManager#head-fc3fe44e92c63867615113b1ef69cf4fc0dc03cf">enable the network manager applet</a> in order to avoid using iwconfig from the terminal all the time.  <a href="http://klamstwo.org/evad/archives/51">Dawid Lorenz reports trouble that he solved</a> by switching from the built in iwl3945 to the freshrpm&#8217;s ipw3945, which have worked well for me on previous versions of Fedora. Note that the <a href="http://mikelococo.com/2006/10/fc5-on-d620/">awful Broadcom 4310</a> required ndis-wrapper to be supported in past versions of Fedora, I&#8217;m not certain what state it&#8217;s in today.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Bluetooth</td>
<td bgcolor="#e9e9e9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66ff66">2D Video</td>
<td bgcolor="#f0f0f0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#ffff66">3D Acceleration</td>
<td bgcolor="#e9e9e9">The NVidia Quadro 110M works well after installing nvidia-x11-drv from freshrpms, bumping glxgears performance from ~900fps to ~2300fps.  Don&#8217;t forget to install kernel-devel for your kernel version and reboot. Note that installing the proprietary drivers will bork suspend/resume until you fix it using the instructions above.</td>
</tr>
<tr>
<td bgcolor="#ffff66">External Monitor</td>
<td bgcolor="#f0f0f0">If all you want is to switch to the external output instead of the internal LCD, you can do so easily right out of the box.  Use the screen resolution control panel to set your resolution, and Fn-F8 to toggle between the displays.  If you choose to install the NVidia driver, it includes a simple dialog for setting up multimonitor support using TwinView.  TwinView isn&#8217;t perfect, windows maximize dumbly (across both displays) and if the resolutions of the two monitors are mismatched there&#8217;s an area where it&#8217;s possible to move the mouse and place windows that doesn&#8217;t show up in any monitor.  All in all, it&#8217;s a bit lame but does get the job done in a pinch.</td>
</tr>
<tr>
<td bgcolor="#66ff66">CD/DVD Burning</td>
<td bgcolor="#e9e9e9">Works out of the box. At one time <a href="http://www.fedoraforum.org/forum/showthread.php?t=114586">this tweak</a> substantially improved burn speed and system responsiveness while burning, I haven&#8217;t tested to determine if it&#8217;s still needed. Post a comment if you&#8217;ve done testing.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Sound Playback</td>
<td bgcolor="#f0f0f0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Sound Recording</td>
<td bgcolor="#e9e9e9">Works, no config needed.  If you&#8217;re not getting recorded sound, check the Volume Control app to make sure that capture is enabled and the recording level isn&#8217;t way down.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Volume Keys</td>
<td bgcolor="#f0f0f0">Now work out of the box. You can mess with the key bindings in System &#8211;&gt; Preferences &#8211;&gt; Keyboard shortcuts but they control volume without any tweaking now.</td>
</tr>
<tr>
<td bgcolor="#66ff66">Radio On/Off Switch</td>
<td bgcolor="#e9e9e9">Works fine, and has a noticeable effect on battery life.  You may need to &#8220;up&#8221; the interface with the connection manager of your choice if you enable the radio while the system is running.</td>
</tr>
<tr>
<td bgcolor="#66ff66">ACPI Power Management</td>
<td bgcolor="#f0f0f0">All the power management features work (fan speed autoadjusts, cpu frequency scaling works, there&#8217;s a gnome applet to easily control it).</td>
</tr>
<tr>
<td bgcolor="#cccccc">Fingerprint Reader</td>
<td bgcolor="#e9e9e9">Untested.</td>
</tr>
<tr>
<td bgcolor="#cccccc">Modem</td>
<td bgcolor="#f0f0f0">Untested.</td>
</tr>
</table>
<h3>Output of lspci</h3>
<p><center><textarea wrap="off" rows="20" cols="70" readonly="readonly">00:00.0 Host bridge: Intel Corporation Mobile 945GM/PM/GMS, 943/940GML and 945GT Express Memory Controller Hub (rev 03)<br /> 00:01.0 PCI bridge: Intel Corporation Mobile 945GM/PM/GMS, 943/940GML and 945GT Express PCI Express Root Port (rev 03)<br /> 00:1b.0 Audio device: Intel Corporation 82801G (ICH7 Family) High Definition Audio Controller (rev 01)<br /> 00:1c.0 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 1 (rev 01)<br /> 00:1c.1 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 2 (rev 01)<br /> 00:1c.2 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 3 (rev 01)<br /> 00:1d.0 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #1 (rev 01)<br /> 00:1d.1 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #2 (rev 01)<br /> 00:1d.2 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #3 (rev 01)<br /> 00:1d.3 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI Controller #4 (rev 01)<br /> 00:1d.7 USB Controller: Intel Corporation 82801G (ICH7 Family) USB2 EHCI Controller (rev 01)<br /> 00:1e.0 PCI bridge: Intel Corporation 82801 Mobile PCI Bridge (rev e1)<br /> 00:1f.0 ISA bridge: Intel Corporation 82801GBM (ICH7-M) LPC Interface Bridge (rev 01)<br /> 00:1f.2 IDE interface: Intel Corporation 82801GBM/GHM (ICH7 Family) SATA IDE Controller (rev 01)<br /> 00:1f.3 SMBus: Intel Corporation 82801G (ICH7 Family) SMBus Controller (rev 01)<br /> 00.0 VGA compatible controller: nVidia Corporation G72M [Quadro NVS 110M/GeForce Go 7300] (rev a1)<br /> 03:01.0 CardBus bridge: O2 Micro, Inc. OZ601/6912/711E0 CardBus/SmartCardBus Controller (rev 40)<br /> 09:00.0 Ethernet controller: Broadcom Corporation NetXtreme BCM5752 Gigabit Ethernet PCI Express (rev 02)<br /> 0c:00.0 Network controller: Intel Corporation PRO/Wireless 3945ABG Network Connection (rev 02)</textarea></center></p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2008/03/fedora8-on-d620/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Multihop SSH with Putty/WinSCP</title>
		<link>http://mikelococo.com/2008/01/multihop-ssh/</link>
		<comments>http://mikelococo.com/2008/01/multihop-ssh/#comments</comments>
		<pubDate>Thu, 10 Jan 2008 04:38:41 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2008/01/multihop-ssh/</guid>
		<description><![CDATA[Introduction
It&#8217;s not always possible to ssh to a host directly.  Many networks require high-value systems to be accessed via an intermediate bastion/proxy host that receives extra attention in terms of security controls and log monitoring.  The added security provided by this connection bouncing comes with a cost in convenience, though.  It requires [...]]]></description>
			<content:encoded><![CDATA[<h3>Introduction</h3>
<p>It&#8217;s not always possible to ssh to a host directly.  Many networks require high-value systems to be accessed via an intermediate bastion/proxy host that receives extra attention in terms of security controls and log monitoring.  The added security provided by this connection bouncing comes with a cost in convenience, though.  It requires multiple logins to access the protected systems and substantially complicates scp/stfp file transfers.</p>
<p>Fortunately, there are a number of ways to automate connection bouncing and make it as convenient as direct connection.  There are already a number of web-sites detailing the approaches to this issue, and I won&#8217;t repeat their contents, to get a broad overview of the topic read the following:</p>
<ul>
<li><a href="http://www.hackinglinuxexposed.com/articles/20040830.html">SSH Bouncing Part 1</a> from Hacking Linux Exposed</li>
<li><a href="http://www.hackinglinuxexposed.com/articles/20040923.html">SSH Bouncing Part 2</a> from Hacking Linux Exposed</li>
