Xen 06 - domU - Base (Golden image)
Xen on Debian 4 Learning · Previous: dom0 - the physical hardware · Next: domU - WWW system - apache2 + mod_security2 + mod_suphp + php5 + php5_suhosin
The Slovak original of this document: Xen 06 - domU - Base (Golden image) (slovensky).
|=---------------------------------=[ XEN ]=-------------------------------=| +---------------------------------------------------------------------------+ | | | XEN-server domU (REAL SERVER HW) | | Debian 4.0 Etch | | BASE SYSTEM | | | +---------------------------------------------------------------------------+ |=-------------------------------=[ BH 2008 ]=-----------------------------=|
1. Creating a new virtual machine (LVM)
Install the utilities for managing xen hosts
============================================
# apt-get install xen-tools
Set the parameters the new VM host needs (32 BIT)
=================================================
# nano /etc/xen-tools/xen-tools.conf
------------------------------------
lvm = system_vhosts
debootstrap = 1
size = 1.5Gb
memory = 256Mb
swap = 256Mb
fs = ext3
dist = etch
image = full
gateway = 10.0.0.254
netmask = 255.0.0.0
passwd = 1
kernel = /boot/vmlinuz-2.6.18-6-xen-686
e.g. /boot/vmlinuz-2.6.18-5-xen-686
initrd = /boot/initrd.img-2.6.18-6-xen-686
e.g. /boot/initrd.img-2.6.18-5-xen-686
------------------------------------END-/etc/xen-tools/xen-tools.conf
Set the parameters the new VM host needs (64 BIT)
=================================================
# nano /etc/xen-tools/xen-tools.conf
------------------------------------
lvm = system_vhosts
debootstrap = 1
size = 1.5Gb
memory = 256Mb
swap = 256Mb
fs = ext3
dist = etch
image = full
gateway = 10.0.0.254
netmask = 255.0.0.0
passwd = 1
kernel = /boot/vmlinuz-2.6.18-6-xen-amd64
e.g. /boot/vmlinuz-2.6.18-5-xen-686
initrd = /boot/initrd.img-2.6.18-6-xen-amd64
e.g. /boot/initrd.img-2.6.18-5-xen-686
------------------------------------END-/etc/xen-tools/xen-tools.conf
Create a VM host named 'base' with the IP address 10.0.0.1
==========================================================
# xen-create-image --ip=10.0.0.1 --hostname=base
Create the logical partitions for the remaining mount points (/var, /var/log, /tmp, /usr)
=========================================================================================
# lvcreate -L 1G -n base-var system_vhosts
# lvcreate -L 1G -n base-varlog system_vhosts
# lvcreate -L 0.5G -n base-tmp system_vhosts
# lvcreate -L 2G -n base-usr system_vhosts
# mkfs.ext3 /dev/system_vhosts/base-var
# mkfs.ext3 /dev/system_vhosts/base-varlog
# mkfs.ext3 /dev/system_vhosts/base-tmp
# mkfs.ext3 /dev/system_vhosts/base-usr
Add the disk partitions to the configuration file of the virtual machine 'base'
===============================================================================
# nano /etc/xen/base.cfg
------------------------
# BASE SYSTEM
# The kernel image, the initrd and the memory for this virtual machine
kernel = '/boot/vmlinuz-2.6.18-6-xen-amd64'
ramdisk = '/boot/initrd.img-2.6.18-6-xen-amd64'
memory = '256'
# Disk devices
root = '/dev/sda1 ro'
disk = [ 'phy:system_vhosts/base-disk,sda1,w', 'phy:system_vhosts/base-swap,sda2,w', 'phy:system_vhosts/base-var,sda3,w', 'phy:system_vhosts/base-varlog,sda4,w', 'phy:system_vhosts/base-tmp,sda5,w', 'phy:system_vhosts/base-usr,sda6,w' ]
# Hostname
name = 'base'
# Network
vif = [ 'ip=10.0.0.1' ]
# Behaviour
on_poweroff = 'destroy'
on_reboot = 'restart'
on_crash = 'restart'
------------------------END->/etc/xen/base.cfg
Start the newly created VM host and switch to its console (-c)
==============================================================
# xm create -c base.cfg
Install 2 packages to prevent warnings from APT
===============================================
# apt-get install locales console-data
Configure the locales package
=============================
# dpkg-reconfigure locales
Install the basic tools
=======================
# apt-get install mc syslog-ng
Leaving the virtual machine console
===================================
CTRL + ]
Returning to the virtual machine console
========================================
# xm console base
Shutting down the virtual machine
=================================
# xm shutdown -H base
Destroying the virtual machine [destroy] (!!! does not do a clean shutdown !!!)
