<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[静怡家园]]></title> 
<link>http://www.zhanghaijun.com/index.php</link> 
<description><![CDATA[书山有路勤为径，学海无涯苦作舟！]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[静怡家园]]></copyright>
<item>
<link>http://www.zhanghaijun.com/post//</link>
<title><![CDATA[RHEL6.X CentOS 6.X系统服务详解]]></title> 
<author>碟舞飞扬 &lt;webmaster@zhanghaijun.com&gt;</author>
<category><![CDATA[Linux技术]]></category>
<pubDate>Thu, 05 Jul 2012 11:14:05 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//</guid> 
<description>
<![CDATA[ 
	<p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">RHEL/CentOS 6.x的系统服务比5.x系列的要多了很多新面孔，估计很多童鞋不甚理解，网上这方面资料也很少。理解这个对运维人员是必要的，因为开启不必要的服务越多，系统就相对越不安全。不需开启的服务尽量关闭。本人结合自己的应用经验做一些讲解说明，有不同理解的童鞋欢迎交流。</p><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px"></p><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">下面列表是在RHEL/CentOS 6.x最小化桌面环境安装下显示出来的系统服务，其中红色字体标注的是用官方的minimal ISO最小化安装系统后的服务列表。</p><table border="1" cellspacing="0" cellpadding="0" style="line-height: 24px; background-color: #ffffff; width: 755px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; height: 1841px; color: #000000; font-size: 13px"><tbody><tr><td><strong>服务名称</strong></td><td><strong>功能</strong></td><td><strong>&nbsp;&nbsp;&nbsp;&nbsp;<br />&nbsp;默认&nbsp;&nbsp;&nbsp; &nbsp; </strong></td><td><strong>&nbsp;&nbsp;<br />&nbsp; 建议 &nbsp;&nbsp;&nbsp;&nbsp;</strong></td><td><strong>备注说明</strong></td></tr><tr><td>NetworkManager</td><td>用于自动连接网络，常用在Laptop上</td><td>开启</td><td>关闭</td><td>对服务器无用</td></tr><tr><td>abrt-ccpp</td><td>&nbsp;</td><td>开启</td><td>自定</td><td>对服务器无用</td></tr><tr><td>abrt-oops</td><td>&nbsp;</td><td>开启</td><td>自定</td><td>对服务器无用</td></tr><tr><td>abrtd</td><td>&nbsp;</td><td>开启</td><td>自定</td><td>对服务器无用</td></tr><tr><td>acpid</td><td>电源的开关等检测管理，常用在Laptop上</td><td>开启</td><td>自定</td><td>对服务器无用</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">atd</span></td><td>在指定时间执行命令</td><td>开启</td><td>关闭</td><td>如果用crond，则可关闭它</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">auditd</span></td><td>审核守护进程</td><td>开启</td><td>开启</td><td>如果用selinux，需要开启它</td></tr><tr><td>autofs</td><td>文件系统自动加载和卸载</td><td>开启</td><td>自定</td><td>只在需要时开启它，可以关闭</td></tr><tr><td>avahi-daemon</td><td>本地网络服务查找</td><td>开启</td><td>关闭</td><td>对服务器无用</td></tr><tr><td>bluetooth</td><td>蓝牙无线通讯</td><td>开启</td><td>关闭</td><td>对服务器无用</td></tr><tr><td>certmonger</td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>cpuspeed</td><td>调节cpu速度用来省电，常用在Laptop上</td><td>开启</td><td>关闭</td><td>对服务器无用</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">crond</span></td><td>计划任务管理</td><td>开启</td><td>开启</td><td>常用，开启</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">cups</span></td><td>通用unix打印服务</td><td>开启</td><td>关闭</td><td>对服务器无用</td></tr><tr><td>dnsmasq</td><td>dns cache</td><td>关闭</td><td>关闭</td><td>DNS缓存服务，无用</td></tr><tr><td>firstboot</td><td>系统安装后初始设定</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>haldaemon</td><td>硬件信息收集服务</td><td>开启</td><td>开启</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">ip6tables</span></td><td>ipv6防火墙</td><td>开启</td><td>关闭</td><td>用到ipv6网络的就用，一般关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">iptables</span></td><td>ipv4防火墙</td><td>开启</td><td>开启</td><td>ipv4防火墙服务</td></tr><tr><td>irqbalance</td><td>cpu负载均衡</td><td>开启</td><td>自定</td><td>多核cup需要</td></tr><tr><td>kdump</td><td>硬件变动检测</td><td>关闭</td><td>关闭</td><td>服务器无用</td></tr><tr><td>lvm2-monitor</td><td>lvm监视</td><td>开启</td><td>自定</td><td>如果使用LVM逻辑卷管理就开启</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">matahari-broker</span></td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>此服务不清楚，我关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">matahari-host</span></td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>此服务不清楚，我关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">matahari-network</span></td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>此服务不清楚，我关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">matahari-service</span></td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>此服务不清楚，我关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">matahari-sysconfig</span></td><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px"><br /></span></td><td>关闭</td><td>关闭</td><td>此服务不清楚，我关闭</td></tr><tr><td>mdmonitor</td><td>软raid监视</td><td>开启</td><td>自定</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">messagebus</span></td><td>负责在各个系统进程之间传递消息</td><td>开启</td><td>开启</td><td>如停用，haldaemon启动会失败</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">netconsole</span></td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">netfs</span></td><td>系统启动时自动挂载网络文件系统</td><td>开启</td><td>关闭</td><td>如果使用<a href="http://www.opsers.org/server/how-to-turn-off-the-rhel-centos-the-rpc-statd-service.html" title="See Also: 如何关掉RHEL/CentOS的rpc.statd服务">nfs</a>服务，就开启</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">network</span></td><td>系统启动时激活所有网络接口</td><td>开启</td><td>开启</td><td>网络基础服务，必需！</td></tr><tr><td><a href="http://www.opsers.org/server/nfs-service-troubleshooting-and-common-solutions.html" title="See Also: NFS服务常见故障排查和解决方法">nfs</a></td><td>网络文件系统</td><td>关闭</td><td>关闭</td><td>nfs文件服务，用到就开启</td></tr><tr><td>nfslock</td><td>nfs相关</td><td>开启</td><td>关闭</td><td>nfs相关服务，用到就开启</td></tr><tr><td>ntpd</td><td>自动对时工具</td><td>关闭</td><td>自定</td><td>网络对时服务，用到就开启</td></tr><tr><td>ntpdate</td><td>自动对时工具</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>oddjobd</td><td>与D-BUS相关</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">portreserve</span></td><td>RPC 服务相关</td><td>开启</td><td>自定</td><td>可以关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px"><a href="http://www.opsers.org/server/chapter-email-services-raiders.html" title="See Also: 第十章:Email服务全攻略">postfix</a></span></td><td>替代sendmail的邮件服务器</td><td>开启</td><td>自定</td><td>如果无邮件服务，可关闭</td></tr><tr><td>psacct</td><td>负荷检测</td><td>关闭</td><td>关闭</td><td>可以关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">qpidd</span></td><td>消息通信</td><td>开启</td><td>开启</td><td>&nbsp;</td></tr><tr><td>quota_nld</td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>可以关闭</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">rdisc</span></td><td>自动检测路由器</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">restorecond</span></td><td>selinux相关</td><td>关闭</td><td>关闭</td><td>如果开启了selinux，就需开启</td></tr><tr><td>rpcbind</td><td>&nbsp;</td><td>开启</td><td>开启</td><td>关键的基础服务，nfs服务和桌面环境都依赖此服务！相当于<a href="http://www.opsers.org/server/centos.html" title="See Also: centos最小化安装系统后的基本调优及安全设置">CentOS</a>&nbsp;5.x里面的portmap服务。</td></tr><tr><td>rpcgssd</td><td>NFS相关</td><td>开启</td><td>关闭</td><td>NFS相关服务，可选</td></tr><tr><td>rpcidmapd</td><td>RPC name to UID/GID mapper</td><td>开启</td><td>关闭</td><td>NFS相关服务，可选</td></tr><tr><td>rpcsvcgssd</td><td>NFS相关</td><td>关闭</td><td>关闭</td><td>NFS相关服务，可选</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">rsyslog</span></td><td>提供系统的登录档案记录</td><td>开启</td><td>开启</td><td>系统日志关键服务，必需！</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">saslauthd</span></td><td>sasl认证服务相关</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>smartd</td><td>硬盘自动检测守护进程</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>spice-vdagentd</td><td>&nbsp;</td><td>开启</td><td>开启</td><td>&nbsp;</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">sshd</span></td><td><a href="http://www.opsers.org/server/scripts-to-prevent-brute-force-ssh-and-vsftpd.html" title="See Also: 脚本防止SSH和vsftpd暴力破解">ssh</a>服务端，可提供安全的<a href="http://www.ha97.com/category/shell" title="shell">shell</a>登录</td><td>开启</td><td>开启</td><td>SSH远程登录服务，必需！