<li><a href="http://samba.anu.edu.au/rsync/firewall.html">Using rsync through a firewall</a>, the concepts in this document apply to all SSH setups, not just those integrating rsync</li>
</ul>
<h3>Terminology</h3>
<h4>SSH Connection &#8220;Chaining&#8221;</h4>
<p>Connection &#8220;chaining&#8221; refers to any approach that involves sshing to an intermediate host, and then sshing from the intermediate host to the next host (for example: <tt>ssh 1 &#8217;ssh 2 &#8220;ssh 3&#8243;&#8216;</tt>).  This solution is attractive for setups with many hops because it&#8217;s easy to extend, for example <a href="http://www.cskk.ezoshosting.com/cs/css/ssh.html#sshto__bangstyle_ssh_to_do_multihop_ssh">sshto</a> makes this very easy.  The primary disadvantage is that end-to-end encryption is lost.  The connection is decrypted by every host in the chain, and an attacker with sufficient privilege on an intermediate system can sniff the connection without compromising either of the endpoints.  I consider this to be a significant failing, and have a strong preference for &#8220;stacked&#8221; connections wherever they are logistically feasible.</p>
<h4>SSH Connection &#8220;Stacking&#8221;</h4>
<p>Connection &#8220;stacking&#8221; refers to any solution that involves tunneling ssh connections inside each other.  &#8220;Nesting&#8221; strikes me as a better term, but stacking seems to be more widely agreed upon. It is typically implemented with proxy-commands or with ssh port-forwarding.  It can be more difficult to manage for connections with many hops, and it forces one of the endpoints to bear the encryption load of all the connections (in chained setups, the load is spread evenly among all the hosts in the chain). It does maintain end-to-end encryption, preventing connection/credential sniffing by intermediate hosts.</p>
<h3>My Setup</h3>
<p>The key properties for my setup are:</p>
<ul>
<li>End-to-end encryption is maintained using stacked connections</li>
<li>Only a single intermediate host is involved, the proxy features I utilize do not trivially scale to longer connection paths</li>
<li>Putty is used for shell connections, and WinSCP is used for scp/sftp connections</li>
<li>No special software is required beyond a default Putty installation, WinSCP, and an SSH server with port forwarding enabled.  Specifically, netcat is not required on the intermediate host as is common with ProxyCommand setups.</li>
</ul>
<h4>WinSCP Config</h4>
<p>The WinSCP Config is quite simple and utilizes its &#8220;tunnel&#8221; feature.  Open WinSCP and configure a saved session for the final destination host as follows:</p>
<ol>
<li> On the Session page, fill in the hostname and user name for the final destination host.  Leave the password blank.</li>
<li>Check the &#8220;Advanced options&#8221; box in the login dialog.</li>
<li>Select the Connection &#8211;&gt; Tunnel page.</li>
<li>Check the &#8220;Connect through SSH tunnel&#8221; box.</li>
<li>Fill in the Host name and user name of the intermediate host.  Leave the password blank.</li>
<li>Save the session using the button in the lower right-hand corner of the window.</li>
</ol>
<p>When you log in using the new profile, you will be prompted for two passwords.  The first is for your account on the intermediate host, and the second is for your account on the final-destination host.  After login, the bounce is entirely transparent and WinSCP works as if you had connected directly to the final-destination host.  The connection process can be made even more transparent and secure by using public key authentication with Pageant instead of passwords.</p>
<h4>Putty Config</h4>
<p>The Putty setup is slightly more complicated and requires that public key authentication be used on the intermediate host. It utilizes Putty&#8217;s &#8220;local proxy&#8221; feature, which allows you to specify an arbitrary command on the local machine to act as a proxy. Instead of creating a TCP connection, PuTTY will communicate using the proxy program&#8217;s standard input and output streams. Our local proxy will be plink, which is a command-line ssh connection program included in the Putty default installation. Plink&#8217;s -nc option provides functionality similar to the ProxyCommand/netcat approach, but does so using the ssh server&#8217;s native port-forwarding interface and does not require that netcat be installed on the intermediate system. To set things up, configure a saved session for the final destination host:</p>
<ol>
<li><a href="http://www.ualberta.ca/CNS/RESEARCH/LinuxClusters/pka-putty.html">Configure public key authentication</a> for the intermediate host and make sure it works.</li>
<li>Start putty and on the &#8220;Session&#8221; page of the &#8220;Putty Configuration Dialog&#8221; that appears, fill in the host name and user name for the final destination host.</li>
<li>Switch to the Connection &#8211;&gt; Proxy page, select &#8220;Local&#8221; as the proxy type enter the following as the local proxy command: <tt>plink.exe intermediate.proxy.host -l username -agent -nc %host:%port\n</tt></li>
<li>Save the session.</li>
</ol>
<p>If all is working properly, when you log in using the new profile plink will handle the login to the intermediate system silently. Putty isn&#8217;t smart enough to prompt if the proxy command requires user input, so you&#8217;ll get a connection error if public key authentication on the intermediate host isn&#8217;t working.  If you use password authentication on the final destination host you&#8217;ll be prompted for your password, or if you use pubkey authentication there as well you&#8217;ll land at a prompt with no fuss at all.</p>
<p>If you have trouble, make sure plink is executing properly. You may need to enter the full pathname, usually c:\program files\putty\plink.exe. You can also try executing the plink command from a prompt, remembering to substitute the %host and %port values of your final destination host.  If it&#8217;s working properly, you&#8217;ll be logged into the intermediate system with your pagean-cached private key, and instead of a prompt you&#8217;ll be presented with the SSH banner for your final destination system.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2008/01/multihop-ssh/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SSH Key Management and Presence</title>
		<link>http://mikelococo.com/2007/12/ssh-presence/</link>
		<comments>http://mikelococo.com/2007/12/ssh-presence/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 04:49:20 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2007/12/ssh-key-management-and-presence/</guid>
		<description><![CDATA[There are a number of excellent guides to setting up public key authentication for ssh, but they tend to stop short of describing how to integrate presence events like a screensaver turning on.  It&#8217;s a topic that isn&#8217;t possible to cover in a generic way, since it depends heavily on your operating system, distribution, [...]]]></description>
			<content:encoded><![CDATA[<p>There are a number of excellent guides to setting up public key authentication for ssh, but they tend to stop short of describing how to integrate presence events like a screensaver turning on.  It&#8217;s a topic that isn&#8217;t possible to cover in a generic way, since it depends heavily on your operating system, distribution, desktop environment, and preferred shell.  I present here the information I&#8217;ve pulled together to get things running under Linux, specifically Fedora 8 with Gnome and Bash.</p>