===============================================================================
# xm destroy base
To have the virtual machine start when the dom0 machine boots
=============================================================
# mkdir /etc/xen/auto
# ln -s /etc/xen/base.cfg /etc/xen/auto/
Starting the new system
=======================
# xm create -c base.cfg
Configuring the domU - base
===========================
# nano /etc/hostname
--------------------
base
# nano /etc/network/interfaces
------------------------------
auto eth0
iface eth0 inet static
address 10.0.0.1
gateway 10.0.0.254
netmask 255.0.0.0
-------------------------------
# cat /etc/fstab
----------------
/dev/sda1 / ext3 errors=remount-ro 0 1
proc /proc proc rw,nodev,nosuid,noexec 0 0
/dev/sda2 none swap sw 0 0
/dev/sda3 /var ext3 defaults,nodev 0 2
/dev/sda4 /var/log ext3 defaults,nodev,nosuid,noexec 0 2
/dev/sda5 /tmp ext3 defaults,nodev,nosuid,noexec 0 2
/dev/sda6 /usr ext3 defaults,nodev 0 2Installing the SSH server (openbsd ssh)
-------------
Install ssh
-------------
# apt-get install ssh
------------
Config ssh
------------
# nano /etc/ssh/sshd_config
---------------------------
ListenAddress 10.0.0.1
PermitRootLogin no
AllowUsers bh skupko firefox
X11Forwarding no
Banner /etc/issue.net
#Subsystem sftp /usr/lib/openssh/sftp-server
---------------------------END->/etc/ssh/sshd_config
-----------------------
Setting up the banner
-----------------------
# nano /etc/issue
-----------------
***************************************************************************
WARNING
This computer system is private property. It may be used only by
authorised users. The privacy of users on this system is not
guaranteed.
Any use of this computer system may be recorded,
monitored, audited, inspected or otherwise checked by the employer,
the owner or the legal authorities.
By using this system the user consents to the recording and monitoring
of their activities in the computer system, and likewise consents to a possible
inspection of their activities in the system by the owner or the legal authorities.
Unauthorised use of the system may lead to disciplinary action by the employer and to
a criminal investigation. By using this system the user confirms that
they are aware of the conditions stated above. If you do not agree with anything
stated above, log out of the system immediately.
****************************************************************************
-----------------END->/etc/issue
# cat /etc/issue > /etc/issue.net
---------------------------------
the same as /etc/issue ;-)
--------------------------
Firewall - Kernel tuning
--------------------------
# nano /etc/sysctl.conf
-----------------------
# TCP SYN Cookie Protection - ON
net.ipv4.tcp_syncookies = 1
# IP Source Routing - OFF
net.ipv4.conf.all.accept_source_route = 0
# ICMP Redirect Acceptance - OFF
net.ipv4.conf.all.accept_redirects = 0
# IP Spoofing Protection - ON
net.ipv4.conf.all.rp_filter = 1
# Ignoring to ICMP Requests - ON
net.ipv4.icmp_echo_ignore_all = 1
# Ignoring Broadcasts Request - ON
net.ipv4.icmp_echo_ignore_broadcasts = 1
# Bad Error Message Protection - ON
net.ipv4.icmp_ignore_bogus_error_responses = 1
# Logging of Spoofed Packets, Source Routed Packets, Redirect Packets - ON
net.ipv4.conf.all.log_martians = 1
# IPV4 Forwarding
net.ipv4.conf.all.forwarding=0
-----------------------END->/etc/sysctl.confInstalling Bastille Linux
------------------
Install bastille
------------------
# apt-get install bastille
-----------------
Config bastille
-----------------
# InteractiveBastille
---------------------
>accept
Q: Would you like to set more restrictive permissions on the administration utilities? [yes]
Q: Would you like to disable SUID status for mount/umount? [yes]
Q: Would you like to disable SUID status for ping? [yes]
Q: Would you like to disable SUID status for at? [Yes]
Q: Would you like to disable SUID status for traceroute? [yes]
Q: Should Bastille disable clear-text r-protocols that use IP-based authentication? [yes]
Q: Would you like to enforce password aging? [no]
Q: Would you like to restrict the use of cron to administrative account? [yes]
