Tuesday, September 22, 2009

HOWTO Include Subversion version identifiers in your Java source code with Eclipse

It's often useful to include version markers in your source code files, especially when it's possible they will be distributed outside the bounds of a version control system. In my case, I'm using Subversion and Eclipse to write code.

Subversion provides keyword substitution for special keywords that are managed by Subversion during checkin an checkout. (See: http://svnbook.red-bean.com/en/1.5/svn.advanced.props.special.keywords.html). These include Date, HeadURL, Revision, Author, and Id (a combination of the others). You can embed these in your text files and SVN will automatically replace them with appropriate values each time. To enable this, you need to do the following:

svn propset svn:keywords "Id HeadURL Revision Author Date" foo.java

Then, you embed a keyword like "$Id" in your file and next time SVN updates your file, it will replace the $Id string with something like $Id: foo.java 148 2006-07-28 21:30:43Z sally $.

To make this easier, you might want to change the [auto-props] section of your config file to automatically set this property any time you create a new java file:

*.java: svn:keywords="
Id HeadURL Revision Author Date";svn:eol-style:native

Typically, this is embedded in a comment block. To make this easy, you can include it in your Eclipse file templates so things get pre-populated when you generate new files.

For general purpose insertion in all your Java source files, use Window > Preferences > Java > Code Style > Templates, then edit the "Files" entry and add the following to the template:

/*
*
* $$Id$$
*/

That will automatically insert the "$Id$" tag into any new source file you create.

Another reference:
http://wiki.collectionspace.org/display/collectionspace/Java+Source+Files+-+Beginning+Comments+Block+Template

For more advanced usage, you can embed a string in a variable that gets compiled into the object code and can be used to identify versions of binaries.

For Java, insert a piece of code that looks like this:

// version identifier automatically filled by svn:keywords "Id"
public static final String __class_id = "$Id$";

This will expand when the files are checked in to be representative of the version of code that was committed.

This can automatically be inserted in new classes with code templates, again. Window > Preferences > Java > Code Style > Templates > Code > Class body. (Make sure you use $$ for the dollar signs when you create the template.)

Pitfall: Make sure you have cleanly committed/updated files when you do this. Don't make the mistake of building your modified code that is checked out, then distributing it. Once you commit this code, the version number will bump up and potentially be different.


HOWTO specify default JVM arguments when using Java JAR manifest

A couple of times I've wanted to be able to specify a set of "default" JVM and program properties using the manifest file of a JAR file so that I could invoke it easily with "java -jar MyProgram." In my case, I wanted to set the JVM system property "https.proxyHost" so that all my web traffic would go through a local proxy.

Unfortunately, there doesn't appear to be a way to specify program arguments in a Java JAR manifest file.

To get around it, the solution is to use properties. I found a useful post here (http://www.velocityreviews.com/forums/t129370-vm-arguments-in-manifest.html) that suggests doing something like this:

static {
System.setProperty("https.proxyHost", proxyHost)
}

This solution actually worked quite well. I ended up writing a "JVMProxyHelper.setProxy(host,port)" routine that I simply invoked from the main() of the program I was running. If I get really fancy, I'll go back and make it read the property out of a file and register it that way, but this works for my quick need.

HOWTO Create Ant build.xml file from Eclipse Java project

I searched around and couldn't find an easy answer for this, but accidentally found it in Eclipse while doing something else. Basically, I created a simple Java program in Eclipse. I wanted to be able to build the program from the command line with ant, but didn't want to hand create the build.xml file when I knew that Eclipse should be able to generate a basic one for me. I kept looking in the "Project" menu and "New" menu for a way to do it.

Answer: It's in the "Export" menu. If you do Export > General > Ant build file, everything works fine.

Beware: it automatically over-writes any build.xml file that may exist with no warning. Don't make modifications unless you figure out a way to preserve them when things change.

Similar task: if you want to produce a runnable JAR file from your project, you can use Export > Java > Runnable Jar to do so. This can also create a custom Ant build file that automatically packs all the Jar stuff you need. NOTE that one of the things this does is re-pack any dependent Jar files you have into one big jar so you can run it with "java -jar."

If you have additional rules in the file that you would like to include in the generated build.xml, you can make Eclipse automatically import these files.

In the same directory, create "build-custom.xml" with the following lines:

<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<?eclipse.ant.import?>
<project default="all" name="Create runnable JARs for everything">
<target name="all" depends="build">
... more stuff ...
</target>
</project>

Then export the build.xml file from Eclipse. It will now include a line
<import file="build-custom.xml">
near the beginning. All rules you define in your custom XML file will appear
as part of the build.xml file. You could now execute "ant all" to invoke your "all" rule from the main command line.

NOTE: I think your filename must start with the word "build....xml" in order for Eclipse to find it.

Monday, September 21, 2009

Using Alfresco 3.2 "Share" capabilities

I recently install Alfresco 3.2 Community on a VMware image on my machine to play with it. For information on how I did that, see my other post.

I had some questions about how, exactly, I might use the 'share' capabilities. These basically emulate a lot of the capabilities that Microsoft Sharepoint provides. I believe, in fact, that Alfresco actually presents a Sharepoint protocol interface that can be used by other sharepoint clients.

Questions:


Questions:

  • Q: How do I get to WebDAV path of files in Document library?
  • A: http://192.168.177.131:8080/alfresco/webdav/Sites/firstsite which is the same technique used for all other Alfresco WebDAV access.
  • Is there a way to directly edit document library files
  • Is there a way to share files between “Share” and “Alfresco” hierarchy?
  • o A: “Alfresco” main site sees the content of the “sites” hierarchy as files data, but I don't think the "Share" sites have a good view of the containing Alfresco instance
  • o Operations on the items seems to be limited. I don't seem to be able to create "rules" on documents within a "site" document library, but I'm not sure I ever was.
  • o Can Embed a “widget” or treat as a “site” ?
  • o Tried with a “web view” applet, but that requires you to login and doesn’t really connect to much.

  • - How would we create a main company site, then show highlights of other sites for projects
  • - How do we create template share sites to create new projects?
  • - Is there a quick way to “monitor” for changes in a site? (e.g. email)

  • Q: Is there a way to create an “intro page” for a site?
  • o A: yes. “Customize Dashboard” to move around widgets.

Setting up Alfresco 3.2 Community in a Linux VM

I've used Alfresco a bunch in the past at work to maintain documents. We're thinking of upgrading from the (very) old 2.2 release to the (much) newer 3.2 release. This is what I did to get started.

I set this up in a VMware image of a Ubuntu Workstation 9.04 (512 MB RAM, 25GB disk). For information on this, see my other blog post.

To get started with Alfresco, I did the following:
- Download Sun jdk 1.6 se, install, move to /usr/local/java
- Sudo apt-get install mysql-server
** Ask for a new root PW. Set one.
- Download alfresco 3.2 community from http://www.alfresco.org
- Sudo ./Alfresco-....-install
o Chose /opt/alfresco as installation location
o Asks for root pw of mysql;
o Creates ‘alfresco’ database in mysql
o Ask for where Open Office is installed. I fed it /usr/lib/openoffice after locating it on my disk.
o Start Alfresco
- . cd /opt/alfresco
- . ./alf_start.sh
- (wait)
- http://localhost:8080/alfresco

This produces and “up and running” version of alfresco. (NOTE: The NAT interface between my host OS and guest Linux OS is 192.168.177.x. Host is .1 and guest is .177, hence the interfaces below.)
- http://192.168.177.131:8080/alfresco allows access from my external machine
- Shows "guest" account view by default
- Login: admin (default PW)
- Created user for rmills
- Tested login and upload of a document.

Alternate Interface: Alfresco Share
  • http://192.168.177.131:8080/share
  • Login: rmills or admin
  • Create a site (Collaboration Site)
  • Name: FirstSite
  • URL: firstsite
  • Public


Friday, September 18, 2009

Setting up an easy VMware Linux machine

I spent a few minutes playing around with VMware to get a linux virtual machine set up on my PC. It was actually fairly easy:

  • Download and install latest VMware Player from www.vmware.com (reboot)
  • Download a Ubuntu 9.04 Desktop virtual machine from the "Appliance > Operating Systems" section of the VM Ware site
  • Unpack the VM image
  • Double click on the virtual machine and VMware player starts up.
Magic. Easy.

Now I have a VM running linux on my machine that I can play with. It seems to be auto configured with NAT networking, so I can use SMB to access shared drives on my host PC to transfer files back and forth. It can also reach the internet with a web browser, etc.

Wednesday, August 5, 2009

Basics of using GPG for signing, encrypting, exchanging, etc.

I recently had need to interchange some information that needed to be signed and encrypted. My colleague was using GPG, so I had to get it set up.

GPG is a good, free, secure package with a very basic command line interface for working with keys, encrypting, and decrypting things. It is basically an open source version of PGP (kind of a defacto standard for cryptography packages).

The basic steps for using it are shown below.

Install GPG

Install GPG by downloading (the Windows version, in my case) the command line interface. (ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe for me). I plopped mine in C:/apps/GnuPG.

Create a Key

Create a key: 'gpg --gen-key.' It asks a bunch of questions and I ended up with a "DSA and Elgamal" key of 2048 bits, non-expiring, with a UID of "Richard Mills (GPG Key) ."