<p>First off, if you&#8217;re not already quite familiar public key authentication, go read the three part IBM developerWorks series on the topic (<a href="http://www.ibm.com/developerworks/library/l-keyc.html">1</a>,<a href="http://www.ibm.com/developerworks/library/l-keyc.html"> </a><a href="http://www.ibm.com/developerworks/library/l-keyc2/">2</a>, <a href="http://www.ibm.com/developerworks/linux/library/l-keyc3/">3</a>), which is the best primer I&#8217;ve found.  I&#8217;m using public key authentication with encrypted keys, am caching my credentials with ssh-agent, and am using keychain as my interface to ssh-agent. My primary goal was to automatically run <tt>keychain &#8211;clear</tt> to clear my credentials any time I left my system unattended.  I also outline how to run <tt>keychain ~/.ssh/id_rsa</tt> when you return to your system (or whenever you open a shell) in order to reload your ssh key.</p>
<h3>Login</h3>
<p>When I log in to my system, keychain runs and does some housekeeping.  It starts an ssh-agent process if one isn&#8217;t already running and prompts for the passwords to my ssh keys if they aren&#8217;t already loaded, or if all that has already been done it just reports its status and exits. The following lines can be placed in ~/.bash_profile which is executed when you log into your system (via remote ssh session, text console, and oddly enough gnome executes bash_profile on login as well).</p>
<pre>
if [ "$PS1" ]; then
   /usr/bin/keychain ~/.ssh/id_rsa
   source ~/.keychain/yourhostname-sh
fi</pre>
<p>The &#8220;if&#8221; statement ensures that keychain is only run for interactive shells.  Because keychain generates output on execution it can confuse some programs that run non-interactively, notably <a href="http://www.openssh.com/faq.html#2.9">sftp breaks</a> if you don&#8217;t do this.</p>
<h3>New Shell</h3>
<p>I actually like keychain to run <em>every</em> time I start a new shell, not just when I first log in. This means that I can clear my credentials manually if I won&#8217;t be using ssh for a while and when I open a fresh terminal window (or &#8220;window&#8221; in a screen session, or whatever) keychain automatically prompts me for my password.  This can be done by placing the same lines from above in ~/.bashrc instead of bash_profile (bashrc is executed from bash_profile, so you only need one or the other).</p>
<h3>Screensaver</h3>
<p>When my screensaver turns on, it&#8217;s an indication that I&#8217;m away from my desk and that my credentials should be cleared. To my knowledge, gnome-screensaver does not provide per-user screensaver-on and screensaver-off scripts where you can easily add these sorts of things (it should, if you ask me).  It does, however, emit a DBUS signal that you can listen for and act on. I found some folks using <a href="http://nxsy.org/blog/archives/2007/03/20/getting-amarok-to-pause-when-the-screen-locks-using-python-of-course#comment-5167">python scripts</a> to handle similar needs and adapted them for my purpose, others have done similar things with <a href="http://live.gnome.org/GnomeScreensaver/FrequentlyAskedQuestions#head-ac43c8f33bc700a5e298e6a82ded0e8bb9b33043">bash script</a>. Once you&#8217;ve customized your DBUS signal listener script, add it to your default gnome session using System &#8211;&gt; Preferences &#8211;&gt; Personal &#8211;&gt; Sessions so that it&#8217;s automatically started when you log in.</p>
<pre>
#!/usr/bin/python
import dbus
from dbus.mainloop.glib import DBusGMainLoop
import gobject
import os

def clear_keychain(state):
     """Called when screensaver on/off events occur"""

     # clear ssh keys when screensaver turns on
     if state == True:
          os.system('/usr/bin/keychain --clear')

     # Load ssh keys when screensaver turns off
     #     if state == False:
     #          os.system('/usr/bin/keychain id_rsa')

# Connect to the gnome session bus:
dbus.mainloop.glib.DBusGMainLoop(set_as_default=True)
bus = dbus.SessionBus()

# Listen for SessionIdleChanged signals
bus.add_signal_receiver(clear_keychain,'SessionIdleChanged','org.gnome.ScreenSaver')
loop = gobject.MainLoop()
loop.run()</pre>
<h3>Logout</h3>
<p>Logging out of the system (whether from a remote ssh session, a local text console, or a graphical gnome session) is an indication that my workstation is going to be idle for a while and that my credentials should be cleared. This can be (mostly) accomplished by making an addition to ~/.bash_logout. This file is run any time a non-gnome login shell exits, like a remote ssh session or a local text console session (but not terminal windows in gnome, screen windows, or other non-login shells):</p>
<pre>/usr/bin/keychain --clear</pre>
<p>For some utterly insane reason, gnome doesn&#8217;t execute bash_logout even though it <strong>does</strong> execute bash_profile on login, and it doesn&#8217;t provide a sane alternative.  The only method I&#8217;m aware of for running a script on gnome-logout involves xsession hackery, but I&#8217;ve punted on this issue since I rarely exit my gnome session. If you find an elegant solution, leave a comment.</p>
<h3>Other SSH Tips</h3>
<ul>
<li><strong>SSH Aliases:</strong> This is somewhat off-topic for this article, but is such a great timesaver that it bears a quick mention in any article about ssh. You can <a href="http://ubuntuforums.org/showpost.php?p=1068839&amp;postcount=3">define short names</a> for hosts you ssh to often in ~/.ssh/config.</li>
<li><strong>Clearing Credentials At Login:</strong> An alternative to all of this, and one of the strategies suggested in the developerWorks series is to start keychain with the &#8211;clear option in .bash_profile or wherever you call it from.  The assumption is that by clearing your credentials on login instead of logout, you can stay authenticated all the time (and gain the benefit of being able to run cron scripts) but an attacker will lose access to your credentials the moment they try to access your account.  It&#8217;s an interesting strategy, but not one I&#8217;m entirely comfortable with. I prefer to clear my credentials when they&#8217;re not being used, and designate special-purpose keys with appropriate <a href="http://ezine.daemonnews.org/200411/openssh.html">constraints</a> for <a href="http://troy.jdmz.net/rsync/index.html">cron jobs</a>.</li>
</ul>
<h3>Conclusion</h3>
<p>With the tips in the developerWorks series, and the information in this article, you can have an incredibly convenient ssh key management setup while you&#8217;re using your computer and know that your credentials will be automatically cleared when you&#8217;re away from your system.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2007/12/ssh-presence/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New York City?!!???!</title>
		<link>http://mikelococo.com/2007/04/new-york-city/</link>
		<comments>http://mikelococo.com/2007/04/new-york-city/#comments</comments>
		<pubDate>Sun, 15 Apr 2007 16:44:25 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2007/04/new-york-city/</guid>
		<description><![CDATA[Making good on the heels of my CISSP certification, I&#8217;m going to be joining the Security Services group at NYU in May as a Senior Network Security Analyst.  Security Services is charged to protect the entire NYU network, which provides connectivity to around 40,000 nodes.