Q: Do you want to set the default umask? [yes]
Q: What umask would you like to set for users on the system? [077]
Q: Should we disallow root login on all ttys? [yes]
Q: Would you like to password-protect the GRUB prompt? [no]
Q: Would you like to disable CTRL-ALT-DELETE rebooting? [yes]
Q: Would you like to password protect single-user mode? [no]
Q: Would you like to set a default-deny on TCP Wrappers and xinetd? [no]
Q: Should Bastille ensure the telnet service does not run on this system? [yes]
Q: Should Bastille ensure inetd's FTP service does not run on this system? [yes]
Q: Would you like to display "Authorized Use" message at log-in time? [no]
Q: Would you like to put limits on system resource usage? [yes]
Q: Should we restrict console access to small group of the user accounts? [yes]
Q: Which accounts should be able to login at console? [root bh skupko firefox]
Q: Would you like to add additional logging? [no]
Q: Would you like to install TMPDIR/TMP scripts? [no]
Q: Would you like to run the packet filtering script? [no]
Q: Are you finished answering the questions, i.e. may we make the changes? [yes]Installing SELinux
Procedure according to: BH_Debian4.0_SeLinux
2. Setting up the network (NAT-ed network)
----
dom0
----
# nano /etc/xen/xend-config.sxp
===============================
(network-script network-nat)
(vif-script vif-nat)
Enable SNAT for the network 10.0.0.0/255.0.0.0
==============================================
# iptables -t nat -A POSTROUTING -s 10.0.0.0/255.0.0.0 -j SNAT --to-source 192.168.254.254
Redirect requests for 192.168.254.254:22221 to 10.0.0.1:22
==========================================================
# iptables -t nat -A PREROUTING -p tcp -s xx.xx.xx.xx -d 192.168.254.254 --dport 22221 -j DNAT --to-destination 10.0.0.1:22Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
- xen-tools and Etch:
xen-create-imagewithdist = etchinstalls a release that has been end-of-life since 2010. Thexen-toolspackage itself is not in the current Debian stable release (it is in unstable and was removed from testing in February 2025), so check that it is available before building a workflow on it. - xm commands:
xmwas removed in Xen 4.5. Usexl create -c /etc/xen/base.cfg,xl console base,xl shutdown -w base(there is no-H) andxl destroy base. - base.cfg: the file carries over to
xlwith these changes: numbers are written without quotes, thephy:prefix is ignored and the target is a full path, Linux PV guests should getxvd*device names instead ofsda1tosda6(sorootand the guest's/etc/fstabchange to/dev/xvda1and so on), andtype = "pvh"selects the current guest type.
type = "pvh" memory = 256 vcpus = 1 root = '/dev/xvda1 ro' disk = [ '/dev/system_vhosts/base-disk,raw,xvda1,rw', '/dev/system_vhosts/base-swap,raw,xvda2,rw' ]
- Guest kernel:
kernelandramdiskpoint at the dom0 kernel, so the guest cannot update its own kernel. With thegrub-xenpackage the config loads GRUB instead (kernel = "/usr/lib/grub-xen/grub-i386-xen_pvh.bin"for PVH) and the guest boots the kernel installed inside it. - Golden image and SSH host keys: the SSH server is installed in the base image, so every guest copied from it with
ddhas the same host keys. Delete/etc/ssh/ssh_host_*in each clone and runssh-keygen -Abefore first use; on a current system also reset/etc/machine-id. - SSH settings, sysctl, Bastille: these parts repeat the dom0 article. The
sshd_configlines are still valid as written; for/etc/sysctl.confand Bastille see the "Current practice" section of the previous article (dom0 - the physical hardware). - SELinux: the article refers to a separate procedure for Etch. On current Debian it is
apt install selinux-basics selinux-policy-default auditd, thenselinux-activate, a reboot for the relabel andcheck-selinux-installation; the system starts in permissive mode and is switched withselinux-config-enforcing 1. - Network:
(network-script network-nat)and(vif-script vif-nat)inxend-config.sxpwent away with xend; the hotplug script is set per interface withscript=in thevifline, and the SNAT and DNAT rules are today written for nftables (see the previous article).
Sources: