Installation of openSUSE Linux Leap 15.4
Instructions for Users
(2023-04-03)
Carlos F. Lange
CFD Lab, MecE, UofA
Style convention: filenames and commands; ; check item
This page contains instructions for openSUSE Linux Leap 15.4 users. It is a follow up to the general installation instructions and it contains settings that have to be adjusted by each user, as well as instructions for certain programs and for remote access.
Important: The highlighted steps are important and should be performed by every user when beginning to work on a new machine (or new installation).
USER SETTINGS
These are some settings that must be performed once by each user after a new installation. The description also includes some useful hints for trouble-shooting.
Steps to be Performed at First Login
- Canada English. : change the region to
- Default Language to Canadian English and uncheck Skip run-together words (and, if you like, enable Automatic spell checking by default). : change the
- Screen Lock (in KDE): Lock screen automatically after. and change the time or uncheck
- KWallet (Classic, blowfish encrypted file, Next, then enter your password twice. ): To store passwords securely in KWallet for wireless connections and encrypted disks, select
- Screen Lock (in XFCE): Open Lock Screen After. , then and change the time or uncheck
- Kile (for LaTeX) and Kate: Line Length Limit to unlimited (option below zero). : change
- KDE: A new user should take the time to customize the many options in .
- One specially useful setting is under Formats change the region to Canada. Apply. And under Spell Checker change the Default Language to Canadian English and uncheck Skip run-together words (and, if you like, enable Automatic spell checking by default). Apply. , then under
- Screen Lock: To change the time or to disable screen locking in
- KDE: Open Lock screen automatically after:. , then and change the time or uncheck
- XFCE: Open Lock Screen After. , then and change the time or uncheck
- No Blinking: To disable cursor blinking, open Cursor Flash Time down to No blinking. Then File / Save. and in the Interface tab, change
- NOTE: After an update existing users start with their old settings. A copy of their old settings and KDE specific files, such as address book, calendar and email, can be found in ~/.kde4_old/.
- KWallet: ( ) Secure password storage.
- To store passwords securely in KWallet for wireless connections and encrypted disks, select Classic, blowfish encrypted file, Next, then enter your password twice. It is sufficiently secure and more convenient in KDE, than the GPG encryption recommended by the popup.
- KWallet can also be used to securely store manually entered passwords in the KWalletManager by left-clicking on the Password folder and right-clicking on Passwords and selecting New.
- To export or import your wallet for transfer to another computer, use or , respectively.
- Firefox: Change following Firefox settings:
- Security / Passwords: ( ) If you allow Firefox to Remember Passwords, then make sure to Use a Primary Password, so that URLs and passwords are encrypted.
- Close Firefox to save these settings.
- Firefox Extensions: ( ) Get Add-ons with many extensions to enhance Firefox. If extensions are downloaded and installed directly from the maker's website, you need to Allow the site to install them in Firefox. Some suggested extensions are:
- Mendeley Web Importer: download papers directly into Mendeley.
- Video DownloadHelper: save videos from YouTube and other sources.
- Chromium and Chrome: To save passwords in Google's Chromium or Chrome, go to Settings, then click on Advanced Sync Settings. Set Encrypt synced passwords with your Google credentials.
- Kile: ( ) The LaTeX user interface. In adjust:
- Kile / General: Template Variables: Document Class Options: delete a4paper,10pt; File Clean-up Details: set Automatically clean-up files after close.
- Tools / Build: The QuickBuild button is set to PDFLatex+ViewPDF by default. Change this only if necessary.
- Tools / Build: Change the ViewHTML Command from konqueror to firefox, otherwise the list of LaTeX commands under cannot be shown.
- Editor / Editing: Spellcheck: change the Default Language to English (Canada) and uncheck Skip run-together words (and, if you like, enable Automatic spell checking by default).
- Editor / Open/Save: General: change Line Length Limit to unlimited (option below zero). If a file with too long lines was open Read Only, then it will be reopened as Read Only, until the option is unchecked.
- OK.
- Kate: ( ) One of the text editors should be configured, in addition to Kile. The other will follow the same configuration. In (or ) adjust:
- Editor Component / Editing (or Editing): Spellcheck: change the Default Language to American English (United States)[CA] and uncheck Skip run-together words (and, if you like, enable Automatic spell checking by default).
- Editor / Open/Save (or Open/Save): General: change Line Length Limit to unlimited (option below zero). If a file with too long lines was open Read Only, then it will be reopened as Read Only, until the option is unchecked.
- OK.
- LibreOffice:
- Replace Microsoft Fonts: To display correctly Microsoft Office documents, replace MS fonts with equivalent open source fonts:
- Go to .
- On the right-hand side, first enable the Replacement Table by checking Apply replacement table.
- Type Calibri into the Font box and select Carlito in the Replace with box. The click the check box to add the replacement to the table.
- Type Cambria into the Font box and select Caladea in the Replace with box. The click the check box to add the replacement to the table.
- Apply. OK.
- LibreOffice Extensions: To add more extensions to LibreOffice, start LibreOffice Writer, then and Get more extensions online.
- Writer: To access text or figures that do not respond to clicking, go to and disable Cursor in protected areas.
- Replace Microsoft Fonts: To display correctly Microsoft Office documents, replace MS fonts with equivalent open source fonts:
- Annotation of PDF files:
- Xournal++: ( ) Although designed for use with tablets, this is the easiest annotation tool for PDFs and it can also be used with regular desktops. Start Xournal++ and open a PDF with . Use the pen and ruler modes to add lines and the text mode to add comments. Save the annotations only with under *.xopp or re-export to PDF with .
- Okular: The default PDF reader can also annotate. Click on the Reviews icon on the left, or or click F6. After adding reviews and bookmarks, save them to be able to see the annotations in another computer.
- With the installation of openSUSE package servicemenu-pdf, many PDF editing operations are now available by right-clicking and choosing .
- Wireless Connections: To avoid having to memorize all wireless passwords, use KWallet to save them securely (you will be prompted for it, select the Classic, blowfish encrypted file mode). You usually only need to type the KWallet password once in each login session.
- University Wireless Service (UWS): To connect to UWS with your laptop, left-click on the KNetworkManager icon in the task bar (Networks) and click on UWS (under Available Connections), then on Manage Connections. Select UWS from the list or type UWS in the Essid field, then Next. Set the following options:
- Security: WPA/WPA2 Enterprise
- EAP: Method: Protected EAP (PEAP)
- CA Certificate: Check Use system CA Certs
- Inner Authentication: MSCHAPv2
- Username: your CCID
- Password: your UofA password
- Sound: There are several ways to control sound in openSUSE.
- Mixer (speaker icon in the System Tray (bottom-right)): The Mixer allows for quick volume control of output and input (microphone). It can be adjusted a left-click.
- Configure Desktop ( ): It allows for individual adjustment in case of different audio devices or programs. You can also create different profiles in the tab.
- PulseAudio ( ): PulseAudio is the lowest level program controlling the audio.
- Printer/Scanner: In case of HP multi-function printer:
- To access the scanner and other printer functions, right-click on the HPLIP Status Service icon in the system tray.
- Select the correct device on the left (Printer, not Fax) and click on the service action, e.g. Scan, on the right pannel.
- If a plugin is missing or needs update for the HP multi-function printer, a message "Driver plugin installation is required" will appear. Only root can complete this update.
- Fonts: To produce accented characters, use the right Ctrl+Shift keys as Compose keys. Press the combination first, then press the accent key, then press the accented letter key. If you have problems displaying foreign characters (accented letters) in any text editor, try changing the font encoding method from utf-8 to iso8859-1.
- Fonts: Manage system fonts. To install new fonts go to Font Management, and Add the files.
- Android and KDE synchronization::
KDE can now synchronize with any Andriod mobile device on the same LAN (local network). This requires installation of the openSUSE package kdeconnect-kde (already installed) and installation of the app KDE Connect from the Google Play Store in the mobile device. After installation (and possibly after reboot of the mobile device or just waiting for a while), you can pair the device with the computer:
- Add the widget KDE Connect to your KDE Desktop background. You can also access KDE-Connect via .
- Open the Firewall (External Zone) Add KDE Connect from the pull-down menu Service to Allow. Next. Finish. ): Under (while shows
- On the mobile device, start KDE Connect and wait (or reboot) until you see the name of your computer under Request Pairing. . Then click on it and
- The computer will show a Accept. . Click
- The name of your computer will move to the Send ping. list in your mobile device. You can test the connection by clicking on the computer name and
- From now on, the computer will show battery status, notifications, and phone calls from the device. You can also control multimedia programs, such as Amarok, VLC, and Kaffeine, remotely from your mobile device. Amarok's music will automatically pause, when you receive a phone call. And there will be a link under Places in Dolphin that allows you to transfer data to and from the phone (you need to unlock the phone screen first).
- If you tap on the computer name under , then on the three dots at the top and , you can select all the different types of connections.
- Oneko: If you are bored with your mouse cursor, run oneko & in a console terminal or in KRunner (Alt+F2: oneko ; Enter) to have a cat chasing your mouse cursor. Add this command to your Autostart for permanent use: : Autostart: Add Program: oneko. OK. OK.
BACKUP
- Personal Backup: Each user is responsible for backing up her/his data. Backup is the single most important system maintenance activity for the user and it can save many days, sometimes weeks, of work in case of hardware failure. Create a habit of regularly backing up locally and off-site your most important data, specially during heavy work periods.
- Local Backup: Each CFD-Lab user is entitled to means for regular local backup (weekly is recommended). This is specially important for very large files and simulation results files, which are not included in the automatic backup. The current means of local backup is:
- An external hard-disk that is connected to the machine through the external disk bay. All backup disks shall be stored in the fireproof safe.
- Off-site Backup: In addition to the local backup, each user should use their own means for regular off-site backup (daily is recommended). Examples of backup media are: large USB memory keys, rewritable DVDs, external hard-disks, or synchronization to an external machine.
- Backup Commands and Scripts: The special scripts below were installed in /usr/local/bin/ during the installation process.
- For full copy use the standard Linux commands:
- cp -a orig dest (local backup)
- scp -rp orig remote-mach:dest (remote backup)
- tar zcvf filename.tar.gz orig (creates a single packed and compressed tar-file (similar to ZIP, but preserving all attributes))
- For efficient incremental synchronization, the best command is rsync. Because of the complexity of the this command, we recommend the use of the following scripts for directory (folder) synchronization:
- syncsend directory remote-mach:
- syncget directory remote-mach:
- syncsendauto directory remote-mach:
- syncgetauto directory remote-mach:
- These scripts also accept local parent directories (use full path) as destinations (ex.: syncsendauto Thesis/ /media/disk/user/ ).
- To generate a compressed tar-ball, containing only new and modified files in a directory (folder) after a certain date, that can be easily stored in a small memory stick, use the backupfromdate script. For example, to backup all new and modified files from the past 24h in a directory use:
backupfromdate yesterday directory
This creates a tar.bz2 file that can be restored later running from the top directory:
tar jxpf file.tar.bz2
Description and another example can be found running backupfromdate --help.
- For full copy use the standard Linux commands:
- Local Backup: Each CFD-Lab user is entitled to means for regular local backup (weekly is recommended). This is specially important for very large files and simulation results files, which are not included in the automatic backup. The current means of local backup is:
- Other Backup and Synchronization Tools: In addition to the scripts above, there are several other tools available for backup and synchronization:
- Grsync: a GUI for rsync.
- luckyBackup: another GUI front-end for rsync. It offers scheduled backups.
- rdiff-backup: an incremental command-line backup tool based on rsync that offers snapshots in time, allowing for the retrieval of past versions of files and folders.