I&#8217;m incredibly excited about the move.  Since my partner [...]]]></description>
			<content:encoded><![CDATA[<p>Making good on the heels of my <a href="http://mikelococo.com/2006/12/cissp-certification/">CISSP certification</a>, I&#8217;m going to be joining the <a href="http://www.nyu.edu/its/security/">Security Services group at NYU</a> in May as a Senior Network Security Analyst.  Security Services is charged to protect the entire NYU network, which provides connectivity to around 40,000 nodes.</p>
<p>I&#8217;m incredibly excited about the move.  Since my partner lives in New York, I&#8217;ve been job hunting there for almost a year and half and I&#8217;ve found that it&#8217;s a very competitive market.  I needed to do a lot of professional development in order to be considered seriously for the positions I wanted, and this was the most interesting position I saw or applied for in my entire search.  To have been hired into it just fantastic.</p>
<p>So anyhoo&#8230; I&#8217;ll be <a href="http://mikelococo.com/forsale/">selling</a> or <a href="http://mikelococo.com/freecycle/">giving away</a> most of my stuff this month so Laura, Kip, and I can fit into an apartment the size of a shoebox.  Have a gander if you need anything.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2007/04/new-york-city/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Poor Battery Life on Latitude D620</title>
		<link>http://mikelococo.com/2007/03/d620-battery-life/</link>
		<comments>http://mikelococo.com/2007/03/d620-battery-life/#comments</comments>
		<pubDate>Sun, 04 Mar 2007 20:21:55 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2007/03/d610-battery-life/</guid>
		<description><![CDATA[Dawid Lorenz, myself, and a number of other folks (read the comments on Dawid&#8217;s page, and also on the product pages for the D620 batteries) have all experienced poor battery life on Dell Latitude D620&#8217;s that are typically less than six months old.  There may or may not be a high failure rate for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://klamstwo.org/evad/archives/3">Dawid Lorenz</a>, <a href="http://mikelococo.com/2007/01/fc6-on-d620/">myself</a>, and a number of other folks (read the comments on Dawid&#8217;s page, and also on the product pages for the D620 batteries) have all experienced poor battery life on Dell Latitude D620&#8217;s that are typically less than six months old.  There may or may not be a high failure rate for this battery model, and this page details my experiences in diagnosing the health of my battery and obtaining a replacement under warranty.</p>
<h3>Determining Battery Health</h3>
<p>There are several methods of determining your battery&#8217;s capacity relative to it&#8217;s initial specification (aka &#8220;health&#8221;).</p>
<ul>
<li>Press and hold the status button located on the bottom of your battery.  The five LED lights will initially display your battery&#8217;s current charge (five lights is charged, zero lights is discharged), and if you continue pressing the status button for three seconds the lights will blink off and back on again, now displaying the health of your battery.  If zero lights appear your battery is operating at greater than 80% of its specified capacity, if five lights appear your battery is operating at less than 60% of its specified capacity.  This information was pulled from the <a href="http://support.dell.com/support/edocs/systems/latd620/en/UG/battery.htm">D620 User Guide</a>.</li>
<li>If you enter the system BIOS by pressing &#8220;F2&#8243; during the Dell logo while booting, there is a &#8220;Battery Health&#8221; option under the &#8220;Sytem&#8221; menu which gives a qualitative assessment of battery health.</li>
<li>The power manager under FC6 tracks the maximum capacity of your battery at its last full charge and generates a health percentage based on the factory spec charge for your battery.  To view this information, right-click the battery meter in your gnome panel, select &#8220;Information&#8221;, and expand the &#8220;More&#8221; area of the &#8220;Device Information&#8221; panel.</li>
<li>If you kept your initial Windows XP install, there is a battery health meter under the Dell Quickset applet in the lower right hand corner of the screen that gives the same information that is available through the system BIOS.</li>
</ul>
<h3>Obtaining a Replacement Battery</h3>
<p>Of course, you always have the option of purchasing a replacement battery from Dell (<a href="http://accessories.us.dell.com/sna/productdetail.aspx?c=us&#038;l=en&#038;cs=19&#038;sku=312-0386">9-cell</a> or <a href="http://accessories.us.dell.com/sna/productdetail.aspx?c=us&#038;l=en&#038;cs=19&#038;sku=312-0383">6-cell</a>), or simply living with degraded battery life.  There are some circumstances where you may be able to obtain a replacement under warranty, though.  If the BIOS/Quickset health gauges are showing the battery as failed even though it&#8217;s less than a year old, Dell will replace it under warranty.  According to the phone rep that I spoke to, a battery is considered to have failed when operating at less than 50% of its rated capacity.  When I called, my battery was five months old and operating at 50%-60% of it&#8217;s capacity (5 death lights, BIOS noted lowered battery life but did not pronounce failure, FC6 power manager rated health at 56%, observed battery life was 50%-60% of expected).  I was able to successfully make the case that the battery was clearly borderline and would certainly be replaced within a month or two, and that doing so now was an opportunity to provide excellent customer service whereas forcing me to wait would serve no purpose other than irritating me.  To his credit, the phone rep immediately acknowledged that my line of thinking was reasonable, spoke to a supervisor, and was able to authorize the early replacement.</p>
<h3>Conclusion</h3>
<p>I love my laptop, and in general I&#8217;m very happy with it.  It does look like there&#8217;s a trend toward premature battery failure, though, and if your situation is severe enough you may be eligible for a warranty replacement.  Once you&#8217;re replacement arrives, go read about how to <a href="http://klamstwo.org/evad/archives/34">monitor and optimize battery performance</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2007/03/d620-battery-life/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fedora Core 6 on a Dell Latitude D620</title>
		<link>http://mikelococo.com/2007/01/fc6-on-d620/</link>
		<comments>http://mikelococo.com/2007/01/fc6-on-d620/#comments</comments>
		<pubDate>Wed, 17 Jan 2007 05:04:39 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2007/01/fc6-on-d620/</guid>
		<description><![CDATA[Preface regarding comments and questions:  Mikelococo.com is not a general linux support forum, please visit someplace like fedoraforum.org for generic linux questions.  Comments that do not advance the community dialog regarding how to configure FC6 on the D620 for optimal hardware support will be deleted in the moderation process.