Export a copy of the key that you can share: 'gpg --export -a > gpgkey.pub.export.txt'

This has an ascii format similar to

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.9 (MingW32)

mQGiBEp5hgoRBADnOunnwGSicNhPXwZfrO+KY5KqM9eEYBzs8xsF6XnKbuHwmewb
rJuPrUkQntwYKCVYJxNiITe+U/i4ovHcdX5bMl6u57N34uUZ2EQPxuSVPodZsOEt
....
eYYKAhsMAAoJEJh6yxSN8tuIgWQAoLuI04SOOxJ6hjGFTsE5wqNBlqkJAKC4A2qC
uC2gEiXUd7Xu0Alquau49w==
=DYre
-----END PGP PUBLIC KEY BLOCK-----

Encrypt Something

To encrypt something, you need the public key of the "Recipient" who you want to be able to decrypt the file. For the simple case, you can encrypt something for yourself that you can decrypt later. It will ask a few questions along the way that you need to answer.

$ gpg --encrypt foo.txt
You did not specify a user ID. (you may use "-r")

Current recipients:

Enter the user ID. End with an empty line: rmills

Current recipients:
2048g/83F23E72 2009-08-05 "Richard Mills (GPG Key) "

Enter the user ID. End with an empty line:

This will result in a file 'foo.txt.gpg' that is the encrypted version of your file. Note that the "Recipient" means the person to whom you want to send the file (could be yourself). You must have this person's public key in your key ring to encrypt it. The only person who will be able to decrypt it will be the person with the matching private key.

Decrypt Something

Decrypt the file (assuming you were the recipient):

$ gpg --decrypt foo.txt.gpg > foo.txt.new

You need a passphrase to unlock the secret key for
user: "Richard Mills (GPG Key) "
2048-bit ELG-E key, ID 83F23E72, created 2009-08-05 (main key ID 8DF2DB88)

gpg: encrypted with 2048-bit ELG-E key, ID 83F23E72, created 2009-08-05
"Richard Mills (GPG Key) "

NOTE that you need to type in the passphrase for the private key in order for the file to be decrypted.

Sign Something

Signing something is useful to ensure the integrity of it during transport. Signing involves applying your private key to something such that your public key can be used to verify that the data has not been modified. In many cases you may want to 'clear text sign' the piece of data such that it is still legible without having to be decrypted.

gpg -s foo.txt

This will create 'foo.txt.gpg' which is a new binary (obscured) version of your data. It will need to be decrypted with 'gpg -d' before it can be read. Alternately, you can use "cleartext" signing that encodes everything in ASCII such that it is readable without actually decrypting it.

gpg --clearsign foo.txt

This produces a file 'foo.txt.asc' which is readable and looks something like this:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iEYEARECAAYFAkp5tk4ACgkQmHrLFI3y24iu8QCePQ/ic5S71V9BkPtUB6OiT1cx
JeQAnRcvjZiaMnTEQJ8KgdZ8DKpFbzSN
=kXkG
-----END PGP SIGNATURE-----

This file can be transported through normal ASCII transport mechanisms (e.g., email). It can be verified (see below) in the same was as if it was obscurred.

Verify Signature and Retrieve Something

Verifying a signature is important to ensure that a piece of data has not been modified since it was signed. To do this, use 'gpg --verify file.signed.' GPG will use your local public key ring to verify any/all people who's keys were used to sign the piece of data. Note that in some cases, multiple people may have signed the data along it's route to you. To properly trust the data, you need to actually trust ALL the people back to the origin.

To actually GET the data that has been signed, you need to decrypt it.

$ gpg -d foo.txt.gpg > foo.verifysig.txt
gpg: Signature made 08/05/09 12:43:05 using DSA key ID 8DF2DB88
gpg: Good signature from "Richard Mills (GPG Key) "

The file "foo.verifysig.txt" will now contain the data you actually want.

Exchange Public Keys with Someone

Generally, you want to be able to pass your public key around to your colleagues such that they can use it to verify signed messages from you as well as encrypt data that can be sent to you. It is important that public keys are maintained intact such that someone cannot masquerade as someone else. More on that below.

The easiest way to exchange keys is to simply email them. Alternately, you can publish them on your web page, or really put them anywhere that people can find them. Use 'gpg --export -a' to generate a ASCII format key (as shown above), then email it to your buddy. He should do the same for you.

Once you get a key, you need to import it into your keyring.

Typing 'gpg --list-keys' will show you all the keys you have in your public key ring (including yours). Also, 'gpg --fingerprint' will show you the finger prints of those keys such that you can verify they match what you expect (e.g., if the other person sent you a finger print to verify it).

Proper Handling of Keys

Generally, you can send your public key to whomever you want (hence the name "public"), but it is critically important to protect your private key and the matching passphrase. If someone were to steal your private key and the passphrase, they would be able to decrypt anything intended for your eyes only was well as masquerade as you when signing messages.

Although you can send public keys to anyone, it is useful for them to ensure that the public key remains intact so they can verify your signature and also encrypt data to send to you. This means the onus comes on the recipient to protect any public keys that are received. This can be done by comparing fingerprints of keys with the keys themselves. Fingerprints are sufficiently small such that you can easily compare them even by reading them over the phone to each other. Once you are confident that a public key is authentic, you can sign it using gpg and assign it a particular value of trust. I'll save that discussion for another day.