- Unison: a graphical bidirectional synchronization tool that can synchronize between Linux and Windows.
- Automatic Backup: (The automatic backup mechanism for the CFD-Lab is currently being updated.)
REMOTE CONNECTIONS
- Remote File Browsing: To browse files on another computer with the SSH protocol, go to the Network place in Dolphin, and Add Network Folder using Secure shell (ssh) protocol. (From Windows, a similar behaviour can be achieved with WinSCP.)
- Remote login: To securely login (ssh) and copy files (scp, sftp) to other computers in a terminal without retyping your password every time:
- First generate a key pair for your computer with
ssh-keygen -t rsa
and save it in the suggested place. - Make sure you use a passphrase, which can later be changed with
ssh-keygen -p -t rsa - Send the public key to each remote computer:
ssh-copy-id machine.name - Finally, every time you login on your local machine, run ssh-add from a Konsole once to load your private key.
- To start ssh-add automatically in KDE together with KWallet, you can add it to the Autostart list: go to , then Add Program and enter ssh-add. OK.
- If ssh-add on a remote machine gives an error, try logging in to that machine with ssh -A to enable auth agent forwarding.
- If the remote machine was upgraded or reinstalled, its fingerprint was changed in the process and SSH will prevent you from logging in, thinking that another machine is pretending to be it. To solve this you have to remove the current version of the RSA key corresponding to the remote machine with:
ssh-keygen -R machine.name -f $HOME/.ssh/knwon-hosts
- First generate a key pair for your computer with
- X2Go Client ( ): To access your desktop remotely or to run single applications use the X2Go Client for best results.
- To access your complete desktop on a remote machine:
- Start a New Session ( ) and enter Server name and .
- Important: Change the to , because X2Go currently has problems supporting the new KDE Plasma 5 desktop.
- In the other tabs you can adjust the connection speed, size of display window, media sound support, and shared folders, if needed. OK.
- Once the session started, you can close the session window or the client window and the session (and any running program) will continue to run in the remote server.
- At the end of a session, do not forget to logout from within the session ( ), to actually terminate the session in the server.
- If login does not work, try restarting the OpenVPN session first, because it may have expired. Alternatively, repair the database in the server computer running x2godbadmin --createdb as root.
- To access a particular application on a remote machine:
- Start a New Session as above and set the to , then enter the application call in the field. OK.
- Note: Matlab must be called from a terminal window that remains open, such as xterm -e matlab.
- At the end of a session, do not forget to quit the application as usual.
- To clean up sessions, in case X2Go is hanging:
- Use the following commands as root:
x2golistsessions, x2goterminate-session, x2gocleansessions
- Use the following commands as root:
- To access your complete desktop on a remote machine:
VERSION CONTROL
To create a record of changes to a large file or a group of files, such the Latex chapters of a thesis, the source files of a program, or the installation scripts and instructions described here, there are several version control systems. They offer the ability to trace related changes across several different files, and to easily go back to an earlier consistent version, in case one changes the mind. The most widely used distributed versioning system currently is Git. Git is very powerful, but it can also be employed for personal use very easily. The initialization and the use of Git with the graphical front end QGit is briefly described here.
- Initialize Git: In terminal at your home directory, initialize your user name and email globally (stored in ~/.gitconfig)
git config --global user.name "Your Name"
git config --global user.email name@provider
This step only needs to be performed once. - Change to the top directory of the project:
cd ProjectDir - Initialize the local Git repository
git init - Add a single file or the entire project directory to be controlled by Git. The directory can contain sub-directories, too.
git add filename
or
git add . - To enter the current version of the project file(s) in the history record of Git, commit them to the repository and include a meaningful comment about the version
git commit -m "Initial Commit" - QGit: From this point on, you can use the graphical user interface QGit to commit new versions to previously added files or to create a branch from an older version. Use to open the project directory.