Dawid Lorenz already has a [...]]]></description>
			<content:encoded><![CDATA[<p><b>Preface regarding comments and questions</b>:  Mikelococo.com is not a general linux support forum, please visit someplace like <a href="http://fedoraforum.org/">fedoraforum.org</a> for generic linux questions.  Comments that do not advance the community dialog regarding how to configure FC6 on the D620 for optimal hardware support will be deleted in the moderation process.</p>
<p>Dawid Lorenz already has a very comprehensive set of notes on running <a href="http://klamstwo.org/evad/archives/3">Fedora Core 6 on the Dell Latitude D620</a>, but I&#8217;m going to drop in my two cents as well for variety&#8217;s sake.</p>
<p>FC6 works quite well on the D620 right out of the box, and with a few tweaks can be just about fully supported.  This guide summarizes what I&#8217;ve done to get things working to my satisfaction.  It is not a step by step howto, but does attempt to link to more detailed resources when they are available.  The table below shows at a glance what is and isn&#8217;t working well on my system.  Green items worked immediately after install without manual intervention, yellow items were made fully functional after some manual configuration, red items have significant unsolved issues associated with them.</p>
<table border=0 cellpadding=3>
<tr>
<td bgcolor="#66FF66">Dual-core Processor</td>
<td bgcolor="#E9E9E9">Both cores are detected on the 2.17GHz Intel Core Duo processor, the 32bit i686 smp kernel is installed and just works.  Dynamic CPU frequency scaling works well and if you wish to monitor/change the scaling behavior there&#8217;s a gnome panel applet to do so.</td>
</tr>
<tr>
<td bgcolor="#66FF66">USB</td>
<td bgcolor="#F0F0F0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">PCMCIA Slot</td>
<td bgcolor="#E9E9E9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Touchpad/Track Stick</td>
<td bgcolor="#F0F0F0">Works, no config needed.  Install <a href="http://gsynaptics.sourceforge.jp/">gsynaptics</a> from Extras if you want to customize the trackpad behavior, or copy/modify <a href="http://klamstwo.org/evad/archives/3">Dawid&#8217;s xorg.config settings</a> (search for &#8220;touchpad&#8221;).</td>
</tr>
<tr>
<td bgcolor="#66FF66">Suspend to Ram</td>
<td bgcolor="#E9E9E9">Works with kernel 2.6.18-1.2869, wireless networking needs to be restarted on wakeup and you need to nudge the volume control to wake up the soundcard.</td>
</tr>
<tr>
<td bgcolor="#FF6666">Hibernate to Disk</td>
<td bgcolor="#F0F0F0">Doesn&#8217;t work, system hangs during hibernation and needs a hard reset.  This worked in Fedora Core 5, so I imagine it will get fixed again relatively soon.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Ethernet</td>
<td bgcolor="#E9E9E9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Wireless Networking</td>
<td bgcolor="#F0F0F0">Install dkms-ipw3945, ipw3945d and ipw3945-firmware from freshrpms, install the kernel-devel package for your kernel, and reboot.  Once you&#8217;re configured, don&#8217;t forget to <a href="http://fedoraproject.org/wiki/Tools/NetworkManager#head-fc3fe44e92c63867615113b1ef69cf4fc0dc03cf">enable the network manager applet</a> so you don&#8217;t have to iwconfig from the terminal all the time.  The Intel 3945 has much better linux support than the <a href="http://mikelococo.com/2006/10/fc5-on-d620/">awful Broadcom 4310</a> in the Dell Truemobile 1390 that was previously installed in this laptop.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Bluetooth</td>
<td bgcolor="#E9E9E9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">2D Video</td>
<td bgcolor="#F0F0F0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">3D Acceleration</td>
<td bgcolor="#E9E9E9">The NVidia Quadro 110M works well after installing nvidia-x11-drv from freshrpms.  Don&#8217;t forget to install kernel-devel for your kernel version and reboot.  <strike>Battery life drops by about 40% while running the NVidia driver, even if you&#8217;re not doing 3D work.</strike>  <a href="http://mikelococo.com/2007/03/d620-battery-life/">I had a bad battery</a>.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">External Monitor</td>
<td bgcolor="#F0F0F0">If all you want is to switch to the external output instead of the internal LCD, you can do so easily right out of the box.  Use the screen resolution control panel to set your resolution, and Fn-F8 to toggle between the displays.  If you choose to install the NVidia driver, it includes a simple dialog for setting up multimonitor support using TwinView.  TwinView isn&#8217;t perfect, windows maximize dumbly (across both displays) and if the resolutions of the two monitors are mismatched there&#8217;s an area where it&#8217;s possible to move the mouse and place windows that doesn&#8217;t show up in any monitor.  All in all, it&#8217;s a bit lame but does get the job done in a pinch.</td>
</tr>
<tr>
<td bgcolor="#66FF66">CD/DVD Burning</td>
<td bgcolor="#E9E9E9">Works out of the box, but <a href="http://www.fedoraforum.org/forum/showthread.php?t=114586">this tweak</a> substantially improves burn speed and system responsiveness while burning.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Sound Playback</td>
<td bgcolor="#F0F0F0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Sound Recording</td>
<td bgcolor="#E9E9E9">Works, no config needed.  If you&#8217;re not getting recorded sound, check the Volume Control app to make sure that capture is enabled and the recording level isn&#8217;t way down.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Volume Keys</td>
<td bgcolor="#F0F0F0"">Go into System &#8211;> Preferences &#8211;> Keyboard shortcuts and assign the multimedia keys to vol down/up/mute (or whatever you want them to do).</td>
</tr>
<tr>
<td bgcolor="#66FF66">Radio On/Off Switch</td>
<td bgcolor="#E9E9E9">Works fine, and has a noticeable effect on battery life.  You may need to &#8220;up&#8221; the interface with the connection manager of your choice if you enable the radio while the system is running.</td>
</tr>
<tr>
<td bgcolor="#66FF66">ACPI Power Management</td>
<td bgcolor="#F0F0F0">All the power management features work (fan speed autoadjusts, cpu frequency scaling works, there&#8217;s a gnome applet to easily control it)<strike>, but battery life is inexplicably poor.  Under FC5, my battery life was over 4 hours with a 9-cell battery, wifi/bt off, backlight dimmed, and cpu locked to 1GHz.  After migrating to FC6, battery life is less than 3 hours and the laptop runs noticeably warmer when performing routine tasks.</strike>  <a href="http://mikelococo.com/2007/03/d620-battery-life/">I had a bad battery</a>.</td>
</tr>
<tr>
<td bgcolor="#CCCCCC">Fingerprint Reader</td>
<td bgcolor="#E9E9E9">Untested.</td>
</tr>
<tr>
<td bgcolor="#CCCCCC">Modem</td>
<td bgcolor="#F0F0F0">Untested.</td>
</tr>
</table>
<h3>Output of lspci</h3>
<p><center><textarea wrap="off" rows=20 cols=70 readonly>00:00.0 Host bridge: Intel Corporation Mobile 945GM/PM/GMS/940GML and 945GT Express Memory Controller Hub (rev 03)<br />
00:01.0 PCI bridge: Intel Corporation Mobile 945GM/PM/GMS/940GML and 945GT Express PCI Express Root Port (rev 03)<br />
00:1b.0 Audio device: Intel Corporation 82801G (ICH7 Family) High Definition Audio Controller (rev 01)<br />
00:1c.0 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 1 (rev 01)<br />
00:1c.1 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 2 (rev 01)<br />
00:1c.2 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 3 (rev 01)<br />
00:1d.0 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #1 (rev 01)<br />
00:1d.1 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #2 (rev 01)<br />
00:1d.2 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #3 (rev 01)<br />