</td></tr><tr><td>sssd</td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>sysstat</td><td>&nbsp;</td><td>开启</td><td>开启</td><td>一组系统监控工具的服务，常用</td></tr><tr><td><span style="padding-bottom: 0px; background-color: transparent; margin: 0px; padding-left: 0px; padding-right: 0px; color: #ff0000; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">udev-post</span></td><td>设备管理系统</td><td>开启</td><td>开启</td><td>&nbsp;</td></tr><tr><td>wdaemon</td><td>&nbsp;</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>wpa_supplicant</td><td>无线认证相关</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr><tr><td>ypbind</td><td>network information service客户端</td><td>关闭</td><td>关闭</td><td>&nbsp;</td></tr></tbody></table><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px"><strong><span style="color: #ff00ff">系统服务管理工具：</span></strong></p><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">chkconfig（所有linux发行版都有），用法很简单，如下：</p><pre style="padding-bottom: 5px; line-height: 24px; background-color: #000000; margin-top: 0px; padding-left: 5px; width: 679px; padding-right: 5px; font-family: Verdana, Tahoma, sans-serif, 'Times neo roman', 'Lucida sans Unicode', Georgia, Arial; word-wrap: break-word; white-space: pre-wrap; margin-bottom: 10px; color: #00ff00; font-size: 1.1em; padding-top: 5px; border-image: initial; background-origin: initial; background-clip: initial; text-shadow: #00ff00 0px 0px 11px; border: #9a9a9a 1px solid"><a href="http://www.opsers.org/server/one-day-of-learning-linux-system-services-that-manage.html" title="See Also: 一天一点学习Linux之系统服务管理">chkconfig</a> --list [name]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;chkconfig --add&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; chkconfig --del&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; chkconfig [--level ]&nbsp;&nbsp; </pre><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">ntsysv（Redhat系发行版特有），直接运行选择服务是否自启动。</p><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">3、查看系统服务的相关说明：<br /><br />在RHEL/CentOS下这些系统服务都是Shell脚本，我们可以使用rpm的命令参数来查看相应服务的说明。如想查看mysqld服务的说明：</p><pre style="padding-bottom: 5px; line-height: 24px; background-color: #000000; margin-top: 0px; padding-left: 5px; width: 679px; padding-right: 5px; font-family: Verdana, Tahoma, sans-serif, 'Times neo roman', 'Lucida sans Unicode', Georgia, Arial; word-wrap: break-word; white-space: pre-wrap; margin-bottom: 10px; color: #00ff00; font-size: 1.1em; padding-top: 5px; border-image: initial; background-origin: initial; background-clip: initial; text-shadow: #00ff00 0px 0px 11px; border: #9a9a9a 1px solid">rpm -qi $(rpm -qf /etc/init.d/mysqld) </pre><p style="padding-bottom: 0px; line-height: 24px; background-color: #ffffff; margin: 0px 0px 10px; padding-left: 0px; padding-right: 0px; font-family: 'Microsoft YaHei', 微软雅黑, Arial, 'Lucida Grande', Tahoma, sans-serif; font-size: 13px; padding-top: 0px; border-image: initial; background-origin: initial; background-clip: initial; border-width: 0px">如图所示：<br /><img class="insertimage" src="attachment.php?fid=105" border="0" /><br /></p><br/>Tags - <a href="http://www.zhanghaijun.com/tags/centos/" rel="tag">centos</a> , <a href="http://www.zhanghaijun.com/tags/6/" rel="tag">6</a> , <a href="http://www.zhanghaijun.com/tags/%25E6%259C%258D%25E5%258A%25A1/" rel="tag">服务</a> , <a href="http://www.zhanghaijun.com/tags/chkconfig/" rel="tag">chkconfig</a>
]]>
</description>
</item><item>
<link>http://www.zhanghaijun.com/post//#blogcomment</link>
<title><![CDATA[[评论] RHEL6.X CentOS 6.X系统服务详解]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>