- After completing changes to one or more files, commit the changes (one file at a time, if changes are unrelated, or groups of files that have related changes) with #. All lines starting with # will be ignored (but they contain useful hints). Click on Commit when ready. (select corresponding file(s) only) and give an explanatory message in the Comments field. You need to add new lines not starting with
- You can easily compare versions by selecting both with the Ctrl key and selecting External Diff from the right-click menu.
- To add a new file to the list that can be committed, you have to run this command in a terminal at the project directory
git add filename
An entire sub-directory can also be added with this command. - To change a file name and keep the file history, you have to use the following Git command:
git mv oldfilename newfilename - To delete a file, you have to use the following Git command:
git rm filename - Branch: If you want to restart your work based on an older version or start a parallel development of another version, create a branch:
- First make a clone of the project in a separate directory:
cd ..
git clone ProjectDir NewProjectDir - In QGit, open the new project directory, select the version to branch out from, right-click and select Make branch. Enter the branch name, say NewBranch. Or, from the command line:
cd NewProjectDir
git branch NewBranch - Then switch to the branch by right-clicking again and selecting the branch name at bottom of the pop-up menu. Or, from the command line: git checkout NewBranch
- First make a clone of the project in a separate directory:
- If you have transferred the project directory from another computer without using the git clone command, then you first need to update the index of QGit with .
ENCRYPTION
In case of a laptop, University rules require that you have a complete encrypted home partition.
In case you want to share files securely over email or otherwise, or if you want to store them securely on your desktop computer or in any backup medium, you need to encrypt the files separately.
Using GnuPG for encryption of files:
- KGpg ( ): KGpg is a key manager and can help encrypt and decrypt files.
First generate a key pair:- When you start KGpg for the first time, accept the binary, Next. Then check Generate New Key and Start KGpg automatically. After the first start, you can also open the Key Manager and go to the menu .
- Give Name, Email and comment for user ID.
- Choose expiration: 0 (never expires).
- Choose the key length: 2048, for example.
- Choose the algorithm: RSA & RSA (or DSA & ElGamal).
- Enter a Passphrase: note that a long sequence of unrelated words is easier to remember and harder to crack than a short sequence of mixed letters and symbols.
- Check Set as Default Key and Save a revocation Certificate.
- You can also generate a key pair from the command line with:
gpg --gen-key
- Now, you can export the public key and give it to others, so they can encrypt files that only you can decrypt. You also can export it to a key server, so others can more easily find it.
- You can also right-click on the key and Export Secret Key, but make sure you encrypt the file and save it in a secure and hidden place. This secret key can be imported into KGpg at another machine to enable encryption and decryption with the same key pair.
- To import an existing key from another machine, first decrypt the file on a machine that has KGpg set, then import the decrypted key in the new machine. Do not forget to delete the decrypted file.
- To Trust your own key (or any imported key), double-click on it, change Owner trust to Ultimately and OK. You may have to refresh the list (F5) to see the Trust colour change.
- You can also set this key as the default key: right-click and select Set as Default Key.
- To encrypt a file, right-click on it and select Open Editor, then Open the text file and click on Encrypt. Select your Public Key from the list, then Save As, if you want a different name for the encrypted file. After saving the encrypted file, do not forget to delete the unencrypted version, in case you used different names. . In case of a text file, you can also right-click on KGpg and select
- You can also encrypt a file from the command line with:
gpg [-r userID] -e file.name
If no userID is given, the default key (your own) is used. The encrypted file is saved in the same directory as file.name.pgp. - To decrypt a file, right-click on it and choose
In case of a text file, you can also right-click on KGpg and select Open Editor, then Open the encrypted file and click on Decrypt, or simply right-click on the file itself and choose Actions / View file decrypted. These two methods do not create an unencrypted file on the disk, just on memory, and the unencrypted text disappears, when you close the Editor window.
. With this method, a copy of the decrypted file will be saved in the same directory. - You can also decrypt a file from the command line with:
gpg -d file.name.pgp > file.name - If you want to modify an encrypted text file, after opening it and decrypting with the KGpg Editor, do not forget to encrypt again the modified text before saving the encrypted file.