00:1d.3 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #4 (rev 01)<br />
00:1d.7 USB Controller: Intel Corporation 82801G (ICH7 Family) USB2 EHCI Controller (rev 01)<br />
00:1e.0 PCI bridge: Intel Corporation 82801 Mobile PCI Bridge (rev e1)<br />
00:1f.0 ISA bridge: Intel Corporation 82801GBM (ICH7-M) LPC Interface Bridge (rev 01)<br />
00:1f.2 IDE interface: Intel Corporation 82801GBM/GHM (ICH7 Family) Serial ATA Storage Controller IDE (rev 01)<br />
00:1f.3 SMBus: Intel Corporation 82801G (ICH7 Family) SMBus Controller (rev 01)<br />
01:00.0 VGA compatible controller: nVidia Corporation Quadro NVS 110M / GeForce Go 7300 (rev a1)<br />
03:01.0 CardBus bridge: O2 Micro, Inc. OZ601/6912/711E0 CardBus/SmartCardBus Controller (rev 40)<br />
09:00.0 Ethernet controller: Broadcom Corporation NetXtreme BCM5752 Gigabit Ethernet PCI Express (rev 02)<br />
0c:00.0 Network controller: Intel Corporation PRO/Wireless 3945ABG Network Connection (rev 02)</textarea></center></p>
<h3>Useful Links</h3>
<ul>
<li><a href="http://klamstwo.org/evad/archives/3">Fedora Core 6 on the D620</a></li>
<li><a href="http://mikelococo.com/2006/10/fc5-on-d620/">My previous guide to Fedora Core 5 on the D620</a></li>
<li><a href="http://www.linux-on-laptops.com/dell.html">Linux on Laptops page for Dells</a> (search the page for 620)</li>
<li><a href="http://javier.rodriguez.org.mx/index.php/linux/debian-gnulinux-on-dell-d620/">Debian on the D620</a></li>
<li><a href="http://earth.geology.yale.edu/~gml27/d620.html">Fedora Core 5 on the D620</a></li>
<li><a href="http://www.oiepoie.nl/linux_on_d620/">Another guide to Fedora Core 5 on the D620</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2007/01/fc6-on-d620/feed/</wfw:commentRss>
		</item>
		<item>
		<title>CISSP Certification</title>
		<link>http://mikelococo.com/2006/12/cissp-certification/</link>
		<comments>http://mikelococo.com/2006/12/cissp-certification/#comments</comments>
		<pubDate>Sat, 16 Dec 2006 21:46:13 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2006/12/cissp-certification/</guid>
		<description><![CDATA[As of Thursday I&#8217;ve fulfilled all the requirements for CISSP certification, my papers should be in the mail by Monday.  I haven&#8217;t wanted to talk about it online until I had some firm results, but folks who know me in meatspace know I&#8217;ve been studying on and off since August.  I&#8217;m a little [...]]]></description>
			<content:encoded><![CDATA[<p>As of Thursday I&#8217;ve fulfilled all the requirements for <a href="https://www.isc2.org/cgi-bin/content.cgi?category=97">CISSP certification</a>, my papers should be in the mail by Monday.  I haven&#8217;t wanted to talk about it online until I had some firm results, but folks who know me in meatspace know I&#8217;ve been studying on and off since August.  I&#8217;m a little <a href="http://mikelococo.com/2006/05/aplus/">more amped about this credential</a> because they&#8217;re not handed out like party-favors and people who have them seem to be doing interesting things.</p>
<p>Although my study schedule was 4 months, my intensity level for the second and third month varied a lot.  I also spent a lot of time doing cover-to-cover reading, which in retrospect isn&#8217;t a terribly efficient way to approach an exam with this much breadth.  I kind of wish I had done more practice tests early in my study process so I could have spent more time on weak areas and less time agonizing over the subtleties of topics that I already fundamentally understood.</p>
<p>Most folks use a number of study resources, and I was no exception:</p>
<ul>
<li>I started with Shon Harris&#8217; <a href="http://www.amazon.com/CISSP-All-One-Guide-Third/dp/0072257121/">CISSP All in One Exam Guide</a>.  Like most Osbourne books, it&#8217;s a little bit chatty, has some laughably bad diagrams, and more than it&#8217;s share of ambiguities, errors, and bad practice questions.  Even still it&#8217;s a pretty good book, especially if you need to bootstrap yourself a bit before you feel prepared for the more no-nonsense books.</li>
<li>Once I felt comfortable with Harris, I started working through the Hansche/Berti/Hare <a href="http://www.amazon.com/Official-ISC-Guide-CISSP-Exam/dp/084931707X/">Official (ISC)<sup>2</sup> Guide to the CISSP Exam</a>, published by Auerbach.  Although dry, I think it&#8217;s important to work with this book.  Because of the strict confidentiality requirements surrounding the test it&#8217;s hard to get reliable information about which topics are emphasized, what the editorial style of the questions is like, and how to disambiguate words that may have a number of meanings depending on what part of the industry you work in but which are used in a specific and consistent way by (ISC)<sup>2</sup>.  I found that I simply absorbed a lot of useful information about the (ISC)<sup>2</sup> writing style when reading this book that gave me a tangible edge in the exam room.  Plus it&#8217;s generally well done and has the best practice questions I was able to find.  The worst thing I can say about it is that the CBK sections at the end of each chapter are fantastically vague, needlessly scary, and completely useless.  They&#8217;re easy to ignore, though, and that&#8217;s what I recommend doing with them.</li>
<li><a href="http://cccure.org/">Cccure.org</a> is an excellent resource for free practice questions.  Quality does vary, but at the high end is very good and on average is pretty ok.</li>
<li>I also bought a set of <a href="http://www.boson.com/Product/132.html">Boson</a> practice questions and was extremely disappointed, to the point of not even using most of them.  Some of the highlights of my Boson experience were:
<ol>
<li>A fill in the blank question with a nine word answer that needed to be typed exactly to be graded correctly.  The answer was obviously not a standard phrase worth memorizing, and <a href="https://www.isc2.org/cgi-bin/content.cgi?page=807#format">the CISSP exam is entirely multiple choice</a>.</li>
<li>A “multiple-choice question” that offered only one answer option&#8230; er&#8230; I mean&#8230; I “single-choice question”&#8230; or&#8230; um&#8230; would that just be a statement?</li>
<li>An email conversation with a Boson support rep that took three rounds of explanation before understanding why a multiple-choice question with no alternate options is defective, and who offered to take no corrective action other than passing the complaint up the chain.</li>
</ol>
</li>
<li>I did a lot of Googling to fill in gaps on topics I wasn&#8217;t familiar with.</ul>
<p>If you&#8217;re thinking of becoming a CISSP, have a look at the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1187">professional experience requirements</a> to make sure you qualify and look through the <a href="https://www.isc2.org/cgi-bin/content.cgi?page=818">FAQ</a>.  Cccure.org also provides an <a href="http://www.cccure.org/flash/intro/player.html">introduction to the process as a flash video tutorial</a> which brings a lot of public information into one place where it&#8217;s easy to digest.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2006/12/cissp-certification/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fedora Core 5 on a Dell Latitude D620</title>
		<link>http://mikelococo.com/2006/10/fc5-on-d620/</link>
		<comments>http://mikelococo.com/2006/10/fc5-on-d620/#comments</comments>
		<pubDate>Sat, 28 Oct 2006 05:57:08 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2006/10/fc5-on-d620/</guid>
		<description><![CDATA[Instructions for getting Fedora Core 5 humming on the Dell Latitude D620 probably fall into the category of “better late than never” at this point.  Since FC6 was recently released, this post will primarily serve as a comparison against a future (and more timely) guide for FC6 on the D620.
FC5 can be made to [...]]]></description>
			<content:encoded><![CDATA[<p>Instructions for getting Fedora Core 5 humming on the Dell Latitude D620 probably fall into the category of “better late than never” at this point.  Since <a href="http://fedoraproject.org/static-tmp/FC6ReleaseSummary.html">FC6 was recently released</a>, this post will primarily serve as a comparison against a future (and more timely) <a href="http://mikelococo.com/2007/01/fc6-on-d620/">guide for FC6 on the D620</a>.</p>
<p>FC5 can be made to work fairly well on the D620, but many things require tweaking to work properly.  This guide summarizes what can be made to work and how.  It is not a step by step howto, but does attempt to link to more detailed resources when they are available.  The table below shows at a glance what is and isn&#8217;t working well on my system.  Green items worked immediately after install without manual intervention, yellow items were made fully functional after some manual configuration, red items have significant unsolved issues associated with them (it&#8217;s worth noting that essentially all of my issues with the laptop stem from the use of a Broadcom wireless card, it&#8217;s a very well supported system when paired with the Intel wireless option).</p>
<table border=0 cellpadding=3>
<tr>
<td bgcolor="#66FF66">Dual-core Processor</td>
<td bgcolor="#E9E9E9">Both cores are detected on the 2.17GHz Intel Core Duo processor, the 32bit i686 smp kernel is installed and just works.</td>
</tr>
<tr>
<td bgcolor="#66FF66">USB</td>
<td bgcolor="#F0F0F0">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">PCMCIA Slot</td>
<td bgcolor="#E9E9E9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Touchpad/Track Stick</td>
<td bgcolor="#F0F0F0">Works, no config needed.  Install <a href="http://gsynaptics.sourceforge.jp/">gsynaptics</a> from Extras if you want to customize the trackpad behavior.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Suspend to Ram</td>
<td bgcolor="#E9E9E9">Works after updating kernel to 2.6.18-1.2200.fc5smp.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Suspend to Disk</td>
<td bgcolor="#F0F0F0">Works after updating kernel to 2.6.18-1.2200.fc5smp.</td>
</tr>
<tr>
<td bgcolor="#66FF66">Ethernet</td>
<td bgcolor="#E9E9E9">Works, no config needed.</td>
</tr>
<tr>
<td bgcolor="#FF6666">Wireless Networking</td>
<td bgcolor="#F0F0F0">Works with ndiswrapper, but conflicts with 3D acceleration (see the 3D section for details).  I accidentally purchased the Dell Truemobile 1390 wireless card option, which is based on the awful Broadcom BCM4310.  You should order the Intel wireless option instead, but if you already have an icky Broadcom it can be made to work using ndiswrapper.  Follow the <a href="http://ndiswrapper.sourceforge.net/mediawiki/index.php/Installation">standard installation instructions</a> using the <a href="http://support.dell.com/support/downloads/download.aspx?c=us&#038;cs=19&#038;l=en&#038;s=dhs&#038;releaseid=R115321&#038;SystemID=INS_PNT_PM_600M&#038;os=WW1&#038;osl=en&#038;deviceid=9110&#038;devlib=0&#038;typecnt=1&#038;vercnt=9&#038;formatcnt=1&#038;libid=0&#038;fileid=152055">r115321.exe driver</a> available from Dell.  Once you&#8217;re configured, don&#8217;t forget to <a href="http://fedoraproject.org/wiki/Tools/NetworkManager#head-fc3fe44e92c63867615113b1ef69cf4fc0dc03cf">enable the network manager applet</a> so you don&#8217;t have to iwconfig from the terminal all the time.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">2D Video</td>
<td bgcolor="#E9E9E9">The native display resolution is incorrectly detected, <a href="http://earth.geology.yale.edu/~gml27/d620.html">add the correct modeline to xorg.conf</a> to fix (ignore the 915resolution stuff if you have an NVidia card like me).</td>
</tr>
<tr>
<td bgcolor="#FF6666">3D Acceleration</td>
<td bgcolor="#F0F0F0">The NVidia Quadro 110M works well after installing NVidia drivers from livna, but causes the Broadcom wireless card to stop working reliably.  I&#8217;m not aware of a workaround other than to use the open source nv driver which doesn&#8217;t offer 3D acceleration (or to purchase the Intel wireless option, which doesn&#8217;t suffer from the issue).  Track progress on the issue <a href="https://launchpad.net/distros/ubuntu/+source/linux-source-2.6.17/+bug/57355">here</a> and <a href="http://www.nvnews.net/vbulletin/showthread.php?t=48327&#038;page=2">here</a>.</td>
</tr>
<tr>
<td bgcolor="#FF6666">External Monitor</td>
<td bgcolor="#E9E9E9">If you don&#8217;t use the NVidia driver, hooking up to the VGA out is painful.  <strike>Changing to a standard (non-wide) resolution and back again requires editing xorg.conf</strike> (some update, not sure which, added the correct resolution to the screen-res dialog so changing resolutions isn&#8217;t that painful anymore), there&#8217;s no proper resolution scaling, and no graphical interface for configuring dual-head.</td>
</tr>
<tr>
<td bgcolor="#66FF66">CD/DVD Burning</td>
<td bgcolor="#F0F0F0">Works out of the box, but <a href="http://www.fedoraforum.org/forum/showthread.php?t=114586">this tweak</a> substantially improves burn speed and system responsiveness while burning.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Sound Playback</td>
<td bgcolor="#E9E9E9">The audio drivers for the Intel High Definition Audio devices used in this system had problems in the initial release of FC5, but it should work fine after a yum update.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Sound Recording</td>
<td bgcolor="#F0F0F0">Works after updating.  If you&#8217;re not getting recorded sound, look in the preferences for the Volume Control app, make sure that &#8220;capture&#8221; is enabled and the recording level isn&#8217;t way down.</td>
</tr>
<tr>
<td bgcolor="#FFFF66">Volume Keys</td>
<td bgcolor="#E9E9E9">Go into System &#8211;> Preferences &#8211;> Keyboard shortcuts and assign the multimedia keys to vol down/up/mute (or whatever you want them to do).</td>
</tr>
<tr>
<td bgcolor="#66FF66">Radio On/Off Switch</td>
<td bgcolor="#F0F0F0">Works fine, and has a noticeable effect on battery life.  You may need to &#8220;up&#8221; the interface with the connection manager of your choice if you enable the radio while the system is running.</td>
</tr>
<tr>
<td bgcolor="#CCCCCC">Fingerprint Reader</td>
<td bgcolor="#E9E9E9">Untested.</td>
</tr>
<tr>
<td bgcolor="#CCCCCC">Bluetooth</td>
<td bgcolor="#F0F0F0">Untested.</td>
</tr>
<tr>
<td bgcolor="#CCCCCC">Modem</td>
<td bgcolor="#E9E9E9">Untested.</td>
</tr>
<tr>
<td bgcolor="#66FF66">ACPI Power Management</td>
<td bgcolor="#F0F0F0">Auto fan speed and cpu frequency scaling work without configuration.  Right-click the top gnome panel (the bar with the applications menu and the clock) and add the cpu frequency scaling monitor if you want some feedback and control over frequency scaling (which definitely affects battery life and laptop temperature during use).</td>
</tr>
</table>
<h3>Output of lspci</h3>
<p><center><textarea wrap="off" rows=20 cols=70 readonly>00:00.0 Host bridge: Intel Corporation Mobile Memory Controller Hub (rev 03)<br />
00:01.0 PCI bridge: Intel Corporation Mobile PCI Express Graphics Port (rev 03)<br />
00:1b.0 Audio device: Intel Corporation 82801G (ICH7 Family) High Definition Audio Controller (rev 01)<br />
00:1c.0 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 1 (rev 01)<br />
00:1c.1 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 2 (rev 01)<br />
00:1c.2 PCI bridge: Intel Corporation 82801G (ICH7 Family) PCI Express Port 3 (rev 01)<br />
00:1d.0 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #1 (rev 01)<br />
00:1d.1 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #2 (rev 01)<br />
00:1d.2 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #3 (rev 01)<br />
00:1d.3 USB Controller: Intel Corporation 82801G (ICH7 Family) USB UHCI #4 (rev 01)<br />
00:1d.7 USB Controller: Intel Corporation 82801G (ICH7 Family) USB2 EHCI Controller (rev 01)<br />
00:1e.0 PCI bridge: Intel Corporation 82801 Mobile PCI Bridge (rev e1)<br />
00:1f.0 ISA bridge: Intel Corporation 82801GBM (ICH7-M) LPC Interface Bridge (rev 01)<br />
00:1f.2 IDE interface: Intel Corporation 82801GBM/GHM (ICH7 Family) Serial ATA Storage Controllers cc=IDE (rev 01)<br />
00:1f.3 SMBus: Intel Corporation 82801G (ICH7 Family) SMBus Controller (rev 01)<br />
01:00.0 VGA compatible controller: nVidia Corporation Unknown device 01d7 (rev a1)<br />
03:01.0 CardBus bridge: O2 Micro, Inc. OZ601/6912/711E0 CardBus/SmartCardBus Controller (rev 40)<br />
09:00.0 Ethernet controller: Broadcom Corporation NetXtreme BCM5752 Gigabit Ethernet PCI Express (rev 02)<br />
0c:00.0 Network controller: Broadcom Corporation BCM4310 UART (rev 01)</textarea></center></p>
<h3>Useful Links</h3>
<ul>
<li><a href="http://www.linux-on-laptops.com/dell.html">Linux on Laptops page for Dells</a> (search the page for 620)</li>
<li><a href="http://javier.rodriguez.org.mx/index.php/linux/debian-gnulinux-on-dell-d620/">Debian on the D620</a></li>
<li><a href="http://earth.geology.yale.edu/~gml27/d620.html">Fedora Core 5 on the D620</a></li>
<li><a href="http://www.oiepoie.nl/linux_on_d620/">Another guide to Fedora Core 5 on the D620</a></li>
<li><a href="http://mikelococo.com/2007/01/fc6-on-d620/">My guide to Fedora Core 6 on the D620</a></li>
<li><a href="http://klamstwo.org/evad/archives/3">Another guide to Fedora Core 6 on the D620</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2006/10/fc5-on-d620/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Parsons Design Workshop</title>
		<link>http://mikelococo.com/2006/09/parsons-design-workshop/</link>
		<comments>http://mikelococo.com/2006/09/parsons-design-workshop/#comments</comments>
		<pubDate>Thu, 28 Sep 2006 22:16:45 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2006/09/parsons-design-workshop/</guid>
		<description><![CDATA[My partner is part of a group of graduate students at Parsons who have been working to design and build a laundromat and community information center in DeLisle, Mississippi.  The student-lead team worked from January to May to design the building and plan its construction, then moved to DeLisle for the summer where they [...]]]></description>
			<content:encoded><![CDATA[<p>My partner is part of a group of graduate students at <a href="http://parsons.edu">Parsons</a> who have been working to design and build a laundromat and community information center in <a href="http://maps.yahoo.com/maps_result?csz=delisle+mississippi">DeLisle, Mississippi</a>.  The student-lead team worked from January to May to design the building and plan its construction, then moved to DeLisle for the summer where they lived and worked to build the structure.</p>
<p>The project was displayed in a group exhibit at the 2006 <a href="http://www.labiennale.org/en/architecture/">Venice Biennale</a>, and is also <a href="http://www.architecturemag.com/2006/09/wash_and_dry_pa.html">featured</a> in this month&#8217;s edition of</p>
<href="http:>Architecture (one of four articles linked off this month&#8217;s homepage for the magazine).  To highlight the student-run nature of the project, the magazine had the students write their own article and submit their own photos, which were taken by Laura. The project has also received recognition from:<br />
</href="http:>
<ul>
<li>
<href="http:> <a href="http://www.dwell.com/"></a><a href="http://www.dwell.com/peopleplaces/profiles/7501232.html">Dwell Magazine</a>, which published an article in June of 2007</href="http:></li>
<li>
<href="http:>Allegedly <a href="http://www.nbc.com/">NBC</a> planned some coverage, but I&#8217;m not sure if it was ever released<a href="http://www.nbc.com/"> </a></href="http:></li>
<li>
<href="http:><a href="http://nytimes.com/"></a>The <a href="http://www.nytimes.com/2006/11/06/arts/design/06pars.html?adxnnl=1">New York Times</a>, who published an article in November of 2006</href="http:></li>
<li><a href="http://www.designtaxi.com/news.jsp?id=11934&amp;monthview=1&amp;month=9&amp;year=2007">AIA</a>, who awarded the project an <font class="text-news-current-body1">AIA New York State Design Award in September of 2006</font></li>
</ul>
<href="http:></href="http:>For more information about the project, click through their <a href="http://www.flickr.com/photos/infowash/">flickr photo page</a> or the <a href="http://www.parsonsdesignworkshop.org/html/intro.htm">website for the project</a>.  For more information about the Parsons Design Workshop in general have a look through the following links:</p>
<ul>
<li><a href="http://www2.parsons.edu/architecture/aidl/designworkshop.html">Parsons site for the Design Workshop</a></li>
<li><a href="http://www.parsons.edu/news/detail.aspx?nID=162">Announcement of 2006 exhibition</a></li>
<li><a href="http://www.parsons.edu/news/detail.aspx?nID=156">Announcement of exhibit at the Biennale</a></li>
<li><a href="http://www.newschool.edu/pressroom/pressreleases/2005/081505_parsons_tdw.html">2005 Retrospective announcement</a></li>
<li><a href="http://www.metropolismag.com/cda/story.php?artid=1709">Writeup of the 2005 project</a></li>
<li><a href="http://www.parsons.edu/news/detail.aspx?nID=61">Writeup of the 2004 project</a></li>
<li><a href="http://www.newschool.edu/html/press%20release/02_06_psd_field.html">Writeup of the 2003 project</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2006/09/parsons-design-workshop/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WuCoco 0.10.2</title>
		<link>http://mikelococo.com/2006/09/wucoco-0102/</link>
		<comments>http://mikelococo.com/2006/09/wucoco-0102/#comments</comments>
		<pubDate>Mon, 25 Sep 2006 04:24:10 +0000</pubDate>
		<dc:creator>mike</dc:creator>
		
		<category><![CDATA[WuCoco]]></category>

		<guid isPermaLink="false">http://mikelococo.com/2006/09/wucoco-0102/</guid>
		<description><![CDATA[This is a bugfix release for WuCoco, it contains no new features but resolves the following issues:

Comments now render properly in IE6.  This is a moderately severe bug.
Posts with complex HTML tags now display properly in the category archives.
All theme variants are now validating again (thanks for the patch Brian).
The comments link now correctly [...]]]></description>
			<content:encoded><![CDATA[<p>This is a bugfix release for WuCoco, it contains no new features but resolves the following issues:</p>
<ul>
<li>Comments now render properly in IE6.  This is a moderately severe bug.</li>
<li>Posts with complex HTML tags now display properly in the category archives.</li>
<li>All theme variants are now validating again (thanks for the patch <a href="http://www.bwbass.com/">Brian</a>).</li>
<li>The comments link now correctly links to the comment form when a post has no existing comments.</li>
</ul>
<p>By now, you know the drill:  Download the <a href="http://mikelococo.com/files/2006/wucoco_1col-0.10.2.zip">one-column layout</a>, the <a href="http://mikelococo.com/files/2006/wucoco_2col-0.10.2.zip">two-column layout</a>, the <a href="http://mikelococo.com/files/2006/wucoco_3col-0.10.2.zip">new three-column layout</a>, or the <a href="http://mikelococo.com/files/2006/wucoco_imgsrc-0.10.0.zip">image sources</a> (which haven’t changed since 0.10.0) in Gimp XCF format. Read the <a href="/projects/wucoco/">project page</a> for the latest downloads and more information.</p>
]]></content:encoded>
			<wfw:commentRss>http://mikelococo.com/2006/09/wucoco-0102/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
